Hablamos Español Insurance Companies We Work With
Learning Center

Comparing Cyber Insurance Companies for a Small Healthcare Practice

Written and reviewed for insurance accuracy by , licensed agent, NPN 19695198. Published July 6, 2026. How we review this

Already know you need this? Get a quote Compare your coverage →

For a small healthcare practice comparing cyber insurance, the honest answer is that there is no single best carrier, only a best fit. In one real comparison we ran for a small mental-health practice, seven markets quoted the same one-million-dollar limit and the total annual cost ranged from about nine hundred thirty dollars to about seventeen hundred dollars. The lowest total came from At-Bay, a non-admitted, security-focused market. But price was not the whole story, because the coverage behind each limit differed.

The markets we compared

The seven markets fall into a few camps. You can read a fuller profile of each on its page:

  • Technology-led markets that scan and monitor your risk: Coalition, At-Bay, Corvus, and Cowbell.
  • Established specialty insurers with deep breach-response services: Beazley and CFC.
  • The excess and surplus lines strength of the Chubb group: Westchester.

Where each tends to fit

The technology-led markets reward good security hygiene, which can mean competitive pricing for a practice with multi-factor authentication and solid backups. At-Bay came in lowest here, and Coalition, Corvus, and Cowbell all bring continuous monitoring. The specialty insurers, Beazley and CFC, are known for broad wordings and mature breach-response teams, which matters when an incident actually happens. Westchester brings the financial strength of a large group on a surplus-lines basis. None of these is a weakness in another. They are different priorities.

Price is not the whole comparison

Every market quoted the same one-million-dollar limit, but the coverage that responds to the most likely loss varied. Cyber crime and social engineering were commonly sublimited to two hundred fifty thousand dollars, and invoice manipulation ranged from fifty thousand to two hundred fifty thousand dollars across the carriers. Ransomware was handled as reimbursement by some and pay-on-behalf by others. Some included a cyber risk report and proactive monitoring; others did not. A lower premium that sublimits your most likely loss more tightly is not a better deal.

Admitted or non-admitted

Four of the seven quoted on an admitted basis and three on a non-admitted, surplus-lines basis. Admitted policies carry state guaranty-fund backing and standardized filings. Non-admitted policies are often more flexible and, as in this comparison, can be the most competitively priced. Neither is automatically better. We walk through the trade-off in admitted vs non-admitted cyber.

If you are a therapy or behavioral health practice

Most of what is written for “small healthcare” assumes a medical clinic. A counseling practice has a different shape, and three things change the answer.

You may not be a HIPAA covered entity at all. The trigger is not your profession and it is not your software. Under 45 CFR 160.103 you are covered if you transmit health information electronically in connection with a covered transaction, which is a closed list: claims, eligibility checks, remittance advice, authorizations and a handful of others. HHS states plainly that using electronic technology such as email does not make a provider a covered entity, and that the transmission has to be in connection with a standard transaction. So a purely cash-pay therapist who never bills electronically may be outside HIPAA. Two things pull you back in: if a billing service files electronically on your behalf, that counts as you doing it, and a single electronic eligibility check is enough.

Being outside HIPAA is not the same as being unregulated, and this is where practices get comfortable too early. The FTC Health Breach Notification Rule at 16 CFR part 318 covers health apps and vendors of personal health records, expressly names mental health, applies only to entities HIPAA does not cover, and carries deadlines that mirror HIPAA almost exactly. State breach law, licensure rules and psychotherapist-patient privilege all run independently. The BetterHelp case in 2023 ended in a 7.8 million dollar settlement, and it was neither a HIPAA case nor a breach-rule case. It was a Section 5 deception case about how client data was shared.

The notification clock starts earlier than people think. Under 45 CFR 164.404 you have up to 60 calendar days from discovery to notify affected individuals, and 60 days is the ceiling rather than the standard, because the rule also requires notice without unreasonable delay. Discovery is defined against your whole workforce: a breach is treated as discovered on the first day it is known, or would have been known by exercising reasonable diligence, to any workforce member other than the person who caused it. An office manager who notices something on a Friday starts the clock, not the owner who hears about it two weeks later. Breaches affecting 500 or more individuals go to HHS contemporaneously with individual notice; anything smaller goes in an annual submission due within 60 days of year end. Media notice is a separate test that triggers at more than 500 residents of a single state. And an impermissible disclosure is presumed to be a breach unless you can document a low probability of compromise across the four factors in 164.402, with the burden of proof on you.

Substance use records are a separate regime, but narrower than most people assume. 42 CFR Part 2 applies to a federally assisted program that holds itself out as providing substance use disorder treatment. The rule says directly that recording information about a substance use disorder does not by itself pull a record into Part 2 when the treating provider is not a Part 2 program. So a general counseling practice that treats clients with substance use issues incidentally is usually not in scope. If you are in scope, the 2024 final rule took effect with a compliance date of February 16, 2026, HIPAA civil and criminal penalties now attach, and enforcement moved to the Office for Civil Rights.

Telehealth is where the paperwork gap usually is

The COVID-era enforcement discretion that let practices use consumer video tools ended at 11:59pm on August 9, 2023. Nothing replaced it. If you see or store client information through a platform, that vendor is a business associate and you need a signed business associate agreement, under 45 CFR 164.502(e)(2).

The assumption that breaks this is encryption. HHS addressed it in one sentence in its cloud guidance: a cloud service provider is a business associate even if it only processes or stores encrypted data and lacks the encryption key. Lacking the key does not exempt anyone. Operating without a signed agreement is itself the violation, separate from any breach. The nearest example is local. In 2016 Oregon Health & Science University paid 2.7 million dollars after storing the information of more than 3,000 individuals on a cloud server with no business associate agreement in place.

The practical version for a therapy practice: Zoom signs agreements on paid plans only, and the free tier is excluded. Doxy.me provides one at no charge, self-generated in account settings. SimplePractice agrees to it automatically when you create an account, including during a trial. Check which of yours is actually signed rather than assumed, because the one most practices miss is the video tool rather than the records system. HHS has also added a third-party AI chatbot on a patient portal to its published list of business associates, which now reaches scheduling and intake tools a practice may have adopted without thinking of them as vendors.

What CPH and HPSO actually cover, and where they stop

Most therapists we talk to already carry professional liability through CPH & Associates or HPSO, and reasonably assume the cyber question is handled. It is worth reading what those actually provide, because both are narrower than a cyber policy and neither hides it.

CPH & Associates offers cyber liability as an optional claims-made endorsement, not a standalone policy, and it requires their professional liability policy underneath it. Published limits outside New York are 15,000 or 25,000 dollars for security event costs and network security and privacy liability. CPH states directly on its own cyber page that the coverage does not include extortion or ransomware. Policies are underwritten by Philadelphia Indemnity, rated A++ by AM Best.

HPSO includes a data breach extension inside the individual policy rather than selling it separately. It pays client notification expenses up to 25,000 dollars and HIPAA fines and penalties where permitted by law, with fines and penalties unavailable in New York. That is notification and fines. It is not network security liability and it does not speak to extortion. HPSO’s separate business and practice program carries an Enterprise Privacy Protection limit up to 100,000 dollars aggregate. The individual policies are underwritten by American Casualty Company of Reading, Pennsylvania.

Read those two paragraphs next to the exclusion that matters most. The loss a small practice is most likely to actually suffer is ransomware or a fraudulent payment instruction, and neither incumbent product is built to answer it. A 25,000 dollar notification benefit is real money and worth having. It is not the same thing as a policy that pays a forensics firm, funds a business interruption period and negotiates an extortion demand. If your practice holds years of session notes in one system, that distinction is the whole decision.

How we would choose

We do not pick a winner and steer everyone to it. We compare the markets on equal coverage, look at your security controls and record volume, and match the fit to your practice, whether that means the lowest-cost option, the broadest wording, or the strongest breach-response bench. That comparison is the value of working with an independent agency rather than buying one brand direct.

Questions to ask your advisor

  • Are these quotes being compared on equal coverage, or just on price?
  • What sublimit does each carrier put on social engineering and invoice manipulation?
  • Which of these markets rewards the security controls I already have?
  • Is this policy admitted or non-admitted, and does that matter for my practice?
  • Which carrier has the breach-response capability I would want if an incident happened?

Want guidance first? Compare your coverage. Already know what you need? Get a quote.

What many people don't realize

The part that catches owners off guard

  • This reflects one real quote comparison for a small practice and is illustrative, not a recommendation for your practice.
  • We are an independent agency and compare markets rather than steering to one carrier.
  • Every market quoted the same one-million-dollar limit, but coverage terms differed.
  • Availability, appetite, and pricing vary by state, class, and your controls.
The Vantage Point

What we see most often

There is no single best cyber carrier. There is a best fit for a given practice, and it turns on coverage terms and controls as much as price. Naming a winner would be dishonest. Showing the trade-offs is the useful part.

Free, two-minute check

See where your coverage stands

Answer a few quick questions and get a clear read on your current coverage in about two minutes. We flag what is worth a closer look.

Compare your coverage
A quick gut check

Where did your current coverage come from?

How you bought your policy shapes whether you are actually getting options. Three situations we see constantly:

A captive agent

If your policy came from an agent who represents one company, they cannot shop the market for you. You are seeing one company's answer, not your options.

Online, on your own

Online portals tend to optimize for the lowest price. That often means important coverages get quietly left out, and you do not find out until a claim.

An independent agent

The right setup, but only if they re-shop and review it. An independent agent who has not reviewed your coverage in years has stopped working for you.

See where you actually stand
When to review

It may be time for a coverage review if:

  • You have more than one cyber quote in hand
  • You are tempted to pick on price alone
  • You want to understand what separates these carriers
  • Your practice has specific systems or record volumes
Compare your coverage Get a quote
Frequently asked

Frequently asked

Which cyber insurance company is best for a small healthcare practice?
There is no single best carrier. The right fit depends on your coverage needs, your security controls, and whether you value an admitted policy or the lowest price. We compare markets side by side and match the fit to your practice.
Who was the cheapest in your comparison?
In one real comparison for a small practice, the lowest total came from At-Bay, a non-admitted, security-focused market, at roughly nine hundred thirty dollars for the year. Cheapest is not automatically best, because sublimits and services differ.
What is the difference between these cyber carriers?
Some are technology-led markets that scan and monitor your risk, such as Coalition, At-Bay, Corvus, and Cowbell. Others are established specialty insurers with deep breach-response services, such as Beazley and CFC. Westchester brings the financial strength of the Chubb group on a surplus-lines basis.
Should I choose an admitted or non-admitted cyber carrier?
Admitted carriers carry state guaranty-fund backing and standardized filings; non-admitted, surplus-lines carriers are often more flexible and can be more competitively priced. Neither is automatically better. It depends on your priorities.
RS
Written and reviewed by

Founder and Principal Advisor, Vantage Point Risk

Richard Sweet runs Vantage Point Risk, an independent insurance and risk advisory for property owners, real estate investors, business owners, and families. He works with investors every week on the coverage decisions that decide how a claim actually turns out, and writes the Learning Center to put those decisions in plain language.

Written and reviewed for insurance accuracy by Richard Sweet, licensed agent, NPN 19695198. Published July 6, 2026. See our editorial process. Spot an error? Email support@vantagepointrisk.com.

Richard also writes The Vantage Point, notes on building a better business.

This article is general information, not insurance, legal, or tax advice. Coverage depends on your policy terms, endorsements, carrier underwriting, and the state you are in. For guidance on your specific situation, talk with a licensed advisor.

Compare your coverage

It's not a quote. It's a real review.

Answer a few quick questions and get a clear read in about two minutes. We will flag what is worth a closer look, and you can hand us your current policy if you want us to dig in. No pressure, no obligation.

We review your current coverage for gaps and overlaps
We compare the market to see if you are overpaying
We tell you what is actually worth changing, and what is not
You get clear answers, even when you are already covered well