It’s Monday morning at a four provider family practice. The front desk turns on the schedule and gets nothing back. No appointments, no charts, no way to check anyone in. The phones still work, which is almost worse, because they start ringing at 8:02 and nobody has an answer.
That practice ends up closed for days. Not because a doctor is out, but because the software the whole office runs on is locked. The bills that show up later are for things nobody ever budgeted: a forensics firm, a lawyer who knows HIPAA, notification letters to every patient, and weeks of visits that never happened.
Here’s the part that catches practice owners off guard. Your malpractice policy won’t touch any of that. Neither will your general liability policy. The only coverage built for this kind of loss is a cyber policy, and healthcare has become one of the hardest industries in the country to insure.
Why small practices keep getting picked
There’s a comfortable myth that attackers only chase big hospital systems. The numbers say otherwise. Through the first half of 2026, the healthcare sector averaged roughly 2.3 ransomware attacks per day, up about 14% from the second half of 2025, and healthcare accounted for close to a third of all ransomware activity in early 2026.
Small clinics, dental offices, and specialty practices get hit precisely because they hold the same valuable data as a hospital with a fraction of the security budget. A patient chart isn’t a name and a card number. It’s a date of birth, a Social Security number, an insurance ID, a diagnosis, and a prescription history. That bundle is worth far more than a stolen credit card, because a card can be cancelled in a minute and a medical history can’t be cancelled at all.
The second reason is leverage. A practice that can’t see patients isn’t only losing data. It’s losing revenue by the hour with people sitting in the waiting room. Attackers understand that pressure, and they price the ransom accordingly.
None of that means you should run your practice scared. It means the exposure is real enough that it deserves a policy written for it, which is what cyber insurance for healthcare is.

What cyber insurance for healthcare actually covers
A cyber policy has two halves, and a practice needs both working together.
The first party side pays for your own damage. That’s the forensics team that figures out what happened, the cost of rebuilding your systems and restoring your data, the income you lost while the office sat idle, the ransom decision if it comes to that, and the whole notification machine: letters to patients, a call center, and credit monitoring. For most practices this is the side that does the heavy lifting, because the bulk of the pain is operational.
The third party side pays when someone else comes after you. Patients who sue over exposed records. The legal defense that follows. And the piece that matters most in healthcare: regulatory defense, meaning the cost of responding when the Office for Civil Rights opens an investigation into your breach.
If you want the full breakdown of how these two sides work, we walk through it in what cyber insurance actually covers and in more detail on the first party versus third party split.

The gap your malpractice and liability policies leave
This is the single most common misunderstanding in medical practices, so it’s worth being blunt about it.
Medical malpractice covers harm from clinical care. If a patient is injured by treatment, that’s malpractice. If a patient’s chart is stolen and posted online, no one was clinically harmed, so malpractice has nothing to respond to. General liability covers bodily injury and property damage on your premises. Data isn’t property in the way a GL policy means it, and a locked server isn’t a slip and fall.
So the breach sits in a gap between two policies you’re already paying for. That’s not a loophole anyone hid from you. It’s just that those policies were written for different problems.

A related question comes up constantly: does a cyber policy pay HIPAA fines? Here’s the honest answer. Regulatory defense costs are covered under virtually every cyber policy that includes a regulatory proceedings provision, and those defense costs are usually the larger and more likely expense. The fine itself is murkier. Most policies cover penalties only “where insurable by law,” which depends on your state and on how the penalty is classified. Some states bar insurers from covering penalties outright, and the higher HIPAA tiers involving willful neglect are the least likely to be insurable anywhere. Read that clause before you assume you’re covered, and ask your broker to explain it in writing.

What a practice pays in 2026
Cyber insurance for healthcare costs more than it does for almost any other industry, and there’s no point pretending otherwise. The median premium for a business under 250 employees across all industries runs about $1,740 a year. Practices sit well above that, for the same reason their breaches cost more: regulated patient data.
Here’s where practices generally land in 2026.
| Practice size | Typical annual premium | What drives it |
|---|---|---|
| Solo or single provider | $1,000 to $2,500 | Record count, security controls |
| Small group, 2 to 10 providers | $2,500 to $8,000 | Patient volume, revenue, limits chosen |
| Most practices overall | $1,500 to $7,000 | Size, patient volume, controls in place |
Those are ranges, not quotes. Two practices the same size can be a few thousand dollars apart based purely on whether they can prove their security controls. If you want the full picture of what moves the number, our cyber insurance cost guide breaks the pricing down, and it’s also the fastest place to start if you want to check what your practice would pay.
How much coverage a practice actually needs
A $1 million limit is the sensible floor and the default most small businesses start at. Practices often need more.
The reason is arithmetic, not fear. Healthcare has been the most expensive industry for data breaches for fourteen years running, and the average healthcare breach cost $7.42 million in 2025, down sharply from $9.77 million the year before but still the highest of any sector. Those averages are pulled up by large systems and don’t describe a ten person clinic. But they explain why underwriters look at a practice holding thousands of patient records and think in millions.
In practice, many advisors point healthcare clients toward $2 million to $5 million in limits once the practice holds meaningful patient volume. Start at $1 million if you’re solo with a light chart count, and size up from there based on how many records you hold and what your contracts require. We walk through the full sizing method in how much cyber insurance you need.
One more thing to check, and it’s the one that quietly wrecks claims: sublimits. Your policy might say $2 million on the cover page and then cap ransomware or wire fraud at $250,000 deep inside. The glossary explains sublimits and the other terms worth knowing before you sign.
The HIPAA clock that makes speed matter
Healthcare has a notification deadline that most industries don’t, and it shapes how a claim unfolds.
Under the HIPAA Breach Notification Rule, a breach affecting 500 or more individuals must be reported to the Office for Civil Rights within 60 calendar days of discovery, along with notice to the affected individuals. If 500 or more of them live in a single state, you also owe notice to prominent media in that area. Breaches under 500 people get reported to OCR by the end of the calendar year in which you found them, though individual notice still runs on the 60 day clock.
Sixty days sounds generous until you try to do it. You have to determine who was affected, which requires forensics, which requires a firm you probably haven’t hired yet. This is exactly why the response team attached to your policy matters as much as the limit. Call your insurer’s hotline first, before you hire anyone, because using a vendor the carrier hasn’t approved is a reliable way to get costs denied. Our breach response checklist covers the first 24 hours in order.
What insurers require before they’ll cover you
Applying for cyber insurance for healthcare stopped being paperwork a while ago. In 2026 it’s a security audit, and practices get the closest look of anyone. Carriers want documentation now: screenshots, written policies, logs, proof that a backup restore was actually tested.
Across the market, insurers are consistently asking for the same five things.
- Multi factor authentication on email, remote access, and admin accounts. This is the one that decides whether you get quoted at all.
- Endpoint detection and response software on every machine, including that one laptop in the back office.
- Encrypted backups kept offline or otherwise out of reach of your network, with a restore you’ve actually tested.
- A written incident response plan naming who calls whom.
- Documented patching on a real schedule.
Practices tend to stumble on the same two: a practice management system that a vendor logs into without MFA, and backups that live on the same network as everything else, which means the ransomware encrypts them too. Our requirements guide covers how to document each control, and the ransomware insurance post explains why these controls decide whether that specific claim pays.

Key takeaways
- Malpractice and general liability don’t cover a breach. Cyber is separate coverage, not an upgrade to something you already own.
- Small practices are targeted on purpose. Healthcare averaged about 2.3 ransomware attacks a day in the first half of 2026.
- Expect $1,000 to $2,500 a year solo, and $2,500 to $8,000 for a small group. Healthcare pays above the roughly $1,740 median for small businesses.
- Start at a $1 million limit; many practices with real patient volume size up toward $2 million to $5 million.
- Regulatory defense is covered almost everywhere. HIPAA fines themselves are only covered where state law allows it.
- The 60 day OCR clock starts at discovery, so call the insurer’s hotline before you hire any vendor.
- MFA, EDR, offline backups, an IR plan, and documented patching are the price of admission in 2026.
Frequently asked questions
Does my malpractice insurance cover a data breach?
Almost never in any meaningful way. Malpractice responds to harm from clinical care. A breach is a data and regulatory event, so it falls outside what that policy was written to do. Some carriers offer a small cyber endorsement bolted onto a malpractice or business owner’s policy, but those endorsements often carry limits in the $50,000 range with no real response team, which doesn’t go far against a breach that triggers patient notification.
Is cyber insurance required by HIPAA?
No. HIPAA requires safeguards, risk analysis, and breach notification. It does not require you to buy insurance. But HIPAA is what makes a breach expensive, and it’s increasingly common for hospital affiliations, payer contracts, and business associate agreements to require cyber coverage even though the law doesn’t.
Does cyber insurance pay HIPAA fines?
It reliably pays the cost of defending the investigation. Whether it pays the penalty itself depends on your state’s law and your policy’s wording, since most policies cover fines only where they’re insurable by law. Penalties tied to willful neglect are the least likely to be covered anywhere.
What if my breach came from my EHR vendor, not from us?
You can still be the one notifying patients, because the records are yours. Your business associate agreement governs what the vendor owes you, and their insurance may eventually respond, but that argument takes months while your notification clock runs in days. Your own policy is what funds the response in the meantime.
Is it worth it for a two person practice?
Run the math on your own numbers rather than the averages. Count your active charts, then look at what notifying every one of those patients would cost, add a week of closed doors, and compare that to a premium near $1,500 a year. For most practices the answer becomes obvious quickly. We work through the same question for businesses generally in is cyber insurance worth it, and the broader picture lives in our small business guide.



