
A cyber breach rarely announces itself with anything dramatic. It usually starts with a locked screen, a vendor alert, or an employee who suddenly cannot access a system that worked fine yesterday. What happens in the hours and weeks that follow determines whether the incident becomes a manageable disruption or a very expensive one, and a lot of that comes down to a question most practices have never actually answered: who pays for what.
The First 72 Hours
Before anyone knows the full scope of a breach, costs are already accumulating.
-
Legal counsel typically has to be involved before any notification decisions get made
-
Notification deadlines start running immediately, and healthcare practices face both state law and HIPAA requirements on top of the usual timeline
-
Forensic investigators need to be engaged early, since the scope of the breach shapes every decision that follows
None of this waits for a complete picture. Decisions get made fast, often before anyone knows exactly what the final bill will look like.
Where the Costs Actually Land
A breach response typically involves several categories of cost, and they do not all show up at once.
-
Forensic investigation and legal counsel, usually first
-
Breach notification and credit monitoring for affected individuals
-
Business interruption, if systems are down long enough to affect operations
-
Regulatory penalties, in some cases, depending on what was exposed
-
Third-party liability, if patient or client data was involved
Some of these are one-time costs. Others, like business interruption or a liability claim, can extend for months, long after the systems themselves are back online.
Why Standard Coverage Does Not Step In
A Business Owner’s Policy is built around property and general liability. Malpractice coverage is built around clinical decisions. Neither is designed to respond to a data incident, even for practices that carry solid coverage everywhere else.
This surprises more practices than it should. Coverage that feels comprehensive on paper can still leave the entire cost of a breach response uncovered, because a data incident simply is not the kind of event either policy was written to address.
Why This Carries More Weight for Medical Practices
The type of data involved changes the stakes considerably. A breach involving patient records triggers notification and regulatory obligations that a typical retail or service business never has to consider, and the potential for third-party liability rises accordingly. Practices handling protected health information are managing a different level of exposure than the general business next door, whether that reality has been factored into their coverage or not.
Assumptions That Cause Problems
A few beliefs come up often, and most do not hold up once a breach actually happens.
-
Our cloud vendor is responsible. Vendors may carry some liability, but the practice named in a breach notification still deals with the regulatory and reputational fallout directly.
-
Our IT company handles security. IT support and breach response are different services, built for different situations.
-
We would just pay and move on. Ransom payments raise legal questions of their own, and paying does not guarantee systems or data come back intact.
What a Cyber Policy Is Actually Built to Do
Cyber coverage is designed to fund and coordinate the response: forensics, legal counsel, notification, credit monitoring, and business interruption, often through a panel of vendors already vetted for exactly this kind of event. That means a practice is not searching for a forensics firm in the middle of a crisis. The response is already built before it is needed.
How Unity Approaches This
This is not about confirming a policy exists. It is about reviewing what a practice’s actual exposure looks like, based on patient volume, the systems in use, and how data moves through the practice, then making sure limits and coverage triggers reflect that exposure before anything happens, not after.

