2 unchanged sentences
Cybersecurity
−Removed: Management and Strategy
−Removed: We have established policies and processes
−Removed: for assessing, identifying, and managing material risk from cybersecurity threats, and we have integrated these processes into our overall
−Removed: risk management program.
−Removed: We assess material risks from cybersecurity threats, including any potential unauthorized occurrence on or conducted
−Removed: through our information systems that may result in adverse effects on the confidentiality, integrity, or availability of our information
−Removed: systems or any information residing therein.
−Removed: We have adopted as the governance framework
−Removed: for our cybersecurity program the Service Organization Control Type 2 (SOC2) and the Health Insurance Portability and Accountability Act
−Removed: We use this framework as a guide to help us identify, assess, respond to, and manage cybersecurity risks relevant to our business.
+Added: Risk Management and Strategy
+Added: We have established policies and processes for assessing,
+Added: identifying, and managing material risk from cybersecurity threats, and we have integrated these processes into our overall risk management
+Added: We assess material risks from cybersecurity threats, including any potential unauthorized occurrence on or conducted through
+Added: our information systems that may result in adverse effects on the confidentiality, integrity, or availability of our information systems
+Added: or any information residing therein.
+Added: We have adopted as the governance framework for
+Added: our cybersecurity program the Service Organization Control Type 2 (“SOC2”) and the Health Insurance Portability and Accountability
+Added: Act (“HIPAA”).
+Added: We use this framework as a guide to help us identify, assess, respond to, and manage cybersecurity risks relevant
+Added: to our business.
Our cybersecurity risk management program includes:
−Removed: • periodic risk assessments designed to help identify material cybersecurity risks to our critical systems,
−Removed: information, and our broader enterprise information technology environment;
−Removed: • skilled information security and data privacy personnel, who support our cybersecurity risk assessment
−Removed: processes, our security controls, and our response to cybersecurity incidents;
−Removed: • external service providers, where appropriate, to monitor, assess, test, or otherwise assist with aspects
−Removed: of our security controls, and to support risk mitigation efforts;
+Added: periodic risk assessments designed to help identify material cybersecurity risks to our critical systems, information, and our broader enterprise information technology environment;
+Added: skilled information security and data privacy personnel, who support our cybersecurity risk assessment processes, our security controls, and our response to cybersecurity incidents;
+Added: external service providers, where appropriate, to monitor, assess, test, or otherwise assist with aspects of our security controls, and to support risk mitigation efforts;
training for our employees on cybersecurity awareness and the importance of protecting information assets.
1 unchanged sentence
a cybersecurity incident response plan that includes procedures for responding to cybersecurity incidents.
−Removed: identified any risks from known cybersecurity threats, including as a result of any prior cybersecurity incidents, that have materially
−Removed: affected or are reasonably likely to materially affect us, including our business strategy, results of operations, or financial condition.
−Removed: Our Board considers cybersecurity
−Removed: risk as part of its risk oversight function and management expects to keep the Board informed of any material cybersecurity threats and
−Removed: expects to provide a report to the Board on a periodic basis and the Board will consider and oversee.
−Removed: Our management team is responsible
−Removed: for assessing and managing our material risks from cybersecurity threats.
−Removed: Our Chief Technology Officer leads a team of information security
−Removed: professionals who have primary responsibility for our overall cybersecurity risk management program and supervises both our internal personnel
−Removed: and our external cybersecurity consultants.
−Removed: Our management
−Removed: team oversees efforts to prevent, detect, mitigate, and remediate cybersecurity risks and incidents through various means, which may
−Removed: include threat briefings from internal personnel and external service providers, as well as alerts and reports produced by security tools
−Removed: deployed in the information technology environment.
+Added: We have not identified any risks from known cybersecurity
+Added: threats, including as a result of any prior cybersecurity incidents, that have materially affected or are reasonably likely to materially
+Added: affect us, including our business strategy, results of operations, or financial condition.
+Added: Our Board considers
+Added: cybersecurity risk as part of its risk oversight function and management expects to keep the Board informed of any material cybersecurity
+Added: threats and expects to provide a report to the Board on a periodic basis and the Board will consider and oversee.
+Added: Our management team
+Added: is responsible for assessing and managing our material risks from cybersecurity threats.
+Added: Our Chief Technology Officer leads a team of
+Added: information security professionals who have primary responsibility for our overall cybersecurity risk management program and supervises
+Added: both our internal personnel and our external cybersecurity consultants.
+Added: Our management team oversees efforts to prevent,
+Added: detect, mitigate, and remediate cybersecurity risks and incidents through various means, which may include threat briefings from internal
+Added: personnel and external service providers, as well as alerts and reports produced by security tools deployed in the information technology
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.