Failure to comply with health and data protection laws and regulations could lead to government enforcement actions, including civil or criminal penalties, private litigation, and adverse publicity and could negatively affect our operating results and business.
We and any current and future collaborators may be subject to federal, state/provincial, municipal and foreign data protection laws and regulations, such as laws and regulations that address privacy and data security. In the United States, numerous federal and state laws and regulations, including federal health information privacy laws, state data breach notification laws, state health information privacy laws, and federal and state consumer protection laws, including Section 5 of the Federal Trade Commission Act, that govern the collection, use, disclosure and protection of health-related and other personal information could apply to our operations or the operations of our collaborators. In addition, we may obtain health information from third parties, including research institutions from which we obtain clinical trial data, that are subject to privacy and security requirements under HIPAA, as amended by HITECH. Depending on the facts and circumstances, we could be subject to civil, criminal, and administrative penalties if we violate HIPAA.
Compliance with U.S. and international data protection laws and regulations could require us to take on more onerous obligations in our contracts, restrict our ability to collect, use and disclose data, or in some cases, impact our ability to operate in certain jurisdictions. Failure to comply with these laws and regulations could result in government enforcement actions (which could include civil, criminal, and administrative penalties), private litigation, and/or adverse publicity and could negatively affect our operating results and business. Moreover, clinical trial subjects, employees, and other individuals about whom we or our current or future collaborators obtain personal information, as well as the providers who share this information with us, may limit our ability to collect, use and disclose the information. Claims that we have violated individuals’ privacy rights, failed to comply with data protection laws, or breached our contractual obligations, even if we are not found liable, could be expensive and time-consuming to defend and could result in adverse publicity that could harm our business.
Our employees, principal investigators, consultants, and commercial partners may engage in misconduct or other improper activities, including non-compliance with regulatory standards and requirements and insider trading.
We are exposed to the risk of fraud or other misconduct by our employees, principal investigators, consultants, and commercial partners. Misconduct by these parties could include intentional failures to comply with FDA regulations or the regulations applicable in other jurisdictions, provide accurate information to the FDA and other regulatory authorities, comply with healthcare fraud and abuse laws and regulations in the United States and abroad, report financial information or data accurately or disclose unauthorized activities to us. In particular, sales, marketing and business arrangements in the healthcare industry are subject to extensive laws and regulations intended to prevent fraud, misconduct, kickbacks, self-dealing and other abusive practices. These laws and regulations restrict or prohibit a wide range of pricing, discounting, marketing and promotion, sales commission, customer incentive programs and other business arrangements. Such misconduct also could involve the improper use of information obtained in the course of clinical trials or interactions with the FDA or other regulatory authorities, which could result in regulatory sanctions and cause serious harm to our reputation. It is not always possible to identify and deter employee misconduct, and the precautions we take to detect and prevent this activity may not be effective in controlling unknown or unmanaged risks or losses or in protecting us from government investigations or other actions or lawsuits stemming from a failure to comply with these laws or regulations. If any such actions are instituted against us and we are not successful in defending ourselves or asserting our rights, those actions could result in significant civil, criminal and administrative penalties, damages, fines, disgorgement, imprisonment, exclusion from participating in government funded healthcare programs, such as Medicare and Medicaid, additional reporting requirements and oversight if we become subject to a corporate integrity agreement or similar agreement to resolve allegations of non-compliance with these laws, contractual damages, reputational harm and the curtailment or restructuring of our operations, any of which could have a negative impact on our business, financial condition, results of operations and prospects.
If our information technology systems, or the information technology systems of our CROs, our CMOs, service providers, our current and potential future partners or other third parties upon which we rely were compromised, we could experience adverse consequences, including but not limited to material disruptions to our business operations, regulatory investigations or actions, litigation, fines and penalties, reputational harm, loss of revenue or profits, or other adverse consequences.
We collect, store, receive, process, generate, use, transfer, disclose, make accessible, protect, secure, dispose of, share, and transmit (collectively, process) proprietary, confidential and sensitive information, including personal information (such as health-related data of clinical trial participants and employee information), in the course of our business. Similarly, third-parties upon which we rely process certain of that information on our behalf.
76