4 unchanged sentences
Key components of our cybersecurity program include:
−Removed: Our board of directors, in coordination with its audit committee, oversees the risks arising from cybersecurity threats, which are embedded in our enterprise risk management (“ERM”) approach.
−Removed: The Board’s audit committee receives regular reports on cybersecurity risks from our Head of Information Security, with prompt escalation of any incident that could materially affect core company operations to the Board.
−Removed: Further, our Head of Information Security works collaboratively across the company to implement and enhance our cybersecurity program.
−Removed: Through ongoing interactions with these teams, our Head of Information
−Removed: Table of Co ntents
−Removed: Security monitors the prevention, detection, mitigation and remediation of cybersecurity threats and incidents in real time.
−Removed: Our Head of Information Security has served in various roles in information technology and information security for over 15 years and holds an undergraduate degree in Management Information System and a graduate degree in Human Resource Management and has attained multiple professional information security certification.
−Removed: Incident Response Planning:
−Removed: We have established protocols to detect, respond to and recover from cybersecurity incidents promptly.
−Removed: Technical Safeguards:
−Removed: We deploy commercially reasonable technical safeguards that are designed to protect our information systems from cybersecurity threats, including firewalls, intrusion prevention and detection systems, anti-malware functionality and access controls, which are evaluated and improved through vulnerability assessments and cybersecurity threat intelligence.
−Removed: In addition, we maintain a risk-based approach to identifying and overseeing cybersecurity risks presented by third parties, including vendors, service providers and other external users of our systems, as well as the systems of third parties that could adversely impact our business in the event of a cybersecurity incident affecting those third-party systems.
−Removed: Employee Education and Awareness:
−Removed: We provide regular mandatory training for employees regarding cybersecurity threats to equip them with effective tools to address cybersecurity threats and to communicate our evolving information security policies, standards, processes and practices.
−Removed: Continuous Monitoring :
−Removed: We engage in the routine, periodic assessment and testing of our standards, policies, processes and practices that are designed to address cybersecurity threats and incidents.
−Removed: These efforts include a wide range of activities, including audits, assessments and other exercises focused on evaluating the effectiveness of our cybersecurity measures and planning.
−Removed: We regularly engage third parties to perform assessments on our cybersecurity measures, including assessments, audits and independent reviews of our information security control environment and operating effectiveness.
−Removed: The results of such exercises are reported to our audit committee, and we adjust our cybersecurity policies, standards, processes and practices as necessary.
−Removed: Artificial Intelligence
−Removed: Artificial intelligence (“AI”) has the potential to transform various work sectors significantly.
−Removed: We continue to enhance and broaden our offerings with AI technologies, and we are exploring potential third-party partnerships to help us offer more robust solutions for providers and patients.
−Removed: For example, we currently deploy a phenotype-driven algorithm that uses machine learning and is used to help identify genes to that may cause disease.
−Removed: While we are dedicated to actualizing AI’s potential in our offerings, we are equally committed to ensuring the security of patient data in line with data privacy laws through the Company’s AI Guidelines.
−Removed: Cybersecurity Threats
−Removed: Risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, have not materially affected, and we believe that such risks are not reasonably likely to materially affect the Company, including its business strategy, results of operations or financial condition.
+Added: Risk Management and Strategy
+Added: We conduct regular assessments of cybersecurity risks, continuously monitor our information systems for potential vulnerabilities, and test these systems in accordance with established cybersecurity policies, processes, and practices that are integrated within our comprehensive risk management program.
+Added: To safeguard our information systems against cyber threats, we employ an array of security tools designed to identify, escalate, investigate, resolve, and facilitate timely recovery from security incidents.
+Added: Our approach involves evaluating cybersecurity risks based on both their likelihood and potential impact to critical business systems and operations.
+Added: High-priority cybersecurity risks are incorporated into our overall risk management framework, each accompanied by a dedicated mitigation plan.
+Added: Progress on these mitigation efforts is reported to the Enterprise Risk Committee, a management committee, and monitored as part of our broader risk management initiatives, which are overseen by our Board of Directors.
+Added: We partner with third-party entities, including cybersecurity assessors, consultants, and other external experts, to evaluate the effectiveness of our prevention and response mechanisms, validate identified risks, and support the development and implementation of mitigation strategies as needed.
+Added: Additionally, we have established due diligence procedures for third parties with whom we engage, ensuring oversight and identification of material risks arising from cybersecurity threats associated with their services, particularly those related to cybersecurity functions.
+Added: To date, the Company is not aware of any cybersecurity risks—including those stemming from previous incidents—that have materially impacted, or are reasonably likely to materially impact, our business strategy, results of operations, or financial condition.
For more information on our cybersecurity risks, see “Risk Factors —Risks Related to Cybersecurity, Privacy and Information Technology ”.
+Added: Our Board of Directors provides oversight of our risk management processes, including those related to cybersecurity, both directly and through designated committees.
+Added: The Audit Committee is responsible for supervising our risk management program, focusing on key risks across short-, intermediate-, and long-term horizons.
+Added: Throughout the year, Audit Committee meetings address specific areas of risk, including those associated with cybersecurity threats.
+Added: The Audit Committee routinely reviews our cybersecurity risk profile in collaboration with management, including the Enterprise Risk Committee, a management committee.
+Added: We maintain a risk-based approach to cybersecurity, implementing comprehensive policies across our operations aimed at addressing and mitigating cybersecurity threats and incidents.
+Added: The Company’s Chief Information Security Officer (“CISO”) oversees the establishment and ongoing maintenance of our cybersecurity program and is responsible for assessing and managing cybersecurity risks.
+Added: Our current CISO brings over 25 years of experience in technology and information security, including more than 12 years in senior roles within large hospitals and healthcare organizations, and holds the requisite education, skills, experience, and industry certifications essential for this position.
+Added: The CISO delivers periodic updates regarding our cybersecurity risk profile to the Audit Committee of the Board of Directors.
+Added: Artificial Intelligence
+Added: Artificial intelligence (“AI”) has the capacity to significantly advance various sectors of work.
+Added: We are actively enhancing and expanding our offerings through AI technologies, including through the use of Fabric Genomics’ AI-based platform for Next Generation Sequencing analysis, which provides interpretation and clinical reporting for rare disease, hereditary risk, and cancer testing.
+Added: In addition, we are exploring strategic partnerships with third parties to provide more comprehensive solutions for providers and patients.
+Added: Our commitment to leveraging AI’s capabilities is matched by our dedication to safeguarding patient data in compliance with relevant data privacy regulations, as outlined in the Company’s AI Guidelines.
+Added: For more information on potential risks related to AI, see “Risk Factors — We use artificial intelligence in our business, and challenges with properly managing its use could result in reputational harm, competitive harm, and legal liability, and adversely affect our results of operations.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.