The renewal application lands in the practice manager's inbox in late September. Question 14: "Does the applicant enforce multifactor authentication on all remote access to its network and email?" Question 19: "Are backups encrypted, stored offline, and tested at least quarterly?" Question 23: "Has the applicant completed a security risk assessment in the past 12 months?" Each has a checkbox. The practice manager, who has never seen the IT contractor's configuration, checks yes on all three because the alternative is a higher premium or no policy.
Two facts frame everything that follows. First, HIPAA does not require cyber insurance. Nothing in the Security Rule at 45 CFR 164.302 through 164.318 mentions a policy, a carrier, or coverage. Second, a cyber policy is not a safeguard. It moves money after an event; it does nothing to reduce the risk to e.P.H.I. (electronic Protected Health Information) that the Security Rule actually regulates. This article covers what the rule does require, what a cyber policy typically covers, why the application is really a compliance attestation, what the policy cannot do for you, and how to write it into the compliance program so both documents tell the same story.
HIPAA Cyber Insurance: Where a Policy Fits in a Compliance Program
What the Security Rule Actually Requires
164.306(a) sets the goal: covered entities and business associates must "ensure the confidentiality, integrity, and availability of all electronic protected health information" they create, receive, maintain, or transmit, and "protect against any reasonably anticipated threats or hazards to the security or integrity of such information." The mechanism is in 164.308(a)(1)(ii). Risk analysis, designated Required: "Conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information." Risk management, also Required: "Implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level."
Read those two together and the place of insurance becomes clear. The rule asks the practice to find its risks and reduce them. A policy does not reduce the probability of a phishing click or the impact of an unencrypted laptop walking out the door. It reimburses some of the cost afterward. The rule does list "the costs of security measures" as a factor in choosing safeguards under 164.306(b)(2)(iii), but that is about which safeguards to buy, not whether to substitute a premium for them. A practice that has a policy and no risk analysis has satisfied its broker and not its regulator. The risk analysis itself is walked through in the security risk assessment guide.
What a Cyber Policy Typically Covers
Policies differ, and the wording of yours is the only thing that binds the carrier. The Federal Trade Commission's small-business guidance, developed with the National Association of Insurance Commissioners, describes the two halves of a typical policy in plain terms. Its lists, condensed:
| First-party coverage (your own costs) | Third-party coverage (claims against you) |
|---|---|
| Legal counsel to determine notification and regulatory obligations | Payments to consumers affected by the breach |
| Recovery and replacement of lost or stolen data | Claims and settlement expenses from disputes or lawsuits |
| Customer notification and call center services | Costs for litigation and responding to regulatory inquiries |
| Lost income from business interruption | Losses related to defamation, copyright, or trademark claims |
| Crisis management and public relations | Other settlements, damages, and judgments |
| Cyber extortion and fraud; forensic investigation | Accounting costs |
| "Fees, fines, and penalties related to the cyber incident" |
The FTC also lists what to look for: coverage for data breaches, for attacks on your data held by vendors and other third parties, for incidents anywhere in the world, "duty to defend" wording for lawsuits and regulatory investigations, and a breach hotline available at all hours. Those are good questions for the broker. One item deserves a caution: "fees, fines, and penalties" appears on the FTC's list of typical first-party coverage, but whether a HIPAA civil money penalty is actually payable under a given policy depends on the policy's wording and on state law. Get that answer from the broker in writing before assuming a resolution agreement is covered.
The Application Is a Compliance Attestation
Look at the questions again. Nearly every one maps to a Security Rule standard, and the honest answer to each is a document the practice either has or does not have.
| Application question | Security Rule item | The evidence that makes "yes" true |
|---|---|---|
| Multifactor authentication on remote access and email | 164.312(d) person or entity authentication; MFA is named explicitly only in the proposed Security Rule update | Admin console screenshots showing MFA enforced for every account |
| Encryption of devices and data in transit | 164.312(a)(2)(iv) and 164.312(e)(2)(ii), both Addressable | Device inventory with encryption status; the written addressable decision |
| Backups encrypted, offline, tested | 164.308(a)(7)(ii)(A) data backup plan, Required | Backup configuration plus dated restore-test records |
| Security awareness training | 164.308(a)(5) | Training log with dates and names |
| Risk assessment in the past 12 months | 164.308(a)(1)(ii)(A) risk analysis, Required | The dated risk analysis and the remediation plan |
| Patching and vulnerability management | 164.308(a)(1)(ii)(B) risk management, Required | Scan results and patch records |
| Incident response plan | 164.308(a)(6)(ii) response and reporting, Required | The written plan with the carrier's hotline in it |
Two cautions. The MFA question is the one most often answered from hope: the current rule requires authentication procedures, and the proposed update would make multifactor authentication an express requirement, but the carrier does not care which rule applies; it cares whether the box is true. And an inaccurate answer is a problem in both directions. It can give the carrier grounds to contest a claim when the practice needs the policy most, and it is a written admission that the practice knew what the safeguard was and did not have it. Answer from evidence, and if the evidence does not exist, the application has just produced the top of the remediation list.
What Insurance Does Not Do
A policy will not write the 164.404 breach letters; it may pay a vendor to mail them, but the 60-day clock and the required contents are the practice's obligation. It will not perform the risk analysis, and OCR's ransomware and hacking cases are, by their titles, Security Rule investigations: the question asked after the incident is whether the safeguards existed, not whether the loss was insured. It will not replace the contingency plan the rule requires under 164.308(a)(7); business-interruption coverage pays for downtime, and the plan is what shortens it. And it does not shorten a corrective action plan. The settlements below all came with multi-year monitoring that no premium buys off.
One point where the compliance program and the policy pull in the same direction: since 2021, federal law directs HHS to consider whether an entity had recognized security practices in place for the prior 12 months when it sets penalties and resolves audits. The documented safeguards that make an application truthful are the same ones that count in that calculation.
What OCR's Ransomware Cases Show
OCR settled a ransomware cybersecurity investigation under the HIPAA Security Rule for $250,000 (September 26, 2024), two more for $90,000 and $500,000 on the same day (October 31, 2024), and imposed a $240,000 civil monetary penalty against Providence Medical Institute in a ransomware cybersecurity investigation (October 3, 2024). A ransomware settlement for $10,000 (January 15, 2025) shows the small end of the scale reaches small entities. In each, the announced basis is the Security Rule. Whatever the entities' carriers paid for forensics and notification, the regulator's finding was about the safeguards. CISA's guidance for ransomware readiness starts in the same place: "conduct regular vulnerability scanning to identify and address vulnerabilities, especially those on internet-facing devices." That is risk management, and it is covered in HIPAA vulnerability scanning requirements.
Using the Policy Well
A policy that is filed with the lease and never read is worth less than it costs. The useful version is integrated with the compliance program at four points:
- The incident response plan. Put the carrier's claim hotline, the policy number, and the panel counsel contact on the first page of the 164.308(a)(6) procedure. Read the notice conditions; many policies require the carrier to be notified before forensic or legal vendors are engaged, and a well-meaning call to the local IT shop can complicate a claim. The first-day sequence is in the ransomware first-72-hours guide.
- The contingency plan. The recovery timeline the practice can actually achieve, and the waiting period and limits in the business-interruption coverage, should be read side by side. If the plan says three days and the policy pays after ten, that gap is a decision to make now.
- The vendor file. Coverage for data held by third parties is on the FTC's checklist. The practice's vendor list and B.A.A. (Business Associate Agreement) file should identify which vendors hold ePHI so the broker can price that risk accurately, and so the vendor-breach response knows whom to call.
- The annual evaluation. 164.308(a)(8) requires a periodic evaluation of the security program. Do it before the renewal application, not after, so every answer on the form is pulled from a current document.
What to Write Into the Policy Set
- A one-paragraph statement in the security management policy that insurance is a financial control, that it does not satisfy any Security Rule standard, and that application answers are drawn from the compliance file.
- The owner (usually the security official under 164.308(a)(2)) who reviews the application against the risk analysis and signs off on its accuracy.
- Carrier notice steps inside the incident response procedure, with the hotline and the notice deadline from the policy.
- A calendar entry: security evaluation and application review 60 days before renewal.
- Retention of each year's application, the evidence behind each answer, and the policy itself, six years under 164.316(b)(2)(i).
Buy the policy if the numbers make sense for the practice; that is a business decision, and this article is not advice on whether to make it. Just do not confuse it with compliance. The Security Rule asks whether you found and reduced your risks. The carrier asks the same question in different words, and the only way to answer both honestly is the same set of documents.
---
FAQ
Does HIPAA require cyber insurance?
No. Nothing in the Security Rule at 45 CFR 164.302 through 164.318 requires insurance. The rule requires a risk analysis, risk management, and the administrative, physical, and technical safeguards; a policy is a financial control, not a safeguard.
Can cyber insurance count as a HIPAA safeguard?
No. Insurance transfers cost after an incident; it does not reduce the risk to ePHI. 164.308(a)(1)(ii)(B) requires security measures that reduce risks to a reasonable and appropriate level, and a premium does not do that.
What does a cyber insurance policy usually cover?
According to FTC small-business guidance, first-party coverage typically includes legal counsel, data recovery, notification and call center costs, business interruption, crisis management, cyber extortion, forensics, and fees, fines, and penalties; third-party coverage typically includes consumer payments, lawsuit and settlement costs, and regulatory inquiry costs. The policy wording controls.
Will cyber insurance pay a HIPAA fine?
It depends on the policy's wording and on state law. Fees, fines, and penalties appear on the FTC's list of typical first-party coverage, but confirm with the broker in writing whether a HIPAA civil money penalty or settlement is covered under the specific policy.
Why do the application questions look like a HIPAA checklist?
Because they map to Security Rule items: authentication, encryption, backups, training, risk analysis, patching, and incident response. Each answer should come from a document in the compliance file, and an inaccurate answer can give the carrier grounds to contest a claim.
Conclusion
The application questions are a Security Rule checklist in disguise, and the practices that answer them honestly are the ones with a current risk analysis. One Guy Consulting's Full-Scope plan includes the risk analysis, the remediation plan, and the policy set that turns each checkbox into a documented, true answer, with consulting time for the renewal conversation. Start with a free 30-minute compliance review. No obligation, no pressure.
Sources
- 45 CFR 164.308 (administrative safeguards: risk analysis, risk management, contingency plan, incident procedures)
- 45 CFR 164.306 (security standards: general rules)
- 45 CFR 164.312 (technical safeguards)
- FTC: Cyber Insurance (small business cybersecurity guidance)
- CISA: StopRansomware.gov
- NIST SP 800-66 Rev. 2: Implementing the HIPAA Security Rule
Related Reading