What We CoverOur ApproachClient StoriesInsightsAboutSchedule a Consultation
All insights

Three clinic stories: why a personal malpractice policy is not enough, and when entity-level cover and cyber insurance both matter at once

Three fictional but realistic stories of Singapore clinic directors who held personal malpractice policies and still found themselves exposed when a cyber incident and a clinical claim arose from the same event. Why entity-level cover is a different product addressing a different party.

Dr Lim has run her GP clinic in Toa Payoh for eleven years. She holds a personal medical malpractice policy. She has always assumed it covers her practice.

It covers her. That is not the same thing.

This is the story of how one event, on one Tuesday morning, can trigger two insurance policies simultaneously and still leave a clinic director exposed, because the wrong one is held at the wrong level.

Story one: the ransomware attack that became a malpractice claim

On a Tuesday morning, Dr Lim's clinic nurse arrives at 8.45am and finds that the practice management system will not load. The screen shows a message demanding payment in cryptocurrency to restore access. Everything is locked: patient records, appointment history, prescription records, and the allergy registry she has maintained for a decade.

Dr Lim makes a decision. Her first patient is already waiting. She will see them from memory and physical notes where she has them. She will manage.

The third patient of the morning is a regular. Dr Lim remembers him broadly but cannot verify his medication history on screen. She prescribes something that, had she been able to check the record, she would have flagged as contraindicated with what he is already on. He fills the prescription at the pharmacy. Two days later, he is hospitalised.

Two things happen at once.

The patient's family hires a lawyer. The claim is directed at Dr Lim personally for the prescribing error. Her personal malpractice policy receives the claim. The insurer begins investigating.

At the same time, the clinic, as an HCSA-licensed entity, has an obligation to notify MOH of the ransomware incident under the Health Information Act. The PDPC is also monitoring for whether the patient data breach crosses the notification threshold. The costs of the forensic investigation, the legal advice on the notification obligations, and the business interruption while the systems are being rebuilt fall on the clinic as an entity.

Dr Lim's personal malpractice policy covers her personal professional liability for the prescribing error. It does not respond to the clinic entity's costs of managing the cyber incident, the MOH notification, or the regulatory engagement with the PDPC.

The clinic has no cyber insurance. Those costs are absorbed directly. While dealing with the operational crisis, Dr Lim is also managing a legal claim against her personally, the regulatory response at the entity level, and her patients' anxiety about their records.

The prescribing error and the ransomware attack are one event. The insurance gaps are three.

Story two: the locum who treats the wrong patient

Dr Chan runs a two-doctor aesthetic clinic in Orchard. She holds a personal malpractice policy. On a Saturday when she is not in clinic, a locum dermatologist she has engaged administers a filler treatment to a patient. The treatment causes a delayed adverse reaction. The patient is distressed and files a complaint with the Singapore Medical Council.

The SMC complaint names Dr Chan. Not because she performed the treatment. Because her clinic is the registered HCSA licensee, and the treatment was performed under the clinic's name, using the clinic's appointment system, by a practitioner she engaged.

Dr Chan's personal malpractice policy covers claims arising from her own clinical acts. It does not automatically cover vicarious liability for the acts of an engaged locum performing treatment at the clinic on a day she was not present.

The clinic entity is the party named in the civil claim that follows. The clinic has no entity-level malpractice cover. The locum's own personal policy covers the locum's individual liability. Nobody's policy covers the clinic.

Three weeks later, Dr Chan receives a notification that the clinic's patient database, which includes the treatment records and before-and-after photographs of several hundred aesthetic patients, was accessed by an unauthorised party. The login credentials of the locum, who used the system during Saturday's sessions, were compromised in an unrelated phishing incident.

Two claims. Two regulatory engagements. One clinic with no entity-level cover on either dimension.

Story three: the GP chain that changed everything

Dr Tan is the medical director of a chain of four GP clinics operating under a single company. He holds a personal malpractice policy as a practising doctor. The company, which is the HCSA licensee for all four clinics, does not hold entity-level malpractice insurance.

A junior doctor at one of the other clinics, where Dr Tan does not practise, misses a red flag in a patient's presentation and does not refer them for further investigation. The patient is diagnosed three months later with something that would have been caught earlier with a timely referral. She brings a civil claim for damages arising from the delayed diagnosis.

The civil claim names the junior doctor. It also names the company that operates the clinic, because the company employs the junior doctor and is the entity that provided the service.

Dr Tan's personal policy covers him. It does not cover the company. It does not cover the junior doctor, who holds no personal malpractice policy of her own. The company has no entity-level malpractice insurance.

At the same time, an audit by the clinic's HIMS provider reveals that the practice management system across all four clinics has been running with a security misconfiguration for seven months. Patient records across the four sites may have been accessible to an unintended third party. The notification assessment under the PDPA and the HIA must begin immediately across all four licensed premises.

Dr Tan is the medical director. He is also the person who, as director of the company, must manage the regulatory response, engage the forensic team, and handle the communications with patients. None of the costs involved, at the company level across any of the four clinics, are covered by his personal malpractice policy.

What these three stories have in common

In each one, the clinic director held a personal malpractice policy. In each one, that policy was genuine and necessary. And in each one, it was not enough.

The gap is not that the personal policy failed. The gap is that a clinic is not a person.

When you operate a clinic as an incorporated entity, or as an HCSA licensee responsible for clinical services delivered under your name, the clinic is a separate legal party that can be named in a claim, receive a regulatory notification obligation, and carry financial exposure that your personal policy was never written to cover.

Entity-level medical malpractice insurance covers the clinic as that legal party: vicarious liability for the clinical acts of employed and engaged practitioners, claims directed at the business entity rather than the individual doctor, and the costs of defending the clinic in proceedings where the clinic, not the doctor, is the respondent.

Cyber insurance covers the clinic's costs when a digital incident creates obligations and expenses at the entity level: the forensic investigation, the regulatory notifications under the PDPA and the Health Information Act, the business interruption while systems are restored, and the third-party liability if patient data is exposed.

The two policies address two different dimensions of a clinic's exposure. Neither is a substitute for the other. And neither is addressed by a personal malpractice policy held in the doctor's own name.

The question worth asking before the next renewal

For any medical director in Singapore who runs, owns, or is responsible for a licensed healthcare entity, one question cuts through all of the above.

If a claim were made tomorrow against your clinic, as a legal entity rather than against you personally, would your current insurance programme respond?

If the answer is yes, confirm it in writing with your insurer.

If the answer is no or uncertain, the gap is worth addressing before the story becomes yours.

You can read more about our medical malpractice cover and cyber insurance on the products page and about the regulatory framework behind the cyber dimension in our post on Singapore's Health Information Act and What It Means for Clinic Cyber and Medical Malpractice Insurance.

If you are a medical director in Singapore and would like to understand whether your current insurance programme covers the entity-level exposure of your clinic, we would be glad to work through it with you.

This article provides general information only. It is not insurance or legal advice. The scenarios described are fictional and illustrative only, constructed to demonstrate how entity-level clinical and cyber exposures can arise simultaneously. They are not based on actual cases or individuals. Health Information Act obligations sourced from MOH published guidance. PDPA notification requirements sourced from the Personal Data Protection Act 2012 as amended and PDPC published guidance. HCSA licensing obligations sourced from the Ministry of Health. Policy availability, terms, conditions, and exclusions vary by insurer and product, and cover is subject to the full policy wording. Please contact TZY CO for advice on your specific situation.

Wondering how this applies to your business?

Schedule a Consultationor message us on WhatsApp →
Back to all insights