Skip to content
Senior Living Liability

Question

Does cyber insurance cover a resident health information breach?

Short answer

Yes for the standard breach response, notification, credit monitoring, regulatory defense and liability, but senior care adds three exposures many forms handle poorly: business interruption when the electronic health record is down, contingent exposure through a pharmacy or billing vendor, and the physical safety consequence of losing an electronic access control or nurse call system.

Why this population is a target

Resident records combine full identity data, Social Security numbers, Medicare numbers, financial account information used for automatic payment of monthly fees, and health data, held for a population less likely to be actively monitoring credit. That is close to the highest-value record set outside a hospital, held by organizations with far smaller security budgets.

The threat that actually arrives is usually ransomware rather than exfiltration for resale, and the damage is operational before it is legal: medication administration records unavailable, care plans unavailable, and staff reverting to paper in a setting where the documentation is the defense to the next liability claim.

What a standard cyber policy handles well

Breach response costs including forensics, legal counsel and notification. Credit and identity monitoring for affected individuals. Regulatory defense and, where insurable, fines under health information privacy rules. Third-party liability for claims by affected individuals. Extortion payments and negotiation, subject to sanctions compliance.

These are the mature parts of the product and the coverage is generally adequate if the limit is. Notification cost scales directly with record count, so an operator with several thousand current and former residents should be thinking in terms of a limit that covers notification for the whole record set, not the current census.

The three senior-care gaps to check

System failure and business interruption. Confirm the policy covers loss of income from an outage caused by your own system failure and not only by a security incident, and confirm the waiting period, because a twelve-hour waiting period is meaningless when the outage lasts two hours and costs you the whole day.

Dependent business interruption. Your electronic health record, your pharmacy, your billing vendor and your payroll processor are all single points of failure you do not control. Contingent coverage should name vendor categories rather than only listed entities.

Bodily injury flowing from a cyber event. Most cyber forms exclude bodily injury and most liability forms exclude cyber, which means an incident where a compromised access control system allows an elopement, or a downed nurse call system delays a response, can fall between the two. Ask for an express carve-back on one side or the other and get it in writing.

What to do before renewal

Get the record count, current and archived, from your health record vendor. Get the vendor list and the recovery time objective each vendor contractually commits to. Confirm multi-factor authentication on remote access and email, because it is now a condition of quoting in most of this market rather than a discount.

Then size the limit against notification cost for the full record set plus a realistic outage. Operators routinely buy a limit sized for the liability tail and find that the operational loss consumed it first.

Primary sources

Sources and references

This answer draws on the following regulatory, statutory, and standards-body sources. Coverage availability and program structure also depend on market appetite and underwriter discretion not captured by these sources.

Related practice areas

Insurance clauses in this area

Related questions

Have a more specific question?

A specialist will reach out by the end of the day.

Request a free coverage review

Last updated

Free coverage review

A specialist will reach out by the end of the day.

No marketing sequences, no list rental.