General Risk Factors
Changes in tax laws and regulations may have a material adverse effect on our business, financial condition and results of operations.
New income, sales, use or other tax laws, statutes, rules, regulations or ordinances could be enacted at any time, which could affect the tax treatment of any of our future domestic and foreign earnings. Any new taxes could adversely affect our domestic and international business operations, and our business and financial performance. Further, existing tax laws, statutes, rules, regulations or ordinances could be interpreted, changed, modified or applied adversely to us. Generally, future changes in applicable U.S. and non-U.S. tax laws and regulations, or their interpretation and application, could have an adverse effect on our business, financial conditions and results of operations. We are unable to predict whether such changes will occur and, if so, the ultimate impact on our business.
We are subject to U.S. and certain foreign export and import controls, sanctions, embargoes, anti-corruption laws, and anti-money laundering laws and regulations. Compliance with these legal standards could impair our ability to compete in domestic and international markets. We can face criminal liability and other serious consequences for violations, which can harm our business.
We are subject to export control and import laws and regulations, including the U.S. Export Administration Regulations, U.S. Customs regulations, various economic and trade sanctions regulations administered by the U.S. Treasury Department’s Office of Foreign Assets Controls, the U.S. Foreign Corrupt Practices Act of 1977, as amended, the U.S. domestic bribery statute contained in 18 U.S.C. § 201, the U.S. Travel Act, the USA PATRIOT Act, and other state and national anti-bribery and anti-money laundering laws in the countries in which we conduct activities. Anti-corruption laws are interpreted broadly and prohibit companies and their employees, agents, contractors and other collaborators from authorizing, promising, offering or providing, directly or indirectly, improper payments or anything else of value to recipients in the public or private sector. We may engage third parties to sell our products outside the United States, to conduct clinical trials and/or to obtain necessary permits, licenses, patent registrations and other regulatory approvals. We have direct or indirect interactions with officials and employees of government agencies or government-affiliated hospitals, universities and other organizations. We can be held liable for the corrupt or other illegal activities of our employees, agents, contractors and other collaborators, even if we do not explicitly authorize or have actual knowledge of such activities. Any violations of the laws and regulations described above may result in substantial civil and criminal fines and penalties, imprisonment, the loss of export or import privileges, debarment, tax reassessments, breach of contract and fraud litigation, reputational harm and other consequences.
Cybersecurity risks and the failure to maintain the security, confidentiality, integrity, or availability of our information technology systems or data, and those maintained on our behalf, could lead to adverse consequences that materially adversely affect our business, including, without limitation, regulatory investigations or actions, a material interruption to our operations, including clinical trials, damage to our reputation and/or subject us to costs, fines and penalties or lawsuits.
We collect and maintain information in digital and other forms that is necessary to conduct our business, and we are increasingly dependent on information technology systems and infrastructure to operate our business. In the ordinary course of our business, we and the third parties with whom we work process sensitive data. We have established certain physical, electronic and organizational measures designed to safeguard and secure our systems in an effort to prevent a data or other compromise; there can, however, be no assurance that these measures will be or have been effective. We have also outsourced elements of our information technology infrastructure, and as a result a number of third-party vendors have access to our sensitive data. Our information technology systems and infrastructure, and those of any future collaborators and our contractors, consultants, vendors and other third parties with whom we work, are vulnerable to and have experienced attacks, damage and interruption from cyber-attacks, malicious internet-based activity, online and offline fraud, malicious code (such as computer viruses, and worms), malware, ransomware attacks, credential stuffing, credential harvesting, supply-chain attacks, natural disasters, fire, terrorism, war, telecommunication and electrical failures, attacks enhanced or facilitated by AI, denial or degradation of service attacks, hacking, sophisticated nation-state and nation-state supported actors, phishing and other social engineering attacks (including through deep fakes, which are increasingly more difficult to identify), attachments to emails, fraud, personnel misconduct or error, server malfunctions, software or hardware failures, loss or theft of data or information technology assets, unauthorized access or use, and other similar threats. In particular, ransomware attacks are becoming increasingly prevalent and can lead to significant interruptions in our operations, loss of sensitive data, reputational harm, and diversion of funds. Extortion payments may alleviate the negative impact of a ransomware attack, but we may be unwilling or unable to make such payments due to, for example, applicable laws or regulations prohibiting such payments.
The risk of a security breach or disruption, particularly through cyber-attacks, including by traditional computer “hackers”, threat actors, “hacktivists”, organized criminal threat actors, sophisticated nation states, and nation-state supported actors, and cyber terrorists, has generally increased as the number, intensity and sophistication of attempted attacks and intrusions from around the world have increased. The prevalent use of mobile devices that access sensitive data also increases the risk of lost or stolen devices, security incidents and data security breaches, which could lead to the loss or other compromise of sensitive data. In a hybrid working environment, we also face risks of a security breach or disruption due to our reliance on information systems that we do not necessarily control and the