In brief
A healthcare professional or clinic reviewing professional indemnity / medical malpractice cover should consider:
- the exact professional services and procedures performed;
- the doctors and other practitioners who need to be insured;
- whether the cover is individual, practice-based or both;
- limits, deductibles and defence-cost treatment;
- claims-made wording and retroactive dates where applicable;
- previous claims and circumstances;
- higher-risk procedures or specialisms;
- patient records, privacy and cyber exposure;
- clinic ownership and contractual arrangements;
- locums, contractors and other practitioners; and
- whether the wider practice also needs cyber, office, public-liability, D&O or employment-related protection.
Medical malpractice should therefore be reviewed as a professional-risk programme, not simply as a certificate held by an individual doctor.
Professional indemnity in medicine protects both sides of the relationship
The Medical Council of Hong Kong describes professional indemnity insurance as protection for both the patient and the doctor against whom medical-negligence claims are made. Its Code of Professional Conduct states that professional indemnity insurance is not a mandatory requirement for every doctor, but that a doctor should seriously assess the risks of their practice, their ability to meet potential compensation and legal costs, and obtain proper cover where appropriate. That distinction is important. The article should not claim that every Hong Kong doctor is legally required to purchase the same form of PI. The appropriate arrangement depends on the professional setting, employer or hospital arrangements, medical defence membership, contractual requirements and the doctor’s own practice.
Start with the actual scope of practice
Healthcare risk varies materially by specialty and procedure. A primary-care clinic, psychologist, physiotherapist, surgeon, diagnostic provider and day-procedure centre do not create the same exposure. Underwriters may consider matters such as:
- specialty;
- procedures performed;
- surgical or invasive work;
- anaesthesia or sedation;
- annual patient numbers;
- claims history;
- practitioner qualifications;
- consent procedures;
- record keeping;
- staff and supervision; and
- the regulatory setting in which services are delivered.
The policy description therefore needs to match what the practitioner or clinic actually does.
Individual doctor cover and practice exposure are not always the same
A clinic can create exposures beyond an individual doctor’s clinical negligence. The legal entity may employ or contract practitioners, hold leases, process patient data, employ administrative staff, advertise services and manage facilities. Depending on its structure, the wider insurance discussion may therefore include:
- entity professional indemnity;
- public liability;
- office/property cover;
- cyber/privacy insurance;
- employees’ compensation;
- management liability; and
- crime/fidelity where relevant.
This is why a growing clinic should not assume that an individual’s indemnity arrangement protects every exposure of the operating company.
Claims-made wording and continuity
Where professional indemnity is written on a claims-made basis, continuity and notification are important. A treatment may have been provided several years earlier but the allegation may arise later. When changing insurer or indemnity arrangement, review:
- retroactive date;
- prior-acts treatment;
- known-circumstance provisions;
- notification requirements; and
- run-off considerations when a practitioner retires, sells or closes a practice.
The exact structure varies, so historic work should be considered before an existing arrangement is cancelled.
What we see in practice
A healthcare business can grow incrementally. A sole practitioner takes a second room. Another doctor joins. The clinic introduces a new procedure. Patient data moves to a cloud practice-management system. A corporate entity signs the lease and employs staff. Each change may look small, but together they can create a very different risk from the one originally presented to the insurer. The annual review should therefore ask not only “any claims?” but “what is different about the practice?”
Patient data creates cyber exposure as well as professional exposure
Healthcare businesses hold particularly sensitive personal and medical information. A cyber incident can create forensic, privacy, interruption and notification issues even where no allegation of clinical negligence exists. A technology failure can also affect appointment systems, patient records or the delivery of services. Healthcare practices should therefore consider how professional indemnity and cyber insurance interact rather than assuming one policy covers every data-related event.
Choosing a limit
The appropriate professional-indemnity limit depends on the risk profile and any professional, contractual or facility requirements that apply. Relevant factors can include:
- specialty and procedure severity;
- patient volume;
- potential injury severity;
- practice structure;
- number of practitioners;
- previous claims;
- contractual requirements; and
- whether defence costs erode the limit.
The correct limit should be reviewed in the context of the practice rather than selected because it is the market default.
A practical healthcare-practice checklist
Review:
- Services – whether the policy accurately describes current procedures and specialties.
- Insureds – whether the entity, doctors, locums and relevant practitioners are treated correctly.
- Claims-made terms – retroactive dates and notification provisions.
- Limits – whether limits and defence-cost arrangements are proportionate.
- Claims – complaints or circumstances that may need notification.
- Operations – clinic expansion, relocation or new services.
- Data – patient-record protection and where cyber cover sits.
- Other covers – whether the operating company also needs public liability, office, Employees Compensation, D&O or crime protection.
The Trusted Union perspective: insure the practice that exists today
Healthcare professionals rightly focus on the clinical side of their work. The insurance review needs to translate that clinical reality into an accurate description of services, practitioners, procedures, entities and operational controls. For a growing clinic, that can mean connecting professional indemnity with cyber, premises and wider business protection rather than maintaining several disconnected arrangements. The purpose is not to create more insurance for its own sake. It is to understand where the professional and operating risks actually sit.
Professional cover should reflect the practice as it operates today.
Trusted Union helps healthcare professionals and practices review professional-indemnity and related business risks with clearer context around services, practitioners, claims and policy structure.
Explore Professional Indemnity
