Small Businesses
Tech Companies
Motor & Fleet
Insurance Basics

Health Tech Insurance Australia: SaMD Startup Guide

August 7, 2026
a list item
12 Mins Read
Health Tech Insurance Australia: SaMD Startup Guide

Most healthtech founders look for insurance for one of two reasons. A hospital or health service has asked for a certificate of currency before granting access to systems or patients. Or an investor's due diligence list has landed and insurance is on it.

Either way it feels like an administrative task until you start answering the questions. Then two things surface. The cover a software company would normally buy may not respond to what your software can actually do. And a regulator may have a view about your product that you had not planned for.

That regulator is the Therapeutic Goods Administration, and its question comes first, because most of the insurance answers follow from it.

What insurance do health tech startups need in Australia?

In short: most Australian health tech businesses assess technology professional indemnity, cyber, and public and products liability as a base. Where the product can contribute to patient harm, medical malpractice or a healthcare professional indemnity extension may also be needed, and product liability may be relevant where the software is a regulated device. Management liability or directors and officers cover becomes relevant as a board forms. Clinical trial cover is arranged separately where trials are planned.

Which of those apply depends on your regulatory position. Software with an intended medical purpose may be a regulated medical device under the Therapeutic Goods Act, and that changes which cover applies, which exclusions bite and what an insurer will write. Most technology startups carry two exposures. Something breaks and a customer loses money, or data leaks. Health tech carries both, plus two more that change the conversation. A regulator may classify your product. And your product may contribute to someone being harmed.

upcover arranges insurance for health tech businesses across Australia as a Corporate Authorised Representative of an AFSL holder.

Is your software a medical device?

This is the question that shapes everything else, and the answer is less obvious than founders expect.

Under section 41BD of the Therapeutic Goods Act 1989 (Cth), software can be a medical device where it is intended to be used for a medical purpose. The listed purposes include diagnosis, prevention, monitoring, treatment or alleviation of disease; diagnosis, monitoring or treatment of an injury or disability; and investigation, replacement or modification of the anatomy or a physiological process. Where software meets that definition, it is commonly described as Software as a Medical Device (SaMD).

Two points matter more than the definition itself.

1. The test is intended purpose, not technology. How your software is built is close to irrelevant. What matters is what you say it does. TGA guidance on software-based medical devices makes clear that marketing, labelling and other information supplied with a product can shape its intended purpose. Amendments in February 2021 exempted or excluded certain software from TGA scope, so some products sit outside it, but the boundary follows your claims.

2. Your marketing can move you across that line. A feature release that adds a risk score, a pitch deck line about detecting a condition, or a website claim about improving outcomes can bring software into scope that was previously outside it. The position is set by the manufacturer's stated intended purpose, which means a marketing decision can become a regulatory one.

What your product does Likely regulatory question What it means for insurance
Tracks activity or wellbeing with no therapeutic claim Likely outside TGA scope where no medical purpose is claimed Technology PI and cyber as a starting point
Provides information a clinician uses in a decision Clinical decision support may fall within scope depending on how it influences management Assess whether patient harm is addressed anywhere
Suggests or indicates a diagnosis Commonly within scope Regulatory position drives the placement
Calculates a dose or treatment parameter Commonly within scope, and higher classification is possible Specialist placement likely
Monitors a patient and raises clinical alerts Commonly within scope Assess bodily injury and product liability treatment
Manages bookings, billing or records with no clinical output Generally outside scope Cyber and technology PI, with health data still in play

Swipe left or right to see the full table.

Whether your software is a regulated medical device, and how it classifies, is a regulatory determination. Those questions belong with the TGA or a qualified regulatory adviser. What upcover can do is discuss the insurance implications of the position you disclose. Talk it through with upcover once you know where you sit, or while you are working it out.

How does TGA classification affect health tech insurance?

Where software is a regulated medical device, inclusion in the Australian Register of Therapeutic Goods (ARTG) is generally required before supply unless the product is exempt or excluded. Classification and role then shape the placement.

Classification runs from Class I to Class III. Australian medical device classification uses Class I, Class IIa, Class IIb and Class III, with in vitro diagnostic devices classified separately. For software the driver is not sophistication but consequence: how significant the information is to a clinical decision, and how serious the condition it addresses. Where more than one classification rule could apply, the highest applicable class generally governs. Higher classes attract more regulatory scrutiny, and underwriters read them the same way.

The Essential Principles apply regardless of class. Devices supplied in Australia must meet the TGA's Essential Principles covering safety, performance, design and the information supplied with the product. For software this reaches into cybersecurity, version control and lifecycle processes. An insurer asking about your quality management system is asking a version of the same question.

Manufacturer, sponsor and distributor are different roles. The manufacturer designs and produces. The sponsor is the entity that imports, exports or supplies in Australia and carries the ARTG obligations. A distributor sits further down the chain. An Australian business importing a device developed overseas can hold sponsor exposure, which surprises teams who think of themselves as resellers. Get the named insured wrong and the policy may not follow the liability.

Obligations continue after approval. Post-market responsibilities include monitoring performance in the field, reporting adverse events to the TGA, and conducting recalls or corrective actions where needed. These matter to insurance in two ways: they generate the evidence an insurer reviews after an incident, and recall costs are commonly excluded from liability cover.

ARTG status can become a policy condition. Some wordings treat regulatory compliance as a condition or a warranty rather than background. If your position is unresolved or your ARTG submission is in progress, say so at quote stage. Insurers deal with pre-ARTG companies routinely. What they handle badly is finding out later.

Does technology PI cover patient harm?

Here is the gap that matters most, and it is the reason a health tech company cannot simply buy what a SaaS company buys. Technology professional indemnity commonly responds to claims that your technology or services caused someone a financial loss. A failed integration, a calculation error, an outage that cost a client revenue. That is the exposure the product was built for.

A health tech failure can produce something else. If a clinical decision support tool contributes to a missed diagnosis, or a monitoring platform fails to escalate, the allegation is not that money was lost. It is that a person was harmed. Many technology wordings exclude bodily injury. Which means the exposure most likely to end the business can be the one the policy does not answer.

How that gap gets closed depends on the policy architecture rather than a single product name:

  • A technology PI wording that expressly includes bodily injury arising from the product, where an insurer will write it
  • Medical malpractice insurance or a healthcare professional indemnity extension, where clinical services are involved
  • Product liability, which may respond where the policy's product definition expressly captures the software or device
  • A specialist life sciences programme, which may combine several of these in one placement

Treatment differs between standalone technology PI, combined liability wordings and specialist life sciences policies. Two policies that look similar on a summary can sit on opposite sides of this question. The practical step is short. Read the exclusions in your current technology PI wording and look for bodily injury. If it is excluded and your product can contribute to patient harm, that is the conversation to have before renewal, not after an incident.

Product type Primary exposure Cover to assess The question for your policy
Wellness or lifestyle app Data, and misleading claims Technology PI, cyber Are health claims in your marketing consistent with the cover?
Clinical decision support A clinician relies on wrong output Technology PI, plus a way to answer patient harm Is bodily injury excluded?
Diagnostic or screening software Missed or incorrect finding Technology PI, malpractice or healthcare PI, product liability Which section responds to patient harm?
Connected device with software Device failure causes injury Product liability plus technology PI Does the product definition capture firmware?
Telehealth platform engaging clinicians Clinical acts of practitioners Malpractice or healthcare PI, plus platform cover Are practitioners insured, and who is named?
Health data platform Breach of sensitive records Cyber, technology PI Are regulatory response costs included?

Swipe left or right to see the full table.

Are practitioners covered by your health tech insurance?

If registered health practitioners deliver care through your platform, two sets of arrangements sit side by side and neither replaces the other.

The practitioner's own position. Registered health practitioners who practise must have appropriate professional indemnity insurance arrangements that comply with the registration standard of their relevant National Board. Those arrangements are not always a policy the practitioner buys. Depending on the applicable Board standard, they may be provided through an employer or another third party. If your platform employs clinicians, you may be part of how they satisfy that standard. Confirm it rather than assume it.

Your company's own exposure. This is separate from practitioner registration compliance, and it comes in two forms.

Direct allegations about the company itself: that the platform selected an unsuitable clinician, set inadequate clinical protocols, failed to escalate, or built a workflow that contributed to harm. These are allegations about your systems, not the clinician's judgement. Vicarious exposure for the clinical acts of practitioners you employ or, depending on the arrangement, contract.

What to check in your policy: whether practitioners are named or covered as insured persons, whether contractors and locums are included or treated differently, whether the definition of professional services covers clinical acts at all or stops at technology failure, and whether cover extends to allegations about the platform's clinical governance. For the difference between the two products, see Medical Malpractice vs professional indemnity insurance.

How does holding health data affect cyber insurance?

Health information is the most sensitive category most startups will ever hold, and both the law and the insurance market treat it that way.

Where the small business exemption may not help. The Privacy Act's $3 million turnover threshold does not assist a business that provides a health service and holds health information. Under section 6FB of the Privacy Act 1988, a health service provider generally includes a private sector entity providing a health service, and those entities are covered regardless of annual turnover.

That test is narrower than it first sounds. Not every software vendor that stores health information is providing a health service. A platform delivering care, or one that itself provides a health service, is in a different position from a vendor supplying software to a clinic. Other exceptions to the exemption can still apply, including where a business trades in personal information. Confirm the position for your specific model rather than assuming it either way.

Why insurers care. The Office of the Australian Information Commissioner received 1,205 data breach notifications in the 2025 calendar year, the highest since the notifiable data breaches scheme began in 2018. Health service providers were the most commonly affected sector, accounting for 225 notifications, or 19% of the national total. Financial services followed with 157.

Two obligations with dates attached. Where there are grounds to suspect an eligible data breach, reasonable steps must be taken to assess it within 30 days, then notify affected individuals and the OAIC as soon as practicable. Separately, since 10 June 2025 a statutory tort for serious invasions of privacy has allowed individuals to bring proceedings directly. It is not strict liability for any privacy incident: the cause of action has defined elements including a reasonable expectation of privacy, seriousness of the invasion, and a public interest balancing test, with defences available.

Automated decisions. From 10 December 2026, APP entities must disclose in their privacy policy where personal information is used in certain automated decisions specifically those that significantly affect an individual's rights or interests, subject to the statutory conditions. Whether a triage, scoring or prioritisation feature meets that threshold depends on what the decision does and how it affects the person, so it is worth assessing rather than assuming.

What this means for the cyber policy itself. Insurers underwriting health data look at controls before price: multi-factor authentication, encryption at rest and in transit, access logging, tested backups, and a documented incident response plan. Cyber insurance may cover incident response, forensic investigation, data restoration, business interruption, notification costs and third-party privacy claims, subject to the terms.

Three questions for the policy document: whether regulatory investigation costs are included and at what sublimit, whether the notification cost limit reflects the number of individuals whose records you hold, and whether any security control is stated as a condition or warranty rather than a question you answered once at inception.

Where you also engage practitioners or hold clinical records, state health records legislation in New South Wales, Victoria and the Australian Capital Territory can apply alongside the federal regime. My Health Record obligations apply where you participate in that system. For cost detail, see how much does cyber insurance cost.

When does a health tech startup need insurance?

Founders usually ask this as a stage question. For health tech it is better answered as a list of moments, because these are the points where the answer changes.

  1. Real health data touches your system. Not at scale, and not at revenue. The first pilot with real patient records is the trigger, because obligations attach to the data rather than the business size.
  2. You make your first clinical claim. The moment your marketing says the product detects, diagnoses, monitors or improves an outcome, TGA scope becomes a live question. This is usually a marketing decision made without a regulatory conversation.
  3. You prepare or submit for ARTG inclusion. Insurers treat pre-ARTG and post-ARTG companies differently, and the transition is worth flagging at renewal.
  4. Your first hospital or health service pilot. Procurement will ask for evidence of insurance before granting access to systems or patients.
  5. You engage your first practitioner. Clinical exposure arrives with them, employed or contracted.
  6. You plan a clinical trial. Trial cover is arranged separately and may need specialist underwriting, so start while the protocol is being written.
  7. You sign your first enterprise or government contract. These bring specified limits, named-insured requirements and certificate deadlines.

For the general startup picture across stages, see when does a startup need insurance.

What insurance do clinical trials and hospital pilots require?

These are the two moments where insurance most often blocks progress, and both reward early attention.

Clinical trials

Trial activity must be expressly included or separately arranged. It is commonly excluded from standard technology and healthcare policies, so assuming an existing one travels is a mistake worth avoiding. Depending on the trial and the insurer, cover may be written as a standalone trial policy or as part of a specialist life sciences programme.

What sits inside a trial placement:

  • Legal liability for injury to participants where the sponsor or investigator is legally liable
  • No-fault compensation, which responds to participant injury without requiring liability to be established, and which sponsors and ethics committees commonly expect
  • Sponsor obligations, since the sponsor carries specific responsibilities and is usually the named insured
  • Run-off, because a participant may bring a claim well after the trial closes

Human research ethics committee requirements sit alongside the insurance and run on a different timeline. Sponsors and sites commonly specify limits, named insureds and evidence before a participant is enrolled. Trial placements may require specialist underwriting and longer lead times than a standard technology policy.

Hospital and health service procurement

Health services ask for evidence of insurance before granting system access, patient contact or data flow. What they commonly request: a certificate of currency naming the correct entity, specified professional indemnity and public liability limits, cyber cover, and sometimes a contractual indemnity your policy has to be able to support. Requirements vary between health services and between contracts, so the schedule you are given is the one that matters.

The practical failure here is timing rather than cover. A pilot agreed in principle stalls while insurance is arranged, and the delay lands on the startup. Have a pilot or trial schedule in front of you? Bring it to upcover and the requirements can be checked against the cover before you sign.

What exclusions and gaps should health tech businesses check?

Exclusions differ between insurers, so treat each of these as a question for your policy rather than a rule.

  1. Regulatory penalties and fines. Generally not insurable. The cost of responding to an investigation may be covered, depending on the terms.
  2. Failure to hold ARTG inclusion where it was required. A compliance failure first, and potentially a cover problem where the policy treats regulatory status as a condition.
  3. Use outside the intended purpose you declared. If clinicians use your product for something you did not declare, the gap may sit with you.
  4. Clinical trial activity, which needs to be expressly included or separately arranged.
  5. Product recall, withdrawal or corrective action costs. Commonly excluded, and the cost of correcting the product itself is generally not covered even where resulting harm may be.
  6. Bodily injury, where the technology PI policy excludes it.
  7. Practitioner acts where practitioners are not insured persons under your policy.
  8. Prior known circumstances and late notification. These wordings commonly operate on a claims-made and notified basis, so a problem you knew about before inception, or one reported late, may fall outside cover. See claims-made vs occurrence insurance.
  9. Contractual liability beyond ordinary legal liability, including indemnities you gave a health service that go further than the law would.

The policy wording, schedule and any endorsements determine cover, not the product name.

How much does health tech insurance cost in Australia?

The direct answer: there is no reliable flat average, and any single figure quoted for health tech would mislead more than it helps. The spread is too wide, because the same headcount and revenue can sit either side of a regulatory line.

Two health tech companies with identical headcount and revenue can price very differently. One tracks steps and makes no clinical claim. The other produces output a clinician relies on when deciding treatment. Same team, different risk class. So rather than a number, here is what moves it, heaviest first.

Your TGA status and clinical output. Whether the software has an intended medical purpose, its classification, and how directly its output influences a clinical decision. This moves the price more than anything else on the list.

Practitioner involvement. Whether registered practitioners deliver care through the platform, and on what basis.

Data volume and sensitivity. How many patient records, what fields, and whether identifiers sit alongside clinical information. Your security controls affect this materially.

Contract requirements. Hospital, health service and government contracts often set the limit floor, so the number is frequently decided by your customers rather than your risk appetite.

Then the ordinary drivers: turnover, funding stage, board composition, claims and incident history, cover level and excess.

On limits. Contract requirements usually decide this. Where they do not, work from the worst realistic claim rather than a round number. Public liability options commonly range from $5 million to $20 million and are contract-driven. Cyber limits for smaller businesses commonly range from $250,000 to $5 million.

What does not fit a price band. Clinical trials, higher-class devices and anything approaching a life-sustaining function are specialist placements. Those move to a broker conversation rather than an online quote, and the honest answer on price is that it depends on the technical file.

How should founders compare health tech insurance policies?

Run your current schedule against these before renewing. They are ordered by how often they turn out to matter.

What to check Why it matters
Is bodily injury arising from the product covered or excluded? The most consequential gap in health tech cover
Does the insured-services definition match your regulatory position and actual product? A wording written for generic software may not describe what you do
Are practitioners insured persons, and which ones? Employed, contracted and locum practitioners are treated differently
Is ARTG status a condition, a warranty or background? Changes what happens if your regulatory position shifts
Is trial activity expressly included, or arranged separately? Commonly excluded, and needed before enrolment
Are you named correctly as manufacturer, sponsor or distributor? The wrong named insured can break the chain
Are defence costs inside or outside the limit? Inside the limit, defence spend reduces what is left for compensation
Is the limit any-one-claim or an annual aggregate? An aggregate can be exhausted by an earlier claim
What sublimits apply, and to what? Regulatory investigation, notification and recall are often sublimited
Can a health service be added as an additional insured? Some procurement schedules require it
Is run-off available if the company is sold or wound up? Health claims can surface long after the work
What is the retroactive date, and is cover continuous? Gaps in cover can leave earlier work unprotected
Does the territory follow your customers? Selling into the United States, United Kingdom or European Union brings other regulators into your contracts

Swipe left or right to see the full table.

What information do you need for a health tech insurance quote?

Having these ready turns a vague conversation into a real quote.

  • Business name, ABN and the entity that contracts with customers
  • Your intended purpose statement, in the words you use publicly, plus current website and pitch claims
  • TGA status, classification if determined, and any ARTG number
  • Whether you are manufacturer, sponsor, distributor or a combination
  • What the product does clinically, and where a human sits in the decision
  • Quality management system status, and any certification held or in progress
  • Practitioner arrangements, including employment status and numbers
  • Data types, volume, and which cloud providers and subcontractors process it
  • Security controls: authentication, encryption, backups, access logging, incident response plan
  • Countries where you sell or hold data
  • Clinical trial activity, with protocol and phase where planned
  • Hospital, health service or government contracts and their insurance schedules
  • Turnover, funding raised and board composition
  • Claims, incidents and complaints history
  • Limits your contracts require

Ready to compare? Explore health tech insurance through upcover with those details to hand. Availability and terms depend on insurer acceptance.

How upcover can help

Health tech placements split into two paths, and knowing which one you are on saves time.

Straightforward technology risk. Where the product makes no clinical claim, sits outside TGA scope and the exposure is data and technology performance, technology professional indemnity and cyber can often be arranged through a standard process for eligible businesses.

Specialist placement. Where the software is a regulated device, contributes to clinical decisions, engages practitioners or involves trials, the placement needs an underwriter who reads technical files. That is a broker conversation, and it takes longer.

If a hospital pilot or trial is waiting on evidence of insurance, say so early. Certificate turnaround is usually straightforward once cover is bound, but arranging the cover is where the time goes.

upcover is a digital-first insurance broker helping Australian small businesses get the right insurance without the paperwork or phone queues. upcover arranges insurance for health tech businesses with access to 80+ insurance partners, including technology professional indemnity, cyber, medical malpractice, public and products liability and directors and officers cover.

  • 70,000+ businesses covered across Australia
  • 4.9/5 customer rating
  • Instant Certificate of Currency on policy confirmation for eligible policies

For the broader startup picture, see the startup insurance guide. For what investors review, see insurance in startup due diligence. For the wider sector view, see technology, media and digital insurance.

upcover Pty Ltd ABN 17 628 197 437 is a Corporate Authorised Representative (CAR 1299211) of Experience Insurance Services Pty Ltd ABN 41 657 596 506, AFSL 539078.

Frequently asked questions

Is health tech insurance legally required in Australia?

There is no single law requiring a health tech company to hold insurance. Workers compensation is compulsory once you employ staff, and registered health practitioners must have appropriate professional indemnity arrangements under their Board's registration standard. Beyond that, most requirements are contractual: hospitals, health services, investors and trial sponsors commonly specify cover and limits.

Is my health app a medical device?

It depends on your intended purpose rather than your technology. Under section 41BD of the Therapeutic Goods Act 1989 (Cth), software intended for a medical purpose such as diagnosis, monitoring or treatment may be a regulated medical device. Wellness apps without therapeutic claims commonly sit outside scope, but a feature or marketing claim can move a product across the line. Classification is a regulatory determination for the TGA or a qualified adviser.

Does technology professional indemnity cover patient harm?

Often not. Technology PI commonly responds to financial loss, and many wordings exclude bodily injury. Where your product can contribute to patient harm, check the exclusions and consider whether a wording that includes bodily injury, malpractice cover or product liability is needed alongside it.

Does product liability insurance cover software as a medical device?

It may, where the policy's product definition expressly captures the software or the device it runs on. Some policies define products in a way that assumes physical goods. If your software is regulated as a device, confirm the definition covers it rather than relying on the classification alone.

What is the difference between health tech insurance and medical device insurance?

Healthtech insurance is a description rather than a product, covering the mix a digital health business assembles. Medical software insurance and medical device liability placements are built around a regulated product, its classification and the sponsor and manufacturer roles. A health tech company supplying a regulated device may need elements of both.

What insurance do hospitals ask health tech companies for?

Requirements vary by health service and contract. Common requests are evidence of cover naming the correct entity, specified professional indemnity and public liability limits, cyber cover, and sometimes an indemnity your policy needs to be able to support. Ask for their insurance schedule before signing.

Does a health tech startup need cyber insurance if turnover is under $3 million?

The Privacy Act's small business exemption does not assist a business that provides a health service and holds health information, which is covered regardless of turnover under section 6FB. Whether your model falls inside that test is worth confirming. Either way, health data breaches carry remediation, notification and commercial consequences that arrive well before any threshold.

Is clinical trial cover included in a standard policy?

Generally not. Trial activity needs to be expressly included or separately arranged, and it is commonly excluded from standard technology and healthcare wordings. Cover may be written standalone or within a specialist life sciences programme, and sponsors and ethics committees commonly expect no-fault compensation alongside legal liability.

Can an Australian health tech policy cover United States customers?

Sometimes, but territory and jurisdiction clauses need checking rather than assuming. North American exposure commonly attracts different terms, higher pricing or exclusion, because the litigation and regulatory environment differs. Tell your insurer before you sell there, not after.

How quickly can I get a certificate of currency for a hospital pilot?

Once cover is arranged and the insurer has accepted the risk, a certificate is usually straightforward. The time goes into arranging cover, which depends on your regulatory position, the information available and whether the risk needs a specialist underwriter. If a pilot is waiting on it, start earlier than feels necessary.

This article is general information only. It does not take into account your objectives, financial situation or needs, and is not personal advice. It does not constitute legal, regulatory, medical or clinical advice. Whether software is a regulated medical device, its classification and any Australian Register of Therapeutic Goods obligations are regulatory determinations that should be confirmed with the Therapeutic Goods Administration or a qualified regulatory adviser. Privacy, therapeutic goods and health records obligations are set by legislation and may change. Regulatory references and statistics in this article were current at the time of writing and should be checked against the source before you rely on them. Insurance market observations describe common practice rather than universal rules, and cover types, limits, inclusions, exclusions and policy structure vary between insurers and policies. All insurance products arranged through upcover are subject to the terms, conditions, limits and exclusions in the relevant policy wording, schedule, endorsements and any applicable Product Disclosure Statement, so read those documents and consider your circumstances before deciding whether a product suits you. upcover Pty Ltd ABN 17 628 197 437 is a Corporate Authorised Representative (CAR 1299211) of Experience Insurance Services Pty Ltd ABN 41 657 596 506, AFSL 539078, and arranges insurance products with selected insurers and underwriters rather than the whole market.

We are digitising commercial insurance and risk management for small, mid-market and technology businesses. We work with a global network of underwriters, challenging legacy brokers and delivering market leading coverage to our customers.