3 April 2026

Insurance levels for healthcare and MedTech suppliers: avoiding last-minute fails

Insurance is one of those requirements that looks simple until it causes a problem. A tender asks for employer’s liability, public liability, product liability or professional indemnity at a specified level. Suppliers assume it is just a matter of sending over the current certificate. However, this is often where late-stage problems start.

For healthcare and MedTech suppliers, insurance is rarely just an administrative check. It intersects with contract terms, product or service risks, data handling responsibilities, and the promises made in the bid. At Bidding, we often see suppliers discover too late that the cover they usually carry does not line up neatly with the wording in the tender or the liabilities in the draft contract.

The result is not always a hard fail, but it can still cause delay, clarification risk or a difficult conversation with brokers and internal stakeholders at exactly the wrong point in the process.

Why this issue appears late so often

Insurance problems often surface late because suppliers tend to check the certificate instead of the requirement.

A certificate may look fine on its own, but the tender may ask for something more specific. That could mean a higher level of cover, a different class of insurance, or a requirement for product liability where the supplier only focused on public liability. There could also be wording that connects insurance directly to the draft contract. Once that gap is found, the supplier may need to check affordability, availability or internal appetite under time pressure.

This matters more in NHS procurement because contract templates and purchase order terms are already set up to deal with risk allocation formally. NHS England’s terms and conditions page makes clear that separate model terms apply for goods, services, combined contracts and purchase order arrangements under both the Procurement Act 2023 and PCR 2015 routes.

That means insurance should not be reviewed in isolation. It should be read alongside the actual contract model the buyer is using.

How to think about risk

The wording in a tender can sometimes encourage suppliers to think only in policy names. A better starting point is to ask what risk the authority is trying to manage.

In a basic service contract, the focus may be on employer’s liability, public liability, and professional indemnity. For a MedTech supplier, product liability may take on greater importance. For a digital health supplier, professional indemnity and cyber-related risks may be more crucial than typical goods-based assumptions imply.

If the service involves handling patient data, remote access or digital products, the wider security and information governance picture can also affect what level and type of cover makes sense. That is one reason this topic naturally overlaps with Cyber Essentials Plus and information security for health and MedTech suppliers and common NHS contract terms.

Not every NHS buyer asks for the same insurance schedule. However, the requirement typically reflects the delivery and liability profile of the specific contract.

Where healthcare and MedTech suppliers often get caught out

There are a few recurring patterns here.

One is assuming that existing annual cover will be enough because it has been enough elsewhere. NHS opportunities do not always use the same thresholds as other sectors, and some buyers will specify levels that are normal for them but not for your wider client base.

Another is treating policy titles as interchangeable. Public liability, product liability and professional indemnity can sound familiar, but they do different jobs. A supplier can be well insured in one area and underinsured in another.

A third is forgetting about scope. Even where cover exists, the business still needs to check whether the legal entity bidding is the entity insured, whether the territorial scope works, whether subcontracted activity is covered and whether the nature of the goods or services fits what the insurer expects.

For MedTech suppliers in particular, the difficult area is often product-related exposure. If the contract involves devices, consumables, components or anything with a patient safety implication, product liability cannot be treated as an afterthought. And if the service includes training, installation, maintenance or advisory input, professional indemnity can become just as important.

Why the draft contract matters as much as the tender pack

Insurance is one of the clearest examples of why contract review should happen before submission, not after award.

NHS England’s Standard Contract materials for 2025/26 and 2026/27 show how detailed the service conditions, general conditions and supporting schedules are for healthcare contracts, while its separate goods and services terms page provides the current model documents for non-clinical goods, services and purchase orders.

That matters because insurance requirements are usually tied to a wider liability structure. A supplier might be comfortable with the insurance levels in the tender summary, but less comfortable once indemnities, data provisions, product obligations, service credits or termination risks are reviewed in the full contract. If those pieces are not looked at together, the bid can end up promising something the business is not actually set up to carry.

What buyers are usually looking for

Most buyers are not trying to create a technical insurance trap. They are trying to reassure themselves that the supplier has the financial and risk protections needed for the work.

That usually means they want evidence that:

NHS Supply Chain’s supplier information makes it clear that suppliers remain subject to structured contract and supplier management processes beyond tender stage. This reinforces the point that risk and assurance are not only checked at submission.

A sensible pre-submission check

This is one of those areas where a short internal checklist can save a lot of pain later.

Before submitting, it is worth confirming:

Suppliers that do this early are in a much better position than those treating insurance as a document collection exercise at the end.

Where this becomes more than a compliance issue

Insurance can look like a narrow procurement requirement, but it often tells you something broader about bid readiness.

If the required cover is hard to obtain, unusually expensive or commercially awkward, that can be an early signal that the contract risk profile needs more scrutiny. It may mean the draft terms need a closer look, the delivery model needs adjustment or internal stakeholders need to revisit whether the opportunity is attractive on the terms offered.

That is why stronger suppliers tend to review insurance alongside the wider evidence stack. Carbon Reduction Plans and Net Zero, Evergreen Sustainable Supplier Assessment, the Modern Slavery Assessment Tool (MSAT), cyber controls and contract terms all contribute to the buyer’s overall view of risk and readiness. Insurance is one part of that picture, but it is often the part that exposes whether the rest has been joined up properly.

Final thought

Insurance levels do not usually fail bids because suppliers have ignored them completely. They fail bids because they are reviewed too late, too narrowly or without enough reference to the contract and delivery model.

For healthcare and MedTech suppliers, the safest approach is to check the insurance requirement early, map it against the actual risks in the opportunity and resolve any mismatch before submission pressure starts to build. That is normally the difference between a straightforward evidence check and a last-minute scramble.