XML 38 R21.htm IDEA: XBRL DOCUMENT v3.26.1
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2025
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
Our cybersecurity policies, standards, processes and practices are designed to align with recognized frameworks, such as those established by the National Institute of Standards and Technology, or NIST, and the International Organization for Standardization. This does not imply that we meet any particular technical standards, specifications, or requirements, only that we use such frameworks as a guide to help us identify, assess and manage cybersecurity risks relevant to our business. In general, we seek to address cybersecurity risks through a comprehensive, cross-functional approach that is designed to preserve the confidentiality, security and availability of the information that we collect and store by identifying, preventing and mitigating cybersecurity threats and responding to cybersecurity incidents when they occur.
Cybersecurity Risk Management and Strategy; Effect of Risk
To identify and assess material risks from cybersecurity threats, we maintain a cybersecurity program designed to ensure our systems are effective and prepared for information security risks, including monitoring for internal and external threats. We consider risks from cybersecurity threats alongside other company risks as part of our overall risk assessment process. We employ a range of tools and services depending on the sensitivity of the information and systems, including network and endpoint monitoring, audits, vulnerability assessments, penetration testing, and threat modeling, which are designed to inform our risk identification and assessment. As discussed in more detail under “Cybersecurity Governance” below, our audit committee provides oversight of our cybersecurity risk management and strategy processes, which are led by our Chief Financial Officer, General Counsel, and Director of Information Technology.
We also identify cybersecurity risks by engaging experts to attempt to test our information systems. Depending on the sensitivity of the data and systems in question, we may also undertake activities such as:
a.monitoring emerging data protection laws;
b.implementing relevant policies, practices, and contracts (as applicable);
c.employing technical safeguards that are designed to protect our information systems from cybersecurity threats, including firewalls, intrusion prevention and detection systems, anti-malware functionality and access controls, which are evaluated through vulnerability assessments and cybersecurity threat intelligence;
d.providing training for our employees and contractors regarding cybersecurity threats;
e.conducting phishing simulations;
f.conducting annual cybersecurity management and incident response training; and
g.carrying information security risk insurance.
Our incident response plan is designed to coordinate the activities we take to prepare for, detect, respond to and recover from cybersecurity incidents, and includes processes to triage, assess severity for, escalate, contain, investigate and remediate incidents, as well as to comply with potentially applicable legal obligations and mitigate damage to our business and reputation.
As part of the above processes, we engage with consultants, internal auditors and other third parties, including annually having an independent third-party review of our cybersecurity.
Our processes also address cybersecurity threat risks associated with our use of third-party service providers, including our suppliers and manufacturers or who have access to patient and employee data or our systems. In addition, cybersecurity considerations affect the selection and oversight of our third-party service providers. We perform diligence on third parties that have access to our systems, data or facilities that house such systems or data, depending on the nature and sensitivity of the data or systems in question, and monitor cybersecurity threat risks identified through such diligence. Additionally, we generally require certain third parties to agree by contract to
manage their cybersecurity risks in specified ways, and to agree to be subject to cybersecurity audits, which we may conduct as appropriate.
We describe whether and how risks from identified cybersecurity threats, including as a result of any previous cybersecurity incidents, have materially affected or are reasonably likely to materially affect us, including our business strategy, results of operations, or financial condition, under the heading “Cybersecurity breaches could expose us to material liability, damage our reputation, compromise our confidential information or otherwise adversely affect our business,” which disclosures are incorporated by reference herein.
Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block]
Our cybersecurity policies, standards, processes and practices are designed to align with recognized frameworks, such as those established by the National Institute of Standards and Technology, or NIST, and the International Organization for Standardization. This does not imply that we meet any particular technical standards, specifications, or requirements, only that we use such frameworks as a guide to help us identify, assess and manage cybersecurity risks relevant to our business. In general, we seek to address cybersecurity risks through a comprehensive, cross-functional approach that is designed to preserve the confidentiality, security and availability of the information that we collect and store by identifying, preventing and mitigating cybersecurity threats and responding to cybersecurity incidents when they occur.
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Board of Directors Oversight [Text Block]
Our board of directors is actively involved in oversight of our risk management activities, and cybersecurity represents an important element of our overall approach to risk management. The audit committee of our board of directors is responsible for the oversight of risks from cybersecurity threats.
At least annually, our audit committee receives an update from management of our cybersecurity threat risk management and strategy processes which may cover topics such as data security posture, results from third-party assessments, progress towards predetermined risk-mitigation-related goals, our incident response plan, and material cybersecurity threat risks or incidents and developments, as well as the steps management has taken to respond to such risks. In such sessions, our audit committee generally receives materials discussing current and emerging material cybersecurity threat risks, and describing our efforts to mitigate those risks, as well as recent developments, evolving standards, technological developments and information security considerations arising with respect to our peers and third parties, and discusses such matters with our Director of Information Technology. Our audit committee also receives information regarding cybersecurity incidents that meet certain thresholds.
Our cybersecurity risk management and strategy processes, which are discussed in greater detail above, are led primarily by our Director of Information Technology, who has several years of prior work experience in various roles involving managing information security, developing cybersecurity strategy, and implementing effective information and cybersecurity programs. Our Director of Information Technology is informed with regard to and monitors the prevention, mitigation, detection, and remediation of cybersecurity incidents through his management of, and participation in, the cybersecurity risk management and strategy processes described above, including the operation of our incident response plan. As discussed above, our management team reports to the audit committee of our board of directors about cybersecurity threat risks, among other cybersecurity related matters, at least annually.
Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] The audit committee of our board of directors is responsible for the oversight of risks from cybersecurity threats.
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] At least annually, our audit committee receives an update from management of our cybersecurity threat risk management and strategy processes which may cover topics such as data security posture, results from third-party assessments, progress towards predetermined risk-mitigation-related goals, our incident response plan, and material cybersecurity threat risks or incidents and developments, as well as the steps management has taken to respond to such risks.
Cybersecurity Risk Role of Management [Text Block] Our cybersecurity risk management and strategy processes, which are discussed in greater detail above, are led primarily by our Director of Information Technology, who has
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
Our board of directors is actively involved in oversight of our risk management activities, and cybersecurity represents an important element of our overall approach to risk management. The audit committee of our board of directors is responsible for the oversight of risks from cybersecurity threats.
At least annually, our audit committee receives an update from management of our cybersecurity threat risk management and strategy processes which may cover topics such as data security posture, results from third-party assessments, progress towards predetermined risk-mitigation-related goals, our incident response plan, and material cybersecurity threat risks or incidents and developments, as well as the steps management has taken to respond to such risks. In such sessions, our audit committee generally receives materials discussing current and emerging material cybersecurity threat risks, and describing our efforts to mitigate those risks, as well as recent developments, evolving standards, technological developments and information security considerations arising with respect to our peers and third parties, and discusses such matters with our Director of Information Technology. Our audit committee also receives information regarding cybersecurity incidents that meet certain thresholds.
Cybersecurity Risk Management Expertise of Management Responsible [Text Block] In such sessions, our audit committee generally receives materials discussing current and emerging material cybersecurity threat risks, and describing our efforts to mitigate those risks, as well as recent developments, evolving standards, technological developments and information security considerations arising with respect to our peers and third parties, and discusses such matters with our Director of Information Technology. Our audit committee also receives information regarding cybersecurity incidents that meet certain thresholds.
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block] Our Director of Information Technology is informed with regard to and monitors the prevention, mitigation, detection, and remediation of cybersecurity incidents through his management of, and participation in, the cybersecurity risk management and strategy processes described above, including the operation of our incident response plan. As discussed above, our management team reports to the audit committee of our board of directors about cybersecurity threat risks, among other cybersecurity related matters, at least annually.
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true