scientific and clinical personnel from universities and research institutions. Failure to succeed in clinical trials may make it more challenging to recruit and retain qualified scientific personnel.
Our internal computer systems, or those of our third-party collaborators or other contractors, may fail or suffer security breaches and cyber attacks, which could result in a material disruption of our development programs.
We believe that we take reasonable steps that are designed to protect the security, integrity and confidentiality of the information we collect, use, store, and disclose, but inadvertent or unauthorized data access may occur despite our efforts. For example, our system protections may be ineffective or inadequate, or we could be impacted by software bugs or other technical malfunctions, as well as employee error or malfeasance. Additionally, privacy and data protection laws are evolving, and it is possible that these laws may be interpreted and applied in a manner that is inconsistent with our data handling safeguards and practices that could result in fines, lawsuits, and other penalties, and significant changes to our or our third-party partners business practices and products and service offerings. To the extent that the measures we or our third-party business partners have taken prove to be insufficient or inadequate, we may become subject to litigation, breach notification obligations, or regulatory or administrative sanctions, which could result in significant fines, penalties, damages, harm to our reputation or loss of patients. While we have not experienced any material losses as a result of any system failure, accident or security breach to date, we have been the subject of certain phishing attempts in the past. If such an event were to occur and cause interruptions in our operations, it could result in a material disruption of our development programs and our business operations, whether due to a loss of our trade secrets or other proprietary information or other similar disruptions. Additionally, a party who circumvents our security measures could, among other effects, appropriate patient information or other proprietary data, cause interruptions in our operations, or expose patients to hacks, viruses, and other disruptions. For example, the loss of clinical trial data from completed or future clinical trials could result in delays in our regulatory approval efforts and significantly increase our costs to recover or reproduce the data. In addition, insurance coverage to compensate for any losses associated with such events may not be adequate to cover all potential losses. The development and maintenance of these systems, controls and processes is costly and requires ongoing monitoring and updating as technologies change and efforts to overcome security measures become increasingly sophisticated.
To the extent that any disruption, security breach, or cyber attack were to result in a loss of, or damage to, our data or applications, or inappropriate disclosure of personal, confidential or proprietary information, we could incur liability, our competitive position could be harmed and the further development and commercialization of our product candidates could be delayed. Depending on the nature of the information compromised, in the event of a data breach or other unauthorized access to our patient data, we may also have obligations to notify patients and regulators about the incident, and we may need to provide some form of remedy, such as a subscription to credit monitoring services, pay significant fines to one or more regulators, or pay compensation in connection with a class-action settlement (including under the new private right of action under the California Consumer Privacy Act of 2018, or the CCPA, which is expected to increase security breach litigation). Such breach notification laws continue to evolve and may be inconsistent from one jurisdiction to another. Complying with these obligations could cause us to incur substantial costs and could increase negative publicity surrounding any incident that compromises patient data. Additionally, the financial exposure from the events referenced above could either not be insured against or not be fully covered through any insurance that we may maintain, and there can be no assurance that the limitations of liability in any of our contracts would be enforceable or adequate or would otherwise protect us from liabilities or damages as a result of the events referenced above. Any of the foregoing could have an adverse effect on our business, reputation, operating results, and financial condition.
Our ability to utilize our net operating loss carryforwards may be subject to limitation.
As of December 31, 2020, we had federal, state and local net operating loss carryforwards, or NOLs, of $69.3 million, $69.3 million and $69.1 million, respectively; an aggregate of $1.5 million of the federal and state NOLs will begin to expire in 2037, if unused, and the remainder will carryforward indefinitely. To the extent that we continue to generate taxable losses, unused losses will carry forward to offset future taxable income, if any. Under legislative changes made by U.S. federal tax legislation, commonly referred to as the Tax Cuts and Jobs Act, or the TCJA, U.S. federal net operating losses incurred in 2018 and in future years may be carried forward indefinitely, but the ability to utilize such