Data Privacy and Security
Numerous state, federal, and foreign laws govern the collection, dissemination, use, access to, confidentiality, and security of personal information, including health-related information. In the United States, numerous federal and state laws and regulations, including state data breach notification laws, state health information privacy laws, and federal and state consumer protection laws and regulations, govern the collection, use, disclosure, and protection of health-related and other personal information could apply to our operations or the operations of our partners. For example, HIPAA, as amended by the Health Information Technology for Economic and Clinical Health, and their respective implementing regulations imposes privacy, security, and breach notification obligations on certain health care providers, health plans, and health care clearinghouses, known as covered entities, as well as their business associates and their covered subcontractors that perform certain services that involve using, disclosing, creating, receiving, maintaining, or transmitting individually identifiable health information for or on behalf of such covered entities. Entities that are found to be in violation of HIPAA may be subject to significant civil, criminal, and administrative fines and penalties and/or additional reporting and oversight obligations if required to enter into a resolution agreement and corrective action plan with the U.S. Department of Health and Human Services (“HHS”) to settle allegations of HIPAA non-compliance. Further, entities that knowingly obtain, use, or disclose individually identifiable health information maintained by a HIPAA covered entity in a manner that is not authorized or permitted by HIPAA may be subject to criminal penalties.
Even when HIPAA does not apply, according to the FTC, violating consumers’ privacy rights or failing to take appropriate steps to keep consumers’ personal information secure may constitute unfair acts or practices in or affecting commerce in violation of Section 5(a) of the Federal Trade Commission Act.
In addition, state laws govern the privacy and security of personal information, including health-related information, in certain circumstances. Failure to comply with these laws, where applicable, can result in the imposition of significant civil and/or criminal penalties and private litigation. For example, the California Consumer Privacy Act, which went into effect on January 1, 2020, has created new data privacy obligations for covered companies and provided new privacy rights to California residents.
Coverage and Reimbursement
In the United States and markets in other countries, patients generally rely on third-party payors to reimburse all or part of the costs associated with their treatment. Adequate coverage and reimbursement from governmental healthcare programs, such as Medicare and Medicaid, and commercial payors is critical to new product acceptance. Our ability to successfully commercialize our product candidates will depend in part on the extent to which coverage and adequate reimbursement for these products and related treatments will be available from government health administration authorities, private health insurers and other organizations. Even if coverage is provided, the approved reimbursement amount may not be high enough to allow us to establish or maintain pricing sufficient to realize a sufficient return on our investment. Government authorities and third-party payors, such as private health insurers and health maintenance organizations, decide which medications they will pay for and establish reimbursement levels.
Significant uncertainty exists as to the coverage and reimbursement status of any pharmaceutical or biological product for which we obtain regulatory approval. Sales of any product, if approved, depend, in part, on the extent to which such product will be covered by third-party payors, such as federal, state, and foreign government healthcare programs, commercial insurance and managed healthcare organizations, and the level of reimbursement, if any, for such product by third-party payors. Decisions regarding whether to cover any of our product candidates, if approved, the extent of coverage and amount of reimbursement to be provided are made on a plan-by-plan basis. Further, no uniform policy for coverage and reimbursement exists in the United States, and coverage and reimbursement can differ significantly from payor to payor. Third-party payors often rely upon Medicare coverage policy and payment limitations in setting their own reimbursement rates, but also have their
80