3 unchanged sentences
Risk Management and Strategy
−Removed: We have implemented robust processes and policies dedicated to assessing, identifying, and effectively managing material risks associated with cybersecurity threats.
−Removed: Our cybersecurity program is designed and evaluated based on recognized frameworks such as the National Institute of Standards and Technology and the Center for Internet Security.
+Added: We have implemented robust processes and policies designed to assess, identify, and effectively manage material risks associated with cybersecurity threats.
+Added: Our cybersecurity program is designed and evaluated based on recognized frameworks such as the National Institute of Standards and Technology (NIST) and the Center for Internet Security (CIS).
These frameworks guide our focus on:
−Removed: (i) cultivating organizational understanding to manage cybersecurity risks, (ii) implementing safeguards to fortify our systems, (iii) promptly detecting cybersecurity incidents, (iv) responding effectively to incidents, and (v) ensuring a swift recovery from any cybersecurity event.
+Added: (i) cultivating organizational understanding to manage cybersecurity risks, (ii) implementing safeguards to protect our systems, (iii) promptly detecting cybersecurity incidents, (iv) responding effectively to incidents, and (v) ensuring a swift recovery from any cybersecurity event.
Where appropriate, these processes and policies are seamlessly integrated into our overarching risk management systems.
3 unchanged sentences
Valuable insights gained from these exercises are incorporated to refine and bolster our cybersecurity measures.
−Removed: Identification of critical third-party relationships vulnerable to cybersecurity threats is an integral part of our risk management program.
−Removed: Upon identification, we conduct thorough due diligence to fortify these relationships.
+Added: Identification of critical third-party relationships that may present heightened cybersecurity risk is an integral part of our risk management program.
+Added: Upon identification, we conduct thorough due diligence to manage these relationships.
Our comprehensive insurance portfolio includes cybersecurity insurance to provide an additional layer of protection.
4 unchanged sentences
The Corporate Governance and Nominating Committee reviews issues concerning our data security posture, results from third-party assessments, progress towards pre-determined risk-mitigation-related goals, incident response plans, and cybersecurity threat risks or incidents and developments, as well as the steps management has taken to respond to these risks.
−Removed: Our information systems management team, comprising the Chief Information Officer (CIO), Chief Technology Officer (CTO), and Chief Information Security Officer (CISO), collectively possesses over 50 years of extensive experience in information technology and cybersecurity.
−Removed: Prior to their current roles with the Company, our CIO, CTO, and CISO held various information technology and cybersecurity positions with other healthcare services and healthcare technology companies.
+Added: Our information systems management team, comprising the Chief Information Officer (CIO) and Chief Information Security Officer (CISO), collectively possesses over 50 years of extensive experience in information technology and cybersecurity.
+Added: Prior to joining the Company, our CIO held information technology leadership roles, including at a publicly traded company, and our CISO held information technology and cybersecurity roles in healthcare services and healthcare technology organizations.
They have collectively obtained various industry-recognized certifications, including the Certified Security Compliance Specialist, Certified Cyber Security Architect, and Certified HIPAA Professional designations.
The CISO holds the position of the Information Security Officer and directs cybersecurity operations.
−Removed: To enhance governance and oversight, we have established a Security Oversight Committee, chaired by the Information Security Officer and joined by key stakeholders such as our Chief Information Officer and General Counsel.
+Added: To enhance governance and oversight, we have established a Security Oversight Committee, chaired by the Information Security Officer and joined by key stakeholders such as our CIO and General Counsel.
This committee convenes regularly, typically on a semi-monthly basis, to foster alignment and cooperation on security-related issues .
4 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.