Skip to content

Business · Guide

Cyber liability insurance for Miami professionals: ransomware, HIPAA, and client data

A Brickell law firm, a Doral clinic, and a Palmetto Bay accountant all keep other people’s data. Ransomware and a wire-fraud email are not covered by general liability. Cyber is a separate form: first-party (your downtime, restoration, extortion) and third-party (clients, regulators). MFA and backups are underwriting, not IT poetry.

September 3, 2026 · 6 min read · Miami-Dade & Florida

What GL will not do

A stolen laptop with a client list, a phishing wire, a ransomware lock on the practice-management server — GL is bodily injury and property damage in the physical world. Cyber is the data event.

First-party vs third-party

First-party: forensics, restoration, business interruption, sometimes extortion. Third-party: claims by clients, notification, defense. Health-adjacent shops should not put diagnoses in a website form; they still need cyber if they email PHI. HIPAA is a program. Cyber is a policy. Both can apply.

What underwriters ask in 2026

MFA on email, backups offline or immutable, who can wire money, EDR. “We use iCloud” is not an answer. A $1 million limit is a starting conversation, not a guess.

How we quote it

Revenue, record counts, whether you take cards or health data, and last year’s IT questionnaire if you have it. Start a business quote and say cyber. An advisor will not sell a $100,000 toy limit to a clinic.

Questions we get

Next

If this sounds like your house, get a number.

Same desk that wrote the guide. Auto and home quote online. Other lines, an advisor.

Keep reading