In September 2021, Oculentis BV, a German manufacturer of intraocular lenses used in cataract and refractive surgery, entered insolvency1. For thousands of patients across the UK who had received an Oculentis LENTIS lens, the implications were not immediately obvious. But over the months/years that followed, a troubling pattern emerged: lenses clouding, vision deteriorating and patients facing revision surgery2. By the time many sought legal advice, the manufacturer they might once have pursued no longer existed.
What followed pointed to something bigger than a single product failure. Claimant firms including Hugh James, Leigh Day and Devonshire’s shifted their focus to the UK clinics that had implanted the devices. The claims were not framed as clinical negligence, but as breaches of contract under the Supply of Goods and Services Act 1982 and the Consumer Rights Act 2015, on the basis that the lenses supplied were not of satisfactory quality.
Leigh Day, for example, brought claims against Optegra, one of the UK’s largest ophthalmology providers, with multiple cases settling without admission of liability3. The significance of these cases lies not simply in their outcome, but in what they reveal about the direction of travel. Surgeons, clinics and procurement decisions were all drawn into litigation, despite no allegation that the procedures themselves had been performed negligently. Liability had moved well beyond the operating theatre.
A market outgrowing its risk framework
That shift is happening against a backdrop of rapid expansion in private healthcare. The UK private acute healthcare market is now worth £13.8 billion, according to LaingBuisson’s tenth edition Private Acute Healthcare UK Market Report, published in December 20254. In 2025, according to the most recent PHIN market update published in June 2026, the Private Healthcare Information Network recorded 953,000 admissions, the highest annual figure since PHIN began collecting data and the fourth consecutive record year, with three of the four quarters setting individual records for their respective periods of the year5.
Private medical insurance now covers 12.2% of the UK population, representing 8.43 million people, the strongest market penetration since 20086. Meanwhile, the post-pandemic self-pay surge that drove much of the sector’s growth between 2021 and 2023 has plateaued, with LaingBuisson estimating self-pay growth of less than 0.1% over 20247. The market’s primary engine has shifted: employer-funded PMI, driven by businesses responding to deteriorating NHS access, is now the dominant force. In ophthalmology alone, revenue across the top five provider chains has grown 191% since 20218.
These are signs of commercial success, but they also point to a concentration of risk that existing governance and indemnity frameworks have not fully kept pace with. More procedures, more devices, more digital systems and more consultants working across NHS and private settings all mean more potential points of failure. They also mean two distinct patient populations, each with different expectations and claims behaviour.
Self-pay patients arrive with personal financial investment and explicit outcome expectations. PMI patients arrive with an insurer behind them, faster access to legal advice and scheme administrators increasingly able to monitor outcomes and identify anomalies at scale. Both groups are willing to litigate, but for different reasons and through different routes. Behind it all sits a litigation environment that is becoming faster, more sophisticated and more willing to pursue novel routes to recovery.
The wider medico-legal market sets the tone. NHS Resolution paid out £3.1 billion in clinical negligence compensation and associated costs in 2024/25, up from £2.8 billion the previous year9. Claimant legal costs alone reached £621 million, a 14% increase in a single year10, and the provision for future liabilities now stands at £60.3 billion11. These figures describe the NHS, but they shape the whole market. Insurers, medical defence organisations and private hospital groups cannot treat them as someone else’s problem.
NHS Resolution and the Government Actuary’s Department have projected that, on the current trajectory, costs could double to £4.1 billion within a decade12. The Public Accounts Committee has described the position as “a swelling accounting of profound suffering.”13 Legal costs for low-value claims, those under £25,000 and which make up three-quarters of NHS Resolution cases, were 3.7 times the damages awarded to claimants in 2024/2514. The economics of clinical negligence are increasingly dysfunctional, and that dysfunction flows directly into the indemnity market.
The patient who expects a guarantee
For private practitioners, one of the most important legal shifts did not come from Parliament. It came from the Supreme Court. In Montgomery v Lanarkshire Health Board [2015], the court changed their approach from the Bolam approach to risk disclosure with a patient-centred standard: practitioners must disclose any material risk that a reasonable person in the patient’s position would consider significant. In doing so, the judgment redrew the consent conversation as a dialogue rather than a clinical judgement, with direct and measurable effects on litigation.
Research published in the QJM found that settled NHS clinical negligence claims involving failure to inform rose four times faster than other categories in the years after Montgomery15. Between 2005 and 2019, approximately 2,300 settled cases were linked to consent failures, with a combined value approaching £400 million16. In private practice, where the patient has chosen their consultant, paid a premium and formed a clear expectation about outcome, the exposure is arguably even more acute.
The Oculentis cases show why. Many of the patients who brought claims against UK clinics did not argue that their surgeon had performed the operation incorrectly. They argued that they had not been properly informed of the risks associated with the specific device used, or that they had not been told an alternative existed. In private elective surgery, where consent to a particular product or technique is inseparable from consent to the procedure itself, a practitioner who cannot demonstrate a documented, individualised consent conversation faces a structurally weak defence.
That risk is amplified by the changing behaviour of private patients more broadly. Consumerisation is not simply a cultural observation; it is a legal and commercial fact. Self-pay patients are increasingly aware of their rights, more likely to complain formally and more likely to seek legal advice when outcomes disappoint. The Joint Council for Cosmetic Practitioners (JCCP), reported to the BBC that the number of local councils logging complaints about cosmetic procedures rose from two in 2023 to 65 by the end of 202417. At the same time, no-win-no-fee advertising by clinical negligence firms has expanded significantly, including campaigns targeting medical device failures and cosmetic complications. Group litigation, once associated mainly with pharmaceutical mass torts, is now a standard feature of medical device disputes.
Social media has accelerated the process further. A poor outcome that once prompted a private letter to the consultant’s secretary can now become a public review, a Facebook group and a call from a claimant firm within weeks. Reputation damage and litigation are no longer sequential; they often happen at the same time.
The product liability trap
The Oculentis situation is not unique to ophthalmology. In January 2023, the MHRA issued a Device Safety Information notice requiring immediate cessation and quarantine of EyeCee One and EyeCee Crystal preloaded intraocular lenses 18— manufactured by NIDEK and distributed in the UK by Bausch + Lomb — following reports of raised intraocular pressure associated with a coating agent on the injector nozzle. NIDEK updated its Field Safety Notice in July 2023, identifying the likely causal batch and recalling specific affected lots19. Patients are now pursuing claims, and with the manufacturer a foreign entity of uncertain reach, the UK clinic and the implanting surgeon are squarely in frame.
That is why procurement governance now matters so much. When a manufacturer is insolvent or effectively beyond the reach of UK courts, the Consumer Rights Act 2015 and the Sale of Goods and Services Act 1982 allow a patient to pursue the entity that supplied the device, typically the UK hospital or clinic, on the basis that the goods were not of satisfactory quality. This is a contract claim, not a negligence claim. It does not require proof that the surgeon made a mistake. It requires only that the product failed and that the clinic supplied it.
The Consumer Protection Act 1987, which imposes strict liability on producers, provides an alternative route where the manufacturer can be identified. But its practical usefulness declines precisely when manufacturers fail, disappear or sit beyond the reach of UK enforcement.
For independent hospital groups and clinics, the implication is clear: procurement decisions are clinical governance decisions with direct indemnity consequences. If the choice of intraocular lens, orthopaedic implant, mesh or surgical robot was driven primarily by cost, and the product later fails, the question in litigation will be whether cost was an appropriate primary driver for a decision with patient safety consequences. The absence of a documented procurement rationale, including alternatives considered, clinical evidence reviewed and reasons for selection, is not just an administrative gap. It is an evidential weakness in a product liability claim.
The regulatory environment is also becoming more demanding. The Medical Devices (Post-market Surveillance Requirements) (Amendment) (Great Britain) Regulations 2024, which came into force in June 2025, require manufacturers to maintain more granular lifecycle vigilance20. They do not, however, remove the exposure that flows to UK distributors and clinics when manufacturers fail. Hospitals and clinic groups that cannot show they had governance frameworks to assess and monitor the devices they implanted will find themselves in a difficult position, both legally and from an insurance perspective.
The exhausted clinician
Behind every insurance claim is a clinical event. And behind a significant proportion of those events, there is a clinician who was tired.
The General Medical Council’s (GMC) National Training Survey 2025 found that 61% of trainee doctors were at moderate or high risk of burnout21. The GMC’s 2025 Workplace Experiences reported that 40% of all registered doctors had seen patient safety compromised as a result of workforce pressures in the preceding year22. 23% had taken stress-related leave in 2024, compared with 12% in 2019, and inadequate staffing was cited as the primary barrier to safe care by 72% of respondents23.
For the private sector, this has a particular significance. Many of the UK’s most active private consultants divide their week between NHS and private lists, often adding telemedicine sessions as a further income stream. The cognitive demands are cumulative. A surgeon who has completed a full NHS list before attending a private afternoon clinic is not operating at the same level as one working fresh. Documentation quality, already under pressure in a fragmented, multi-system environment, deteriorates under cognitive load. Consent conversations become shorter. Follow-up communications become less precise.
That matters because documentation is the primary instrument of defence in clinical negligence litigation. HHJ Blair QC, in Malik v St George’s (2021), recorded that he was “taken aback” by a consultant who had relied on a GP letter rather than contemporaneous consent notes as evidence of what had been discussed with the patient24. The lesson is straightforward: in a Montgomery world, the absence of a documented, individualised consent conversation is not neutral. It is evidence of failure. In the private sector, where the patient paid for a specific outcome and a specific professional relationship, that failure is even harder to explain away.
Telemedicine adds another layer. Remote consultations bring documentary risks that face-to-face practice does not: uncertainty about who else was present, limitations in examination, and the risk that a follow-up call with a remote practitioner who does not have full access to the patient record creates a gap later turned into a claim. Medical defence organisations and insurers have not yet fully repriced for these risks, but the claims trajectory suggests they will need to.
When the algorithm fails
The same pattern is now emerging in the digital supply chain. In June 2024, the Qilin ransomware group attacked Synnovis, the pathology provider serving NHS and private patients across several major London trusts25. Within hours, blood testing systems across King’s College Hospital, Guy’s and St Thomas’, Princess Royal University Hospital and others were offline. More than 11,000 outpatient and elective appointments were delayed26, and 1,134 planned operations were cancelled in the first 13 days at two trusts alone27. By November 2025, when Synnovis completed its forensic notification process, data potentially relating to almost an estimated one million patients had been identified as having been taken28.
The Synnovis attack is one of the clearest recent examples of how patient safety risk is migrating into the IT supply chain. When a pathology system fails, clinical decisions that depend on test results cannot be made safely. When the failure lasts not for hours but for weeks, the care consequences become clinically significant. The liability chain does not stop at the hospital firewall.
The Information Commissioner’s Office (ICO) made that point in practical terms with its £3.07 million fine against Advanced Computer Software, the provider of NHS 111’s patient management system, following a 2022 ransomware attack29. Advanced had failed to implement multi-factor authentication across its systems, a basic security control. The ICO’s John Edwards described the shortfall as a serious failure by an organisation processing large volumes of sensitive data30. The fine was the first imposed by the ICO on a data processor under UK GDPR, and its importance extends beyond the amount. It confirmed that third-party IT suppliers to healthcare organisations are directly exposed to regulatory enforcement, and that weak cyber governance has consequences across the supply chain.
For private hospital groups, the question is obvious: how well do you understand the cyber governance posture of every supplier whose failure could harm patients or disrupt care pathways?
AI is adding a further dimension. Ambient AI scribes, which listen to consultations and generate structured notes, are now being deployed in some NHS and private settings. NHSE published guidance in January 2026 establishing a register of self-certified suppliers31, while the tools themselves are, in many cases, regulated as Class I medical devices by the MHRA32. The regulatory perimeter remains unsettled. The National Commission into the Regulation of AI in Healthcare, whose call for evidence findings were published by the MHRA in June 2026, found that the current framework — designed for static medical devices — is not well suited to iterative and adaptive AI systems33. The MHRA's AI Airlock sandbox, now in its third phase following the completion of Phase 2 in May 2026, is the primary mechanism through which those gaps are being identified and addressed, with formal guidance yet to follow34.
Lawton et al., writing in the Future Healthcare Journal in 2024, identified the liability issue with precision: clinicians risk becoming 'liability sinks' for AI — absorbing legal responsibility for decisions shaped by systems they do not and cannot fully understand35. A 2025 whitepaper from the same research group, drawing on trials of six AI decision-support tools, found that this perceived burden of liability was the greatest single threat to clinical adoption of AI in healthcare36. When an ambient scribe generates an inaccurate note that a pressured clinician does not review carefully, or when a clinical decision support tool recommends a course of action that later proves wrong, the practitioner who relied on the output, and the organisation that deployed the system without adequate governance, is likely to face the claim. The developer of the algorithm is, in the current legal environment, much harder to reach.
What needs to change
For hospitals and clinic groups, the first shift is conceptual. Product procurement is not a buying function; it is a clinical governance function with direct indemnity consequences. Every device selection decision should be documented: the alternatives considered, the clinical evidence reviewed, the reason for the final choice and the financial parameters within which that choice was made. Where cost is a significant factor, the clinical justification for the selected product needs to be explicit and auditable. And when a manufacturer recall occurs, the hospital must be able to show that it had a system capable of identifying and tracing affected patients. The governance audit trail that insurers and Medical Advisory Committees are increasingly expecting is not bureaucracy. It is the foundation of a defensible position.
Consent documentation should be treated as litigation preparation from the outset. The Malik judgment should be required reading for every private consultant. Where a specific device or technique is being used, the consent note must record that the patient was informed of the relevant risks, that alternatives were discussed and that they were given adequate time to consider their decision. A signature on a standard form is not enough. A contemporaneous, individualised record is.
AI adoption requires contractual clarity before deployment. Hospitals and clinic groups procuring ambient scribes or clinical decision support tools need to establish, in the vendor contract, who bears liability when the tool contributes to a clinical error. Without that allocation, the default position is that the clinician and the organisation absorb the risk. DTAC compliance, DCB0129/0160 safety case documentation and MHRA registration status should be verified before any AI tool enters a clinical workflow.
Cyber resilience is now an indemnity condition in substance, even where it is not yet mandated in policy terms. Multi-factor authentication (MFA) across all clinical systems, supply chain due diligence for IT processors and Data Security and Protection Toolkit compliance should be treated as baseline requirements. NHSE’s instruction following the Synnovis attack, mandating MFA for all NHS systems including those of suppliers, sets a standard that private sector operators have every reason to match.
For insurers and medical defence organisations, the implication is a more fundamental reassessment of risk segmentation. Pricing by specialty alone no longer captures the exposure. A consultant ophthalmologist working across an NHS list, a private list and a telemedicine service, operating in a facility that uses an AI scribe and sources devices from a European supplier, carries a risk profile that cannot be reduced to a single procedure code. The interconnection of clinical, technological, supplier and governance risk is what underwriting models now need to reflect.
The system node
The practitioners and hospitals that will manage the next decade successfully are those that understand they are no longer operating as isolated clinical entities. They are nodes in a web of interconnected liability: connected to device suppliers, IT processors, AI vendors, telemedicine platforms and a patient population that understands its rights and has no hesitation in exercising them.
The Oculentis case made that reality visible. A German manufacturer enters insolvency. Thousands of UK patients lose access to redress from the entity that made the product that harmed them. Liability then travels to the clinic that procured the device, the consultant who implanted it and the governance framework that did not ask the right questions about supplier solvency, product alternatives or documented rationale.
The question facing every independent practitioner, every hospital group and every insurer writing medical malpractice cover is not whether claims will become more complex. They will. The question is whether governance is sophisticated enough to keep pace, and whether the indemnity structures supporting UK private healthcare are built for the claims environment that already exists, not the one that existed a decade ago.
Howden provides specialist insurance solutions for the healthcare sector, including medical malpractice, cyber, and professional indemnity cover for independent practitioners and hospital groups. For more information on how we work with clients across the independent healthcare sector, please contact Peter Wickham, [email protected].
Peter Wickham has more than 30 years' experience in the insurance industry, specialising in medical malpractice and healthcare risk across the full spectrum of the healthcare sector. He works with a diverse range of organisations, from hospitals, clinics and individual practitioners to National Governing Bodies, professional associations, and high-profile sports clubs.
Alongside his extensive expertise in medical malpractice, Pete also advises life sciences businesses, including research and development organisations, helping them navigate complex and evolving risks at every stage of growth.
Pete is known for taking the time to understand what matters most to every stakeholder involved, enabling him to develop tailored insurance and risk management solutions that support long-term success. Passionate about solving problems, he works closely with clients to identify practical, innovative approaches to even the most complex challenges.
Whether partnering with ambitious start-ups, rapidly growing businesses or well-established organisations, Pete combines deep sector knowledge with a collaborative approach to help clients achieve their objectives with confidence.
