For a small healthcare practice comparing cyber insurance, the honest answer is that there is no single best carrier, only a best fit. In one real comparison we ran for a small mental-health practice, seven markets quoted the same one-million-dollar limit and the total annual cost ranged from about nine hundred thirty dollars to about seventeen hundred dollars. The lowest total came from At-Bay, a non-admitted, security-focused market. But price was not the whole story, because the coverage behind each limit differed.
The markets we compared
The seven markets fall into a few camps. You can read a fuller profile of each on its page:
- Technology-led markets that scan and monitor your risk: Coalition, At-Bay, Corvus, and Cowbell.
- Established specialty insurers with deep breach-response services: Beazley and CFC.
- The excess and surplus lines strength of the Chubb group: Westchester.
Where each tends to fit
The technology-led markets reward good security hygiene, which can mean competitive pricing for a practice with multi-factor authentication and solid backups. At-Bay came in lowest here, and Coalition, Corvus, and Cowbell all bring continuous monitoring. The specialty insurers, Beazley and CFC, are known for broad wordings and mature breach-response teams, which matters when an incident actually happens. Westchester brings the financial strength of a large group on a surplus-lines basis. None of these is a weakness in another. They are different priorities.
Price is not the whole comparison
Every market quoted the same one-million-dollar limit, but the coverage that responds to the most likely loss varied. Cyber crime and social engineering were commonly sublimited to two hundred fifty thousand dollars, and invoice manipulation ranged from fifty thousand to two hundred fifty thousand dollars across the carriers. Ransomware was handled as reimbursement by some and pay-on-behalf by others. Some included a cyber risk report and proactive monitoring; others did not. A lower premium that sublimits your most likely loss more tightly is not a better deal.
Admitted or non-admitted
Four of the seven quoted on an admitted basis and three on a non-admitted, surplus-lines basis. Admitted policies carry state guaranty-fund backing and standardized filings. Non-admitted policies are often more flexible and, as in this comparison, can be the most competitively priced. Neither is automatically better. We walk through the trade-off in admitted vs non-admitted cyber.
If you are a therapy or behavioral health practice
Most of what is written for “small healthcare” assumes a medical clinic. A counseling practice has a different shape, and three things change the answer.
You may not be a HIPAA covered entity at all. The trigger is not your profession and it is not your software. Under 45 CFR 160.103 you are covered if you transmit health information electronically in connection with a covered transaction, which is a closed list: claims, eligibility checks, remittance advice, authorizations and a handful of others. HHS states plainly that using electronic technology such as email does not make a provider a covered entity, and that the transmission has to be in connection with a standard transaction. So a purely cash-pay therapist who never bills electronically may be outside HIPAA. Two things pull you back in: if a billing service files electronically on your behalf, that counts as you doing it, and a single electronic eligibility check is enough.
Being outside HIPAA is not the same as being unregulated, and this is where practices get comfortable too early. The FTC Health Breach Notification Rule at 16 CFR part 318 covers health apps and vendors of personal health records, expressly names mental health, applies only to entities HIPAA does not cover, and carries deadlines that mirror HIPAA almost exactly. State breach law, licensure rules and psychotherapist-patient privilege all run independently. The BetterHelp case in 2023 ended in a 7.8 million dollar settlement, and it was neither a HIPAA case nor a breach-rule case. It was a Section 5 deception case about how client data was shared.
The notification clock starts earlier than people think. Under 45 CFR 164.404 you have up to 60 calendar days from discovery to notify affected individuals, and 60 days is the ceiling rather than the standard, because the rule also requires notice without unreasonable delay. Discovery is defined against your whole workforce: a breach is treated as discovered on the first day it is known, or would have been known by exercising reasonable diligence, to any workforce member other than the person who caused it. An office manager who notices something on a Friday starts the clock, not the owner who hears about it two weeks later. Breaches affecting 500 or more individuals go to HHS contemporaneously with individual notice; anything smaller goes in an annual submission due within 60 days of year end. Media notice is a separate test that triggers at more than 500 residents of a single state. And an impermissible disclosure is presumed to be a breach unless you can document a low probability of compromise across the four factors in 164.402, with the burden of proof on you.
Substance use records are a separate regime, but narrower than most people assume. 42 CFR Part 2 applies to a federally assisted program that holds itself out as providing substance use disorder treatment. The rule says directly that recording information about a substance use disorder does not by itself pull a record into Part 2 when the treating provider is not a Part 2 program. So a general counseling practice that treats clients with substance use issues incidentally is usually not in scope. If you are in scope, the 2024 final rule took effect with a compliance date of February 16, 2026, HIPAA civil and criminal penalties now attach, and enforcement moved to the Office for Civil Rights.
Telehealth is where the paperwork gap usually is
The COVID-era enforcement discretion that let practices use consumer video tools ended at 11:59pm on August 9, 2023. Nothing replaced it. If you see or store client information through a platform, that vendor is a business associate and you need a signed business associate agreement, under 45 CFR 164.502(e)(2).
The assumption that breaks this is encryption. HHS addressed it in one sentence in its cloud guidance: a cloud service provider is a business associate even if it only processes or stores encrypted data and lacks the encryption key. Lacking the key does not exempt anyone. Operating without a signed agreement is itself the violation, separate from any breach. The nearest example is local. In 2016 Oregon Health & Science University paid 2.7 million dollars after storing the information of more than 3,000 individuals on a cloud server with no business associate agreement in place.
The practical version for a therapy practice: Zoom signs agreements on paid plans only, and the free tier is excluded. Doxy.me provides one at no charge, self-generated in account settings. SimplePractice agrees to it automatically when you create an account, including during a trial. Check which of yours is actually signed rather than assumed, because the one most practices miss is the video tool rather than the records system. HHS has also added a third-party AI chatbot on a patient portal to its published list of business associates, which now reaches scheduling and intake tools a practice may have adopted without thinking of them as vendors.
What CPH and HPSO actually cover, and where they stop
Most therapists we talk to already carry professional liability through CPH & Associates or HPSO, and reasonably assume the cyber question is handled. It is worth reading what those actually provide, because both are narrower than a cyber policy and neither hides it.
CPH & Associates offers cyber liability as an optional claims-made endorsement, not a standalone policy, and it requires their professional liability policy underneath it. Published limits outside New York are 15,000 or 25,000 dollars for security event costs and network security and privacy liability. CPH states directly on its own cyber page that the coverage does not include extortion or ransomware. Policies are underwritten by Philadelphia Indemnity, rated A++ by AM Best.
HPSO includes a data breach extension inside the individual policy rather than selling it separately. It pays client notification expenses up to 25,000 dollars and HIPAA fines and penalties where permitted by law, with fines and penalties unavailable in New York. That is notification and fines. It is not network security liability and it does not speak to extortion. HPSO’s separate business and practice program carries an Enterprise Privacy Protection limit up to 100,000 dollars aggregate. The individual policies are underwritten by American Casualty Company of Reading, Pennsylvania.
Read those two paragraphs next to the exclusion that matters most. The loss a small practice is most likely to actually suffer is ransomware or a fraudulent payment instruction, and neither incumbent product is built to answer it. A 25,000 dollar notification benefit is real money and worth having. It is not the same thing as a policy that pays a forensics firm, funds a business interruption period and negotiates an extortion demand. If your practice holds years of session notes in one system, that distinction is the whole decision.
How we would choose
We do not pick a winner and steer everyone to it. We compare the markets on equal coverage, look at your security controls and record volume, and match the fit to your practice, whether that means the lowest-cost option, the broadest wording, or the strongest breach-response bench. That comparison is the value of working with an independent agency rather than buying one brand direct.
Questions to ask your advisor
- Are these quotes being compared on equal coverage, or just on price?
- What sublimit does each carrier put on social engineering and invoice manipulation?
- Which of these markets rewards the security controls I already have?
- Is this policy admitted or non-admitted, and does that matter for my practice?
- Which carrier has the breach-response capability I would want if an incident happened?
Want guidance first? Compare your coverage. Already know what you need? Get a quote.