Mitigating Cybersecurity Risk: Is Cyber Insurance the Answer?

by Colin Konschak and Shane Danaher

 

Until recently, healthcare executives tended to ignore the need for cybersecurity, as it was perceived to only be a consequence affecting data, which can be replaced. However, since 2014 when cyberattacks against healthcare began ratcheting up, the industry leaders have been forced to acknowledge the increasing cyber threats and consider cybersecurity protection.

Though cybercrime has increased at a steady rate as technology becomes more pervasive, there has been a dramatic rise in cybercrime in the past eight years, with no sign of slowing down.  Still, healthcare systems see cybersecurity as more of an IT challenge with a relatively reactive approach to IT breaches. This leaves the health system significantly unprepared for cybercriminals and making the system not well-equipped to mitigate cyber threats, despite the economic importance of medical records. Health organizations are therefore beginning to turn toward cyber insurance providers as internet threats increase.

Is cyber insurance a good cybercrime strategy, just one component of an overall strategy, or is cyber insurance even unnecessary?

Leaders in all business sectors are realizing cybercrime can make virtually every business risk a reality, including reputation loss, business interruption, breach of privacy, liability for regulatory penalties, and even outright business failure. Throughout this cybersecurity whitepaper series, we have delved into steps organizations can take to protect their network, software and human attack surfaces. But what about insurance against attacks? Do healthcare organizations need cyber insurance? If so, what kind of coverage should they choose? In this whitepaper, we examine the kinds of business risks healthcare organizations face, the ways they can guard against those risks becoming realities, and how to blunt the impact if they do, including coverage with cyber insurance.

Download the full white paper Mitigating Cybersecurity Risk: Is Cyber Insurance the Answer?

About Divurgent

Divurgent is a full-service, healthcare-focused/HIT consulting firm led by people you actually want to work with. We’re one of the only firms out there that has your back for the whole journey. We can help you select an EHR or tool, implement it, staff it, bring you live, optimize it, and more. Three-hundred sixty degrees. Most of our focus is on EHRs, but we do much more than that. We think beyond the system and below the surface. Think workflow, digital strategy, operational readiness, change management and more. We’re most excited by helping you solve your most complex challenges.

We Attract, Develop, and Retain Top Talent | Our team has been in your shoes. Our consultants have worked within health systems, across all levels, so we bring operational and clinical expertise to every role. We have experts in EHR implementation, analytics, digital strategy, project management, managed services, and more, and we can rapidly source talent that fits our client’s project and culture.

Our Methodology is Proven | Our methodology considers operational realities, health system structural dynamics, and change management to present tailored solutions that are data-driven, scalable, and primed for adoption. And it’s future-focused: we design based on where your organization is going, not where it is today.

We Do What’s Right and Can Do It Quickly | Since 2007, we’ve been privately-owned, healthcare-focused, and driven foremost by commitment to our clients. This independence allows us to be agile – team members are empowered to make critical decisions in real-time – and flexible. Our relationships are much greater than the value of our contracts.

Join us at Club CHIME during ViVE 2026