5 unchanged sentences
We rely on information technology networks and systems to process and store electronic information.
−Removed: We collect and store sensitive data, including personal identifiable information on our information technology networks.
+Added: We collect and store sensitive data, including PHI on our information technology networks.
As we collect and manage large quantities of data, it is possible that hardware failures or errors in our systems could result in data loss or corruption or cause the information that we collect to be incomplete or contain inaccuracies that our partners regard as significant.
3 unchanged sentences
Except as otherwise provided herein, this Item 1C reflects the Company’s cybersecurity policies and procedures as of December 31, 2024.
−Removed: In 2023, we did not identify any cybersecurity threats that have materially affected or are reasonably likely to materially affect our business strategy, results of operations, or financial condition.
+Added: In 2024, we did not identify any cybersecurity threats that would have materially affected or are reasonably likely to materially affect our business strategy, results of operations, or financial condition .
However, despite our efforts, we cannot eliminate all risks from cybersecurity threats, or provide assurances that we have not experienced undetected cybersecurity incidents.
−Removed: For additional information about these risks, see Part I, Item 1A, “Risk Factors” in this Annual Report.
+Added: For additional information about these risks, see Part I, Item 1A, “ Risk Factors — Risks Related to IT Systems and Cybersecurity ” in this Annual Report.
Risk Management and Strategy
2 unchanged sentences
The IT Security Team is tasked with the prevention, detection, mitigation, and remediation of cybersecurity incidents through a variety of technical and operational measures, and reports to our DevOPS/Security Manager.
−Removed: The team is comprised of personnel with a broad range of experience across the business and information technology industries, including our DevOPS/Security Manager, a DevOPS Security Administrator, and employees in senior legal and administrative roles.
+Added: The team is comprised of personnel with a broad range of experience across the business and information technology industries, including our DevOPS/Security Manager, and employees in senior legal and administrative roles.
The IT Security Team relies on the advice of the Manager DevOPS/Security related to the security of our data and any mitigation steps necessary.
2 unchanged sentences
Prior to joining the Company, our DevOPS/Security Manager served for 15 years in a senior leadership role in the IT department of a large, publicly traded Fortune 500 company.
−Removed: The DevOPS/Security Manager provides quarterly updates to the Cybersecurity Committee on the Company’s cybersecurity program, including cybersecurity risks, incidents, and mitigation strategies.
−Removed: Our DevOPS Security Administrator has experience developing and maintaining an IT security program for a Fortune 500 company, has a bachelor’s degree in information technology, and maintains a Comptia Security+ certification.
+Added: The DevOPS/Security Manager reports directly to the Company’s Chief Technology Officer, and provides quarterly updates to the Cybersecurity Subcommittee on the Company’s cybersecurity program, including cybersecurity risks, incidents, and mitigation strategies.
+Added: The identification of cybersecurity risks is a continuous and evolving assessment.
+Added: As a data company, we are subject to cybersecurity risks.
+Added: We have identified certain cybersecurity risks specific to our business, which are identified above in Part I, Item 1A, “ Risk Factors — Risks Related to IT Systems and Cybersecurity ” in this Annual Report.
The Company has established processes for assessing, identifying, and managing material risks from cybersecurity threats.
10 unchanged sentences
This endpoint has live protection and performs a deep system scan daily.
−Removed: Our endpoint protection
−Removed: products are managed by our IT Security Team via a dashboard that provides our team with immediate alerts, device isolation, and investigation features, and also contracted the use of a Managed Detection and Response (“MDR”) service.
+Added: Our endpoint protection products are managed by our IT Security Team via a dashboard that provides our team with immediate alerts, device isolation, and investigation features, and also contracted the use of a Managed Detection and Response (“MDR”) service.
The MDR service monitors our protected endpoints, servers, and network equipment at all times.
5 unchanged sentences
An independent third-party company conducts annual penetration and vulnerability detection as well.
−Removed: Our offices are physically secured with key card access controls for parking, first floor access, and elevator access.
+Added: Our offices are physically secured with key card access controls for parking and floor access.
In addition, security guards monitor building reception areas and parking garages, and receptionists are located in our lobbies to greet visitors.
1 unchanged sentence
The Company engages third party vendors in connection with our cybersecurity processes, including penetration and vulnerability scanning, auditing of our information security management program (ISMP);
−Removed: and a provider of products and services to secure users, networks, and endpoints against ransomware, malware, exploits, phishing and the wide range of other cyber attacks.
−Removed: In addition, the Company engaged national accounting and advisory services firms to audit the operating effectiveness of our security program, which incorporates cybersecurity in our processes.
+Added: and a provider of products and services to secure users, networks, and endpoints against ransomware, malware, exploits, phishing and the wide range of other cyberattacks.
+Added: In addition, the Company engaged national accounting and advisory services firms to audit the operating effectiveness of our security program, which
+Added: incorporates cybersecurity in our processes.
On an annual basis, the Company conducts a SOC 2 Type II audit and a HITRUST assessment.
2 unchanged sentences
HITRUST assessments also provide a level of assurance that delivers full transparency, accuracy, consistency, and integrity.
−Removed: In April 2022, an AICPA member firm and HITRUST authorized External Assessor Organization (the “Assessor”) completed an independent assessment of the Company’s systems.
−Removed: These independent assessments verified that we met the healthcare industry’s highest standards in protecting healthcare information and mitigating this risk, including compliance with HIPAA rules and regulations.
−Removed: On March 2, 2023, the Assessor reported that the Company’s data recovery system’s commitments and system requirements meet or exceed the stringent SOC 2 Type II applicable trust services criteria.
+Added: In 2023, the Company engaged a HITRUST Authorized External Assessor and AICPA member firm `, which completed independent assessments of MSP Recovery’s system.
+Added: These independent assessments verified that we met the healthcare industry’s highest standards in protecting healthcare information and mitigating this risk, including compliance with the HIPAA Security Rule.
On October 13, 2023, HITRUST certified that the platforms, facilities, and supporting infrastructure of our organization meet the HITRUST CSF® v11 Implemented, 1-year (i1) certification criteria.
−Removed: For our cloud computing services, we currently use a cloud service provider who is also HITRUST certified for the contracted services.
+Added: For our cloud computing services, we currently use Amazon Web Services (“AWS”) which is also HITRUST certified.
+Added: On June 14, 2024, an Independent Service Auditor provided MSP Recovery a report opining that our data recovery system’s commitments and system requirements meet or exceed the stringent SOC 2 Type II applicable trust services criteria.
The Company has processes to oversee and identify risks from cybersecurity threats associated with its use of third-party service providers.
4 unchanged sentences
The Board has established a Cybersecurity Subcommittee of the Audit Committee responsible for the oversight of risks from cybersecurity threats.
−Removed: On February 7, 2024, the Board established the Cybersecurity Subcommittee of the Audit Committee (the “Cybersecurity Committee”) to assist the Board in fulfilling its oversight responsibilities with respect to assessing and mitigating the Company’s cybersecurity risks.
+Added: On February 7, 2024, the Board established the Cybersecurity Subcommittee of the Audit Committee (the “Cybersecurity Subcommittee”) to assist the Board in fulfilling its oversight responsibilities with respect to assessing and mitigating the Company’s cybersecurity risks.
The Company’s management, under the guidance of the IT Security Team, is responsible for the preparation, presentation, and self-assessment of the Company’s cybersecurity policies and practices.
1 unchanged sentence
The IT Security Team reports to the Cybersecurity Subcommittee on a quarterly basis to inform the committee about and monitoring, prevention, detection, mitigation, and remediation of cybersecurity incidents , and is tasked with notifying the Cybersecurity Subcommittee of a cybersecurity incident upon discovery.
−Removed: We lease our corporate headquarters and maintain our executive offices in an office building located at 2701 S.
−Removed: Le Jeune Road, 10th Floor, Coral Gables, Florida 33134.
+Added: The Cybersecurity Subcommittee held three meetings during the year ended December 31, 2024.
+Added: We lease our corporate headquarters and maintain our executive offices in an office building located at 3150 SW 38th Avenue, Suite 1100, Miami, Florida 33146.
We also lease office space in Puerto Rico.
1 unchanged sentence
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.