Skip to Main Content

August 25, 2026

The insurance blind spots in digital health

Why the MSO/PC model creates coverage complexity

The Management Services Organization/Professional Corporation (MSO/PC) model is a structural backbone of modern digital health. Born out of corporate practice of medicine laws that require physician-owned entities to deliver actual medical care, the model splits a digital health company into two interdependent parts: an MSO that owns the technology platform, employs business staff, and manages operations, and one or more PCs that house the licensed providers who treat patients.¹

It’s an elegant legal solution. It’s also an insurance challenge, and many brokers encounter complexity in this structure every day.

Why the MSO/PC structure creates unique insurance risk

In a traditional business, one entity generates one set of exposures, and one insurance program can cover them. The MSO/PC model changes that logic. You now have two or more legally distinct entities whose operations are closely intertwined. The MSO’s technology platform delivers patients to the PC’s providers. The PC’s clinical decisions generate data that flows through the MSO’s systems. A single patient interaction can implicate medical professional liability, technology errors and omissions, and cyber/privacy exposure simultaneously across both entities.

When a claim arises in this environment, the question isn’t just “What happened?” It’s also “Which entity is responsible, which policy responds, and do they coordinate effectively?” For companies insured under fragmented programs, the answer to that last question is often no.

The seven pitfalls in MSO/PC coverage

1. No coverage continuity between the MSO and the PC
This is a foundational issue. Some brokers insure the MSO and the PC as if they were independent businesses rather than two halves of one operation. The MSO gets a tech E&O and cyber policy. The PC gets a medical professional liability policy. Neither policy is written with awareness of the other, and neither is designed to respond when a claim crosses the boundary between clinical care and technology. In digital health, that’s often where the risk lives.

The result can be a structural gap at the exact point where coverage matters most: the intersection of medical and technology risk.

2. Splitting med mal from tech E&O and cyber
This is one of the most common mistakes in digital health placements. It often feels intuitive: medical professional liability for the doctors, tech and cyber coverage for the platform. Two different risk categories, two different policies, often two different carriers.

The problem is that digital health doesn’t always work that way. A telehealth visit can involve a patient connecting through a technology platform, being triaged by algorithms or intake software, consulting with a provider via video or asynchronous messaging, receiving a diagnosis, and potentially getting a prescription managed through the platform. If something goes wrong — a misdiagnosis, a platform failure that delays care, or a data breach that exposes patient records — the incident may not fit neatly into one coverage bucket. It can trigger multiple lines simultaneously.

When those lines are split across carriers, coverage questions can arise. Was the adverse outcome a clinical error (med mal) or a technology failure (tech E&O)? Was the data breach a cyber event or the result of clinical recordkeeping failures? Each carrier may view the facts differently. The company can end up paying multiple deductibles, hiring coverage counsel, and discovering that coverage is contested.

3. Standalone med mal policies with technology and cyber exclusions
Standalone medical professional liability policies, the kind written for traditional physician practices, often contain exclusions for technology-related acts or cyber events. Those exclusions can make sense in a world where doctors practice in brick-and-mortar offices. They are less workable for a digital health company where every clinical encounter is delivered through technology.

If a provider misdiagnoses a patient because a platform glitch corrupted the patient’s uploaded imaging, a standalone med mal policy may not respond the way the company expects if the policy wording treats the issue as a technology failure rather than a clinical judgment error. The company can be left without responsive coverage for the exact scenario its business model creates.

4. Standalone tech E&O and cyber policies with medical professional liability limitations
The mirror image of the previous pitfall can also occur. Technology E&O carriers are often reluctant to cover claims involving bodily injury. Cyber carriers exclude bodily injury from their policies. So if a cyberattack takes down a telehealth platform during a patient consultation, and the patient suffers harm because care was delayed or disrupted, the tech/cyber policy may not address the bodily injury component, while the med mal policy may not address the technology/cyber component.

This isn’t just a theoretical concern. As the digital health claims landscape matures, incidents increasingly sit at this intersection. According to CFC Underwriting’s Digital Healthcare Report 2025, roughly two-thirds of digital health claims in its dataset stem from sources beyond traditional medical malpractice, including cyber events, technology failures, IP disputes, and regulatory actions.² A piecemeal insurance program isn’t always designed to handle that mix of exposures.

5. Core business exclusions that can limit the policy
This is one of the most important issues because it often goes undetected until a claim is filed. We regularly encounter policies, both on the med mal side and the tech E&O/cyber side, that contain exclusions affecting the company’s core business operations.

For example, a tech E&O policy for a digital therapeutics company might exclude claims arising from “the provision of medical advice or treatment,” which is central to the company’s operations. A med mal policy might exclude claims arising from “software-as-a-medical-device” or “algorithm-driven clinical decision support,” which is also central to the company’s offering. These exclusions sometimes appear in base policy forms that weren’t designed for digital health, and a broker can overlook them unless the policy wording is reviewed carefully.

The company may pay a premium for a policy that doesn’t respond to claims related to what the company actually does.

6. Incomplete entity listing across policies
The MSO/PC model often involves multiple entities: the parent MSO, one or more PCs (sometimes in different states due to varying corporate practice of medicine laws), affiliated entities, and subsidiary operations. Every entity that faces potential liability exposure should be listed as a named insured or additional insured on every relevant policy.

This can be overlooked. The MSO may be listed on the tech/cyber policy but not all PCs. The “flagship” PC may be listed on the med mal policy, but newer PCs formed in expansion states are omitted. When a claim arises against an unlisted entity, the carrier may have grounds to contest coverage. This is a manageable issue, but only if the broker fully understands the corporate structure being insured.

7. One workers’ compensation policy when the MSO and PC may need separate policies
This operational issue often flies under the radar. Because the MSO and PC are legally separate entities with different employee populations — the MSO employing technology, business, and administrative staff, and the PC employing or contracting licensed healthcare providers — they may require separate workers’ compensation policies.

When a broker places a single workers’ comp policy covering both entities, several issues can arise. The employee classification codes and rates are different for technology workers versus healthcare providers, which can complicate the annual premium audit and lead to unexpected additional premium charges. The MSO may end up subsidizing the PC’s higher-risk classification, or vice versa. And in some states, combining entities with fundamentally different risk profiles on a single policy can create regulatory issues or compliance gaps.

A bundled, coordinated coverage approach from a specialist carrier

Every one of these pitfalls traces back to the same root cause: treating a digital health company’s insurance needs as a collection of independent coverage lines rather than an integrated program designed around how the business actually operates.

One option is a bundled medical professional liability, technology E&O, and cyber/privacy policy, placed with a carrier that understands the MSO/PC model and underwrites it as a unified risk. This approach can offer several important advantages.

Coverage coordination at the point of a claim. When a single incident triggers medical, technology, and cyber exposure simultaneously, there’s one carrier, one policy form, one deductible, and one claims team. That can reduce finger-pointing between carriers and help avoid coverage gaps at the boundaries between lines.

Economies of scale in pricing. A bundled program can reduce redundant underwriting, overlapping coverage charges, and administrative overhead associated with maintaining multiple separate policies with multiple separate carriers.

Administrative simplicity that scales. Perhaps the most underappreciated benefit, particularly for high-growth digital health companies, is that a properly structured bundled policy can reduce the need for individual applications for each provider added to the PC, and can lessen the need for departing providers to purchase individual tail or extended reporting period coverage. In a traditional med mal program, every provider hire can require an endorsement, every departure can trigger a tail policy decision, and the administrative burden grows with headcount. A bundled digital health policy can cover the entity and its providers as a group, making it easier to manage as the company scales from ten providers to hundreds.

Scalability across states and entities. As digital health companies expand into new states and form new PC entities, a specialist carrier can add entities to the program more seamlessly. That can help reduce the entity-listing gaps described above.

The bottom line

The MSO/PC model exists for good legal reasons, but it creates insurance complexity that deserves specialized attention. The consequences of getting it wrong aren’t abstract. They can include coverage disputes, denied claims, and financial exposure that can be material to the company.

Digital health companies should work with brokers and carriers who understand their business model, can design coverage that matches how risk flows through an MSO/PC structure, and can help deliver programs that scale as the company grows. The cost of specialized expertise is modest compared with the cost of discovering that the insurance program has a gap when it matters most.

Endnotes

¹ For an overview of corporate practice of medicine restrictions and how MSO/PC structures serve as the standard compliance framework in multi-state telehealth, see Foley & Lardner LLP, “Oregon’s New Corporate Practice of Medicine Restrictions: Five Takeaways for Digital Health and Telemedicine Companies” (September 30, 2025), foley.com.

² CFC Underwriting, Digital Healthcare Report 2025 (April 2025), p. 9. CFC’s claims data shows 33% of eHealth claims involve bodily injury in the traditional sense, with the remaining 67% distributed across cyber/privacy, breach of contract, regulatory costs and fines, IP rights infringement, cybercrime, and other emerging categories.

Make sure your digital health care risk management program is ready when it matters most.

Talk to MMA’s Digital Health practice today.

Contributors

Placeholder Image

Brett Buchanan

Executive Vice President, Business Insurance

Placeholder Image

Beracah Stortvedt

Executive Vice President, Business Insurance