By Tyler Cobb, Business Risk Advisor, Tower Street Insurance
LinkedIn: Tyler Cobb
LinkedIn: Tower Street Insurance
Every health system onboards vendors constantly: digital health platforms, connected medical devices, diagnostic labs, revenue cycle tools, analytics companies. Somewhere in each purchase contract or master services agreement sits an insurance section, and somewhere in the onboarding checklist someone confirms a certificate of insurance was received. In most organizations, that is where the verification ends. It is also where most of the risk begins.
A certificate of insurance is a one-page summary issued as a convenience. It is not a policy, it confers no rights, and it says almost nothing about whether the endorsements behind it actually match what the contract requires. When a vendor incident occurs, whether a data breach, a device failure, or a service outage that disrupts patient care, the health system discovers what the vendor’s program really covers. By then the answer is already fixed.
Why This Matters More Than It Used To
Third-party risk has become a primary exposure pathway for provider organizations. Breaches involving business associates now account for a substantial share of the incidents reported to the U.S. Department of Health and Human Services Office for Civil Rights, which publishes them on its breach portal. At the same time, the vendors connecting to health system environments are increasingly early-stage companies: digital health startups, clinical-stage life sciences firms, and niche device manufacturers whose insurance programs were often purchased quickly to satisfy a contract rather than built to respond to a claim.
The contract usually says the right things. It requires commercial general liability at stated limits, technology errors and omissions, cyber liability, sometimes products liability for devices. It names the health system as an additional insured, requires primary and non-contributory coverage, and demands notice of cancellation. The gap is that each of those items lives at the endorsement level of the vendor’s policies, and a certificate can appear compliant while the endorsements underneath tell a different story.
Where Vendor Programs Quietly Fall Short
A few patterns arise across vendor claims:
- Additional insured status that is narrower than promised. Many policies grant additional insured status only for ongoing operations, or only where a written contract predates the loss. A device already installed or software already deployed can fall outside the grant entirely.
- Cyber policies that exclude what the contract assumed. Some vendor cyber policies exclude regulatory fines, contain sublimits for breach response far below the contract’s required limit, or exclude incidents traced to unsupported systems. If the vendor signed a business associate agreement under HIPAA, its obligations may exceed what its policy will fund.
- Claims-made coverage with no continuity plan. Technology errors and omissions and cyber policies are typically claims-made. If the vendor switches carriers, lets the policy lapse after the project ends, or is acquired, a claim reported later can fall outside every policy the certificate ever referenced.
- Indemnity that exceeds insurance. Vendors routinely agree to broad indemnification, then carry policies that respond only to their own negligence. The promise is bigger than the funding behind it, and an unfunded indemnity from a thinly capitalized startup is worth roughly the startup itself.
A Practical Verification Step for Onboarding
None of this requires health systems to become insurance experts. It requires adding one step between contract signature and go-live: request the actual endorsements, not just the certificate, for the handful of items the contract depends on. Confirm the additional insured endorsement covers completed operations and existing installations. Confirm the cyber limit and breach response sublimits against the contract requirement. Confirm primary and non-contributory wording exists as an endorsement rather than a certificate notation. Ask who is responsible for maintaining claims-made coverage after the relationship ends, and for how long.
Vendor contracting teams tend to answer these questions quickly when asked before signature, because the deal depends on it. The same questions asked after an incident get answered by coverage counsel, slowly, and usually not in the health system’s favor.
The certificate is the receipt. The endorsements are the coverage. Health systems that learn to ask for the second one will resolve vendor incidents with far fewer surprises, and the ones that keep filing certificates will keep discovering, one claim at a time, exactly what those certificates were worth.