HIPAA breach notification
A breach exposes 800 client records. Legal review, notification letters, and credit monitoring run to roughly $60,000, covered as breach response.
Insurance Solutions
Home care runs on client health records, and that data is a target. Cyber liability insurance pays for breach notification, ransomware response, and the regulatory fallout when protected health information is exposed.
Cyber liability insurance covers the cost of a data breach and the cyberattacks that cause it. For a home care agency, that means the expense of responding when client information is exposed, stolen, or held for ransom. It pays for the investigation, the legally required notifications, the credit monitoring, the legal defense, and the regulatory penalties where they can be insured.
Most policies have two sides. First-party coverage pays your own costs to respond to an incident: forensics, breach notification, data restoration, and lost income while your systems are down. Third-party coverage pays when affected people or regulators come after you, covering legal defense and settlements. Home care needs both, because a breach hits you with your own response bill and someone else claim at the same time.
The reason this is its own policy is simple. Your other coverages were written for the physical world, for injuries and accidents and vehicles. None of them were built for stolen data. When client protected health information leaks, cyber liability is the only policy in your program designed to respond.
You hold a gold mine of sensitive data, whether you think of it that way or not. Client names, dates of birth, Social Security numbers, diagnoses, medication lists, and insurance details all live in your scheduling system, your billing software, and the laptops and phones your staff carry. Protected health information sells for more than credit card numbers on the criminal market, and that makes you a target.
Healthcare has become one of the most attacked sectors, and small providers are not too small to hit. Attackers know that a home care agency often has thinner defenses than a hospital and the same valuable records. Ransomware crews lock up scheduling and billing systems and demand payment. Phishing emails trick a staffer into handing over a password. A laptop gets left in a car and stolen. Any of these can expose hundreds of client records at once.
What turns an incident into a financial event is the law. The HIPAA breach notification rule in 45 CFR requires you to notify every affected individual, and for larger breaches to notify the Department of Health and Human Services and sometimes the media. That notification is not a courtesy, it is mandatory, and it is expensive: legal review, printed letters, call centers, and credit monitoring for everyone affected. Even a breach of a few hundred records can cost tens of thousands to handle correctly.
Then there is enforcement. The HHS Office for Civil Rights investigates breaches and can impose penalties that scale with how careless the agency was. For a small business, a serious enforcement action on top of the response costs can be the end. Cyber insurance is what keeps a bad click or a stolen device from becoming a closure.
The figures below show how a typical policy responds to common home care cyber incidents. They illustrate the kind of event each part of the coverage answers for, not a promise of any specific payout.
A breach exposes 800 client records. Legal review, notification letters, and credit monitoring run to roughly $60,000, covered as breach response.
Scheduling and billing systems are locked. The policy covers forensics, negotiation, data restoration, and the income lost while you are down.
An unencrypted laptop with client records is stolen from a car. The resulting breach notification and response costs are covered.
An attacker breaks into your online records system. Investigation, containment, and notification of affected clients are covered.
The Office for Civil Rights opens an investigation. The policy funds legal defense and, where insurable, the penalties assessed.
Clients sue over the exposure of their information. Third-party coverage pays the defense and any settlement up to your limit.
Cyber policies vary more than most, so reading the terms matters. These are the common boundaries to know.
The exclusions reward good habits. Encryption, multi-factor authentication, and honest answers on your application all keep claims payable and premiums lower.
Cyber limits are usually built from several parts rather than one number. There is an overall aggregate limit, and then sublimits for specific exposures like ransomware, social engineering, and regulatory fines. A policy might show a $1 million aggregate but cap ransomware at $250,000 and social engineering at $100,000. The headline number is not the whole story, so the sublimits are where you look.
Most small and mid-size home care agencies carry $1 million in aggregate cyber coverage, which is enough to handle a typical breach plus the legal and regulatory tail. The right limit depends on how many client records you hold, because notification and monitoring costs scale with the number of people affected. An agency with thousands of clients carries more exposure than one with a few dozen.
Coverage also splits between first-party and third-party, as noted earlier. First-party pays your response and business interruption. Third-party pays claims from affected individuals and regulators. A complete policy covers both, and we make sure neither side is left thin.
| Provider | Aggregate limit | Common ransomware sublimit |
|---|---|---|
| Solo or very small agency | $500,000 | $100,000 |
| Small agency | $1,000,000 | $250,000 |
| Mid-size agency | $1,000,000 to $2,000,000 | $250,000 to $500,000 |
Cyber pricing tracks your data and your defenses. The more client records you hold and the weaker your security, the higher the premium. Agencies that use multi-factor authentication, encrypt devices, and train staff on phishing usually pay less, because they are less likely to file a claim.
These are typical annual ranges for a small to mid-size agency, not quotes. They move with revenue, record count, systems, and controls.
$1,000 to $1,800 / year
A small client base and a few devices. Basic security controls keep this at the low end.
$1,500 to $2,800 / year
A growing record count across scheduling and billing systems. Controls and claims history shape the price.
$2,500 to $3,500 / year
More clients and more systems mean more exposure. Strong security is the best way to hold the line on cost.
The single best way to lower this premium is to improve your security, because it lowers both your price and your odds of a claim. Multi-factor authentication, encrypted laptops, and regular backups are the basics carriers reward. Get your cyber liability quote and we will tell you which controls move your number most.
Details are changed, but these patterns repeat across home care, and they show how the coverage behaves when it gets used.
A scheduler laptop was stolen from a parked car. It held an unencrypted spreadsheet with names, addresses, and diagnoses for more than 700 clients. Under the breach notification rule, the agency had to notify every one of them and offer credit monitoring. Legal review, the mailing, and monitoring came to about $58,000. Cyber insurance covered it. The agency learned a hard lesson about encryption, which would have made the device a non-event.
An employee clicked a convincing invoice email and ransomware spread through the agency network, locking the scheduling and billing systems. Care coordination ground to a halt. The policy paid for forensic investigators, the negotiation, data restoration from backups, and the revenue lost during the days the agency was down. The total response ran past $90,000. Without coverage, a small agency would have faced that bill alone while unable to bill for services.
A staff member sent a file of client information to the wrong email address, a simple slip that still counts as a breach. The agency had to investigate, notify the affected clients, and document its response for regulators. Cyber coverage paid the legal and notification costs, around $22,000, and the OCR closed its inquiry without a penalty. Small mistakes trigger the same legal duties as a sophisticated hack.
Cyber liability covers the one risk none of your other policies were built for, the loss of data, and it sits alongside them rather than overlapping. Knowing the line keeps you from assuming a different policy will respond.
Your general liability handles physical injuries and property, not data. Your professional liability handles harm from the care, even when records are part of the story, but not the breach itself. Cyber is the only policy that pays for notification, ransomware, and regulatory response. Most agencies add it as a distinct line in the program, sized to the volume of client information they hold.
The federal floor is HIPAA. The breach notification rule in 45 CFR sets out who you must tell and how fast when protected health information is exposed, and the HHS Office for Civil Rights enforces it. Those duties apply no matter which state you operate in, and they are the main reason a breach gets expensive so quickly.
States layer their own rules on top. California has some of the strictest data privacy laws in the country, and New York adds its own breach and security requirements through the SHIELD Act. A multi-state agency has to satisfy HIPAA and every state law that applies to its clients. Cyber coverage that includes regulatory response helps you meet all of them without absorbing the cost alone.
Cyber policies differ more than any other coverage in your program, so the details below decide whether yours actually responds. Here is what to check.
For the rules that drive these claims, the HHS Office for Civil Rights publishes the HIPAA breach notification requirements, and the National Association for Home Care and Hospice offers data security guidance for home-based care.
The questions home care owners ask us most about this coverage.
Because you hold some of the most sensitive data there is: client names, diagnoses, medications, Social Security numbers, and insurance details. That protected health information is valuable to criminals and increasingly targeted. A single breach triggers legally required notification, credit monitoring, and potential regulatory penalties, and those costs land on the agency. Cyber insurance pays for the response so one incident does not drain your operating account.
Yes, and this is one of its most important functions. The HIPAA breach notification rule in 45 CFR requires you to notify affected individuals, and in larger breaches the Department of Health and Human Services and the media. That process means letters, call centers, credit monitoring, and legal review. Cyber policies pay these breach response costs, which can run into the tens of thousands even for a small agency.
A ransomware policy typically covers the costs of responding: forensic investigation, negotiation, data restoration, business interruption while you are locked out, and in some cases the ransom payment itself subject to the policy terms. Home care agencies that run scheduling, billing, or electronic medical records online are exposed, because losing access to those systems can stop care and billing cold.
Usually yes. A lost or stolen laptop, phone, or thumb drive holding unencrypted client information is one of the most common breaches in healthcare. If that device exposes protected health information, the breach notification and response costs are covered. It also shows why encryption matters: an encrypted device that is lost may not count as a reportable breach at all.
No. General liability covers bodily injury and property damage, not the loss of electronic data. This is one of the most common and dangerous coverage assumptions agencies make. A data breach falls squarely outside general liability, which is exactly the gap cyber insurance was created to fill.
For a small to mid-size home care agency, cyber liability typically runs $1,000 to $3,500 a year. The price depends on your revenue, how many client records you hold, the systems you use, and the security controls you have in place. Agencies with basic protections like multi-factor authentication and encryption often qualify for better pricing.
The HHS Office for Civil Rights enforces HIPAA and can impose penalties that scale with the level of negligence, reaching well into six and seven figures for serious or willful violations. Even a modest enforcement action plus the cost of notification and monitoring can be devastating to a small agency. Cyber policies that include regulatory coverage help pay for the defense and, where insurable, the penalties.
Physical injury and property coverage, the part cyber does not touch.
Explore general liabilityCoverage for harm that comes from the care itself.
See professional liabilityThe full set of coverages a home care program can include.
Browse every solutionSkilled providers running electronic medical records and billing.
Home health agency insuranceNursing providers holding detailed clinical records.
Private duty nursing coverageNon-medical agencies that still hold sensitive client data.
Coverage for home care agenciesSend us your agency details and a specialist will price cyber coverage sized to the records you hold and the systems you run. It takes a few minutes and there is no obligation.