Purpose of the Template
Your underwriting questionnaire is crucial in determining your coverage, premium costs, and the speed of claim processing. Generic cyber questionnaires often overlook the specific vulnerabilities that make healthcare organizations prime targets. This template provides a healthcare-specific structure that addresses the technical and operational realities insurers use to assess your risk.
Use this template when preparing for renewal, switching carriers, or conducting an internal cyber maturity assessment. It highlights the critical gaps in healthcare environments: VPN security, legacy system management, vendor dependencies, and interconnected clinical infrastructure, which differentiate your organization from others like retail chains or manufacturing plants.
Preparation Checklist
Before completing the questionnaire, gather:
- Your current network architecture diagram, including all remote access points.
- A complete inventory of medical devices and IoT endpoints.
- Vendor management documentation, especially for billing, EHR, and pharmacy systems.
- Your incident response plan and tabletop exercise records.
- Documentation of your MFA implementation across all user types (clinical, administrative, vendor).
- Your most recent penetration test or vulnerability scan results.
You'll need input from your IT security lead, compliance officer, and someone familiar with your clinical workflow. No single person can accurately complete this questionnaire alone.
The Template
Section 1: Remote Access and Authentication
1.1 List all remote access methods in use (VPN, SSL VPN, Remote Desktop Protocol, cloud-based access).
1.2 For each method, confirm MFA enforcement:
- Is MFA required for all accounts? (Yes/No)
- Which user types are exempt, if any?
- What happens after five failed login attempts?
- Do you block connections from anonymous networks, public VPNs, proxies, or TOR?
1.3 Password policy enforcement:
- Minimum complexity requirements
- Password rotation frequency
- Use of password managers (required/recommended/optional)
Section 2: Clinical and Legacy Systems
2.1 List all systems that cannot support current security patches:
- System name and vendor
- Last patch date
- Compensating controls in place
- Planned replacement date (if applicable)
2.2 Medical device inventory:
- Total number of connected medical devices
- Number requiring vendor-managed access
- Number on isolated network segments
- Devices running unsupported operating systems
2.3 Electronic Health Record (EHR) system:
- Vendor name
- Cloud-hosted or on-premises
- Last major version update
- Backup frequency and tested recovery time
Section 3: Vendor and Third-Party Risk
3.1 Critical vendor dependencies:
- Billing systems vendor
- Pharmacy management vendor
- Lab systems vendor
- Telehealth platform vendor
3.2 For each critical vendor:
- Do you have documented evidence of their security controls?
- When did you last review their SOC 2 or equivalent report?
- Do your contracts include breach notification timelines?
- Have you tested your operational continuity if this vendor goes offline?
3.3 Vendor access management:
- How many vendors have direct network access?
- Is vendor access logged and monitored?
- Do vendors use MFA for remote access?
Section 4: Incident Response and Business Continuity
4.1 Incident response plan:
- Date of last full update
- Date of last tabletop exercise
- Does your plan specifically address ransomware scenarios?
- Does your plan include patient care continuity procedures?
4.2 Backup and recovery:
- Backup frequency for clinical systems
- Are backups stored offline or air-gapped?
- Last successful full restoration test date
- Maximum tolerable downtime for EHR system
4.3 Breach notification procedures:
- Do you have pre-drafted HIPAA breach notification templates?
- Do you have external breach coach contact information documented?
- Do you have a patient communication protocol ready?
Section 5: Website and Patient Portal Security
5.1 Patient portal and public website:
- List all third-party analytics or tracking tools in use
- Have you conducted a privacy impact assessment for each tool?
- Do you have documented data-sharing agreements with each vendor?
- When did you last audit what patient data these tools can access?
5.2 Online appointment scheduling:
- Is this function handled by a third-party vendor?
- What patient information is transmitted?
- Is transmission encrypted end-to-end?
Customizing the Template
Start with Section 1. If you can't answer "yes" to MFA enforcement across all accounts, address this before submitting your questionnaire. About 50-60% of ransomware incidents in healthcare stem from VPN accounts lacking proper MFA enforcement, and insurers are aware of this. An honest "no" here could disqualify you or significantly increase your premium.
In Section 2, be specific about legacy systems. Instead of saying "some older devices," specify "12 radiology workstations running Windows 7, isolated on VLAN 40, scheduled for replacement Q3 2026." Insurers can price known, managed risk but not vague uncertainty.
Section 3 requires cross-departmental collaboration. Your IT team knows the technical vendors; your finance team knows the billing vendors; your clinical operations team knows the pharmacy and lab vendors. Map the full ecosystem, then identify which vendors could halt patient care if they went offline. These are your critical dependencies.
In Section 4, if your last tabletop exercise was over 12 months ago, schedule one before renewal. If you've never tested a full EHR restoration, document this gap with a remediation timeline.
For Section 5, remove any tracking pixels or analytics tools from patient-facing systems unless you have explicit legal review confirming HIPAA compliance. The settlement risk here averages $5-6 million when things go wrong, and it's entirely preventable.
Validation Steps
Before submitting this questionnaire to your broker or insurer:
Internal validation: Have your Chief Information Security Officer and compliance officer both sign off. Resolve any discrepancies before submission. Misrepresentations can void your coverage when you need it most.
Gap identification: For every "no" or "in progress" answer, document your remediation plan with specific completion dates. Insurers will accept documented gaps with credible remediation timelines but not unidentified or unplanned gaps.
Broker review: Share this with your broker before formal submission. A good broker will tell you which gaps are deal-breakers and which are negotiable. They should also help you frame your compensating controls in language underwriters recognize.
Year-over-year comparison: If you completed a similar questionnaire last year, compare your answers. If your security posture hasn't improved, expect your premium to reflect that. Attack frequency in healthcare surged by roughly 90% in 2025 compared to the previous year, and pricing will follow risk.
Your completed questionnaire becomes your baseline. Update it quarterly, not just at renewal. When your insurer identifies a critical vulnerability mid-term, your response time matters. Organizations that treat cyber resilience as a continuous operational practice, not an annual paperwork exercise, get better terms and faster claims resolution when incidents occur.




