> No insurance company is going to take that deal because infosec audits are not perfect and they can not audit every possible software release.
That doesn't cause them to be unwilling to write a policy. What it does is cause the premiums to be high.
But the insurance companies will still want to mitigate the risk as much as possible, so they'll still dump compliance costs on the policy holders to try to mitigate the risk. And since the insurance is mandatory, they have no real incentive to minimize those costs or ensure that they achieve a worthwhile cost/benefit ratio. So mental health providers will have two new large operating costs imposed on them.
And the breaches will still happen, because most of the compliance requirements will be in the nature of having to install antivirus on your Linux servers and mandating passwords to be changed often enough that everybody writes them on a sticky note on the side of their monitor and the password reset mechanism becomes "easy to use" with the obvious implications of that.
This style of solution is common in healthcare in the US and is one of the reasons it's so expensive.