Question
What insurance do you need to partner with or resell a telehealth company's services?
Short answer
A company marketing or reselling another telehealth provider's services is typically required to carry general liability, products liability, and cyber liability (including HIPAA and privacy coverage), name the telehealth partner as an additional insured, and provide coverage on a primary and non-contributory basis.
The short answer
Telehealth and digital-health platforms routinely require their marketing partners, resellers, and affiliates to carry insurance before they will let another company promote or distribute their services. The requirement protects the platform from liability arising out of how the partner markets and delivers access to the service.
The coverages are usually general liability, products or professional liability, and cyber liability with privacy and HIPAA-related coverage. Limits are commonly modest, and the requirement is achievable even for an early-stage or pre-revenue company.
The typical requirement
A common structure is commercial general liability at $1,000,000 per occurrence and $3,000,000 aggregate, products and completed operations at similar limits, and cyber liability at $1,000,000 covering privacy, data security, and HIPAA-related claims. The exact figures come from the specific partnership agreement.
The platform will usually also require to be named as an additional insured on the general liability policy, coverage that responds on a primary and non-contributory basis, and a certificate of insurance evidencing all of it before the agreement goes live.
Why cyber and HIPAA coverage are non-negotiable
Anything that touches protected health information, whether the partner stores it, transmits it, or simply routes users into a service that does, creates data-privacy exposure. Telehealth platforms require cyber liability with HIPAA and privacy coverage precisely because a breach or privacy claim can reach both parties.
A general liability policy does not respond to a data breach or a privacy violation. Cyber liability is a separate line, and the HHS HIPAA framework is the reference point for what a privacy or security failure involving health data can trigger. This is why the exhibit lists cyber as its own required coverage rather than folding it into general liability.
How to meet it without holding up the deal
Read the insurance section of the partnership agreement against your current coverage, or against a proposed program if you do not have coverage yet, and confirm each required line and each piece of endorsement wording is present. The additional-insured and primary and non-contributory language is where certificates most often fall short.
For a pre-revenue or early-stage operator, the coverages are generally available at reasonable cost, and the program can usually be put in place quickly. The goal is to produce a certificate that satisfies the platform's exhibit on the first review so the partnership can go live on schedule.
Primary sources
Sources and references
This answer draws on the following regulatory, statutory, and standards-body sources. Coverage availability and program structure also depend on carrier appetite and underwriter discretion not captured by these sources.
- HHS - HIPAA for Professionalshttps://www.hhs.gov/hipaa/for-professionals/index.html
Related practice areas
Insurance clauses in this area
Related questions
Have a more specific question?
A specialist will reach out by the end of the day.
Request a free coverage review