We expect to receive health information and other highly sensitive or confidential information and data of patients and other third parties (e.g., healthcare providers who refer patients for scans), which we expect to compile and analyze. Collection and use of this data might raise privacy and data protection concerns, which could negatively impact our business. There are numerous federal, state and international laws and regulations regarding privacy, data protection, information security, and the collection, storing, sharing, use, processing, transfer, disclosure, and protection of personal information and other data, and the scope of such laws and regulations may change, be subject to differing interpretations, and may be inconsistent among countries and regions we intend to operate in (e.g., the U.S., the EU and Israel), or conflict with other laws and regulations. The regulatory framework for privacy and data protection worldwide is, and is likely to remain for the foreseeable future, uncertain and complex, and this or other actual or alleged obligations may be interpreted and applied in a manner that we may not anticipate or that is inconsistent from one jurisdiction to another and may conflict with other rules or practices including ours. Further, any significant change to applicable laws, regulations, or industry practices regarding the collection, use, retention, security, or disclosure of data, or their interpretation, or any changes regarding the manner in which the consent of relevant users for the collection, use, retention, or disclosure of such data must be obtained, could increase our costs and require us to modify our services and candidate products, possibly in a material manner, which we may be unable to complete, and may limit our ability to store and process patients' data or develop new services and features.
In particular, we will be subject to U.S. data protection laws and regulations (i.e., laws and regulations that address privacy and data security) at both the federal and state levels. The legislative and regulatory landscape for data protection continues to evolve, and in recent years there has been an increasing focus on privacy and data security issues. Numerous federal and state laws, including state data breach notification laws, state health information privacy laws, and federal and state consumer protection laws, govern the collection, use, and disclosure of health-related and other personal information. Failure to comply with such laws and regulations could result in government enforcement actions and create liability for us (including the imposition of significant civil or criminal penalties), private litigation and/or adverse publicity that could negatively affect our business. For instance, California enacted the California Consumer Privacy Act, or the CCPA, on June 28, 2018, which took effect on January 1, 2020. The CCPA creates individual privacy rights for California consumers and increases the privacy and security obligations of entities handling certain personal data. The CCPA provides for civil penalties for violations, as well as a private right of action for data breaches that is expected to increase data breach litigation. The CCPA may increase our compliance costs and potential liability, and many similar laws have been proposed at the federal level and in other states.
In addition, we expect to obtain health information that is subject to privacy and security requirements under the Health Information Technology for Economic and Clinical Health, or HITECH, and its implementing regulations. The Privacy Standards and Security Standards under the federal Health Insurance Portability and Accountability Act of 1996, or HIPAA, establish a set of standards for the protection of individually identifiable health information by health plans, health care clearinghouses and certain health care providers, referred to as Covered Entities, and the business associates with whom Covered Entities enter into service relationships pursuant to which individually identifiable health information may be exchanged. Notably, whereas HIPAA previously directly regulated only Covered Entities, HITECH makes certain of HIPAA's privacy and security standards also directly applicable to Covered Entities' business associates. As a result, both Covered Entities and business associates are now subject to significant civil and criminal penalties for failure to comply with Privacy Standards and Security Standards. As part of our normal operations, we expect to collect, process and retain personal identifying information regarding patients, including as a business associate of Covered Entities, so we expect to be subject to HIPAA, including changes implemented through HITECH, and we could be subject to criminal penalties if we knowingly obtain or disclose individually identifiable health information in a manner that is not authorized or permitted by HIPAA. A data breach affecting sensitive personal information, including health information, also could result in significant legal and financial exposure and reputational damages that could potentially have an adverse effect on our business.
HIPAA requires Covered Entities (like many of our potential customers) and business associates, like us, to develop and maintain policies and procedures with respect to protected health information that is used or disclosed, including the adoption of administrative, physical and technical safeguards to protect such information. HITECH expands the notification requirement for breaches of patient-identifiable health information, restricts certain disclosures and sales of patient-identifiable health information and provides for civil monetary penalties for HIPAA violations. HITECH also increased the civil and criminal penalties that may be imposed against Covered Entities and business associates and gave state attorneys general new authority to file civil actions for damages or injunctions in federal courts to enforce HIPAA and its implementing regulations and seek attorney's fees and costs associated with pursuing federal civil actions. Additionally, certain states have adopted comparable privacy and security laws and regulations, some of which may be more stringent than HIPAA.
Internationally, many jurisdictions have or are considering enacting privacy or data protection laws or regulations relating to the collection, use, storage, transfer, disclosure and/or other processing of personal data, as well as certification requirements for the hosting of health data specifically. Such laws and regulations may include data hosting, data residency or data localization requirements (which generally require that certain types of data collected within a certain country be stored and processed within that country), data export restrictions, international transfer laws (which prohibit or impose conditions upon the transfer of such data from one country to another), or may require companies to implement privacy or data protection and security policies, enable users to access, correct and delete personal data stored or maintained by such companies, inform individuals of security breaches that affect their personal data or obtain individuals' consent to use their personal data. For example, European legislators adopted the EU's GDPR which became effective on May 25, 2018, and are now in the process of finalizing the ePrivacy Regulation to replace the European ePrivacy Directive (Directive 2002/58/EC as amended by Directive 2009/136/EC). The GDPR, supplemented by national laws and further implemented through binding guidance from the European Data Protection Board, imposes more stringent EU data protection requirements and provides for significant penalties for noncompliance.
Virtually every jurisdiction in which we expect to operate has established its own data security and privacy legal framework with which we must, and our target customers will need to, comply, including the rules and regulation mentioned above. We may also need to comply with varying and possibly conflicting privacy laws and regulations in other jurisdictions. As a result, we could face regulatory actions, including significant fines or penalties, adverse publicity and possible loss of business.
While we are preparing to implement various measures intended to enable us to comply with applicable privacy or data protection laws, regulations and contractual obligations, these measures may not always be effective and do not guarantee compliance. Any failure or perceived failure by us to comply with our contractual or legal obligations or regulatory requirements relating to privacy, data protection, or information security may result in governmental investigations or enforcement actions, litigation, claims, or public statements against us by consumer advocacy groups or others and could result in significant liability, cause our customers, partners or patients to lose trust in us, and otherwise materially and adversely affect our reputation and business. Furthermore, the costs of compliance with, and other burdens imposed by, the laws, regulations, and policies that are applicable to the businesses of our customers or partners may limit the adoption and use of, and reduce the overall demand for, our products and services. Additionally, if third parties we work with violate applicable laws, regulations, or agreements, such violations may put the data we have received at risk, could result in governmental investigations or enforcement actions, fines, litigation, claims, or public statements against us by consumer advocacy groups or others and could result in significant liability, cause our customers, partners or patients to lose trust in us, and otherwise materially and adversely affect our reputation and business. Further, public scrutiny of, or complaints about, technology companies or their data handling or data protection practices, even if unrelated to our business, industry or operations, may lead to increased scrutiny of technology companies, including us, and may cause government agencies to enact additional regulatory requirements, or to modify their enforcement or investigation activities, which may increase our costs and risks.