In the normal course of our business, we collect, process, use and disclose information about individuals, including protected health information and other patient data, as well as information relating to health professionals and our employees. The collection, processing, use, disclosure, disposal and protection of such information is highly regulated both in the U. S. and other jurisdictions, including but not limited to, under HIPAA, as amended by HITECH; United States state privacy, security and breach notification and healthcare information laws; the European Union's GDPR, UK GDPR, and other European and UK privacy laws, as well as the expanding number of privacy laws around the world, including China and Canada. These laws are complex and their interpretation is rapidly evolving, making implementation and enforcement, and thus compliance requirements, uncertain and potentially inconsistent. In addition, our collection, use, disclosure, protection and other processing of information is subject to related contractual requirements. Compliance with such laws and related contractual requirements may require changes to our information processing practices, and may thereby increase compliance costs. Failure to comply with such laws and/or related contractual obligations could result in regulatory enforcement or claims against us for breach of contract, or may lead third parties to terminate their contracts with us and/or choose not to work with us in the future. Should this occur, there could be a material adverse effect on our reputation, business, financial condition, and results of operations.
These regulations often govern the handling of information about individuals, including personal health information and require the use of standard contracts, privacy and security standards and other administrative simplification provisions. In relation to HIPAA, we do not consider our service offerings to generally cause us to be subject as a covered entity; however, in certain circumstances, we are subject to HIPAA as a business associate and may enter into business associate agreements.
Additionally, the FTC and many state attorneys general are interpreting existing federal and state consumer protection laws to impose evolving standards for the online collection, use, dissemination and security of information about individuals, including health-related information. Courts may also adopt the standards for fair information practices promulgated by the FTC, which concern consumer notice, choice, security and access. Consumer protection laws require us to publish statements that describe how we handle information about individuals and choices individuals may have about the way we handle their information. If such information that we publish is considered untrue, we may be subject to government claims of unfair or deceptive trade practices, which could lead to significant liabilities and consequences. Furthermore, according to the FTC, violating consumers' privacy rights or failing to take appropriate steps to keep information about consumers secure may constitute unfair acts or practices in or affecting commerce in violation of Section 5(a) of the FTC Act.
In addition, certain states have adopted robust privacy and security laws and regulations. Such laws and regulations will be subject to interpretation by various courts and other governmental authorities, thus creating potentially complex compliance issues for us and our future customers and strategic partners. For example, the CCPA, imposes obligations and restrictions on businesses regarding their collection, use, and sharing of personal information and provides new and enhanced data privacy rights to California residents, such as affording them the right to access and delete their personal information and to opt out of certain sharing of personal information. Protected health information that is subject to HIPAA is excluded from the CCPA, however, information we hold about individuals that is not subject to HIPAA would be subject to the CCPA. It is unclear how HIPAA and the other exceptions may be applied under the CCPA. The CCPA may increase our compliance costs and potential liability. Many similar privacy laws have been proposed at the federal level and in other states.
The GDPR and the UK GDPR regulate our processing of personal data, and imposes stringent requirements. Failure to comply with the GDPR or UK GDPR may result in fines up to the greater of €20 million or 4.0% of worldwide gross annual revenue and applies to services providers such as us under each of GDPR and UK GDPR.
There is uncertainty regarding transfers of personal data from the EEA to the United States, including regarding the status and enforceability of the EU-US Privacy Shield Framework ("Privacy Shield") under which personal data could be transferred from the EEA to U.S. entities who had self-certified under the Privacy Shield scheme. While the Court of Justice of the European Union (CJEU) upheld the adequacy of the standard contractual clauses (a standard form of contract approved by the European Commission as an adequate personal data transfer mechanism, and potential alternative to the Privacy Shield), it made clear that reliance on them alone may not necessarily be sufficient in all circumstances; and the validity of the standard contractual clauses as a transfer mechanism remains uncertain. We have previously relied on our own Privacy Shield certification and our relevant customers' and third parties' Privacy Shield certification(s) for the purposes of transferring personal data from the EEA to the United States in compliance with the GDPR's data export conditions. We also currently rely on the standard contractual clauses to transfer personal data outside the EEA, including to the United States. If all or some jurisdictions within the European Union or the United Kingdom determine that the standard contractual clauses do not provide sufficient safeguards to transfer personal data to the United States, our ability to effect cross-border transfers of personal data will be severely limited or cause us to need to establish systems to maintain certain data in the EEA or UK, and thereby divert resources from other aspects of our operations, all of which may adversely affect our business or we may face governmental enforcement actions, litigation, fines and penalties or adverse publicity, which could have an adverse effect on our reputation and business.
We believe we maintain adequate processes and systems in compliance with the requirements of the GDPR and UK GDPR, but it is possible that we could fail to comply or that we could incur liability due to the acts or omissions of our vendors. In the event we are not able to secure indemnification or the indemnification and any insurance coverage is inadequate to cover our losses, we could suffer significant financial, operational, reputational and other harm and our business, results of operations, financial condition and/or cash flows could be materially adversely affected. Furthermore, as supervisory authorities issue further guidance on personal data export mechanisms, including circumstances where the standard contractual clauses cannot be used, and/or start taking enforcement action, we could suffer additional costs, complaints and/or regulatory investigations or fines, and/or if we are otherwise unable to transfer personal data between and among countries and regions in which we operate, it could affect the manner in which we provide our services, the geographical location or segregation of our relevant systems and operations, and could adversely affect our financial results.
Privacy and data security laws are rapidly evolving both in the United States and internationally, and the future interpretation of those laws is somewhat uncertain. Additional legislation or regulation might, among other things, require us to implement new security measures and processes or bring within the legislation or regulation de-identified health or other information about individuals, each of which may require substantial expenditures or limit our ability to offer some of our services.