The Health Insurance Portability and Accountability Act of 1996, as amended, and the regulations that have been issued under it, or collectively HIPAA, and similar laws outside the United States, contain substantial restrictions and requirements with respect to the use and disclosure of individuals' protected health information. The HIPAA privacy rules prohibit "covered entities," such as healthcare providers and health plans, from using or disclosing an individual's protected health information, unless the use or disclosure is authorized by the individual or is specifically required or permitted under the privacy rules. Under the HIPAA security rules, covered entities must establish administrative, physical and technical safeguards to protect the confidentiality, integrity and availability of electronic protected health information maintained or transmitted by them or by others on their behalf. While we do not believe that we will be a covered entity under HIPAA, we believe many of our customers will be covered entities subject to HIPAA. Such customers may require us to enter into business associate agreements, which will obligate us to safeguard certain health information we obtain in the course of our relationship with them, restrict the manner in which we use and disclose such information and impose liability on us for failure to meet our contractual obligations.
In addition, under The Health Information Technology for Economic and Clinical Health Act of 2009, or HITECH, which was signed into law as part of the U.S. stimulus package in February 2009, certain of HIPAA's privacy and security requirements are now also directly applicable to "business associates" of covered entities and subject them to direct governmental enforcement for failure to comply with these requirements. We may be deemed as a "business associate" of some of our customers. As a result, we may be subject as a "business associate" to civil and criminal penalties for failure to comply with applicable privacy and security rule requirements. Moreover, HITECH created a new requirement obligating "business associates" to report any breach of unsecured, individually identifiable health information to their covered entity customers and imposes penalties for failing to do so.
In addition to HIPAA, most U.S. states have enacted patient confidentiality laws that protect against the disclosure of confidential medical information, and many U.S. states have adopted or are considering adopting further legislation in this area, including privacy safeguards, security standards, and data security breach notification requirements. These U.S. state laws, which may be even more stringent than the HIPAA requirements, are not preempted by the federal requirements, and we are therefore required to comply with them to the extent they are applicable to our operations.
These and other possible changes to HIPAA or other U.S. federal or state laws or regulations, or comparable laws and regulations in countries where we conduct business, could affect our business and the costs of compliance could be significant. Failure by us to comply with any of the standards regarding patient privacy, identity theft prevention and detection, and data security may subject us to penalties, including civil monetary penalties and in some circumstances, criminal penalties. In addition, such failure may damage our reputation and adversely affect our ability to retain customers and attract new customers.
The protection of personal data, particularly patient data, is subject to strict laws and regulations in many countries. The collection and use of personal health data in the European Union (the "EU") is governed by the provisions of Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data, commonly known as the Data Protection Directive. The Data Protection Directive imposes a number of requirements including an obligation to seek the consent of individuals to whom the personal data relates, the information that must be provided to the individuals, notification of data processing obligations to the competent national data protection authorities of individual EU Member States and the security and confidentiality of the personal data. The Data Protection Directive also imposes strict rules on the transfer of personal data out of the EU to the U.S. Failure to comply with the requirements of the Data Protection Directive and the related national data protection laws of the EU Member States may result in fines and other administrative penalties and harm our business. We may incur extensive costs in ensuring compliance with these laws and regulations, particularly if we are considered to be a data controller within the meaning of the Data Protection Directive.
We will be highly dependent on information technology networks and systems, including the Internet, to securely process, transmit and store this critical information. Security breaches of this infrastructure, including physical or electronic break-ins, computer viruses, attacks by hackers and similar breaches, can create system disruptions, shutdowns or unauthorized disclosure or modification of confidential information. The secure processing, storage, maintenance and transmission of this critical information will be vital to our operations and business strategy, and we plan to devote significant resources to protecting such information. Although we will take measures to protect sensitive information from unauthorized access or disclosure, our information technology and infrastructure, and that of our third-party providers, may be vulnerable to attacks by hackers or viruses or breached due to employee error, malfeasance or other disruptions.
Any breach or interruption could compromise our networks or those of our third-party providers, and the information stored there could be inaccessible or could be accessed by unauthorized parties, publicly disclosed, lost or stolen. Any such interruption in access, improper access, disclosure or other loss of information could result in legal claims or proceedings, liability under laws that protect the privacy of personal information, such as HIPAA, and regulatory penalties. Unauthorized access, loss or dissemination could also disrupt our operations, including our ability to perform tests, provide test results, bill payers or patients, process claims and appeals, provide customer assistance services, conduct research and development activities, collect, process and prepare company financial information, provide information about our current and future products and other patient and clinician education and outreach efforts through our website, and manage the administrative aspects of our business and damage our reputation, any of which could adversely affect our business. Any such breach could also result in the compromise of our trade secrets and other proprietary information, which could adversely affect our competitive position.
In addition, the interpretation and application of consumer, health-related, privacy and data protection laws in the U.S., the EU and elsewhere are often uncertain, contradictory and in flux. It is possible that these laws may be interpreted and applied in a manner that is inconsistent with our practices. If so, this could result in government-imposed fines or orders requiring that we change our practices, which could adversely affect our business. Complying with these various laws could cause us to incur substantial costs or require us to change our business practices and compliance procedures in a manner adverse to our business.