Contact Us
December 2024

Trium HITRUST Shared Risk Facility

We wanted to share an update on a specific industry-focused offering launched by Trium London in collaboration with HITRUST. The HITRUST Shared Risk Facility is available to HITRUST r2-certified entities, allowing Trium to use information already provided to HITRUST as part of the underwriting assessment. This approach streamlines the underwriting process, replacing traditional applications and delivering greater efficiency for you and your clients.

The HITRUST Shared Risk Facility offers a unique approach to underwriting HITRUST-certified companies. It’s not limited to healthcare networks or providers—it also applies to other organisations that handle sensitive healthcare information and have, or may choose to obtain, HITRUST r2 certification. This includes sectors such as technology, accounting, and law firms.

For the first-year quote, we can use the traditional application process already completed for your current programme. All we need is confirmation that the client is r2 certified along with the application. Since the insured holds r2 certification, Trium can underwrite the risk more favourably, recognising the high standards required to achieve this certification. From the first renewal onwards, Trium can streamline the process further by offering terms based on information received through their API integration with HITRUST.

From 1st January 2025, clients will have access to an API within their HITRUST portal, enabling them to grant Trium consent to access the necessary underwriting information. Using this data, Trium can provide a quote and issue a statement of fact detailing the information used during the underwriting process. This statement can be shared with the client, producer, and any excess insurers as needed.

There are two offerings available: one tailored for mid-market clients with revenues under $1 billion, and another for large-market clients with revenues exceeding $1 billion. All policyholders participating in the HITRUST Shared Risk Facility gain access to Trium’s True Risk Avoidance and Mitigation (TRAM) services. Trium has developed bespoke policy wordings for this offering. Copies of both wordings are attached, with highlights including:

  • $15M in global capacity
  • Coverage breadth: concise form designed to provide broad coverage with simple and clear language.
  • Exclusionary language intentionally narrow to provide insured with broadest possible coverage
  • Extortion coverage – “pay on behalf’
  • BI, CBI, Network Failure, Rep Harm, and Voluntary Shutdown cover given as standard full limits
  • No restriction on period of restoration for BI, CBI and Network Failure (i.e. all the time the Insured needs to get back up and running)
  • Restoration Costs – replacement cost value
  • Broad period of restoration for Rep Harm – 365 days
  • Faster settlement of BI losses. Forensic accountant chosen from our panel by mutual agreement will be used to adjust the loss. Costs of the forensic accountant will be borne by the Insurer in addition to the aggregate cover so that claim adjustment costs won’t erode the limit of insurance
  • Cryptojacking, Invoice Manipulation and Transfer Loss – $250,000 sublimit
  • Automatic acquisitions clause set at 25% – above market standard
  • 80/20 Consent to Settle provision
  • Broad range of endorsements to fit the insured’s needs:
  • Prof/Tech E&O
  • Wrongful Collection
  • Contingent Network Failure
  • Limit Reinstatement
  • Income Loss Advance

Below are links to documents that provide more details about this offering. We encourage you to review them and share them with your clients and colleagues. For those unfamiliar with Trium or HITRUST, we’ve also included a brief summary of each for your reference:

TRIUM

Trium Syndicate 1322 is the first monoline, cyber-only syndicate approved by Lloyd’s of London. Their team comprises highly experienced professionals across underwriting, claims, IT, finance, exposure management, risk, security, and operations. Each member is dedicated to delivering innovative insurance products, tailored risk management solutions, and effective loss mitigation services.

 Large Market Summary                     Middle Market Summary

                                 

HITRUST

HITRUST, the Health Information Trust Alliance, provides a standardised approach to information security, privacy, and compliance for healthcare organisations. Its certifications are widely regarded as the gold standard for demonstrating information security maturity, regulatory compliance, and overall posture. The r2 assessment and certification is particularly suited for organisations needing to comply with authoritative frameworks such as HIPAA, the NIST Cybersecurity Framework, and numerous others, or for those requiring tailored controls based on identified risk factors. It represents HITRUST’s most comprehensive and robust assessment.

Large Market Summary                     Middle Market Summary

                                 

If you have any questions on the Trium HITRUST Shared Risk Facility, please contact one of the Cyber team for more details.