Insurance
The HIPAA question on cyber-insurance applications
Published July 24, 2026
Buried in some cyber-insurance applications is a small question with a big footing: whether your practice complies with HIPAA. Yes, no, or N/A — and your signature at the bottom of the form. Here’s which applications ask, what a “yes” actually implies, and where an answer you can stand behind starts.
What the forms actually ask
We read the actual application forms, so here is the honest picture. Hiscox’s cyber application asks you to confirm your compliance with a list of regulations that includes the “Health Insurance Portability and Accountability Act (HIPAA)” — yes, no, or N/A. USLI’s asks you to “list the regulatory or compliance frameworks you are compliant with (such as HIPAA, HITECH, PCI-DSS…)”.
Just as honestly: many small-practice forms don’t ask. Applications from several widely used carriers, and the cyber programs bundled with some professional-liability policies, carry no HIPAA question at all. And notably, none of the small-practice forms we reviewed asks you to produce the underlying paperwork — there’s no “attach your risk assessment” field. The question, where it appears, is a bare yes-or-no. On the Hiscox form, the PCI question about card payments comes with a follow-up asking the date of your last assessment; the HIPAA question doesn’t. They take your word for it — with your signature on the application.
What a “yes” implies
HIPAA’s Security Rule starts with one foundational requirement: an accurate, thorough, documented assessment of the risks to the patient information your practice holds (45 CFR 164.308(a)(1)(ii)(A)). It is the first item on the list, the thing everything else in the rule builds on — and the specific failure federal enforcement has focused on since 2024. So a “yes” on that insurance form quietly assumes homework the rule assigned years ago: if no risk assessment has ever been done or written down, it’s hard to say what that yes is standing on.
This isn’t a reason to panic — it’s a reason to be accurate. Answers on an insurance application matter because the policy is priced and issued on them, and an answer that turns out to have nothing behind it can become a real problem at the wrong moment: after an incident, when the claim is being reviewed. The fix is not creative wording. The fix is doing the homework before you answer, so whatever you say has something real under it.
Where a defensible answer starts
A documented, dated risk assessment — what it looked at, what it found, what you’re doing about it. That’s where a defensible answer starts; it’s the foundation the rest of your compliance work sits on, not the whole of it. Carriers also care about the concrete controls their forms spend most of their pages on — multi-factor authentication, backups, endpoint protection — and an assessment doesn’t substitute for those. What it does is turn “I think we’re fine” into a paper trail with a date on it: the difference between hoping your answer is right and knowing what it rests on.
If your form doesn’t ask
It might not. Small-practice cyber policies renew on each practice’s own purchase anniversary, brokers handle much of the paperwork, and some renewals auto-issue with no questionnaire at all. If that’s your year, nothing lands on your desk asking about HIPAA. The obligation doesn’t go away with the question, though — the risk-assessment requirement comes from federal law, not from your insurer, and it’s the one a federal investigation asks about whether or not your carrier ever did.
Before you sign
If a cyber application — or a broker walking you through one — puts the HIPAA question in front of you, the useful move is simple: do the risk assessment first, and date it. The free assessment walks you through exactly that, in plain English, and ends in the documented paper trail. And if a broker or application wants something to hold, the Insurance-Ready Summary is the carrier-facing version of the evidence behind your answers — the homework, showable.
Free — no account needed to start, and your answers never leave your browser. Not legal advice: for questions about your specific obligations, talk to a healthcare attorney.