Ensuring business arrangements comply with applicable healthcare laws, as well as responding to possible investigations by government authorities, can be time- and resource-consuming and can divert a company’s attention from the business.
Efforts to ensure that our business arrangements will comply with applicable healthcare laws may involve substantial costs. It is possible that governmental authorities will conclude that our business practices may not comply with current or future statutes, regulations, guidance or case law interpreting applicable fraud and abuse or other healthcare laws and regulations. If any such actions are instituted against us, and we are not successful in defending ourselves or asserting our rights, those actions could have a significant impact on our business, including the imposition of significant penalties, including civil, criminal and administrative penalties, damages, fines, disgorgement, individual imprisonment, possible exclusion from participation in federal and state funded healthcare programs, contractual damages and the curtailment or restricting of our operations, as well as additional reporting obligations and oversight if we become subject to a corporate integrity agreement or other agreement to resolve allegations of non-compliance with these laws. Any action for violation of these laws, even if successfully defended, could cause a device manufacturer to incur significant legal expenses and divert management’s attention from the operation of the business. Prohibitions or restrictions on sales or withdrawal of future marketed products could materially affect business in an adverse way. It is not always possible to identify and deter employee misconduct, and the precautions we take to detect and prevent inappropriate conduct may not be effective in controlling unknown or unmanaged risks or losses or in protecting us from governmental investigations or other actions or lawsuits stemming from a failure to be in compliance with such laws or regulations. In addition, the approval and commercialization of any of our investigational devices outside the United States will also likely subject us to foreign equivalents of the healthcare laws mentioned above, among other foreign laws.
We and the third parties with whom we work are subject to stringent and evolving U.S. and foreign laws, regulations, and rules, contractual obligations, industry standards, policies and other obligations related to data privacy and security. Our (or the third parties with whom we work) actual or perceived failure to comply with such obligations could lead to regulatory investigations or actions; litigation (including class claims) and mass arbitration demands; fines and penalties; disruptions of our business operations; reputational harm; loss of revenue or profits; loss of customers or sales; and other adverse business consequences.
In the ordinary course of business, we collect, receive, store, process, generate, use, transfer, disclose, make accessible, protect, secure, dispose of, transmit, and share (collectively, process) personal data and other sensitive information, including proprietary and confidential business data, trade secrets, intellectual property, data we collect about trial participants in connection with clinical trials, protected health information, individually identifiable health information, sensitive third-party data, insurance data, and payment data (collectively, sensitive information).
Our data processing activities subject us to numerous data privacy and security obligations, such as various laws, regulations, guidance, industry standards, external and internal privacy and security policies, contractual requirements, and other obligations relating to data privacy and security.
In the United States, federal, state, and local governments have enacted numerous data privacy and security laws, including data breach notification laws, personal data privacy laws, consumer protection laws (e.g., Section 5 of the Federal Trade Commission Act), and other similar laws (e.g., wiretapping laws). For example, we are considered a “covered entity” under HIPAA, as amended by HITECH, and regulations implemented thereunder, or collectively HIPAA. HIPAA imposes specific requirements relating to the privacy, security, breach notification obligation on certain healthcare providers, health plans, healthcare clearinghouses, known as covered entities, as well as their business associates that perform certain services that involve creating, receiving, maintaining or transmitting individually identifiable health information for or on behalf of such covered entities, and their covered subcontractors. HIPAA requires covered entities and business associates to develop and maintain policies with respect to the protection of, use and disclosure of PHI, including the adoption of
64