Skip to content
Senior Living Liability

TL;DR

  • Senior care holds health information, financial information and identity documents for a population that is a preferred fraud target.
  • The operational half matters more than most operators expect: care cannot pause while systems are restored.
  • Regulatory response and notification costs are frequently the largest component of a breach, ahead of any liability.
  • Business associate agreements mean a vendor breach can become your notification obligation.

Line of coverage

Cyber liability for senior carea health care data problem attached to an operation that runs on paper and shift handoffs

Cyber is the line senior care operators most often treat as a technology problem and buy accordingly. It is a health care data problem sitting on top of an operation that mixes electronic records with paper charting, shift handoffs, personal devices and a workforce with high turnover.

It is also two distinct exposures sold in one policy. The first is the data: resident health information, Social Security numbers, insurance details, and in many buildings resident financial accounts. The second is the operation: what happens to care delivery when the electronic health record, the medication administration system, the call light platform or the door access controls stop working.

Last updated

Who this applies to

Every operator holding resident health information, which is all of them. Providers subject to HIPAA as covered entities carry regulatory obligations on top of the liability, and business associate agreements pull vendors into the same framework.

01

What the line actually does

First-party coverage pays your own costs after an incident: forensic investigation, legal counsel, notification to affected individuals, credit monitoring, public relations, and restoration of data and systems.

Business interruption and extra expense within the cyber policy responds to income lost and cost incurred while systems are down. This is a distinct trigger from the property policy business income, which generally requires physical damage.

Cyber extortion covers ransom demands and the negotiation and response costs around them, subject to conditions and to applicable law.

Third-party liability responds to claims by individuals whose information was exposed, and to regulatory proceedings, including fines and penalties where insurable.

Regulatory defense and the cost of responding to an enforcement inquiry are frequently the largest single component, and they arrive whether or not anyone sues.

02

Why senior care is not the general case

The data set is unusually rich. Health information, Social Security numbers, Medicare and Medicaid identifiers, insurance details, and often bank or trust account information for residents. That combination supports both medical identity theft and financial fraud, and the resident population is a preferred target for both.

Care does not pause. A retailer with encrypted systems loses sales. A skilled nursing facility with an encrypted electronic health record still has to administer medications, document assessments and respond to call lights, on paper, with staff who may never have done it that way. The downtime procedure is a clinical safety issue rather than an inconvenience, and gaps in it produce medication errors that become liability claims.

Notification obligations attach to health information under HIPAA and to personal information under state breach laws, and the two do not align. A single incident can trigger both, on different timetables.

Business associate agreements mean the pharmacy, the therapy contractor, the billing vendor and the electronic health record host all handle your residents data. A breach at any of them can become your notification obligation and your reputational event.

The workforce profile creates phishing exposure: high turnover, shared workstations, personal devices used for scheduling and communication, and limited security training budget.

03

Where it goes wrong

Limits sized to revenue rather than to record count. Notification cost scales with the number of individuals affected, and a mid-sized operator holding years of resident records can face a notification population far larger than its current census.

Business interruption within the cyber policy carrying a waiting period long enough to exclude the outage you are actually likely to have.

Dependent or contingent business interruption missing, so an outage at your electronic health record vendor, which is the likeliest scenario, is not covered.

Ransomware sublimits well below the policy limit, sometimes with coinsurance.

Conditions precedent nobody has verified: multifactor authentication, backup practices, patching cadence. Some forms make these warranties, and a mismatch between the application answers and the actual environment is a coverage problem at the worst moment.

Prior acts and the discovery problem. Breaches are frequently discovered long after they occur, so a policy with a recent retroactive date may not respond to an intrusion that began earlier.

No coordination with the professional liability program when a downtime event causes a clinical error. That claim is a care claim arising from a cyber event, and the two policies need to agree about it.

04

What to actually do

Size the limit against the number of individuals whose records you hold, not against revenue. Ask your electronic health record vendor how many resident records exist historically, including discharged and deceased residents, because those records are still notifiable.

Confirm dependent business interruption is included and that it reaches your electronic health record host, pharmacy system and billing vendor by name or by category.

Check the business interruption waiting period against a realistic outage. A waiting period measured in days can exclude most real events.

Verify the security warranties on the application match reality, in writing, before binding. If the form asks about multifactor authentication and the answer is partial, say so.

Collect the business associate agreements and confirm each vendor carries its own cyber coverage with a limit proportionate to the data it holds.

Build and drill the downtime procedure as a clinical process rather than an IT one: paper medication administration records, paper charting, manual call light rounds, door and elevator access. This is the control that prevents a cyber event from becoming a liability claim.

Ask how a clinical error occurring during a system outage would be handled across the cyber and professional liability policies. Get the coordination answer before you need it.

Follow-up questions

Cyber and HIPAA: what operators ask

We are a small operator with mostly paper records. Do we need cyber?

Almost certainly yes. Billing runs electronically, payroll runs electronically, email carries resident information routinely, and most operators hold more electronic data than they think. Paper charting reduces one exposure without removing the notification obligation that attaches to whatever is electronic.

How should we size the limit?

By record count rather than revenue, because notification and credit monitoring costs scale with the number of individuals affected. Include historical records: discharged and deceased residents are still notifiable, and for a long-established building that population can be many times current census.

Our electronic health record vendor was breached. Is that our problem?

Usually yes to some degree. As the covered entity you generally retain notification obligations to affected individuals even where the vendor caused the incident. The business associate agreement governs allocation between you, which is why those agreements and the vendor own coverage are worth reviewing before anything happens.

Does cyber cover a medication error caused by a system outage?

That is a coordination question worth answering in advance. The outage is a cyber event and the harm is a care event, so both policies are arguably implicated and each may point at the other. Ask both carriers, in writing, how they would handle it, and make sure the downtime procedure is documented and drilled so the underlying error is less likely.

Go deeper

Other lines of coverage

Free coverage review

One line is never the whole program.

Send the declarations page and five years of loss runs. A specialist reads this line against the rest of the structure and tells you where the gaps actually are, within one business day.