United States
HIPAA small practice cyber insurance conditions
For a covered entity or business associate, the HIPAA Security Rule adds its own lines: the risk analysis, the security management process, backups and contingency testing, authentication, audit controls, encryption and business associate agreements. Each line shows the section of 45 CFR Part 164 behind it.
The controls
- A written risk assessment of the information systems is done and repeated periodically
- A written information security program exists, owned by a named qualified individual or officer
- Backups of data, applications and settings run on a schedule set by how critical each system is, and can be restored to a common point in time
- Staff sign in to email and the online services that hold business data (office suite, accounting, practice or client software) with multi-factor authentication
- Privileged access events and logs from internet-facing servers are collected centrally, protected from change, and reviewed in a timely manner
- Laptops, phones and removable media that hold sensitive data are encrypted
- IT and cloud providers with access to systems or data are listed, and their contracts carry security requirements
Start from the template, or mark the controls in the control list. How the schedule works.
Questions
- Does this page say the business can be covered?
- No. It shows the gaps and the rule behind each; cover is the insurer's decision.
- What does it cost?
- One applicant on screen is free in any jurisdiction. Saving clocks and the applicant link are on Solo.