The Analyst Note Healthcare series · piece 6 of 6 · Last updated July 2026
Healthcare cyber insurance: what carriers now require.
Cyber insurance for healthcare is underwritten on an audit of controls that are actually running, not on a compliance attestation. The list carriers require has converged with the public frameworks, so being HIPAA compliant is not the same as being insurable. The same controls clear both, and the application you sign is a warranty.
11 min read · Healthcare series · piece 6 of 6
Questions this article answers
- We are HIPAA compliant. Why is our cyber insurance renewal still a problem?
- What controls do carriers actually require now, and where does the list come from?
- Why have the insurance questionnaire and the security frameworks converged?
- Can a claim be denied over a control we said we had?
- How do we prepare for a renewal so it strengthens security, not just checks a box?
- What do we verify and evidence before we sign the application?
The structural fact about healthcare cyber insurance is that it is no longer priced on a questionnaire of intentions, it is priced on an audit of controls that are actually running in the environment. A decade ago a cyber policy was close to a commodity, bound on a short application and a modest premium. The ransomware losses of the intervening years ended that. Carriers now underwrite the specific technical controls that stop or contain an incident, and they confirm, before binding and again after a loss, whether those controls were enforced on the day it mattered. That shift makes cyber insurance a sourcing problem for the same technology stack this series has been mapping, because the controls the carrier requires are bought, deployed, and evidenced, not asserted.
This is the sixth and final piece in the Healthcare series. The anchor set out the constraints, and earlier pieces covered EHR integration, the Business Associate Agreement, connectivity, and the behavioral-health backbone. Cyber insurance closes the series because it sits on top of all of them. The BAA allocates who pays after a vendor breach; the insurance decides whether the operator's own losses are covered; and the connectivity and platform choices are where several of the required controls live. The through-line is the same: what protects the operator is specific, verifiable, and sourced, not a claim on a slide.
HIPAA compliant is not the same as insurable.
The first thing to separate is regulatory compliance from insurability, because operators routinely conflate them and get caught at renewal. HIPAA sets a floor for protecting PHI, much of it framed at the level of policies, risk analysis, and safeguards. A cyber insurer is asking a narrower and more technical question: were phishing-resistant MFA, monitored endpoint detection and response, immutable and tested backups, and a current incident response plan actually operating in your environment, on every relevant account and system, on the day of the loss. An operator can hold a defensible HIPAA posture and still fail that audit, and the consequences are financial rather than regulatory: sharply higher premiums, coverage exclusions that hollow out the protection, or a declination that pushes the operator into the surplus-lines market at a multiple of standard rates.
The reframe for a buyer is that compliance and insurability are two overlapping tests with different evidence standards, and the insurance test is the more literal of the two. HIPAA will ask whether you have a process. The carrier will ask whether the control was on. Sourcing technology with only the first question in mind produces a stack that passes an audit of intentions and fails an audit of execution. The operator that treats insurability as a distinct requirement, and sources the controls to satisfy it, ends up compliant as a byproduct, because the insurance list is the stricter superset.
The carrier control list has converged with the public frameworks.
The controls carriers require are not idiosyncratic, they have settled into a recognizable list that maps onto the government's own cybersecurity frameworks. On the carrier side the recurring requirements are phishing-resistant MFA on every account that touches business data, endpoint detection and response monitored around the clock rather than legacy antivirus, immutable and restore-tested backups, a written and recently exercised incident response plan, email authentication and filtering, network segmentation, separation of privileged accounts, and timely patching of known-exploited vulnerabilities. That list is nearly a restatement of CISA's Cross-Sector Cybersecurity Performance Goals, which specify phishing-resistant MFA, network segmentation, system backups, incident response plans, and email security as named goals, and of the HHS Healthcare and Public Health Cybersecurity Performance Goals published for the sector. NIST Cybersecurity Framework 2.0, released in February 2024 with its new Govern function and heightened emphasis on supply-chain risk, provides the organizing structure underneath both.
This convergence is the useful part for a buyer. Because the insurance questionnaire, the CISA and HHS goals, and the direction of the proposed HIPAA Security Rule are asking for substantially the same controls, sourcing to satisfy them is one initiative rather than three competing ones. The proposed Security Rule update, discussed in the BAA piece, would move measures such as encryption and MFA from addressable to mandatory, pulling the regulatory floor toward the control set the carriers already demand. An operator that builds to the frameworks is building to the insurance application at the same time, and to where the regulation is heading. The controls do not conflict. They are the same controls described by three different institutions.
The application is a warranty, so control accuracy is not optional.
The most expensive mistake in cyber insurance is answering the application optimistically, because the answers are warranties the carrier relies on to issue the policy. When an operator attests that MFA is enforced on all remote access, or that backups are immutable and tested, those statements become representations. If a loss occurs and the carrier's forensics find that the attested control was not actually enforced on the compromised account, or that backups were never immutable, the misrepresentation can support reduced payment, a specific exclusion, or rescission of the policy entirely. The coverage an operator paid for can evaporate at the moment it is needed, not because the premium lapsed, but because a control claimed on the application was not running in fact.
This puts a premium on the same evidence discipline that governs a vendor audit right in the BAA. An operator should be able to prove, for each attested control, that it was deployed and enforced across the stated scope, with configuration records, coverage reports, and dated test results. That evidence is not bureaucratic overhead. It is the difference between a paid claim and a rescinded policy. The buyer-side move is to answer the application only against controls the operator can demonstrate, and to close any gap between what the questionnaire asks and what is actually running before signing, rather than attesting to an aspiration and discovering the gap during a claim.
EDR — Monitored around the clock, endpoints and servers. First action: confirm coverage on every device, not a sample, and that alerts are watched.
Backups — Immutable, isolated, restore-tested with dated proof. First action: run and document a restore test; do not attest untested backups.
Evidence — The application is a warranty. First action: assemble proof each attested control was enforced, on the scope claimed.
Prepare the renewal as a controls project, before the questionnaire.
The decision an operator faces is concrete: treat the renewal as a form to fill in, or as a controls project to complete before the form arrives. The answer is the second, because the questionnaire is a snapshot of an environment the operator can improve if it starts early enough. Preparing means mapping the carrier's required controls against what is actually deployed and enforced, then closing the gaps in MFA coverage, EDR deployment, backup immutability and testing, and incident response before answering a single question. Because the carrier list and the CISA and HHS frameworks overlap so heavily, that preparation doubles as regulatory improvement, and it is far cheaper to do on the operator's schedule than under the time pressure of a renewal deadline or, worse, a claim.
The checklist below is the cyber insurance control-readiness set we run before a healthcare renewal or first placement. Each item is a control carriers now commonly treat as required, paired with what to verify and what to keep as evidence. It is deliberately vendor-agnostic; the point is the control and its proof, not a particular product. Paste it into your renewal preparation and work it before the application is due.
Reusable artifact · The cyber insurance control-readiness checklist
- Phishing-resistant MFA. Enforce on every account touching business data: email, VPN, remote desktop, cloud admin, EHR, banking. Evidence: coverage report showing no exempted privileged accounts. Prefer app or hardware tokens over SMS.
- Monitored EDR. Deploy detection and response on every endpoint and server, watched around the clock by an internal team or an MDR service. Evidence: deployment coverage and a monitoring runbook. Legacy antivirus does not satisfy this.
- Immutable, tested backups. Keep backups isolated and immutable, and test restoration on a set cadence. Evidence: the dated restore-test result. Do not attest to backups you have not restored.
- Incident response plan. Maintain a written plan and exercise it within the last year. Evidence: the plan and the dated tabletop or drill record, tied to the notification windows in your BAA.
- Email security. Enable SPF, DKIM, and DMARC set to reject, plus filtering. Evidence: DNS records and filtering configuration. This is a named framework goal, not an extra.
- Network segmentation. Separate clinical, guest, and medical-device traffic and constrain lateral movement, as designed in the connectivity phase. Evidence: segmentation design and firewall policy.
- Privileged-access separation. Ensure administrators use separate accounts and that privileges are reviewed. Evidence: privileged-account inventory and review log.
- Known-vulnerability patching. Remediate known-exploited vulnerabilities on internet-facing systems within a risk-informed window. Evidence: patch cadence and vulnerability-scan results.
- Warranty accuracy. Answer the application only against controls you can prove were enforced on the stated scope. Evidence: a mapping of each attested answer to its supporting record.
What breaks is the gap between the attestation and the deployment.
The failure modes in cyber insurance are gaps between what was claimed and what was running, and none of them is about buying the wrong brand. The first is the compliance-equals-insurable assumption, where an operator with a clean HIPAA posture is surprised at renewal because the carrier audits controls the compliance program never verified were enforced. The second is partial deployment, where MFA covers most accounts but not the service account that gets compromised, or EDR is licensed but not installed on the server that is hit, so a control that exists on paper is absent where it counts. The third is the optimistic attestation, where the application claims a control the operator intends to have, and the gap surfaces as a denied or rescinded claim after a loss. The fourth is the stale plan, an incident response document written once and never exercised, which the carrier discounts and the incident exposes.
Each is corrected by the same discipline the rest of this series has argued for: specify the control precisely, deploy it across the full scope, and hold the evidence that it is running. The remedy is not a different insurer or a different security vendor. It is refusing to let an attestation stand in for a deployment, in exactly the way the earlier pieces refused to let a brand name stand in for a specification.
What this means for procurement.
What closes the cyber insurance decision is a stack of controls that are deployed, enforced, and evidenced before the application is signed, sourced to a list that satisfies the carrier, the CISA and HHS frameworks, and the direction of the HIPAA Security Rule at once. The prudent operator prepares the renewal as a controls project on its own schedule, answers the warranty only against what it can prove, and treats the convergence of the insurance questionnaire and the public frameworks as leverage, because one initiative now serves compliance, security, and insurability together. A cheaper posture that clears a compliance audit but not a controls audit is not cheaper. It is an uninsurable position, or a rescinded policy, with a discount attached.
The security-officer framing of these decisions is in our CISO briefing and the financial exposure in our CFO briefing, the vertical view is in the Healthcare library, and the network controls underneath sit in the connectivity piece. This closes the Healthcare series. Across all six pieces the constraint set held: the record, the contract, the wire, the platform, and now the insurance are each governed by a specific, verifiable requirement, and the resolution of each is where the sourcing work actually is.
How Cardinal handles a cyber insurance readiness review.
When a buyer engages us ahead of a cyber insurance renewal, we map the carrier's required controls against what is actually deployed and enforced, then source and evidence the gaps before the application is answered. The Cardinal Method aligns the control set to CISA's Cross-Sector goals, the HHS Healthcare and Public Health goals, and NIST Cybersecurity Framework 2.0, so a single initiative serves the renewal, the regulatory posture, and the proposed Security Rule direction. Because the application is a warranty, we confirm each attested control can be proven on its stated scope, so a claim is not lost to a misrepresentation the operator did not know it had made.
See the Cardinal Method → · Healthcare coverage → · For CISOs →
In short
- Cyber insurance is underwritten on controls that are actually running, not on a compliance attestation. HIPAA compliant is not the same as insurable.
- The carrier control list, phishing-resistant MFA, monitored EDR, immutable tested backups, incident response, email security, segmentation, has converged with CISA's CPGs, the HHS HPH goals, and NIST CSF 2.0.
- Because the frameworks and the questionnaire ask for the same controls, sourcing to satisfy them is one project, and it tracks where the HIPAA Security Rule is heading.
- The application is a warranty. A control claimed but not enforced on the day of loss can support reduced payment, exclusion, or rescission.
- Prepare the renewal as a controls project before the questionnaire, and answer only against controls you can prove were running on the stated scope.
This is piece 6, the final piece of the Healthcare series. See the anchor and the pieces on EHR integration, the BAA, connectivity, and the behavioral-health backbone.
Sources
- CISA — "Cross-Sector Cybersecurity Performance Goals" (named goals: phishing-resistant MFA 2.H, network segmentation 2.F, system backups 2.R, incident response plans 2.S, email security 2.M) — cisa.gov
- HHS Cyber Gateway — "Healthcare and Public Health Cybersecurity Performance Goals" (sector-specific essential and enhanced goals) — hhscyber.hhs.gov
- NIST — "Cybersecurity Framework (CSF) 2.0" (released February 26, 2024; Govern function; supply-chain emphasis) — nist.gov
- Federal Register — "HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information" (NPRM, January 6, 2025; proposed mandatory encryption and MFA) — federalregister.gov
- HHS Office for Civil Rights — "Breach Portal: Notice to the Secretary of HHS Breach of Unsecured Protected Health Information" (breach frequency driving the healthcare cyber market) — ocrportal.hhs.gov
All linked sources were live at time of publish (July 2026). Verify before quoting in a procurement document.
Want a calibration on your specific stack?
Run the Tier 1 benchmark.
Submit your current UCaaS, CCaaS, SD-WAN, or security contract. We return a benchmark PDF in five business days showing where you are paying above peer median. Free. No follow-up sales drip.
Run the Tier 1 benchmark →