Political, economic and regulatory developments may further complicate pricing negotiations, and pricing negotiations may continue after coverage and reimbursement have been obtained. Reference pricing used by various countries and parallel distribution or arbitrage between low-priced and high-priced countries, can further reduce prices. To obtain reimbursement or pricing approval in some countries, we may be required to conduct a clinical trial that compares the cost-effectiveness of our product candidate to other available therapies, which is time-consuming and costly. If coverage and reimbursement of our product candidates are unavailable or limited in scope or amount, or if pricing is set at unsatisfactory levels, our business could be harmed, possibly materially.
We are subject to stringent and evolving U.S. and foreign laws, regulations, rules, industry standards, contractual obligations, policies and other obligations related to data security and privacy. Our actual or perceived failure to comply with such obligations could lead to government enforcement actions, which could include civil, criminal or administrative penalties, litigation (including class claims) and arbitration demands, fines and penalties, disruptions of our business operations, reputational harm, adverse publicity, and/or and other adverse business consequences and could negatively affect our operating results and business, financial condition, results of operations and prospects.
In the ordinary course of business, we collect, receive, store, process, generate, use, transfer, disclose, make accessible, protect, secure, dispose of, transmit, and share (collectively, processing) personal data and other sensitive information, including proprietary and confidential business data, trade secrets, intellectual property, data we may collect about trial participants in connection with clinical trials, sensitive third-party data, business plans, transactions, and financial information.
The global data protection landscape is rapidly evolving, and we are or may become subject to or be affected by evolving federal, state and foreign data protection laws and regulations, such as laws and regulations that address privacy and data security. In the United States, numerous federal and state laws and regulations, including federal and state health information privacy laws, state data breach notification laws, and federal and state consumer protection laws, such as Section 5 of the Federal Trade Commission Act, govern the collection, use, disclosure and protection of health information and other personal information and could apply to our operations. These laws and regulations are subject to differing interpretations and may be inconsistent among jurisdictions, and guidance on implementation and compliance practices are often updated or otherwise revised, which adds to the complexity of processing personal information. HIPAA, as amended by HITECH, imposes, among other things, certain standards relating to the privacy, security, transmission and breach reporting of individually identifiable health information. We do not believe that we are currently acting as a covered entity or business associate under HIPAA and thus are not directly subject to its requirements or penalties. However, we may obtain health information from third parties, including research institutions from which we obtain clinical trial data, that are subject to privacy and security requirements under HIPAA. Depending on the facts and circumstances, we could face substantial criminal penalties if we knowingly receive individually identifiable health information from a HIPAA-covered healthcare provider or research institution that has not satisfied HIPAA’s requirements for disclosure of individually identifiable health information.
Certain states have also adopted comparable privacy and security laws and regulations governing the privacy, processing and protection of personal information. For example, the California Consumer Privacy Act of 2018 (“CCPA”) requires businesses to provide specific disclosures in privacy notices and honor requests of California residents to exercise certain privacy rights. The CCPA provides for civil penalties of up to $7,500 per violation and allows private litigants affected by certain data breaches to recover significant statutory damages. Although the CCPA exempts some data processed in the context of clinical trials, the CCPA increases compliance costs and potential liability with respect to other personal data we maintain about California residents. In addition, the California Privacy Rights Act of 2020 (“CPRA”) expands the CCPA’s requirements, including by adding a new right for individuals to correct their personal information and establishing a new regulatory agency to implement and enforce the law. Several other states, including Virginia, Colorado, Utah, and Connecticut have also passed comprehensive privacy laws, and similar laws have been passed or are being considered in other states, as well as at the federal and local levels. While