The cost of a cyberattack swells around the recovery rather than in it: forensic investigation, outside specialists, patient notification, a call centre, lost revenue while care is suspended, and rebuilding afterwards. Whether your working capital can absorb that is where the cyber insurance question starts.
Providers who begin looking often come away feeling that the product is not what they expected. Cyber insurance does not make you whole. Coverage differs by contract, meaningful exclusions are written in, and insurers expect a level of control before they will bind.
This article sets out what to confirm before signing. It does not compare products or quote premiums — policies are individually underwritten, so generalising about price has little practical value. Obtain and read the policy wording.
Disclaimer: This is general information, not a recommendation of any product nor advice on insurance contracts. Coverage, exclusions, and underwriting conditions vary by insurer and contract.
What Cyber Insurance Is Trying to Cover
Costs fall into layers of different character. Work out which layer is heavy for you first, then compare products.
| Layer | Content | Weight for a provider |
|---|---|---|
| Incident response costs | Forensics, outside specialists, legal advice | High. Few providers can investigate in-house |
| Notification and handling | Postal notification, an enquiry line, press handling | Scales with patient numbers |
| Recovery | Data recovery, system rebuild | Depends on architecture; large if rebuilding |
| Business interruption | Lost revenue, cost of workarounds | Can become the largest item in a long outage |
| Liability | Claims from patients and counterparties | Depends on volume and nature |
| Regulatory handling | Costs of responding to reporting duties | Moderate — see breach reporting |
Business interruption is the most overlooked. Weeks of suspended care can exceed forensics and notification combined — but it is also the most complex layer to underwrite, and waiting periods and calculation methods change the payout substantially.
What Tends to Be Excluded
A policy's value lies as much in what is carved out.
| Issue | Typical treatment |
|---|---|
| System upgrades | Improvements beyond restoring the prior state are usually excluded |
| Unpatched known vulnerabilities | Failing to apply fixes can trigger exclusion or reduction |
| Pre-existing events | Incidents occurring or known before inception are excluded |
| Insider wrongdoing | Covered in some policies, not others. Confirm |
| Ransom payments | Treated inconsistently; often excluded or conditioned |
| Incidents originating at a supplier | Treatment splits along the responsibility boundary |
| Regulatory fines | May be excluded depending on jurisdiction and nature |
Unpatched known vulnerabilities deserve the most attention. A perimeter device left unpatched for months, or unsupported equipment still in service, will become a point of contention at claim time. Conversely, keeping vulnerability management records protects the policy's usefulness. See Managing VPN Device Vulnerabilities.
Note too that restoring the prior state and improving on it are treated differently — align expectations with the insurer while recovery strategy is still being decided.
What Insurers Expect Before Binding
- Backups — frequency, generation management, whether any copy is offline
- Multi-factor authentication — especially remote access and administrator accounts
- Endpoint protection — anti-malware and detection
- Vulnerability management — patch status, any unsupported equipment
- Access control — privileged ID management, removal of leavers' accounts
- Incident response — a plan, a named manager, evidence of drills
- Staff training — delivery and records
Read that list against the FY2026 add-on requirements and the Guidelines for the Safe Management of Medical Information Systems and the overlap is obvious: the work of qualifying for the add-on is largely the work of becoming insurable.
See A BCP for Cyberattacks, The Medical Information Safety Manager Role, Introducing Multi-Factor Authentication, and Access Control and Privileged IDs.
Disclose accurately. "Planned" must not be recorded as "implemented"; the discrepancy surfaces at claim time.
Questions to Ask Before Signing
| Item | The question |
|---|---|
| Covered events | What counts as a cyber event? Is business interruption without any data leak covered? |
| Business interruption basis | Waiting period? How is lost revenue calculated? Is post-recovery shortfall included? |
| Limits | Per event or aggregate? Are there sublimits per cost category? |
| Deductible | How much do you bear? |
| Response services | Are specialist referral and deployment bundled? Is intake 24-hour? |
| Supplier-originated events | How are cloud and maintenance provider failures treated? |
| Notification costs | Caps relative to patient numbers; call centre treatment |
| Regulatory and disclosure | Are the costs of reporting and press handling included? |
| Notice to insurer | By when must you notify the insurer after an incident? |
| Renewal | Renewability after a claim, and likely condition changes |
Bundled response services matter most in practice. Finding specialists after the fact costs days, as described in First Response to Ransomware. If the policy provides a hotline and arranges responders, first response gets faster; if the bundle is thin, arrange a separate retainer.
Notice deadlines to the insurer are easily missed while everyone is firefighting. Put the insurer and broker on the incident plan's contact list.
Insurance Is Not a Substitute for Controls
Cyber insurance does not return lost clinical time or patient trust. It offsets part of the financial loss. It does not shorten recovery, undo the impact on regional care provision, or discharge the duty to explain. For a healthcare provider, the largest loss is usually the stoppage itself, which sits outside monetary compensation.
The correct placement:
- Prevention — backup design, vulnerability management, network segmentation
- Preparedness — an incident plan, a BCP, drills
- Insurance — transferring the residual financial risk once the first two are done
The evaluation process has a side benefit: an underwriting questionnaire functions as a control inventory. Use the exercise of finding out whether you are insurable as a way of seeing where you stand. For the same purpose, the checklist MHLW published on 14 May 2025 is more systematic — see How to Use the MHLW Security Checklist.
Conclusion
- Coverage splits into response, notification, recovery, business interruption, and liability; business interruption dominates in long outages
- Checking exclusions matters as much as checking coverage — upgrades, pre-existing events, insiders, ransom payments
- Unpatched known vulnerabilities can void or reduce a claim. Vulnerability records protect the policy
- Underwriting questions overlap heavily with the add-on requirements and the guidelines
- Confirm bundled response services and the notice deadline, and put them in the incident plan
- Insurance is not a substitute for controls — it transfers what remains after prevention and preparedness
Evaluating insurance pairs naturally with taking stock of your risks and controls. Pottech advises from the standpoint of designing and operating medical information systems — contact us. For assessing a supplier's management system, see What Is an ISMS (ISO/IEC 27001)?.
References and Sources
- Guidelines for the Safe Management of Medical Information Systems | MHLW
- FY2026 Medical Fee Revision | MHLW
- Information-technology Promotion Agency (IPA)
- Personal Information Protection Commission
Note: coverage, exclusions, and underwriting conditions vary by insurer and contract and are subject to change. This article is a general framing, not a product recommendation or insurance advice.