Back to resources

Cyber insurance is one of the most misunderstood products small practices buy. Owners assume the policy covers them the way auto insurance covers a car accident. They pay the premium, they file a claim, they get paid. That's not how it works.

Insurers pay out when a breach happens and you had the right controls in place before it happened. If the controls weren't there, the claim gets denied. You've paid premiums for years and you're still holding the full cost of the breach.

Here's what's actually in a standard cyber policy, where the gaps are, and what you need to have documented before you need to use it.

What a standard cyber policy typically covers

Cyber insurance policies vary, but most small-practice policies include some version of the following:

The key phrase in every cyber policy: "At the time of the incident, the insured had reasonable security controls in place." That phrase is doing a lot of work. What counts as reasonable is defined in the application you signed — and auditors will check it.

Why claims get denied

Denial reasons fall into three categories. All of them are preventable.

1. You checked "yes" on the application but the control wasn't in place

When you applied for coverage, you answered questions about your security setup. Multi-factor authentication, password policies, backups, staff training. If you said yes to something that wasn't actually implemented, and the breach traces back to that gap, the insurer will deny the claim as a material misrepresentation.

This isn't rare. Many practice owners answer application questions based on what they intend to have in place, or what their IT vendor told them was set up. The audit after a breach is much more thorough than the application process before it.

2. A required control was missing entirely

Some controls are now standard requirements for coverage, not just nice-to-haves. Multi-factor authentication (MFA) on email and remote access is the most common. If your staff can log into your email system with just a password, and a breach happens through a compromised password, your claim is at risk.

Endpoint detection and response (EDR) software, offsite backups, and written incident response plans are increasingly required by mid-tier policies.

3. You didn't report the incident within the required window

Most policies require you to report a known or suspected breach within 24 to 72 hours of discovery. Waiting to see if it's "really a breach" before calling your insurer often means waiting too long. Report early. You can always update the report as facts develop.

Common scenario: A staff member's email gets compromised. You reset the password and move on. Three months later, you discover the attacker had been in your system the whole time and accessed patient records. The clock for reporting started at the first incident, not when you discovered the full scope.

What your policy probably doesn’t cover

Even good policies have exclusions worth knowing before you need them:

What to do before you file a claim (or before you need to)

The best time to prepare for a cyber insurance claim is before anything happens. Three things make the biggest difference:


Cyber insurance is worth having. But it works best as a backstop for a practice that already has reasonable controls in place, not as a substitute for them. If you're not sure what your policy requires or whether your current setup meets it, that gap is worth closing before a claim forces the question.

Not sure if your setup would hold up under a claim review?

The free Cyber Health Score gives you an instant read on the controls insurers look for most. Takes 5 minutes.

Get your free Cyber Health Score