damage from computer viruses, cybersecurity threats, computer hackers, malicious code, employee error or malfeasance, theft or misuse, denial-of-service attacks, sophisticated nation-state and nation-state-supported actors, unauthorized access, natural disasters, terrorism, war, fire and telecommunication and electrical failures. The risk of a security breach or disruption has generally increased as the number, intensity and sophistication of attempted attacks and intrusions from around the world have increased. We may not be able to anticipate all types of security threats, and we may not be able to implement preventive measures effective against all such security threats. The techniques used by cyber criminals change frequently, may not be recognized until launched, and can originate from a wide variety of sources, including outside groups such as external service providers, organized crime affiliates, terrorist organizations or hostile foreign governments or agencies. Our information technology and other internal infrastructure systems, including corporate firewalls, servers and connection to the Internet, face the risk of systemic failure that could disrupt our operations.
If such an event were to occur and cause interruptions in our operations or result in the unauthorized use, disclosure of or access to personally identifiable information or individually identifiable health information (potentially violating certain privacy laws such as the GDPR), it could result in a material disruption of our development programs and our business operations, whether due to a loss of our trade secrets or other similar disruptions cause us to breach our contractual obligations, subject us to mandatory corrective action, and otherwise subject us to liability under laws, regulations and contracts that protect the privacy and security of personal information, which could result in significant legal and financial exposure and reputational damages. Some applicable federal, state and foreign government requirements include obligations of companies to notify individuals of security breaches involving particular personally identifiable information, which could result from breaches experienced by us or by our vendors, contractors, or organizations with which we have formed strategic relationships. Any costs might not be covered by insurance, in whole or in part. Even though we may have contractual protections with such vendors, contractors, or other organizations, notifications and follow-up actions related to a security breach could impact our reputation, cause us to incur significant costs, including legal expenses, harm customer confidence, hurt our expansion into new markets, cause us to incur remediation costs, or cause us to lose existing customers. For example, the loss of clinical trial data from completed or future clinical trials could result in delays in our regulatory approval efforts and significantly increase our costs to recover or reproduce the data. We also rely on third parties to manufacture our product candidates, and similar events relating to their computer systems could also have a material adverse effect on our business. To the extent that any disruption or security breach were to result in a loss of, or damage to, our data or applications, or inappropriate disclosure or use of confidential or proprietary information, we could incur liability, the further development and commercialization of our product candidates could be delayed, and we could be subject to significant fines, penalties or liabilities for any noncompliance with certain privacy and security laws. Any of the foregoing could have a material adverse effect on our business, financial condition, results of operations or prospects.
Business disruptions could seriously harm our future revenue and financial condition and increase our costs and expenses.
Our operations could be subject to earthquakes, power shortages, telecommunications failures, water shortages, floods, hurricanes, typhoons, fires, extreme weather conditions, medical epidemics and other natural or manmade disasters or business interruptions, for which we are predominantly self-insured. We rely on third-party manufacturers to produce our product candidates. Our ability to obtain clinical supplies of our product candidates could be disrupted if the operations of these suppliers were affected by a man-made or natural disaster or other business interruption. The occurrence of any of these business disruptions could seriously harm our operations and financial condition and increase our costs and expenses.
Our employees and independent contractors, including principal investigators, CROs, consultants and vendors, may engage in misconduct or other improper activities, including noncompliance with regulatory standards and requirements.
We are exposed to the risk that our employees and independent contractors, including principal investigators, CROs, consultants and vendors, may engage in misconduct or other improper activities. Misconduct by these parties could include intentional, reckless and/or negligent conduct or disclosure of unauthorized activities to us that violate: (1) the laws and regulations of the FDA, the NMPA or other similar regulatory requirements, including those laws that require the reporting of true, complete and accurate information to such authorities, (2) manufacturing standards, including cGMP requirements, (3) federal and state data privacy, security, fraud and abuse and other
46