DATA BREACH, NETWORK SECURITY, CYBER LIABILITY, PRIVACY PROTECTION: ARE YOU INSURED? February 3, 2012 Steve Brown, Agency Manager West Virginia Medical Insurance Agency
How many in the audience today will answer Yes to this Question: Does My Medical Practice have Insurance Coverage for Data Breach, Network Security, Cyber Liability, Privacy Protection? YES NO
Where to Obtain Cyber Liability Insurance A. From Medical Professional Liability Insurance Carrier B. From Business Owners Carrier (BOP) C. From Stand Alone Markets
A. From MPL Insurance Carrier Most medical professional liability insurers in West Virginia have by endorsement added a premium free coverage to their MPL policy that provides: (1) e-md TM Network Security and Privacy: coverage for legal obligations of the Insured to pay for claim(s) resulting from a Network Security Wrongful Act or Privacy Wrongful Act. (2) Regulatory Fines and Penalties Insurance: coverage to reimburse the Insured for regulatory fines and penalties the Insured becomes legally obligated to pay. (3) Patient Notification on Credit Monitoring Costs Insurance: coverage to pay notification and credit monitoring costs incurred by the Insured, with the written consent of the Insurer, by reason of a claim(s) for Privacy Wrongful Act. (4) Data Recovery Costs Insurance: coverage to pay data recovery costs incurred by the Insured, with the written consent of the Insurer, as the result of a claim for a Data Interference Act. These coverages are generally free of charge to the Insured.
NOTE: WVMIC offers the highest underlying limit ($250,000) of cyber liability coverage, and consequently, offers the greatest discount on the purchase of higher limits (limits above $250,000) Also, WVMIC additionally provides Broad Form Administrative Endorsement, also at no charge, which provides investigative cost coverage for such things as RAC audits.
Names of Coverage Endorsements: WVMIC: Privacy Protection and Network Security Endorsement ProAssurance: Limited Network Related Coverage Endorsement Medicus: Medicus Gold Advantage Endorsement
Coverage Limits: Coverage WVMIC ProAssurance Medicus e-med Net. S&P $100,000 *1 $50,000 $100,000 Reg. Fines & Penalties $100,000 *1 $50,000 $100,000 Patient Notif & Credit Monitoring $100,000 *1 $50,000 $100,000 Data Recovery Costs $100,000 *1 $50,000 $100,000 Aggregate Limit $100,000 *1 $50,000 $100,000 *1 Effective with renewal in 2012, this limit ($100,000) will increase to $250,000 Higher limits available.
B: From Business Owners (BOP) Carrier As the need for Cyber Liability Insurance expands, other carriers (non-medical professional liability carriers) with a desire to provide coverage, specifically designed for Medical Practices will add this benefit.
Examples: The Hartford s Data Breach Coverage Response Expense Coverage Provided: First Party Response Expenses for: Legal & Forensic Services Notification Expenses Crisis Management/Public Relations Third Party Defense & Liability: Civil Awards Settlements Judgements that an Insured is legally obligated to pay Offered as optional coverage through The Hartford s Spectrum (Business Owners Policy) Limits Available: $10,000; $25,000; $50,000; $100,000 with various sublimits.
C. From Stand Alone Carrier Stand Alone essentially meaning a carrier who is providing only one coverage. Scenario: If you do not have cyber liability insurance as part of your medical professional liability policy or your business owners policy, you may want to purchase it a stand alone market may be available to offer you this benefit. Examples: NAS Insurance Services (will also offer limits in excess of WVMIC/ProAssurance/Medicus) HISCOX Specialty Hartford Financial Possible Target Markets: Physicians with MPL Coverage in the Excess/Surplus Lines Market (companies not licensed in WV) Physicians purchasing MPL policies from RRGs (Risk Retention Groups)
e-md Policy Highlights Limits of Liability up to $10,000,000/$10,000,000 Minimum Deductible of $1,000 Minimum Premium of $990 Large Breach Response Limits with Breach Response Costs Outside of the limits available Full Prior Acts Available Broad Coverage for date that is stored with a third party including, but not limited to Outsourcers and Independent Contractors Acts committed by rogue employees are covered, as well as privacy claims from employees Network Asset Protection including Business Interruption includes adminitrative and operational mistakes policy trigger as well as cyber crimes Property Damage exclusion does not include electronic data Final Adjudication language for Defense for allegations of fraud or intentional wrongdoing Coverage continues through bankruptcy Commercial and Corporate confidential information is covered Multimedia Coverage includes liability assumed under contract Worldwide coverage claims can be brought outside of the US Extended Reporting Period is available up to 3 years, but additional coverage may be available upon request