← Blog  ·   ·  Regulatory & Bureaus

NCCI Cyber Coverage: Ensure $5 Million Limits for Health‑Record Clients After FTC Probe

FTC probe of Epic Systems highlights the need for $5 million cyber limits for health‑record clients. Verify coverage scope and limits now.

When you’re working with a health‑records client, make sure their cyber liability policy covers data‑breach notification and remediation costs and carries a $5 million limit. As a national WC PM, I see many agents overlooking cyber limits for health‑record clients. I urge you to double‑check the $5 million benchmark and confirm riders are attached.

Why $5 Million Limits Matter for Health‑Record Clients

The FTC has opened an investigation into Epic Systems, focusing on alleged privacy violations and how patient data is collected, stored, and shared. Insurance Journal reports that the probe centers on Epic’s data‑handling practices.

Data‑breach costs are climbing

Insurance Journal noted that the average cost of a data breach has climbed to a record $5 million, covering notification, remediation, legal fees, and reputational damage. For a health‑records client, a breach could quickly exceed the limits of a standard cyber policy if coverage is not sized appropriately.

What this means for agents

Agents covering health‑records clients—hospitals, clinics, or EHR vendors—should now treat cyber liability as a core policy element. Here’s how to adjust your practice:

How to handle renewals and new business

When renewing a policy, compare the current limits to the $5 million benchmark. If the client’s data volume has grown, adjust the limit accordingly. For new business, start the application with a cyber coverage checklist that includes the items above. This proactive approach reduces the risk of under‑insurance and positions you as a knowledgeable advisor.

What this means for your placements

By ensuring that health‑records clients carry cyber liability limits of at least $5 million, you protect both the client and the insurer from costly claims. This diligence can also become a selling point—clients will appreciate an agent who anticipates regulatory scrutiny and market realities. In a market where data breaches are increasingly common, a well‑structured cyber policy can be a differentiator that keeps clients loyal and reduces the likelihood of disputes during claims.


Sources

  1. Insurance Journal (2026-08-17)
  2. Insurance Journal (2026-08-17)

Tags: cyber liability, data breach, health records, FTC probe

Have a placement question this raises?

Send a name, FEIN, and operations description and Justin will respond personally.

Contact Justin arrow_forward