Blog

Cybersecurity Financial Exposure for Medical Practices

The dollar cost of a cyber event at a medical practice is not the ransom. The ransom, when there is one, is often the smallest line on the tab. The larger costs come from downtime, notification obligations, HHS penalty exposure, class-action risk, and the operational drag of running a practice without functioning systems for weeks. A physician-owner in Idaho or Utah who thinks “we would just pay the ransom and move on” has usually not read the actual playbook.

This piece frames cybersecurity as a financial risk, not just an IT problem. It covers the five categories of cyber exposure, where cyber insurance actually covers a practice and where it does not, the controls that move underwriters’ answers on premium and coverage, how to read policy sublimits, and what a post-breach financial response looks like.

The Five Categories of Cyber Financial Exposure

A ransomware or PHI breach event at a medical practice generates costs across five categories:

  • Downtime cost (encounters not delivered, revenue not billed, staff paid without productive work)
  • Ransom payment, if paid, plus the negotiation and cryptocurrency handling costs that come with it
  • Incident response and forensics (breach coach, forensic firm, external counsel)
  • Regulatory response (HHS Office for Civil Rights investigation, state attorney general notifications, potential civil monetary penalties)
  • Notification and remediation (patient notification, credit monitoring, call center support, media response)

Plus, in a growing number of cases, class-action litigation costs. Patient plaintiffs’ firms have found productive ground in HIPAA-related breach cases, and the settlement cost per affected patient in the current environment can be meaningful.

The total for a mid-sized practice event routinely exceeds seven figures. For a small practice, the total can still comfortably reach mid-six figures.

Where Cyber Insurance Actually Covers You (and Where It Does Not)

Cyber insurance policies vary widely, and the differences matter. Areas most policies cover well:

  • First-party incident response costs (forensics, breach coach, external counsel)
  • Notification costs (letter production, mail, call center)
  • Business interruption revenue loss during downtime, subject to a waiting period
  • Cyber extortion (ransom) with prior insurer approval

Areas where coverage is limited or excluded:

  • Regulatory fines and penalties (some coverage, but often sublimited or excluded depending on state)
  • Reputation harm and long-term revenue impact after downtime ends
  • Prior acts (events that started before the policy inception)
  • Voluntary shutdowns that were not required by the incident

Sublimits are where policies quietly narrow. A policy with a $2 million aggregate can have a $250,000 sublimit for ransom, a $100,000 sublimit for regulatory fines, and a $500,000 sublimit for business interruption. Add up the sublimits before assuming the aggregate is available for any single category.

The Controls That Move Underwriters’ Answers

Cyber insurance underwriters look at a specific short list of controls when pricing and offering coverage. Practices that have these in place get better terms; practices that do not sometimes cannot get coverage at all:

  • Multi-factor authentication on all remote access and privileged accounts
  • Endpoint detection and response (EDR) software, not just anti-virus
  • Offsite immutable backups tested in the last 90 days
  • Documented incident response plan
  • Annual phishing simulations and staff training
  • Restricted admin privileges (least-privilege access model)

These controls are not exotic. A well-run practice IT program has them in place already. Practices that are not sure whether they do usually do not.

How to Read Your Cyber Policy Sublimits

Reading a cyber policy properly means reading the declarations page for each sublimit and the coverage grid that maps sublimits to specific event types. Three questions to answer:

What is the aggregate limit and how much of it is available for the most likely category (business interruption for most practices)?

What are the sublimits for ransom, regulatory response, notification, and forensic costs, and does the sum of expected costs by category fit under them?

What is the retention (deductible) per category, and does the practice have the liquidity to cover it while claim resolution proceeds?

The Post-Breach Financial Playbook

The first 48 hours after a suspected breach determine much of the downstream cost. The financial playbook, in order:

  • Contact the cyber insurance carrier’s incident response line before doing anything else (call in the middle of the night if that is when it is discovered)
  • Engage the breach coach the carrier assigns; do not communicate about the incident outside privileged channels
  • Preserve evidence; do not power off affected systems until forensics has directed the response
  • Notify legal counsel and, if the incident involves financial systems, the practice’s CPA
  • Do not pay a ransom without carrier and counsel involvement

The playbook matters because the wrong first move can void insurance coverage or attract regulatory scrutiny that would otherwise have been avoidable.

Cooper Norman’s healthcare accounting team reviews cyber policy sublimits and financial preparedness for medical practices across Idaho and Utah. To review your own exposure and coverage adequacy, talk with a Cooper Norman advisor.

Back to the Journal

Newsletter

Practical owner guidance, monthly.

Tax, transition, and decision insights from the Cooper Norman team.