1 unchanged sentence
CYBERSECURITY
−Removed: The Company’s Board of Directors takes seriously both the responsibility to guard against cybersecurity threats and its compliance with the SEC Cybersecurity regulations adopted on July 26, 2023.
−Removed: The Board of Directors receives an annual cybersecurity update from the Chief Information Officer (CIO) and Chief Information Security Officer (CISO) at every November Board meeting and, accordingly, received its customary detailed briefing from the CIO and CISO at its November 2, 2023 meeting.
−Removed: The Board also received an extensive separate briefing this year on cybersecurity threats and regulations presented by the CIO and outside expert consultants at its August 3, 2023 meeting.
−Removed: The CIO reports relevant information regarding cybersecurity threats and risks to the Certification Committee, which is chaired by the Chairman of the Audit Committee.
−Removed: The Chairman of the Audit Committee will then elevate any matters of significance, as warranted, to the full Audit Committee.
−Removed: The Audit Committee can then further elevate matters to the full Board of Directors, as necessary or required.
−Removed: The Company has adopted processes to identify, assess, and manage material risks from cybersecurity threats.
−Removed: It has also adopted processes to evaluate material effects, or reasonably likely material effects, of risks from cybersecurity threats and previous cybersecurity incidents.
−Removed: The Company has adopted processes to assess and evaluate the necessity of any material disclosures required on Form 8-K.
−Removed: The Company’s CIO has more than 40 years of experience in information technology and cyber matters in healthcare.
−Removed: The Company’s CISO has 26 years in cybersecurity matters and has served as the Company’s CISO for 6 years.
−Removed: The Company has an Incident Response Planning Committee who will meet, as necessary, to address, identify, and manage any material cybersecurity threats.
−Removed: The Company also has a crisis team consisting of the Compliance Officer, General Counsel, Chief Financial Officer, Human Resources Officer, Facilities Management Administrator, and the Network Systems Administrator, which will be engaged if an event poses a significant risk to the Company.
+Added: The Company’s Board of Directors is committed to both safeguarding against cybersecurity threats and complying with the SEC Cybersecurity regulations adopted on July 26, 2023.
+Added: The Board receives an annual cybersecurity update from the Chief Information Officer (CIO) and Chief Information Security Officer (CISO) at one of the Board meetings held throughout the year.
+Added: Accordingly, they received their customary detailed briefing from the CIO and CISO at the August 8, 2024 meeting.
+Added: The CIO provides relevant information on cybersecurity threats and risks to the Certification Committee on a quarterly basis.
+Added: This meeting is chaired by the Chairman of the Audit Committee.
+Added: The Chairman of the Audit Committee will then escalate any significant matters to the full Audit Committee.
+Added: If necessary, the Audit Committee can further elevate these matters to the full Board of Directors.
+Added: The Company has implemented processes and continues to look at improved ways to identify, assess, and manage material risks from cybersecurity threats.
+Added: Additionally, it has established procedures to evaluate any material effects, or reasonably likely material effects, of risks from cybersecurity threats and past cybersecurity incidents.
+Added: The Company also has processes in place to assess and determine the necessity of any material disclosures required on Form 8-K.
+Added: The Company’s CIO brings over 40 years of experience in information technology and cybersecurity within the healthcare sector.
+Added: The CISO has more than 25 years of expertise in technology and cybersecurity and has served as the Company’s CISO for 7 years.
+Added: The Company has an Incident Response Planning Committee that convenes quarterly to address, identify, and manage any significant cybersecurity threats.
+Added: Additionally, the Company has a crisis team, comprising the Compliance Officer, General Counsel, Chief Financial Officer, Human Resources Officer, Facilities Management Administrator, and Network Systems Administrator, which is activated if an event poses a significant risk to the Company.
The Company and the Board of Directors are committed to remaining updated on evolving cybersecurity regulations and best practices, as well as the development and amendment of processes to meet these changing demands.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.