What cyber security requirements do malpractice carriers impose?
Short Answer
Many malpractice and cyber liability carriers now require multi-factor authentication, encrypted email for client communications, regular data backups, endpoint protection software, and employee security training as conditions of coverage. Failure to maintain these controls can result in claim denials or reduced coverage limits.
Malpractice and cyber liability carriers have increasingly moved from simply asking about your cybersecurity posture to requiring specific controls as conditions of coverage. Failing to implement and maintain these controls can result in coverage denial when a claim arises.
Multi-factor authentication (MFA) has become the single most important requirement. Nearly all cyber carriers and many malpractice carriers now require MFA on email accounts, client portals, remote access systems, and cloud-based practice management tools. The absence of MFA is grounds for application denial at many carriers.
Encrypted communications are increasingly expected for client communications containing confidential information. While not all carriers mandate encrypted email, the standard of care for handling client data is evolving, and carriers look favorably on firms that use encrypted email portals or end-to-end encrypted messaging.
Regular data backups with offline or air-gapped copies are essential for ransomware resilience. Carriers want to know that you can restore your systems without paying a ransom. The ideal backup strategy includes automated daily backups, off-site or cloud storage, and periodic restoration testing.
Endpoint protection — antivirus, anti-malware, and endpoint detection and response (EDR) software — must be current and actively managed across all firm devices, including laptops and mobile devices used for firm business.
Employee security awareness training is required by most cyber carriers and recommended by malpractice carriers. Training should cover phishing recognition, social engineering tactics, password hygiene, and proper handling of client data. Most carriers require annual training at minimum, with some expecting quarterly phishing simulations.
When completing your insurance application, be accurate about your cybersecurity controls. Misrepresenting your security posture on an application can be treated as material misrepresentation, potentially voiding your coverage entirely — not just for cyber claims but for your entire policy if the malpractice and cyber coverage are bundled.
The cost of implementing these controls is modest — typically $50 to $200 per user per month — and is far less than the premium savings and claim protection they provide.
Related coverage
Get a free coverage review
Tell us about your firm and we'll compare your current program against best practices -- no cost, no obligation.