LIVE WEBINAR

Insurance and Cybersecurity Considerations for Psychologists: Am I Meeting My Cyber Insurance Requirements?

Friday, October 30, 2026, 10:00 AM - 1:00 PM MDT
Join the LIVE webinar on October 30, 2026
  • 3 Hours
  • English
  • $115.00
Empty space, drag to resize
Note: The recording will be available in the course player after the live webinar has concluded.
Empty space, drag to resize
overview
Your cyber insurance application asks whether you have multifactor authentication, device encryption, regular backups, patching, and annual staff training. You sign it. This session is about what happens if you have to prove it. Kelly Paisley, who runs the IT company that answers these questions for a living, sits down with Chris Pawluk for three hours on what psychologists are actually being asked to attest to, where the gaps usually are, and what a defensible file looks like before an insurer, broker, or regulator asks for one.
Empty space, drag to resize
Certification included
This webinar is eligible for 3 Continuing Education (CE) Credits on behalf of the Canadian Psychological Association.
ABOUT THE WEBINAR
LEARNING OBJECTIVES
PRESENTATION MATERIALS
DISCLOSURE
Empty space, drag to resize
Before the live webinar, the following will be accessible for your use:
  • Speaker Slide Deck
  • Resource Links
  • Downloadable PDFs 
    Connect with Kelly at: https://theitco.ca/

Empty space, drag to resize
The session starts with why cyber insurance changed the conversation. For years, cybersecurity in private practice was a matter of professional judgment and a privacy policy. Now it is a set of contractual conditions with a signature under them, and the three-way problem is that your regulator, your insurer, and your actual working systems each expect something slightly different.

From there it takes apart the most common belief in the room: all my patient data is in the EMR, and the EMR is secure and backed up, so we are fine. That claim is usually true and almost never complete. Client information also lives in email, in downloaded reports, in scoring platforms, on laptops and phones, in cloud storage nobody has audited, and increasingly in AI tools. The session follows that trail and connects it to data-retention and system-security decisions.

The middle of the session is worked examples. A green, yellow and red framework for triaging what you find, then a run of insurance-readiness vignettes: a misdirected report, a compromised email account, a departing staff member whose access nobody closed, an AI scribe nobody vetted. Each one gets the practical answer, not the theoretical one.

The last hour is the file itself. What a minimum viable insurance-readiness record contains, how to assemble one without an IT department, and what actually happens in the first hour after an incident, including who you are obliged to tell and in what order.
Empty space, drag to resize
Upon completion of this webinar, participants will be able to:

1. Identify the safeguards commonly required on cyber insurance applications, including multifactor authentication, device encryption, backups, patching, endpoint protection, and staff training, and explain what each one means in the context of a psychology practice.
2. Map where client information actually lives across their practice systems, including practice management software, email, cloud storage, devices, scoring platforms, and AI tools, and connect that map to data-retention and system-security decisions rather than assuming everything stays in the EMR.
3. Apply a green, yellow and red framework to triage cybersecurity and privacy risks in their own practice, distinguishing defensible baselines, workflows needing review, and items requiring prompt correction.
4. Assemble a minimum viable insurance-readiness file that documents systems, safeguards, access, vendors, and incident-response contacts in a form defensible to an insurer, broker, or regulator.
5. Describe the first response steps after common incidents, including containment, evidence preservation, and reporting obligations to broker, insurer, and privacy bodies.
Mr. Paisley is President and CEO of The I.T. Company, a managed services and cybersecurity provider, and The I.T. Company provides IT services to Hexagon Psychology. This session is educational and is not a sales presentation. No product, platform, or vendor is endorsed, and Mr. Paisley receives no speaker fee from Hexagon Training for this presentation.
MEET THE SPEAKER

Kelly Paisley, CEO

Kelly Paisley, President and CEO, The I.T. Company

Kelly Paisley is President and CEO of The I.T. Company, a managed services and technology consulting firm established in 2008. His path into IT began early, taking apart the family electronics and teaching himself to put them back together before anyone noticed, and he was working as an IT administrator shortly after college. 

Two decades on, his focus has moved from the helpdesk to strategy: growth planning, business consulting, and helping organizations use technology to increase revenue while reducing their digital vulnerabilities. 

The I.T. Company provides managed IT services, cloud solutions, cybersecurity and IT consulting, and is an approved advisor under the Canada Digital Adoption Program. Kelly works with professional practices on cybersecurity, managed services and
insurance readiness. Outside work he spends most of his time with his son, boxing, reading and at the occasional comic convention.

Reserve your spot to attend our live webinar!