XML 27 R12.htm IDEA: XBRL DOCUMENT v3.26.1
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2025
Cybersecurity Risk Management, Strategy, and Governance [Abstract]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block] We maintain a cybersecurity risk-management program that is scaled to our business, products, and data environment. Our products are physical medical devices without integrated software, and we do not collect or store patient health information in the ordinary course. However, we do rely on information systems that support our operations, and we maintain sensitive business information. 

Our cybersecurity processes include written policies and procedures that address threat identification, user practices, incident response, backup and recovery, and data handling. We periodically engage third parties to assess our environment. We periodically engage independent third-party cybersecurity experts to perform risk assessments and penetration testing. In the past, external providers conducted cybersecurity assessments and provided advisory services, including CISO-as-a-service support. In early 2026, we engaged another independent cybersecurity firm to perform an updated cybersecurity risk assessment, and management intends to prioritize remediation activities once the results are completed.

 

We also manage certain third-party risks through vendor selection and contract provisions and by limiting access to our systems and data to an extent reasonably practicable for business operations. We do not disclose further technical details of our controls to avoid increasing security risk.

 
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Board of Directors Oversight [Text Block] Our board of directors oversees enterprise-level risks generally as part of its overall risk-management responsibilities. Cybersecurity risk is managed at the executive level and incorporated into this broader framework. Management provides updates to our board of directors on cybersecurity matters as appropriate in the context of overall operational risk. 

Management’s Role and Expertise

 

Our Executive Vice President of Finance and Regional Manager has executive responsibility for cybersecurity risk management and coordinates the program with our internal information technology (“IT”) team and external advisors. Day-to-day cybersecurity activities are performed by our internal IT staff, including an IT professional with hands-on experience in systems administration and cybersecurity disciplines. Our Management experience has been developed through overseeing our cybersecurity processes and working with external providers. These responsibilities include, but are not limited to, maintaining and updating policies, coordinating periodic assessments and testing, managing user access practices and backup routines, and leading incident response activities if needed.

  

Third-Party Engagement

 

We use external cybersecurity firms for risk assessments, penetration testing, and advisory services. These engagements supplement our internal capabilities and help identify and prioritize risk mitigation. Contracts with key providers contain customary security and confidentiality provisions.

 

Incident Experience and Materiality

 

As of the date of this Annual Report on Form 10-K, we have not identified any cybersecurity incidents that have materially affected our business strategy, results of operations, or financial condition. We cannot guarantee that future incidents will not occur, and we may not promptly detect all incidents despite our efforts. For more information about these risks, please see “Item 1.A – Risk Factors – Risks Related to Our Business Operations – Our business and operations would suffer in the event of computer system failures, cyber-attacks or deficiencies in our cyber-security.” in this Annual Report on Form 10-K.

 

Insurance

 

We maintain cyber risk insurance. However, such insurance may not cover all losses or may be subject to exclusions or disputes.

 
Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] Management provides updates to our board of directors on cybersecurity matters as appropriate in the context of overall operational risk.
Cybersecurity Risk Management Positions or Committees Responsible [Text Block] board of directors oversees enterprise-level risks generally as part of its overall risk-management responsibilities.