Technology
Malpractice Carrier IT Questionnaires: What They're Really Asking

Every year, the renewal questionnaire shows up, and every year, someone at the firm answers the IT-security section as honestly as they can, which sometimes means guessing. “Is multi-factor authentication enabled?” Probably, on most things. “Do you have endpoint detection and response?” What exactly counts as that? The questions read like a checklist, but they’re not really asking whether a box is technically checked. They’re asking whether the firm would survive being tested.
Here’s what’s actually behind the questions most carriers ask.
“Is MFA Enabled?”
This isn’t really asking whether MFA exists somewhere in the firm. It’s asking whether it’s enforced everywhere it matters: email, remote access, practice-management software, anything touching privileged client communications. A firm that has MFA on some accounts but not others is, from a risk standpoint, closer to a firm with no MFA than one that’s fully covered. The gap is where a breach happens.
“Do You Have Endpoint Detection and Response?”
Antivirus software answers “is there something known and bad on this machine.” Endpoint detection and response answers a different question: is something happening on this machine that looks wrong, even if nothing recognizable has triggered yet. Carriers ask about this specifically because most modern attacks don’t look like traditional viruses. They look like a legitimate-seeming login from an unusual location, or a process quietly copying files at 2am.
“What’s Your Incident Response Plan?”
This question isn’t asking whether you have a document. It’s asking whether, at 2am on a Saturday, the people who’d need to act would actually know what to do, who to call, and in what order. A plan that exists as a file nobody’s reviewed in two years answers the question on paper without answering it in practice. The firms that handle an actual incident well are the ones who’ve thought through the sequence before they needed it.
“How Often Is Data Backed Up, and Have You Tested Restoring It?”
The first half of this question is easy. Nearly every firm backs something up nightly. The second half is where most answers get shaky, because a backup that’s never been restored is a backup you’re hoping works. Carriers ask this specifically because ransomware claims often hinge on exactly this: whether the firm could recover without paying, and how long that recovery actually took versus how long it was assumed to take.
“How Is Access Removed When Someone Leaves?”
This question is really about whether access control is a process or a memory. If offboarding depends on someone remembering to revoke access across every system an employee touched, that’s a gap that widens every time staff turnover happens. Carriers see enough claims tracing back to a former employee’s still-active account to ask this directly rather than assume it’s handled.
Why Honest Answers Matter More Than Impressive Ones
It’s tempting to answer these questions optimistically, especially under deadline pressure to get a renewal submitted. But a questionnaire answered generously and a firm’s actual security posture eventually get compared, usually during a claim, which is the worst possible moment for a gap to surface. An honest “not yet, here’s our plan to close it” is a stronger position than an optimistic “yes” that doesn’t hold up.
Getting to Where the Answers Are Actually True
The firms that answer these questions confidently aren’t guessing, because the underlying systems were built with these exact questions in mind from the start, not retrofitted the week the renewal is due. That’s the same approach behind our work on Gleichman Law Firm’s infrastructure: build to what a law license and its insurer actually require, verify it, document it, and keep it that way, so the next questionnaire is a formality instead of a scramble. If you’re not sure your current answers would hold up, that’s exactly what IT built for law firms is supposed to fix.


