When you’re working with a health‑records client, make sure their cyber liability policy covers data‑breach notification and remediation costs and carries a $5 million limit. As a national WC PM, I see many agents overlooking cyber limits for health‑record clients. I urge you to double‑check the $5 million benchmark and confirm riders are attached.
Why $5 Million Limits Matter for Health‑Record Clients
The FTC has opened an investigation into Epic Systems, focusing on alleged privacy violations and how patient data is collected, stored, and shared. Insurance Journal reports that the probe centers on Epic’s data‑handling practices.
Data‑breach costs are climbing
Insurance Journal noted that the average cost of a data breach has climbed to a record $5 million, covering notification, remediation, legal fees, and reputational damage. For a health‑records client, a breach could quickly exceed the limits of a standard cyber policy if coverage is not sized appropriately.
What this means for agents
Agents covering health‑records clients—hospitals, clinics, or EHR vendors—should now treat cyber liability as a core policy element. Here’s how to adjust your practice:
- Verify coverage scope. Ask the underwriter to confirm that the policy includes both data‑breach notification and remediation costs. Many policies list these as separate riders; ensure they are attached.
- Check limits. Use the $5 million average cost as a benchmark. If the client’s potential exposure (e.g., number of patient records, volume of data stored) is high, request a limit of at least $5 million. For larger practices, consider $10 million or more.
- Document in the submission. Add a line to the policy application that notes the client’s data‑handling scope and the required coverage limits. This protects you and the insurer from later disputes.
- Educate the client. Explain that the FTC probe signals heightened scrutiny and that adequate cyber coverage is not just a regulatory requirement but a financial safeguard.
- Review exclusions. Some policies exclude coverage for certain types of data breaches (e.g., those involving third‑party vendors). Verify that the client’s EHR vendor, such as Epic, is covered under the policy or that a separate vendor liability rider is in place.
How to handle renewals and new business
When renewing a policy, compare the current limits to the $5 million benchmark. If the client’s data volume has grown, adjust the limit accordingly. For new business, start the application with a cyber coverage checklist that includes the items above. This proactive approach reduces the risk of under‑insurance and positions you as a knowledgeable advisor.
What this means for your placements
By ensuring that health‑records clients carry cyber liability limits of at least $5 million, you protect both the client and the insurer from costly claims. This diligence can also become a selling point—clients will appreciate an agent who anticipates regulatory scrutiny and market realities. In a market where data breaches are increasingly common, a well‑structured cyber policy can be a differentiator that keeps clients loyal and reduces the likelihood of disputes during claims.
Sources
- Insurance Journal (2026-08-17)
- Insurance Journal (2026-08-17)
Tags: cyber liability, data breach, health records, FTC probe