1 unchanged sentence
Cybersecurity
−Removed: Management and Strategy
−Removed: information security and risk management program is designed to identify, assess, and manage material risks from cybersecurity threats
−Removed: to our applications, computer networks, third-party hosted services, communications systems, hardware and software, and our critical
−Removed: data, including intellectual property, confidential information that is proprietary, strategic or competitive in nature, personal information,
−Removed: or PHI (collectively, “Information Systems”).
−Removed: information security program’s basis is a comprehensive set of policies and procedures covering various information security domains
−Removed: (collectively, “Information Security Policies”), including, but not limited to:
−Removed: ● Third-party
−Removed: training, and awareness,
−Removed: continuity and disaster recovery,
−Removed: protection and privacy, and
−Removed: security domains.
−Removed: risk management process is based on a standard methodology, and risks are identified based on:
−Removed: risk assessments,
−Removed: ● Information
−Removed: on past incidents,
−Removed: penetration tests, and
−Removed: security assessments.
−Removed: risks are documented in a central Risk Register and tracked for mitigation and other treatment decisions.
−Removed: information security program is audited annually against a well-known security framework, by an accredited third party.
−Removed: carry a HITRUST certification, which is a security assessment that targets the healthcare industry and HIPAA compliance.
−Removed: We are currently
−Removed: working towards a SOC 2 audit and assessment,
−Removed: which has more general applicability and covers the trust services criteria of security, confidentiality, privacy, accessibility, and
−Removed: processing integrity.
−Removed: 2023 , we stored and processed certain PHI on behalf of customers.
−Removed: From a cybersecurity perspective,
−Removed: this data was stored on secure AWS managed servers in the contiguous United States and encrypted at rest and in transit.
−Removed: End users did
−Removed: not have permission to access PHI unless the end user’s account had the proper end user role permissions (ie HCPs or hub service
+Added: Risk Management and Strategy
+Added: Our information security and risk management program
+Added: is designed to identify , assess, and manage material risks from cybersecurity threats to our applications, computer networks, third-party
+Added: hosted services, communications systems, hardware and software, and our critical data, including intellectual property, confidential information
+Added: that is proprietary, strategic or competitive in nature, personal information, or protected health information (PHI) (collectively, “Information
+Added: Our information security program’s basis
+Added: is a comprehensive set of policies and procedures covering various information security domains (collectively, “Information Security
+Added: Policy”), including, but not limited to:
+Added: ● Access control,
+Added: ● Endpoint protection,
+Added: ● Third-party oversight ,
+Added: ● Education, training, and awareness,
+Added: ● Network security,
+Added: ● Risk management,
+Added: ● Incident response,
+Added: ● Business continuity and disaster recovery,
+Added: ● Data protection and privacy, and
+Added: ● Other security domains.
+Added: Our risk management process is based on a standard
+Added: methodology, and risks are identified based on:
+Added: ● Annual risk assessments,
+Added: ● Information on past incidents,
+Added: ● Internal audits,
+Added: ● Security penetration tests, and
+Added: ● Other security assessments.
+Added: All risks are documented in a central Risk Register
+Added: and tracked for mitigation and other treatment decisions.
+Added: Our information security program is audited annually
+Added: against a well-known security framework, by an accredited third-party.
+Added: In 2024, we allowed our HITRUST certification to lapse and we replaced
+Added: it with System and Organization Controls (SOC) 2 assessment, which has more general applicability and covers the trust services criteria
+Added: of security, confidentiality, privacy, and accessibility.
+Added: we stored certain PHI on behalf of customers on secure AWS managed servers in the contiguous United States, encrypted at rest and in transit.
+Added: End users did not have permission to access PHI unless the end user’s account had the proper end user role permissions (e.g., HCPs
+Added: or hub service providers).
These end user roles were assigned according to the customer’s needs to see the information.
−Removed: At all times, such information
−Removed: was segregated so that one customer could not access records containing PHI that were associated with another customer.
−Removed: In late 2023 ,
−Removed: we discontinued PHI processing;
−Removed: however, certain PHI remains stored on the secure AWS managed servers to the extent information needs
−Removed: to be accessed by a customer.
−Removed: external audits and assessments identify and evaluate material risks from cybersecurity threats against our overall business objectives
−Removed: on a periodic basis and form the basis of internal reports, which can be shared with the management team, the Audit Committee of the
−Removed: Board of Directors, and the Board of Directors to evaluate our overall enterprise risk.
−Removed: incident response program consists of an Incident Response Plan document and a cross-functional Incident Response Team, which are defined
−Removed: in our Information Security Policies.
−Removed: All workforce members are trained on incident reporting procedures, and there is a single point
−Removed: of contact for reporting all incidents.
−Removed: Incident response training is conducted annually, followed by a tabletop exercise.
−Removed: Response Plan instructs personnel on how to notify our Incident Response Team in case of an incident.
−Removed: The VP of Information Security
−Removed: is the point person for incident responses and coordinates mitigation and remediation of cybersecurity incidents.
−Removed: We log all incidents
−Removed: and response plans for purposes of internal documentation.
−Removed: We report critical incidents to the management team, the Audit Committee,
−Removed: and the Board of Directors.
−Removed: Company’s VP of Information Security is responsible for implementing Information Security Policies on a day-to-day basis along
−Removed: with the Security Team (as defined in the Information Security Policies), which includes the VP of Information Security, the Chief Product
−Removed: Officer, the VP of Data Engineering and Platform Services, and the VP of Technology (Information Technology).
−Removed: use third-party service providers to perform a variety of functions throughout our business, including, but not limited to infrastructure
−Removed: support and maintenance, CRM, contract management, data hosting, and miscellaneous finance and accounting projects.
−Removed: We assess our vendors
−Removed: with respect to cybersecurity risk according to the services provided, the sensitivity of the Information Systems at issue, and the provider’s
−Removed: In appropriate cases, we will seek enhanced contractual obligations or guarantees related to cybersecurity on the service provider.
−Removed: Vendor risk assessments are performed before each vendor is engaged, and annual reviews are conducted to ensure vendors continue to meet
−Removed: security requirements.
−Removed: also maintain technical errors and omissions insurance which includes a cyber incident endorsement of up to $20 million with a premium
−Removed: This endorsement provides coverage for Network Security and Privacy, Privacy Regulation Proceeding, Privacy Event Expense
−Removed: Reimbursement, Extortion Demand Reimbursement, Data Restoration, Network Restoration, Business Interruption and System Failure.
−Removed: coverage reimburses the most common costs for information security incidents, including attorney’s fees, consumer notification
−Removed: costs, and regulatory fines.
−Removed: Company has no material incidents to report through the date of this filing.
−Removed: more information on risks from cybersecurity threats that may materially affect the Company, see Item 1A.
+Added: At all times,
+Added: such information was segregated so that one customer could not access records containing PHI that were associated with another customer.
+Added: Our external audits and assessments identify and
+Added: evaluate material risks from cybersecurity threats against our overall business objectives on a periodic basis and form the basis of internal
+Added: reports, which can be shared with the management team, the Audit Committee of the Board of Directors, and the Board of Directors to evaluate
+Added: our overall enterprise risk.
+Added: Our incident response program consists of an Incident
+Added: Response Plan document and a cross-functional Incident Response Team, which are defined in our Information Security Policies.
+Added: All workforce
+Added: members are trained on incident reporting procedures, and there is a single point of contact for reporting all incidents.
+Added: Incident response
+Added: training is conducted annually, followed by a tabletop exercise.
+Added: Our Incident Response Plan instructs personnel on how to notify our Incident
+Added: Response Team in case of an incident.
+Added: The VP of Information Security is the point person for incident responses and coordinates mitigation
+Added: and remediation of cybersecurity incidents.
+Added: We log all incidents and response plans for purposes of internal documentation.
+Added: critical incidents to the management team, the Audit Committee, and the Board of Directors.
+Added: The Company’s VP of Information Security
+Added: is responsible for implementing the Information Security Policy on a day-to-day basis along with the Security Committee (as defined in
+Added: the Information Security Policy), which includes the heads of the following departments, at a minimum:
+Added: Information Security, Technology,
+Added: Compliance, Product Management, Internal Audit, and Legal.
+Added: We use third-party service providers to perform
+Added: a variety of functions throughout our business, including, but not limited to infrastructure support and maintenance, CRM, contract management,
+Added: data hosting, and miscellaneous finance and accounting projects.
+Added: We assess our vendors with respect to cybersecurity risk according to
+Added: the services provided, the sensitivity of the Information Systems at issue, and the provider’s identity.
+Added: In appropriate cases, we will
+Added: seek enhanced contractual obligations or guarantees related to cybersecurity on the service provider.
+Added: Vendor risk assessments are performed
+Added: before each vendor is engaged, and annual reviews are conducted to ensure vendors continue to meet security requirements.
+Added: We also maintain technical errors and omissions
+Added: insurance which includes a cyber incident endorsement of up to $20 million.
+Added: This endorsement provides coverage for Network Security and
+Added: Privacy, Privacy Regulation Proceeding, Privacy Event Expense Reimbursement, Extortion Demand Reimbursement, Data Restoration, Network
+Added: Restoration, Business Interruption and System Failure.
+Added: This coverage reimburses the most common costs for information security incidents,
+Added: including attorney’s fees, consumer notification costs, and regulatory fines.
+Added: To our knowledge, during 2024, there were no material
+Added: cybersecurity incidents or threats that materially affected or are reasonably likely to materially affect the Company’s business
+Added: strategy, results of operations, or financial condition.
+Added: For more information on risks from cybersecurity
+Added: threats that may materially affect the Company, see Item 1A.
“Risk Factors”.
−Removed: Board of Directors’ oversight function includes cybersecurity risk management.
+Added: The Board of Directors’ oversight function
+Added: includes cybersecurity risk management.
+Added: The Board of Directors has three members with skills and experience in information security and
+Added: cybersecurity through their experience as current and former executives of digital technology companies.
The Board of Directors has tasked the Audit Committee
−Removed: with overseeing the Company’s cybersecurity risk management processes and with determining which threats are likely to impact the
−Removed: Company’s strategy, business operations, and financial condition.
−Removed: cybersecurity risk assessment and management processes are implemented and maintained by our VP of Information Security and the Security
−Removed: For strategic decisions regarding cybersecurity, the VP of Information Security consults with the Chief Product Officer, the Chief
−Removed: Financial Officer, the General Counsel and Chief Compliance Officer, and the VP of Compliance.
−Removed: VP of Information Security is responsible for hiring appropriate personnel, performing vendor risk assessments, and communicating information
−Removed: security priorities to relevant personnel, so that we can build cybersecurity risk considerations into our business practices.
−Removed: of Information Security also plans related budgets, designs cybersecurity processes, and reviews security assessments and related reports.
−Removed: Board of Directors has three members with skills and experience in information security and cybersecurity through their experience as
−Removed: current and former executives of digital technology companies.
+Added: with overseeing the Company’s cybersecurity risk management processes and determining which threats are likely to impact the Company’s
+Added: strategy, business operations, and financial condition.
+Added: Pursuant to its charter, the Audit Committee of
+Added: the Board of Directors reviews the Company’s policies regarding information technology security and protection from cyber risks.
+Added: In particular, the Audit Committee reviews with management the Company’s key IT Systems and evaluates the adequacy of the Company’s
+Added: information security program, compliance, and controls.
+Added: Our cybersecurity risk assessment and management
+Added: processes are implemented and maintained by our VP of Information Security and the Security Committee.
+Added: For strategic decisions regarding
+Added: cybersecurity, the VP of Information Security consults with the Chief Technology Officer, the Chief Financial Officer, the Chief Legal
+Added: Officer, and the VP of Compliance.
+Added: The VP of Information Security is responsible
+Added: for hiring appropriate personnel, performing vendor risk assessments, and communicating information security priorities to relevant personnel,
+Added: so that we can build cybersecurity risk considerations into our business practices.
+Added: The VP of Information Security also plans related
+Added: budgets, designs cybersecurity processes, and reviews security assessments and related reports.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.