As internal and external hospital professional liability (HPL) risks multiply, hospital risk executives emphasize the importance of collaboration, harnessing analytical tools to better understand emerging risks, and the advantages of the captive structure in managing risk. Once mostly confined to clinical risk management, hospital risk management today encompasses a wide variety of areas including sexual abuse and misconduct, cybersecurity, artificial intelligence and technology risk, clinical burnout—and more.
As US hospitals consolidate and purchase physician practices, hospital risk management programs are growing larger, offering risk managers the opportunity to use their captives and risk retention groups to mitigate a wide variety of risks, creating an enterprise risk management structure tailored to their needs.
“The advantage of a captive is the control over how you strategize and manage and apply your professional liability program,” said Elaine Ziemba, senior vice president and chief risk officer at Stanford Medicine Enterprise. “I can self-fund for a lot of things in my captive and recognize that how I do things is within our control versus within the control of an insurer, and I can, quote, be more creative, unquote, with what risks I put into that captive.”
As the hospital enterprise risk management profession matures, risk management executives prioritize a holistic approach to managing both internal and external risks. In today’s uncertain environment, risks such as sexual abuse and misconduct, cybersecurity, and clinical burnout are joined by emerging risks such as supply chain management and artificial intelligence and technology.
In the second part of our two-part series on HPL risk, you’ll gain a broader understanding of the tools that hospital risk executives use to manage risk, their take on how risk management approaches have evolved, their views on the outlook for HPL over the next three to five years, and commentary on a variety of risks faced within HPL.
Advantages of the Captive Structure
Captives are licensed insurance companies created, maintained, and operated by hospitals and health systems. There are several different types of captives, including a single-parent or pure captive, group captive, and a risk retention group captive. A single-parent or pure captive is a traditional captive created by a single organization to manage potential liabilities. A group captive is a self-insurance company formed by a group of businesses to manage risk. A risk retention group (RRG) captive is owned by its policyholders, who are the insured within the captive. An RRG is primarily designed to provide liability coverage and can’t include workers’ compensation or property insurance.
Many captives are formed in the US. Vermont, North Carolina, Delaware, and Hawaii are the most popular domestic domiciles; the most popular international domiciles are the Cayman Islands and Bermuda. Capitalization requirements vary depending on jurisdiction. Captives tend to dominate the hospital and health system market, while commercial MPL carriers tend to dominate physician groups and smaller physician practices.
Hospital risk executives embrace captives for the flexibility and control they offer in managing risk.
For Ziemba, Stanford’s captive allowed her to solve what might seem like a small problem for the hospital and employees who drive from one location to the other during their workday: a gap in coverage for car accidents. “There’s a situation where the captive structure helped us solve a problem,” she said. “Like many other health systems, when we buy an auto policy for our organization, it insures any of your vehicles, your Stanford posted vehicles for those whose primary function is driving. But if you’re an employee going from one of our hospitals to another and you have an accident, we have classically said, ‘Call your insurer.’”

“But now insurers are saying that if the accident occurred in the course of a work gig, the employer is responsible,” she continued. “We didn’t have a mechanism for that, which put employees in a squeeze of having no coverage for an accident. We understand why the insurers don’t necessarily feel inclined to cover it. So the captive allowed us creativity to design a solution to cover our employees in the event of an accident.”
Hospital Enterprise Risk Management
Hospital enterprise risk management is by nature strategic rather than reactive. That means risk executives focus on building multidisciplinary enterprise risk management capabilities across the enterprise. Hospital risk executives collaborate with teams across the enterprise, beginning with the board and C-suite, as the chief risk officer provides advice on the hospital’s overall risk profile and most appropriate risk management strategies to mitigate those risks. From there, risk committees in clinical operations, finance, legal, IT, facilities, and human resources monitor risks and implement proactive risk management practices.
“I believe in a strong organizational approach to risk management,” said Ziemba. “No longer is risk management left to the risk professionals; it’s absolutely an organizational game. It’s not me sitting in some office while the rest of the organizations goes about their merry business, it is a team sport more than ever. The view of enterprise risk has to be very broad. We look broadly at everything we do, how we do it, and what impacts how we do it.”
Sexual Abuse and Misconduct Risk
Sexual abuse and misconduct is under-reported. Only 5% to 10% of victims report sexual abuse by healthcare providers; most abuse victims are female and adult. A number of sexual abuse cases in recent years have resulted in settlements of hundreds of millions or billions of dollars.
In 2025, Columbia University and New York-Presbyterian Hospital settled hundreds of sexual abuse claims for $750 million after former gynecologist Robert Hadden, MD was convicted and imprisoned on federal crime charges. In the case of Larry Nassar, formerly of the Michigan State University sports medicine program and US Gymnastics, settlements have exceeded $1 billion from the University of Michigan, USA Gymnastics, and the US Department of Justice. Nassar was sentenced to 175 years in prison for decades of sexual abuse crimes.
As large cases have worked their way through the courts and generated large settlements, sexual abuse and molestation insurance premiums have risen due to the heightened risk associated with this area of liability coverage.
Cyber Security
Between 2009 and 2024, 6,759 healthcare cybersecurity breaches affected 500 or more individuals, with many impacted more than once. The largest cybersecurity risks include ransomware, phishing, third-party and supply chain compromise, medical device vulnerabilities, and insider threats. Ransomware attacks increase in-hospital mortality rates by between 20% to 35% for patients admitted to a hospital under a ransomware attack.
To mitigate hospital cyberattack risk, the US Department of Health and Human Services published 10 healthcare-specific Cybersecurity Performance goals, which include patching known vulnerabilities, encrypting sensitive data, testing and updating the incident response plan, and maintaining and testing data backups.
The Evolution of HPL: Three to Five Year Outlook
As the HPL environment evolves, there’s no way to exactly predict what could happen in the next three to five years. But hospital risk executives are prepared for a number of scenarios.
“In Kentucky, if tort reform is not achieved in the next three to five years—and we’ve already started to do some of this—we’ll just continue to restructure our coverage and limits,” said Melissa Updike, CEO of the Kentuckiana Medical Reciprocal Risk Retention Group. “We’re going to figure out ways to provide adequate coverage to mitigate the financial exposure for physicians and for the healthcare system. If a plaintiff’s lawyer demands $70 million or $100 million, a healthcare company our size can’t go out and place $100 million of coverage. And the fact of the matter is there is no carrier out there selling that amount of coverage.”
To structure the amount of coverage to be able to fully insure the amounts being demanded in cases today (and sometimes awarded) several towers of coverage must be purchased from multiple carriers to establish limits to cover losses at those levels, she continued. There is not enough insurance capacity, and it’s not affordable or sustainable.
“There is risk around every corner, especially in healthcare,” Updike said. “We will continue to restructure and retool our coverages to meet the needs of the insured. We’re getting more aggressive at trial, spending a lot of time on witness preparation, on outlining and defining real damages. We’re setting realistic standard of care expectations and talking about that openly with juries.”
Ziemba noted that the key for the next three to five years in HPL is collaboration within risk management teams across the Stanford enterprise. “I can identify the risks that we know exist, but there is always something that will impact us that we frankly didn’t anticipate, because we just didn’t go there,” she said.
“Having an organizational framework for not only identifying your current risks but also being open and adaptable for the risks you didn’t anticipate is important,” she added. “For the next three to five years, build up your risk infrastructure in your organization, nurture relationships with insurers, and get out of your own world and look at the world more broadly.”
Over the next three to five years Ziemba identified external risk such as technology, market, regulatory, and geopolitical risk as the biggest risks hospitals will face. “None of us thought about COVID before January of 2020. We thought a global pandemic would never happen. Now we know that it can, so we need to take lessons from that and prepare for the future.”
A Final Word
“It’s an interesting time, but certainly the way we have done things in the profession for years, thinking that we are anticipating risks and adjusting for them, has kind of gone out the window,” said Ziemba. “Every day I feel like there is something new in front of me and I don’t have the luxury of time to figure out the perfect answer. I have to figure out a really good answer and adapt that as I learn.”