|
Cybersecurity Risk Management and Strategy Disclosure
|12 Months Ended
Dec. 31, 2025
|Cybersecurity Risk Management, Strategy, and Governance [Line Items]
|Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
|
We regularly assess risks from cybersecurity threats; monitor our information systems for potential vulnerabilities; and test those systems pursuant to our cybersecurity policies, processes, and practices, which are integrated into our overall risk management program. To protect our information systems from cybersecurity threats, we use various security tools that are designed to help identify, escalate, investigate, resolve, and recover from security incidents in a timely manner. Our Technology Risk Management Committee, which is comprised of representatives from our business operations and support functions (e.g., legal, finance, internal audit, commercial, privacy), assesses cybersecurity risks based on probability and potential impact to key business systems and processes. Cybersecurity risks that are considered high are incorporated into our overall risk management program. A mitigation plan is developed for each identified high risk, with progress on risk mitigation reported to the Technology Risk Management Committee and tracked as part of our overall risk management program, which is overseen by the Audit Committee of our board of directors.
We collaborate with third parties to assess the effectiveness of our cybersecurity prevention and response systems and processes. These include cybersecurity assessors, consultants, and other external cybersecurity experts to assist in the identification, verification, and validation of cybersecurity risks, as well as to support associated mitigation plans when necessary. We have also developed a process to conduct due diligence on third parties with which we work to oversee and identify material risks from cybersecurity threats associated with our use of those third parties' services, including those that perform cybersecurity services.
To date, the Company is not aware of risks from cybersecurity threats, including those resulting from any previous cybersecurity incidents, that have materially affected or are reasonably likely to materially affect our Company, including our business strategy, results of operations, or financial condition. Refer to the risk factor captioned "Significant disruptions of information technology systems or breaches of data security could adversely affect our business" in Part I, Item 1A. "Risk Factors" for additional information regarding cybersecurity risks and potential related impacts on our Company.
|Cybersecurity Risk Management Processes Integrated [Flag]
|true
|Cybersecurity Risk Management Processes Integrated [Text Block]
|
We regularly assess risks from cybersecurity threats; monitor our information systems for potential vulnerabilities; and test those systems pursuant to our cybersecurity policies, processes, and practices, which are integrated into our overall risk management program. To protect our information systems from cybersecurity threats, we use various security tools that are designed to help identify, escalate, investigate, resolve, and recover from security incidents in a timely manner. Our Technology Risk Management Committee, which is comprised of representatives from our business operations and support functions (e.g., legal, finance, internal audit, commercial, privacy), assesses cybersecurity risks based on probability and potential impact to key business systems and processes. Cybersecurity risks that are considered high are incorporated into our overall risk management program. A mitigation plan is developed for each identified high risk, with progress on risk mitigation reported to the Technology Risk Management Committee and tracked as part of our overall risk management program, which is overseen by the Audit Committee of our board of directors.
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Third Party Oversight and Identification Processes [Flag]
|true
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag]
|false
|Cybersecurity Risk Board of Directors Oversight [Text Block]
|
Our board of directors oversees our risk management process, including as it pertains to cybersecurity risks, directly and through its committees. The Audit Committee of the board oversees our risk management program, which focuses on the most significant risks we face in the short-, intermediate-, and long-term timeframe. Audit Committee meetings include discussions of specific risk areas throughout the year, including, among others, those relating to cybersecurity threats, and reports from the Chief Audit Executive on our enterprise risk profile on an annual basis. The Audit Committee reviews our cybersecurity risk profile with management on a periodic basis using key performance and/or risk indicators. These key performance indicators are metrics and measurements designed to assess the effectiveness of our cybersecurity program in the prevention, detection, mitigation, and remediation of cybersecurity incidents.
|Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
|Audit Committee
|Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]
|The CISO provides periodic updates on our cybersecurity risk profile to management's Technology Risk Management Committee and the Audit Committee of our board of directors.
|Cybersecurity Risk Role of Management [Text Block]
|
We take a risk-based approach to cybersecurity and have implemented cybersecurity policies throughout our operations that are designed to address cybersecurity threats and incidents. The Company's Chief Information Security Officer ("CISO"), in coordination with the Chief Digital & Technology Officer and the Technology Risk Management Committee, is responsible for the establishment and maintenance of our cybersecurity program, as well as the assessment and management of cybersecurity risks. The current CISO has over 35 years of experience in technology and information security, including operating in the role of the CISO for several large companies in the pharmaceutical and healthcare industries, and possesses the requisite education, skills, experience, and industry certifications expected of an individual assigned to these duties. The CISO provides periodic updates on our cybersecurity risk profile to management's Technology Risk Management Committee and the Audit Committee of our board of directors.
|Cybersecurity Risk Management Positions or Committees Responsible [Flag]
|true
|Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
|The Company's Chief Information Security Officer ("CISO"), in coordination with the Chief Digital & Technology Officer and the Technology Risk Management Committee, is responsible for the establishment and maintenance of our cybersecurity program, as well as the assessment and management of cybersecurity risks. The current CISO has over 35 years of experience in technology and information security, including operating in the role of the CISO for several large companies in the pharmaceutical and healthcare industries, and possesses the requisite education, skills, experience, and industry certifications expected of an individual assigned to these duties. The CISO provides periodic updates on our cybersecurity risk profile to management's Technology Risk Management Committee and the Audit Committee of our board of directors.
|Cybersecurity Risk Management Expertise of Management Responsible [Text Block]
|The current CISO has over 35 years of experience in technology and information security, including operating in the role of the CISO for several large companies in the pharmaceutical and healthcare industries, and possesses the requisite education, skills, experience, and industry certifications expected of an individual assigned to these duties.
|Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
|The CISO provides periodic updates on our cybersecurity risk profile to management's Technology Risk Management Committee and the Audit Committee of our board of directors.
|Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag]
|true
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef