Cyber insurance is one of the most misunderstood products small practices buy. Owners assume the policy covers them the way auto insurance covers a car accident. They pay the premium, they file a claim, they get paid. That's not how it works.
Insurers pay out when a breach happens and you had the right controls in place before it happened. If the controls weren't there, the claim gets denied. You've paid premiums for years and you're still holding the full cost of the breach.
Here's what's actually in a standard cyber policy, where the gaps are, and what you need to have documented before you need to use it.
What a standard cyber policy typically covers
Cyber insurance policies vary, but most small-practice policies include some version of the following:
- First-party costs: Your own costs after a breach. This includes forensic investigation, data recovery, notifying affected clients or patients, and credit monitoring if required by state law.
- Business interruption: Lost revenue during downtime caused by the incident. Coverage here varies widely. Read the sublimits carefully.
- Ransomware response: Negotiation costs, ransom payments (in some policies), and recovery support. Not all policies cover ransom payments. Some require you to notify law enforcement before paying.
- Third-party liability: Defense costs and settlements if a client or patient sues because their data was exposed through your practice.
- Regulatory fines: Coverage for fines from HIPAA enforcement actions or state data breach regulators. This coverage is often capped and conditional.
The key phrase in every cyber policy: "At the time of the incident, the insured had reasonable security controls in place." That phrase is doing a lot of work. What counts as reasonable is defined in the application you signed — and auditors will check it.
Why claims get denied
Denial reasons fall into three categories. All of them are preventable.
1. You checked "yes" on the application but the control wasn't in place
When you applied for coverage, you answered questions about your security setup. Multi-factor authentication, password policies, backups, staff training. If you said yes to something that wasn't actually implemented, and the breach traces back to that gap, the insurer will deny the claim as a material misrepresentation.
This isn't rare. Many practice owners answer application questions based on what they intend to have in place, or what their IT vendor told them was set up. The audit after a breach is much more thorough than the application process before it.
2. A required control was missing entirely
Some controls are now standard requirements for coverage, not just nice-to-haves. Multi-factor authentication (MFA) on email and remote access is the most common. If your staff can log into your email system with just a password, and a breach happens through a compromised password, your claim is at risk.
Endpoint detection and response (EDR) software, offsite backups, and written incident response plans are increasingly required by mid-tier policies.
3. You didn't report the incident within the required window
Most policies require you to report a known or suspected breach within 24 to 72 hours of discovery. Waiting to see if it's "really a breach" before calling your insurer often means waiting too long. Report early. You can always update the report as facts develop.
Common scenario: A staff member's email gets compromised. You reset the password and move on. Three months later, you discover the attacker had been in your system the whole time and accessed patient records. The clock for reporting started at the first incident, not when you discovered the full scope.
What your policy probably doesn’t cover
Even good policies have exclusions worth knowing before you need them:
- Unencrypted devices: A stolen laptop with unencrypted patient files is often excluded, or treated as negligence that voids the claim.
- Prior known vulnerabilities: If you knew about a security issue and didn't fix it, and that issue led to the breach, coverage may be denied.
- Social engineering/wire fraud: If a staff member was tricked into sending money to a fraudulent account, this is often a separate endorsement, not covered under the base policy.
- Reputational damage: The cost of clients leaving after a breach is not covered. Neither is the PR work to manage the fallout.
- Betterment: Your insurer won't pay for security upgrades after a breach that are better than what you had before. They'll pay to restore, not to improve.
What to do before you file a claim (or before you need to)
The best time to prepare for a cyber insurance claim is before anything happens. Three things make the biggest difference:
- Audit your application answers against reality. Pull out your current policy application. Go through every "yes" answer and verify it's actually in place. If it's not, either fix it or notify your broker. Proactive disclosure is always better than denial after a claim.
- Document your controls. Insurers ask for proof, not promises. Having a written record of what you have, when it was implemented, and who is responsible is the difference between a smooth claim and a fight.
- Know your policy's reporting window. Read the incident reporting section of your policy now. Write down the number to call. Put it somewhere your whole team can find it.
Cyber insurance is worth having. But it works best as a backstop for a practice that already has reasonable controls in place, not as a substitute for them. If you're not sure what your policy requires or whether your current setup meets it, that gap is worth closing before a claim forces the question.
Not sure if your setup would hold up under a claim review?
The free Cyber Health Score gives you an instant read on the controls insurers look for most. Takes 5 minutes.
Get your free Cyber Health Score