Third Party Index

Snapshot 30751

Document
Registry listing
URL
https://data.sec.gov/submissions/CIK0001412408.json#annual
Fetched
HTTP status
200
Content type
application/json
Fetch mode
api
Size
14195 bytes
SHA-256 (raw)
fd756c9eb46136a1a2f789fa4b1d82e215bf6ca45b204f6c8dbf9c2f196ea270
SHA-256 (normalized text)
dc23be4f02532d1e26cd889097e206c352c3f28087218f7ffed52093ec53ae65

Normalized text

Scripts and page chrome removed; this is what change detection compares.

{
  "cik": "1412408",
  "name": "Phreesia, Inc.",
  "reports": [
    {
      "accession": "0001412408-26-000079",
      "document": "https://www.sec.gov/Archives/edgar/data/1412408/000141240826000079/phr-20260131.htm",
      "filed": "2026-03-31",
      "form": "10-K",
      "index": "https://www.sec.gov/Archives/edgar/data/1412408/000141240826000079/0001412408-26-000079-index.htm",
      "period": "2026-01-31",
      "text": "As a healthcare-focused company, we understand the importance of managing cybersecurity risks that we face and have established a cybersecurity risk management program as part of our enterprise risk management program.\nCyber Risk Management and Strategy\nOur cybersecurity risk management program is informed by recognized industry standards and frameworks and incorporates elements of the same, including elements of the National Institute of Standards and Technology Cybersecurity Framework and The Health Information Trust Alliance (HITRUST) Common Security Framework. Additionally, we are certified as a PCI-DSS Level 1 Service Provider. The Company’s cybersecurity program utilizes a cross functional, multilayered defense-in-depth approach designed to: (i) identify, prevent and mitigate cybersecurity threats to the Company; (ii) preserve the confidentiality, security and availability of the information that we collect and store; (iii) protect the Company’s intellectual property; (iv) maintain the confidence of our customers, clients and business partners; and (v) provide appropriate public disclosure and required notices of cybersecurity risks and incidents when required.\nOur cybersecurity program includes safeguards that are designed to protect the Company’s information systems from cybersecurity threats. Such safeguards include firewalls, automated intrusion detection systems, anti-malware functionality and access controls, which are evaluated and improved through periodic vulnerability assessments and ongoing cybersecurity threat intelligence. We have established and maintain an incident response plan that addresses the Company’s response to and recovery from a cybersecurity incident. The incident response plan is tested and evaluated on an annual basis.\nThe Company’s cybersecurity program is supported by engagement of third-party service providers who help identify, assess and respond to cybersecurity risks. For example, the Company regularly engages third parties to perform and facilitate assessments on our cybersecurity measures, including information security maturity assessments, audits, tabletop exercises, threat modeling and independent reviews of our information security control environment and operating effectiveness. The results of such assessments, audits and reviews are reported to leadership, the Audit Committee, and/or the Board, as appropriate, and the Company adjusts its cybersecurity policies, standards, processes and practices as appropriate based on the information provided by the assessments, audits and reviews.\nAs part of our cybersecurity risk management program, we maintain a risk-based approach to identifying and overseeing cybersecurity risks presented by third parties, including vendors, service providers and other external users of the Company’s systems, as well as the systems of third parties that could adversely impact our business. Further, all personnel are required to undergo cybersecurity training during onboarding and, thereafter, on an annual basis to reinforce the Company’s information security policies, standards and practices. Additionally, we conduct extensive cybersecurity assessments of potential acquisition targets to understand potential threats and mitigate risks, and the acquisition integration process includes alignment with relevant information security policies and procedures following completion of the transaction. We maintain cyber liability insurance to help mitigate potential liabilities resulting from cybersecurity issues, although our insurance may not cover all types of cybersecurity incidents or all losses that we incur.\nWe have not identified any cybersecurity incidents or threats that have materially affected us or are reasonably likely to materially affect us, including our business strategy, results of operations, or financial condition. However, like other companies in our industry, we and our third-party vendors have experienced and will likely experience threats and security incidents that could affect our information or systems. See Item 1A “Risk Factors” in this Annual Report on Form 10-K for more information.\nGovernance\nPhreesia takes a cross-functional approach to address the risks from cybersecurity threats. The Company’s Board of Directors (the “Board”) maintains oversight responsibility over the Company’s enterprise risk management (“ERM”) program, which incorporates the Company’s cybersecurity risk management program. The Board’s oversight of cybersecurity risk management is supported by the Audit Committee of the Board (the “Audit Committee”), which regularly interacts with the Company’s ERM function, the Company’s Chief Technology Officer, along with other members of management including the Chief Information Security Officer and the Chief Privacy Officer.\nThe Company’s Chief Information Security Officer is principally responsible for day-to-day management of the Company’s cybersecurity risk management program and reports to the Chief Technology Officer. The Chief Information Security Officer has more than 15 years of cybersecurity experience, including leadership roles at four publicly traded companies. He is a Certified Information Systems Security Professional, holds a M.S. in Security Technologies from the University of Minnesota and is an alumnus of the FBI Citizen’s Academy. The Chief Technology Officer has served in various leadership roles in information technology and information security at the Company for over 15 years and holds a B.S. in computer science from Worcester Polytechnic Institute. The Chief Technology Officer reports directly to the Chief Executive Officer and works in coordination with the other members of the leadership team, which includes our General Counsel, President, Provider Solutions, President, Network Solutions and Chief Financial Officer. The Chief Technology Officer oversees a team of security professionals, which is led by the Chief Information Security Officer. The security team includes approximately 40 security professionals, 30 of whom are security engineers or analysts. The security team’s functions include identity and access management; security operations and incident response; governance, risk, and compliance; security architecture; third-party risk management, and application security.\nThe Board and the Audit Committee each receive quarterly presentations and reports from the Company’s Chief Technology Officer and/or General Counsel on cybersecurity risks, which address a wide range of topics including, among others, recent developments, evolving standards, vulnerability assessments, third-party and independent reviews, the threat environment, technological trends and information security considerations arising with respect to the Company’s peers and third party service providers. The Board and the Audit Committee also receive prompt and timely information regarding any cybersecurity incident that meets established reporting thresholds under the Company’s incident response plan."
    },
    {
      "accession": "0001412408-25-000010",
      "document": "https://www.sec.gov/Archives/edgar/data/1412408/000141240825000010/phr-20250131.htm",
      "filed": "2025-03-13",
      "form": "10-K",
      "index": "https://www.sec.gov/Archives/edgar/data/1412408/000141240825000010/0001412408-25-000010-index.htm",
      "period": "2025-01-31",
      "text": "As a healthcare-focused company, we understand the importance of managing cybersecurity risks that we face and have established a cybersecurity risk management program as part of our enterprise risk management program.\nCyber Risk Management and Strategy\nOur cybersecurity risk management program is informed by recognized industry standards and frameworks and incorporates elements of the same, including elements of the National Institute of Standards and Technology Cybersecurity Framework and The Health Information Trust Alliance (HITRUST) Common Security Framework. Additionally, we are certified as a PCI-DSS Level 1 Service Provider. The Company’s cybersecurity program utilizes a cross functional, multilayered defense-in-depth approach designed to: (i) identify, prevent and mitigate cybersecurity threats to the Company; (ii) preserve the confidentiality, security and availability of the information that we collect and store; (iii) protect the Company’s intellectual property; (iv) maintain the confidence of our customers, clients and business partners; and (v) provide appropriate public disclosure and required notices of cybersecurity risks and incidents when required.\nOur cybersecurity program includes safeguards that are designed to protect the Company’s information systems from cybersecurity threats. Such safeguards include firewalls, automated intrusion detection systems, anti-malware functionality and access controls, which are evaluated and improved through periodic vulnerability assessments and ongoing cybersecurity threat intelligence. We have established and maintain an incident response plan that addresses the Company’s response to and recovery from a cybersecurity incident. The incident response plan is tested and evaluated on an annual basis.\nThe Company’s cybersecurity program is supported by engagement of third-party service providers who help identify, assess and respond to cybersecurity risks. For example, the Company regularly engages third parties to perform and facilitate assessments on our cybersecurity measures, including information security maturity assessments, audits, tabletop exercises, threat modeling and independent reviews of our information security control environment and operating effectiveness. The results of such assessments, audits and reviews are reported to leadership, the Audit Committee, and/or the Board, as appropriate, and the Company adjusts its cybersecurity policies, standards, processes and practices as appropriate based on the information provided by the assessments, audits and reviews.\nAs part of our cybersecurity risk management program, we maintain a risk-based approach to identifying and overseeing cybersecurity risks presented by third parties, including vendors, service providers and other external users of the Company’s systems, as well as the systems of third parties that could adversely impact our business. Further, all personnel are required to undergo cybersecurity training during onboarding and, thereafter, on an annual basis to reinforce the Company’s information security policies, standards and practices.\nWe have not identified any cybersecurity incidents or threats that have materially affected us or are reasonably likely to materially affect us, including our business strategy, results of operations, or financial condition. However, like other companies in our industry, we and our third-party vendors have experienced and will likely experience threats and security incidents that could affect our information or systems. See Item 1A “Risk Factors” in this Annual Report on Form 10-K for more information.\nGovernance\nPhreesia takes a cross-functional approach to address the risks from cybersecurity threats. The Company’s Board of Directors (the “Board”) maintains oversight responsibility over the Company’s enterprise risk management (“ERM”) program, which incorporates the Company’s cybersecurity risk management program. The Board’s oversight of cybersecurity risk management is supported by the Audit Committee of the Board (the “Audit Committee”), which regularly interacts with the Company’s ERM function, the Company’s Chief Technology Officer, along with other members of management including the Chief Information Security Officer, the Chief Privacy Officer, and the compliance, audit, and risk teams.\nThe Company’s Chief Information Security Officer is principally responsible for day-to-day management of the Company’s cybersecurity risk management program and reports to the Chief Technology Officer. The Chief Information Security Officer has more than 15 years of cybersecurity experience, including leadership roles at four publicly traded companies. He is a Certified Information Systems Security Professional, holds a M.S. in Security Technologies from the University of Minnesota and is an alumnus of the FBI Citizen’s Academy. The Chief Technology Officer has served in various leadership roles in information technology and information security at the Company for over 14 years and holds a B.S. in computer science from Worcester Polytechnic Institute. The Chief Technology Officer reports directly to the Chief Executive Officer and works in coordination with the other members of the leadership team, which includes our General Counsel, Chief Operating Officer, and Chief Financial Officer. The Chief Technology Officer oversees a team of security professionals, which is led by the Chief Information\nSecurity Officer. The security team includes approximately 36 security professionals, 25 of whom are security engineers. Other members of the team oversee and manage identity, risk, compliance and audit functions.\nThe Board and the Audit Committee each receive quarterly presentations and reports from the Company’s Chief Technology Officer and/or General Counsel on cybersecurity risks, which address a wide range of topics including, among others, recent developments, evolving standards, vulnerability assessments, third-party and independent reviews, the threat environment, technological trends and information security considerations arising with respect to the Company’s peers and third party service providers. The Board and the Audit Committee also receive prompt and timely information regarding any cybersecurity incident that meets established reporting thresholds under the Company’s incident response plan."
    }
  ]
}