Medical billing companies carry three insurance types that matter to physician-practice clients. Each covers a distinct category of risk.
1. Cyber-liability insurance
Cyber-liability, also called network security and privacy liability, covers the financial consequences of data breaches, ransomware, and other cyber incidents.
Standard coverage components:
- First-party costs: breach notification expenses, forensic investigation, legal counsel, credit monitoring for affected individuals, public relations, business interruption during system recovery
- Third-party costs: legal defense of claims by affected individuals or regulators, settlements and judgments
- Regulatory defense and fines: coverage for HHS OCR investigations, state attorney general actions, and PCI DSS enforcement (fine coverage varies by policy and state law)
- Ransomware and extortion: ransom payments (where legally permitted), extortion negotiator fees, restoration costs
- Business interruption: revenue loss during downtime from a covered incident
Industry norms:
- Per-incident limit: $1 million to $5 million
- Aggregate limit: typically 2x per-incident
- Deductibles: $10,000 to $100,000+ depending on vendor size
- Enterprise vendors serving major health systems: often $10 million+ per incident
Practice-side considerations:
- Confirm subcontractor incidents are covered (offshore coders, cloud infrastructure providers)
- Confirm HIPAA breach notification costs are explicitly covered
- Confirm whether regulatory fines are insurable (varies by state)
- Consider requesting additional-insured status
2. Professional liability (errors and omissions)
Professional liability, also called E&O or medical billing liability insurance, covers financial damages caused by professional mistakes in the vendor's work.
Standard coverage components:
- Coding errors: incorrect CPT, HCPCS, or ICD-10 codes that trigger payer clawback or denial
- Missed filing deadlines: claims not submitted within timely filing windows
- Payment misposting: EOB reconciliation errors, unposted refunds, incorrect adjustments
- Prior authorization failures: services rendered without required authorizations that the vendor was responsible for obtaining
- Incorrect fee schedule application: contracted rates not applied, resulting in under-collection or over-billing
- Administrative errors: missed follow-up on denials, expired secondary claim windows
Standard exclusions:
- Intentional acts or criminal conduct
- Prior known circumstances (issues known before the policy inception)
- Employment practice claims (handled by separate employment practices liability insurance)
- Bodily injury or property damage (handled by general commercial liability)
Industry norms:
- Per-incident limit: $1 million to $5 million
- Retroactive date: coverage should extend back to the beginning of the vendor's relationship with the practice, or the earliest applicable date
- Extended reporting period (tail coverage): important if the vendor's policy is claims-made rather than occurrence-based
3. General commercial liability
General commercial liability (CGL) covers standard business risks unrelated to professional services:
- Bodily injury on vendor premises
- Property damage caused by vendor operations
- Personal and advertising injury (defamation, copyright infringement)
- Products and completed operations
Industry norms:
- Per-occurrence limit: $1 million
- Aggregate limit: $2 million
CGL is standard for any operating business and is generally not a differentiator among medical billing vendors. It matters for practices that visit vendor offices or rely on vendors that come on-site.
Additional insurance to consider
Employment practices liability insurance (EPLI) covers claims by vendor employees against the vendor for discrimination, harassment, or wrongful termination. Not directly relevant to the practice but signals vendor operational maturity.
Directors and officers (D&O) insurance covers vendor executives for management decisions. Larger vendors carry this; smaller vendors often do not.
Employment identity theft coverage protects vendor employees from identity theft; often bundled with cyber-liability.
Fiduciary liability covers claims related to employee benefit plans. Not usually a factor.
Additional insured status
Additional insured status extends coverage under the vendor's insurance policy to defend and indemnify your practice for claims arising from the vendor's operations. Common in:
- General commercial liability: usually granted on request
- Professional liability: sometimes granted, depends on carrier
- Cyber-liability: increasingly available, especially for larger clients
Request additional insured status in writing during contract negotiation. Obtain a certificate of insurance showing the additional insured endorsement. Renew annually.
Certificate of insurance (COI)
A certificate of insurance is a one-page document showing:
- Insured entity (vendor name)
- Insurance carrier(s)
- Policy numbers
- Coverage types and limits
- Effective and expiration dates
- Additional insured status (if applicable)
- Certificate holder (your practice, if requested)
Request a fresh COI at contract signing and annually thereafter. The COI is evidence of coverage; the underlying policy is the enforceable document.
What insurance does not cover
- Intentional acts and criminal conduct by vendor personnel — coverage is void
- Prior known circumstances — issues known before policy inception are typically excluded
- War, terrorism, nuclear risks — standard exclusions in commercial policies
- Contractual liability beyond common law — contractual indemnification obligations may not be fully covered
Understand what the insurance does not cover as clearly as what it does cover.
Red flags in vendor insurance disclosures
- No cyber-liability insurance carried at all
- Cyber-liability limits below $1 million per incident
- Professional liability policy has a retroactive date after the vendor's founding (coverage gap)
- Policy is claims-made without extended reporting period option
- Vendor cannot produce a current COI on request
- Vendor refuses to add practice as additional insured or certificate holder
- Recent lapses in coverage visible on the COI
Practical verification steps
- Request current COI showing all three insurance types with limits and expiration dates
- Confirm cyber-liability covers HIPAA breach notification and regulatory defense
- Confirm professional liability covers coding errors, misposted payments, missed filing deadlines
- Request additional insured status where available
- Confirm subcontractor incidents are covered under vendor's cyber-liability
- Set an annual reminder to request a fresh COI
Bottom line
Three insurance categories — cyber-liability, professional liability, and general commercial liability — cover the vendor risk surface. Industry norms are $1M-$5M per incident across all three. Verify with a current certificate of insurance at signing and annually. Request additional insured status where available. Insurance is not a substitute for vendor vetting, but a vendor without adequate insurance is signaling something important about operational maturity.