CBA Record September-October 2026

cover fines and penalties at all. For example, if you have protected medi cal data and a breach exposes it, you could be facing fines from the Health and Human Services Office for Civil Rights. If a HIPAA violation is not corrected within 30 days, the penal ties could hit six figures, but if the policy caps coverage at $25,000 for regulatory penalties, the firm could be liable for the difference. l Incidents that occurred before the pol icy’s effective date cannot be covered at all. Let’s say the investigation reveals that hackers have been inside your system for months and only triggered the ransomware on their way out after stealing the client data they were after. If that was before your effective date, there may be no coverage. When your policy is next up for renewal, or if you are getting a new policy, I recommend that you talk with your broker and review the policy care fully. Some top points to check: 1. What are the sub limits for social engi neering/fraudulent wire transfer and ransomware payments, and how do they compare to the aggregate limit? 2. Does the policy cover breaches at third-party vendors (e.g., cloud stor age, practice management software), or only the firm’s own systems? 3. Does coverage depend on maintaining specific security controls (e.g., MFA, encryption), and what happens to a claim if the firm can’t prove compliance? 4. Is the firm required to use the insurer’s approved panel of forensic investiga tors and breach counsel, or can the firm choose their own? 5. Where does malpractice coverage end and cyber coverage begin? Is there overlap or a gap? Insurers are increasingly requiring baseline cyber hygiene. Your coverage can depend on how compliant you are. Documenting your compliance before an incident can be extremely helpful. In practice, this could be a written Informa tion Security plan, requiring safeguards such as multifactor authentication and annual training. Making sure the system

LPMT BITS & BYTES BY KEVIN THOMPSON Stop Guessing: What Does Cyber Insurance Really Cover for Your Solo/Small Firm?

M any more law firms are find ing themselves targets for ran somware and other attacks as a repository of client data. If their clients have good security, the hackers attack the weakest link, which could be the law firm. The time to read the exclusions on your cyber insurance policy is not when a claim is denied. It’s important to understand the gaps, and to know what is covered and what is not, in a standard policy. Furthermore, your malpractice carrier may be asking separate questions about your cyber coverage. Many car riers are increasingly requiring proof of specific security controls as a condition of binding coverage. A typical cyber insurance policy will cover first party costs, such as breach response, forensics, notification costs, and credit monitoring for affected cli ents. It will also cover third party claims, such as from a client or other third party after a breach. In some states, it will cover business interruption as well as payments for cyber extortion/ransomware pay ment. So where are the gaps? Consider the following seven areas of vulnerability: l Some policies will exclude coverage for social engineering or wire fraud or limit claims to a specific dollar amount. This could lead to huge liability for a firm when such attacks happen during a big transaction and closing funds get wired to the fraud sters instead of the proper party. l Some agreements have clauses for “failure to maintain minimum secu

rity standards” that can void coverage after the fact. If you have a security policy that is not followed and a breach results, this clause can result in the entire incident not being covered. l Some policies will not cover you for the breach caused by your vendor or other third party. What happens when the breach is with your practice management software vendor? You may be reliant on their insurance and policy limits rather than your own. l Some policies have sub limits for certain types of incidents. For exam ple, your overall policy might be for $1 million, but the coverage for cyberextortion could be capped at $100,000 per incident. Let’s say there was a fraudulent wire transfer in the amount of $200,000, but that policy has a $50,000 limit per incident of social engineering. That would leave the firm on the hook for the remain ing $150,000. l Often, limits are placed on how much the policy will pay for notification and credit monitoring. If the policy sets compensation at $2 per affected person, for example, this could be inadequate coverage for notifications and credit monitoring for large popu lations. l Regulatory fines and penalties are usually not covered at all, or if cov ered, they are severely sub limited. Illinois generally allows fines to be covered if they are remedial in nature, not punitive. To avoid such a determination, many policies will not

38 September/October 2026

Made with FlippingBook - Online catalogs