Information security and privacy management is based on the ISO/IEC 27001:2022 and 27701:2019 standards and is overseen by an Information Security and Privacy Management Committee. The Data security and privacy HC-DR-230a.1 Description of policies and practices to secure customers’ personal health data records and other personal data key practices adopted to ensure the confidentiality and integrity of customer and employee data include: information classification, access control, encryption, backups, device and vulnerability monitoring, confidentiality agreements, risk monitoring with senior leadership involvement, audits, and an incident response plan. The guidelines governing data management are codified in internal and external corporate policies, such as the Privacy Policy, Information Security Policy, Information Classification Policy, Personal Data Retention Policy, and incident management and communication policies. The company also provides a Privacy Portal so that customers can exercise their rights regarding personal data.