settlement orders, plans of correction or similar agreements with or imposed by any Applicable Regulatory Authority; and (viii) along with its employees, officers and directors, has not been excluded, suspended or debarred from participation in any government health care program or human clinical research and, to the knowledge of the Company, is not subject to a governmental inquiry, investigation, proceeding, or other similar action that could reasonably be expected to result in debarment, suspension, or exclusion.
The term “Health Care Laws” means Title XVIII of the Social Security Act, 42 U.S.C. §§ 1395-1395hhh (the Medicare statute); Title XIX of the Social Security Act, 42 U.S.C. §§ 1396-1396v (the Medicaid statute); the Federal Anti-Kickback Statute, 42 U.S.C. § 1320a-7b(b); the civil False Claims Act, 31 U.S.C. §§ 3729 et seq.; the criminal False Claims Act, 42 U.S.C. 1320a-7b(a); any criminal laws relating to health care fraud and abuse, including but not limited to 18 U.S.C. Sections 286, 287, 1347 and 1349, and the health care fraud criminal provisions under the Health Insurance Portability and Accountability Act of 1996, 42 U.S.C. §§ 1320d et seq. (“HIPAA”); the Civil Monetary Penalties Law, 42 U.S.C. §§ 1320a-7a and 1320a-7b; the Physician Payments Sunshine Act, 42 U.S.C. § 1320a-7h; the Exclusion Statute, 42 U.S.C. § 1320a-7; the Federal Food, Drug, and Cosmetic Act, 21 U.S.C. §§ 301 et seq.; the Patient Protection and Affordable Care Act (Pub. L. 111-148), as amended by the Health Care and Education Reconciliation Act of 2010 (Pub. L. 111-152) and Section 1899 of the Social Security Act; the regulations promulgated pursuant to such laws; and any other local, state, federal, national, supranational and foreign laws, relating to the regulation of the Company and the ownership, testing, development, manufacture, packaging, processing, use, distribution, marketing, labeling, promotion, sale, offer for sale, storage, import, export or disposal of any product candidate or product under development, manufactured or distributed by the Company.
(aaa) Privacy Laws. Except as would not, individually or in the aggregate, reasonably be expected to have a Material Adverse Effect, the Company and its subsidiaries have complied and are presently in compliance with all internal and external privacy policies, industry standards, all applicable statutes, judgments, orders, rules, regulations of any court or arbitrator or other governmental or regulatory entity, any other legal obligations, and applicable data privacy and security laws and regulations, including, without limitation, the California Consumer Privacy Act (“CCPA”), the European Union General Data Protection Regulation (“GDPR”) (EU 2016/679) (collectively, “Privacy Laws”) and any other applicable contractual obligation, in each case relating to the collection, use, transfer, import, export, storage, protection, disposal and disclosure by the Company or any of its subsidiaries of personal, personally identifiable, household, sensitive, confidential or regulated data (“Data Security Obligations”). To ensure compliance with the Data Security Obligations, the Company and its subsidiaries have in place, comply with, and take appropriate steps reasonably designed to ensure compliance in all material respects with their policies and procedures relating to data privacy and security and the collection, storage, use, disclosure, handling and analysis of Personal Data (the “Policies”). The Company provides accurate notice of its Policies to its employees, third party vendors and representatives as required by the applicable Privacy Laws. The Policies provide accurate and sufficient notice of the Company’s then-current privacy practices relating to its subject matter and such Policies do not contain any material omissions of the Company’s then-current privacy practices. “Personal Data” means (i) a natural persons’ name, street address, telephone number, email address, photograph, social security number, bank information, or customer or account number; (ii) any information which would qualify as “personally identifying information” under the Federal Trade Commission Act, as amended; (iii) “personal data” as defined by GDPR; and (iv) any other piece of information that allows the identification of such natural person, or his or her family, or permits the collection or analysis of any data related to an identified person’s health or sexual
18