(aaa) No Integration. Neither the Company nor, to the Company’s knowledge, any of its affiliates (within the meaning of Rule 144 under the Securities Act) has, prior to the date hereof, made any offer or sale of any securities which could be “integrated” (within the meaning of the Securities Act) with the offer and sale of the Shares hereunder.
(bbb) Compliance with HIPAA. The Company has operated and currently is in compliance with all applicable health care laws, rules and regulations (except where such failure to operate or non-compliance would not, singly or in the aggregate, result in a Material Adverse Effect), including, without limitation, to the extent applicable, (i) the Federal, Food, Drug and Cosmetic Act (21 U.S.C. §§ 301 et seq.); (ii) all applicable federal, state, local and all applicable foreign healthcare related fraud and abuse laws, including, without limitation, the federal Anti-kickback Statute (42 U.S.C. § 1320a-7b(b)), the U.S. Physician Payments Sunshine Act (42 U.S.C. § 1320a-7h), the civil False Claims Act (31 U.S.C. §§ 3729 et seq.), the criminal False Claims Law (42 U.S.C. § 1320a-7b(a)), all criminal laws relating to healthcare fraud and abuse, including but not limited to 18 U.S.C. Sections 286 and 287, the healthcare fraud criminal provisions under the U.S. Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) (42 U.S.C. Section 1320d et seq.), the exclusion laws (42 U.S.C. § 1320a-7), and the civil monetary penalties law (42 U.S.C. § 1320a-7a); (iii) HIPAA, as amended by the Health Information Technology for Economic Clinical Health Act (42 U.S.C. Section 17921 et seq.); (iv) the regulations promulgated pursuant to such laws; and (v) any other similar local, state, federal, or foreign laws (collectively, the “Health Care Laws”). Neither the Company, nor to the Company’s knowledge, any of its officers, directors, employees or agents have engaged in activities which are, as applicable, cause for false claims liability, civil penalties, or mandatory or permissive exclusion from Medicare, Medicaid, or any other state or federal healthcare program. The Company has not received written notice or other correspondence of any Action from any court or arbitrator or governmental or regulatory authority or third party alleging that any product operation or activity is in violation of any Health Care Laws, and, to the Company’s knowledge, no such Action is threatened. The Company is not a party to and does not have any ongoing reporting obligations pursuant to any corporate integrity agreement, deferred prosecution agreement, monitoring agreement, consent decree, settlement order, plan of correction or similar agreement imposed by any governmental or regulatory authority. Additionally, neither the Company, nor to the Company’s knowledge, any of its employees, officers or directors, has been excluded, suspended or debarred from participation in any U.S. state or federal health care program or human clinical research or, to the knowledge of the Company, is subject to a governmental inquiry, investigation, proceeding, or other similar action that could reasonably be expected to result in debarment, suspension, or exclusion.
(ccc) Compliance with Privacy Laws; Cybersecurity. The Company and its subsidiaries have operated their business in a manner compliant in all material respects with all United States federal, state, local and non-United States privacy, data security and data protection laws and regulations and all contractual obligations applicable to the Company’s collection, use, transfer, protection, disposal, disclosure, handling, storage and analysis of personal data (“Data Security Obligations”). The Company and its subsidiaries have been and are in compliance in all material respects with internal policies and procedures designed to ensure the integrity and security of the data collected, handled or stored in connection with its business; the Company and its subsidiaries have been and are in compliance in all material respects with internal policies and procedures designed to ensure compliance with the Health Care Laws that govern privacy and data security and take, and have taken, reasonably appropriate steps designed to assure compliance with such policies and procedures. There is no pending, or to the knowledge of the Company, threatened, action, suit or proceeding by or before any court or governmental agency, authority or body pending or threatened alleging non-compliance with any Data Security Obligations. The Company and its subsidiaries have taken reasonable steps to maintain the confidentiality of its personally identifiable information, protected health information, consumer information and other confidential information of the Company, its subsidiaries and any third parties in its possession (“Sensitive Company Data”). The tangible or digital information technology systems (including computers, screens, servers, workstations, routers, hubs, switches, networks, data communications lines, technical data and hardware), software, websites, applications and telecommunications systems used or held for use by the Company and its subsidiaries (the “Company IT Assets”) are, in all material respects, adequate and operational for, in accordance with their documentation and functional specifications, the business of the Company and its subsidiaries as now operated and as currently proposed to be conducted as described in the Registration Statement and the Prospectus, free and clear of all material bugs, errors, defects, Trojan horses, time bombs, malware and other corruptants. The Company and its subsidiaries have used reasonable efforts to establish, and have established, commercially reasonable disaster recovery and security plans, procedures and facilities for the business consistent with industry standards and practices in all material respects, including, without limitation, for the Company IT Assets and data held or used by or for the Company and its subsidiaries. To the Company’s knowledge, the Company and its subsidiaries have not suffered or incurred any security breaches, compromises or incidents with respect to any Company IT Asset or Sensitive Company Data, except where such breaches, compromises or incidents would not reasonably be expected to, singly or in the aggregate, result in a Material Adverse Effect; and, to the Company’s knowledge, there has been no unauthorized or illegal use of or access to any Company IT Asset or Sensitive Company Data by any unauthorized third party. The Company and its subsidiaries have not been required to notify any individual of any information security breach, compromise or incident involving Sensitive Company Data.
16