If you’re renewing cyber insurance in U.S. healthcare, a filled-out form is no longer enough. You now need proof.

I’d sum it up like this: Beazley underwriters want dated records that show your controls are on, enforced, and tested - especially for MFA, EDR, backups, incident response, patching, and vendor risk. That shift makes sense when healthcare breaches average $9.77 million and third parties play a role in 90% of serious healthcare data breaches.

Here’s the short version of what matters most:

  • MFA must cover remote access, email, cloud apps, and admin accounts
  • EDR must cover business systems, servers, and clinical endpoints
  • Backups must be immutable and tested with restore records
  • Incident response plans must be written, current, and tested
  • Patching and vulnerability work must show scan results, SLAs, and fixes
  • Vendor oversight must show assessments, contract terms, and audit records
  • Legacy systems and medical devices need segmentation, patch plans, or retirement dates

Underwriters are not just asking, “Do you have this control?” They’re asking, “Show me the logs, reports, test results, and dates.”

A few numbers shape that review:

Area What it shows
$9.77 million Average healthcare breach cost
1 in 3 Americans People affected by the Change Healthcare breach
17% Revenue drop some hospitals reported after claims disruption
31% Cyber claims in 2024 tied to vendor issues
6% vs. 18% Premium increases tied to stronger vs. weaker NIST CSF coverage

For me, the main takeaway is simple: better renewal talks start with organized proof. If you can hand over MFA reports, restore test logs, patch dashboards, tabletop notes, and vendor review records, you put yourself in a much stronger position.

Cyber Insurance Renewal: What Beazley Underwriters Now Expect from Healthcare Organizations

Cyber Insurance Renewal: What Beazley Underwriters Now Expect from Healthcare Organizations

Understanding Your Cyber Insurance Needs & Keys to Obtaining Coverage (Sponsored by Imprivata)

How underwriting shifted from self-attestation to proof of control

Not long ago, cyber insurance was pretty simple: fill out a questionnaire, check a few boxes, and sign. If you said MFA was in place, underwriters often took your word for it.

That’s changed.

Now they want proof that MFA is actually enforced. More broadly, underwriters have moved toward auditable proof - evidence that controls are in place, turned on, and tested. You can see that shift in the paperwork they ask for now.

Organizations with stronger NIST CSF coverage saw smaller premium increases than those without it [1]. That gap points to documented control maturity. And the pace is changing too. Christopher Henderson, Senior Director of Threat Operations at Huntress, has predicted a move toward six-month or even quarterly underwriting periods [2]. The logic is pretty simple: cyber risk changes fast. The controls you documented last October may not match your exposure today.

Why healthcare gets more scrutiny than most other sectors

Healthcare organizations deal with a stack of risks that draws more attention from underwriters. A cyberattack can disrupt patient care and safety, not just data access. On top of that, massive amounts of Protected Health Information (PHI) move across large vendor ecosystems, which adds more points of risk.

Then there’s the tech problem. Many healthcare organizations still depend on legacy clinical systems and medical devices that are hard to patch and tough to isolate from the rest of the network. Underwriters know this. That’s why healthcare applications usually get more follow-up questions, tighter review of third-party relationships, and less room for control gaps than most other sectors.

That’s also why underwriters ask for dated artifacts, not policy statements.

What underwriters mean by evidence today

Today, evidence means dated, verifiable proof that a control is active and working. Underwriters are asking for items like these:

Control Area Evidence Underwriters Expect
Identity & Access MFA enforcement logs for remote, email, and admin access; help desk identity-verification procedure and call-back logs
Vulnerability Management Documented patch SLAs; remediation records for internet-facing assets
Third-Party Risk Vendor risk assessment outputs; supply chain security maturity scores
Incident Response Tabletop exercise summaries; backup restoration test records
Governance SOC 2 or ISO 27001 audit reports; NIST CSF maturity assessments

One detail stands out: underwriters now ask whether the help desk has a tested identity-verification process before resetting credentials. That’s not random paperwork. It ties directly to a known attack path.

That standard now drives the core controls Beazley underwriters expect.

Core security controls Beazley underwriters now expect

Next, you need to show that these controls aren’t just written down. They have to be enforced, tested, and documented. When underwriters review healthcare applications, they’re looking for dated artifacts and proof they can verify, not just policy language, across each core control area.

MFA and privileged access controls across remote, email, cloud, and admin access

Partial MFA no longer cuts it. Underwriters want to see MFA enforced across remote network access, email, cloud apps, and every privileged account that can reach PHI or core operations.

The February 2024 Change Healthcare ransomware attack turned that into a hard underwriting standard. Attackers used stolen credentials on a legacy remote access portal that did not have MFA enforced. The breach exposed the PHI of about 1 in 3 Americans, and some hospitals reported revenue drops of up to 17% because claims processing was disrupted [3].

That event now comes up often in underwriting discussions. If a legacy portal can’t support modern MFA, underwriters increasingly expect either:

  • a documented decommissioning timeline
  • compensating network segmentation

They also look closely at privileged access scope: how many high-privilege accounts exist, and which systems each one can reach. A long list of powerful accounts with broad access is a red flag. What they want to see instead is least-privilege enforcement, backed by an account inventory and an access-scope map.

At renewal, have these records ready:

  • MFA enforcement logs
  • policy settings
  • exception lists with justification
  • help desk identity-verification scripts
  • call-back logs

Access control is only one part of the renewal review. Recovery and response matter just as much.

EDR coverage for clinical and business systems

Endpoint visibility is now part of the same renewal check. Underwriters want to see EDR across clinical workstations, servers, and business systems, not just corporate laptops.

Gaps on medical device networks or legacy clinical endpoints are a known flag. And installed is not the same as managed. Underwriters want proof that EDR is active and monitored.

Be ready to provide an endpoint inventory that shows coverage percentage, EDR policy settings, and documented alert-response procedures that show the tool is being actively managed.

Secure backups and tested recovery for clinical and business systems

Underwriters want proof that backups sit in immutable storage, not on systems ransomware could reach and encrypt.

Just as important, they want dated proof that restores have been tested for systems like EHR and billing. Backups that haven’t been tested don’t prove you can recover.

The records to keep on hand include immutable backup logs, restore test records with dates and results, and documented BCP results for critical clinical systems.

A written incident response plan that has been tested

Underwriters also want proof that the organization can recover and respond, not just block access.

A general business continuity document won’t satisfy them. They want a malware- and intrusion-specific incident response plan with named roles, clear escalation paths, and documented response steps.

Provide dated plan versions, tabletop exercise records based on healthcare breach scenarios, issue-management records, and proof of annual review and testing. That includes a tested contingency for critical outages lasting more than 72 hours, including cases where EHR or billing systems are fully offline [3]. Organizations that can’t show that contingency usually face tougher renewal discussions.

Governance gaps that hurt renewal outcomes: patching, vulnerability management, and third-party risk

Once core controls are in place, underwriters shift to a different question: can they trust you to keep those controls working over time? That’s where governance starts to matter. They now look closely at how steadily you patch systems, track vulnerabilities, and manage vendors. Those areas can shape renewal outcomes because they show control maturity. It’s not just about having the right tools on paper. It’s about using them again and again, and keeping records that prove it.

Patch and vulnerability management for internet-facing and high-risk assets

Underwriters usually ask for different proof based on the asset involved. For insurers, the issue isn’t whether these assets exist. It’s whether they’re controlled tightly enough to insure.

For internet-facing systems, underwriters usually expect routine scan results, documented remediation timelines, and proof that critical findings move to the front of the line. Unsupported systems exposed to the internet get even closer review.

Medical devices are a known weak spot. If immediate patching isn’t possible, underwriters look for MDS2 forms and Software Bill of Materials (SBOM) records from device manufacturers. They also want technical proof of network segmentation that separates the device from the broader environment. Legacy platforms need a decommissioning timeline, plus network isolation until retirement.

Asset Type Evidence Controls
Internet-Facing Systems Scan results, remediation logs, MFA enforcement WAF, IP whitelisting, geo-blocking
Medical Devices MDS2 attestation, SBOM, patch procedures Network segmentation, traffic filtering
Legacy Platforms Decommissioning timeline, architecture review Isolated VLANs, strictly enforced MFA

Third-party risk oversight for vendors that handle PHI or support clinical operations

Third-party oversight is still a common gap, and it’s one underwriters notice fast. Vendor failures drive a large share of healthcare breaches and cyber claims. 90% of serious healthcare data breaches involve a third party [3], and 31% of cyber insurance claims in 2024 were linked to vendor issues [3].

Supply chain risk management is also still the lowest-coverage area in the NIST Cybersecurity Framework (CSF) across healthcare, even though stronger coverage is tied to smaller premium increases [1]. The 2024 Change Healthcare attack put concentration risk and subcontractor risk front and center. In plain English, it showed that you can’t stop at your direct vendor. You also need to understand the risk created by that vendor’s subcontractors [3].

Stronger oversight usually includes:

  • standardized assessments
  • contract requirements
  • evidence review
  • tracked remediation

Underwriters want proof that PHI-handling vendors and care-delivery vendors can produce security audits, SOC 2 reports, ISO 27001 certifications, and vulnerability management reports. Organizations using NIST CSF saw smaller premium increases than those that did not [1].

These records become part of the renewal file underwriters review.

How meeting these expectations improves insurability and cyber resilience

Better controls can help with both insurability and recovery. But at renewal, proof is what matters.

These controls help cut downtime, speed up recovery, and reduce breach costs. Higher NIST CSF coverage in resilience categories is also tied to smaller premium increases and better business continuity [1].

What to include in an underwriting evidence package

For renewal, it helps to group everything into one evidence packet by control area. That makes the review easier and gives underwriters something concrete to work with instead of broad claims.

Include:

  • MFA deployment reports that show coverage across remote access, email, and admin accounts
  • Backup architecture diagrams along with restore test records and test dates
  • Patch dashboards and vulnerability exception logs
  • Tabletop exercise notes from incident response testing, including dates, participants, and findings
  • Vendor assessment records and supply chain risk management policies, including SOC 2 Type II reports or ISO 27001 certifications for PHI-handling and care-delivery vendors

SOC 2 Type II reports and ISO 27001 certifications give underwriters independent proof that controls work as described [2].

That’s what shifts the underwriting conversation from saying to showing.

Comparison table

Control Category Underwriting Impact Patient Safety & Resilience Impact
MFA & Identity Verification High; a gating item for renewal [2] Reduces identity-based and social engineering risk
NIST CSF Adoption Strong; linked to 6% vs. 18% premium increases [1] Improves business continuity and breach mitigation
Vulnerability Management High; underwriters scrutinize remote access and admin tools [2] Reduces the likelihood of downtime from exploited known flaws
Incident Response Testing Moderate to High; reinforces stronger "Respond" maturity [1] Supports faster recovery and readiness
Supply Chain Risk Management Associated with smaller premium increases [1] Helps limit third-party breach exposure across care delivery

Conclusion: stronger controls lead to better renewal conversations

Stronger controls and cleaner evidence can lead to better renewal terms, fewer surprises, and faster negotiations.

FAQs

What counts as acceptable proof for cyber insurance renewal?

Acceptable proof means verifiable documentation that shows your security controls are active and working, not just statements saying they are.

Examples include current SOC 2 Type II reports, HITRUST certifications, recent penetration test summaries, configuration evidence, logging data, proof of universal MFA, incident response plans, and records of disaster recovery or backup tests. If controls are misconfigured or turned off during an incident, claim disputes are more likely.

How should we handle legacy systems that can’t support modern security controls?

Don’t stop at documenting legacy systems. If the risk is still there, you need to deal with it.

Put compensating controls in place and document them. That might mean an identity-aware proxy, a Privileged Access Management jump host, or gateways that add authentication without changing the system itself.

You should also use network segmentation, restricted access hours, and tighter monitoring. Track every exception in an active register that includes the risk, the controls in place, and a time-bound retirement or upgrade plan. Review that register once a year.

What should be included in a healthcare cyber insurance evidence package?

Include proof of active security controls, not just paperwork. That means showing MFA for remote and admin access, EDR deployment, incident response plans with recent tabletop results, vulnerability and penetration testing reports, and backup records that show tested RTO and RPO.

You should also include:

  • BAAs
  • Vendor security assessments or audit findings
  • Logging and monitoring evidence
  • A current risk register with owners, remediation timelines, and executive risk acceptance

The point is simple: documents alone don't tell the whole story. You need evidence that these controls are in place, being used, and being checked.

Related Blog Posts