not discover all such incidents or activity or be able to respond or otherwise address them promptly, in sufficient respects or at all. Any specific interruption or attack, any failure to maintain performance, reliability, security, and availability of our products, or failure to prevent software bugs and other corruptants such as those listed above, to the satisfaction of our clients or their patients, may harm our reputation and our ability to retain existing clients, negatively affect our clients and their patients, and adversely impact our business, results of operations, and financial condition.
In addition, some of our third-party service providers and vendors also Process our personal information and other sensitive information such as our clients’ data on our behalf. These service providers and vendors are subject to similar threats of cyber-attacks, security incidents, and other malicious internet-based activities, which could also expose us to risk of loss, litigation, potential liability, and/or other costs. We may have limited insight into the data privacy or security practices of third-party vendors and providers, including as it relates to our AI algorithms. We have also acquired and may continue to acquire companies that are vulnerable to cyber-attacks and security incidents and breaches, and we may be responsible for any such attacks, incidents, and breaches of these newly acquired companies.
Further, the security systems in place at our employees’, vendors’, and service providers’ offices and homes may be less secure than those used in our offices, and while we have implemented technical, physical, and administrative safeguards to help protect our systems when our employees, vendors, and service providers work from their offices, homes, and other remote locations, we may be subject to increased cybersecurity risk, which could expose us to risks of data or financial loss, and could disrupt our business operations. There is no guarantee that the data security and privacy safeguards we have put in place will ultimately be effective or that we will not encounter risks associated with employees, vendors, and service providers accessing company data and systems remotely. If an actual or perceived breach of security occurs to our systems or a third-party’s systems, we could be required to expend significant resources to mitigate the breach of security, pay any applicable fines, and address matters related to any such breach, including notifying impacted individuals or regulators, making public disclosures, and addressing reputational harm.
Any theft, loss, or misappropriation of, or access to, clients’, or other proprietary data, or other breach of our third-party service providers’ or vendors’ information technology systems could result in fines, legal claims, or proceedings, including regulatory investigations and actions, or liability for failure to comply with privacy and information security laws, which could disrupt our operations, damage our reputation, and expose us to claims from clients, individuals, and others, any of which could have a material adverse effect on our business, financial condition, and results of operations.
The costs of mitigating data security risks are significant and are likely to increase in the future. Although we carry cybersecurity insurance, we cannot ensure our limits are sufficient to cover us against all potential losses for damages or fines in an amount exceeding our policy.
Our business is subject to complex and evolving laws and regulations regarding privacy, data protection, and cybersecurity.
There are numerous U.S. federal, state, local, and international laws and regulations regarding privacy, data protection, and cybersecurity that govern the Processing of personal information and other information. The scope of these laws and regulations is expanding and evolving, subject to differing interpretations, may be inconsistent among jurisdictions, or conflict with other rules. We are also subject to the terms of our privacy policies and obligations to third parties related to privacy, data protection, and cybersecurity.
For example, the California Consumer Privacy Act of 2018 (the “CCPA”) took effect on January 1, 2020, which broadly defines personal information, gives California residents expanded privacy rights and protections, and provides for civil penalties for certain violations. Furthermore, in November 2020, California voters passed the California Privacy Rights and Enforcement Act of 2020 (the “CPRA”), which amended and expanded the CCPA with additional data privacy compliance requirements and established a regulatory agency dedicated to enforcing those requirements. Additional states, such as Virginia, Colorado, Connecticut, Iowa, Utah, and others have