The privacy and security of personal information stored, maintained, received or transmitted electronically is an enforcement priority in the United States and internationally. While we strive to comply with all applicable privacy and security laws and regulations, as well as our own posted privacy policies and legal standards for privacy, any failure or perceived failure to comply with such requirements may result in proceedings or actions against us by government entities or private parties, or could cause us to lose clients or members, any of which could have a material adverse effect on our business. Recently, there has been an increase in public awareness of privacy issues in the wake of revelations about the activities of various government agencies and in the number of private privacy-related lawsuits filed against companies. Any allegations about our practices with regard to the collection, use, disclosure, or security of personal information or other privacy-related matters, even if unfounded and even if we are in compliance with applicable laws, could damage our reputation and harm our business.
In the United States, numerous federal and state laws and regulations govern collection, storage, dissemination, use, retention, transfer, disposal, security and confidentiality of personal information, including HIPAA; U.S. state privacy, security and breach notification and healthcare information laws; the California Consumer Protection Act ("CCPA"); and other data protection laws.
HIPAA requires us to maintain policies and procedures governing PHI that are used or disclosed, and to implement administrative, physical and technical safeguards to protect PHI, including PHI maintained, used and disclosed in electronic form. Ongoing implementation and oversight of these measures involves significant time, effort and expense.
HIPAA also requires that patients be notified of any unauthorized acquisition, access, use or disclosure of their unsecured PHI that compromises the privacy or security of such information, with certain exceptions related to unintentional or inadvertent use or disclosure by employees or authorized individuals. Further, if a breach affects 500 patients or more, it must be reported to the U.S. Department of Health and Human Services Office ("HHS") without unreasonable delay, and HHS will post the name of the breaching entity on its public web site. Breaches affecting 500 patients or more in the same state or jurisdiction must also be reported to the local media. If a breach involves fewer than 500 people, the covered entity must record it in a log and notify HHS at least annually.
Entities that are found to be in violation of HIPAA as the result of a breach of unsecured PHI or following a complaint about privacy practices or an audit by HHS, may be subject to significant civil, criminal and administrative fines and penalties and/or additional reporting and oversight obligations if required to enter into a resolution agreement and corrective action plan with HHS to settle allegations of HIPAA non-compliance. HIPAA also authorizes state attorneys general to file suit on behalf of their residents and HIPAA's standards have been used as the basis for duty of care in state civil suits such as those for negligence or recklessness in the misuse or breach of PHI. Any such penalties or lawsuits could harm our business, financial condition, results of operations and prospects.
In addition to HIPAA, the U.S. federal government and various states and governmental agencies have adopted or are considering adopting various laws, regulations and standards regarding the collection, use, retention, security, disclosure, transfer and other processing of sensitive and personal information, to which we are or may become subject. For example, California implemented the California Consumer Privacy Act, or CCPA, which came into effect in 2020, and the California Privacy Rights Act ("CPRA"), which came into effect on January 1, 2023, which we are subject. The CCPA imposes obligations and restrictions on businesses regarding their collection, use, processing, retaining and sharing of personal information and provides new and enhanced data privacy rights to California residents. Protected health information that is subject to HIPAA is excluded from the CCPA; however, information we hold about individual residents of California that is not subject to HIPAA would be subject to the CCPA. The CPRA significantly amends and expands the CCPA, including by providing consumers with additional rights with respect to their personal information. The CPRA also creates a new state agency that will be vested with authority to implement and enforce the CCPA and the CPRA. We expect states to continue to enact legislation similar to the CCPA and CPRA that provides consumers with new privacy rights and increases the privacy and security obligations of entities handling certain personal information of such consumers. Laws similar to the CCPA and CPRA have passed in Virginia and Colorado, and have been proposed in other states and at the federal level, reflecting a trend toward more stringent privacy legislation in the United States.
Moreover, we are subject to certain other state laws such as the California Confidentiality of Medical Information Act, which imposes restrictive requirements regulating the use and disclosure of health information and other personal information. Such laws and regulations are not necessarily preempted by HIPAA, particularly if a state affords greater protection to individuals than HIPAA. Where state laws are more protective, we have to comply with the stricter provisions. Further, in addition to fines and penalties imposed upon violators, some of these state laws, such as the CCPA, also afford private rights of action to individuals who believe their personal information has been misused.
In the aggregate, state-based data privacy and security laws and regulations may impact our business. All of these evolving compliance and operational requirements impose significant costs that are likely to increase over time, may require us to modify our data processing practices and policies, divert resources from other initiatives and projects could restrict the way services involving data are offered and could subject us to additional liabilities, all of which may adversely affect our results of operations, business, and financial condition.
Furthermore, there are numerous foreign laws, regulations and directives regarding privacy and the collection, storage, transmission, use, processing, disclosure and protection of personal information, the scope of which is continually evolving and subject to differing interpretations. If we provide services to users outside the United States, we may be subject to such laws, regulations, directives and obligations in relation to processing of personal information, and we may be subject to significant consequences, including penalties, fines and contractual liability, for our failure to comply. We are subject to the EU GDPR and the UK data privacy regime consisting primarily of the UK General Data Protection Regulation and the UK Data Protection Act 2018 (the "UK GDPR") (the EU GDPR and the UK GDPR, collectively the "GDPR"), which impose a strict data protection compliance regime including stringent data protection requirements. EU Member States and the UK are also able to legislate separately on sensitive data (i.e., mental health), and we must comply with these local laws where we offer our services.
The GDPR also imposes strict rules on the transfer of personal data out of the EEA and the UK, including to the United States. The European Commission has published revised standard contractual clauses for data transfers from the EEA: the revised clauses must be used for relevant new data transfers from September 27, 2021; existing standard contractual clauses arrangements must be migrated to the revised clauses by December 27, 2022. We will be required to implement the revised standard contractual clauses within the relevant time frames. The revised standard contractual clauses apply only to the transfer of personal data outside of the EEA and not the UK; the UK's Information Commissioner's Office launched a public consultation on its draft revised data transfers mechanisms in August 2021. We continue to monitor updates and we may be required to implement new or revised documentation and processes in relation to our data transfers subject to the UK GDPR, within the relevant time frames. As supervisory authorities issue further guidance on data export mechanisms, including circumstances where the standard contractual clauses cannot be used, and/or start taking enforcement action, we could suffer additional costs, complaints and/or regulatory investigations or fines, and/or if we are otherwise unable to transfer personal information between and among countries and regions in which we operate, it could affect the manner in which we provide our services, the geographical location or segregation of our relevant systems and operations, and could adversely affect our financial results.
The relationship between the UK and the EU in relation to certain aspects of data protection law, particularly transfers of personal data, remains unclear following the UK's departure from the EU on January 1, 2021, and it is unclear how UK data protection laws and regulations will develop in the medium to longer term, and how data transfers to and from the UK will be regulated in the long term. These changes will lead to additional costs and increase our overall risk exposure.
Failure to comply with the requirements of the GDPR may result in fines of up to €20,000,000/ £17.5 million or up to 4% of our total worldwide annual revenue for the preceding financial year, whichever is higher. In addition, a breach of the GDPR could result in regulatory investigations, reputational damage, orders to cease/ change our processing of our data, enforcement notices, and/ or assessment notices (for a compulsory audit). We may also face civil claims including representative actions and other class action type litigation (where individuals have suffered harm), potentially amounting to significant compensation or damages liabilities, as well as associated costs, diversion of internal resources, and reputational harm.
We also publish statements to our clients and members that describe how we handle and protect personal information. If federal or state regulatory authorities or private litigants consider any portion of these statements to be inaccurate, incomplete, or not fully implemented, we may be subject to claims of deceptive practices or other violation of law, which could lead to significant liabilities and consequences, including, without limitation, costs of responding to investigations, defending against litigation, settling claims and complying with regulatory or court orders.
Because of the breadth of these laws and the narrowness of their exceptions and safe harbors, it is possible that our business activities can be subject to challenge under one or more of such laws. The applicability, scope and enforcement of each of these laws is uncertain and subject to rapid change in the current environment of healthcare reform. Federal, state and foreign enforcement bodies have recently increased their scrutiny of interactions between healthcare companies and healthcare providers and of processing of health data generally, which has led to a number of investigations, prosecutions, convictions and settlements in the healthcare industry. Any such investigations, prosecutions, convictions or settlements could result in significant financial penalties, damage to our brand and reputation, and a loss of clients and/or members, any of which could have an adverse effect on our business.
In addition, any significant change to applicable laws, regulations or industry practices regarding the collection, use, retention, security or disclosure of our users' personal information content, or regarding the manner in which the express or implied consent of users for the collection, use, retention or disclosure of such content is obtained, could increase our costs and require us to modify our services and features, possibly in a material manner, which we may be unable to complete and may limit our ability to store and process users' personal information data or develop new services and features. Any of the foregoing could harm our competitive position, business, financial condition, results of operations and prospects.