Sam and two co-founders run a mobile app studio in Redmond with eight developers. For years they built apps for startups that never asked about insurance. Then a large healthcare company chose them to build a patient scheduling app, and procurement sent over a vendor questionnaire.
Section six: technology errors and omissions of $2 million, network security and privacy liability of $2 million, and proof within ten business days.
What he asked for
Whatever gets the contract signed.
What the review found
The studio had no professional liability at all. Its only policy was a business owners policy for the office. A bug in a scheduling app that double-books patients or loses appointments is a claim for financial loss caused by the studio's work. That is professional liability, specifically technology E&O, and the BOP excluded it.
Healthcare data raised the cyber stakes. The app would handle patient names, appointment details, and possibly health information. The client's contract required the studio to cover breach costs caused by its code or its systems.
The contract's limitation of liability was uncapped. The studio's liability for data breaches was carved out of the contract's general cap. That is common in healthcare contracts and important to know about, even when it cannot be negotiated away.
Eight developers, three recent hires, no EPLI.
What we put in place
We placed a combined technology E&O and cyber liability policy, the structure most tech clients expect. One policy covers the studio's errors in software and services, security and privacy liability to third parties, and the studio's own breach response costs, each at $2 million. The carrier's application asked about code review, testing, access controls, and multi-factor authentication. The studio had solid practices for most of it and tightened two things during the application.
Because the policy was new, we set the retroactive date as early as the carrier allowed, giving some protection for apps the studio had shipped in prior years.
We added employment practices liability, priced modestly for a team of eight.
Why it mattered
The certificate went to procurement on day eight, and the contract was signed. More useful for the long term: the studio now answers the insurance section of any enterprise questionnaire the same afternoon it arrives, which has become a small competitive advantage in pitches against larger firms.
If you build software for clients
- Your BOP almost certainly excludes errors in the software you deliver
- Buy tech E&O and cyber together; clients usually ask for both
- Read the contract's limitation of liability, especially data breach carve-outs
- Set the earliest retroactive date you can get on a new policy
See how we work with technology companies, or get a free policy review before your next vendor questionnaire.