
Healthcare due diligence in 2026: the billing problem that surfaces after close
Healthcare due diligence in 2026: the 8 review areas, the billing and overpayment trap buyers inherit, and how to run a data room for healthcare due diligence.
Insurance due diligence is the review of a target company's insurance programme and loss history before an acquisition closes. It answers two questions: is the business actually covered for the risks it runs, and what will that cover cost the buyer once the shares change hands?
Insurance is the workstream buyers most often delegate and least often read. The broker reports that the programme is broadly adequate, and nobody notices that the directors and officers policy is claims-made, that the seller has no intention of buying run-off, and that the buyer has just inherited six years of unfunded exposure for acts it had nothing to do with. This guide covers the 12 policy lines, how loss runs and the modification rate set the price, what transfers in an asset deal versus a stock deal, and how to run the review without emailing claims files to five parties.
Insurance diligence is unusually multi-party. The broker, the lender, the seller's risk manager, and often a representations and warranties underwriter all read the same claims history. A data room for insurance due diligence gives each of them one link with its own folder scope. Section 9 covers the setup step by step.
Insurance due diligence is a structured review of everything a target does to transfer risk to an insurer: the policies it buys, the limits and retentions it carries, the claims it has made, the collateral it has posted, and the insurance obligations it has promised to customers, landlords, and lenders. It is commissioned by the buyer after a letter of intent, performed by a broker or a specialist risk advisory team, and delivered as a report that prices the programme on a go-forward basis and flags gaps.
The workstream sits next to financial and legal diligence but asks a different question. Financial diligence asks what the business earned, legal diligence asks what it owes, and insurance diligence asks what happens when something goes wrong and whether the cost lands on the insurer or on the buyer's income statement. On a labour-heavy target the answer moves the model more than buyers expect, because insurance is often the third or fourth largest operating cost after payroll, materials, and rent.
The review also earns its place because insurance is the mechanism by which many other diligence findings get resolved. An environmental exposure, a product recall risk, or an employment claim found elsewhere in the process usually gets handled with cover rather than with a price adjustment, and the insurance reviewer is the person who can say whether that cover exists and what it costs.
Be precise about one distinction. Insurance due diligence reviews the target's own operational programme. Representations and warranties insurance is a transactional product that pays the buyer if the seller's representations turn out to be untrue. They are often placed by the same broker and they are frequently confused. A policy covering a breach of a compliance representation does nothing about a workers' compensation programme running at a 1.24 experience modification rate.
A complete insurance due diligence review covers 12 lines. Not every target buys all 12, and the absence of a line is itself a finding: a manufacturer with no product liability cover, a professional services firm with no errors and omissions policy, or a business holding payment data with no cyber policy each carries an uninsured exposure the buyer owns from closing.
The reviewer works through each line the same way. What limit is carried, what retention sits underneath it, whether the policy is occurrence or claims-made, what the loss history looks like, and what the go-forward premium will be under new ownership. That last point matters most, because a target inside a group programme buys at rates a standalone business of the same size rarely earns.
| # | Policy line | What the reviewer checks | Typical red flag |
|---|---|---|---|
| 1 | Property | Values declared, valuation basis, business interruption limit | Values understated, so coinsurance reduces any claim |
| 2 | General liability | Limits, aggregate erosion, additional insured endorsements | Aggregate already eroded by open claims |
| 3 | Commercial auto | Fleet schedule, driver records, hired and non-owned cover | Personal vehicles used for work with no non-owned cover |
| 4 | Workers' compensation | Experience modification rate, class codes, payroll audit history | Modification rate above 1.00 and rising |
| 5 | Umbrella and excess | Attachment points, following-form wording, gaps in the tower | A gap between the primary limit and the excess attachment |
| 6 | Directors and officers | Claims-made status, run-off availability, entity cover | No run-off budgeted at closing |
| 7 | Employment practices | Retention level, open matters, wage-and-hour sublimit | Wage-and-hour claims excluded or sublimited to a token amount |
| 8 | Professional liability | Retroactive date, scope of professional services covered | Retroactive date later than the start of trading |
| 9 | Cyber | Limit against record count, ransomware and business interruption cover | No policy at all despite holding customer data |
| 10 | Environmental | Site coverage, historic operations, pollution legal liability | Historic operations excluded from a current policy |
| 11 | Crime and fidelity | Employee dishonesty limit, social engineering endorsement | No social engineering cover on a payments-heavy business |
| 12 | Product liability | Recall cover, completed operations, geographic scope | US exposure excluded on a policy written outside the US |
Two lines deserve more attention than they get. Cyber is the most frequently missing, and its limit is meaningless unless set against the number of personal records held or the daily revenue at risk from an outage. Environmental is the line where the exposure predates the policy: a pollution liability policy written in 2024 will not necessarily answer contamination created in 1998.
The list below is also the folder structure a seller should build before the room opens, because it maps to how the broker will work.
| Document | Why the reviewer wants it | Typical count | Sensitivity |
|---|---|---|---|
| Policy schedules and full wordings | Limits, retentions, endorsements, and exclusions as actually written | 12 to 25 | Medium |
| Loss runs, 5 policy years | Claims frequency and severity, which drive go-forward premium | 10 to 20 | High |
| Experience modification worksheets | Workers' compensation pricing and whether it is trending up | 3 to 5 | Medium |
| Open claim files and reserves | Reserve adequacy and any claim likely to breach a retention | 5 to 40 | Very high |
| Certificates of insurance issued to customers | What the target has promised contractually | 20 to 200 | Low |
| Collateral and letters of credit | What the buyer must replace at closing on deductible programmes | 2 to 6 | High |
| Safety programme and loss control reports | Whether the loss trend is being actively managed | 5 to 15 | Medium |
The sensitivity column is what drives how the room is configured. Open claim files are the most sensitive documents in the set, because they contain employee names, medical detail, litigation strategy, and reserve estimates that the seller would not want a competitor or a departing employee to read. They should not carry the same permissions as the policy schedules.
Loss runs are the most informative document in insurance due diligence. A loss run is the insurer's own record of every claim made under a policy: date of loss, description, amount paid, amount reserved, and whether the claim is open or closed. Five policy years is the standard request.
What the reviewer looks for is not the total but the shape. High frequency with low severity means an operational problem, usually too many small slips, vehicle incidents, and strains. That is expensive but fixable, and it responds to a safety programme within two or three policy years. Low frequency with high severity means a catastrophic exposure that has already materialised once, and it prices the buyer out of the market for several renewals regardless of operational fixes.
Reserves matter as much as payments. An open claim carries a reserve, the insurer's estimate of what it will ultimately pay, and reserves move. A workers' compensation claim reserved at $40,000 in year one can develop into a $400,000 claim by year four as the medical picture becomes clearer. On a large-deductible programme that development is the buyer's cost, not the insurer's, which is why open claims get their own line in the diligence report rather than being netted into a total.
For workers' compensation specifically, the pricing mechanism is the experience modification rate, which compares a company's actual losses against the expected losses for its industry and payroll size, with 1.00 representing the industry average. A rate of 1.24 means the company pays roughly 24 percent more than an average peer for identical payroll. On a business with a $12M payroll in a hazardous class code, the gap between 1.24 and 0.85 is a six-figure annual cost that flows straight into the deal model. The rate is also forward-looking, because it is calculated on a rolling multi-year window: a rate that was 1.05 three years ago and is 1.24 today will keep climbing even if the safety programme is fixed tomorrow.
This is the finding that most often surprises a first-time buyer, and it is entirely avoidable. Policies come in two shapes. An occurrence policy responds to events that happened during the policy period whenever the claim is eventually made, which is why a general liability policy from 2019 still answers an injury that occurred in 2019 even if the claim arrives in 2026. A claims-made policy responds only to claims first made while the policy is in force.
Four of the twelve lines are usually written claims-made: directors and officers, employment practices, professional liability, and cyber. On those lines, letting the policy lapse does not just end cover for the future. It ends cover for the past. The moment the seller's directors and officers policy is cancelled at closing, every act and omission of the previous management team becomes uninsured, and the claim that arrives eighteen months later has nowhere to go.
The remedy is run-off cover, also called tail cover or an extended reporting period, which keeps the expiring policy alive for claims arising from acts before closing but reported afterwards. Six years is the market standard on directors and officers cover in a private company sale, chosen to line up with common limitation periods, and brokers commonly quote it at roughly 200 to 300 percent of the expiring annual premium as a single payment at closing.

Open claim files go to the broker and the underwriter, not to the lender or the operational reviewers.
Three practical points follow. Run-off is bought once and cannot be bought later, so it belongs in the purchase agreement rather than in a post-closing checklist. Who pays is a negotiation, and the usual outcome is that the seller pays because it protects the seller's own former directors, but a buyer who never raises it will end up paying. And the retroactive date on any replacement claims-made policy should be checked, because a new policy dated at closing offers nothing at all for prior acts.
Deal structure changes the insurance answer completely, and it is worth being explicit because the two cases look nothing alike.
In a stock purchase, the buyer acquires the legal entity and the entity keeps its policies. Occurrence cover for prior years stays where it is, historic claims stay with the same insurers, and the practical work is a change-of-control notice to each carrier plus a decision about whether to keep the programme or move onto the buyer's own policies at renewal. Even here the reviewer checks change-of-control clauses, because a target inside a group programme falls out of that programme at closing.
In an asset purchase, the policies stay with the seller's entity because they belong to that entity. The buyer acquires machines, contracts, and employees, and acquires no insurance at all. That produces two exposures. Cover has to be bound before closing rather than after. And nothing insures the buyer for something that happened before closing, even where the liability transfers with the assets under successor liability principles: a product manufactured last year that injures someone next year is an exposure the buyer may own with no policy responding to it.
Collateral deserves its own note because it is a cash item rather than an expense item. A business running a large-deductible workers' compensation programme has usually posted a letter of credit so the insurer is secured for the deductible layer it pays out and bills back. That collateral is supported by the seller's credit and does not transfer, so the buyer posts replacement collateral at closing. On a mid-sized labour-heavy business that is a seven-figure draw on the buyer's own facility that nobody modelled.
The last place a reviewer looks is usually where the biggest surprise sits: the target's own contracts. Insurance obligations are written into customer master agreements, subcontracts, property leases, and loan documents, drafted by the counterparty's lawyers rather than by the target's broker, and nobody checks whether the two match until diligence.
Three obligations recur. Minimum limits specify how much cover the target must carry, so a target with a $2M general liability limit that signed contracts requiring $5M is in breach of every one. Additional insured status extends the policy to the customer for liability arising out of the target's work, which needs a specific endorsement and is not automatic. Waiver of subrogation stops the insurer recovering against the customer after paying a claim, and also requires an endorsement.
| Contract requirement | What it obliges the target to do | How it fails in practice |
|---|---|---|
| Minimum limits | Carry a stated limit per line for the contract term | Limits reduced at a renewal to save premium, contracts never re-read |
| Additional insured | Endorse the customer onto the policy | Certificate says additional insured, no endorsement was ever issued |
| Waiver of subrogation | Waive the insurer's recovery rights against the customer | Endorsement missing, insurer sues the customer after paying |
| Primary and non-contributory | Respond before the customer's own policy | Wording absent, both insurers argue and the customer escalates |
| Notice of cancellation | Give the customer 30 days notice of any lapse | Policy changed at renewal, notice never sent, customer alleges breach |
| Landlord and lender interests | Name the landlord or lender on property cover | Property sold or refinanced, schedule never updated |
There is a documentation trap here as well. A certificate of insurance is evidence, not cover: it is a one-page broker summary that explicitly disclaims conferring rights. A certificate stating the customer is an additional insured proves nothing unless the endorsement exists on the policy. During diligence that means sampling. Pick the five largest customer contracts, read the insurance clause, then find the matching endorsement rather than accepting the certificate.

Open claim files carry employee names and medical detail, so the folder is view-only and watermarked per viewer.
A lower middle market private equity fund agrees to acquire Kestrel Facilities Services, a $48M revenue commercial cleaning and building maintenance company with 620 employees across three states. The business is labour-heavy and vehicle-heavy, which means the insurance programme is dominated by workers' compensation and auto, and it is exactly the profile where insurance due diligence changes the model rather than confirming it.
The broker requests five years of loss runs and the current policy schedules on day three. Total insured premium comes to $1.42M a year: workers' compensation $780,000, general liability and commercial auto together $310,000, umbrella and excess $130,000, property $95,000, management liability covering directors and officers plus employment practices $70,000, and cyber $35,000.
Worked scenario. Workers' compensation is 55 percent of the programme, which is why the 1.24 experience modification rate is the finding that matters most.
Three findings emerge. The experience modification rate is 1.24 and was 1.05 three years ago, so the fund models premium at $1.42M rather than the $1.15M the seller allocated internally. The management liability policies are claims-made with no run-off budgeted, so the fund negotiates a six-year run-off into the purchase agreement at the seller's cost. And Kestrel runs a $250,000 per-claim deductible on workers' compensation behind a $1.5M letter of credit posted by the seller, which the fund must replace at closing.
A fourth finding is contractual. Sampling the six largest cleaning contracts shows four require $5M of general liability cover and additional insured status, while Kestrel carries $2M primary with a $5M umbrella and has no endorsement on file for two of them. The remedy costs a few thousand dollars and takes a week, but only because someone read the contracts before closing.
Diligence runs through a room holding 180 documents across nine folders, with the broker, the lender, and the representations and warranties underwriter each on their own link. The open claims folder is view-only and watermarked, because it names 23 injured employees.
The most common mistake is starting the insurance review after the model is fixed. Insurance findings are cost findings, and a $270,000 annual premium increase discovered in the last week of exclusivity is very hard to reflect in a price already agreed in principle. The broker should have loss runs in week one, not week five.
The second is accepting certificates of insurance as proof of cover. Sample the largest contracts and verify against the policy endorsements instead. If an additional insured endorsement cannot be produced, it does not exist.
The third is forgetting run-off. Four of the twelve lines are usually claims-made, run-off can only be bought at closing, and the party who benefits most is the seller's own former board. It belongs in the purchase agreement alongside the escrow and the working capital peg. Our guide to the M&A due diligence checklist covers where this sits in the wider process.
The fourth is treating a group-programme target as if it keeps group pricing. Ask the broker to price the programme standalone and put the difference in the model as a permanent cost increase.
The fifth is circulating claims files carelessly. Open claim files name injured employees, describe medical treatment, and set out litigation strategy. Emailing them to a broker, a lender, an underwriter, and two advisors creates a privacy exposure the seller carries even if the deal never completes. The data room checklist covers how to structure this properly.
A data room for insurance due diligence is not the same artifact as the financial room. The financial folder holds commercially sensitive numbers. The claims folder holds employee names, medical detail, and reserve estimates, which are sensitive in a different and more regulated way. That difference should change how the room is built and who gets which link.
Papermark is a secure, fully customizable, and developer-friendly data room built for modern dealmakers, with page-by-page analytics, dynamic watermarking, and transparent pricing (open-source and self-hosting available).

An insurance due diligence data room with one folder per policy line, so permissions differ by folder rather than by document.
Most insurance diligence still runs over email, because the broker asks for loss runs and the seller's risk manager attaches them to a reply. There are four reasons a dedicated data room for insurance due diligence earns its place instead. If you are still choosing a platform, our comparison of the best virtual data rooms covers pricing model, permissions, and compliance across the main providers.
Claims files contain personal and medical data. An open workers' compensation file names an injured employee and describes their treatment. Under GDPR that is special category data, and a breach affecting it triggers a 72-hour notification duty. Emailing those files to four external parties is a processing decision nobody documented, and the seller carries the exposure even if the deal never completes.
Four parties need four different views. The broker needs everything. The lender needs certificates and collateral and nothing else. The representations and warranties underwriter needs loss runs and schedules but has no business reading individual claim files. A shared drive gives you one permission set; a data room for insurance due diligence gives you one per link over the same documents.
Requests arrive in waves. The broker asks for loss runs, then for the three open claim files they reference, then for reserve development on one of those. Across 180 documents and 40 open questions an email thread loses track, and the same question gets asked twice.
The disclosure record matters at claim time. If a representations and warranties claim arises two years after closing, the underwriter asks what was disclosed and when, because anything the buyer knew before binding is excluded. A per-visitor audit log answers that. An inbox does not.
The rest of this section is the practical setup: five steps that handle all four.
Create one folder per policy line, plus a claims folder, a collateral folder, and a contracts folder for the certificates and customer insurance clauses. That structure is what makes differentiated access possible later, and it matches how the broker works, which shortens the review.
Upload in bulk by dragging the folder tree straight in. Automatic file indexing on Data Rooms Plus builds and maintains the index as documents arrive, which matters here because loss runs land in waves.

Drag the policy and claims folder tree in as a whole; the index builds itself as files arrive.
This is where an insurance room differs most from a financial one, because one folder is materially more sensitive than the rest.
| Reviewer | Folders granted | Rights |
|---|---|---|
| Buyer's insurance broker | All 12 lines, claims, collateral, contracts | View and download |
| Representations and warranties underwriter | Policy schedules, loss runs, safety reports | View only, watermarked |
| Lender | Certificates, collateral, property schedules | View only |
| Buyer's operational reviewer | Safety programme and loss control | View only |
Granular file-level permissions are set per link rather than per user, so each party gets one link carrying its own folder scope, email allowlist, and download rule. Access is link-based, so no reviewer creates an account, which removes the friction that makes a busy broker fall back to email.

Permissions are set per link, so the lender and the underwriter see different folders of the same insurance room.
Set the claims folder to view-only and turn on dynamic watermarking, which stamps every page with the viewer's email, IP address, and timestamp as it renders. On files naming individual employees, that is the difference between an untraceable leak and a traceable one. Screenshot protection adds a further deterrent on the open claim files.
State the honest limit: a downloaded file is legally treated as read, and no platform can recall it. That is why download is disabled rather than discouraged on this folder.
The broker asks about reserve development, the underwriter asks the same question a week later, and the risk manager answers both separately with slightly different numbers.
The Q&A module attaches each question to the document that prompted it, with permissions controlling who sees which threads, so the lender never reads the underwriter's questions. Answers publish to one group or to everyone, and the log exports for the closing file.
Page-level analytics show which reviewer opened which document, when, and for how long. In insurance diligence that is an early warning: a broker who has spent thirty minutes inside one open claim file has found a reserve problem, and you will hear about it a week before the report lands.

Per-visitor analytics show which policy and claims documents each reviewer opened and for how long.
After closing, data room freeze makes the room immutable and exports it as an archived ZIP with a certificate. If a representations and warranties claim arises two years later, that archive is the record of exactly what was disclosed, to whom, and on what date.

Papermark is our #1 VDR provider for M&A transactions right now. In two deals we used custom branding, dynamic watermarking, and granular permissions.
Tyler
The Data Rooms plan is €99/month with a 7-day free trial and includes 3 team members, unlimited data room visitors, unlimited data rooms, unlimited documents, custom domain, dynamic watermarking, NDA agreements, and granular file-level permissions. Data Rooms Plus at €249/month adds 5 team members, the Q&A module, the audit log, automatic file indexing, and SOC 2 Type II. Data Rooms Premium at €549/month adds 10 team members, AI redaction, full API access, SSO, and whitelabeling. Data Rooms Unlimited at €999/month removes per-seat charges entirely, so teams that add reviewers mid-deal pay one number regardless of headcount, and it carries every Premium capability including AI redaction. For a buyer running several acquisitions a year, unlimited data rooms under one subscription means one insurance room per deal with no per-project fee.
No credit card required.