Back to Columns
Healthcare Security12 min read

Cyber Insurance for Healthcare Providers: What Is Covered, and What Is Not

September 14, 2026

Cyber Insurance for Healthcare Providers: What Is Covered, and What Is Not
Share this article

The cost of a cyberattack swells around the recovery rather than in it: forensic investigation, outside specialists, patient notification, a call centre, lost revenue while care is suspended, and rebuilding afterwards. Whether your working capital can absorb that is where the cyber insurance question starts.

Providers who begin looking often come away feeling that the product is not what they expected. Cyber insurance does not make you whole. Coverage differs by contract, meaningful exclusions are written in, and insurers expect a level of control before they will bind.

This article sets out what to confirm before signing. It does not compare products or quote premiums — policies are individually underwritten, so generalising about price has little practical value. Obtain and read the policy wording.

Disclaimer: This is general information, not a recommendation of any product nor advice on insurance contracts. Coverage, exclusions, and underwriting conditions vary by insurer and contract.

What Cyber Insurance Is Trying to Cover

Costs fall into layers of different character. Work out which layer is heavy for you first, then compare products.

LayerContentWeight for a provider
Incident response costsForensics, outside specialists, legal adviceHigh. Few providers can investigate in-house
Notification and handlingPostal notification, an enquiry line, press handlingScales with patient numbers
RecoveryData recovery, system rebuildDepends on architecture; large if rebuilding
Business interruptionLost revenue, cost of workaroundsCan become the largest item in a long outage
LiabilityClaims from patients and counterpartiesDepends on volume and nature
Regulatory handlingCosts of responding to reporting dutiesModerate — see breach reporting

Business interruption is the most overlooked. Weeks of suspended care can exceed forensics and notification combined — but it is also the most complex layer to underwrite, and waiting periods and calculation methods change the payout substantially.

What Tends to Be Excluded

A policy's value lies as much in what is carved out.

IssueTypical treatment
System upgradesImprovements beyond restoring the prior state are usually excluded
Unpatched known vulnerabilitiesFailing to apply fixes can trigger exclusion or reduction
Pre-existing eventsIncidents occurring or known before inception are excluded
Insider wrongdoingCovered in some policies, not others. Confirm
Ransom paymentsTreated inconsistently; often excluded or conditioned
Incidents originating at a supplierTreatment splits along the responsibility boundary
Regulatory finesMay be excluded depending on jurisdiction and nature

Unpatched known vulnerabilities deserve the most attention. A perimeter device left unpatched for months, or unsupported equipment still in service, will become a point of contention at claim time. Conversely, keeping vulnerability management records protects the policy's usefulness. See Managing VPN Device Vulnerabilities.

Note too that restoring the prior state and improving on it are treated differently — align expectations with the insurer while recovery strategy is still being decided.

What Insurers Expect Before Binding

  1. Backups — frequency, generation management, whether any copy is offline
  2. Multi-factor authentication — especially remote access and administrator accounts
  3. Endpoint protection — anti-malware and detection
  4. Vulnerability management — patch status, any unsupported equipment
  5. Access control — privileged ID management, removal of leavers' accounts
  6. Incident response — a plan, a named manager, evidence of drills
  7. Staff training — delivery and records

Read that list against the FY2026 add-on requirements and the Guidelines for the Safe Management of Medical Information Systems and the overlap is obvious: the work of qualifying for the add-on is largely the work of becoming insurable.

See A BCP for Cyberattacks, The Medical Information Safety Manager Role, Introducing Multi-Factor Authentication, and Access Control and Privileged IDs.

Disclose accurately. "Planned" must not be recorded as "implemented"; the discrepancy surfaces at claim time.

Questions to Ask Before Signing

ItemThe question
Covered eventsWhat counts as a cyber event? Is business interruption without any data leak covered?
Business interruption basisWaiting period? How is lost revenue calculated? Is post-recovery shortfall included?
LimitsPer event or aggregate? Are there sublimits per cost category?
DeductibleHow much do you bear?
Response servicesAre specialist referral and deployment bundled? Is intake 24-hour?
Supplier-originated eventsHow are cloud and maintenance provider failures treated?
Notification costsCaps relative to patient numbers; call centre treatment
Regulatory and disclosureAre the costs of reporting and press handling included?
Notice to insurerBy when must you notify the insurer after an incident?
RenewalRenewability after a claim, and likely condition changes

Bundled response services matter most in practice. Finding specialists after the fact costs days, as described in First Response to Ransomware. If the policy provides a hotline and arranges responders, first response gets faster; if the bundle is thin, arrange a separate retainer.

Notice deadlines to the insurer are easily missed while everyone is firefighting. Put the insurer and broker on the incident plan's contact list.

Insurance Is Not a Substitute for Controls

Cyber insurance does not return lost clinical time or patient trust. It offsets part of the financial loss. It does not shorten recovery, undo the impact on regional care provision, or discharge the duty to explain. For a healthcare provider, the largest loss is usually the stoppage itself, which sits outside monetary compensation.

The correct placement:

The evaluation process has a side benefit: an underwriting questionnaire functions as a control inventory. Use the exercise of finding out whether you are insurable as a way of seeing where you stand. For the same purpose, the checklist MHLW published on 14 May 2025 is more systematic — see How to Use the MHLW Security Checklist.

Conclusion

  1. Coverage splits into response, notification, recovery, business interruption, and liability; business interruption dominates in long outages
  2. Checking exclusions matters as much as checking coverage — upgrades, pre-existing events, insiders, ransom payments
  3. Unpatched known vulnerabilities can void or reduce a claim. Vulnerability records protect the policy
  4. Underwriting questions overlap heavily with the add-on requirements and the guidelines
  5. Confirm bundled response services and the notice deadline, and put them in the incident plan
  6. Insurance is not a substitute for controls — it transfers what remains after prevention and preparedness

Evaluating insurance pairs naturally with taking stock of your risks and controls. Pottech advises from the standpoint of designing and operating medical information systems — contact us. For assessing a supplier's management system, see What Is an ISMS (ISO/IEC 27001)?.

References and Sources

Note: coverage, exclusions, and underwriting conditions vary by insurer and contract and are subject to change. This article is a general framing, not a product recommendation or insurance advice.

Share this article

Related Articles

Healthcare Security

Access Control and Privileged ID Management: What Is Realistic in a Hospital

Role-based permissions, least privilege, offboarding and transfer reviews, vendor maintenance accounts, and what to do where shared IDs genuinely cannot be eliminated. Access design that actually limits blast radius within the constraints of clinical work.

September 14, 2026
Healthcare Security

Antivirus and EDR: What a Hospital Should Decide Before Buying

How EDR differs from conventional antivirus, why it is not a product that protects you simply by being installed, how to choose an operating model for the alerts it produces, what to do about devices it cannot be installed on, and what to settle before you buy.

September 14, 2026
Healthcare Security

Logging and Audit Trails: Getting Past 'We Collect It but Nobody Looks'

What to log, how long to retain it, and the real problem — logs collected but never read. Which logs actually matter during an incident, and how to make review a sustainable routine in a hospital with limited staff.

September 14, 2026
Healthcare Security

Backup Design for Hospitals: The 3-2-1 Rule and the Tier 1 Requirement

Japan's FY2026 revision makes multi-method backup with part of it held offline a tier 1 requirement. We cover the three methods accepted as meeting it — external media, automated transfer to a permanently detached NAS, and a logically separated area within a cloud service — plus generation management and why an untested backup does not count.

September 14, 2026
AI Karte

Explore AI Karte

An AI-native EHR connecting reception, documentation, accounting, claims, and analytics into one cycle.

View the product page

ISMS Certification Support as an Option

From scope design and documentation to training, internal audit, and dealing with the certification body. Pottech supports healthcare companies through ISO/IEC 27001 certification end to end.