1 unchanged sentence
Cybersecurity
−Removed: Our board of directors recognizes the critical importance of maintaining the trust and confidence of our customers, healthcare providers, clients, business partners, and employees.
−Removed: Our board of directors actively oversees our risk management program, and cybersecurity represents an important component of our overall approach to enterprise risk management (“ERM”).
−Removed: In general, we seek to address cybersecurity risks through a cross-functional approach focused on preserving the confidentiality, security, and availability of the information that we collect and store by identifying, preventing and mitigating cybersecurity threats and effectively responding to cybersecurity incidents when they occur.
−Removed: Risk Management and Strategy
−Removed: As one of the critical elements of our overall ERM approach, our cybersecurity program is focused on the following key areas:
−Removed: As discussed in more detail under the heading “Governance,” the audit committee of our board of directors supports the board of directors oversight of cybersecurity risk management, which regularly interacts with our ERM function, our Head of Information Security (“HIS”) and other members of management.
−Removed: Cross-Functional Approach:
−Removed: We have implemented a cross-functional approach to identifying, preventing, and mitigating cybersecurity threats and incidents, while also implementing controls and procedures that provide for the prompt escalation of certain cybersecurity incidents so that decisions regarding the public disclosure and reporting of such incidents can be made by management in a timely manner.
+Added: The Company is committed to maintaining the trust and confidence of our customers, healthcare providers, clients, business partners and employees through a cybersecurity program focused on protecting the confidentiality, security and availability of the information that we collect and store.
+Added: We actively identify prevent, detect and mitigate cybersecurity threats and are positioned to effectively respond to cybersecurity incidents.
+Added: Key components of our cybersecurity program include:
+Added: Our board of directors, in coordination with its audit committee, oversees the risks arising from cybersecurity threats, which are embedded in our enterprise risk management (“ERM”) approach.
+Added: The Board’s audit committee receives regular reports on cybersecurity risks from our Head of Information Security, with prompt escalation of any incident that could materially affect core company operations to the Board.
+Added: Further, our Head of Information Security works collaboratively across the company to implement and enhance our cybersecurity program.
+Added: Through ongoing interactions with these teams, our Head of Information
+Added: Table of Co ntents
+Added: Security monitors the prevention, detection, mitigation and remediation of cybersecurity threats and incidents in real time.
+Added: Our Head of Information Security has served in various roles in information technology and information security for over 15 years and holds an undergraduate degree in Management Information System and a graduate degree in Human Resource Management and has attained multiple professional information security certification.
+Added: Incident Response Planning:
+Added: We have established protocols to detect, respond to and recover from cybersecurity incidents promptly.
Technical Safeguards:
We deploy commercially reasonable technical safeguards that are designed to protect our information systems from cybersecurity threats, including firewalls, intrusion prevention and detection systems, anti-malware functionality and access controls, which are evaluated and improved through vulnerability assessments and cybersecurity threat intelligence.
−Removed: Third-Party Risk Management:
−Removed: We maintain a risk-based approach to identifying and overseeing cybersecurity risks presented by third parties, including vendors, service providers and other external users of our systems, as well as the systems of third parties that could adversely impact our business in the event of a cybersecurity incident affecting those third-party systems.
−Removed: Education and Awareness:
−Removed: We provide regular, mandatory training for personnel regarding cybersecurity threats as a means to equip our personnel with effective tools to address cybersecurity threats, and to communicate our evolving information security policies, standards, processes and practices.
−Removed: We engage in the routine, periodic assessment and testing of our policies, standards, processes and practices that are designed to address cybersecurity threats and incidents.
+Added: In addition, we maintain a risk-based approach to identifying and overseeing cybersecurity risks presented by third parties, including vendors, service providers and other external users of our systems, as well as the systems of third parties that could adversely impact our business in the event of a cybersecurity incident affecting those third-party systems.
+Added: Employee Education and Awareness:
+Added: We provide regular mandatory training for employees regarding cybersecurity threats to equip them with effective tools to address cybersecurity threats and to communicate our evolving information security policies, standards, processes and practices.
+Added: Continuous Monitoring :
+Added: We engage in the routine, periodic assessment and testing of our standards, policies, processes and practices that are designed to address cybersecurity threats and incidents.
These efforts include a wide range of activities, including audits, assessments and other exercises focused on evaluating the effectiveness of our cybersecurity measures and planning.
−Removed: We regularly engage third parties to perform assessments on our cybersecurity measures, including information security maturity assessments,
−Removed: audits and independent reviews of our information security control environment and operating effectiveness.
−Removed: The results of such assessments, audits and reviews are reported to our audit committee, and we adjust our cybersecurity policies, standards, processes, and practices as necessary based on the information provided by these assessments, audits and reviews.
−Removed: Our board of directors, in coordination with our audit committee, oversees our ERM process, including the management of risks arising from cybersecurity threats.
−Removed: Our audit committee receives regular presentations and reports on cybersecurity risks.
−Removed: Our board of directors and audit committee receives and reviews prompt and timely information regarding any incident that may be considered material to investor or otherwise could materially affect core company operations.
−Removed: Our HIS works collaboratively across the company to implement a program designed to protect our information systems from cybersecurity threats and to promptly respond to any cybersecurity incidents in accordance with our incident response and recovery plans.
−Removed: Through ongoing communications with these teams, our HIS monitors the prevention, detection, mitigation and remediation of cybersecurity threats and incidents in real time, and such threats and incidents are reported to our audit committee when appropriate.
−Removed: Our HIS has served in various roles in information technology and information security for over 14 years and holds an undergraduate degree in Management Information System and a graduate degree in Human Resource Management and has attained the professional certification of Certified Chief Information Security Officer.
−Removed: Risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, have not materially affected, and the Company believes that such risks are not reasonably likely to materially affect the Company, including its business strategy, results of operations or financial condition.
−Removed: Although we are subject to ongoing and evolving cybersecurity threats, we are not aware of any material risks from cybersecurity threats in 2023 that have materially affected or are reasonably likely to materially affect us, including our business strategy, results of operations or financial condition.
+Added: We regularly engage third parties to perform assessments on our cybersecurity measures, including assessments, audits and independent reviews of our information security control environment and operating effectiveness.
+Added: The results of such exercises are reported to our audit committee, and we adjust our cybersecurity policies, standards, processes and practices as necessary.
+Added: Artificial Intelligence
+Added: Artificial intelligence (“AI”) has the potential to transform various work sectors significantly.
+Added: We continue to enhance and broaden our offerings with AI technologies, and we are exploring potential third-party partnerships to help us offer more robust solutions for providers and patients.
+Added: For example, we currently deploy a phenotype-driven algorithm that uses machine learning and is used to help identify genes to that may cause disease.
+Added: While we are dedicated to actualizing AI’s potential in our offerings, we are equally committed to ensuring the security of patient data in line with data privacy laws through the Company’s AI Guidelines.
+Added: Cybersecurity Threats
+Added: Risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, have not materially affected, and we believe that such risks are not reasonably likely to materially affect the Company, including its business strategy, results of operations or financial condition.
For more information on our cybersecurity risks, see “Risk Factors —Risks Related to Cybersecurity, Privacy and Information Technology ”.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.