|
Cybersecurity Risk Management and Strategy Disclosure
|12 Months Ended
Jun. 30, 2025
|Cybersecurity Risk Management, Strategy, and Governance [Line Items]
|Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
|
Our Cybersecurity Program (“Program”) is designed from a risk- and compliance-based approach for resilience and protection across our operations and the appropriate access, use, and/or disclosure of PHI and PII. Our Program employs the National Institute of Standards Technology (NIST) Cybersecurity Framework (CSF) and strategy to deliver multi-layered defenses and relevant technologies that are designed to control, audit, monitor, and protect access to sensitive information. We also leverage government partnerships, industry and government associations, third-party benchmarking, audits, threat intelligence feeds and other similar resources to inform our cybersecurity efforts and allocate resources.
We maintain our Program with physical, administrative and technical safeguards, and we maintain plans and procedures whose objective is to help us prevent and respond to cybersecurity incidents. Elements of our Program include: (i) required training for our employees (including onboarding and annual training), exercises (including advanced phishing exercises), and awareness for our employees to promote vigilance of cybersecurity risks, including those that may be exacerbated by artificial intelligence, and (ii) compliance audits and assessments, which include routine technical and non-technical audits and assessments internally and in collaboration with independent third parties at least annually. In addition, we engage various third-party consultants to assist us in assessing, enhancing, implementing and monitoring our Program and responding to incidents.
As a company managing the use and disclosure of PHI and PII, we annually undergo internal and/or third-party HIPAA Security Rule risk assessments of our administrative, physical, and technical safeguards. In addition, external assessors periodically evaluate our safeguards against multiple frameworks, including NIST CSF.
Our Program is integrated into our Enterprise Risk Management (ERM) program and includes a vendor risk management program supported by our security and compliance teams. We assess vendor cybersecurity risks according to HIPAA and NIST CSF standards and have established an oversight process which we periodically review to manage cybersecurity risks related to the products and services we procure.During the fiscal year ended June 30, 2025, we did not identify risks from cybersecurity threats, including as a result of previous cybersecurity incidents, that have materially affected or are reasonably likely to materially affect our business strategy, results of operations, or financial condition. While prior incidents have not had a material impact on us, future incidents could have a material impact on our business, operations, and reputation. See “Security breaches, loss of data and other disruptions have in the past and could in the future compromise sensitive information related to our business or our participants, or prevent us from accessing critical information and expose us to liability, and could adversely affect our business and our reputation” in Item 1A “Risk Factors” in this Annual Report.
|Cybersecurity Risk Management Processes Integrated [Flag]
|true
|Cybersecurity Risk Management Processes Integrated [Text Block]
|Our Program is integrated into our Enterprise Risk Management (ERM) program and includes a vendor risk management program supported by our security and compliance teams. We assess vendor cybersecurity risks according to HIPAA and NIST CSF standards and have established an oversight process which we periodically review to manage cybersecurity risks related to the products and services we procure.
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Third Party Oversight and Identification Processes [Flag]
|true
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag]
|false
|Cybersecurity Risk Board of Directors Oversight [Text Block]
|
While our full Board has overall responsibility for risk oversight, it has delegated primary oversight of certain risks to its committees. Our Audit Committee monitors cybersecurity risks, and the steps our management has taken to monitor and control exposures. Our Chief Information Officer (CIO) and Chief Information Security Officer (CISO) brief the Audit Committee quarterly on cybersecurity risks, updates on the regulatory and cyber landscape and significant cybersecurity events, as needed. Our Audit Committee reports to our Board on cybersecurity matters quarterly, or more often as the need arises.
We have an Information Security Team to strengthen our cybersecurity risk management activities across the Company, with its members having experience in public and private companies within the healthcare industry, as well as various cybersecurity certifications. The Information Security Team reports to our CISO who works in collaboration with our CIO, Chief Compliance Officer and General Counsel. The Information Security Team is responsible for the oversight and operation of our Program, and the management our security standards and operating procedures.
Cole Naus is our CISO. Mr. Naus has over 10 years of experience in the cybersecurity industry. Mr. Naus holds a degree in Cybersecurity and Information Assurance and holds other cybersecurity certifications. Mr. Naus reports directly to Cara Babachicos, our CIO. Ms. Babachicos has over 20 years of experience in the cybersecurity industry, having previously worked as Chief Information Officer at other companies in the healthcare industry.
|Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
|While our full Board has overall responsibility for risk oversight, it has delegated primary oversight of certain risks to its committees. Our Audit Committee monitors cybersecurity risks, and the steps our management has taken to monitor and control exposures
|Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]
|We have an Information Security Team to strengthen our cybersecurity risk management activities across the Company, with its members having experience in public and private companies within the healthcare industry, as well as various cybersecurity certifications. The Information Security Team reports to our CISO who works in collaboration with our CIO, Chief Compliance Officer and General Counsel. The Information Security Team is responsible for the oversight and operation of our Program, and the management our security standards and operating procedures.
|Cybersecurity Risk Role of Management [Text Block]
|Our Audit Committee monitors cybersecurity risks, and the steps our management has taken to monitor and control exposures. Our Chief Information Officer (CIO) and Chief Information Security Officer (CISO) brief the Audit Committee quarterly on cybersecurity risks, updates on the regulatory and cyber landscape and significant cybersecurity events, as needed. Our Audit Committee reports to our Board on cybersecurity matters quarterly, or more often as the need arises.
We have an Information Security Team to strengthen our cybersecurity risk management activities across the Company, with its members having experience in public and private companies within the healthcare industry, as well as various cybersecurity certifications. The Information Security Team reports to our CISO who works in collaboration with our CIO, Chief Compliance Officer and General Counsel. The Information Security Team is responsible for the oversight and operation of our Program, and the management our security standards and operating procedures.Cole Naus is our CISO. Mr. Naus has over 10 years of experience in the cybersecurity industry. Mr. Naus holds a degree in Cybersecurity and Information Assurance and holds other cybersecurity certifications. Mr. Naus reports directly to Cara Babachicos, our CIO. Ms. Babachicos has over 20 years of experience in the cybersecurity industry, having previously worked as Chief Information Officer at other companies in the healthcare industry
|Cybersecurity Risk Management Positions or Committees Responsible [Flag]
|true
|Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
|Our Chief Information Officer (CIO) and Chief Information Security Officer (CISO) brief the Audit Committee quarterly on cybersecurity risks, updates on the regulatory and cyber landscape and significant cybersecurity events, as needed. Our Audit Committee reports to our Board on cybersecurity matters quarterly, or more often as the need arises.
|Cybersecurity Risk Management Expertise of Management Responsible [Text Block]
|
Cole Naus is our CISO. Mr. Naus has over 10 years of experience in the cybersecurity industry. Mr. Naus holds a degree in Cybersecurity and Information Assurance and holds other cybersecurity certifications. Mr. Naus reports directly to Cara Babachicos, our CIO. Ms. Babachicos has over 20 years of experience in the cybersecurity industry, having previously worked as Chief Information Officer at other companies in the healthcare industry.
|Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
|Our Chief Information Officer (CIO) and Chief Information Security Officer (CISO) brief the Audit Committee quarterly on cybersecurity risks, updates on the regulatory and cyber landscape and significant cybersecurity events, as needed. Our Audit Committee reports to our Board on cybersecurity matters quarterly, or more often as the need arises.
|Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag]
|true
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef