disruptions, shutdowns or unauthorized disclosure or modification of confidential information. The secure processing, storage, maintenance and transmission of this critical information are vital to our operations and business strategy, and we devote significant resources to protecting such information. Although we take measures to protect sensitive information from unauthorized access or disclosure, our information technology and infrastructure, and that of our third-party billing and collections provider, may be vulnerable to attacks by hackers or viruses or breached due to employee error, malfeasance or other disruptions. In addition, as a result of the COVID-19 pandemic, we may face increased cybersecurity risks due to our or our third-party billing agent’s reliance on internet technology and the number of our and our third-party billing agent’s employees who are working remotely, which may create additional opportunities for cybercriminals to exploit vulnerabilities.
A security breach or privacy violation that leads to disclosure or modification of or prevents access to consumer information (including personally identifiable information or protected health information) could harm our reputation, compel us to comply with disparate state breach notification laws, require us to verify the correctness of database contents and otherwise subject us to liability under laws that protect personal data, resulting in increased costs or loss of revenue. If we are unable to prevent such security breaches or privacy violations or implement satisfactory remedial measures, our operations could be disrupted, and we may suffer loss of reputation, financial loss and other regulatory penalties because of lost or misappropriated information, including sensitive consumer data. In addition, these breaches and other inappropriate access can be difficult to detect, and any delay in identifying them may lead to increased harm of the type described above.
Any such breach or interruption could compromise our networks or those of our third-party billing agent, and the information stored there could be inaccessible or could be accessed by unauthorized parties, publicly disclosed, lost or stolen. Any such interruption in access, improper access, disclosure or other loss of information could result in legal claims or proceedings, liability under laws that protect the privacy of personal information, such as the Health Insurance Portability and Accountability Act of 1996, or HIPAA, and regulatory penalties. Unauthorized access, loss or dissemination could also disrupt our operations, including our ability to perform tests, provide test results, bill our payers or patients, process claims and appeals, provide customer assistance services, conduct research and development activities, collect, process and prepare company financial information, provide information about our current and future products and solutions and other patient and clinician education and outreach efforts through our website, and manage the administrative aspects of our business, any of which could damage our reputation and adversely affect our business. Any such breach could also result in the compromise of our trade secrets and other proprietary information, which could adversely affect our competitive position.
In addition, the interpretation and application of consumer, health-related, privacy and data protection laws in the U.S., Europe and elsewhere are often uncertain, contradictory and in flux. It is possible that these laws may be interpreted and applied in a manner that is inconsistent with our practices. If so, this could result in government-imposed fines or orders requiring that we change our practices, which could adversely affect our business. Complying with these various laws could cause us to incur substantial costs or require us to change our business practices and compliance procedures in a manner adverse to our business. For example, the California Consumer Privacy Act, or the CCPA, took effect on January 1, 2020. The CCPA, among other things, requires covered companies to provide disclosures to California consumers concerning the collection and sale of personal information, and will give such consumers the right to opt-out of certain sales of personal information. The CCPA may increase our compliance costs and potential liability, and we cannot yet predict the impact of the CCPA on our business.
If we are unable to protect the confidentiality of our trade secrets, our business and competitive position would be harmed.
In addition to seeking patents for some of our technologies and solutions, we also rely on trade secrets, including unpatented know-how, technology and other proprietary information, to maintain our competitive position. We seek to protect these trade secrets, in part, by entering into non-disclosure and confidentiality agreements with parties who have access to them, such as our employees, corporate collaborators, outside
S-15