Client support portal Pay invoice Sales(615) 555-0110 Support(615) 555-0111
Chartline Health IT
Cyber insurance readiness

The carrier’s checklist is the product specification.

This is the most reliable purchase trigger in small and midsize healthcare, because it is dated and dollar-denominated. It is also the clearest specification anyone will ever hand you: the controls below are what a 2026 carrier will ask about, and three of them decline applications outright.

The three that decline applications

Miss any one of these in 2026 and applications are declined rather than surcharged. Missing MFA on remote access is the single most common cause of declination.

Phishing-resistant MFA on every account touching business data

Email, VPN, remote desktop, cloud administration, banking, and the practice management system. Not just Microsoft 365.

Declines

EDR on every endpoint and every server, with 24/7 monitoring

Antivirus is not EDR, and workstation-only coverage is the gap carriers now specifically ask about. The server is where the database lives.

Declines

Immutable, offsite, regularly tested backups

Immutable means an attacker holding domain administrator cannot delete or encrypt them. Tested means a documented, timed restore, not a backup job reporting success.

Declines

Asked on every application

These will not usually decline an application on their own, but each one prices the policy and several of them are verified rather than taken on trust.

A written incident response plan that has been tested

Tested means a tabletop with minutes and after-action items inside the last twelve months.

Security awareness training with phishing simulation

With completion records. Carriers increasingly ask for the click-rate trend, not just whether the programme exists.

Email filtering beyond the platform default

An API-layer or gateway inspection tier that catches business email compromise Microsoft alone lets through.

Privileged access management

Named administrator accounts, no shared credentials, and a documented break-glass procedure.

Network segmentation

Particularly separation of clinical devices, imaging, and guest Wi-Fi from administrative systems.

Patch cadence with reporting

Critical patches inside 14 days, with a compliance report you can produce rather than a policy that says you do.

End-of-life systems inventory

Unsupported operating systems, with compensating controls documented for the ones you cannot replace.

Vendor and business associate inventory

Who holds your data. Carriers ask because third-party incidents are now a large share of claims.

Funds transfer controls

Out-of-band verification for any payment instruction change. This is the control behind most social engineering claims.

Prior incident history, honestly disclosed

Non-disclosure is the fastest way to have a future claim denied for material misrepresentation.

Verified rather than attested, increasingly

Underwriting has moved from attestation to evidence. Carriers now run external attack-surface scans during underwriting and conduct mid-cycle audits.

External attack surface

Exposed remote access, unpatched edge appliances, and — for imaging-heavy specialties — internet-reachable DICOM services on ports 104, 11112, and 8042.

Domain and email authentication

SPF, DKIM, and DMARC at enforcement rather than monitoring.

Credential exposure

Whether your domain appears in known breach corpora. Carriers check; most applicants have not.

MFA coverage as implemented, not as described

In Travelers v. International Control Services a court permitted rescission of a cyber policy because an executive attested to MFA on privileged access that was not actually in place.

How to use it

Score it honestly, ninety days out.

Renewals fail at the last minute because nobody looked at the application until the last minute. Ninety days is enough time to deploy EDR to servers, enforce MFA on the remaining paths, and run a documented restore test. Two weeks is not.

Go down the list and mark each control as in place, partial, or absent — and be strict about the difference between in place and described in a policy. Underwriting has moved from attestation to evidence. Carriers now run external attack-surface scans during underwriting and conduct mid-cycle audits, so a control that exists on paper and not in the tenant will be found.

The three that matter most

If you only fix three things before renewal: multi-factor authentication on every remote access path, endpoint detection and response on servers as well as workstations, and immutable backups with a timed restore test. Miss one of those three and the application is declined rather than surcharged, and missing MFA on remote access is the single most common cause of declination in 2026.

One thing not to do

Do not attest to a control you have not verified. It feels like a formality at signing and it is not. A misstatement on the application gives the carrier grounds to rescind the policy at exactly the moment you need it, which converts an insured event into an uninsured one.

This is why we complete the technical sections with clients and attest only to what we can evidence. If we cannot produce the report, we do not tick the box, and we tell you which box we did not tick.

At renewal

We complete the technical sections with you.

And we attest only to what we can evidence, which is the entire point. In Travelers v. International Control Services a court permitted rescission of a policy because an executive attested to MFA that was not actually in place.

Under attack right now? (615) 555-0119

Our incident line is answered 24/7/365 by a security engineer, not a queue. Clients and non-clients both. If you are mid-incident, call before you email.