3 unchanged sentences
Our board of directors is actively involved in oversight of our risk management activities, and cybersecurity represents an important element of our overall approach to risk management.
−Removed: Our cybersecurity standards, processes and practices are based on recognized frameworks established by the National Institute of Standards and Technology, or NIST, the International Organization for Standardization and other applicable industry standards.
−Removed: In general, we seek to address cybersecurity risks through a comprehensive, cross-functional approach that is focused on preserving the confidentiality, security and availability of the information that we collect and store by identifying, preventing and mitigating cybersecurity threats and effectively responding to cybersecurity incidents when they occur.
+Added: Our cybersecurity standards, processes and practices are based on recognized frameworks established by the National Institute of Standards and Technology (“NIST”), the International Organization for Standardization and other applicable industry standards.
+Added: In general, we seek to address cybersecurity risks through a comprehensive, cross-functional approach that is focused on preserving the confidentiality, security and availability of the information that we collect and
+Added: store by identifying, preventing and mitigating cybersecurity threats and effectively responding to cybersecurity incidents when they occur.
Cybersecurity Risk Management and Strategy ;
4 unchanged sentences
As discussed in more detail under “Cybersecurity Governance” below, our audit committee provides oversight of our cybersecurity risk management and strategy processes, which are led by Chief Executive Officer.
−Removed: We also identify our cybersecurity threat risks by comparing our processes to standards set by the National Institute of Standards and Technology, or NIST, International Organization for Standardization, Center for Internet Security as well as by engaging experts to attempt to infiltrate our information systems.
+Added: We also identify our cybersecurity threat risks by comparing our processes to standards set by the NIST, International Organization for Standardization, Center for Internet Security as well as by engaging experts to attempt to infiltrate our information systems.
To provide for the availability of critical data and systems, maintain regulatory compliance, manage our material risks from cybersecurity threats, and protect against and respond to cybersecurity incidents, we undertake the following activities:
9 unchanged sentences
Our processes also address cybersecurity threat risks associated with our use of third-party service providers, including our suppliers and manufacturers or who have access to patient and employee data or our systems.
−Removed: In addition, cybersecurity considerations affect the selection and oversight of our third-party service providers.
+Added: cybersecurity considerations affect the selection and oversight of our third-party service providers.
We perform diligence on third parties that have access to our systems, data or facilities that house such systems or data, and continually monitor cybersecurity threat risks identified through such diligence.
9 unchanged sentences
and discusses such matters with our Chief Executive Officer.
−Removed: Our audit committee also receives prompt and timely information regarding any cybersecurity
−Removed: incident that meets establishing reporting thresholds, as well as ongoing updates regarding any such incident until it has been addressed.
+Added: Our audit committee also receives prompt and timely information regarding any cybersecurity incident that meets establishing reporting thresholds, as well as ongoing updates regarding any such incident until it has been addressed.
Our cybersecurity risk management and strategy processes, which are discussed in greater detail above, are led by our Chief Executive Officer, with the assistance of a third-party cyber specialist.
2 unchanged sentences
As discussed above, our Chief Executive Officer reports to the audit committee of our board of directors about cybersecurity threat risks, among other cybersecurity related matters, on an annual basis .
+Added: Artificial intelligence presents risks and challenges that can impact our business including by posing security risks to our confidential information, proprietary information, and personal data.
+Added: Issues in the development and use of artificial intelligence, combined with an uncertain and evolving regulatory environment, may result in reputational harm, liability, or other adverse consequences to our business operations.
+Added: As with many technological innovations, artificial intelligence presents risks and challenges that could impact our business.
+Added: Additionally, our vendors and suppliers may incorporate generative artificial intelligence tools into their offerings without disclosing this use to us, and the providers of these generative artificial intelligence tools may not meet existing or rapidly evolving regulatory or industry standards with respect to privacy and data protection, which may inhibit our or
+Added: our vendors’ and suppliers’ ability to maintain an adequate level of service and experience.
+Added: Additionally, we expect to see increasing government and supranational regulation related to artificial intelligence use and ethics, which may also significantly increase the burden and cost of research, development and compliance in this area.
+Added: For example, the European Union’s Artificial Intelligence Act (the “EU AI Act”) is the world’s first comprehensive law regulating the development and use of artificial intelligence—entered into force on August 1, 2024 and, with some exceptions, will become fully effective from August 2, 2026.
+Added: The EU AI Act regulates artificial intelligence systems based on risk level, has extraterritorial reach in certain circumstances, and imposes obligations on providers, manufacturers, importers, distributors, and deployers of artificial intelligence systems.
+Added: The EU AI Act also prohibits certain uses of artificial intelligence.
+Added: If we develop or use artificial intelligence systems that are governed by the EU AI Act, we may be required to ensure higher standards of data quality, transparency, and human oversight, and adhere to specific and potentially burdensome and costly ethical, accountability, and administrative requirements.
+Added: If we, our vendors, our suppliers, or our third-party partners experience an actual or perceived breach of privacy or other cybersecurity incident because of the use of generative artificial intelligence, we may lose valuable intellectual property, personal information, and confidential information, and our reputation and the public perception of the effectiveness of our privacy and security measures could be harmed.
+Added: These events could also result in obligations pursuant to, and subject us to liability under, applicable laws and contracts that we have entered into.
+Added: Further, bad actors around the world use increasingly sophisticated methods, including the use of artificial intelligence, to engage in illegal activities involving the theft and misuse of personal information, confidential information, and intellectual property.
+Added: Any of these outcomes could damage our reputation, result in the loss of valuable property and information, and adversely impact our business.
Our headquarters is located in Staten Island, New York, where we lease a total of approximately 150 square feet of office.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.