actions and/or significant penalties, including the imposition of significant civil, criminal and administrative penalties, damages, disgorgement, monetary fines, imprisonment, possible exclusion from participation in Medicare, Medicaid and other federal healthcare programs or similar foreign programs, contractual damages, reputational harm, diminished profits and future earnings, additional reporting requirements and/or oversight if we become subject to a corporate integrity agreement or similar agreement to resolve allegations of non-compliance with these laws, and curtailment of our operations, any of which could adversely affect our ability to operate our business and our results of operations. In addition, the approval and commercialization of denifanstat or any of our future drug candidates outside the United States will also likely subject us to foreign equivalents of the healthcare laws mentioned above, among other foreign laws.
Our internal computer systems, or those used by our CROs or other contractors or consultants, may fail or suffer security breaches.
We and the third parties upon which we rely face a variety of evolving threats, which could cause security incidents, such as cyber-attacks, malicious internet-based activity, online and offline fraud, and other similar activities. Such threats are prevalent and continue to rise, are increasingly difficult to detect, and come from a variety of sources.
Despite the implementation of security and back-up measures designed to protect against security incidents, our internal computer, server, and other information technology systems as well as those of our third-party collaborators, consultants, contractors, suppliers, and service providers upon which we rely, may be vulnerable to various threats including, but not limited to, damage from physical or electronic break-ins, computer viruses, malware, ransomware, personnel misconduct or error, supply chain attacks, natural disasters, terrorism, war, telecommunication and electrical failure, denial of service, and other cyberattacks or disruptive incidents that could result in unauthorized access to, use or disclosure of, corruption of, or loss of sensitive, and/or proprietary data, including personal information, and health-related information, and could subject us to significant liabilities and regulatory and enforcement actions, and reputational damage. In particular, severe ransomware attacks are becoming increasingly prevalent and can lead to significant interruptions in our operations.
For example, the loss of clinical trial data from completed or ongoing clinical trials could result in delays in any regulatory approval or clearance efforts and significantly increase our costs to recover or reproduce the data, and subsequently commercialize the product. Additionally, theft of our intellectual property or proprietary business information could require substantial expenditures to remedy. Such theft could also lead to loss of intellectual property rights through disclosure of our proprietary business information, and such loss may not be capable of remedying.
In addition, our reliance on third-party partners could introduce new cybersecurity risks and vulnerabilities. If we or our third-party collaborators, consultants, contractors, suppliers, or service providers upon which we rely were to suffer an attack or breach, for example, that resulted in the unauthorized access to or use or disclosure of personal information, we may have to notify consumers, partners, collaborators, government authorities, other stakeholders and the media, and may be subject to investigations, civil penalties, administrative and enforcement actions, and litigation, any of which could harm our business and reputation. Any such disclosures may involve inconsistent requirements and are costly, and the disclosure or the failure to comply with such requirements could lead to adverse consequences. Likewise, we rely on third parties to conduct clinical trials, and similar events relating to their computer systems could also have a material adverse effect on our business. While we may be entitled to damages if these providers fail to satisfy their data privacy or security-related obligations to us, any award may be insufficient to cover our damages, or we may be unable to recover such award. In addition, supply-chain attacks have increased in frequency and severity, and we cannot guarantee that third parties’ infrastructure in our supply chain or our third-party partners’ supply chains have not been compromised.
Our reliance on internet technology and the number of our employees, and those of our CROs, who continue to work remotely may create additional opportunities for cybercriminals to exploit vulnerabilities, as this has caused an increased usage of computers operated on home networks, while in transit, or in public locations. Furthermore, because the techniques used to obtain unauthorized access to, or to sabotage, systems change frequently and often are not recognized until launched against a target, we may be unable to