Question
Does cyber insurance cover a resident health information breach?
Short answer
Yes for the standard breach response, notification, credit monitoring, regulatory defense and liability, but senior care adds three exposures many forms handle poorly: business interruption when the electronic health record is down, contingent exposure through a pharmacy or billing vendor, and the physical safety consequence of losing an electronic access control or nurse call system.
Why this population is a target
Resident records combine full identity data, Social Security numbers, Medicare numbers, financial account information used for automatic payment of monthly fees, and health data, held for a population less likely to be actively monitoring credit. That is close to the highest-value record set outside a hospital, held by organizations with far smaller security budgets.
The threat that actually arrives is usually ransomware rather than exfiltration for resale, and the damage is operational before it is legal: medication administration records unavailable, care plans unavailable, and staff reverting to paper in a setting where the documentation is the defense to the next liability claim.
What a standard cyber policy handles well
Breach response costs including forensics, legal counsel and notification. Credit and identity monitoring for affected individuals. Regulatory defense and, where insurable, fines under health information privacy rules. Third-party liability for claims by affected individuals. Extortion payments and negotiation, subject to sanctions compliance.
These are the mature parts of the product and the coverage is generally adequate if the limit is. Notification cost scales directly with record count, so an operator with several thousand current and former residents should be thinking in terms of a limit that covers notification for the whole record set, not the current census.
The three senior-care gaps to check
System failure and business interruption. Confirm the policy covers loss of income from an outage caused by your own system failure and not only by a security incident, and confirm the waiting period, because a twelve-hour waiting period is meaningless when the outage lasts two hours and costs you the whole day.
Dependent business interruption. Your electronic health record, your pharmacy, your billing vendor and your payroll processor are all single points of failure you do not control. Contingent coverage should name vendor categories rather than only listed entities.
Bodily injury flowing from a cyber event. Most cyber forms exclude bodily injury and most liability forms exclude cyber, which means an incident where a compromised access control system allows an elopement, or a downed nurse call system delays a response, can fall between the two. Ask for an express carve-back on one side or the other and get it in writing.
What to do before renewal
Get the record count, current and archived, from your health record vendor. Get the vendor list and the recovery time objective each vendor contractually commits to. Confirm multi-factor authentication on remote access and email, because it is now a condition of quoting in most of this market rather than a discount.
Then size the limit against notification cost for the full record set plus a realistic outage. Operators routinely buy a limit sized for the liability tail and find that the operational loss consumed it first.
Primary sources
Sources and references
This answer draws on the following regulatory, statutory, and standards-body sources. Coverage availability and program structure also depend on market appetite and underwriter discretion not captured by these sources.
- U.S. Department of Health and Human Services, Office for Civil Rights breach portalhttps://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
- HHS, HIPAA Breach Notification Rulehttps://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html
Related practice areas
Insurance clauses in this area
Related questions
Have a more specific question?
A specialist will reach out by the end of the day.
Request a free coverage reviewLast updated