1 unchanged sentence
Cybersecurity
−Removed: manages cybersecurity and data protection through a continuously evolving framework.
−Removed: The framework allows us to identify, assess and
−Removed: mitigate the risks we face, and assists us in establishing policies and safeguards to protect our systems and the information of those
−Removed: Our cybersecurity program is managed by our Director Product Management, Head of Data.
−Removed: The Audit Committee of the Board of
−Removed: Directors has oversight of our cybersecurity program and is responsible for reviewing and assessing the Company’s cybersecurity
−Removed: and data protection policies, procedures and resource commitment, including key risk areas and mitigation strategies.
−Removed: As part of this
−Removed: process, the Audit receives regular updates from the Director Product Management, Head of Data on critical issues related to our information
−Removed: security risks, cybersecurity strategy, supplier risk and business continuity capabilities.
−Removed: The Company’s framework includes an
−Removed: incident management and response program that continuously monitors the Company’s information systems for vulnerabilities, threats
−Removed: and incidents;
+Added: manages cybersecurity and data protection through a continuously evolving framework, as described in further detail below.
+Added: The framework
+Added: allows us to identify, assess and mitigate the risks we face, and assists us in establishing policies and safeguards to protect our systems
+Added: and the information of those we serve.
+Added: Our cybersecurity program is managed by James Wang, our Chief Technology Officer.
+Added: a degree in computer science from the University of Hawaii at Manoa and has 19 years of development experience focused on architecture
+Added: and security.
+Added: In his career, he has led initiatives for companies to attain SOC2 compliance and PCI compliance for their product solutions.
+Added: The Audit Committee of the Board of Directors has oversight of our cybersecurity program and is responsible for reviewing and assessing
+Added: the Company’s cybersecurity and data protection policies, procedures and resource commitment, including key risk areas and mitigation
+Added: As part of this process, the Audit Committee receives regular updates from the Chief Technology Officer on critical issues
+Added: related to our information security risks, cybersecurity strategy, supplier risk and business continuity capabilities .
+Added: The Company’s
+Added: framework includes an incident management and response program that continuously monitors the Company’s information systems for
+Added: vulnerabilities, threats and incidents;
manages and takes action to contain incidents that occur;
remediates vulnerabilities;
−Removed: and communicates the details of
−Removed: threats and incidents to management, including the Director Product Management, Head of Data, as deemed necessary or appropriate.
−Removed: to the Company’s incident response plan, any incidents are to be reported to the Audit Committee, appropriate government agencies
−Removed: and other authorities, as deemed necessary or appropriate, considering the actual or potential impact, significance and scope.
+Added: and communicates
+Added: the details of threats and incidents to management, including the Director Product Management, Head of Data, as deemed necessary or appropriate.
+Added: Pursuant to the Company’s incident response plan, any incidents are to be reported by the Chief Technology Officer to the Audit
+Added: Committee, appropriate government agencies and other authorities, as deemed necessary or appropriate, considering the actual or potential
+Added: impact, significance and scope.
+Added: The Company is no t aware of any cybersecurity incidents or threats that are reasonably likely to materially
+Added: affect its business strategy, results of operations, or financial condition.
employ an array of data security technologies, processes, and methods across our infrastructure to protect systems and sensitive information
4 unchanged sentences
of security information and event management tools.
−Removed: We developed, maintain and utilize a global integrated information security framework
+Added: We developed, maintained and utilized a global integrated information security framework
to guide our practices, based on relevant industry frameworks and laws, including, but not limited to NIST, GxP, HITRUST, the ISO 27000
7 unchanged sentences
We continuously monitor for threats and unauthorized access.
−Removed: draw on the knowledge and insight of external cybersecurity experts and vendors, and internally employ dedicated, certified, cybersecurity
−Removed: staff, such as but not limited to, CISSP, CISM, CISA, CSSP or other equivalent certifications, that leverage an array of third-party
−Removed: tools to secure OneMedNet information infrastructure and protect systems and information from unauthorized access.
−Removed: Non-technical safeguards
−Removed: also play an important role in our cybersecurity program.
−Removed: We provide various training programs and tools to employees so they can avoid
−Removed: risky practices and help us promptly identify potential or actual issues.
−Removed: We also have global incident response procedures, global service
−Removed: tools to log incidents and issues for investigation, and an ethics line to report concerns and follow-up on matters already reported.
−Removed: The Compliance team, led by our Chief Compliance Officer, develops and implements our strategy, as well as monitors systems and devices
−Removed: for risks and threats.
−Removed: corporate headquarters is in Eden Prairie, Minnesota is leased on a month-to-month basis.
+Added: draw on the knowledge and insight of external cybersecurity experts and vendors, and our Chief Technology Officer’s experience
+Added: in building solutions that are secure and compliant with our information security framework.
+Added: OneMedNet leverages an array of security
+Added: services and tools to secure OneMedNet information infrastructure and protect systems and information from unauthorized access.
+Added: products and solutions, including 3 rd party software and services such as hosted cloud based platforms are monitored by a
+Added: healthcare cloud, security and compliance organization that provides a real-time dashboard to monitor for potential threats and vulnerabilities.
+Added: Non-technical safeguards also play an important role in our cybersecurity program.
+Added: We provide various training programs and tools to
+Added: employees so they can avoid risky practices and help us promptly identify potential or actual issues.
+Added: We also have global incident response
+Added: procedures, global service tools to log incidents and issues for investigation, and an ethics line to report concerns and follow up on
+Added: matters already reported.
+Added: The Compliance team, led by our Chief Technology Officer, develops and implements our strategy, as well as
+Added: monitors systems and devices for risks and threats.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.