|
Cybersecurity
|12 Months Ended
Dec. 31, 2024
|Cybersecurity Risk Management, Strategy, and Governance [Line Items]
|Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
|
Item 1C. Cybersecurity
The Company has adopted processes designed to identify, assess and manage material risks from cybersecurity threats. Those processes include response to and an assessment of internal and external threats to the security, confidentiality, integrity and availability of company data and systems along with other material risks to company operations, at least annually or whenever there are material changes to the Company’s systems or operations. Our business strategy, results of operations and financial condition have not been materially affected by risks from cybersecurity threats, including as a result of previously identified cybersecurity incidents, but we cannot provide assurance that they will not be materially affected in the future by such risks or any future material breaches. As part of our risk management process, the Company engages outside providers to conduct periodic penetration testing and other cybersecurity audits. The Company stores company data in cloud environments with security appropriate to data involved and has adopted controls around, among other things, vendor risk assessment, information classification, access and acceptable use and backup and recovery.
The Company's Senior Vice President of IT Security ("SVP of IT Security") has over 35 years of experience in the informational technology field, with 19 years of healthcare IT experience with an emphasis in IT security and computer forensics. The SVP of IT Security has operational responsibility for ensuring the adequacy and effectiveness of the company’s risk management, control and governance processes, who periodically reports to the Operational Risk Committee ("ORC"), responsible for applying the policy decisions and, in coordination with the Chief Digital Officer and Chief Executive Officer, reports to the Board of Directors at least annually or more regularly at the discretion of the ORC.
The Audit Committee of the Board of Directors is briefed on cybersecurity risks at least once each calendar year and also receives prompt and timely information regarding any cybersecurity incident that meets established reporting thresholds. The SVP of IT Security reports quarterly to the Audit Committee and such report addresses overall assessment of the Company’s compliance with this and other cybersecurity policies, including topics such as risk assessment, risk management and control decisions, service provider arrangements, test results, security incidents and responses, recommendations for changes and/or updates to policies and procedures.
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Third Party Oversight and Identification Processes [Flag]
|true
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag]
|false
|Cybersecurity Risk Board of Directors Oversight [Text Block]
|
The Company's Senior Vice President of IT Security ("SVP of IT Security") has over 35 years of experience in the informational technology field, with 19 years of healthcare IT experience with an emphasis in IT security and computer forensics. The SVP of IT Security has operational responsibility for ensuring the adequacy and effectiveness of the company’s risk management, control and governance processes, who periodically reports to the Operational Risk Committee ("ORC"), responsible for applying the policy decisions and, in coordination with the Chief Digital Officer and Chief Executive Officer, reports to the Board of Directors at least annually or more regularly at the discretion of the ORC.
|Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
|The SVP of IT Security has operational responsibility for ensuring the adequacy and effectiveness of the company’s risk management, control and governance processes, who periodically reports to the Operational Risk Committee ("ORC"), responsible for applying the policy decisions
|Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]
|the Chief Digital Officer and Chief Executive Officer, reports to the Board of Directors at least annually or more regularly at the discretion of the ORC.
|Cybersecurity Risk Role of Management [Text Block]
|The Audit Committee of the Board of Directors is briefed on cybersecurity risks at least once each calendar year and also receives prompt and timely information regarding any cybersecurity incident that meets established reporting thresholds. The SVP of IT Security reports quarterly to the Audit Committee and such report addresses overall assessment of the Company’s compliance with this and other cybersecurity policies, including topics such as risk assessment, risk management and control decisions, service provider arrangements, test results, security incidents and responses, recommendations for changes and/or updates to policies and procedures
|Cybersecurity Risk Management Expertise of Management Responsible [Text Block]
|The Company's Senior Vice President of IT Security ("SVP of IT Security") has over 35 years of experience in the informational technology field, with 19 years of healthcare IT experience with an emphasis in IT security and computer forensics
|Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
|The SVP of IT Security reports quarterly to the Audit Committee and such report addresses overall assessment of the Company’s compliance with this and other cybersecurity policies, including topics such as risk assessment, risk management and control decisions, service provider arrangements, test results, security incidents and responses, recommendations for changes and/or updates to policies and procedures.
|Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag]
|true
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef