1 unchanged sentence
CYBERSECURITY
−Removed: Cybersecurity risks
−Removed: are a growing threat to us and other businesses, including our ERP and other third-party providers, which are vulnerable to
−Removed: cyberattacks, malware, and other system failures that may result in unauthorized access, damage, and other harms to our business or
−Removed: Protecting the confidentiality, integrity, and availability of our business information, intellectual property,
−Removed: customer, patient and employee data, and technology systems is critical to our business and operations, ability to comply with
−Removed: regulatory requirements, and reputation.
−Removed: Accordingly, Cybersecurity is an important and integrated part of the
−Removed: Company’s enterprise risk management function that identifies, monitors, and mitigates business, operational, and legal
−Removed: we have established Cybersecurity standards, policies, and operating procedures, for the purpose of implementing information
−Removed: protection processes and technologies;
−Removed: carrying out Cybersecurity risk detection, identification, assessment, response, and
−Removed: assigning responsibility within our organization for risk detection and oversight;
+Added: Cybersecurity
+Added: risks are a growing threat to us and other businesses, including our ERP and other third-party providers, which are vulnerable to cyberattacks,
+Added: malware, and other system failures that may result in unauthorized access, damage, and other harms to our business or reputation.
+Added: the confidentiality, integrity, and availability of our business information, intellectual property, customer, patient and employee data,
+Added: and technology systems is critical to our business and operations, ability to comply with regulatory requirements, and reputation.
+Added: Cybersecurity is an important and integrated part of the Company’s enterprise risk management function that identifies, monitors,
+Added: and mitigates business, operational, and legal risks.
+Added: we have established Cybersecurity standards, policies, and operating procedures, for the purpose of implementing information protection
+Added: processes and technologies;
+Added: carrying out Cybersecurity risk detection, identification, assessment, response, and monitoring;
+Added: responsibility within our organization for risk detection and oversight;
implementing Cybersecurity training;
−Removed: governing internal communications regarding Cybersecurity risks;
−Removed: and making required public and regulatory disclosures regarding Cybersecurity threats
−Removed: and incidents.
−Removed: We oversee risks from Cybersecurity threats associated with our use of third-party service providers by requiring
−Removed: our vendors to agree that they have and will maintain appropriate Cybersecurity controls, such as through standard contractual
−Removed: provisions, and by coordinating with key vendors with respect to integration with our systems.
−Removed: Our Cybersecurity risk management
−Removed: program is based on the National Institute of Standards and Technology (“NIST”) framework.
−Removed: components of our Cybersecurity risk management program include the use of third-party service providers, as appropriate, to
−Removed: assess, test, or otherwise assist with aspects of our security processes.
−Removed: For example, we employed a third-party cyber risk consultant
−Removed: to assess our overall Cybersecurity risk framework against NIST standards.
−Removed: We have also engaged third-party experts to perform
−Removed: penetration testing of our IT systems, and we have considered the results of such tests to enhance our Cybersecurity systems
−Removed: and controls, as appropriate.
−Removed: management, including leaders from our IT, information security, legal, and compliance teams, is responsible for implementing our Cybersecurity standards,
−Removed: policies, and operating procedures, under the ultimate oversight of our Chief Financial Officer.
−Removed: We regularly discuss and assess Cybersecurity risks.
−Removed: Audit Committee assists our Board in overseeing Cybersecurity risk management and the integrity of our information
−Removed: technology systems, processes, and data.
−Removed: Periodically, the Audit Committee reviews and discusses with management, and, in its
−Removed: discretion, third party vendors or other external experts, the adequacy of security for our information technology systems,
+Added: governing internal communications
+Added: regarding Cybersecurity risks;
+Added: and making required public and regulatory disclosures regarding Cybersecurity threats and incidents.
+Added: oversee risks from Cybersecurity threats associated with our use of third-party service providers by requiring our vendors to agree that
+Added: they have and will maintain appropriate Cybersecurity controls, such as through standard contractual provisions, and by coordinating
+Added: with key vendors with respect to integration with our systems.
+Added: Our Cybersecurity risk management program is based on the National Institute
+Added: of Standards and Technology (“NIST”) framework.
+Added: components of our Cybersecurity risk management program include the use of third-party service providers, as appropriate, to assess,
+Added: test, or otherwise assist with aspects of our security processes.
+Added: For example, we employed a third-party cyber risk consultant to assess
+Added: our overall Cybersecurity risk framework against NIST standards.
+Added: We have also engaged third-party experts to perform penetration testing
+Added: of our IT systems, and we have considered the results of such tests to enhance our Cybersecurity systems and controls, as appropriate.
+Added: management, including leaders from our IT, information security, legal, and compliance teams, is responsible for implementing our Cybersecurity
+Added: standards, policies, and operating procedures, under the ultimate oversight of our Chief Financial Officer.
+Added: We regularly discuss and
+Added: assess Cybersecurity risks.
+Added: Audit Committee assists our Board in overseeing Cybersecurity risk management and the integrity of our information technology systems,
processes, and data.
−Removed: our incident response and contingency plans in the event of a breakdown or security breach affecting the
−Removed: security of our information technology systems or data or the information technology systems, processes, and data of our clients;
−Removed: and any new threats or incidents that have or may impact us.
−Removed: The Audit Committee receives reports on the operation of such programs
−Removed: from the Chief Financial Officer as appropriate.
−Removed: The Audit Committee also reviews management reports regarding the evolving threat
−Removed: environment, vulnerability assessments, and specific Cybersecurity incidents.
−Removed: Periodically, the Audit Committee reports on
−Removed: Cybersecurity matters, incidents, and risk oversight to the Board.
−Removed: we have not experienced a cyberattack or other Cybersecurity incident that has materially affected us, we cannot guarantee
−Removed: that we will not experience Cybersecurity incidents that may have a material effect on us in the future.
−Removed: We may not be able
−Removed: to protect our systems and networks, or the confidentiality of our confidential or other information (including personal information),
−Removed: from cyberattacks and other unauthorizedaccess, disclosure, and disruption.
+Added: Periodically, the Audit Committee reviews and discusses with management, and, in its discretion, third party vendors
+Added: or other external experts, the adequacy of security for our information technology systems, processes, and data;
+Added: our incident response
+Added: and contingency plans in the event of a breakdown or security breach affecting the security of our information technology systems or
+Added: data or the information technology systems, processes, and data of our clients;
+Added: and any new threats or incidents that have or may impact
+Added: The Audit Committee receives reports on the operation of such programs from the Chief Financial Officer as appropriate.
+Added: Committee also reviews management reports regarding the evolving threat environment, vulnerability assessments, and specific Cybersecurity
+Added: Periodically, the Audit Committee reports on Cybersecurity matters, incidents, and risk oversight to the Board.
+Added: we have no t experienced a cyberattack or other Cybersecurity incident that has materially affected us, we cannot guarantee that we will
+Added: not experience Cybersecurity incidents that may have a material effect on us in the future.
+Added: We may not be able to protect our systems
+Added: and networks, or the confidentiality of our confidential or other information (including personal information), from cyberattacks and
+Added: other unauthorized access, disclosure, and disruption.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.