The mental model
Healthcare is the industry where professional liability dominates the insurance program. A typical commercial insured sees professional liability as one specialty among many; a healthcare insured sees it as the foundation, with everything else organized around it. The reason is severity: a single med mal verdict in a sympathetic forum can run into eight or nine figures, and the average severity has climbed steadily for two decades. Healthcare programs are built to survive that severity.
The structural complexity comes from how healthcare is organized. A community hospital carries direct hospital professional liability and provides physician coverage through employment or credentialing. A multi-state health system carries the same coverages plus managed care E&O for any health plan operations, plus property at scale across hospitals, clinics, and outpatient facilities. A single-specialty physician group carries practice professional liability with carrier-specific endorsements for that specialty. A telehealth platform carries technology E&O combined with professional liability for the physicians delivering remote care across state lines. Each business model produces a different program shape. Layered on top of this: HIPAA-driven cyber exposure that is more consequential than in any other industry, EPL exposure in a workforce with elevated stress and turnover, and a regulatory environment (CMS, state medical boards, DEA, FDA, state insurance departments for managed care) that creates compliance overhead unique to healthcare.
Healthcare programs are claims-made programs with long tails. Med mal, hospital professional, managed care E&O, D&O, and cyber all run on claims-made forms. Tail coverage decisions, prior acts coverage, and retroactive dates accumulate into a program where coverage continuity is as important as current limits. A coverage gap can resurface as a denied claim a decade later.
The healthcare segment landscape
Healthcare is not one industry; it is a portfolio of segments with different risk profiles and different insurance needs.
Hospitals and health systems
The largest healthcare insureds. Acute care hospitals, academic medical centers, integrated health systems with multiple hospitals, employed physicians, and outpatient operations. Programs include hospital professional liability, employed physician med mal, GL, property, cyber, D&O, EPL, fiduciary, auto for ambulance and patient transport, and (increasingly) managed care E&O for system-owned health plans.
Physician groups and clinics
Independent and group physician practices, ambulatory surgery centers, specialty clinics, urgent care chains. Programs are physician-centered: practice professional liability for the physicians, supporting GL and property, plus cyber for HIPAA exposure. Single-specialty groups (radiology, anesthesiology, OB/GYN, neurosurgery) have specialty-specific underwriting.
Long-term care
Skilled nursing facilities, assisted living, memory care, continuing care retirement communities. The line is challenging because of staffing-driven liability, regulatory exposure, and recent litigation environments in several states. Some carriers have exited or restricted long-term care.
Allied health and ancillary providers
Home health agencies, physical therapy, dental practices, behavioral health, substance abuse treatment, pharmacy. Each has its own professional liability profile and operational risks.
Health plans and managed care
Insurance carriers, HMOs, PPOs, third-party administrators, pharmacy benefit managers, accountable care organizations, and the managed care arms of health systems. Managed care E&O is the foundational coverage; the line responds to claims arising from utilization management decisions, network adequacy, claim denials, and member services.
Healthcare technology
EHR vendors, telehealth platforms, digital health, medical device software, healthcare analytics, healthcare AI. Programs combine tech E&O with cyber and (depending on operations) some healthcare-specific liability coverage.
Pharmaceuticals and biotech
Distinct from the rest of healthcare. Products liability is the foundational line, with clinical trial liability, regulatory liability, and IP overlay. Programs differ enough that pharma is often analyzed as its own industry rather than part of healthcare.
Medical malpractice
Medical malpractice is the foundational professional liability line for healthcare. Covered in detail in Chapter 6; here is the healthcare program angle.
Coverage trigger and form
Almost universally claims-made. The retroactive date defines what work is covered; the extended reporting period extends the reporting window after policy expiration. Tail coverage at retirement, death, disability, or career transition is a major underwriting and pricing question for individual physicians and small practices.
Per-claim and aggregate limits
Limits are typically expressed as per-claim and annual aggregate. A common physician policy is $1M per claim and $3M annual aggregate. Hospital and large group programs run substantially higher, with primary limits frequently in the $1M-$5M range and excess layers stacking to $50M-$100M+ for major academic medical centers.
Specialty differentiation
Severity varies dramatically by specialty. OB/GYN, neurosurgery, orthopedic surgery, and emergency medicine carry the highest premiums. Family practice, internal medicine, and dermatology carry lower premiums. Underwriting reflects specialty-specific claim patterns and severity distributions.
Defense costs
The defense within limits vs outside limits question is critical in med mal. Many physician policies provide defense outside limits (defense doesn't erode the indemnity limit). Hospital policies and large group policies vary; some provide defense outside limits, others within. The structure significantly affects effective coverage on severity claims.
Hospital-employed vs independent physicians
The trend over the past two decades has been toward hospital employment of physicians. An employed physician is covered under the hospital's professional liability program; an independent physician is credentialed at the hospital but carries their own coverage. The shift to employment has consolidated severity into hospital programs and concentrated underwriting attention on the largest hospital systems.
State-level variation
Med mal premium varies enormously by state. Tort reform states (Texas, California with MICRA, Indiana with damages caps) have lower severity environments. Plaintiff-friendly states (Pennsylvania, Illinois, New York, Florida) have higher severity. State-level claim climate is a primary underwriting variable.
Hospital and corporate liability
Hospital professional liability is broader than physician med mal. It covers the hospital as an institution for claims arising from hospital operations.
Hospital professional liability scope
- Direct hospital negligence. Failure of hospital systems, equipment, or non-physician staff that contributes to patient harm. Nursing care, infection control, medication errors, fall prevention, equipment failure, environmental failures.
- Vicarious liability. The hospital's liability for the acts of employed physicians and (in some doctrines) credentialed physicians.
- Corporate negligence. Liability for credentialing decisions, peer review failures, and systemic operational decisions that contribute to harm.
- EMTALA exposure. Federal Emergency Medical Treatment and Active Labor Act exposure for emergency department screening and stabilization failures.
Captive and self-insurance
Many large hospital systems use captive insurance structures (Chapter 29) for primary med mal and hospital professional liability. The captive provides primary layers; commercial reinsurers and excess carriers provide layers above the captive's retention. The structure matches healthcare's combination of high frequency, manageable severity at the captive level, and tail-risk severity that requires commercial market capacity above.
Reinsurance
Healthcare reinsurance is a specialty market. Few reinsurers write large healthcare med mal layers; the ones that do (often London market) command pricing power and impose specific underwriting requirements. Recent severity escalation has made healthcare reinsurance a hard market.
Risk management and patient safety
Carriers underwrite hospital systems heavily on risk management infrastructure: peer review processes, root cause analysis programs, patient safety committees, claim trending and corrective action, JCAHO accreditation and other quality certifications. Strong risk management programs receive material premium credit.
Cyber and HIPAA
Healthcare faces the most consequential cyber exposure of any industry. The reasons: patient data is the highest-value data class on the dark market, healthcare operations cannot tolerate downtime, and HIPAA imposes statutory liability that other industries do not face.
Why healthcare cyber is distinct
- Operational dependency. A ransomware attack on a hospital can disable EHR systems, imaging systems, lab systems, medication dispensing systems, and operating room scheduling. Patients in active care are affected immediately.
- HIPAA enforcement. The HHS Office for Civil Rights actively enforces HIPAA breach notification and Privacy Rule violations, with civil monetary penalties scaling with severity.
- Class action exposure. Healthcare data breaches reliably generate class action litigation, with consolidated multidistrict litigation common for major incidents.
- State-level requirements. States have layered additional health-data privacy requirements (Texas HB 300, California's CCPA/CPRA, several state-specific mental health and substance abuse confidentiality requirements).
- Connected medical devices. The expanding fleet of connected medical devices creates attack surface that healthcare carriers underwrite as a separate exposure category.
Cyber program structure
Healthcare cyber programs are typically multi-tower with primary, excess, and (for large systems) reinsurance. Limits scale with patient record count and operational footprint. A 5-hospital system might carry $25M-$50M in cyber limits; a major academic medical center carries $100M+.
Coverage components
- First-party. Forensic investigation, notification costs, credit monitoring, business interruption, data restoration, ransomware payments (subject to OFAC compliance).
- Third-party. Patient class action defense and settlement, regulatory defense and penalties, media liability.
- Specific healthcare extensions. Some forms specifically address connected medical device attack, telehealth platform interruption, EHR vendor interruption.
Underwriting controls
Carriers underwrite healthcare cyber on a defined controls framework: MFA, EDR, immutable backups, network segmentation, privileged access management, incident response planning, third-party vendor risk management, employee security training. The 2020-2022 ransomware wave drove control requirements that effectively excluded carriers from underwriting any system that did not meet baseline controls.
Property and business interruption
Healthcare property has distinctive exposure characteristics that drive specialized underwriting.
Mission-critical occupancy
Hospitals operate continuously with patients who cannot easily be evacuated or transferred. Property loss prevention is engineered around this reality: dual electrical feeds, on-site generators sized for full operation, medical-grade gas and vacuum systems, water purification, redundant HVAC. Loss control engineering is more intensive than in almost any other property class.
Equipment values
Hospital equipment values are extraordinarily high. MRI scanners, CT scanners, linear accelerators for oncology, robotic surgical systems, cath lab equipment. Single equipment items can exceed $5M; a major academic medical center may carry $200M+ in equipment values. Boiler and machinery / equipment breakdown coverage is a meaningful component of healthcare property programs.
Business interruption
Healthcare BI is calculated differently than typical commercial BI. Hospital revenue is heavily insurance-billed; revenue per occupied bed-day, surgical case volume, and emergency department volume are the key metrics. BI calculations must account for payor mix and the time-pattern of revenue recovery as patients return to the facility.
Catastrophe exposure
Hospitals are concentrated in dense urban areas and serve catastrophe-affected populations. Hurricane, earthquake, flood, and wildfire exposure all matter. Healthcare carriers underwrite catastrophe accumulation carefully because hospital concentration in major metro areas means a single event can affect multiple insureds.
Property recovery patterns
Hospital property losses have unusual recovery patterns. Equipment replacement requires regulatory approval (state DOH, Certificate of Need in some states, FDA for certain devices). Construction in operating hospitals requires infection control and patient-flow management that extends recovery timeframes. BI periods of 24-36 months are not unusual for major events.
D&O, EPLI, and fiduciary
The management liability stack carries healthcare-specific dimensions that distinguish it from generic D&O, EPL, and fiduciary.
Healthcare D&O
- Antitrust exposure. Healthcare consolidation, hospital-physician affiliations, and managed care contracting all generate antitrust scrutiny. Federal and state antitrust enforcement against healthcare entities is sustained and well-resourced.
- Stark and Anti-Kickback. Federal physician self-referral and anti-kickback statutes create regulatory and qui tam exposure that flows into D&O coverage.
- False Claims Act. Healthcare is the largest source of False Claims Act recoveries by industry. Whistleblower-driven qui tam actions against healthcare entities for billing fraud, kickbacks, and quality misrepresentation generate sustained D&O exposure.
- Tax-exempt status. Many hospitals operate as tax-exempt 501(c)(3) entities, with D&O implications around community benefit, charity care, and tax-exempt-specific governance obligations.
Healthcare EPLI
- High-friction workforce. Healthcare workforces include physicians, nurses, technicians, and support staff with substantial wage and hour issues, classification disputes, and discrimination exposure.
- Physician-specific employment claims. Wrongful termination of credentialed physicians, peer review confidentiality issues, employment disputes around productivity-based compensation.
- Patient harassment claims. Patient-reported harassment by employees, with statutory and licensing-board overlay distinct from generic EPL exposure.
- Mandatory vaccination disputes. COVID-era disputes around mandatory vaccination policies generated specific EPL claim categories that persist.
Healthcare fiduciary
Hospital systems sponsor large benefit plans (defined benefit pension plans for legacy systems, defined contribution plans for current employees, retiree health plans for many). ERISA fiduciary exposure for plan administration is consequential, particularly for legacy defined-benefit plans with funding adequacy issues. Multiemployer plan exposure exists for unionized hospital systems participating in multiemployer pension plans.
Managed care, telehealth, and emerging exposures
Three areas of healthcare insurance that have evolved substantially in recent years and continue to evolve.
Managed care E&O
Health plans, HMOs, PPOs, MCOs, and the managed care arms of integrated systems carry managed care E&O. The line responds to claims arising from utilization management, claim denials, network adequacy, member services, prior authorization decisions, and (increasingly) algorithmic decision-making in claims processing.
- Utilization management exposure. Denials of coverage based on medical necessity determinations have generated sustained class action exposure, with several large settlements and ongoing regulatory scrutiny.
- Network adequacy. Claims arising from network inadequacy in narrow-network and Medicare Advantage products. State and federal regulators have increased network adequacy requirements.
- Algorithmic decisions. The use of AI and algorithmic tools in coverage decisions has generated specific litigation, including class actions challenging automated denials. The exposure category is rapidly evolving.
Telehealth
Telehealth exposure expanded dramatically post-COVID and has remained elevated. Coverage questions:
- Cross-state licensing. Physicians delivering telehealth across state lines must be licensed in the patient's state. The Interstate Medical Licensure Compact has streamlined this for member states; non-member states still require individual licensure.
- Standard of care for remote diagnosis. Underdeveloped case law around the standard of care for telehealth-only diagnosis. Carriers underwrite the standard of care question carefully.
- Platform liability. Telehealth platforms (often technology companies, not insurance-licensed entities) face combined tech E&O and professional liability exposure that is structurally novel.
Emerging exposures
- AI-assisted clinical decision making. Diagnostic AI, clinical decision support, AI-assisted radiology and pathology. The standard of care implications and liability allocation between physicians, hospitals, and AI vendors are unsettled.
- Genetic information and privacy. Genetic data privacy under GINA and state-level genetic privacy laws creates exposure categories that overlap with cyber and managed care.
- Reproductive healthcare post-Dobbs. State-by-state variation in reproductive healthcare regulation has created specific exposures for providers operating across state lines or providing care that may be legal in one state and prohibited in another.
- Behavioral health expansion. Expansion of behavioral health services has generated capacity issues, with workforce shortages, virtual care quality concerns, and parity-related coverage disputes.
Where IDP earns its keep
Healthcare submission processing and claim handling generate large document volumes with consistent structures within each segment. Hospital programs run to thousands of pages including credentialing files, claim files, peer review documentation, and quality reports. Physician group submissions include credential lists, claim history per physician, and specialty-specific underwriting questions. Cyber submissions include detailed control assessments and HIPAA program documentation.
Healthcare is heavy on document-rich underwriting. Physician credentialing and roster processing across thousands of providers in major systems. Med mal claim history extraction with physician-level loss attribution. HIPAA breach notification documentation. Hospital quality and patient safety report processing for risk management credits. Cyber control attestation review against carrier-required frameworks. Peer review documentation for credentialing decisions. Long-term care state survey extraction for jurisdictional compliance review. Managed care utilization management documentation for class action defense. The healthcare segment also has heavy claim-side document volumes: medical record review, expert witness reports, billing records, deposition transcripts, settlement documentation.