4.4 Specialty Coverage Lines: D&O, Cyber, Workers' Compensation, and Property

Key Takeaways

  • The general liability versus professional liability boundary turns on whether the injury arose from an act in the rendering of professional services, not on where in the facility it happened.
  • D&O is written in three parts: Side A pays individuals when the organization cannot indemnify, Side B reimburses the organization for indemnification it provides, and Side C covers the entity itself.
  • Fiduciary liability covers breach of ERISA duties in administering a benefit plan; a fidelity bond covers employee dishonesty and theft. They are different products and are routinely confused.
  • Cyber first-party grants pay the organization's own breach response, restoration, extortion, and network business interruption; third-party grants pay privacy liability, regulatory defense, and fines where insurable by law.
  • Property business interruption requires direct physical loss or damage, so it does not respond to income lost during a ransomware outage; workers' compensation Part A pays unlimited statutory benefits while Part B, employer's liability, carries limits.
Last updated: July 2026

Quick Answer: Domain 2 expects the risk manager to map each exposure to the coverage line that actually responds. Directors and Officers (D&O) liability protects governance decisions, cyber liability splits into first-party response costs and third-party privacy liability, workers' compensation is the exclusive statutory remedy for employee injury, and the general liability (GL) versus professional liability (PL) boundary turns on whether professional judgment was involved, not on where the injury happened.

Why the Exam Tests Specialty Lines

Risk Financing carries 15 of the 100 scored CPHRM items, and task D of that domain asks the risk manager to "develop enterprise risk financing strategies to address the organization's areas of exposure (e.g., general liability, professional liability, cyber liability)." Items rarely ask you to underwrite or price a policy. They present a loss and ask which line responds, which line does not, and where the gap is.

Keep the authority boundary in view. The risk manager identifies the exposure, routes the notice, and advises leadership. The risk manager does not tell a claimant "we are covered," does not tell a department a loss is uninsured before coverage counsel reviews the policy, and does not bind or amend coverage. Answer choices that have the risk manager declaring coverage outcomes are almost always wrong.

The occurrence versus claims-made trigger, tail coverage, and prior acts (nose) coverage are taught separately and apply across every line below. This section works line by line.

The General Liability vs. Professional Liability Boundary

This is the single most heavily tested coverage distinction in the domain, and candidates consistently get it backward by reasoning from location instead of from the nature of the act.

  • Commercial General Liability (CGL) responds to third-party bodily injury and property damage arising from premises, operations, and products — a visitor slipping on a wet lobby floor, a falling ceiling tile, a maintenance error. CGL forms contain a professional services exclusion that carves out injury arising from the rendering of or failure to render professional health care services.
  • Professional Liability (PL), also called Hospital Professional Liability or Medical Professional Liability, responds when the injury arises out of an act, error, or omission in the rendering of professional services — anything requiring clinical training, judgment, or licensure.

Apply the test to two nearly identical facts. A visitor slips on a wet floor in a patient corridor: the housekeeping and inspection process failed, no clinical judgment was involved, and it is a GL loss. A patient assessed as high fall risk climbs out of bed and fractures a hip after the bed alarm was never activated: the failure was in the execution of a nursing care plan, so it is a PL loss. The room is the same. The act is not.

Because many systems buy GL and PL from different carriers on different forms, a coverage seam can open where each carrier points at the other. The risk manager's job is to notice both and let the carriers allocate.

Management Liability: D&O, EPLI, Fiduciary, and Crime

Directors and Officers (D&O) liability covers wrongful acts — errors in judgment, misstatements, breaches of duty, mismanagement — committed by board members and executives in their organizational capacity. It is written in three insuring agreements:

  • Side A pays individual directors and officers directly when the organization cannot or does not indemnify them (insolvency, or an indemnification the law or bylaws bar).
  • Side B, the corporate reimbursement agreement, reimburses the organization for indemnification it lawfully provides to those individuals. Side B usually carries a retention; Side A usually does not.
  • Side C, entity coverage, responds to liability of the organization itself.

Employment Practices Liability Insurance (EPLI) covers discrimination, harassment, retaliation, wrongful termination, and failure to promote. In health systems it is often endorsed onto the D&O program, and it is frequently the highest-frequency management liability line.

Fiduciary liability is not D&O. It covers breach of the duties imposed by the Employee Retirement Income Security Act of 1974 (ERISA) on people who administer employee benefit plans — imprudent investment selection, excessive recordkeeping fees, failure to follow plan documents. D&O covers running the corporation; fiduciary covers running the plan.

Crime and fidelity bonds cover employee dishonesty, theft, forgery, funds transfer fraud, and social engineering fraud. Note the classic confusion: a fidelity bond responds to dishonesty and theft, while fiduciary liability responds to breach of duty. They are different products. ERISA section 412 separately requires a bond for plan officials handling plan funds, at 10% of funds handled, minimum $1,000 and maximum $500,000 (raised to $1,000,000 for plans holding employer securities).

D&O and fiduciary forms exclude bodily injury and property damage. A board sued for failing to oversee patient safety may trigger D&O for the governance allegation while the underlying patient injuries stay with professional liability.

Cyber Liability: First-Party vs. Third-Party

Cyber policies are modular, and the exam tests whether you can separate your own losses from claims others bring against you.

First-party grants fund what the organization spends on itself: breach response and incident management, forensic investigation, legal breach counsel, notification of affected individuals, credit monitoring and call center costs, data restoration and re-creation, network business interruption for lost income during an outage, contingent or dependent business interruption when a vendor is attacked, and cyber extortion and ransomware payments plus negotiation services.

Third-party grants fund liability to others: privacy liability for patient class actions after a protected health information exposure, network security liability when malware transmits from your network, media liability, regulatory defense costs for HIPAA and state attorney general proceedings, fines and penalties where insurable by law, and Payment Card Industry assessments.

Two gaps recur. First, betterment — the cost of upgrading systems to a more secure state — is typically excluded; the policy restores, it does not improve. Second, the property policy will not pay the operating income lost during a ransomware outage, because property business interruption requires direct physical loss or damage. Most cyber programs also require use of panel vendors and prompt hotline notice; retaining your own forensic firm first is a common way to have costs denied.

Workers' Compensation and Employer's Liability

Workers' compensation is a statutory, no-fault system. The employee receives scheduled medical and indemnity benefits without proving negligence, and in exchange the exclusive remedy doctrine bars a tort suit against the employer. The employer gives up the common-law defenses of contributory negligence, assumption of risk, and the fellow-servant rule.

Exclusive remedy is not absolute, and the exceptions vary by state:

  • Intentional acts or, in some states, conduct substantially certain to cause injury.
  • Dual capacity, where the employer is sued in a second independent role — a hospital that treats its own employee as a patient can face a professional liability claim for that treatment on top of the compensation benefits.
  • Third-party over actions, where an injured employee sues a vendor and the vendor impleads the hospital under a contractual indemnity.
  • Derivative claims such as a spouse's loss of consortium, in some jurisdictions.

The workers' compensation policy has two parts. Part A pays statutory benefits with no policy limit — the limit is whatever the state law requires. Part B, employer's liability, pays damages for employment-related bodily injury suits at law that escape exclusive remedy. Part B does carry limits; standard limits are commonly $100,000 bodily injury by accident each accident, $500,000 bodily injury by disease policy limit, and $100,000 bodily injury by disease each employee, raised by endorsement so an umbrella can sit above them.

Property, Business Interruption, Auto, and Products

Property coverage is written on named perils or, more commonly, special form (all risk with exclusions). Valuation matters more than limit: replacement cost rebuilds without depreciation, actual cash value deducts it. Flood, earthquake, and named windstorm usually carry separate percentage deductibles.

Business interruption (BI) replaces net income plus continuing normal operating expenses during the period of restoration. Extra expense pays the additional costs of continuing to operate — mobile imaging, leased space, agency staffing. Hospitals routinely underinsure BI because they value it on operating margin rather than on the revenue actually lost while beds are closed, and because a licensed facility's period of restoration includes permitting, certificate of need, and re-licensure time.

Business auto must be written to reach three categories: owned vehicles, hired vehicles, and non-owned autos — employee personal vehicles driven on organizational business. Home health nurses, case managers, and courier-running staff create real non-owned exposure, and the employee's personal auto limits are usually far too low. Valet operations add garagekeepers exposure.

Product liability attaches when the organization is treated as a seller or supplier: implanted devices, reprocessed single-use devices, compounded or repackaged medications, durable medical equipment, cafeteria food. Many states hold that a hospital supplying a device incidental to treatment renders a service rather than a sale, so strict product liability does not attach and the claim proceeds in negligence or professional liability instead — but this varies by state and should never be assumed.

Coverage Line Reference Table

LineWhat triggers itTypical healthcare exposureCommon gap
Professional liabilityAct, error, or omission in rendering professional servicesDelayed diagnosis, medication error, surgical injuryEmployed vs. contracted physicians; locums and telehealth providers left off the schedule
Commercial general liabilityPremises or operations bodily injury and property damage, not professionalVisitor falls, ceiling collapse, assault on premisesProfessional services exclusion creates a seam with the PL carrier
Directors and officersWrongful act by a director or officer in that capacityGovernance oversight failure, antitrust, merger disputesBodily injury and property damage excluded; Side A limits too thin
Employment practicesWrongful employment act against an applicant or employeeDiscrimination, harassment, retaliation, wrongful terminationWage and hour claims usually excluded or sublimited
Fiduciary liabilityBreach of ERISA duty in administering a benefit planExcessive fee litigation, imprudent plan investmentsConfused with the fidelity bond, which covers theft, not duty
Cyber liabilitySecurity failure or privacy eventRansomware, PHI exposure, vendor breachBetterment excluded; non-panel vendor costs denied
Workers' compensationInjury arising out of and in the course of employmentLifting injuries, needlesticks, workplace violenceDual capacity and third-party-over suits fall to Part B, not Part A
Property and BIDirect physical loss or damage by a covered perilFire, water intrusion, windstorm, equipment breakdownNo physical damage means no cyber outage income; BI valued on margin, not lost revenue
Business autoOwnership, maintenance, or use of an autoShuttles, patient transport, home health travelNon-owned auto omitted; employee's personal limits inadequate
Products liabilityDefect in a product sold or suppliedImplants, compounded drugs, DME, food serviceService-versus-sale doctrine varies by state
Test Your Knowledge

A health system's board is sued derivatively for allegedly failing to oversee the cybersecurity program before a ransomware attack. The bylaws permit indemnification and the health system advances defense costs for the individual directors. Which D&O insuring agreement reimburses the health system for those advanced amounts?

A
B
C
D

Real Healthcare Scenario: One Event, Four Coverage Lines

Scenario: At 2:00 a.m., ransomware encrypts a 400-bed community hospital's electronic health record and its scheduling and revenue cycle systems. The emergency department diverts for six days, elective surgery stops for nine, and 41,000 patients' records are exfiltrated. Six weeks later, two patient class actions are filed, the state attorney general opens an inquiry, and a board member files a derivative action alleging the directors ignored two prior penetration test reports.

Coverage mapping the risk manager presents to the finance committee:

  1. Cyber, first party. Breach counsel, forensics, notification and credit monitoring for 41,000 individuals, data restoration, and network business interruption for the diversion and surgical shutdown. The carrier hotline is called before any vendor is engaged, because the policy requires panel vendors.
  2. Cyber, third party. Defense and indemnity for the two class actions, plus regulatory defense costs for the attorney general inquiry and any penalties insurable under applicable law.
  3. Directors and officers. The derivative action alleges a governance oversight failure, which is a wrongful act by directors in their capacity as directors. Side B responds if the hospital indemnifies; Side A responds for any portion it cannot.
  4. Property. Does not respond. There is no direct physical loss or damage, so the property business interruption grant is not triggered no matter how large the income loss.
  5. Professional liability. A separate notice is filed for two patients whose care was delayed during downtime procedures, because those are clinical-judgment allegations rather than security allegations.

The risk manager notices every potentially implicated carrier rather than choosing among them, and lets the carriers argue allocation. Choosing one line and staying silent to the others is how coverage is lost.

Exam Traps on Coverage Lines

  • Reasoning from location instead of act. An injury inside a patient room is not automatically professional liability, and an injury in the lobby is not automatically general liability. Ask whether professional judgment was involved.
  • Confusing fiduciary liability with a fidelity bond. Duty versus dishonesty.
  • Expecting D&O to pay bodily injury. Management liability forms exclude it.
  • Expecting property BI to pay a cyber outage. No physical damage, no trigger.
  • Assuming exclusive remedy ends every employee claim. Dual capacity, intentional acts, and third-party-over suits survive it, and the exceptions vary by state.
  • Forgetting non-owned auto. The organization's exposure follows the errand, not the title on the vehicle.
  • Declaring a coverage outcome. The risk manager reports the facts, notices the carriers, and refers the coverage question to the broker and coverage counsel.
Test Your Knowledge

Ransomware forces a hospital's emergency department onto diversion for six days and halts elective surgery for nine. No building, server, or piece of equipment suffers any physical damage. Which grant most directly funds the operating income lost during the outage?

A
B
C
D
Test Your Knowledge

A nurse injures her back lifting a patient, receives workers' compensation benefits, and is treated in her own employer's emergency department, where she alleges the radiologist misread her spinal imaging and worsened the injury. Which analysis is most accurate?

A
B
C
D