Data Privacy & Cybersecurity
Insmed’s data privacy and cybersecurity program is built to protect the information we create and receive, promoting trust, security, and resilience across every system we operate.
Safeguarding sensitive information
We are focused on meticulously securing information about patients, HCPs, and our employees. To address risks to information security, our cybersecurity strategy includes:
- Strengthening physical, technical, and administrative safeguards to limit risk exposure within and beyond the perimeter.
- Identifying and mitigating cyberattacks and data exploitation attempts.
- Promoting the incorporation of data privacy and security best practices into our operations and culture.
Insmed’s Chief Information Officer (CIO) oversees our cybersecurity program and provides regular updates to the Executive Committee. The Audit Committee and full Board of Directors are briefed at least annually on cyber risks, threats, ongoing security initiatives, and the evolving threat landscape. Our Executive Director of Cybersecurity and Risk Management reports directly to the CIO and leads Insmed’s enterprise-wide cybersecurity strategy, policies, standards, and processes.
Insmed is committed to compliance with data privacy regulations applicable to our collection, use, and disclosure of personally identifiable information. Applicable regulations may include the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), Washington’s My Health My Data Act, the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations (HIPAA), and the EU’s Cyber Resilience Act.
Learn more by reading Insmed’s Global Privacy Policy and Code of Business Conduct and Ethics.
Helping employees stay alert and aware
All Insmed employees complete data privacy and cybersecurity training at hire, with refreshers every two years. Ongoing phishing simulations and internal cybersecurity notices keep our teams alert to emerging threats.
Our cybersecurity program is built on proactive, layered defenses, including:
Preventive and hygiene controls
Defensive and perimeter protections
Continuous monitoring
Culture and policy integration
Third-party risk management and incident response support
Cybersecurity initiatives are embedded in our Enterprise Risk Management program, with regular internal and external assessments to track effectiveness and drive continuous improvement. We also actively collaborate with key vendors, industry partners, law enforcement, and cyber threat intelligence communities to strengthen our information security policies and procedures.
Read more about our recent data privacy and cybersecurity efforts
Next section

Your Privacy Choices