Question
Does cyber insurance respond to an OCR HIPAA enforcement action when there was no breach?
Short answer
Not automatically, and this is worth checking rather than assuming. Many cyber insuring agreements are triggered by a security failure, a privacy event, or a breach of protected information. An OCR enforcement action arising purely from an inadequate risk analysis, missing policies, or an absent business associate agreement may involve no such event, which can leave a breach-triggered policy without a trigger to attach to.
Why this is worth raising at all
Coverage summaries across the industry, including elsewhere on this site, routinely list regulatory defense for HHS Office for Civil Rights proceedings as a cyber policy feature. That is accurate as far as it goes, and it can create a reasonable but incomplete impression that any OCR matter is covered.
The precise question is not whether the policy contemplates OCR. It is what has to happen before the policy responds at all. Coverage grants attach to a defined trigger, and if the trigger is an event involving compromised information, an enforcement action about paperwork may sit outside it.
What OCR actually enforces
A significant share of enforcement is not about a dramatic intrusion. Recurring themes include the failure to conduct an accurate and thorough risk analysis across the organisation, missing or unexecuted business associate agreements, failure to provide individuals timely access to their own records, and inadequate policies, procedures, or workforce training.
Several of those categories can be established without any unauthorised access to protected health information ever occurring. An investigation can also begin from a patient complaint or a compliance review rather than from a reported breach.
Where the attachment problem sits
Read the trigger language in the regulatory defense and penalties agreement rather than the marketing summary of it. The useful distinction is between an agreement that responds to a regulatory proceeding arising from a privacy or security event, and one that responds to a regulatory proceeding arising from an actual or alleged violation of a privacy regulation.
The second is materially broader, because it does not require an event to have occurred. Where a policy uses the narrower construction, an access-rights or risk-analysis matter may not attach, and that is the scenario to test with your broker in writing.
Penalties themselves carry the usual limitation: insurable only where law permits. Defense costs are the more dependable component of the agreement in any construction.
The same logic you already apply to FDA inspections
This is not an unfamiliar problem in life sciences. An FDA Form 483 observation or a warning letter is a regulatory finding, and the question of whether any policy funds the response to it is one operators in this sector already understand.
Treat OCR the same way. Ask which policy pays for counsel, which pays for the technical remediation the resolution agreement will require, and whether a corrective action plan running for years creates costs nobody has budgeted.
The practical action
Ask your broker one specific question and keep the answer: does the regulatory agreement respond to an OCR investigation opened without any breach of protected health information, for example one arising from a risk-analysis deficiency or an individual access complaint.
If the answer is no or is qualified, that is a wording negotiation at renewal rather than an emergency. It is a far better conversation to have then than during an investigation.
Primary sources
Sources and references
This answer draws on the following regulatory, statutory, and standards-body sources. Coverage availability and program structure also depend on carrier appetite and underwriter discretion not captured by these sources.
- HHS Office for Civil Rights - Enforcement Highlightshttps://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/data/enforcement-highlights/index.html
- HHS - HIPAA Security Rulehttps://www.hhs.gov/hipaa/for-professionals/security/index.html
- HHS - Individuals’ Right of Accesshttps://www.hhs.gov/hipaa/for-professionals/privacy/guidance/access/index.html
Related practice areas
Insurance clauses in this area
Related questions
Have a more specific question?
A specialist will reach out by the end of the day.
Request a free coverage review