Skip to main content
Category: Policy Exclusions

Bodily Injury and Property Damage Exclusion

Also known as: BI/PD Exclusion, Bodily Injury/Property Damage Exclusion
Simply put

A bodily injury and property damage exclusion is a provision in an insurance policy that removes coverage for certain claims involving physical harm to people or damage to physical property. Rather than a single standard clause, the exclusion appears in various forms and can be tied to specific circumstances, such as liability assumed under a contract or damage that develops continuously over time. Whether a particular loss is excluded depends on the exact wording of the provision and how it interacts with the rest of the policy.

Formal definition

In commercial general liability (CGL) policies, exclusions addressing 'bodily injury' and 'property damage', terms typically defined within the policy, operate to withdraw coverage that the insuring agreement would otherwise provide, and they take several distinct forms rather than a single uniform clause. Examples described in the evidence include exclusions for bodily injury or property damage the insured is liable for through an assumption of liability in a contract; the 'expected or intended' exclusion (Exclusion a in the CGL form), which bars coverage for bodily injury or property damage expected or intended from the standpoint of the insured; property-related exclusions such as the 'Own Property' and 'Your Work' exclusions; and 'continuous or progressive' injury or damage exclusions, which can alter the policy's occurrence trigger and complicate the analysis of which policy period(s) respond to a claim. Application of any such exclusion is subject to the specific policy wording, endorsements, definitions, and applicable jurisdiction; the placement and lettering of exclusions within a given form (for example under Exclusion j or other designated exclusions) can vary and should be confirmed against the actual form at issue.

Why it matters

Bodily injury and property damage exclusions determine whether a commercial general liability (CGL) policy will respond to some of the most consequential claims an organization can face, physical harm to people and damage to physical property. Because these exclusions take several distinct forms rather than a single uniform clause, a claim that looks covered under the insuring agreement can be withdrawn from coverage by a specific exclusion. For example, some policies exclude bodily injury or property damage that the insured becomes liable for through an assumption of liability in a contract, and the 'expected or intended' exclusion bars coverage for injury or damage expected or intended from the standpoint of the insured. Whether a given loss falls inside or outside coverage therefore turns on the exact wording and how it interacts with the policy's definitions and other exclusions.

Who it's relevant to

Insurance Brokers and Underwriters
Brokers placing CGL coverage and underwriters drafting or reviewing it need to understand which form of the bodily injury and property damage exclusion applies, how it is lettered in the specific form, and how endorsements modify it. Because these exclusions take multiple forms and their placement varies between forms, confirming the exact wording against the actual form at issue is essential rather than relying on generic descriptions.
Risk Managers
Risk managers evaluating whether a CGL policy responds to physical-harm claims should note that contractual assumptions of liability, expected or intended conduct, and property owned by or worked on by the insured may be carved out of coverage. This affects decisions about contractual indemnity obligations and whether additional coverage or endorsements are needed to close gaps.
Legal and Coverage Professionals
The 'continuous or progressive' exclusion's effect on the occurrence trigger makes coverage allocation across multiple policy periods more difficult, which is directly relevant to counsel analyzing which policies to place on notice and how a claim is allocated. Because interpretation depends on specific wording, definitions, and jurisdiction, coverage analysis should be grounded in the actual form and applicable law.

Inside Bodily Injury and Property Damage Exclusion

Bodily Injury and Property Damage Exclusion
A provision commonly found in cyber insurance policies that excludes coverage for claims arising out of physical bodily injury to persons and physical damage to or destruction of tangible property. Its purpose is to draw a boundary between cyber policies and traditional casualty lines such as commercial general liability (CGL), so that physical-harm risks are underwritten under the policies designed for them. Whether and how the exclusion applies depends on the specific policy wording, definitions, endorsements, and jurisdiction.
Bodily injury (as typically defined)
In many cyber forms this refers to physical injury, sickness, or death, and sometimes associated mental anguish only where it flows from a physical injury. Cyber policies frequently exclude these because bodily injury is the province of CGL and other casualty coverages. The precise definition varies by insurer form and can materially affect scope.
Property damage / tangible property (as typically defined)
Generally means physical injury to, or loss of use of, tangible property. Many cyber forms expressly state that electronic data is not tangible property, which is central to how the exclusion interacts with data-focused cyber coverage. The treatment of data varies across forms and is a frequent point of negotiation.
Relationship to CGL exclusions
The cyber exclusion is intended to complement, not duplicate, casualty coverage. Cyber policies exclude bodily injury and physical property damage on the expectation that such exposures are addressed under CGL or similar policies. In the standard ISO CGL form (CG 00 01), Damage to Property is Exclusion j and Damage to Your Work is Exclusion l; these are distinct CGL exclusions and should not be treated as a single grouping. These CGL provisions are separate from the cyber policy exclusion and operate under their own wording.
Potential carve-backs and exceptions
Some cyber policies include limited exceptions or endorsements that restore coverage for specified consequences, for example certain cyber-related physical outcomes or resulting mental anguish, subject to sublimits and conditions. Availability and breadth of any carve-back depend entirely on the specific wording and negotiated terms.
Coverage gap significance
Because this exclusion sits at the intersection of cyber and casualty lines, it is a common source of coverage gaps where a cyber event produces physical consequences that neither the cyber policy nor the CGL policy clearly covers. This is a first-party and third-party issue depending on whose loss is at stake and how the claim is framed.

Common questions

Answers to the questions practitioners most commonly ask about Bodily Injury and Property Damage Exclusion.

Does a bodily injury and property damage exclusion in a cyber policy mean I have no protection at all if a cyber event causes physical harm?
Not necessarily, but you should not assume the gap is filled. The exclusion typically removes bodily injury and tangible property damage from the cyber policy's coverage, on the theory that such losses belong in general liability or property programs. However, whether those other policies actually respond depends on their own wording, which may contain their own cyber-related exclusions. The practical risk is a coverage gap where neither the cyber policy nor the traditional policy clearly responds. This should be reviewed across your full program rather than assumed to be covered somewhere, subject to the specific wording of each policy and applicable endorsements.
Isn't data corruption or the loss of electronic files considered 'property damage' that this exclusion would cover or exclude?
This depends entirely on how the policy defines property damage. Many forms tie property damage to loss of, or injury to, tangible property, and some expressly state that electronic data is not tangible property. Under that wording, corruption or loss of data would generally not be treated as property damage at all, so the bodily injury and property damage exclusion would not be the operative provision for that loss. Data restoration is more commonly addressed as a first-party coverage under the cyber policy itself. The bodily injury and property damage exclusion is aimed at physical injury and damage to tangible things, not at digital assets, subject to the specific definitions used in your policy.
How can I identify where a bodily injury and property damage exclusion appears in my policy and how broadly it is worded?
Review the exclusions section of the cyber policy wording and any endorsements that amend it. Look at how the terms bodily injury, property damage, and tangible property are defined in the definitions section, because the breadth of the exclusion turns on those definitions. Note any carve-backs or exceptions that restore limited coverage for specific scenarios. Because forms vary significantly among insurers, comparing the exact language across your renewal options and against your other policies is the reliable approach rather than relying on the exclusion's title alone.
What steps help address the potential gap between a cyber policy's bodily injury and property damage exclusion and my general liability or property coverage?
Map the exclusion in the cyber policy against the corresponding grants and exclusions in your general liability and property policies to see whether a cyber-triggered physical loss would fall into a gap. Where a gap exists, discuss with your broker whether an endorsement, a difference-in-conditions approach, or a specialty coverage could address it. Confirm which category any resulting coverage would fall under, since bodily injury and property damage liability to others is third-party in nature while damage to your own property is first-party. Any solution is subject to the specific wording, exclusions, and conditions of the policies involved.
How should this exclusion factor into scenario planning for an operational technology or industrial control system incident?
Cyber events affecting operational technology can plausibly lead to physical damage or injury, which is exactly the category a bodily injury and property damage exclusion is likely to remove from the cyber policy. When planning for such scenarios, identify which of your policies is intended to respond to the physical consequences and confirm that neither the cyber exclusion nor a cyber exclusion in the property or liability policy leaves the loss unaddressed. This is a coverage-mapping exercise and does not reduce the likelihood of the incident; it should sit alongside, not replace, the mitigation and resilience measures for the operational environment.
What documentation or wording should I request from an underwriter to understand the exclusion's practical effect?
Request the full exclusion text, the relevant definitions, and any related endorsements or carve-backs, rather than a summary. Ask how the insurer treats electronic data relative to tangible property, and how it views losses that begin as a cyber event but result in physical consequences. Where possible, obtain the insurer's position on the interaction between this exclusion and other exclusions such as war or infrastructure exclusions. Because interpretation can differ among underwriters and by jurisdiction, documenting the insurer's stated intent in writing is prudent, though the binding effect ultimately rests on the policy wording and applicable law.

Common misconceptions

Because I have a cyber policy, any harm resulting from a cyber incident is covered, including injuries or physical damage caused by a hacked system.
Many cyber policies exclude bodily injury and physical property damage regardless of whether the triggering event was a cyber incident. Such losses are typically expected to fall to CGL or other casualty coverage, subject to those policies' own wording and exclusions. A cyber incident with physical consequences can fall between policies, creating a gap.
The bodily injury and property damage exclusion in a cyber policy and the property-damage exclusions in a CGL policy are the same thing arranged together.
They are separate provisions in separate policies. In the standard ISO CGL form (CG 00 01), Damage to Property is Exclusion j and Damage to Your Work is Exclusion l, distinct exclusions, not a single grouped item. The cyber policy's exclusion is worded independently and must be read on its own terms.
Damage to my data or systems counts as property damage, so this exclusion could wipe out my data restoration coverage.
Many cyber forms specify that electronic data is not tangible property, meaning the property damage exclusion is generally aimed at physical property rather than data. Data restoration is often addressed as distinct first-party cyber coverage. However, this turns on the specific definitions of 'property damage' and 'tangible property' in the policy, so the wording must be checked.

Best practices

Read the cyber policy's definitions of 'bodily injury,' 'property damage,' and 'tangible property' together with the exclusion, since the scope of the exclusion is driven by those definitions and by whether electronic data is treated as tangible property.
Map cyber and CGL (and any other casualty) policies side by side to identify gaps where a cyber event with physical consequences may fall outside both, and address them with brokers and underwriters before binding.
Do not assume CGL exclusion structure mirrors the cyber exclusion; review the actual CGL form (noting, for example, that in ISO CG 00 01 property damage and your-work exclusions are separate provisions) rather than relying on general groupings.
Where physical-consequence exposure is material, ask whether limited carve-backs or endorsements are available, and confirm any sublimits, conditions, and jurisdictional limitations attached to them.
Document how the organization's most plausible cyber-physical scenarios would be treated under each policy, so coverage expectations are tested against realistic loss pathways rather than assumptions.
Remember that insurance is risk transfer and does not reduce the likelihood of a cyber-physical event; pair coverage analysis with mitigation and resilience measures for exposures the exclusion leaves uninsured.
Promotional banner for the Penetration Report Template Kit