of employees and reduced productivity among current employees. Our expected growth could require greater capital expenditures and may divert financial resources from other projects, such as the development of product candidates. If our management is unable to effectively manage our growth, our expenses may increase more than expected, our ability to create value and/or generate revenues could be reduced, and we may not be able to implement our business strategy. Our future financial performance and our ability to develop and commercialize seladelpar and other potential product candidates and compete effectively will depend, in part, on our ability to effectively manage any future growth.
Significant disruptions of information technology systems or breaches of data security could materially adversely affect our business, results of operations and financial condition.
We collect and maintain information in digital form that is necessary to conduct our business, and we are increasingly dependent on information technology systems and infrastructure to operate our business, particularly in view of our current remote work schedule. In the ordinary course of our business, we collect, store and transmit confidential information, including intellectual property, proprietary business information and personal information. It is critical that we do so in a secure manner to maintain the confidentiality and integrity of such confidential information. We have established physical, electronic and organizational measures to safeguard and secure our systems to prevent a data compromise, and rely on commercially available systems, software, tools, and monitoring to provide security for our information technology systems and the processing, transmission and storage of digital information. We have also outsourced elements of our information technology infrastructure, and as a result a number of third-party vendors may or could have access to our confidential information. Our internal information technology systems and infrastructure, and those of our current and any future collaborators, contractors and consultants and other third parties on which we rely, are vulnerable to damage from computer viruses, malware, natural disasters, terrorism, war, telecommunication and electrical failures, cyber-attacks or cyber-intrusions over the Internet, attachments to emails, persons inside our organization, or persons with access to systems inside our organization.
The risk of a security breach or disruption, particularly through cyber-attacks or cyber intrusion, including by computer hackers, foreign governments and cyber terrorists, has generally increased as the number, intensity and sophistication of attempted attacks and intrusions from around the world have increased. In addition, the prevalent use of mobile devices that access confidential information increases the risk of data security breaches, which could lead to the loss of confidential information or other intellectual property. The costs to us to mitigate network security problems and security vulnerabilities could be significant, and our efforts to address these problems may not be successful, and these problems could result in unexpected interruptions, delays, cessation of service and other harm to our business and our competitive position. If such an event is to occur and cause interruptions in our operations or our vendors, it may result in a material disruption of our product development programs and our reputation could be materially damaged. We could also be exposed to a risk of loss or litigation and potential liability, which could materially adversely affect our business, results of operations and financial condition.
Changes in and failures to comply with United States and foreign privacy and data protection laws, regulations and standards may adversely affect our business, operations and consolidated financial performance.
We are subject to or affected by numerous federal, state and foreign laws and regulations, as well as regulatory guidance, governing the collection, use, disclosure, retention, and security of personal data, such as information that we collect about patients and healthcare providers in connection with clinical trials in the United States and abroad. The global data protection landscape is rapidly evolving, and implementation standards and enforcement practices are likely to remain uncertain for the foreseeable future. This evolution may create uncertainty in our business, affect our or our vendors’ ability to operate in certain jurisdictions or to collect, store, transfer, use and share personal information, necessitate the acceptance of more onerous obligations in our contracts, result in liability or impose additional costs on us. The cost of compliance with these laws, regulations and standards is high and is likely to increase in the future. Any failure or perceived failure by us to comply with federal, state or foreign laws or regulation, our internal policies and procedures or our contracts governing our processing of personal information could result in negative publicity, diversion of management time and effort and proceedings against us by governmental entities or others. In many jurisdictions, enforcement actions and consequences for noncompliance are rising.
In the United States, HIPAA imposes, among other things, certain standards relating to the privacy, security, transmission and breach reporting of individually identifiable health information. Certain states have also adopted comparable privacy and security laws and regulations, some of which may be more stringent than HIPAA. Such laws and regulations will be subject to interpretation by various courts and other governmental authorities, thus creating potentially complex compliance issues for us and our future customers and strategic partners. In the event that we are subject to HIPAA or other United States privacy and data protection laws, any liability from failure to comply with the requirements of these laws could adversely affect our financial condition. Our operations abroad may also be subject to increased scrutiny or attention from data protection authorities. Many countries in these regions have established or are in the process of establishing privacy and data security legal frameworks with which we, our customers, or our vendors must comply. For example, the EU has adopted the General Data Protection Regulation (EU) 2016/679, or GDPR, which went into effect in May 2018 and includes strict requirements for processing the personal information of EU subjects, including clinical trial data. The
46