Healthcare cyber attacks - HIPAA security and data protection

HIPAA Tip: Cyber Insurance

Cyber insurance (or cyber liability insurance) protects businesses from financial losses due to cyberattacks, data breaches, and other security incidents by covering costs like legal fees, customer notification, system recovery, lost revenue, and ransom payments. This is a specialized policy, often separate from general liability, addressing liabilities from unauthorized access, data leaks, ransomware, and regulatory fines, offering both first-party (your own losses) and third-party (lawsuits from others) coverage.

Cyber insurance has become more and more difficult to purchase due to skyrocketing costs, complex underwriting requirements, unclear coverage (negligence, war), the nature of cyber threats and the ever-increasing security incidents and data breaches.

Healthcare organizations must prepare themselves in order to be eligible for cyber insurance. Some of the cyber coverage requirements include:

  • Cybersecurity training for all staff, physicians and owners, and C-Suite conducted and completed at least quarterly if not monthly. Follow-up training for workforce members who fail training and email phishing tests.
  • Multi-factor authentication (MFA) enabled for systems and applications containing ePHI, especially when connecting via remote access. MFA adds an additional layer of protection, making it more difficult for threat actors to access unauthorized resources.
  • Strong password policies along with identity access management. A password that is 16+ characters will take a very long time for a threat actor to crack. Reviewing users and their privileges regularly ensures least privileged access and the minimum necessary rule.
  • Disaster Recovery Plan (DRP) is in place, updated any time changes to the environment occurs: ePHI and critical data is added, moved (cloud/web), and technologies have been modified. Backups are in place (onsite and offsite), test restores are completed, and the DRP is tested at least bi-annually.