XML 48 R33.htm IDEA: XBRL DOCUMENT v3.26.1
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Mar. 31, 2026
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
Risk Management and Security
As a diversified healthcare services leader that is dedicated to advancing health outcomes for patients everywhere, cybersecurity risk management is integral to our enterprise risk management strategy. Our management, with involvement and input from external consultants and oversight from our Board of Directors (“Board”), performs an annual enterprise-wide risk assessment (“ERA”) to identify key existing and emerging risks. One of the principal risks identified and assessed through this process is cybersecurity, which remains a key focus for the Company, management, and our Board.
Our Cybersecurity Program is aligned with the National Institute of Standards and Technology Cybersecurity Framework (“NIST CSF”) and other industry best practices. The Cybersecurity Program is designed to identify, assess and mitigate material cybersecurity risks.
We have implemented cybersecurity controls designed to protect our systems, data, and operations from cybersecurity risks. Enterprise-wide cybersecurity and privacy training continues to serve an important role in risk reduction and protection of the Company and our stakeholders. We require periodic access-based and role-based privacy and cybersecurity training, which is updated to reflect changes in the threat environment, audit findings, laws, and regulations. We also engage and educate employees through cybersecurity and privacy awareness programs and communication campaigns. In addition, as cybersecurity attacks become increasingly complex in part due to the emergence of new AI enabled technologies that allow threat actors to target particular entities and IT systems, we are taking measures to manage these risks by deploying new tools and capabilities, including AI.
Our Cybersecurity Incident Response Plan (“CIRP”) provides a framework for responding to cybersecurity incidents. The CIRP is based on the NIST CSF framework and governs activities such as preparation, detection, coordination, eradication and recovery. It also provides processes for appropriate escalations to the Company’s senior management, disclosure committee, Board, and relevant Board committees. The CIRP is routinely tested, reviewed, and updated as appropriate under the leadership of our Chief Information Officer and Chief Technology Officer (“CIO/CTO”) with the assistance of the Company’s Chief Information Security Officer (“CISO”).
We also engage internal and external assessors, consultants, auditors, and other third-parties, to assess our Cybersecurity Program’s maturity. We manage cybersecurity risks associated with third parties, including vendors, service providers, and external users of our systems. This includes conducting due diligence on the third parties we use along with using third party cybersecurity monitoring and alerting tools.
Although we believe that we maintain reasonable cybersecurity measures, we recognize that cyber threats continue to evolve, and no system is immune to risk.
As of March 31, 2026, we are not aware of any cybersecurity incidents that have materially affected, or are reasonably likely to materially affect, our business strategy, results of operations, or financial condition. For a discussion of whether and how any risks from cybersecurity threats have affected or, if realized, are reasonably likely to materially affect the Company, see “Risk Factors” in Item 1A of Part I above for additional information on risks related to our business, including for example, risks related to privacy and data protection, cybersecurity incidents, third-party relationships, and continuity of our information systems and networks, operational technology, and technology products or services.
Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block]
As a diversified healthcare services leader that is dedicated to advancing health outcomes for patients everywhere, cybersecurity risk management is integral to our enterprise risk management strategy. Our management, with involvement and input from external consultants and oversight from our Board of Directors (“Board”), performs an annual enterprise-wide risk assessment (“ERA”) to identify key existing and emerging risks. One of the principal risks identified and assessed through this process is cybersecurity, which remains a key focus for the Company, management, and our Board.
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Board of Directors Oversight [Text Block]
Governance
Our CIO/CTO leads management’s assessment and management of cybersecurity risk with the assistance of the Company’s CISO who reports to the CIO/CTO. The CIO/CTO reports to our CEO, is a member of the Executive Operating Team, and provides updates to the Board about cybersecurity matters. Our CIO/CTO has more than 30 years of experience managing technology and risks, and advising on cybersecurity issues and our CISO has more than 22 years of relevant experience, is a Certified Information System Security Professional (CISSP), and a Certified Information Systems Auditor (CISA).
Cybersecurity is among the risks identified by our ERA for Board-level oversight. The Audit Committee of the Board has oversight of information technology controls related to financial reporting, while the Compliance Committee of the Board has oversight of technology-related risk, including privacy and cybersecurity. The Audit Committee and Compliance Committee meet jointly at least annually to review cybersecurity risks and programs, and they are updated as needed on cybersecurity threats, incidents, or new developments in our cybersecurity risk profile. The chairs of the Audit Committee and Compliance Committee provide updates to the Board after each committee meeting. The CIO/CTO and CISO provide regular updates to the Board, Audit Committee, or Compliance Committee about material risks from cybersecurity threats. The CIO/CTO or CISO also provides regular updates to the Board, Audit Committee, or Compliance Committee about cybersecurity trends and regulatory updates, data governance and usage, technology infrastructure, our training and compliance efforts, and implications for our business strategy. In addition to the information provided in these meetings, members of our Board have access to continuing education, which includes topics relating to cybersecurity risks.
Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] The Audit Committee of the Board has oversight of information technology controls related to financial reporting, while the Compliance Committee of the Board has oversight of technology-related risk, including privacy and cybersecurity.
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] The Audit Committee and Compliance Committee meet jointly at least annually to review cybersecurity risks and programs, and they are updated as needed on cybersecurity threats, incidents, or new developments in our cybersecurity risk profile. The chairs of the Audit Committee and Compliance Committee provide updates to the Board after each committee meeting.
Cybersecurity Risk Role of Management [Text Block] Our CIO/CTO leads management’s assessment and management of cybersecurity risk with the assistance of the Company’s CISO who reports to the CIO/CTO. The CIO/CTO reports to our CEO, is a member of the Executive Operating Team, and provides updates to the Board about cybersecurity matters.
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block] The CIO/CTO and CISO provide regular updates to the Board, Audit Committee, or Compliance Committee about material risks from cybersecurity threats. The CIO/CTO or CISO also provides regular updates to the Board, Audit Committee, or Compliance Committee about cybersecurity trends and regulatory updates, data governance and usage, technology infrastructure, our training and compliance efforts, and implications for our business strategy. In addition to the information provided in these meetings, members of our Board have access to continuing education, which includes topics relating to cybersecurity risks.
Cybersecurity Risk Management Expertise of Management Responsible [Text Block] Our CIO/CTO has more than 30 years of experience managing technology and risks, and advising on cybersecurity issues and our CISO has more than 22 years of relevant experience, is a Certified Information System Security Professional (CISSP), and a Certified Information Systems Auditor (CISA).
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block] The CIO/CTO and CISO provide regular updates to the Board, Audit Committee, or Compliance Committee about material risks from cybersecurity threats. The CIO/CTO or CISO also provides regular updates to the Board, Audit Committee, or Compliance Committee about cybersecurity trends and regulatory updates, data governance and usage, technology infrastructure, our training and compliance efforts, and implications for our business strategy. In addition to the information provided in these meetings, members of our Board have access to continuing education, which includes topics relating to cybersecurity risks.
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true