commission(s), certain customer incentive programs and other business arrangements generally. Activities subject to these laws also involve the improper use of information received in the course of patient recruitment for clinical trials. See the section in the Company’s Annual Report on Form 10-K for the fiscal year ended December 31, 2021 entitled “Business – Government Regulation – Other Healthcare Laws.”
The distribution of pharmaceutical products is subject to additional requirements and regulations, including extensive record-keeping, licensing, storage and security requirements intended to prevent the unauthorized sale of pharmaceutical products. In addition, there has been a trend of increased state regulation of payments made to physicians for marketing. Some states mandate implementation of corporate compliance programs, along with the tracking and reporting of gifts, compensation, and other remuneration to physicians.
The scope and enforcement of each of these laws is uncertain and subject to rapid change in the current environment of healthcare reform, especially in light of the lack of applicable precedent and regulations. Federal and state enforcement bodies have recently increased their scrutiny of interactions between healthcare companies and healthcare providers, which has led to a number of investigations, prosecutions, convictions and settlements in the healthcare industry. Ensuring business arrangements comply with applicable healthcare laws, as well as responding to possible investigations by government authorities, can be time and resource consuming and can divert a company’s attention from the business.
It is possible that governmental and enforcement authorities will conclude that our business practices may not comply with current or future statutes, regulations or case law interpreting applicable fraud and abuse or other healthcare laws and regulations. If any such actions are instituted against us, and we are not successful in defending ourselves or asserting our rights, those actions could have a significant impact on our business, including the imposition of civil, criminal and administrative penalties, damages, fines, disgorgement, individual imprisonment, possible exclusion from participation in federal and state funded healthcare programs, contractual damages and the curtailment or restricting of our operations, as well as additional reporting obligations and oversight if we become subject to a corporate integrity agreement or other agreement to resolve allegations of non-compliance with these laws. Any action for violation of these laws, even if successfully defended, could cause a pharmaceutical manufacturer to incur significant legal expenses and divert management’s attention from the operation of the business. Prohibitions or restrictions on sales or withdrawal of future marketed products could materially affect business in an adverse way.
Failure to comply with health and data protection laws and regulations could lead to government enforcement actions (which could include civil or criminal penalties), private litigation, and/or adverse publicity and could negatively affect our operating results and business.
We, our CROs, and any potential collaborators may be subject to strict and changing federal, state, and foreign data protection laws and regulations (i.e., laws and regulations that address privacy and data security) and policies and contractual obligations related to data privacy and security. In the U.S., numerous federal and state laws and regulations, including federal health information privacy laws, state data breach notification laws, state health information privacy laws, and federal and state consumer protection laws (e.g., Section 5 of the Federal Trade Commission Act), that govern the collection, use, disclosure and protection of health-related and other personal information could apply to our operations or the operations of our CROs and collaborators. In addition, we may obtain health information from third parties (including research institutions from which we obtain clinical trial data) that are subject to privacy and security requirements under HIPAA, as amended by HITECH. Depending on the facts and circumstances, we could be subject to civil, criminal, and administrative penalties if we knowingly obtain, use, or disclose individually identifiable health information maintained by a HIPAA-covered entity in a manner that is not authorized or permitted by HIPAA.
Compliance with U.S. and international data protection laws and regulations could require us to take on more onerous obligations in our contracts, restrict our ability to collect, use and disclose data, or in some cases, impact our ability to operate in certain jurisdictions. Failure to comply with these laws and regulations could result in government enforcement actions (which could include civil, criminal and administrative penalties), private litigation, and/or adverse publicity and could negatively affect our operating results and business. Moreover, clinical trial subjects, employees and other individuals about whom we or our potential collaborators obtain personal information, as well as the providers who share this information with us, may limit our ability to collect, use and disclose the information. Claims that we have violated individuals’ privacy rights, failed to comply with data protection laws, or breached our contractual obligations,