Select how you’d like to proceed with your insurance needs.
Talk to a real insurance expert on your time.
15-minutes consultation with licensed advisors
Perfect if you’re unsure about coverage needs
Get personalised recommendations
Already have coverage? Let’s simplify your service
Keep your current carriers & policies
Simple digital authorisation process
Seamless transition to better service

Most healthtech founders look for insurance for one of two reasons. A hospital or health service has asked for a certificate of currency before granting access to systems or patients. Or an investor's due diligence list has landed and insurance is on it.
Either way it feels like an administrative task until you start answering the questions. Then two things surface. The cover a software company would normally buy may not respond to what your software can actually do. And a regulator may have a view about your product that you had not planned for.
That regulator is the Therapeutic Goods Administration, and its question comes first, because most of the insurance answers follow from it.
In short: most Australian health tech businesses assess technology professional indemnity, cyber, and public and products liability as a base. Where the product can contribute to patient harm, medical malpractice or a healthcare professional indemnity extension may also be needed, and product liability may be relevant where the software is a regulated device. Management liability or directors and officers cover becomes relevant as a board forms. Clinical trial cover is arranged separately where trials are planned.
Which of those apply depends on your regulatory position. Software with an intended medical purpose may be a regulated medical device under the Therapeutic Goods Act, and that changes which cover applies, which exclusions bite and what an insurer will write. Most technology startups carry two exposures. Something breaks and a customer loses money, or data leaks. Health tech carries both, plus two more that change the conversation. A regulator may classify your product. And your product may contribute to someone being harmed.
upcover arranges insurance for health tech businesses across Australia as a Corporate Authorised Representative of an AFSL holder.
This is the question that shapes everything else, and the answer is less obvious than founders expect.
Under section 41BD of the Therapeutic Goods Act 1989 (Cth), software can be a medical device where it is intended to be used for a medical purpose. The listed purposes include diagnosis, prevention, monitoring, treatment or alleviation of disease; diagnosis, monitoring or treatment of an injury or disability; and investigation, replacement or modification of the anatomy or a physiological process. Where software meets that definition, it is commonly described as Software as a Medical Device (SaMD).
Two points matter more than the definition itself.
1. The test is intended purpose, not technology. How your software is built is close to irrelevant. What matters is what you say it does. TGA guidance on software-based medical devices makes clear that marketing, labelling and other information supplied with a product can shape its intended purpose. Amendments in February 2021 exempted or excluded certain software from TGA scope, so some products sit outside it, but the boundary follows your claims.
2. Your marketing can move you across that line. A feature release that adds a risk score, a pitch deck line about detecting a condition, or a website claim about improving outcomes can bring software into scope that was previously outside it. The position is set by the manufacturer's stated intended purpose, which means a marketing decision can become a regulatory one.
Whether your software is a regulated medical device, and how it classifies, is a regulatory determination. Those questions belong with the TGA or a qualified regulatory adviser. What upcover can do is discuss the insurance implications of the position you disclose. Talk it through with upcover once you know where you sit, or while you are working it out.
Where software is a regulated medical device, inclusion in the Australian Register of Therapeutic Goods (ARTG) is generally required before supply unless the product is exempt or excluded. Classification and role then shape the placement.
Classification runs from Class I to Class III. Australian medical device classification uses Class I, Class IIa, Class IIb and Class III, with in vitro diagnostic devices classified separately. For software the driver is not sophistication but consequence: how significant the information is to a clinical decision, and how serious the condition it addresses. Where more than one classification rule could apply, the highest applicable class generally governs. Higher classes attract more regulatory scrutiny, and underwriters read them the same way.
The Essential Principles apply regardless of class. Devices supplied in Australia must meet the TGA's Essential Principles covering safety, performance, design and the information supplied with the product. For software this reaches into cybersecurity, version control and lifecycle processes. An insurer asking about your quality management system is asking a version of the same question.
Manufacturer, sponsor and distributor are different roles. The manufacturer designs and produces. The sponsor is the entity that imports, exports or supplies in Australia and carries the ARTG obligations. A distributor sits further down the chain. An Australian business importing a device developed overseas can hold sponsor exposure, which surprises teams who think of themselves as resellers. Get the named insured wrong and the policy may not follow the liability.
Obligations continue after approval. Post-market responsibilities include monitoring performance in the field, reporting adverse events to the TGA, and conducting recalls or corrective actions where needed. These matter to insurance in two ways: they generate the evidence an insurer reviews after an incident, and recall costs are commonly excluded from liability cover.
ARTG status can become a policy condition. Some wordings treat regulatory compliance as a condition or a warranty rather than background. If your position is unresolved or your ARTG submission is in progress, say so at quote stage. Insurers deal with pre-ARTG companies routinely. What they handle badly is finding out later.
Here is the gap that matters most, and it is the reason a health tech company cannot simply buy what a SaaS company buys. Technology professional indemnity commonly responds to claims that your technology or services caused someone a financial loss. A failed integration, a calculation error, an outage that cost a client revenue. That is the exposure the product was built for.
A health tech failure can produce something else. If a clinical decision support tool contributes to a missed diagnosis, or a monitoring platform fails to escalate, the allegation is not that money was lost. It is that a person was harmed. Many technology wordings exclude bodily injury. Which means the exposure most likely to end the business can be the one the policy does not answer.
How that gap gets closed depends on the policy architecture rather than a single product name:
Treatment differs between standalone technology PI, combined liability wordings and specialist life sciences policies. Two policies that look similar on a summary can sit on opposite sides of this question. The practical step is short. Read the exclusions in your current technology PI wording and look for bodily injury. If it is excluded and your product can contribute to patient harm, that is the conversation to have before renewal, not after an incident.
If registered health practitioners deliver care through your platform, two sets of arrangements sit side by side and neither replaces the other.
The practitioner's own position. Registered health practitioners who practise must have appropriate professional indemnity insurance arrangements that comply with the registration standard of their relevant National Board. Those arrangements are not always a policy the practitioner buys. Depending on the applicable Board standard, they may be provided through an employer or another third party. If your platform employs clinicians, you may be part of how they satisfy that standard. Confirm it rather than assume it.
Your company's own exposure. This is separate from practitioner registration compliance, and it comes in two forms.
Direct allegations about the company itself: that the platform selected an unsuitable clinician, set inadequate clinical protocols, failed to escalate, or built a workflow that contributed to harm. These are allegations about your systems, not the clinician's judgement. Vicarious exposure for the clinical acts of practitioners you employ or, depending on the arrangement, contract.
What to check in your policy: whether practitioners are named or covered as insured persons, whether contractors and locums are included or treated differently, whether the definition of professional services covers clinical acts at all or stops at technology failure, and whether cover extends to allegations about the platform's clinical governance. For the difference between the two products, see Medical Malpractice vs professional indemnity insurance.
Health information is the most sensitive category most startups will ever hold, and both the law and the insurance market treat it that way.
Where the small business exemption may not help. The Privacy Act's $3 million turnover threshold does not assist a business that provides a health service and holds health information. Under section 6FB of the Privacy Act 1988, a health service provider generally includes a private sector entity providing a health service, and those entities are covered regardless of annual turnover.
That test is narrower than it first sounds. Not every software vendor that stores health information is providing a health service. A platform delivering care, or one that itself provides a health service, is in a different position from a vendor supplying software to a clinic. Other exceptions to the exemption can still apply, including where a business trades in personal information. Confirm the position for your specific model rather than assuming it either way.
Why insurers care. The Office of the Australian Information Commissioner received 1,205 data breach notifications in the 2025 calendar year, the highest since the notifiable data breaches scheme began in 2018. Health service providers were the most commonly affected sector, accounting for 225 notifications, or 19% of the national total. Financial services followed with 157.
Two obligations with dates attached. Where there are grounds to suspect an eligible data breach, reasonable steps must be taken to assess it within 30 days, then notify affected individuals and the OAIC as soon as practicable. Separately, since 10 June 2025 a statutory tort for serious invasions of privacy has allowed individuals to bring proceedings directly. It is not strict liability for any privacy incident: the cause of action has defined elements including a reasonable expectation of privacy, seriousness of the invasion, and a public interest balancing test, with defences available.
Automated decisions. From 10 December 2026, APP entities must disclose in their privacy policy where personal information is used in certain automated decisions specifically those that significantly affect an individual's rights or interests, subject to the statutory conditions. Whether a triage, scoring or prioritisation feature meets that threshold depends on what the decision does and how it affects the person, so it is worth assessing rather than assuming.
What this means for the cyber policy itself. Insurers underwriting health data look at controls before price: multi-factor authentication, encryption at rest and in transit, access logging, tested backups, and a documented incident response plan. Cyber insurance may cover incident response, forensic investigation, data restoration, business interruption, notification costs and third-party privacy claims, subject to the terms.
Three questions for the policy document: whether regulatory investigation costs are included and at what sublimit, whether the notification cost limit reflects the number of individuals whose records you hold, and whether any security control is stated as a condition or warranty rather than a question you answered once at inception.
Where you also engage practitioners or hold clinical records, state health records legislation in New South Wales, Victoria and the Australian Capital Territory can apply alongside the federal regime. My Health Record obligations apply where you participate in that system. For cost detail, see how much does cyber insurance cost.
Founders usually ask this as a stage question. For health tech it is better answered as a list of moments, because these are the points where the answer changes.
For the general startup picture across stages, see when does a startup need insurance.
These are the two moments where insurance most often blocks progress, and both reward early attention.
Trial activity must be expressly included or separately arranged. It is commonly excluded from standard technology and healthcare policies, so assuming an existing one travels is a mistake worth avoiding. Depending on the trial and the insurer, cover may be written as a standalone trial policy or as part of a specialist life sciences programme.
What sits inside a trial placement:
Human research ethics committee requirements sit alongside the insurance and run on a different timeline. Sponsors and sites commonly specify limits, named insureds and evidence before a participant is enrolled. Trial placements may require specialist underwriting and longer lead times than a standard technology policy.
Health services ask for evidence of insurance before granting system access, patient contact or data flow. What they commonly request: a certificate of currency naming the correct entity, specified professional indemnity and public liability limits, cyber cover, and sometimes a contractual indemnity your policy has to be able to support. Requirements vary between health services and between contracts, so the schedule you are given is the one that matters.
The practical failure here is timing rather than cover. A pilot agreed in principle stalls while insurance is arranged, and the delay lands on the startup. Have a pilot or trial schedule in front of you? Bring it to upcover and the requirements can be checked against the cover before you sign.
Exclusions differ between insurers, so treat each of these as a question for your policy rather than a rule.
The policy wording, schedule and any endorsements determine cover, not the product name.
The direct answer: there is no reliable flat average, and any single figure quoted for health tech would mislead more than it helps. The spread is too wide, because the same headcount and revenue can sit either side of a regulatory line.
Two health tech companies with identical headcount and revenue can price very differently. One tracks steps and makes no clinical claim. The other produces output a clinician relies on when deciding treatment. Same team, different risk class. So rather than a number, here is what moves it, heaviest first.
Your TGA status and clinical output. Whether the software has an intended medical purpose, its classification, and how directly its output influences a clinical decision. This moves the price more than anything else on the list.
Practitioner involvement. Whether registered practitioners deliver care through the platform, and on what basis.
Data volume and sensitivity. How many patient records, what fields, and whether identifiers sit alongside clinical information. Your security controls affect this materially.
Contract requirements. Hospital, health service and government contracts often set the limit floor, so the number is frequently decided by your customers rather than your risk appetite.
Then the ordinary drivers: turnover, funding stage, board composition, claims and incident history, cover level and excess.
On limits. Contract requirements usually decide this. Where they do not, work from the worst realistic claim rather than a round number. Public liability options commonly range from $5 million to $20 million and are contract-driven. Cyber limits for smaller businesses commonly range from $250,000 to $5 million.
What does not fit a price band. Clinical trials, higher-class devices and anything approaching a life-sustaining function are specialist placements. Those move to a broker conversation rather than an online quote, and the honest answer on price is that it depends on the technical file.
Run your current schedule against these before renewing. They are ordered by how often they turn out to matter.
Having these ready turns a vague conversation into a real quote.
Ready to compare? Explore health tech insurance through upcover with those details to hand. Availability and terms depend on insurer acceptance.
Health tech placements split into two paths, and knowing which one you are on saves time.
Straightforward technology risk. Where the product makes no clinical claim, sits outside TGA scope and the exposure is data and technology performance, technology professional indemnity and cyber can often be arranged through a standard process for eligible businesses.
Specialist placement. Where the software is a regulated device, contributes to clinical decisions, engages practitioners or involves trials, the placement needs an underwriter who reads technical files. That is a broker conversation, and it takes longer.
If a hospital pilot or trial is waiting on evidence of insurance, say so early. Certificate turnaround is usually straightforward once cover is bound, but arranging the cover is where the time goes.
upcover is a digital-first insurance broker helping Australian small businesses get the right insurance without the paperwork or phone queues. upcover arranges insurance for health tech businesses with access to 80+ insurance partners, including technology professional indemnity, cyber, medical malpractice, public and products liability and directors and officers cover.
For the broader startup picture, see the startup insurance guide. For what investors review, see insurance in startup due diligence. For the wider sector view, see technology, media and digital insurance.
upcover Pty Ltd ABN 17 628 197 437 is a Corporate Authorised Representative (CAR 1299211) of Experience Insurance Services Pty Ltd ABN 41 657 596 506, AFSL 539078.
There is no single law requiring a health tech company to hold insurance. Workers compensation is compulsory once you employ staff, and registered health practitioners must have appropriate professional indemnity arrangements under their Board's registration standard. Beyond that, most requirements are contractual: hospitals, health services, investors and trial sponsors commonly specify cover and limits.
It depends on your intended purpose rather than your technology. Under section 41BD of the Therapeutic Goods Act 1989 (Cth), software intended for a medical purpose such as diagnosis, monitoring or treatment may be a regulated medical device. Wellness apps without therapeutic claims commonly sit outside scope, but a feature or marketing claim can move a product across the line. Classification is a regulatory determination for the TGA or a qualified adviser.
Often not. Technology PI commonly responds to financial loss, and many wordings exclude bodily injury. Where your product can contribute to patient harm, check the exclusions and consider whether a wording that includes bodily injury, malpractice cover or product liability is needed alongside it.
It may, where the policy's product definition expressly captures the software or the device it runs on. Some policies define products in a way that assumes physical goods. If your software is regulated as a device, confirm the definition covers it rather than relying on the classification alone.
Healthtech insurance is a description rather than a product, covering the mix a digital health business assembles. Medical software insurance and medical device liability placements are built around a regulated product, its classification and the sponsor and manufacturer roles. A health tech company supplying a regulated device may need elements of both.
Requirements vary by health service and contract. Common requests are evidence of cover naming the correct entity, specified professional indemnity and public liability limits, cyber cover, and sometimes an indemnity your policy needs to be able to support. Ask for their insurance schedule before signing.
The Privacy Act's small business exemption does not assist a business that provides a health service and holds health information, which is covered regardless of turnover under section 6FB. Whether your model falls inside that test is worth confirming. Either way, health data breaches carry remediation, notification and commercial consequences that arrive well before any threshold.
Generally not. Trial activity needs to be expressly included or separately arranged, and it is commonly excluded from standard technology and healthcare wordings. Cover may be written standalone or within a specialist life sciences programme, and sponsors and ethics committees commonly expect no-fault compensation alongside legal liability.
Sometimes, but territory and jurisdiction clauses need checking rather than assuming. North American exposure commonly attracts different terms, higher pricing or exclusion, because the litigation and regulatory environment differs. Tell your insurer before you sell there, not after.
Once cover is arranged and the insurer has accepted the risk, a certificate is usually straightforward. The time goes into arranging cover, which depends on your regulatory position, the information available and whether the risk needs a specialist underwriter. If a pilot is waiting on it, start earlier than feels necessary.
This article is general information only. It does not take into account your objectives, financial situation or needs, and is not personal advice. It does not constitute legal, regulatory, medical or clinical advice. Whether software is a regulated medical device, its classification and any Australian Register of Therapeutic Goods obligations are regulatory determinations that should be confirmed with the Therapeutic Goods Administration or a qualified regulatory adviser. Privacy, therapeutic goods and health records obligations are set by legislation and may change. Regulatory references and statistics in this article were current at the time of writing and should be checked against the source before you rely on them. Insurance market observations describe common practice rather than universal rules, and cover types, limits, inclusions, exclusions and policy structure vary between insurers and policies. All insurance products arranged through upcover are subject to the terms, conditions, limits and exclusions in the relevant policy wording, schedule, endorsements and any applicable Product Disclosure Statement, so read those documents and consider your circumstances before deciding whether a product suits you. upcover Pty Ltd ABN 17 628 197 437 is a Corporate Authorised Representative (CAR 1299211) of Experience Insurance Services Pty Ltd ABN 41 657 596 506, AFSL 539078, and arranges insurance products with selected insurers and underwriters rather than the whole market.
We are digitising commercial insurance and risk management for small, mid-market and technology businesses. We work with a global network of underwriters, challenging legacy brokers and delivering market leading coverage to our customers.