XML 51 R35.htm IDEA: XBRL DOCUMENT v3.25.4
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2025
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
The proper confidentiality, integrity, and availability of the Company’s information systems are critical to the business. Securing the Company’s business information, customer, patient and employee data, and technology systems is essential for the continuity of its businesses, meeting applicable regulatory requirements, and maintaining the trust of its stakeholders. As part of its enterprise risk management program, the Company has processes in place to assess, identify, and manage material business, operational and legal risks from security threats, including cybersecurity threats. Such risks include business disruption, fraud, extortion, reputational harm, violations of laws and regulations, litigation, and harm to employees, patients, customers and business partners.
Information Security Program Overview
The Company’s information security program is structured around the cybersecurity framework (“Cybersecurity Framework”) of the National Institute of Standards and Technology (“NIST”), an agency of the U.S. Department of Commerce. The Cybersecurity Framework provides best practices to prevent, detect, identify, respond to, and recover from cyber-attacks. The Company’s information security program involves establishing information security policies, procedures and standards, investing in and implementing information protection processes, security measures and technologies, ongoing monitoring of systems and networks on which the Company relies, cybersecurity training and collaborating with public and private organizations on cyber threat information and best practices. We also assess and identify potential cyber and information security risks relating to third-party technology providers. These efforts may include due diligence to assess the party’s cybersecurity practices, controls, and compliance with relevant statutes and regulations; the use of contractual agreements that outline certain cybersecurity requirements; and using outside services to perform ongoing monitoring of select suppliers and third-party service providers. We may also collaborate with third-party suppliers to develop and align incident response plans. The Company actively monitors the current threat landscape in an effort to identify material risks arising from new and evolving cybersecurity threats. The Company engages an independent security firm to complete an annual cyber penetration test, as well as application and service specific tests. The Company engages an external third-party healthcare-focused cybersecurity assessor to perform an annual assessment or validation of the cybersecurity program in accordance with the Cybersecurity Framework and the HIPAA Security Risk Assessment Tool of the U.S. Health and Human Services Office for Civil Rights.
Management continuously assesses the potential impact of risks from cybersecurity threats on the Company, and regularly evaluates how such risks could materially affect the Company’s business strategy, operational results, and financial condition. As noted above, an assessment of the information security program leveraging the Cybersecurity Framework is completed annually by an independent and qualified external third-party cybersecurity assessor. The Company has not experienced a cybersecurity breach or information security breach during the past four fiscal years. The Company, from time to time, has been notified of third-party information cybersecurity breaches, but none of them has had a material impact on the Company’s operations or financial results. The Company annually purchases a cybersecurity risk insurance policy to help defray the costs associated with any covered cybersecurity incident. Although the Company did not experience a material cybersecurity incident during the year ended December 31, 2025, the scope and impact of any future incident cannot be predicted.
Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block]
The proper confidentiality, integrity, and availability of the Company’s information systems are critical to the business. Securing the Company’s business information, customer, patient and employee data, and technology systems is essential for the continuity of its businesses, meeting applicable regulatory requirements, and maintaining the trust of its stakeholders. As part of its enterprise risk management program, the Company has processes in place to assess, identify, and manage material business, operational and legal risks from security threats, including cybersecurity threats. Such risks include business disruption, fraud, extortion, reputational harm, violations of laws and regulations, litigation, and harm to employees, patients, customers and business partners.
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Board of Directors Oversight [Text Block] The Board of Directors of the Company provides strategic oversight on information security matters, including risks associated with cybersecurity threats.
Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] The Company’s management, including the Company’s CIO and CISO, is responsible for assessing and managing material risks from cybersecurity threats.
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] The Company’s Chief Information Officer (“CIO”) is Brian Rusignuolo. The Company’s Chief Information Security Officer (“CISO”) is Justin Stover. Three directors of information security directly report to the CISO. The CISO directly reports to the CIO. The Company’s Chief Compliance Officer (“COO”) is Robert Breighner. The CISO and CCO serve as data protection officers. The CIO, CISO, and the CCO provide annual written reports and quarterly briefings on the Company’s information security program to the Board of Directors. They also provide quarterly information security updates to the Audit and Compliance Committee. The reports to the Board of Directors include details and metrics on, among other things, the Company’s quarterly Cybersecurity Framework assessment updates, internal and external threat intelligence, quarterly information security program progress, business associate risk assessments and ongoing monitoring, company-wide awareness training, device security compliance, routine resilience efforts including disaster recovery exercises, tabletop security incident response exercises, and cyber penetration tests.
Cybersecurity Risk Role of Management [Text Block]
The Company’s management, including the Company’s CIO and CISO, is responsible for assessing and managing material risks from cybersecurity threats. The Company’s CIO and CISO each have more than 20 years of experience in cybersecurity. The Company provides formalized information security and cybersecurity training for newly-hired employees and annually for existing employees. In addition, the Company provides cybersecurity awareness training and information security education throughout the year. The annual cybersecurity training curriculum includes modules on information security, the employee’s role in protecting Company information, recognizing different cybersecurity incidents, identifying phishing emails, understanding the appropriate personnel to approach with information or questions, and acceptance of the Company’s Information Security Policy. The Company’s management is informed of cybersecurity incidents through ongoing monitoring and, in some cases, through receipt of notifications from third-party service providers. The CISO maintains and annually updates a Cybersecurity Incident Response Plan, which is a guide for the Company’s cybersecurity team to respond effectively to cybersecurity incidents in a coordinated manner in the interest of minimizing the risk of harm. The team works with colleagues in various departments throughout the Company, including Information Technology, Human Resources, Legal, Risk Management and Compliance, to prevent, mitigate and remediate cybersecurity incidents impacting the Company.
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block] The Company’s management, including the Company’s CIO and CISO, is responsible for assessing and managing material risks from cybersecurity threats.
Cybersecurity Risk Management Expertise of Management Responsible [Text Block] The Company’s CIO and CISO each have more than 20 years of experience in cybersecurity.
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
The Board of Directors of the Company provides strategic oversight on information security matters, including risks associated with cybersecurity threats. The Company’s Chief Information Officer (“CIO”) is Brian Rusignuolo. The Company’s Chief Information Security Officer (“CISO”) is Justin Stover. Three directors of information security directly report to the CISO. The CISO directly reports to the CIO. The Company’s Chief Compliance Officer (“COO”) is Robert Breighner. The CISO and CCO serve as data protection officers. The CIO, CISO, and the CCO provide annual written reports and quarterly briefings on the Company’s information security program to the Board of Directors. They also provide quarterly information security updates to the Audit and Compliance Committee. The reports to the Board of Directors include details and metrics on, among other things, the Company’s quarterly Cybersecurity Framework assessment updates, internal and external threat intelligence, quarterly information security program progress, business associate risk assessments and ongoing monitoring, company-wide awareness training, device security compliance, routine resilience efforts including disaster recovery exercises, tabletop security incident response exercises, and cyber penetration tests.
Management’s Role in Information Security Risk Management
The Company’s management, including the Company’s CIO and CISO, is responsible for assessing and managing material risks from cybersecurity threats. The Company’s CIO and CISO each have more than 20 years of experience in cybersecurity. The Company provides formalized information security and cybersecurity training for newly-hired employees and annually for existing employees. In addition, the Company provides cybersecurity awareness training and information security education throughout the year. The annual cybersecurity training curriculum includes modules on information security, the employee’s role in protecting Company information, recognizing different cybersecurity incidents, identifying phishing emails, understanding the appropriate personnel to approach with information or questions, and acceptance of the Company’s Information Security Policy. The Company’s management is informed of cybersecurity incidents through ongoing monitoring and, in some cases, through receipt of notifications from third-party service providers. The CISO maintains and annually updates a Cybersecurity Incident Response Plan, which is a guide for the Company’s cybersecurity team to respond effectively to cybersecurity incidents in a coordinated manner in the interest of minimizing the risk of harm. The team works with colleagues in various departments throughout the Company, including Information Technology, Human Resources, Legal, Risk Management and Compliance, to prevent, mitigate and remediate cybersecurity incidents impacting the Company.
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true