|
Cybersecurity
|12 Months Ended
Dec. 31, 2024
|Cybersecurity Risk Management, Strategy, and Governance [Line Items]
|Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
|
Item 1C. Cybersecurity
As trusted partners to healthcare providers, patients, biopharmaceutical companies, academic and non-profit institutions, business partners and employees, we appreciate the importance of maintaining a comprehensive and trustworthy information security program. Our information security program is fully integrated into our operations, and a hallmark of our program is its cross-functional approach with our internal privacy objectives and stakeholders.
Our cybersecurity program is based on the ISO 27001 security controls set, and in particular, it focuses on the principles of confidentiality, integrity and availability. We maintain an ISO 27001 certification with a fully integrated set of operational policies and procedures to adhere to the domains of ISO 27001. This includes but is not limited to the organization of information security to assign roles and responsibilities within Adaptive, access control to restrict employees’ access to view only that information that is relevant to their roles, information security incident management, and compliance to broadly ensure alignment with applicable laws and regulations. We perform an annual risk assessment conducted by an outside assessor and conduct vendor risk assessments for third party vendors to evaluate how their systems may impact our business in the event of a cybersecurity incident. We also provide annual, mandatory cybersecurity training for employees to equip our workforce with the knowledge to identify and respond to cybersecurity threats, such as phishing attempts.
The internal body with executive oversight of our cybersecurity program is our Privacy and Information Security Steering Committee (“PISSC”), which applies a multidisciplinary framework to cybersecurity risks and risk assessment by integrating information security, privacy and human resources expertise, oversight and reporting. The PISSC is made up of our Privacy Officer, Chief Operations Officer (who is also acting as head of our security team), Chief Financial Officer, General Counsel and Chief People Officer and meets on a quarterly basis. Julie Rubinstein, who serves as our Chief Operations Officer, is leading our security team on an interim basis and is supported by a fractional chief information security officer.
Our board of directors is kept apprised of cybersecurity risks and assessments through regular presentations to the Audit Committee regarding our information security and privacy governance and reports on information security and privacy incidents. Cybersecurity threats, including as a result of any past cybersecurity incidents, have not materially affected us, including our business strategy, results of operations or financial condition. For more information regarding how cybersecurity risks may affect us, see the “Risk Factors” section.
|Cybersecurity Risk Management Processes Integrated [Flag]
|true
|Cybersecurity Risk Management Processes Integrated [Text Block]
|Our information security program is fully integrated into our operations, and a hallmark of our program is its cross-functional approach with our internal privacy objectives and stakeholders.Our cybersecurity program is based on the ISO 27001 security controls set, and in particular, it focuses on the principles of confidentiality, integrity and availability. We maintain an ISO 27001 certification with a fully integrated set of operational policies and procedures to adhere to the domains of ISO 27001. This includes but is not limited to the organization of information security to assign roles and responsibilities within Adaptive, access control to restrict employees’ access to view only that information that is relevant to their roles, information security incident management, and compliance to broadly ensure alignment with applicable laws and regulations.
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Third Party Oversight and Identification Processes [Flag]
|true
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag]
|false
|Cybersecurity Risk Board of Directors Oversight [Text Block]
|
The internal body with executive oversight of our cybersecurity program is our Privacy and Information Security Steering Committee (“PISSC”), which applies a multidisciplinary framework to cybersecurity risks and risk assessment by integrating information security, privacy and human resources expertise, oversight and reporting. The PISSC is made up of our Privacy Officer, Chief Operations Officer (who is also acting as head of our security team), Chief Financial Officer, General Counsel and Chief People Officer and meets on a quarterly basis. Julie Rubinstein, who serves as our Chief Operations Officer, is leading our security team on an interim basis and is supported by a fractional chief information security officer.
Our board of directors is kept apprised of cybersecurity risks and assessments through regular presentations to the Audit Committee regarding our information security and privacy governance and reports on information security and privacy incidents. Cybersecurity threats, including as a result of any past cybersecurity incidents, have not materially affected us, including our business strategy, results of operations or financial condition. For more information regarding how cybersecurity risks may affect us, see the “Risk Factors” section.
|Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
|Our board of directors is kept apprised of cybersecurity risks and assessments through regular presentations to the Audit Committee
|Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]
|
Our board of directors is kept apprised of cybersecurity risks and assessments through regular presentations to the Audit Committee regarding our information security and privacy governance and reports on information security and privacy incidents. Cybersecurity threats, including as a result of any past cybersecurity incidents, have not materially affected us, including our business strategy, results of operations or financial condition. For more information regarding how cybersecurity risks may affect us, see the “Risk Factors” section.
|Cybersecurity Risk Role of Management [Text Block]
|
The internal body with executive oversight of our cybersecurity program is our Privacy and Information Security Steering Committee (“PISSC”), which applies a multidisciplinary framework to cybersecurity risks and risk assessment by integrating information security, privacy and human resources expertise, oversight and reporting. The PISSC is made up of our Privacy Officer, Chief Operations Officer (who is also acting as head of our security team), Chief Financial Officer, General Counsel and Chief People Officer and meets on a quarterly basis. Julie Rubinstein, who serves as our Chief Operations Officer, is leading our security team on an interim basis and is supported by a fractional chief information security officer.
|Cybersecurity Risk Management Positions or Committees Responsible [Flag]
|true
|Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
|The PISSC is made up of our Privacy Officer, Chief Operations Officer (who is also acting as head of our security team), Chief Financial Officer, General Counsel and Chief People Officer and meets on a quarterly basis. Julie Rubinstein, who serves as our Chief Operations Officer, is leading our security team on an interim basis and is supported by a fractional chief information security officer.
|Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
|Our board of directors is kept apprised of cybersecurity risks and assessments through regular presentations to the Audit Committee regarding our information security and privacy governance and reports on information security and privacy incidents. Cybersecurity threats, including as a result of any past cybersecurity incidents
|Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag]
|true
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef