v3.25.4
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2025
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
The Cybersecurity Risk Management Program is designed to identify potential vulnerabilities and threats and develop strategies to mitigate and remediate them. To assess, identify, manage, address and minimize the effects of a cybersecurity threat or incident, or a series of related cybersecurity threats or incidents, the Company undertakes a range of activities, including continuous monitoring of its systems and networks, incident response planning, and employee training. The Company also has business continuity and disaster recovery plans in place in the event of a cybersecurity incident, which are regularly reviewed and updated as needed. The Company also regularly engages third-party assessors, consultants, auditors, and other experts to help identify, assess and address potential threats or incidents.
The Cybersecurity and Risk Management Team, as described below, is responsible for the operationalization of the Company's cybersecurity practices, which consists of, but are not limited to: (i) updating and enhancing the Cybersecurity Risk Management Program, (ii) overseeing third-party assessors, consultants, auditors, and other experts, and (iii) assessing, identifying, managing and addressing potential threats or incidents.
When a cybersecurity threat or incident is identified, the Cybersecurity and Risk Management Team will perform a technical investigation which typically consists of the following phases:
i.Detection, which includes identifying the threat or incident, gathering all available facts surrounding the matter and performing an initial analysis to determine its level of severity. If the incident is classified as “Severity 1,” the Materiality Committee, as defined below, is notified to further assess the matter.
ii.Containment and Eradication, which includes determining the cause and vulnerabilities so that the threat or incident can be isolated and eliminated.
iii.Recovery, which includes repairing the impacted systems, and if applicable, notifying and instructing impacted parties of next steps.
iv.Post-Incident, which includes issuing a report summarizing the threat or incident, and the steps taken in assessing and eliminating the threat, as well as steps to implement to attempt to prevent similar future incidents.
The Materiality Committee is responsible for assessing whether a threat or an incident has materially affected or is likely to materially affect the Company’s business strategy, results of operations or financial condition. The Materiality Committee considers both quantitative and qualitative factors. Once it is determined that a matter has had a material impact or it is reasonably likely to have a material impact on the Company, the Materiality Committee is required to immediately report the incident to the Disclosure Committee and Audit and Risk Committee (the "Audit Committee") of the Board of Directors (the “Board”).
The Company emphasizes continuous risk evaluation and mitigation to improve the Cybersecurity Risk Management Program’s resilience and to instill a culture of vigilance across the Company's business. To promote employee awareness of best practices, the Company socializes policies and tips through its intranet site, sends regular phishing simulations, emails newsletters and hosts cybersecurity learning exercises, all in addition to standard company-wide cybersecurity awareness trainings. The Company also participates in various cybersecurity network memberships, including:
H-ISAC: a global cybersecurity best practice-sharing and threat intelligence network for health care stakeholders and
Domestic Security Alliance Council: a partnership between U.S. government agencies and private sector organizations that exchanges security and intelligence information.
The Company has also implemented a risk management process designed to mitigate cybersecurity risks that arise from utilizing third-party service providers. The Company’s control over and ability to monitor the security posture of third parties with whom it does business remains limited and there can be no assurance that the Company can prevent, mitigate or remediate the risk of any compromise or failure in the security infrastructure owned or controlled by such third parties. Additionally, any contractual protections with such third parties, including the Company’s right to indemnification, if any at all, may be limited or insufficient to prevent a negative impact on its business from any such compromise or failure.
Impact of cybersecurity risks on business strategy, results of operations or financial condition
Despite our efforts, we cannot eliminate all risks from cybersecurity threats, or provide assurances that we have not experienced an undetected cybersecurity incident. For more information about these risks, please see “Risk Factors—Risks Relating to Information Technology—We have become increasingly dependent on information technology systems and infrastructure and any breakdown, interruption, breach or other compromise of our information technology systems or those of our third party service providers could subject us to liability or interrupt the operation of our business, which could have a material adverse effect on our business, financial condition, cash flows and results of operations and could cause the market value of our common shares to decline” under Item 1A of this Annual Report on Form 10-K.
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Board of Directors Oversight [Text Block]
Because cybersecurity and data privacy can affect all facets of the Company's business, the Company employs governance structures that facilitate cross-functional, proactive risk management. The Board is responsible for oversight of the Company’s risks from cybersecurity threats and incidents and the Audit Committee maintains primary responsibility related to monitoring this oversight. As noted above, the Company has in place the following teams who are responsible for maintaining various phases of the Cybersecurity Risk Management Program:
Cybersecurity and Risk Management Team which is led by the VP, IT Security and Risk Management, who reports directly to the Chief Information Officer (“CIO”). The Cybersecurity and Risk Management Team is overseen by: (i) the Executive Committee, which consists of, among others, the Chief Executive Officer, Chief Financial Officer, Chief Legal Officer and Chief Compliance and Privacy Officer, and (ii) the Audit Committee. The Cybersecurity and Risk Management Team is responsible for maintaining and carrying out the Cybersecurity Risk Management Program.
Materiality Committee, which is led by the CIO, Controller and Chief Accounting Officer, and SVP, Assistant General Counsel. The Cybersecurity and Risk Management Team informs the Materiality Committee of Severity 1 incidents and the Materiality Committee is then responsible for assessing whether a threat or an incident has materially affected or is likely to materially affect the Company’s business strategy, results of operations or financial condition. Once it is determined that a matter has had a material impact or it is reasonably likely to have a material impact on the Company, the Materiality Committee is required to immediately report the incident to the Disclosure Committee and Audit Committee.
Audit Committee, which is comprised of independent directors, oversees the Cybersecurity and Risk Management Team and the team’s implementation of its Cybersecurity Risk Management Program. The Audit Committee receives quarterly updates regarding cybersecurity risks and/or policy. In addition, the Materiality Committee updates the Audit Committee, as necessary, regarding any material cybersecurity incidents.
Disclosure Committee, which is led by the Chief Legal Officer and Chief Financial Officer. The Disclosure Committee is informed of potentially material threats and incidents by the Cybersecurity and Risk Management Team and Materiality Committee and the Disclosure Committee is responsible for the preparation, review and filing of any disclosure required by applicable law.
Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] Cybersecurity and Risk Management Team which is led by the VP, IT Security and Risk Management, who reports directly to the Chief Information Officer (“CIO”). The Cybersecurity and Risk Management Team is overseen by: (i) the Executive Committee, which consists of, among others, the Chief Executive Officer, Chief Financial Officer, Chief Legal Officer and Chief Compliance and Privacy Officer, and (ii) the Audit Committee. The Cybersecurity and Risk Management Team is responsible for maintaining and carrying out the Cybersecurity Risk Management Program.
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]
When a cybersecurity threat or incident is identified, the Cybersecurity and Risk Management Team will perform a technical investigation which typically consists of the following phases:
i.Detection, which includes identifying the threat or incident, gathering all available facts surrounding the matter and performing an initial analysis to determine its level of severity. If the incident is classified as “Severity 1,” the Materiality Committee, as defined below, is notified to further assess the matter.
ii.Containment and Eradication, which includes determining the cause and vulnerabilities so that the threat or incident can be isolated and eliminated.
iii.Recovery, which includes repairing the impacted systems, and if applicable, notifying and instructing impacted parties of next steps.
iv.Post-Incident, which includes issuing a report summarizing the threat or incident, and the steps taken in assessing and eliminating the threat, as well as steps to implement to attempt to prevent similar future incidents.
Cybersecurity Risk Role of Management [Text Block] The Cybersecurity and Risk Management Team, as described below, is responsible for the operationalization of the Company's cybersecurity practices, which consists of, but are not limited to: (i) updating and enhancing the Cybersecurity Risk Management Program, (ii) overseeing third-party assessors, consultants, auditors, and other experts, and (iii) assessing, identifying, managing and addressing potential threats or incidents.
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
Because cybersecurity and data privacy can affect all facets of the Company's business, the Company employs governance structures that facilitate cross-functional, proactive risk management. The Board is responsible for oversight of the Company’s risks from cybersecurity threats and incidents and the Audit Committee maintains primary responsibility related to monitoring this oversight. As noted above, the Company has in place the following teams who are responsible for maintaining various phases of the Cybersecurity Risk Management Program:
Cybersecurity and Risk Management Team which is led by the VP, IT Security and Risk Management, who reports directly to the Chief Information Officer (“CIO”). The Cybersecurity and Risk Management Team is overseen by: (i) the Executive Committee, which consists of, among others, the Chief Executive Officer, Chief Financial Officer, Chief Legal Officer and Chief Compliance and Privacy Officer, and (ii) the Audit Committee. The Cybersecurity and Risk Management Team is responsible for maintaining and carrying out the Cybersecurity Risk Management Program.
Materiality Committee, which is led by the CIO, Controller and Chief Accounting Officer, and SVP, Assistant General Counsel. The Cybersecurity and Risk Management Team informs the Materiality Committee of Severity 1 incidents and the Materiality Committee is then responsible for assessing whether a threat or an incident has materially affected or is likely to materially affect the Company’s business strategy, results of operations or financial condition. Once it is determined that a matter has had a material impact or it is reasonably likely to have a material impact on the Company, the Materiality Committee is required to immediately report the incident to the Disclosure Committee and Audit Committee.
Audit Committee, which is comprised of independent directors, oversees the Cybersecurity and Risk Management Team and the team’s implementation of its Cybersecurity Risk Management Program. The Audit Committee receives quarterly updates regarding cybersecurity risks and/or policy. In addition, the Materiality Committee updates the Audit Committee, as necessary, regarding any material cybersecurity incidents.
Disclosure Committee, which is led by the Chief Legal Officer and Chief Financial Officer. The Disclosure Committee is informed of potentially material threats and incidents by the Cybersecurity and Risk Management Team and Materiality Committee and the Disclosure Committee is responsible for the preparation, review and filing of any disclosure required by applicable law.
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
The Cybersecurity Risk Management Program is designed to identify potential vulnerabilities and threats and develop strategies to mitigate and remediate them. To assess, identify, manage, address and minimize the effects of a cybersecurity threat or incident, or a series of related cybersecurity threats or incidents, the Company undertakes a range of activities, including continuous monitoring of its systems and networks, incident response planning, and employee training. The Company also has business continuity and disaster recovery plans in place in the event of a cybersecurity incident, which are regularly reviewed and updated as needed. The Company also regularly engages third-party assessors, consultants, auditors, and other experts to help identify, assess and address potential threats or incidents.
The Cybersecurity and Risk Management Team, as described below, is responsible for the operationalization of the Company's cybersecurity practices, which consists of, but are not limited to: (i) updating and enhancing the Cybersecurity Risk Management Program, (ii) overseeing third-party assessors, consultants, auditors, and other experts, and (iii) assessing, identifying, managing and addressing potential threats or incidents.
When a cybersecurity threat or incident is identified, the Cybersecurity and Risk Management Team will perform a technical investigation which typically consists of the following phases:
i.Detection, which includes identifying the threat or incident, gathering all available facts surrounding the matter and performing an initial analysis to determine its level of severity. If the incident is classified as “Severity 1,” the Materiality Committee, as defined below, is notified to further assess the matter.
ii.Containment and Eradication, which includes determining the cause and vulnerabilities so that the threat or incident can be isolated and eliminated.
iii.Recovery, which includes repairing the impacted systems, and if applicable, notifying and instructing impacted parties of next steps.
iv.Post-Incident, which includes issuing a report summarizing the threat or incident, and the steps taken in assessing and eliminating the threat, as well as steps to implement to attempt to prevent similar future incidents.
The Materiality Committee is responsible for assessing whether a threat or an incident has materially affected or is likely to materially affect the Company’s business strategy, results of operations or financial condition. The Materiality Committee considers both quantitative and qualitative factors. Once it is determined that a matter has had a material impact or it is reasonably likely to have a material impact on the Company, the Materiality Committee is required to immediately report the incident to the Disclosure Committee and Audit and Risk Committee (the "Audit Committee") of the Board of Directors (the “Board”).
The Company emphasizes continuous risk evaluation and mitigation to improve the Cybersecurity Risk Management Program’s resilience and to instill a culture of vigilance across the Company's business. To promote employee awareness of best practices, the Company socializes policies and tips through its intranet site, sends regular phishing simulations, emails newsletters and hosts cybersecurity learning exercises, all in addition to standard company-wide cybersecurity awareness trainings. The Company also participates in various cybersecurity network memberships, including:
H-ISAC: a global cybersecurity best practice-sharing and threat intelligence network for health care stakeholders and
Domestic Security Alliance Council: a partnership between U.S. government agencies and private sector organizations that exchanges security and intelligence information.
The Company has also implemented a risk management process designed to mitigate cybersecurity risks that arise from utilizing third-party service providers. The Company’s control over and ability to monitor the security posture of third parties with whom it does business remains limited and there can be no assurance that the Company can prevent, mitigate or remediate the risk of any compromise or failure in the security infrastructure owned or controlled by such third parties. Additionally, any contractual protections with such third parties, including the Company’s right to indemnification, if any at all, may be limited or insufficient to prevent a negative impact on its business from any such compromise or failure.
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true