Five things to check before you sign or renew a cyber policy
- The funds transfer fraud sublimit, in dollarsNot the headline limit. This is the number that answers a stolen payment.why →
- Whether it requires a call-back you actually doSome policies pay only where the habit existed and was defeated.why →
- Where this policy stops and malpractice startsOne event can touch both. Neither substitutes for the other.why →
- Which controls you must maintain all yearAnd what happens if one quietly lapses in month seven.why →
- Who you call first, before you hire anyoneCalling your own forensics firm first can cost you the reimbursement.why →
Who is writing this
I am not an insurance agent and this is not a recommendation to buy. My own business is insured, not certified, meaning not HIPAA, HITRUST, or SOC 2. What I do is put the controls in place and document them so you can answer for them. I bought technology errors and omissions plus cyber coverage this year, so the fine print is fresh.
Lines 1 and 2
The number on the front page is rarely the number that pays.
The most likely way either kind of office loses real money is a rerouted payment. On many policies that loss never touches the headline limit. It falls under a funds transfer fraud sublimit, often a fraction of the figure on the cover.
An office can hold a policy measured in millions and find the coverage for its most likely loss is a fraction of the amount taken. Get the sublimit and its conditions in writing. How the fraud itself works →
What this policy does, and what it never did
Most offices that skip cyber coverage believe professional liability already covers it. It usually does not.
The cyber policy
The incident itself- Forensics, notification, and recovery after ransomware
- Often the income lost while you could not work
- Claims from clients or patients whose data was in the files
Your malpractice policy
Your professional work- Responds when your advice or care allegedly harmed someone
- A data breach is not a professional error, and a carrier can decline on that ground
- A cyber policy, in turn, will not defend your judgment
A breach that delays a filing, or an outage that changes a treatment decision, can touch both. Only an agent holding both documents can draw that line.
The five controls that set your price
The application is mostly an IT questionnaire, and the same five come up whether the letterhead says law office or medical practice. Answer the way you could prove it on a claim.
A no on the questionnaire is a fixable problem. A yes the records do not support is what an insurer points at when a claim is disputed. Question by question →
Looks at your office from the outside. Nothing to install.
Then the part specific to you
Same five controls, different thing at stake
Law firms
- Money in motionTrust and escrow accounts move real amounts on a guessable schedule. Line 1 matters most here.
- Deadlines do not moveA filing date does not care that your document system is down.
- Your clients may decide for youOutside counsel guidelines often require proof of coverage. What the Florida Bar expects is a question for the Bar, not for me.
Medical and dental
- A full schedule is the whole dayWhen the chart system stops, the waiting room does not. Read the business interruption terms closely.
- One application runs everythingPractice management, imaging, and billing lean on the same unwatched box. The backup question is about that box.
- Records duties are not optionalAsk where the policy responds to a regulatory proceeding and where it stops.
On the healthcare side specifically
Four years of my career were corporate IT for a large healthcare organization operating under HIPAA and HITRUST standards, so a practice's technical questions are familiar ground, and I sign a business associate agreement. I am still not certified.
The day it happens, in order
Coverage can be lost in the first two hours by doing the reasonable thing in the wrong order.
- 01Stop the lossIf money moved, call the bank now and ask for a recall. If a machine is compromised, disconnect it and leave it alone. Do not wipe it.
- 02Call the carrier hotline or your brokerBefore you hire anyone. Many policies only reimburse vendors they approved.
- 03Breach counsel takes the wheelFrom the carrier panel, usually. They direct the investigation and own the notification decision.
- 04Forensics, then your IT provider under that directionPreservation and restoration in the order counsel asks for. Rebuilding first destroys the evidence the claim rests on.
- 05Then the questions about your controls arriveThis is when the application answers get re-read. Documented controls are the difference between a claim and an argument.
Questions I get asked
Will a cyber policy pay if a wire or payment is stolen?
Sometimes, and often for less than expected. Stolen payments usually fall under a social engineering or funds transfer fraud sublimit much smaller than the headline limit. Ask your agent for the exact number, and treat the phone call-back on changed payment instructions as the real control.
If our IT is in good shape, can we skip the insurance?
That is a decision for you and your agent, not for an IT provider. Good controls make an incident less likely and a policy cheaper. They do not pay for forensics, notification, or a claim after the incident that still gets through.
What happens to my practice if the chart system is down for a week?
That is what the business interruption section is for, and it is the part a practice should read hardest. Check how the waiting period is measured, whether it starts at the incident or at the claim, and whether it covers income lost from appointments you could not reschedule.
Are you HIPAA compliant, and will you sign a BAA?
I will sign a business associate agreement. I am not HIPAA, HITRUST, or SOC 2 certified, and neither is any vendor who tells you they are, because compliance belongs to your practice rather than to a supplier. What I bring is four years inside a large healthcare organization operating under those standards, and controls documented well enough for you to answer for them.
Do we need a managed plan to get help with these controls?
No. Work for businesses not on a plan is billed at $125 per hour, and larger projects are quoted up front so you approve the number before the work starts.
Before the renewal, not after
Make the application answers true first.
The controls carriers price on are the work I do for law offices and practices across Lee County. Neither the check nor the conversation costs anything.
About the author
Mario Del Mazo is the owner of IT First Response, a managed IT and security practice in Fort Myers serving Lee County, Florida. His background is corporate IT for a healthcare organization operating under HIPAA and HITRUST standards. He publishes his prices, and every client environment is documented so nothing has to be explained twice. More about Mario.
Nothing in this guide is insurance, legal, or tax advice. Coverage varies by policy and carrier, and only a licensed agent reading your own documents can tell you what yours does.
