Managed Care Organizations continue to see significant breaches of their systems, software and vendors, so the need for Cyber Security coverage has never been more critical to their financial and operational health. These breaches show the importance and need for the insurance, as well as the need to constantly update operational and systems controls and procedures. Compliance with Federal regulations including the PPACA, HIPAA and Hitech, as well as State Laws regarding notification and other legal requirements, come under immediate scrutiny following a breach of any size. A breach also leads to questions regarding the organization’s commitment to its insureds, members, and clients. Investigations by Federal and State regulators and the resulting press can be devastating to an unprepared organization. Phishing and web-borne malware, ransomware and denial of service attacks are among the most common of these security threats. Lost or stolen mobile and computing devices remain the number one exposure to loss.
Data breaches in the healthcare industry are increasingly costly and frequent, continuing to put patient data at risk. The IBM Cost of a Data Breach report for 2020 shows the average cost of a breach is now $3.86 million. For the tenth year in a row, Healthcare remains the most expensive industry with an average cost of $7.13 million. The report shows that criminal attacks are the number one cause of a data breach and ransomware demands have steadily increased. They also report that 52% of breaches are caused by malicious attacks and 80% of breaches include customer PII. Average cost per PII record is $150, which increases to $175 per record when the attached is malicious. 19% of malicious attacks involved the use of compromised credentials and that these are generally the most expensive cause of malicious data breaches. Finally, the report shows that the average lifecycle of a breach in the healthcare sector is 329 days, a full 96 days more that average of the financial sector in general.
So what can an organization do to protect themselves in today's environment? First and foremost, develop the appropriate organizational and financial commitment to maintaining a secure and robust organizational solution to protect the entire organization's data. Second, have risk management plan in place to address a data breach event, and third, purchase insurance that provides liability protection and access to a Breach coach along with other resources to help you develop your organizational plan. Finally, have a written implementation plan ready to go in the event of an actual breach event.
Travelers CyberRisk® policy is available to all types of Managed Care Organizations within the Chatham Insurance Services program. Travelers' cyber coverage solutions are specifically designed to help in the event of a cyber breach and provide options that include coverage for forensic investigations and litigation expenses associated with the breach. Additional options are available for regulatory defense expenses and related fines, crisis management or public relations expenses, business interruption, and cyber extortion.
The policy includes access to Travelers eRisk Hub®, a specialized web portal powered by NetDiligence®. This risk management portal provides access to tools that will help prevent and respond to cyber events. It automatically includes tools to build privacy controls, as well as information and IT security programs, white papers, articles, webinars, calculators, regulatory and legal updates. Travelers eRisk Hub® provides access to Travelers Breach Coach service that provides a 30 minute consultation with an attorney to receive immediate triage assistance after a breach.
We can also provide Excess coverage with the Travelers Excess Liability policy. See Excess Page for more information.
"Nothing stated herein affects the terms, condition and coverages of any insurance policy or bond issued by any of the referenced insurers, nor does it imply that coverage does or does not exist for any particular claim or type of claim under any such policy or bond. Availability of coverage referenced in this document can depend on underwriting qualifications and state regulations."
Coverage underwritten by Travelers Casualty and Surety Company of America and its property casualty affiliates, Hartford, CT 06183