We may receive health information and other highly sensitive or confidential information and data of patients and other third parties, which we may compile and analyze. Collection and use of this data might raise privacy and data protection concerns, which could negatively impact our business. There are numerous federal, state and international laws and regulations regarding privacy, data protection, information security, and the collection, storing, sharing, use, processing, transfer, disclosure, and protection of personal information and other data, and the scope of such laws and regulations may change, be subject to differing interpretations, and may be inconsistent among countries and regions we intend to operate in (e.g., the U.S., the European Union and Israel), or conflict with other laws and regulations. The regulatory framework for privacy and data protection worldwide is, and is likely to remain for the foreseeable future, uncertain and complex, and this or other actual or alleged obligations may be interpreted and applied in a manner that we may not anticipate or that is inconsistent from one jurisdiction to another and may conflict with other rules or practices including ours. Further, any significant change to applicable laws, regulations, or industry practices regarding the collection, use, retention, security, or disclosure of data, or their interpretation, or any changes regarding the manner in which the consent of relevant users for the collection, use, retention, or disclosure of such data must be obtained, could increase our costs and require us to modify our services and candidate products, possibly in a material manner, which we may be unable to complete, and may limit our ability to store and process patients' data or develop new services and features.
CCPA
Covered Entities of our normal operations, we expect to collect, process and retain personal identifying information regarding patients, including as a business associate of Covered Entities, so we expect to be subject to HIPAA, including changes implemented through HITECH, and we could be subject to criminal penalties if we knowingly obtain or disclose individually identifiable health information in a manner that is not authorized or permitted by HIPAA. A data breach affecting sensitive personal information, including health information, also could result in significant legal and financial exposure and reputational damages that could potentially have an adverse effect on our business.
HIPAA requires Covered Entities (like many of our potential customers) and business associates, like us, to develop and maintain policies and procedures with respect to protected health information that is used or disclosed, including the adoption of administrative, physical and technical safeguards to protect such information. HITECH expands the notification requirement for breaches of patient-identifiable health information, restricts certain disclosures and sales of patient-identifiable health information and provides for civil monetary penalties for HIPAA violations. HITECH also increased the civil and criminal penalties that may be imposed against Covered Entities and business associates and gave state attorneys general new authority to file civil actions for damages or injunctions in federal courts to enforce HIPAA and its implementing regulations and seek attorney's fees and costs associated with pursuing federal civil actions. Additionally, certain states have adopted comparable privacy and security laws and regulations, some of which may be more stringent than HIPAA.
GDPR
Virtually every jurisdiction in which we expect to operate has established its own data security and privacy legal framework with which we must, and our target customers will need to, comply, including the rules and regulation mentioned above. We may also need to comply with varying and possibly conflicting privacy laws and regulations in other jurisdictions. As a result, we could face regulatory actions, including significant fines or penalties, adverse publicity and possible loss of business.
While we are preparing to implement various measures intended to enable us to comply with applicable privacy or data protection laws, regulations and contractual obligations, these measures may not always be effective and do not guarantee compliance. Any failure or perceived failure by us to comply with our contractual or legal obligations or regulatory requirements relating to privacy, data protection, or information security may result in governmental investigations or enforcement actions, litigation, claims, or public statements against us by consumer advocacy groups or others and could result in significant liability, cause our customers, partners or patients to lose trust in us, and otherwise materially and adversely affect our reputation and business. Furthermore, the costs of compliance with, and other burdens imposed by, the laws, regulations, and policies that are applicable to the businesses of our customers or partners may limit the adoption and use of, and reduce the overall demand for, our products and services. Additionally, if third parties we work with violate applicable laws, regulations, or agreements, such violations may put the data we have received at risk, could result in governmental investigations or enforcement actions, fines, litigation, claims, or public statements against us by consumer advocacy groups or others and could result in significant liability, cause our customers, partners or patients to lose trust in us, and otherwise materially and adversely affect our reputation and business. Further, public scrutiny of, or complaints about, technology companies or their data handling or data protection practices, even if unrelated to our business, industry or operations, may lead to increased scrutiny of technology companies, including us, and may cause government agencies to enact additional regulatory requirements, or to modify their enforcement or investigation activities, which may increase our costs and risks.