Do Healthcare Organizations Need Cyber Insurance?
Consider this—you’re going on an epic trip to Peru to see Machu Picchu. You have plans for incredible food, hikes, and photos, and then someone offers an extra ziplining excursion while you’re in the country. You’ve already paid so much for what will already be an amazing trip, so do you really need to make the extra investment?
While the circumstances are admittedly a little less fun, the debate over cyber liability insurance poses a very similar question for healthcare organizations—you’re likely already doing so much to protect the information in your charge so that you can comply with HIPAA, so is the extra step of getting insurance really necessary?
As HIPAA assessors on the front lines of developments in cybersecurity, our experience in both worlds gives us great perspective to help you decide. In this article, we’ll delve into what cybersecurity insurance is, why it’s trending up, and whether or not it’s worth it by exploring the pros and cons.
You may already feel somewhat comfortable going one way or the other, but read on to make sure you make the best decision for your organization.
What is Cybersecurity Insurance?
In the event of a data breach or malicious software attack, cyber liability insurance protects healthcare organizations from the high costs that come with such events that see sensitive information compromised. Also called cybersecurity insurance, it covers what will become necessary expenses such as:
- Customer notification
- Credit monitoring,
- Legal fees
- Fines
Mitigating the financial consequences of a data breach or another emergency probably sounds well and good, but on the flip side, the costs and application complexity of cybersecurity insurance are rising, as unprecedented claim payouts from ransomware attacks have led to a hardened market and cyber insurers wanting to reduce their risk—nowadays, you’re looking at a potentially high policy/premium cost—or even outright denial of coverage—based on factors such as:
- Your organization’s healthcare specialization,
- Your level of cyber risk
- The type and amount of sensitive data stored
- Coverage limits
The Challenges of Cyber Liability Insurance in the Healthcare Industry
But that’s a bridge to cross when you come to it—the question is, should you even come to it? How can you know?
When deciding whether to purchase cybersecurity insurance, you should always first assess and understand your risk profile—if you handle sensitive data, such as financial information or social security numbers that comes with higher risk, you may want to further consider making a purchase.
Medical records and other health data are sensitive as well, making the healthcare industry a frequent target for cybercrime like data breaches and ransomware attacks. Recovery can be financially devastating even after perceived smaller, accidental problems like a software malfunction or a lost laptop—the healthcare sector has reported the highest average cost of a data breach 12 years in a row.
As such, underwriters have adjusted to require more stringent security controls from healthcare organizations to demonstrate that they are safe to ensure, but the challenge for covered entities doesn’t stop there—not only is it difficult to obtain, but renewing and maintaining cyber insurance is also becoming increasingly difficult, and premium costs have significantly increased in the healthcare sector due to the number of attacks.
The Pros of Cybersecurity Insurance
Despite these challenges, it’s hard to make an argument against cyber insurance—a policy can help you transfer some of the risks of cyberattacks to go with some of the other advantages it offers:
- Comprehensive Financial Relief: This may seem obvious, but considering the average cost of a data breach for healthcare organizations is $10 million, it’s helpful to have a policy that can pay for some of that financial fallout, including:
- Costs related to identifying and correcting cybersecurity flaws that led to the breach
- Cyber extortion demands
- Any resulting HIPAA fines
- Legal fees, including any damages awarded due to a lawsuit
- Public relations expenses
- Business Interruption Reimbursement: Cyber liability policies can help cover loss of income during business operation interruptions caused by attacks.
- Legal Support: Some cyber insurance firms are partnering with attorneys and incident response specialists to help with auditing and provide additional services for healthcare organizations.
- Compliance Assistance: If you are required to comply with various laws and regulations regarding data protection and privacy, cyber insurance can aid with compliance by covering the costs of assessments and audits.
The Cons of Cybersecurity Insurance
However, while they do have their benefits, there are some limitations of cybersecurity insurance policies, including the following:
- Limited Coverage: As comprehensive as it may be, cyber insurance does not cover everything—some policies may have exclusions or limits on the types of losses they will cover.
- For example, a policy may not cover losses resulting from employee negligence or failure to follow proper cybersecurity protocols, nor does it cover the loss of potential profits in the future.
- High Premiums: For those that are considered to be at high risk for cyber-attacks or data breaches—like healthcare organizations—higher policy premiums can consume a significant portion of your cybersecurity budget, making it a significant burden for small businesses or startups that may be operating on a tight budget.
- Complexity: Cyber liability insurance policies can be complex, and it may be difficult to understand whether a business is adequately covered or if there are any gaps in its coverage.
- False Sense of Security: The perceived safety net that is cyber liability insurance could lead to what in reality is a hollow comfort that you’re completely insulated against cyber-attacks—that translates into a lack of vigilance when it comes to implementing strong cybersecurity measures.
Next Steps Regarding Your Cybersecurity Insurance
Notwithstanding these drawbacks, cyber liability insurance can play an important part in your risk management strategy and provide comprehensive financial relief, should you ever fall victim to an attack. Now knowing the pros and cons, you’re in a better position to decide for your organization regarding this additional investment.
Still, it's important to remember that insurance is not a replacement for good cybersecurity practices—rather, it’s a tool to help you recover after an incident has occurred. So, while you consider the financial protections of a policy, it’s important to also both adopt adequate cybersecurity measures and partner with a trusted independent assessor to help ensure those measures remain up to date over time.
Controls like a robust firewall and frequent updates to your software will not only solidify your overall cyber defenses and strengthen your comfort levels regarding your security, but they can also help keep the aforementioned insurance premiums down.
To help you get started there, check out our other content that can help you bolster your cybersecurity:
About Schellman
Schellman is a leading provider of attestation and compliance services. We are the only company in the world that is a CPA firm, a globally licensed PCI Qualified Security Assessor, an ISO Certification Body, HITRUST CSF Assessor, a FedRAMP 3PAO, and most recently, an APEC Accountability Agent. Renowned for expertise tempered by practical experience, Schellman's professionals provide superior client service balanced by steadfast independence. Our approach builds successful, long-term relationships and allows our clients to achieve multiple compliance objectives through a single third-party assessor.