The cyber insurance market for healthcare organizations hardened significantly in 2023 and has not relaxed. Carriers that paid hospice and home health claims following ransomware attacks have responded by tightening underwriting requirements, sub-limiting healthcare coverage, and non-renewing organizations that do not meet minimum security standards.
For a hospice agency, cyber insurance is not optional — it is the financial backstop against a ransomware incident that could otherwise be existential. But getting coverage you can actually use when you need it requires more than checking boxes on an application. It requires having the controls in place, documented and verifiable.
What Every Major Carrier Now Requires for Hospice
MFA — No Exceptions
Every major cyber insurance carrier — Chubb, Travelers, Beazley, Coalition, CNA, Tokio Marine — requires multi-factor authentication as a condition of coverage for healthcare organizations. The MFA requirement is not negotiable and applies to:
- All email accounts (Microsoft 365, Google Workspace)
- Remote access systems (VPN, RDP, EHR portals accessed from outside the office network)
- Any administrative systems with access to ePHI
For hospice agencies, the relevant external-access systems include your EHR (Netsmart myUnity, Brightree, Axxess, MatrixCare, Suncoast), your email platform, and any remote management tools your IT vendor uses.
Carriers will increasingly ask this question explicitly: "Is MFA enforced for all users on all email and remote access systems?" If the answer is no — even for a single account — it can result in a policy exclusion, sub-limit, or higher premium.
Endpoint Detection and Response (EDR)
Antivirus is insufficient for healthcare cyber insurance underwriting. Carriers understand that modern ransomware is polymorphic — it changes enough to evade signature-based antivirus. They require behavioral EDR that detects threat activity based on behavior rather than signatures.
EDR must cover all endpoints — not just office workstations. For hospice agencies with field staff on personal devices, this means MDM-managed EDR on devices that access EHR and email. Carriers are beginning to ask specifically about field device coverage, not just office endpoints.
Immutable or Offline Backups — Tested
Carriers have learned from claims experience that backups connected to the primary network are encrypted alongside production systems. They now require explicit confirmation that backups are immutable (cannot be modified or deleted) or air-gapped (stored offline, disconnected from the network), and that restoration has been tested within the past 12 months.
The test documentation matters as much as the backup itself. A backup system that has never been tested for successful restoration is, from a claims perspective, an untested claim.
Documented Incident Response Plan
A written incident response plan is increasingly requested at underwriting — not just at the time of a claim. Carriers want to know that your agency has a pre-planned, documented response to a ransomware attack that does not require improvisation at 2am.

