The Evidence File Your Renewal Actually Requires

Here is a prediction about your next cyber insurance renewal. Someone will forward the carrier’s questionnaire with a short note and a close deadline. You will spend the next two weeks pulling exports from five systems, chasing sign-offs from three people, and reconstructing a training report the LMS should have kept. You’ll make the deadline, barely, and know the whole time that you’ll do it again next year.

The two weeks are optional. The evidence the carrier wants already exists in your environment. What’s missing is a habit of gathering it before anyone asks, and that habit has a name: the evidence file, refreshed quarterly, five categories, one folder. Keep it current and renewal becomes retrieval instead of a scramble.

Five Categories, One Folder

MFA enforcement exports prove multi-factor authentication is running, not merely purchased and configured. Pull the enforcement report from your identity provider, dated. Access review sign-offs prove someone looked at who can touch what, and removed the access that no longer belongs. The signature and date matter as much as the review. 

Backup test results prove a restore actually succeeded. A log showing the backup job ran is not the same document, and carriers know the difference. Training records tie completions to individual names and dates. A percentage on a dashboard won’t survive scrutiny. BAA inventory is the live list of business associate agreements, checked against your actual vendor roster, because the two drift apart faster than anyone expects.

Read that list again and notice something. Your team already produces all of it. The evidence file adds no new controls and no new work beyond one quarterly export session. It converts work you’ve already done into proof you can hand over.

What “Almost Done” Costs at Claim Time

The City of Hamilton’s IT team knew their cyber policy required MFA starting in fall 2022. They did what most teams do with a big rollout: piloted it, department by department. Reasonable sequencing. Then ransomware arrived in February 2024, mid-rollout, and the insurer denied roughly $5 million in claims because the policy excluded losses where missing MFA was the root cause (CBC News, 2025).

The lesson for a hands-on team isn’t “move faster,” though speed would have helped. It’s that an insurer scores deployment as binary. Eighty percent coverage and zero percent coverage produce the same denial letter if the breach walks in through the uncovered 20 percent. A quarterly evidence file forces the honest number in front of your own team four times a year, while there’s still time to close the gap quietly, instead of once, in a forensic report, when there isn’t.

The Refresh Is the Control

A file assembled once decays into fiction within a year. People change roles, vendors rotate, a backup job silently starts failing. The quarterly refresh is what keeps every document in the file younger than 90 days, which is what makes it credible to a carrier, an auditor, or your own leadership on short notice. Healthcare’s average breach now costs $7.42 million, the highest of any industry for 14 straight years (IBM, 2025). Those are the stakes the carrier is pricing when it reads your file. A current one reads very differently from a reconstructed one.

Renewal season always starts with the same question: can we prove it? Pick one category this week, MFA enforcement is the best first choice, and pull the export. What you find, either way, is worth knowing now. Which of the five would your team least want to produce on a two-week deadline?


At Xpio Health, we work with security and IT teams to build the evidence file before the next renewal cycle opens. Contact us to get started.
#HealthIT #CyberInsurance #HIPAASecurityRule #BehavioralHealth #PeopleFirst #XpioHealth


References

  1. CBC News. Insurance won’t cover $5M in City of Hamilton claims for cyberattack, citing lack of log-in security. CBC. 2025. https://www.cbc.ca/news/canada/hamilton/cybersecurity-breach-1.7597713
  2. IBM. Cost of a Data Breach Report 2025. IBM. 2025. https://www.ibm.com/reports/data-breach