We are exposed to the risk of employee fraud or other illegal activity by our employees, independent contractors, consultants, commercial partners and vendors. Misconduct by these parties could include intentional, reckless and/or negligent conduct that fails to: comply with the regulations of the FDA and other similar foreign regulatory authorities, provide true, complete and accurate information to the FDA and other similar foreign regulatory authorities, comply with manufacturing standards we have established, comply with healthcare fraud and abuse laws in the United States and similar foreign fraudulent misconduct laws or report financial information or data accurately or to disclose unauthorized activities to us. If we obtain FDA approval of any of our product candidates and begin commercializing those products in the United States, our potential exposure under such laws and regulations will increase significantly, and our costs associated with compliance with such laws and regulations are also likely to increase. These laws may impact, among other things, our current activities with principal investigators and research patients, as well as proposed and future sales, marketing and education programs. In particular, the promotion, sales and marketing of healthcare items and services, as well as certain business arrangements in the healthcare industry, are subject to extensive laws designed to prevent fraud, kickbacks, self-dealing and other abusive practices. These laws and regulations may restrict or prohibit a wide range of pricing, discounting, marketing and promotion, structuring and commission(s), certain customer incentive programs and other business arrangements generally. Activities subject to these laws also involve the improper use of information obtained in the course of patient recruitment for clinical trials. The laws that may affect our ability to operate include, but are not limited to:
- the federal Anti-Kickback Statute, which prohibits, among other things, knowingly and willfully soliciting, receiving, offering or paying any remuneration (including any kickback, bribe, or rebate), directly or indirectly, overtly or covertly, in cash or in kind, to induce, or in return for, either the referral of an individual, or the purchase, lease, order or recommendation of any good, facility, item or service for which payment may be made, in whole or in part, under a federal healthcare program, such as the Medicare and Medicaid programs. In addition, the government may assert that a claim including items or services resulting from a violation of the federal Anti-Kickback Statute constitutes a false or fraudulent claim for purposes of the federal civil False Claims Act or federal civil money penalties statute; - federal civil and criminal false claims laws and civil monetary penalty laws, which prohibit, among other things, individuals or entities from knowingly presenting, or causing to be presented, claims for payment or approval from Medicare, Medicaid, or other third-party payors that are false or fraudulent or knowingly making a false statement to improperly avoid, decrease or conceal an obligation to pay money to the federal government; - the federal Health Insurance Portability and Accountability Act of 1996 (HIPAA), which created new federal criminal statutes that prohibit knowingly and willfully executing, or attempting to execute, a scheme to defraud any healthcare benefit program or obtain, by means of false or fraudulent pretenses, representations, or promises, any of the money or property owned by, or under the custody or control of, any healthcare benefit program, regardless of the payor (for example, public or private) and knowingly and willfully falsifying, concealing or covering up by any trick or device a material fact or making any materially false statements in connection with the delivery of, or payment for, healthcare benefits, items or services relating to healthcare matters; - HIPAA, as amended by the Health Information Technology for Economic and Clinical Health Act of 2009 (HITECH), and their respective implementing regulations, which impose requirements on certain covered healthcare providers, health plans, and healthcare clearinghouses as well as their respective business associates that perform services for them that involve the use, or disclosure of, individually identifiable health information, relating to the privacy, security and transmission of individually identifiable health information without appropriate authorization; - the federal Physician Payments Sunshine Act, created under the Affordable Care Act and its implementing regulations, which require manufacturers of drugs, devices, biologicals and medical supplies for which payment is available under Medicare, Medicaid or the Children's Health Insurance Program (with certain exceptions) to report annually to HHS information related to payments or other transfers of value made to physicians (currently defined to include doctors, dentists, optometrists, podiatrists and chiropractors) and teaching hospitals, as well as ownership and investment interests held by physicians and their immediate family members. Effective January 1, 2022, these reporting obligations will extend to include transfers of value made during the previous year to certain non-physician providers such as physician assistants and nurse practitioners; and - federal consumer protection and unfair competition laws, which broadly regulate marketplace activities and activities that potentially harm consumers.
Additionally, we are subject to state and foreign equivalents of each of the healthcare laws described above, among others, some of which may be broader in scope and may apply regardless of the payor.
We have adopted a code of business conduct and ethics, but it is not always possible to identify and deter employee misconduct, and the precautions we take to detect and prevent inappropriate conduct may not be effective in controlling unknown or unmanaged risks or losses or in protecting us from governmental investigations or other actions or lawsuits stemming from a failure to be in compliance with such laws or regulations.
Efforts to ensure that our business arrangements with third parties will comply with applicable healthcare laws and regulations will involve substantial costs. Because of the breadth of these laws and the narrowness of the statutory exceptions and safe harbors available, it is possible that some of our business activities could be subject to challenge under one or more of such laws. It is possible that governmental authorities will conclude that our business practices may not comply with current or future statutes, regulations or case law involving applicable fraud and abuse or other healthcare laws and regulations. If our operations are found to be in violation of any of these laws or any other governmental regulations that may apply to us, we may be subject to significant criminal, civil and administrative sanctions including monetary penalties, damages, fines, disgorgement, individual imprisonment, and exclusion from participation in government funded healthcare programs, such as Medicare and Medicaid, additional reporting requirements and oversight if we become subject to a corporate integrity agreement or similar agreement to resolve allegations of non-compliance with these laws, reputational harm, and we may be required to curtail or restructure our operations, any of which could adversely affect our ability to operate our business and our results of operations.
The shifting compliance environment and the need to build and maintain robust and expandable systems to comply with multiple jurisdictions with different compliance and/or reporting requirements increases the possibility that a healthcare company may run afoul of one or more of the requirements. Any action against us for violation of these laws, even if we successfully defend against it, could cause us to incur significant legal expenses and divert our management's attention from the operation of our business.
The provision of benefits or advantages to physicians to induce or encourage the prescription, recommendation, endorsement, purchase, supply, order or use of medicinal products is also prohibited in the EU. The provision of benefits or advantages to physicians is governed by the national anti-bribery laws of EU Member States, such as the U.K. Bribery Act 2010, or the Bribery Act. Infringement of these laws could result in substantial fines and imprisonment. Payments made to physicians in certain EU Member States must be publicly disclosed. Moreover, agreements with physicians often must be the subject of prior notification and approval by the physician's employer, his or her competent professional organization and/or the regulatory authorities of the individual EU Member States. These requirements are provided in the national laws, industry codes or professional codes of conduct, applicable in the EU Member States. Failure to comply with these requirements could result in reputational risk, public reprimands, administrative penalties, fines or imprisonment.
The collection, use, disclosure, transfer, or other processing of personal data regarding individuals in the EU, including personal health data, is subject to the EU General Data Protection Regulation (GDPR), which became effective on May 25, 2018. The GDPR is wide-ranging in scope and imposes numerous requirements on companies that process personal data, including requirements relating to processing health and other sensitive data, obtaining consent of the individuals to whom the personal data relates, providing information to individuals regarding data processing activities, implementing safeguards to protect the security and confidentiality of personal data, providing notification of data breaches, and taking certain measures when engaging third-party processors. The GDPR also imposes strict rules on the transfer of personal data to countries outside the EU, including the United States, and permits data protection authorities to impose large penalties for violations of the GDPR, including potential fines of up to €20 million or 4% of annual global revenues, whichever is greater. The GDPR also confers a private right of action on data subjects and consumer associations to lodge complaints with supervisory authorities, seek judicial remedies, and obtain compensation for damages resulting from violations of the GDPR. Compliance with the GDPR will be a rigorous and time-intensive process that may increase our cost of doing business or require us to change our business practices, and despite those efforts, there is a risk that we may be subject to fines and penalties, litigation, and reputational harm in connection with our European activities.