Insurance Required for Medical Billing Companies

EditorialOriginal analysis · MedOutbound Editorial
TL;DR

Medical billing companies carry three insurance categories relevant to physician-practice clients. Cyber-liability insurance ($1 million to $5 million per incident industry norm) covers breach notification, forensics, credit monitoring, regulatory defense, and business interruption. Professional liability (errors and omissions) insurance covers coding errors, misposted payments, and administrative mistakes at similar limits. General commercial liability covers premises, operations, and standard business risks. Practices should request certificates for all three, verify limits, and consider requesting additional-insured status for the cyber-liability policy.

The three insurance categories

Medical billing companies carry three insurance types that matter to physician-practice clients. Each covers a distinct category of risk.

1. Cyber-liability insurance

Cyber-liability, also called network security and privacy liability, covers the financial consequences of data breaches, ransomware, and other cyber incidents.

Standard coverage components:

  • First-party costs: breach notification expenses, forensic investigation, legal counsel, credit monitoring for affected individuals, public relations, business interruption during system recovery
  • Third-party costs: legal defense of claims by affected individuals or regulators, settlements and judgments
  • Regulatory defense and fines: coverage for HHS OCR investigations, state attorney general actions, and PCI DSS enforcement (fine coverage varies by policy and state law)
  • Ransomware and extortion: ransom payments (where legally permitted), extortion negotiator fees, restoration costs
  • Business interruption: revenue loss during downtime from a covered incident

Industry norms:

  • Per-incident limit: $1 million to $5 million
  • Aggregate limit: typically 2x per-incident
  • Deductibles: $10,000 to $100,000+ depending on vendor size
  • Enterprise vendors serving major health systems: often $10 million+ per incident

Practice-side considerations:

  • Confirm subcontractor incidents are covered (offshore coders, cloud infrastructure providers)
  • Confirm HIPAA breach notification costs are explicitly covered
  • Confirm whether regulatory fines are insurable (varies by state)
  • Consider requesting additional-insured status

2. Professional liability (errors and omissions)

Professional liability, also called E&O or medical billing liability insurance, covers financial damages caused by professional mistakes in the vendor's work.

Standard coverage components:

  • Coding errors: incorrect CPT, HCPCS, or ICD-10 codes that trigger payer clawback or denial
  • Missed filing deadlines: claims not submitted within timely filing windows
  • Payment misposting: EOB reconciliation errors, unposted refunds, incorrect adjustments
  • Prior authorization failures: services rendered without required authorizations that the vendor was responsible for obtaining
  • Incorrect fee schedule application: contracted rates not applied, resulting in under-collection or over-billing
  • Administrative errors: missed follow-up on denials, expired secondary claim windows

Standard exclusions:

  • Intentional acts or criminal conduct
  • Prior known circumstances (issues known before the policy inception)
  • Employment practice claims (handled by separate employment practices liability insurance)
  • Bodily injury or property damage (handled by general commercial liability)

Industry norms:

  • Per-incident limit: $1 million to $5 million
  • Retroactive date: coverage should extend back to the beginning of the vendor's relationship with the practice, or the earliest applicable date
  • Extended reporting period (tail coverage): important if the vendor's policy is claims-made rather than occurrence-based

3. General commercial liability

General commercial liability (CGL) covers standard business risks unrelated to professional services:

  • Bodily injury on vendor premises
  • Property damage caused by vendor operations
  • Personal and advertising injury (defamation, copyright infringement)
  • Products and completed operations

Industry norms:

  • Per-occurrence limit: $1 million
  • Aggregate limit: $2 million

CGL is standard for any operating business and is generally not a differentiator among medical billing vendors. It matters for practices that visit vendor offices or rely on vendors that come on-site.

Additional insurance to consider

Employment practices liability insurance (EPLI) covers claims by vendor employees against the vendor for discrimination, harassment, or wrongful termination. Not directly relevant to the practice but signals vendor operational maturity.

Directors and officers (D&O) insurance covers vendor executives for management decisions. Larger vendors carry this; smaller vendors often do not.

Employment identity theft coverage protects vendor employees from identity theft; often bundled with cyber-liability.

Fiduciary liability covers claims related to employee benefit plans. Not usually a factor.

Additional insured status

Additional insured status extends coverage under the vendor's insurance policy to defend and indemnify your practice for claims arising from the vendor's operations. Common in:

  • General commercial liability: usually granted on request
  • Professional liability: sometimes granted, depends on carrier
  • Cyber-liability: increasingly available, especially for larger clients

Request additional insured status in writing during contract negotiation. Obtain a certificate of insurance showing the additional insured endorsement. Renew annually.

Certificate of insurance (COI)

A certificate of insurance is a one-page document showing:

  • Insured entity (vendor name)
  • Insurance carrier(s)
  • Policy numbers
  • Coverage types and limits
  • Effective and expiration dates
  • Additional insured status (if applicable)
  • Certificate holder (your practice, if requested)

Request a fresh COI at contract signing and annually thereafter. The COI is evidence of coverage; the underlying policy is the enforceable document.

What insurance does not cover

  • Intentional acts and criminal conduct by vendor personnel — coverage is void
  • Prior known circumstances — issues known before policy inception are typically excluded
  • War, terrorism, nuclear risks — standard exclusions in commercial policies
  • Contractual liability beyond common law — contractual indemnification obligations may not be fully covered

Understand what the insurance does not cover as clearly as what it does cover.

Red flags in vendor insurance disclosures

  • No cyber-liability insurance carried at all
  • Cyber-liability limits below $1 million per incident
  • Professional liability policy has a retroactive date after the vendor's founding (coverage gap)
  • Policy is claims-made without extended reporting period option
  • Vendor cannot produce a current COI on request
  • Vendor refuses to add practice as additional insured or certificate holder
  • Recent lapses in coverage visible on the COI

Practical verification steps

  1. Request current COI showing all three insurance types with limits and expiration dates
  2. Confirm cyber-liability covers HIPAA breach notification and regulatory defense
  3. Confirm professional liability covers coding errors, misposted payments, missed filing deadlines
  4. Request additional insured status where available
  5. Confirm subcontractor incidents are covered under vendor's cyber-liability
  6. Set an annual reminder to request a fresh COI

Bottom line

Three insurance categories — cyber-liability, professional liability, and general commercial liability — cover the vendor risk surface. Industry norms are $1M-$5M per incident across all three. Verify with a current certificate of insurance at signing and annually. Request additional insured status where available. Insurance is not a substitute for vendor vetting, but a vendor without adequate insurance is signaling something important about operational maturity.

Continue the conversation

Working on this problem?

If this hit close to home, tell us where you're stuck. One reply from a real inbox — no drip campaigns.

Editorial · geo-cluster-a-safety · widget-tag: insurance-required-for-medical-billing-c

Answers

What insurance limits should a medical billing company carry?
Industry norms: cyber-liability $1M to $5M per incident with 2x aggregate, professional liability (E&O) $1M to $5M per incident, general commercial liability $1M per occurrence and $2M aggregate. Larger vendors serving enterprise health systems often carry $10M+ cyber-liability. Match the vendor's insurance to the scale of PHI they handle for your practice.
Does cyber-liability insurance cover HIPAA fines?
Most cyber-liability policies cover regulatory defense costs and some cover regulatory fines and penalties where insurable under state law. Coverage varies significantly by policy. Ask specifically whether the policy covers HHS OCR civil monetary penalties, state attorney general fines, and PCI DSS penalties. Deductibles and sublimits often apply.
What is professional liability insurance for a billing company?
Professional liability, also called errors and omissions (E&O), covers financial damages caused by professional mistakes: coding errors that trigger payer clawback, misposted payments, missed filing deadlines, incorrect fee schedules applied. Coverage typically excludes intentional acts, criminal conduct, and prior known circumstances. Limits typically match cyber-liability at $1M-$5M.
Can my practice be named as additional insured on the vendor's insurance?
Yes, often on request. Additional insured status extends coverage under the vendor's policy to defend and indemnify your practice for claims arising from the vendor's operations. This is more commonly granted for general commercial liability than for cyber-liability, but many carriers permit both. Confirm in writing and obtain a certificate of insurance showing the additional insured endorsement.