Item 1B. Unresolved Staff Comments
ITEM
1B. UNRESOLVED STAFF COMMENTS
None.
ITEM
IC. CYBERSECURITY
We
believe cybersecurity is critical to advancing our technological advancements. As a healthcare services company, we face a multitude
of cybersecurity threats that range from attacks common to most industries, such as ransomware and denial-of service. Our customers,
suppliers, subcontractors, and business partners face similar cybersecurity threats, and a cybersecurity incident impacting us or any
of these entities could materially adversely affect our operations, performance, and results of operations. These cybersecurity threats
and related risks make it imperative that we expend resources on cybersecurity including protection across our operations and to ensure
the appropriate acquisition, access, use, and/or disclosure of protected health information (“PHI”), personal identifiable
information (“PII”), and payment card information (“PCI”)
The
Administrative Simplification Provisions of the Health Insurance Portability and Accountability Act (“HIPAA”) and its implementing
regulations include substantial restrictions and requirements with respect to the use and disclosure of a subset of PHI, and require
covered entities, including health plans, healthcare clearinghouses, and most healthcare providers, to implement administrative, physical,
and technical safeguards to protect the confidentiality, integrity, and availability of electronic PHI maintained or transmitted by them
or by others on their behalf.
Our
Board of Directors oversees management’s processes for identifying and mitigating risks, including cybersecurity risks, to help
align our risk exposure with our strategic objectives. The full Board retains oversight of cybersecurity because of its importance. In
the event of an incident, we intend to follow our detailed incident response playbook, which outlines the steps to be followed from incident
detection to mitigation, recovery, and notification, including notifying functional areas (e.g., legal), as well as senior leadership
and the Board, as appropriate. We have implemented a governance structure and processes to assess, identify, manage, and report cybersecurity
risks.
Text extracted from the filing as submitted to EDGAR. Formatting, tables and exhibits are simplified for reading; the original document is authoritative for anything you rely on.