FOR BUSINESSES WITH $10M+ IN ANNUAL REVENUE
Insurance for established healthcare groups and service businesses
An established healthcare group should coordinate clinical professional liability, premises and general liability, cyber, employment practices, property, and any technology E&O without treating them as interchangeable. The review must map each location, entity, provider, contractor, patient-data flow, claims-made date, and critical system. Insurance can support a risk program but does not satisfy HIPAA or other legal obligations.
Who this page is for
Physician and dental groups, home-health agencies, med-spas, and other healthcare service businesses can combine clinical care, premises, employees, contractors, patient information, billing, and patient-facing technology across many locations. A program review should separate clinical professional liability from business liability and technology E&O, then coordinate their entities, dates, and limits.
This page does not claim a medical malpractice program. Whether OnePark Risk can arrange clinical professional liability for a particular group is confirmed during the conversation; the discussion here concerns how the clinical policy should coordinate with the rest of the program.
Discuss your healthcare services program with a senior broker
Start with a conversation. No application or documents required.
Share five contact details and, if you like, a little context about revenue band, main operating state, and what you want to discuss. A member of the OnePark Risk team contacts you to arrange the next conversation. There is no application, no document upload, and no obligation.
No insurance application or document upload required.
Which policy addresses clinical, business, and technology allegations?
Clinical professional liability, often called medical malpractice, addresses defined allegations arising from professional healthcare services, subject to the form. General liability addresses covered premises and operations injury but commonly excludes professional services. Technology E&O addresses defined technology products or services, such as a telehealth platform or patient-facing software, and should not be assumed to cover clinicians' diagnosis or treatment.
A multi-service group should classify each activity rather than choose one broad label. A physician visit, dental procedure, home-health visit, med-spa treatment, scheduling application, and leased-office incident can implicate different policies. Contracts and patient communications should describe who delivers the service and which entity is responsible. More limit on one policy does not extend its definition into another category.
This page does not claim a medical malpractice program. Whether OnePark Risk can arrange clinical professional liability for a particular group is confirmed during the conversation; the discussion here concerns how the clinical policy should coordinate with the rest of the program. Specialty capability and market availability cannot be inferred from serving healthcare businesses.
How should providers joining or leaving the group be handled?
Clinical professional liability may be written with individual provider limits, an entity limit, or another structure. The review should identify every employed and contracted provider, specialty, license state, work location, services, schedule, and entity through which care is delivered. A provider policy does not automatically protect the practice entity, and an entity policy does not automatically include every clinician.
Many clinical professional liability forms are claims-made, meaning coverage depends on when the claim is made and reported and whether the service occurred after the applicable retroactive date. When a provider joins, prior acts must be allocated between earlier coverage and the group's policy. When a provider leaves, an extended reporting period, commonly called a tail, or continuing coverage may be needed for later claims arising from earlier services.
Provider contracts should allocate responsibility for maintaining coverage, limits, tail cost, incident reporting, cooperation, and outside work. Employed and contracted status can affect insured status but does not settle it; the policy definition controls. Acquisitions require review of prior entities, services, known incidents, and run-off arrangements before policy periods are changed.
What changes across locations and provider models?
The schedule should map each clinic, dental office, administrative site, storage location, and patient home-service territory to the operating entity, providers, employees, equipment, and lease. Premises liability, property values, business income, medical equipment, tenant improvements, and landlord requirements vary by site. Mobile equipment and supplies may require coverage away from a scheduled location.
Home-health agencies and groups using contracted clinicians should distinguish employees from independent contractors with qualified legal advice. Workers' compensation is statutory and depends on applicable state law, payroll, and classifications; it is not a $3M, $5M, or $10M package. General liability, hired and non-owned auto, abuse or misconduct exclusions, and professional services each require separate attention based on operations.
Employment practices exposure grows across locations because hiring, supervision, accommodations, discipline, scheduling, and termination may be handled by different managers. The review should examine insured entities, employees, third-party allegations, defense and settlement terms, retentions, exclusions, and acquisitions. Insurance does not replace consistent human-resources practices or state-specific legal advice.
Does cyber insurance satisfy HIPAA obligations?
No. The Health Insurance Portability and Accountability Act privacy and security requirements create legal obligations for covered entities and, where applicable, business associates. Insurance does not establish compliance, satisfy required safeguards, or replace agreements and procedures. The organization should confirm its status and duties using current U.S. Department of Health and Human Services guidance and qualified counsel.
The insurance review maps protected health information and other sensitive data from collection through storage, access, sharing, retention, and disposal. It should identify electronic health records, imaging, billing, laboratories, pharmacies, telehealth, portals, mobile devices, vendors, and paper records. The cyber form can then be reviewed for defined privacy and security events, incident response, notification, regulatory proceedings where insurable, restoration, and exclusions.
Business associate agreements and vendor contracts can impose security, notification, cooperation, indemnity, and insurance duties. Those obligations may be broader than policy coverage. A breach-notification obligation can depend on law and facts even when an insurer disputes coverage, so incident plans should route decisions to privacy counsel and operational leaders rather than waiting for an insurance conclusion.
How do system outages and regulatory matters fit?
An electronic health record, scheduling, billing, telehealth, identity, or communications outage can stop care and revenue across locations. The review should estimate lost income, extra staffing, patient rescheduling, data reconstruction, downtime procedures, and vendor dependency. Cyber business interruption may require a defined event, waiting period, and restoration period; a dependent-system event can carry a separate sublimit.
A patient-facing software company or a group that sells technology to others may have technology E&O exposure beyond ordinary use of a vendor platform. The insured-services definition should specify the software or platform delivered and distinguish technical failure allegations from clinical judgment. Cyber and technology E&O may share an annual aggregate, so the review should not assume each coverage part supplies a separate headline limit.
Billing, coding, licensing, credentialing, reimbursement, and other regulatory matters are often excluded, restricted, or sublimited in liability forms. Government investigations, repayment demands, penalties, and defense may not fit clinical malpractice, general liability, or D&O as expected. The review should identify applicable exclusions and separate legal compliance from insurable response without implying that every regulatory exposure can be covered.
What should a coordinated healthcare review produce?
The exposure summary should connect parent and operating entities to locations, clinical services, provider rosters, employment or contractor status, license states, retroactive dates, leases, equipment, patient-data systems, vendors, vehicles, billing activity, and acquisitions. It should identify which entity contracts with patients, payors, landlords, vendors, and technology customers and preserve uncertainty for counsel to resolve.
The policy comparison should show clinical provider and entity structure, per-claim limits, annual aggregates, tails or prior acts, general liability, property and business income, cyber, employment practices, technology E&O, exclusions, sublimits, retentions, and defense treatment. A casualty umbrella should not be assumed to extend clinical professional liability, cyber, technology E&O, or property.
$10M in annual revenue does not mean $10M of every coverage. Revenue describes the size of the business; each policy limit has to be evaluated against the contracts, loss scenarios, and policy wording that apply to that coverage.
Hypothetical scenario: Hypothetical multi-location healthcare group review
Consider a hypothetical healthcare group with $42M in annual revenue, several physician and dental locations, a home-health affiliate, contracted providers, and a patient scheduling and telehealth portal. The review would map clinical providers and entities, retroactive dates and tail responsibilities, premises and employment exposures, patient-information vendors, and a multi-location electronic-health-record outage. It would distinguish clinical allegations from a technology failure and examine whether cyber and technology E&O share an annual aggregate. Billing and licensing exclusions would be identified for counsel and management. This illustration frames coordination questions and does not assume clinical placement capability, policy response, or a claim outcome.
What your senior broker should examine
- Which entities and providers deliver each clinical service, at which locations and under which contracts?
- Are provider and entity limits coordinated, and do retroactive dates and tail arrangements address joining and departing clinicians?
- How are employed and contracted providers treated under clinical, general liability, workers' compensation, and employment policies?
- Where does patient information travel, and which vendors, business associate agreements, and incident duties apply?
- What would an electronic-health-record, scheduling, billing, or telehealth outage cost across locations?
- Which billing, licensing, credentialing, reimbursement, or regulatory matters are excluded or sublimited?
Questions businesses ask
Does this page mean OnePark Risk offers medical malpractice insurance?
No. It does not claim a medical malpractice program or specialty placement capability. Whether clinical professional liability can be arranged for a particular group is confirmed during the conversation; this page explains how that policy should coordinate with the business program.
What is the difference between provider and entity malpractice coverage?
Provider coverage addresses an insured clinician under its terms, while entity coverage addresses the insured organization and its defined professional exposure. A group should verify both structures, shared or separate aggregates, employed and contracted providers, and who funds tail coverage.
Does cyber insurance make a healthcare group HIPAA compliant?
No. HIPAA creates legal privacy and security obligations that insurance does not satisfy. Cyber coverage can respond to defined events and expenses under its terms, while compliance requires operational, technical, contractual, and legal work.
Is telehealth exposure always medical malpractice?
No. Clinical diagnosis or treatment can create clinical professional liability, while failure of a platform sold or operated for others can create technology E&O exposure. The service, contracting entity, users, and policy definitions determine the analysis.
Sources
- U.S. Department of Health and Human Services: The Security Rule — accessed 2026-09-19; supports the statement that HIPAA security obligations are legal and operational duties rather than insurance coverage.
- U.S. Department of Health and Human Services: The Privacy Rule — accessed 2026-09-19; supports the discussion of privacy obligations for covered entities and applicable business associates.
- U.S. Department of Health and Human Services: Breach Notification Rule — accessed 2026-09-19; supports the statement that breach-notification duties arise from law and facts rather than an insurer's coverage decision.
Educational content for businesses evaluating a senior broker engagement. It is not a quote, a coverage recommendation, or a representation that any limit, carrier, or program is available to a particular business. Coverage is subject to policy terms and placement availability. OnePark Risk is a P&C broker licensed in NY, CA, DE, MA, PA, NJ, NV, FL, and VA.