Healthcare providers, physicians and third-party payors will play a primary role in the recommendation and prescription of any therapeutic candidates for which we obtain regulatory approval. Our current and future arrangements with third-party payors and customers may expose us to broadly applicable fraud and abuse and other healthcare laws and regulations that may constrain the business or financial arrangements and relationships through which we conduct research and would market, sell and distribute our therapeutics. As a pharmaceutical company, even though we do not and will not control referrals of healthcare services or bill directly to Medicare, Medicaid or other third-party payors, federal and state healthcare laws and regulations pertaining to fraud and abuse and patients' rights are and will be applicable to our business. Restrictions under applicable federal and state healthcare laws and regulations that may affect our ability to operate include the following:
- the federal Anti-Kickback Statute, which prohibits, among other things, persons or entities from knowingly and willfully soliciting, receiving, offering or paying any remuneration (including any kickback, bribe or rebate), directly or indirectly, overtly or covertly, in cash or in kind, to induce, or in return for, the purchase, lease, order, arrangement, or recommendation of any good, facility, item or service for which payment may be made, in whole or in part, under a federal healthcare program, such as the Medicare and Medicaid programs. A person or entity does not need to have actual knowledge of the federal Anti-Kickback Statute or specific intent to violate it to have committed a violation. Violations are subject to civil and criminal fines and penalties for each violation, plus up to three times the remuneration involved, imprisonment, and exclusion from government healthcare programs. In addition, the government may assert that a claim including items or services resulting from a violation of the federal Anti-Kickback Statute constitutes a false or fraudulent claim for purposes of the federal False Claims Act or federal civil money penalties;- the federal civil and criminal false claims laws and civil monetary penalty laws, such as the federal False Claims Act, which impose criminal and civil penalties and authorize civil whistleblower or qui tam actions, against individuals or entities for, among other things: knowingly presenting, or causing to be presented, to the federal government, claims for payment that are false or fraudulent; knowingly making, using or causing to be made or used, a false statement of record material to a false or fraudulent claim or obligation to pay or transmit money or property to the federal government or knowingly concealing or knowingly and improperly avoiding or decreasing an obligation to pay money to the federal government. Manufacturers can be held liable under the federal False Claims Act even when they do not submit claims directly to government payors if they are deemed to "cause" the submission of false or fraudulent claims. The federal False Claims Act also permits a private individual acting as a "whistleblower" to bring actions on behalf of the federal government alleging violations of the federal False Claims Act and to share in any monetary recovery;- the federal Health Insurance Portability and Accountability Act of 1996 ("HIPAA"), which created new federal criminal statutes that prohibit a person from knowingly and willfully executing, or attempting to execute, a scheme to defraud any healthcare benefit program or obtain, by means of false or fraudulent pretenses, representations or promises, any of the money or property owned by, or under the custody or control of, any healthcare benefit program, regardless of the payor (e.g., public or private) and knowingly and willfully falsifying, concealing or covering up by any trick or device a material fact or making any materially false, fictitious, or fraudulent statements or representations in connection with the delivery of, or payment for, healthcare benefits,items or services relating to healthcare matters; similar to the federal Anti-Kickback Statute, a person or entity does not need to have actual knowledge of the statute or specific intent to violate it in order to have committed a violation;- HIPAA, as amended by the Health Information Technology for Economic and Clinical Health Act of 2009 ("HITECH") and their respective implementing regulations, including the Final Omnibus Rule published in January 2013, which impose requirements on certain covered healthcare providers, health plans, and healthcare clearinghouses as well as their respective business associates, independent contractors or agents of covered entities, that perform services for them that involve the creation, maintenance, receipt, use, or disclosure of, individually identifiable health information relating to the privacy, security and transmission of individually identifiable health information. HITECH also created new tiers of civil monetary penalties, amended HIPAA to make civil and criminal penalties directly applicable to business associates, and gave state attorneys general new authority to file civil actions for damages or injunctions in federal courts to enforce the federal HIPAA laws and seek attorneys' fees and costs associated with pursuing federal civil actions. In addition, there may be additional federal, state and non-U.S. laws which govern the privacy and security of health and other personal information in certain circumstances, many of which differ from each other in significant ways and may not have the same effect, thus complicating compliance efforts;- the U.S. federal transparency requirements under the ACA, including the provision commonly referred to as the Physician Payments Sunshine Act, and its implementing regulations, which requires applicable manufacturers of drugs, devices, biologics and medical supplies for which payment is available under Medicare, Medicaid or the Children's Health Insurance Program to report annually to CMS, information related to payments or other transfers of value made to physicians (defined to include doctors, dentists, optometrists, podiatrists and chiropractors), certain other licensed health care practitioners (defined to include physician assistants, nurse practitioners, clinical nurse specialists, certified registered nurse anesthetists and anesthesiologist assistants, and certified-nurse midwives) and teaching hospitals, as well as ownership and investment interests held by the physicians described above and their immediate family members;- federal government price reporting laws, which require us to calculate and report complex pricing metrics in an accurate and timely manner to government programs; and - federal consumer protection and unfair competition laws, which broadly regulate marketplace activities and activities that potentially harm consumers.
Additionally, we are subject to state and foreign equivalents of each of the healthcare laws and regulations described above, among others, some of which may be broader in scope and may apply regardless of the payor. Many U.S. states have adopted laws similar to the federal Anti-Kickback Statute and False Claims Act, and may apply to our business practices, including, but not limited to, research, distribution, sales or marketing arrangements and claims involving healthcare items or services reimbursed by non-governmental payors, including private insurers. In addition, some states have passed laws that require pharmaceutical companies to comply with the April 2003 Office of Inspector General Compliance Program Guidance for Pharmaceutical Manufacturers and/or the Pharmaceutical Research and Manufacturers of America's Code on Interactions with Healthcare Professionals. Several states also impose other marketing restrictions or require pharmaceutical companies to make marketing or price disclosures to the state and require the registration of pharmaceutical sales representatives. State and foreign laws, including for example the EU General Data Protection Regulation (which became effective on May 25, 2018) ("EU GDPR") and the UK General Data Protection Regulation (which became effective following UK withdrawal from the EU as of January 2021) ("UK GDPR)" also govern the privacy and security of health information in some circumstances, many of which differ from each other in significant ways and often are not preempted by HIPAA, thus complicating compliance efforts. There are ambiguities as to what is required to comply with these state requirements and if we fail to comply with an applicable state law requirement we could be subject to penalties. Finally, there are state and foreign laws governing the privacy and security of health information, many of which differ from each other in significant ways and often are not preempted by HIPAA, thus complicating compliance efforts.
Federal and state enforcement bodies have recently increased their scrutiny of interactions between healthcare companies and healthcare providers, which has led to a number of investigations, prosecutions, convictions and settlements in the healthcare industry. Ensuring business arrangements comply with applicable healthcare laws, as well as responding to possible investigations by government authorities, can be time and resource consuming and can divert a company's attention from the business.
Ensuring that our internal operations and future business arrangements with third parties comply with applicable healthcare laws and regulations will involve substantial costs. It is possible that governmental authorities will conclude that our business practices do not comply with current or future statutes, regulations, agency guidance or case law involving applicable fraud and abuse or other healthcare laws and regulations. If our operations are found to be in violation of any of the laws described above or any other governmental laws and regulations that may apply to us, we may be subject to significant penalties, including administrative, civil and criminal penalties, damages, fines, disgorgement, the exclusion from participation in federal and state healthcare programs, individual imprisonment, reputational harm, and the curtailment or restructuring of our operations, as well as additional reporting obligations and oversight if we become subject to a corporate integrity agreement or other agreement to resolve allegations of non-compliance with these laws. Further, defending against any such actions can be costly and time-consuming, and may require significant financial and personnel resources. Therefore, even if we are successful in defending against any such actions that may be brought against us, our business may be impaired. If any of the physicians or other providers or entities with whom we expect to do business is found to not be in compliance with applicable laws, they may be subject to criminal, civil or administrative sanctions, including exclusions from government funded healthcare programs and imprisonment. If any of the above occur, our ability to operate our business and our results of operations could be adversely affected. For more information, see the section "Business-Healthcare Law and Regulation" in this Annual Report.