Public companies are required to disclose risks that can affect the business and impact the stock. These disclosures are known as “Risk Factors”. Companies disclose these risks in their yearly (Form 10-K), quarterly earnings (Form 10-Q), or “foreign private issuer” reports (Form 20-F). Risk factors show the challenges a company faces. Investors can consider the worst-case scenarios before making an investment. TipRanks’ Risk Analysis categorizes risks based on proprietary classification algorithms and machine learning.
EngageSmart disclosed 78 risk factors in its most recent earnings report. EngageSmart reported the most risks in the “Finance & Corporate” category.
Risk Overview Q1, 2023
Risk Distribution
35% Finance & Corporate
24% Tech & Innovation
19% Legal & Regulatory
12% Ability to Sell
6% Production
4% Macro & Political
Finance & Corporate - Financial and accounting risks. Risks related to the execution of corporate activity and strategy
This chart displays the stock's most recent risk distribution according to category. TipRanks has identified 6 major categories: Finance & corporate, legal & regulatory, macro & political, production, tech & innovation, and ability to sell.
Risk Change Over Time
S&P500 Average
Sector Average
Risks removed
Risks added
Risks changed
EngageSmart Risk Factors
New Risk (0)
Risk Changed (0)
Risk Removed (0)
No changes from previous report
The chart shows the number of risks a company has disclosed. You can compare this to the sector average or S&P 500 average.
The quarters shown in the chart are according to the calendar year (January to December). Businesses set their own financial calendar, known as a fiscal year. For example, Walmart ends their financial year at the end of January to accommodate the holiday season.
Risk Highlights Q1, 2023
Main Risk Category
Finance & Corporate
With 27 Risks
Finance & Corporate
With 27 Risks
Number of Disclosed Risks
78
No changes from last report
S&P 500 Average: 32
78
No changes from last report
S&P 500 Average: 32
Recent Changes
0Risks added
0Risks removed
0Risks changed
Since Mar 2023
0Risks added
0Risks removed
0Risks changed
Since Mar 2023
Number of Risk Changed
0
-2
From last report
S&P 500 Average: 4
0
-2
From last report
S&P 500 Average: 4
See the risk highlights of EngageSmart in the last period.
Risk Word Cloud
The most common phrases about risk factors from the most recent report. Larger texts indicate more widely used phrases.
Risk Factors Full Breakdown - Total Risks 78
Finance & Corporate
Total Risks: 27/78 (35%)Above Sector Average
Share Price & Shareholder Rights10 | 12.8%
Share Price & Shareholder Rights - Risk 1
Our stock price may fluctuate significantly and purchasers of our common stock could incur substantial losses.
The market price of our common stock could vary significantly as a result of a number of factors, some of which are beyond our control. In the event of a drop in the market price of our common stock, you could lose a substantial part or all of your investment in our common stock. The following factors could affect our stock price:
- our operating and financial performance and prospects;- quarterly variations in the rate of growth (if any) of our financial indicators, such as net income per share, net income and revenues;- the public reaction to our press releases, our other public announcements and our filings with the Securities and Exchange Commission ("SEC");- strategic actions by our competitors;- changes in operating performance and the stock market valuations of other companies;- overall conditions in our industry and the markets in which we operate;- announcements related to litigation;- our failure to meet revenue or earnings estimates made by research analysts or other investors;- changes in revenue or earnings estimates, or changes in recommendations or withdrawal of research coverage, by equity research analysts;- speculation in the press or investment community;- issuance of new or updated research or reports by securities analysts;- sales of our common stock by us or our stockholders, or the perception that such sales may occur;- changes in accounting principles, policies, guidance, interpretations, or standards;- additions or departures of key management personnel;- actions by our stockholders;- general market conditions;- economic, legal and regulatory factors unrelated to our performance;- announcement by us or our competitors of significant acquisitions, strategic partnerships, joint ventures or capital commitments;- security breaches impacting us or other similar companies;- expiration of contractual lock-up agreements with our executive officers, directors and stockholders;- material weaknesses in our internal control over financial reporting; and - the realization of any risks described under this "Risk Factors" section, or other risks that may materialize in the future.
The stock markets in general have experienced extreme volatility that has often been unrelated to the operating performance of particular companies. These broad market fluctuations may adversely affect the trading price of our common stock. Securities class action litigation has often been instituted against companies following periods of volatility in the overall market and in the market price of a company's securities. Such litigation, if instituted against us, could result in very substantial costs, divert our management's attention and resources and harm our business, financial condition, and results of operations.
Share Price & Shareholder Rights - Risk 2
General Atlantic has significant influence over EngageSmart, including control over decisions that require the approval of stockholders, which could limit your ability to influence the outcome of matters submitted to stockholders for a vote.
As of December 31, 2022, General Atlantic owns approximately 59% of the outstanding shares of our common stock. As long as General Atlantic owns or controls a majority of our outstanding voting power, General Atlantic will have the ability to exercise substantial control over all corporate actions requiring stockholder approval, irrespective of how our other stockholders may vote, including:
- the election and removal of directors and the size of our board of directors;- any amendment of our articles of incorporation or bylaws; or - the approval of mergers and other significant corporate transactions, including a sale of substantially all of our assets.
Moreover, ownership of our shares by General Atlantic may also adversely affect the trading price for our common stock to the extent investors perceive disadvantages in owning shares of a company with a controlling stockholder. For example, the concentration of ownership held by General Atlantic could delay, defer, or prevent a change in control of our company or impede a merger, takeover, or other business combination which may otherwise be favorable for us. In addition, directors appointed by General Atlantic currently comprise a majority of the members of our board of directors. General Atlantic is also in the business of making investments in companies and may, from time to time, acquire interests in businesses that directly or indirectly compete with our business, as well as businesses that are significant existing or potential customers. Some of the companies in which General Atlantic invests may compete with us. General Atlantic may acquire or seek to acquire assets complementary to our business that we seek to acquire and, as a result, those acquisition opportunities may not be available to us or may be more expensive for us to pursue, and as a result, the interests of General Atlantic may not coincide with the interests of our other stockholders. So long as General Atlantic continues to directly or indirectly own a significant amount of our equity, even if such amount is less than 50%, General Atlantic will continue to be able to substantially influence or effectively control our ability to enter into corporate transactions.
Share Price & Shareholder Rights - Risk 3
We are a "controlled company" within the meaning of the NYSE rules and, as a result, qualify for and intend to rely on exemptions from certain corporate governance requirements.
General Atlantic controls a majority of the voting power of our outstanding voting stock, and as a result we are a controlled company within the meaning of the NYSE corporate governance standards. Under the NYSE rules, a company of which more than 50% of the voting power is held by another person or group of persons acting together is a controlled company and may elect not to comply with certain corporate governance requirements, including the requirements that:
- a majority of the board of directors consist of independent directors;- the nominating and corporate governance committee be composed entirely of independent directors with a written charter addressing the committee's purpose and responsibilities;- the compensation committee be composed entirely of independent directors with a written charter addressing the committee's purpose and responsibilities; and - there be an annual performance evaluation of the nominating and corporate governance and compensation committees.
We may utilize these exemptions as long as we remain a controlled company. Accordingly, you may not have the same protections afforded to stockholders of companies that are subject to all of the corporate governance requirements of the NYSE. After we cease to be a "controlled company," we will be required to comply with the above referenced requirements within one year.
Share Price & Shareholder Rights - Risk 4
Anti-takeover provisions contained in our charter documents and Delaware law could prevent a takeover that stockholders consider favorable and could also reduce the market price of our stock.
Our amended and restated certificate of incorporation (the "Amended Charter") and our amended and our bylaws ("Bylaws") contain provisions that could delay or prevent a change in control of our company. These provisions could also make it more difficult for stockholders to elect directors and take other corporate actions. These provisions include:
- a classified board of directors with three-year staggered terms, which may delay the ability of stockholders to change the membership of a majority of our board of directors;- no cumulative voting in the election of directors, which limits the ability of minority stockholders to elect director candidates;- the exclusive right (subject to certain rights granted pursuant to our stockholders agreement) of our board of directors to elect a director to fill a vacancy created by the expansion of the board of directors or the resignation, death or removal of a director, which prevents stockholders from being able to fill vacancies on our board of directors;- the ability of our board of directors to authorize the issuance of shares of preferred stock and to determine the price and other terms of those shares, including preferences and voting rights, without stockholder approval, which could be used to significantly dilute the ownership of a hostile acquiror;- the ability of our board of directors to alter our Bylaws without obtaining stockholder approval;- the required approval of, prior to the first date General Atlantic and its affiliated companies cease to beneficially own in aggregate at least 40% of our shares entitled to vote (the "Stockholder Consent Trigger Date"), at least a majority of the voting power of all outstanding shares entitled to vote, and on or after the Stockholder Consent Trigger Date, at least 66 2/3% of the shares entitled to vote at an election of directors to adopt, amend or repeal certain provisions of our Amended Charter, including anti-takeover provisions related to our classified board of directors to alter our Bylaws without stockholder approval, the inability of stockholders to act by written consent, exclusive right of the board of directors to call special meetings of stockholders, and choice of forum, and the required stockholder vote to amend the forgoing provisions of our Amended Charter.
- a prohibition on stockholder action by written consent from and after the Stockholder Consent Trigger Date, which forces stockholder action to be taken at an annual or special meeting of our stockholders;- the requirement that a special meeting of stockholders may be called only by our board of directors, or prior to the Stockholder Consent Trigger Date, by the chairman of our board of directors at the written request of General Atlantic, which may delay the ability of our stockholders to force consideration of a proposal or to take action, including the removal of directors; and - advance notice procedures that stockholders must comply with in order to nominate candidates to our board of directors or to propose matters to be acted upon at a stockholders' meeting, which may discourage or deter a potential acquiror from conducting a solicitation of proxies to elect the acquiror's own slate of directors or otherwise attempting to obtain control of us.
These and other provisions in our Amended Charter and our Bylaws and under Delaware law could discourage potential takeover attempts, reduce the price investors might be willing to pay in the future for shares of our common stock, and result in the market price of our common stock being lower than it would be without these provisions.
Share Price & Shareholder Rights - Risk 5
Our Amended Charter provides that certain courts in the State of Delaware or the federal district courts of the United States for certain types of lawsuits will be the sole and exclusive forum for substantially all disputes between us and our stockholders, which could limit our stockholders' ability to obtain a favorable judicial forum for disputes with us or our directors, officers, or employees.
Our Amended Charter provides that, unless we consent in writing to the selection of an alternative forum, the Court of Chancery of the State of Delaware is the sole and exclusive forum for (i) any derivative action or proceeding brought on our behalf, (ii) any action asserting a claim of breach of a fiduciary duty owed by any of our directors or officers to us or our stockholders, creditors, or other constituents (iii) any action asserting a claim arising pursuant to any provision of the Delaware General Corporation Law ("DGCL") or of our certificate of incorporation or our bylaws, or (iv) any action asserting a claim related to or involving the Company that is governed by the internal affairs doctrine. The exclusive forum provision provides that it will not apply to claims arising under the Securities Act, the Exchange Act or other federal securities laws for which there is exclusive federal or concurrent federal and state jurisdiction. Unless we consent in writing to the selection of an alternative forum, the federal district courts of the United States of America shall be the exclusive forum for the resolution of any complaint asserting a cause of action arising under the Securities Act.
Any person or entity purchasing or otherwise acquiring any interest in shares of our capital stock will be deemed to have notice of and, to the fullest extent permitted by law, to have consented to the provisions of our certificate of incorporation described above. Although we believe this exclusive forum provision benefits us by providing increased consistency in the application of Delaware law and federal securities laws in the types of lawsuits to which each applies, the choice of forum provision may limit a stockholder's ability to bring a claim in a judicial forum that it finds favorable for disputes with us or our directors, officers, other employees or stockholders, which may discourage such lawsuits against us and our directors, officers, other employees or stockholders. However, the enforceability of similar forum provisions in other companies'certificates of incorporation has been challenged in legal proceedings. If a court were to find the exclusive choice of forum provision contained in our certificate of incorporation to be inapplicable or unenforceable in an action, we may incur additional costs associated with resolving such action in other jurisdictions, which could materially adversely affect our business, financial condition, and results of operations.
Share Price & Shareholder Rights - Risk 6
You may be diluted by the future issuance of additional common stock or convertible securities in connection with our incentive plans, acquisitions or otherwise, which could adversely affect our stock price.
As of December 31, 2022, we had 483,918,989 shares of common stock authorized but unissued. Our certificate of incorporation authorizes us to issue these shares of common stock and options, rights, warrants and appreciation rights relating to common stock for the consideration and on the terms and conditions established by our board of directors in its sole discretion, whether in connection with acquisitions or otherwise. As of December 31, 2022, we had approximately 4,723,325 options outstanding, which could be exercisable following the satisfaction of vesting conditions into approximately 4,723,325 shares of common stock. As of December 31, 2022 we had 2,336,745 restricted stock units outstanding. As of December 31, 2022, we had 12,354,217 remaining available for future grant under our 2021 Plan and 2,155,456 shares available for future issuance under the 2021 Employee Stock Purchase Plan ("2021 ESPP"). Any common stock that we issue, including under our 2021 Plan or other equity incentive plans that we may adopt in the future, as well as under outstanding options would dilute the percentage ownership held by the investors who purchase common stock.
From time to time in the future, we may also issue additional shares of our common stock or securities convertible into common stock pursuant to a variety of transactions, including acquisitions. Our issuance of additional shares of our common stock or securities convertible into our common stock would dilute your ownership of us and the sale of a significant amount of such shares in the public market could adversely affect prevailing market prices of our common stock.
Share Price & Shareholder Rights - Risk 7
Future sales of our common stock in the public market, or the perception in the public market that such sales may occur, could reduce our stock price.
As of December 31, 2022, we had 166,081,011 shares of common stock outstanding. In addition, 21,569,743 shares of our common stock that are either subject to outstanding stock awards or reserved for future issuance under our 2021 Plan and 2021 ESPP are eligible for sale in the public market to the extent permitted by the provisions of various vesting schedules and Rule 144 and Rule 701 under the Securities Act. If these additional shares of common stock are sold, or if it is perceived that they will be sold, in the public market, the trading price of our common stock could decline. Moreover, General Atlantic, Summit and Robert P. Bennett, our Chief Executive Officer and a director, have certain rights to require us to register the sale of common stock held by such stockholders, including in connection with underwritten offerings, subject to the terms of the registration rights agreement. Sales of significant amounts of stock in the public market or the perception that such sales may occur, could adversely affect prevailing market prices of our common stock or make it more difficult for you to sell your shares of common stock at a time and price that you deem appropriate.
Share Price & Shareholder Rights - Risk 8
We are an "emerging growth company," and are able take advantage of reduced disclosure requirements applicable to "emerging growth companies," which could make our common stock less attractive to investors.
We are an "emerging growth company," as defined in the JOBS Act, and have taken advantage of certain exemptions from various disclosure requirements applicable to companies that are not "emerging growth companies." These exemptions include reduced disclosure obligations regarding executive compensation and historical financial statements. In addition, "emerging growth companies" can delay adopting new or revised accounting standards until such time as those standards apply to private companies. We have elected to use this extended transition period for complying with new or revised accounting standards. As a result, our consolidated financial statements may not be comparable to companies that comply with new or revised accounting pronouncements as of public company effective dates.
We cannot predict if investors will find our common stock less attractive because we rely on these exemptions. If some investors find our common stock less attractive as a result of any choices to reduce disclosure, there may be a less active trading market for our common stock and our stock price may decline or become more volatile and it may be difficult for us to raise additional capital if and when we need it.
Share Price & Shareholder Rights - Risk 9
If securities or industry analysts do not publish research or reports about our business or publish negative reports, our stock price could decline.
The trading market for our common stock is influenced by the research and reports that industry or securities analysts publish about us, our business or our market. If one or more of these analysts ceases coverage of our company or fails to publish reports on us regularly, we could lose visibility in the financial markets, which in turn could cause our stock price or trading volume to decline. Moreover, if one or more of the analysts who cover our company issues adverse or misleading research or reports regarding us, our business model, our stock performance or our market, or if our operating results do not meet their expectations, our stock price could decline.
Share Price & Shareholder Rights - Risk 10
We may issue preferred securities, the terms of which could adversely affect the voting power or value of our common stock.
Our certificate of incorporation authorizes us to issue, without the approval of our stockholders, one or more classes or series of preferred securities having such designations, preferences, limitations, and relative rights, including preferences over our common stock respecting dividends and distributions, as our board of directors may determine. The terms of one or more classes or series of preferred securities could adversely impact the voting power or value of our common stock. For example, we might grant holders of preferred securities the right to elect some number of our directors in all events or on the happening of specified events or the right to veto specified transactions. Similarly, the repurchase or redemption rights or liquidation preferences we might assign to holders of preferred securities could affect the residual value of the common stock.
Accounting & Financial Operations7 | 9.0%
Accounting & Financial Operations - Risk 1
We do not anticipate paying dividends on our common stock in the foreseeable future and, consequently, your ability to achieve a return on your investment will depend on appreciation of the value of our common stock.
We do not anticipate paying any dividends in the foreseeable future on our common stock. We intend to retain all future earnings for the operation and expansion of our business and the repayment of outstanding debt. Our 2021 Revolving Credit Facility contains, and any future indebtedness likely will contain, restrictive covenants that impose significant operating and financial restrictions on us, including restrictions on us and our ability to pay dividends and make other restricted payments. As a result, any return to stockholders will be limited to any appreciation in the value of our common stock, which is not certain. While we may change this policy at some point in the future, we cannot assure you that we will make such a change.
Accounting & Financial Operations - Risk 2
We do not generate any revenue and rely on dividends, distributions, and other payments, advances, and transfers of funds from our subsidiaries to meet its obligations.
We are a holding company that does not conduct any material revenue-generating business operations of our own. As a result, we are largely dependent upon cash dividends and distributions and other transfers, including for payments in respect of our indebtedness, from our subsidiaries to meet our obligations. The ability of our subsidiaries to pay cash dividends and/or make loans or advances to us will be dependent upon their respective abilities to achieve sufficient cash flows after satisfying their respective cash requirements to enable the payment of such dividends or the making of such loans or advances. The agreements governing the indebtedness of our subsidiaries impose restrictions on our subsidiaries' ability to pay dividends or other distributions to us. See "Management's Discussion and Analysis of Financial Condition and Results of Operations-Liquidity and Capital Resources." Each of our subsidiaries is a distinct legal entity, and under certain circumstances legal and contractual restrictions may limit our ability to obtain cash from them and we may be limited in our ability to cause any future joint ventures to distribute their earnings to us. The deterioration of the earnings from, or other available assets of, our subsidiaries for any reason could also limit or impair their ability to pay dividends or other distributions to us.
Accounting & Financial Operations - Risk 3
Our ability to utilize our net operating loss carryforwards and certain other tax attributes to offset taxable income or taxes may be limited.
As of December 31, 2022, we had U.S. federal and state net operating loss carryforwards of $1.8 million and $12.5 million, respectively. The federal net operating loss carryforwards will expire at various dates beginning in 2032. We continue to evaluate the utilization of state net operating loss carryforwards. Portions of these net operating loss carryforwards could expire unused and be unavailable to offset future income tax liabilities. Under the legislation enacted in 2017, commonly referred to as the Tax Cuts and Jobs Act (the "Tax Act"), as modified by the Coronavirus Aid, Relief, and Economic Security (the "CARES Act"), U.S. federal net operating losses incurred in taxable years beginning after December 31, 2017, may be carried forward indefinitely, but the deductibility of such federal net operating losses in taxable years beginning after December 31, 2020, is limited. It is uncertain how various states will respond to the Tax Act and the CARES Act. For state income tax purposes, there may be periods during which the use of net operating loss carryforwards is suspended or otherwise limited, which could accelerate or permanently increase state taxes owed.
In addition, under Sections 382 and 383 of the Internal Revenue Code ("IRC") of 1986, as amended, and corresponding provisions of state law, if a corporation undergoes an "ownership change," which is generally defined as a greater than 50% change, by value, in its equity ownership over a three-year period, the corporation's ability to use its pre-change net operating loss carryforwards and other pre-change tax attributes to offset its post-change income or taxes may be limited. We may experience ownership changes as a result of subsequent shifts in our stock ownership, some of which may be outside of our control, causing additional limitations beyond what we are already subject to. If an ownership change occurs and our ability to use our net operating loss carryforwards is materially limited, it would harm our future results of operations by effectively increasing our future tax obligations.
For tax years beginning after December 31, 2021, the Tax Act eliminated the option to deduct research and development expenditures in the period incurred and requires taxpayers to capitalize and amortize such expenditures over five or fifteen years, as applicable, pursuant to Section 174 of the IRC. For the tax year ended December 31, 2022, this tax law change did not result in any U.S. federal tax liability due to the use of existing U.S. federal net operating loss carryforwards and research and development credits. However, for any future tax years, this tax law change may harm our results of operations by effectively increasing our future tax obligations.
Accounting & Financial Operations - Risk 4
Our reported financial results may be adversely affected by changes in accounting principles generally accepted in the United States.
GAAP is subject to interpretation by the Financial Accounting Standards Board ("FASB"), the SEC, and various bodies formed to promulgate and interpret appropriate accounting principles. The accounting for our business is complicated,particularly in the area of revenue recognition, and is subject to change based on the evolution of our business model, interpretations of relevant accounting principles, enforcement of existing or new regulations, and changes in SEC or other agency policies, rules, regulations, and interpretations of accounting regulations. Changes to our business model and accounting methods, principles, or interpretations could result in changes to our consolidated financial statements, including changes in revenue and expenses in any period, or in certain categories of revenue and expenses moving to different periods, may result in materially different financial results, and may require that we change how we process, analyze, and report financial information and our financial reporting controls.
Accounting & Financial Operations - Risk 5
If our estimates or judgments relating to our critical accounting policies prove to be incorrect, our results of operations could be adversely affected.
The preparation of financial statements in conformity with GAAP requires management to make estimates and assumptions that affect the reported amounts of assets and liabilities, the disclosure of contingent assets and liabilities at the date of our consolidated financial statements, and the reported amounts of expenses during the reporting periods. We base our estimates on historical experience, known trends and other market-specific or other relevant factors that we believe to be reasonable under the circumstances, as provided in the section titled "Management's Discussion and Analysis of Financial Condition and Results of Operations-Critical Accounting Policies and Estimates." The results of these estimates form the basis for making judgments about the carrying values of assets, liabilities, and equity, and the amount of revenue and expenses. Significant estimates and judgments involve revenue recognition, valuation of goodwill and intangible assets, stock-based compensation and income taxes. Our results of operations may be adversely affected if our assumptions change or if actual circumstances differ from those in our assumptions, which could cause our results of operations to fall below the expectations of securities analysts and investors, resulting in a decline in the market price of our common stock.
Accounting & Financial Operations - Risk 6
We expect fluctuations in our quarterly operating results, making it difficult to project future results, and if we fail to meet the expectations of securities analysts or investors with respect to our operating results, the market price of our common stock could decline.
Our rapid growth makes it difficult for us to forecast our future operating results. Our quarterly operating results have fluctuated in the past and are expected to fluctuate in the future due to a variety of factors, many of which are outside of our control. As a result, our past results may not be indicative of our future performance.
In addition to the other risks described herein, factors that may affect our operating results include the following:
- fluctuations in demand for our solutions;- our ability to attract new customers and retain and increase adoption by our existing customers;- our ability to expand our relationships with our partners and identify and attract new partners;- changes in payment method preferences and channels by clients, which may affect our revenue, particularly as a result of interchange fees and other related transaction processing fees;- variations across the industries of our customers, which may affect payment methods used by clients and average payment amounts and, in turn, our revenue, particularly as a result of interchange fees and other related transaction processing fees;- the continued impact of the COVID-19 pandemic on our operating results, liquidity and financial condition and on our employees, customers, partners, clients and other key stakeholders;- changes in customer preference for cloud-based services as a result of security breaches in the industry or privacy concerns, or other security or reliability concerns regarding our products;- fluctuations or delays in purchasing decisions in anticipation of new products or product enhancements by us or our competitors;- changes in customer and client budgets and in the timing of their budget and billing cycles and purchasing decisions;- changes in the implementation timeline of our solutions with new customers;- potential and existing customers choosing our competitors' products or developing their own solutions in-house;- the development or introduction of new solutions that are easier to use or more advanced than our current solutions;- our ability to adapt to new forms of payment that become widely accepted, including cryptocurrencies;- the adoption or retention of more entrenched or rival services in the markets where we compete or plan to compete;- our ability to control costs, including our operating expenses;- the amount and timing of payment for operating expenses, particularly research and development and sales and marketing expenses, including commissions;- the amount and timing of non-cash expenses, including stock-based compensation, goodwill impairments and other non-cash charges;- the amount and timing of costs associated with recruiting, training and integrating new employees, and retaining and motivating existing employees;- the effects of acquisitions and their integration;- the effects of dispositions of solutions and other assets;- general economic conditions (including inflation), both domestically and internationally, as well as economic conditions specifically affecting industries in which our customers operate;- the impact of new accounting pronouncements;- changes in the competitive dynamics of our markets;- security breaches of, technical difficulties with, or interruptions to, the delivery and use of our solutions from our payment vendors, technology vendors, and/or our own developed technology; and - awareness of our brand and our reputation in our target markets.
Any of these and other factors, or the cumulative effect of some of these factors, may cause our operating results to vary significantly. In addition, we expect to incur significant additional expenses due to the increased costs of operating as a public company. If the assumptions used to plan our business are incorrect, our revenue may fail to meet our expectations and we may fail to meet profitability expectations. Further, if our quarterly operating results fall below the expectations of investors and securities analysts who follow our common stock, the price of our common stock could decline substantially, and we could face costly lawsuits, including securities class action lawsuits.
Accounting & Financial Operations - Risk 7
We have a history of losses, anticipate increasing our operating expenses in the future, and may not be able to sustain profitability.
We incurred operating losses in the past, including in the years ended December 31, 2021 and December 31, 2020. Our operating expenses may increase substantially in the foreseeable future as we continue to expend financial resources to grow our business, including to build new products and add features and functionality to existing products; expand our sales force and marketing to win new customers; expand into new verticals; pursue strategic acquisitions or strategic investments; improve our technology infrastructure, including systems architecture, scalability, availability, performance and network security; comply with laws and regulations; and invest in general administration, including increased legal and accounting expenses associated with being a public company. The increased costs associated with these and other investments we may make in our business may fail to generate the expected benefits. If we are unable to increase our revenue at a rate sufficient to offset the expected increase in our costs, our business, operating results, and financial condition will be harmed, and we may not be able to sustain profitability in the near term or over the long term.
Debt & Financing3 | 3.8%
Debt & Financing - Risk 1
Restrictions imposed by our indebtedness may materially limit our ability to operate our business and finance our future operations or capital needs.
The terms of our 2021 Revolving Credit Facility restrict us and our restricted subsidiaries from engaging in specified types of transactions. These covenants restrict our ability, and that of our restricted subsidiaries, to, among other things:
- incur indebtedness;- incur certain liens;- make investments, loans, advances, guarantees and acquisitions;- pay dividends or make other distributions on equity interests, or redeem, repurchase or retire equity interests;- consolidate, merge or sell or otherwise dispose of assets;- enter into transactions with affiliates;- enter into sale and leaseback transactions;- alter the business conducted by us and our subsidiaries;- amend or modify governing documents and certain other documents; and - change their fiscal year.
A breach of any of these covenants, or any other covenant in the documents governing our 2021 Revolving Credit Facility, could result in a default or event of default under our 2021 Revolving Credit Facility. In the event of any event of default under our 2021 Revolving Credit Facility, the applicable lenders or agents could elect to terminate borrowing commitments and declare all borrowings and loans outstanding thereunder, together with accrued and unpaid interest and any fees and other obligations, to be immediately due and payable. In addition, or in the alternative, the applicable lenders or agents could exercise their rights under the security documents entered into in connection with our 2021 Revolving Credit Facility. We have pledged substantially all of our assets as collateral securing our 2021 Revolving Credit Facility and any such exercise of remedies on any material portion of such collateral would likely materially adversely affect our business, financial condition or results of operations.
If we were unable to repay or otherwise refinance these borrowings and loans when due, and the applicable lenders proceeded against the collateral granted to them to secure that indebtedness, we may be forced into bankruptcy or liquidation. In the event that the applicable lenders accelerate the repayment of our borrowings, we may not have sufficient assets to repay that indebtedness. Any acceleration of amounts due under our 2021 Revolving Credit Facility or other outstanding indebtedness would also likely have a material adverse effect on us.
Our 2021 Revolving Credit Facility requires us to maintain a maximum total net leverage ratio. Our ability to borrow under our Credit Facilities depends on our compliance with these financial covenants. Events beyond our control, including changes in general economic and business conditions, may affect our ability to satisfy the financial covenant. We cannot assure you that we will satisfy the financial covenant in the future, or that our lenders will waive any failure to satisfy the financial covenant.
Debt & Financing - Risk 2
Our ability to raise capital in the future may be limited.
Our business and operations may consume resources faster than we anticipate. In the future, we may need to raise additional funds through the issuance of new equity securities, debt or a combination of both. Additional financing may not be available on favorable terms or at all. If adequate funds are not available on acceptable terms, we may be unable to fund our capital requirements. If we issue new debt securities, the debt holders would have rights senior to holders of our common stock to make claims on our assets and the terms of any debt could restrict our operations, including our ability to pay dividends on our common stock. If we issue additional equity securities or securities convertible into equity securities, existing stockholders will experience dilution and the new equity securities could have rights senior to those of our common stock. Because our decision to issue securities in any future offering will depend on market conditions and other factors beyond our control, we cannot predict or estimate the amount, timing or nature of our future offerings. Thus, you bear the risk of our future securities offerings reducing the market price of our common stock and diluting their interest.
Debt & Financing - Risk 3
Our debt obligations contain restrictions that impact our business and expose us to risks that could materially adversely affect our liquidity and financial condition.
As of December 31, 2022, we had no outstanding indebtedness. We may incur additional indebtedness in the future, including borrowings under our senior secured revolving credit facility with commitments in an aggregate principal amount of $75.0 million (the "2021 Revolving Credit Facility"). Our indebtedness could have significant effects on our business, such as:
- limiting our ability to borrow additional amounts to fund capital expenditures, acquisitions, debt service requirements, execution of our growth strategy and other purposes;- limiting our ability to make investments, including acquisitions, loans and advances, and to sell, transfer or otherwise dispose of assets;- requiring us to dedicate a substantial portion of our cash flow from operations to pay principal and interest on our borrowings, which would reduce availability of our cash flow to fund working capital, capital expenditures, acquisitions, execution of our growth strategy and other general corporate purposes;- making us more vulnerable to adverse changes in general economic, industry and competitive conditions, in government regulation and in our business by limiting our ability to plan for and react to changing conditions;- placing us at a competitive disadvantage compared with our competitors that have less debt; and - exposing us to risks inherent in interest rate fluctuations because our borrowings are at variable rates of interest, which could result in higher interest expense in the event of increases in interest rates.
In addition, if we incur debt, we may not be able to generate sufficient cash flow from our operations to repay our indebtedness when it becomes due and to meet our other cash needs. If we are not able to pay our borrowings as they become due, we will be required to pursue one or more alternative strategies, such as selling assets, refinancing or restructuring our indebtedness or selling additional debt or equity securities. We may not be able to refinance our debt or sell additional debt or equity securities or our assets on favorable terms, if at all, and if we must sell our assets, it may negatively affect our business, financial condition, and results of operations.
Corporate Activity and Growth7 | 9.0%
Corporate Activity and Growth - Risk 1
We incur, and expect to continue to incur, significant costs and devote substantial resources and management time as a result of operating as a public company, particularly after we are no longer an "emerging growth company." In addition, the requirements of being a public company may affect our ability to attract and retain executive management and qualified board members.
As a public company, we are subject to the reporting requirements of the Exchange Act, the Sarbanes-Oxley Act, the Dodd-Frank Act, as well as rules and regulations subsequently implemented by the SEC, and the NYSE, our stock exchange, including the establishment and maintenance of effective disclosure and financial controls and changes in corporate governance practices. For example, the Exchange Act requires, among other things, that we file annual, quarterly, and current reports with respect to our business and results of operations. In addition, the rules governing management's assessment of our internal control over financial reporting are complex and require significant documentation, testing and possible remediation. Compliance with these requirements has increased our legal and financial compliance costs and made some activities more time consuming and costly. In addition, our management and other personnel need to divert attention from operational and other business matters to devote substantial time to these public company requirements. In particular, we expect to continue incurring significant expenses and devote substantial management effort toward ensuring compliance with the requirements of the Sarbanes-Oxley Act. Although we have already hired additional employees to assist us in complying with these requirements, we may need to hire additional accounting and financial staff with appropriate public company experience and technical accounting knowledge, which will increase our operating expenses. In addition, changing laws, regulations, and standards relating to corporate governance and public disclosure create uncertainty for public companies, increasing legal and financial compliance costs, and making some activities more time-consuming. Furthermore, these rules and regulations require us to incur legal and financial compliance costs and make some activities more time-consuming and costly. For example, these rules and regulations make it more difficult and more expensive for us to obtain director and officer liability insurance, and we may be required to accept reduced policy limits and coverage or incur substantially higher costs to obtain the same or similar coverage. As a result, it may be more difficult for us to attract and retain qualified people to serve on our board of directors, our board committees or as executive officers.
Once we cease to be an "emerging growth company," we will not be entitled to the exemptions provided in the JOBS Act. After we are no longer an "emerging growth company," we expect to incur additional management time and cost to comply with the more stringent reporting requirements applicable to companies that are deemed accelerated filers or large accelerated filers, including complying with the auditor attestation requirements of Section 404 of the Sarbanes-Oxley Act. Although the material weaknesses that we previously disclosed have been remediated as of December 31, 2022, there can be no assurance that we will not identify additional material weaknesses in the future. If we identify material weaknesses in the future and are unable to comply with the requirements of Section 404 in a timely manner or assert that our internal control over financial reporting is effective, or if our independent registered public accounting firm is unable to express an opinion as to the effectiveness of our internal control over financial reporting once we are no longer an emerging growth company, investors may lose confidence in the accuracy and completeness of our financial reports and the market price of our common stock could be negatively affected, and we could become subject to investigations by the stock exchange on which our securities are listed, the SEC or other regulatory authorities, which could require additional financial and management resources. Moreover, we cannot predict or estimate the amount of additional costs we may incur as a result of operating as a public company or the timing of such costs.
Corporate Activity and Growth - Risk 2
If we are unsuccessful in establishing, growing or maintaining strategic partnerships, our ability to compete could be impaired, and our operating results may suffer.
We rely on integration of our various solutions into third-party software products, including customer information systems, enterprise risk management systems and accounting systems, which enables us to power such software products' capabilities. We also rely on strategic partnerships to refer new customers to our solutions in our Enterprise Solutions segment, where we rely on a few strategic partners to help us generate a significant portion of the revenue for certain of our solutions. Although our relationships with strategic partners are independent of one another, if our reputation in the industries in which we operate were to suffer, or if we were unable to establish relationships with new strategic partners and grow our relationships with existing strategic partners, our growth prospects would weaken and our business, financial position, and operating results may be adversely affected. In addition, we have revenue sharing arrangements with certain of our strategic partners. If our strategic partners request a greater percentage of revenue from their referrals, our operating results will be adversely impacted.
To grow our business, we have expanded and will continue to seek to expand our existing relationships and establish additional relationships with our partners. Establishing such relationships, particularly with core system providers and other large enterprises, entails extensive sales and marketing efforts with no guarantee of success. Sales and marketing to large organizations involve risks that may not be present, or that are present to a lesser extent, with sales and marketing to other, smaller organizations. We must invest significant time educating and selling to multiple management and technical decision-makers to obtain their support. In addition, we may be required to meet wide-ranging and detailed ancillary requirements. For example, insurance and consumer finance organizations generally require us to submit to an exhaustive security audit, given the sensitivity and importance of storing customer billing and payment data on our solutions. Adoption is also frequently subject to budget constraints and unplanned administrative, processing and other delays, including considerable efforts to negotiate and document relationships. Further, deployment of solutions and integration with partners' software requires significant effort. If we are unable to increase adoption of our solutions by partners and manage the costs associated with marketing our solutions to potential partners and integrating with their systems, our business, operating results and financial condition may be adversely affected. In addition, if we are unsuccessful in establishing, growing or maintaining partnerships, our ability to compete could be impaired, and our operating results may suffer. If we lost one or more of our largest partnerships, we could also lose associated customer relationships or payment channels and our business, operating results and financial condition could be harmed.
Corporate Activity and Growth - Risk 3
If we cannot maintain our company culture as we grow, our success and our business and competitive position may be harmed.
Engaged employees are imperative to achieving excellent customer service and strong company performance. We strive to hire exceptionally talented people who embrace our culture because it is critical to our success. Any failure to preserve our culture could negatively affect our ability to retain and recruit personnel, which is critical to our growth, and to effectively focus on and pursue our corporate objectives. As we grow and develop the infrastructure of a public company, we may find it difficult to maintain these important aspects of our culture. If we fail to maintain our company culture, our business and competitive position may be harmed.
Corporate Activity and Growth - Risk 4
We might not implement our growth strategies successfully which would limit our growth and cause our stock price to decline.
Our future profitability will depend, in part, on our ability to implement successfully our growth strategies. We expect to invest substantial amounts to:
- build new products and add features and functionality to existing products;- grow our salesforce and marketing to win new customers;- expand relationships with our existing customers;- expand into new verticals;- pursue strategic acquisitions or strategic investments;- improve our technology infrastructure, including systems architecture, scalability, availability, performance and network security;- comply with regulatory requirements and risk management; and - expand into new channels, verticals and markets.
Our investment in these programs could adversely affect our short-term profitability. Additionally, we may fail to successfully implement these programs or to increase substantially adoption of our electronic payment method by customers who pay for the service. This would impact revenues adversely and cause our business to suffer.
Corporate Activity and Growth - Risk 5
We have in the past and may in the future acquire or invest in companies, which may divert our management's attention and result in additional dilution to our stockholders. We may be unable to integrate acquired businesses and technologies successfully or achieve the expected benefits of such acquisitions.
Our success will depend, in part, on our ability to grow our business in response to changing technologies, customer demands and competitive pressures. In some circumstances, we may choose to do so through the acquisition of businesses and technologies rather than through internal development. The identification of suitable acquisition candidates can be difficult, time-consuming and costly, and we may not be able to successfully complete identified acquisitions. The risks we face in connection with acquisitions include:
- an acquisition may negatively affect our results of operations because it may require us to incur charges or assume substantial debt or other liabilities, may cause adverse tax consequences or unfavorable accounting treatment, may expose us to claims and disputes by stockholders and third parties, including intellectual property claims and disputes, or may not generate sufficient financial return to offset additional costs and expenses related to the acquisition;- we may encounter difficulties or unforeseen expenditures in integrating the business, technologies, products, personnel or operations of any company that we acquire, particularly if key personnel of the acquired company decide not to work for us;- we may not be able to realize anticipated synergies;- an acquisition may disrupt our ongoing business, divert resources, increase our expenses, and distract our management;- we may encounter challenges integrating the employees of the acquired company into our company culture;- we may encounter difficulties in, or may be unable to, successfully sell any acquired products;- our use of cash to pay for acquisitions would limit other potential uses for our cash;- if we incur debt to fund any acquisitions, such debt may subject us to material restrictions on our ability to conduct our business financial maintenance covenants; and - if we issue a significant amount of equity securities in connection with future acquisitions, existing stockholders may be diluted and earnings per share may decrease.
The occurrence of any of these risks could have an adverse effect on our business, results of operations and financial condition.
In addition, we face a variety of tax risks related to acquisitions, including that we may be required to make tax withholdings in various jurisdictions in connection with such transactions or as part of our continuing operations following a transaction, and that the companies or businesses we acquire may cause us to alter our international tax structure or otherwise create more complexity with respect to tax matters. Additionally, while we typically include indemnification provisions in our definitive agreements related to acquisitions and other strategic transactions, these indemnification provisions may be insufficient in the event that tax liabilities are greater than expected or in areas that are not fully covered by indemnification. If we are unable to adequately predict and address such tax issues as they arise, our business, financial condition, and results of operations could be adversely affected.
Corporate Activity and Growth - Risk 6
Our risk management efforts may not be effective to prevent fraudulent activities, which could expose us to material financial losses and liability and otherwise harm our business.
We offer solutions that, among other things, automate the entire bill payment lifecycle, providing electronic bill presentment, client engagement, and payment processing for a large number of customers and clients. For some of our solutions, we share in the responsibility of verifying the identity of our customers and monitoring transactions for fraud. We and our customers have been in the past and will continue to be targeted by parties who seek to commit acts of financial fraud using techniques such as stolen identities and bank accounts, compromised business email accounts, employee or insider fraud, account takeover, false applications, and check fraud. We have in the past, and may in the future, suffer losses from acts of financial fraud committed by or against our customers, partners, clients, employees, or other third-parties.
The techniques used to attempt to perpetrate fraud through our solutions are continually evolving, and we expend considerable resources to continue to monitor and combat them. In addition, when we introduce new products and functionality, or expand existing products, we may not be able to identify all risks created by the new products or functionality. Our risk management policies, procedures, techniques, and processes may not be sufficient to identify all of the risks to which we are exposed, to enable us to prevent or mitigate the risks we have identified, or to identify additional risks to which we may become subject in the future. Furthermore, our risk management policies, procedures, techniques, and processes may contain errors, or our employees or agents may commit mistakes or errors in judgment, as a result of which we may suffer large financial losses. The software-driven and highly automated nature of our solutions could enable criminals and those committing fraud to cause significant losses to our business. As greater numbers of customers, partners, and clients use our solutions, our exposure to the risk of losses from a single user, or from a small number of users, will increase.
Our current business and anticipated growth will continue to place significant demands on our risk management efforts, and we will need to continue developing and improving our existing risk management infrastructure, policies, procedures, techniques, and processes. As techniques used to perpetrate fraud evolve, we may need to modify our solutions to mitigate fraud risks. As our business grows and becomes more complex, we may be less able to forecast and carry appropriate reserves on our books for fraud related losses. Further, these types of fraudulent activities on our solutions can also expose us to civil and criminal liability and governmental and regulatory sanctions as well as potentially cause us to be in breach of our contractual obligations to our third-party partners.
Corporate Activity and Growth - Risk 7
Our rapid growth may not be sustainable or indicative of our future growth.
Our recent rapid growth may not be sustainable or indicative of our future growth. Even though the number of customers who use our solutions has grown rapidly in recent years, there can be no assurance that we will be able to attract new customers or retain existing customers. Our ability to attract new customers, retain revenue from existing customers, or increase adoption of our solutions by both new and existing customers is impacted by a number of factors, including:
- our fees and certain of our customers' ability to pass them on to clients;- our ability to timely expand the functionality and scope of our solutions;- our ability to maintain the rates at which our customers pay us and continue to use our solutions;- competitive factors, including the introduction of competing solutions, discount pricing and other strategies that may be implemented by our competitors;- for SimplePractice, our ability to continue to offer free trials at reasonable costs to us that attracts customers to our paid solution;- our ability to recruit, retain and develop the talent needed to continue to grow the business;- our ability to gain the domain knowledge in selected vertical markets needed to appropriately influence product and service roadmaps;- our ability to establish and/or maintain product leadership and growth in our vertical solutions;- our ability to establish and/or maintain efficient go to market strategies;- our ability to gain and synthesize the customer feedback needed to appropriately influence product and service roadmaps;- our ability to translate customer needs into working solutions that deliver enough value for customers to keep or select our solutions over competing providers;- our ability to make timely delivery of solutions to customers;- our ability to adequately train customers to use our solutions and enhancements to our solutions when available;- our ability to maintain high-quality customer support for customers and clients;- our ability to attract and retain strategic partners;- our ability to expand into new industries and market segments;- actual or perceived privacy or security breaches;- the frequency and severity of any system outages, technological changes, or similar issues;- the impact of COVID-19;- our ability to successfully identify, acquire and integrate, or invest in businesses, products, or technologies that we believe could complement or expand our solutions;- our ability to increase awareness of our brands and successfully compete with other companies; and - our focus on long-term value over short-term results, meaning that we may make strategic decisions that may not maximize our short-term revenue or profitability if we believe that the decisions are consistent with our mission and will improve our financial performance over the long-term.
Tech & Innovation
Total Risks: 19/78 (24%)Above Sector Average
Innovation / R&D3 | 3.8%
Innovation / R&D - Risk 1
If we fail to adapt and respond effectively to rapidly changing technology, evolving industry standards and regulations, and changing business needs, requirements, or preferences, our products may become less competitive, and our growth rate could decline.
The market for our solutions is relatively new and subject to ongoing technological change, evolving industry standards and payment methods, shifting laws and regulations, and changing customer and client needs, requirements, and preferences. The success of our business will depend, in part, on our ability to adapt and respond effectively to these changes on a timely basis, including launching new solutions. The success of any new solutions, or any enhancements or modifications to existing solutions, depends on several factors, including the timely completion, introduction, and market acceptance of such solutions, enhancements, and modifications. If we are unable to enhance our solutions or develop new solutions that keep pace with technological and regulatory change and achieve market acceptance, or if new technologies emerge that are able to deliver competitive solutions at lower prices, more efficiently, more conveniently or more securely than our products, our business, operating results and financial condition would be adversely affected. Moreover, we may experience delays in the development and introduction of new solutions due to the effects of the COVID-19 pandemic. Furthermore, modifications to our existing solutions or technology will increase our research and development expenses. Any of the foregoing could reduce the demand for our services, result in customer, partner and client dissatisfaction and adversely affect our business.
Innovation / R&D - Risk 2
If we are not able to introduce new features or services successfully and to make enhancements to our solutions, our business and results of operations could be adversely affected.
Our ability to attract new customers and increase revenue from existing customers depends in part on our ability to enhance and improve our solutions and to introduce new features and services. To grow our business and remain competitive, we must continue to enhance our solutions and develop features that reflect the constantly evolving nature of technology and our customers' needs. The success of SimplePractice, InvoiceCloud, and any other solutions, products, enhancements, or developments depends on several factors: our anticipation of market changes, demands, and product features, including timely product introduction and conclusion, sufficient customer demand, cost effectiveness in our product development efforts and the proliferation of new technologies that are able to deliver competitive offerings at lower prices, more efficiently, more conveniently or more securely. In addition, because our solutions are designed to operate with a variety of systems, applications, data, and devices, we will need to continuously modify and enhance our solutions to keep pace with changes and updates in such systems. We may not be successful in developing these modifications and enhancements. Furthermore, the addition of features to our solutions will increase our research and development expenses. Any new features that we develop may not be introduced in a timely or cost-effective manner or may not achieve the market acceptance necessary to generate sufficient revenue to justify the related expenses. It is difficult to predict customer adoption of new features. Such uncertainty limits our ability to forecast our future results of operations and subjects us to several challenges, including our ability to plan for and model future growth. If we cannot address such uncertainties and successfully develop new features, enhance our solutions, or otherwise overcome technological challenges and competing technologies, our business and results of operations could be adversely affected.
We also offer certain additional services such as integration and training. If we cannot introduce new solutions or enhance our existing solutions to keep pace with changes in our customers' deployment strategies, we may not be able to attract new customers, retain existing customers, and expand their use of our software or secure renewal contracts, which are important for the future of our business.
Innovation / R&D - Risk 3
The market for our solutions may develop more slowly or differently than we expect.
It is difficult to predict customer adoption rates and demand for our products, the entry of competitive products or the future growth rate and size of the cloud-based software and SaaS business software markets. The expansion of these markets depends on a number of factors, including: the cost, performance, and perceived value associated with cloud-based and SaaS business software as an alternative to legacy systems, as well as the ability of cloud-based software and SaaS providers to address heightened data security and privacy concerns. If we have a security incident or other cloud-based software and SaaS providers experience security incidents, loss of customer data, disruptions in delivery or other similar problems, which is an increasing focus of the public and investors in recent years, the market for these applications as a whole, including our solutions, may be negatively affected. If cloud-based and SaaS business software does not continue to achieve market acceptance, or there is a reduction in demand caused by a lack of customer acceptance, technological challenges, weakening economic conditions, data security or privacy concerns, governmental regulation, competing technologies and products, or decreases in information technology spending or otherwise, the market for our solutions might not continue to develop or might develop more slowly than we expect, which would adversely affect our business, financial condition, and results of operations.
Trade Secrets4 | 5.1%
Trade Secrets - Risk 1
Indemnity provisions in various agreements to which we are party potentially expose us to substantial liability for infringement, misappropriation or other violation of intellectual property rights, data protection and other losses.
In the normal course of business, we may provide indemnification of varying scope and terms to third parties and may enter into commitments and guarantees under which we may be required to make payments. The duration of these agreements varies, and in certain cases, may be indefinite with no limit to our maximum potential payment exposure. Large payments under these agreements could harm our business, financial condition, and results of operations. In addition, although we carry general liability insurance, our insurance may not be adequate to indemnify us for all liability that may be imposed or otherwise protect us from liabilities or damages with respect to claims alleging compromises of customer data, and any such coverage may not continue to be available to us on acceptable terms or at all.
Trade Secrets - Risk 2
Our business depends in part on intellectual property and proprietary rights and technology licensed from or otherwise made available to us by third parties.
Some of our business relies on key technologies developed or licensed by third parties. These third-party software components may become obsolete, defective or incompatible with future versions of our services, relationships with the third-party licensors or technology providers may deteriorate, or our agreements with the third-party licensors or technology providers may expire or be terminated. Additionally, these licensed technologies and software may not be available to us in the future on terms that are acceptable, or at all, or that allow our solutions to remain competitive. Our inability to obtain licenses on favorable terms could have a material and adverse effect on our business and results of operations. Furthermore, incorporating intellectual property or technology licensed from third parties on a non-exclusive basis in our solutions could result in competitors licensing the same intellectual property or technology in order to provide similar solutions to ours.
Trade Secrets - Risk 3
We may in the future become subject to claims of intellectual property infringement or other intellectual property disputes, which are costly and time-consuming to defend against or pursue, and may subject us to significant liability and increased costs of doing business.
We may in the future become subject to and involved in lawsuits, disputes, legal proceedings or claims by third parties that we have infringed, misappropriated or otherwise violated their intellectual property. Even if we believe that particular intellectual property-related claims are without merit, litigation may be necessary to defend against these allegations. The ultimate outcome of any allegation is often uncertain and, regardless of the outcome, lawsuits, with or without merit, are time-consuming and expensive to resolve and they divert management's time and attention and require us to, among other things, redesign or stop providing our solutions, pay substantial amounts to satisfy judgments or settle claims or lawsuits, pay substantial royalty or licensing fees, or satisfy indemnification obligations that we have with certain parties with whom we have commercial relationships. Although we carry insurance, our insurance may not cover potential claims of this type or may not be adequate to indemnify us for all liability that may be imposed. We cannot predict the outcome of lawsuits and cannot assure you that the results of any such actions will not have an adverse effect on our business, operating results or financial condition.
Companies in the software and technology industries, including some of our current and potential competitors, own significant numbers of patents, copyrights, trademarks and trade secrets and frequently enter into litigation based on allegations of infringement or other violations of intellectual property rights. In addition, many of these companies have the capability to dedicate greater resources than we can to enforce their intellectual property rights and to defend claims that may be brought against them. We cannot guarantee that our intellectual property rights will be able to withstand all third-party challenges. There is also a risk that the litigation may also involve patent holding companies or other adverse patent owners that have no relevant product revenue, and therefore, our patents may provide little or no deterrence as we would not be able to assert them against such entities or individuals. If a third party is able to obtain an injunction preventing us from practicing such third party's intellectual property rights, or if we cannot license or develop alternative technology for any infringing aspect of our business, we would be forced to limit or stop sales of our products or cease business activities that infringe such intellectual property. Any inability to license third-party technology in the future would have an adverse effect on our business or operating results and would adversely affect our ability to compete. We could also face trademark infringement claims brought by owners of other registered or unregistered trademarks that are similar to ours. Any such claims could damage our reputation, force us to rebrand and could adversely affect our growth prospects.
We also are, and may in the future become, contractually obligated to indemnify our customers and partners in the event of infringement, misappropriation or other violation of a third party's intellectual property rights. Responding to such claims, regardless of their merit, can be time-consuming, costly to defend and damaging to our reputation and brand.
Trade Secrets - Risk 4
If we fail to adequately obtain, maintain, protect or enforce our intellectual property and proprietary rights, our competitive position could be impaired, our reputation could be harmed and we may lose valuable assets, generate less revenue and incur costly litigation to protect our rights.
Our success is dependent, in part, upon protecting our intellectual property and proprietary technology. We rely on a combination of patent, copyright, trademark and trade secret laws, as well as contractual provisions with our employees, independent contractors, consultants and third parties with whom we have relationships to establish and protect our intellectual property and proprietary rights. However, the steps we take to protect our intellectual property may be inadequate, may not afford complete protection and may not adequately permit us to gain or keep any competitive advantage. Further, despite our efforts to obtain and maintain intellectual property rights, we cannot guarantee that we will be able to prevent unauthorized use or disclosure of our confidential information, intellectual property or technology, and we may not have adequate remedies in the event of unauthorized use or disclosure of our confidential information, intellectual property or technology.
Various factors outside our control pose a threat to our intellectual property rights, as well as to our products, services and technologies. Although we have been issued patents in the United States and have additional patent applications pending, we may be unable to obtain patent protection for the technology covered in our patent applications or obtain the coverage originally sought. In addition, our existing patents, as well as the patents we obtain in the future may not provide us with competitive advantages or may be successfully challenged by third parties, which could result in them being narrowed in scope or declared invalid or unenforceable. For example, it is possible that third parties, including our competitors, may obtain patents relating to technologies that overlap or compete with our technology. If third parties obtain patent protection with respect to such technologies, they may assert that our technology infringes their patents and seek to charge us a licensing fee or otherwise preclude the use of our technology or file suit against us. We also may allow certain of our registered intellectual property rights, or our pending applications for intellectual property rights, to lapse or to become abandoned if we determine that obtaining or maintaining the applicable registered intellectual property rights is not worthwhile. Despite our efforts to protect our intellectual property and proprietary rights, there can be no guarantee that such rights will be sufficient to protect against others offering products or services that are substantially similar to ours, to prevent them from independently developing similar products, designing around our patents, adopting trade names or domain names similar to ours, or attempting to copy aspects of our technology and using information that we consider proprietary to compete with us, thereby impeding our ability to promote our solutions and possibly leading to customer or client confusion.
Despite our efforts to protect our proprietary rights, unauthorized parties may attempt to copy, reverse engineer or otherwise obtain and use our technology, systems, methods, processes, intellectual property and other information that we regard as proprietary to create solutions that compete with ours. Policing unauthorized use of intellectual property and technology can be expensive and time consuming, and regardless of what measures we take, we cannot guarantee that we will be able to detect unauthorized uses. Even if we detect unauthorized uses, we cannot be certain that we will be able to successfully enforce our intellectual property, particularly in foreign countries where the laws may not protect our proprietary rights as comprehensively as in the United States. Litigation may be necessary to enforce our intellectual property rights, to protect our trade secrets or to determine the validity and scope of the proprietary rights of others, which could result in substantial costs and diversion of our resources. Further, our enforcement efforts may be met with defenses and counterclaims challenging the validity and enforceability of our intellectual property rights and may result in a court determining that our intellectual property is invalid or unenforceable. Any changes in, or unexpected interpretations of, intellectual property laws may also compromise our ability to enforce our intellectual property rights. Failure to obtain or maintain protection of our trade secrets or other proprietary information could harm our competitive position and materially and adversely affect our business, operating results and financial condition.
In addition, while we rely in part on confidentiality and intellectual property assignment agreements with our employees and contractors involved in the development of material intellectual property for us, which place restrictions on the employees' and contractors' use and disclosure of this intellectual property, these assignments in these agreements may not be self-executing, and the confidentiality provisions may not be sufficient in scope, may be unenforceable, or may otherwise not provide meaningful protection for our trade secrets or other proprietary information in the event of unauthorized use or disclosure or other breaches of the agreements. We cannot guarantee that we have entered into such agreements with each person or entity that may have or have had access to our trade secrets or proprietary information or otherwise developed intellectual property or technology for us. Individuals who were involved in the development of intellectual property for us or who had access to our intellectual property but who are not subject to these agreements may make adverse ownership claims to our current and future intellectual property. Further, these agreements may be breached, and as a result, our trade secrets and other proprietary information may be disclosed or become known to our competitors, which could cause us to lose any competitive advantage, and we may not have adequate remedies for such breaches. Additionally, to the extent that our employees, independent contractors or other third parties with whom we do business use intellectual property owned by others in their work for us, disputes may arise as to the rights in related or resulting works of authorship, know-how and inventions. The loss of trade secret protection could make it easier for third parties to compete with our solutions by copying their functionality.
Obtaining and maintaining effective patent, copyright, trademark, service mark, trade secret and domain name protection is time-consuming and expensive. Accordingly, we do not and may not own registered trademarks for all trademarks and logos used in our business in all of the jurisdictions in which we operate or may operate in the future. We may also choose not to seek patent protection for all patentable inventions, and we have chosen not to seek the registration of copyrights in our software solutions. Further, we have and may in the future employ individuals who previously were employed by our competitors, and, as a result, those competitors may bring claims against such individuals or us alleging their intellectual property rights have been infringed, misappropriated or otherwise violated.
Technology12 | 15.4%
Technology - Risk 1
We use open-source software in our solutions, which may pose particular risks to our proprietary software in a manner that could subject us to litigation or other actions, negatively affect our ability to sell our products or otherwise adversely affect our business, operating results and financial condition.
Our solutions incorporate software modules licensed to us by third-party authors under "open-source" licenses, and we expect to continue to incorporate open-source software in our solutions in the future. Some open-source licenses have so called "copy-left" provisions, which may require those who distribute open-source software as part of their own software product to provide the source code to their software to licensees and permit the licensees to make derivative works, may prohibit charging fees to licensees in connection with the licensing of the software product, and may also impose attribution requirements.
While we try to use open-source code in a manner that we believe does not subject our proprietary solutions to copy-left provisions, the terms of many open-source licenses to which we are subject have not been interpreted by U.S. or foreign courts, and there is a risk that these licenses could be construed in a way that could impose unanticipated conditions or restrictions on our ability to provide, or distribute our solutions related to, the open-source software subject to those licenses. In addition, the public availability of such software may make it easier for others to compromise our solutions, and licensors of open-source software generally do not provide warranties and limit their liability to the fullest extent permitted. Accordingly, we may not have any recourse against the open-source licensors if our solutions are compromised or we incur other problems due to an issue with the open-source software. Although we generally monitor our use of open-source software to avoid subjecting our solutions to conditions we do not intend and to try to ensure that none is used in a manner that would require us to disclose our proprietary source code or that would otherwise breach the terms of an open-source agreement, such use could inadvertently occur, or could be claimed to have occurred. Moreover, we cannot assure you that our processes for controlling our use of open-source software in our solutions will be effective. From time to time, there have been claims challenging the ownership of open-source software against companies that incorporate it into their products. Likewise, we could become subject to lawsuits and face claims from third parties claiming ownership of, or demanding release of, any open-source software or derivative works that we have developed using such software, which could include our proprietary source code, or otherwise seeking to enforce the terms of the applicable open-source license. These claims could result in litigation and could require us to make our software source code freely available, purchase a costly license or cease offering the implicated solutions. Litigation could be costly for us to defend, have a negative effect on our business, operating results and financial condition or require us to devote additional research and development resources to change our products. If we are held to have breached or failed to fully comply with all the terms and conditions of an open-source software license, we could face infringement or other liability, or be required to seek costly licenses from third parties, to continue providing our offerings on terms that are not economically feasible, to re-engineer our solutions (which could involve substantial time and resources), to discontinue or delay the provision of our offerings if re-engineering could not be accomplished on a timely basis or to make generally available, in source code form, our proprietary code, any of which could adversely affect our business, operating results and financial condition.
In addition to risks related to complying with applicable license requirements, a release of our proprietary code could also allow our competitors to create similar offerings with lower development effort and time and ultimately could result in a loss of our competitive advantages. Furthermore, use and distribution of open-source software may entail greater risks than use of third-party commercial software, as opensource licensors generally do not provide support, warranties, indemnification or other contractual protections regarding infringement claims or the quality of the code.
Technology - Risk 2
We may experience software and technology defects, undetected errors, development delays or other performance problems in our software and other technology used as part of our solutions, which could damage customer and partner relations, harm our reputation, result in significant costs to us, decrease our potential profitability and expose us to substantial liability.
Our software and other technology used as part of our solutions may contain undetected errors, viruses or defects when implemented or when new functionality is released, as we may modify, enhance, upgrade and implement new systems, procedures and controls to reflect changes in our business, technological advancements and changing industry trends. Despite extensive testing, from time to time we have discovered and may in the future discover defects or errors in our solutions. Any performance problems or defects in our solutions could materially and adversely affect our business, operating results and financial conditions. Defects, errors or other similar performance problems or disruptions, whether in connection with day-to-day operations or otherwise, could be costly for us, adversely affect our customers' or partners' businesses, harm our reputation and result in reduced sales or a loss of, or delay in, the market acceptance of our solutions. In addition, if we have any such errors, defects or other performance problems, our customers or partners could seek to terminate, or elect not to renew, their contracts with us, delay or withhold payment or make claims against us. Any of these actions could result in liability, lost business, increased insurance costs, difficulty in collecting accounts receivable, costly litigation or adverse publicity, which could materially and adversely affect our business, operating results and financial condition. Additionally, our software uses open-source software and any defects or security vulnerabilities in such open-source software could materially and adversely affect our business, operating results and financial condition. In addition, we rely on technologies and software supplied by third parties that may also contain undetected errors, viruses or defects. Software defects and errors or delays in electronic bill presentment or our facilitation of payment processing could result in additional development costs, diversion of technical and other resources from our other development efforts, loss of credibility with current or potential customers, partners and clients, harm to our reputation and exposure to liability claims, any of which could result in a material adverse effect on our business, operating results and financial condition.
Technology - Risk 3
Interruptions or delays in the services provided by our third-party data centers or internet service providers could impair the delivery of our solutions. Any changes in the systems that these providers make available to us that degrade the functionality of our solutions, impose additional costs or requirements on us, or give preferential treatment to competitors' services, including their own services, could materially and adversely affect usage of our solutions.
Our third-party service providers are ultimately responsible for maintaining their own network security, disaster recovery and system management procedures, and our review processes for such providers may be insufficient to identify, prevent or mitigate adverse events. The owners and operators of our current and future hosting facilities do not guarantee that our customers' or partners' or their clients' access to our solutions will be uninterrupted, error-free or secure. We or our third-party service providers have in the past, and may in the future, experience website disruptions, outages and other performance problems. We have periodically experienced service disruptions in the past, and we cannot assure you that we will not experience service interruptions or delays in the future. We depend on our third-party service providers to protect their infrastructure against damage, interruption and other performance problems, to maintain their respective configuration, architecture and interconnection specifications and to protect information stored by such providers, and we also depend upon internet service providers for the transmission of data. We may also incur significant costs for using alternative equipment or taking other actions in preparation for, or in reaction to, events that damage the data storage and transmission services we use.
Although we have disaster recovery plans that use multiple data storage locations, any incident affecting their infrastructure that may be caused by fire, flood, severe storm, earthquake, power loss, telecommunications failures, unauthorized entry or intrusion, sabotage, criminal acts, intentional acts of vandalism and other misconduct, computer viruses and disabling devices, natural disasters, military actions, terrorist attacks, negligence, infrastructure changes, human or software errors, fraud, spikes in customer, partner or client usage and denial of service issues, hardware failures, improper operation, data loss, compromise or corruption, cybersecurity attacks, wars, hurricanes, tornadoes and other similar events beyond our control could negatively affect our solutions. In some instances, we may not be able to identify the cause or causes of these performance problems within an acceptable period of time. Any prolonged service disruption affecting our solutions for any of the foregoing reasons could result in lengthy interruptions in the delivery of our solutions, cause system interruptions, prevent our customers, partners or clients from accessing their accounts online, damage our reputation with current and potential customers, partners or clients, expose us to liability, cause us to lose customers, partners or clients, cause the loss of critical data, prevent us from supporting our platform, products or services, result in regulatory investigations, enforcement actions and litigation or cause us to incur additional expense in investigating, remediating and responding to these disruptions and arranging for new facilities and support or otherwise harm our business.
Also, in the event of damage to our systems or interruption of our services, our insurance policies may not adequately compensate us for any losses that we may incur. System failures or outages could compromise our ability to perform these functions in a timely manner, which could harm our ability to conduct business or delay our financial reporting. Such failures could adversely affect our operating results and financial condition. In addition, certain of our third-party service providers are required to notify us if they experience a security breach or unauthorized disclosure of certain personal information, or, in some cases, confidential data or information of ours or our customers, partners or clients, and their failure to timely notify us of such a breach or disclosure may cause us to incur significant costs or otherwise harm our business.
Our solutions are accessed by many customers, partners and clients, often at the same time. As we continue to expand the number of our customers, partners and clients, as well as the number of products available through our solutions, we may not be able to scale our technology to accommodate the increased capacity requirements, which may result in interruptions or delays in service. In addition, the failure of data centers, internet service providers or other third-party service providers to meet our capacity requirements could result in interruptions or delays in access to our solutions or impede our ability to grow our business and scale our operations. If our third-party infrastructure service agreements are terminated, or there is a lapse of service, interruption of internet service provider connectivity, or damage to data centers, we could experience interruptions in access to our solutions as well as delays and additional expense in arranging new facilities and services.
We also depend on third-party internet-hosting providers and continuous and uninterrupted access to the internet through third-party bandwidth providers to operate our business. If we lose the services of one or more of our internet-hosting or bandwidth providers for any reason or if their services are disrupted, for example due to viruses, ransomware, or extortion based attacks, denial of service or other attacks on their systems, or due to human error, intentional bad acts, power loss, hardware failures, telecommunications failures, fires, wars, terrorist attacks, floods, earthquakes, hurricanes, tornadoes or similar catastrophic events, we could experience disruption in our ability to offer our solutions and adverse perception of our solutions' reliability, or we could be required to retain the services of replacement providers, which could increase our operating costs and materially and adversely affect our business, operating results and financial condition.
Furthermore, prolonged interruption in the availability, or reduction in the speed or other functionality, of our solutions could materially harm our reputation and business. Frequent or persistent interruptions in accessing our solutions could cause customers, partners or clients to believe that our solutions are unreliable, leading them to switch to our competitors or to avoid our solutions, and could permanently harm our reputation and business.
Additionally, as our customers and partners and their clients may use our solutions for critical transactions, any errors, defects or other infrastructure problems could result in damage to such customers', partners' or clients' businesses. These customers, partners and clients could seek significant compensation from us for their losses and our insurance policies may be insufficient to cover a claim. Even if unsuccessful, this type of claim may be time-consuming and costly for us to defend. Any of the foregoing could have a material adverse effect on our business, operating results and financial condition.
Technology - Risk 4
If we are unable to ensure that our solutions interoperate with a variety of software suites, applications and other technologies that are developed by others, including our partners, or if there are performance issues with such third-party systems, our solutions will not operate effectively, we may become less competitive and our business, operating results and financial condition may be harmed.
Our solutions must integrate with a variety of software suites, applications and other technologies that are developed by third parties, and we need to continuously modify and enhance our solutions to adapt to changes in such software and other technologies. In particular, we have developed our solutions to be able to easily integrate with key third-party applications of our software partners. We are typically subject to standard terms and conditions of providers of software or other technology, which govern the distribution and operation of such software and other technologies and are subject to change by such providers from time to time. Our business may be harmed if any provider of such software or other technologies:
- discontinues or limits our access to its software or other technologies;- modifies its terms of service or other legal terms or policies, including by raising fees or placing additional restrictions on us;- changes how information is accessed by us or our customers or partners or their clients;- has performance or other problems that affect the operation or perception of our platform, products or services;- establishes exclusive or more favorable relationships with one or more of our competitors; or - develops or otherwise favors its own competitive offerings over our solutions.
For example, to deliver comprehensive solutions, we integrate our solutions with offerings of popular software providers, through APIs made available by these software providers. If any providers of software or other technologies change the features of their APIs, discontinue their support of such APIs, restrict our access to their APIs or alter the terms governing their use in a manner that is adverse to our business, our ability to provide the synchronized capabilities will be impaired, which could significantly diminish the value of our solutions and harm our business, operating results and financial condition.
Third-party services and products are constantly evolving, and we may not be able to modify our solutions to assure its compatibility with that of other third parties as they continue to develop or emerge in the future, or we may not be able to make such modifications in a timely and cost-effective manner. In addition, some of our competitors may be able to disrupt the operations or compatibility of our solutions with their products or services, or exert strong business influence on our ability to, and terms on which we, operate our solutions. Should any of our competitors modify their products or standards in a manner that degrades the functionality of our solutions or gives preferential treatment to our competitors or competitive products, whether to enhance their competitive position or for any other reason, the interoperability of our solutions with these products could be adversely affected, and our business, results of operations and financial condition would be harmed. If we are not permitted or able to integrate with these and other third-party software suites, applications and other technologies in the future, our business, results of operations and financial condition would be harmed.
Furthermore, the functionality of our solutions also depends on our and our partners' ability to integrate our solutions with their offerings. These partners periodically update and change their systems, and although we have been able to adapt our solutions to their evolving needs in the past, there can be no guarantee that we will be able to do so in the future or in a way such that our customers or partners or their clients are satisfied with the quality of work performed by us or with the technical support services rendered. In particular, if we are unable to adapt to the needs of our partners' platforms, software and solutions, our customers' and partners' operations may be disrupted, which could result in disputes with our customers or partners or their clients or other third parties, and we may incur additional costs to address the situation. Additionally, our customers and partners may terminate their relationship with us, and we may lose access to large numbers of customer referrals as a result.
Any negative publicity related to our solutions may adversely affect our reputation, business, operating results and financial condition, regardless of its accuracy, and whether or not our solutions are actually the ultimate cause of any poor performance.
Technology - Risk 5
If our healthcare-related solutions fail to provide accurate billing and coding information, then healthcare practitioner customers or third parties, including government regulators, could assert claims against us that could result in substantial costs and harm to us.
Our SimplePractice solution allows practitioners to efficiently optimize patient outcomes by adding an assessment from a robust template library to a patient's profile or adding a diagnosis and an ICD-10 code from an auto-populated list developed from information we source from the American Psychiatric Association and the Centers for Medicare & Medicaid Services ("CMS") rather than create a treatment plan from scratch. Practitioners can also access Wiley Treatment Planners to choose from over 1,000 pre-written treatment goals, objectives, and interventions organized by commonly encountered problems in treating patients who seek mental health care. Even though we advise our health care practitioner customers that they are responsible for confirming the accuracy of such pre-populated information, if our healthcare-related solutions cause our healthcare practitioner customers to provide inaccurate billing and coding information and result in the submission of incorrect requests for payment, then healthcare practitioner customers or third parties, including government regulators, could assert claims against us that could result in substantial costs and harm to us.
Technology - Risk 6
We rely on Internet infrastructure, bandwidth providers, data center providers, other third parties and our own systems for providing our solutions to our customers, and any failure or interruption in the services provided by these third parties or our own systems could expose us to litigation and negatively impact our relationships with clients, adversely affecting our brand and our business.
Our ability to deliver our solutions is dependent on the development and maintenance of the infrastructure of the Internet and other telecommunications services by third parties. This includes maintenance of a reliable network connection with the necessary speed, data capacity and security for providing reliable Internet access and services and reliable telephone and facsimile services. Our services are designed to operate without interruption in accordance with our service level commitments.
However, we have experienced limited interruptions in these systems in the past, including server failures that temporarily slow down the performance of our services, and we may experience more significant interruptions in the future. We rely on internal systems as well as third-party suppliers, including cloud providers, to provide our services. Interruptions in these systems, whether due to system failures, computer viruses, physical or electronic break-ins or other catastrophic events, could affect the security or availability of our services and prevent or inhibit the ability of our partners to access our services. In the event of a catastrophic event with respect to one or more of these systems or facilities, we may experience an extended period of system unavailability, which could result in substantial costs to remedy those problems or negatively impact our relationship with our customers, our business, results of operations and financial condition. To operate without interruption, both we and our service providers must guard against:
- damage from fire, power loss and other natural disasters;- telecommunications failures;- software and hardware errors, failures and crashes;- security breaches, computer viruses and similar disruptive problems; and - other potential interruptions.
Any disruption in the network access, telecommunications or co-location services provided by third-party providers or any failure of or by third- party providers' systems or our own systems to handle current or higher volume of use could significantly harm our business. We exercise limited control over our third-party suppliers, which increases our vulnerability to problems with the services they provide. We have experienced failures by third-party providers' systems which resulted in a limited interruption of our system, although this failure did not result in any claims against us. Any errors, failures, interruptions or delays experienced in connection with these third-party technologies and information services or our own systems could negatively impact our relationships with customers and adversely affect our business and could expose us to third-party liabilities.
Although we maintain insurance for our business, the coverage under our policies may not be adequate to compensate us for all losses that may occur. In addition, we cannot provide assurance that we will continue to be able to obtain adequate insurance coverage at an acceptable cost.
The reliability and performance of our Internet connections may be harmed by increased usage or by denial-of-service attacks. The Internet has experienced a variety of outages and other delays as a result of damages to portions of its infrastructure, and it could face outages and delays in the future. These outages and delays could reduce the level of Internet usage as well as the availability of the Internet to us for delivery of our Internet-based services.
Technology - Risk 7
Our solutions must integrate with a variety of operating systems, and the hardware that enables clients to accept payment cards must interoperate with third-party mobile devices utilizing those operating systems. If we are unable to ensure that our solutions interoperate with such operating systems and devices, our business may be materially and adversely affected.
We are dependent on the ability of our solutions to integrate with a variety of operating systems, as well as web browsers that we do not control. Any changes in these systems that degrade the functionality of our solutions, impose additional costs or requirements on us, or give preferential treatment to competitors' services, including their own services, could materially and adversely affect usage of our solutions. In addition, we rely on app marketplaces, such as the Apple App Store and Google Play, to drive downloads of our mobile apps. Apple, Google, or other operators of app marketplaces regularly make changes to their marketplaces, and those changes may make access to our solutions more difficult. In the event that it is difficult for our customers to access and use our solutions, our business may be materially and adversely affected.
Technology - Risk 8
If our healthcare-related solutions fail to provide accurate and timely information, or if our content or any other element of our solutions is associated with faulty clinical decisions or treatment, we could have liability to healthcare practitioner customers or patients, which could adversely affect our business, results of operations and financial condition.
Our healthcare-related solutions and related content are utilized by our healthcare practitioner customers in managing the administrative tasks related to their practice, including making patient information, such as medical histories, treatment plans, medical conditions and the use of particular medications, easily accessible for the providers. If our healthcare-related solutions or content fail to provide accurate and timely information that are relied on by our healthcare practitioner customers and are associated with faulty clinical decisions or treatment, then healthcare practitioner customers or their patients could assert claims against us that could result in substantial costs to us, harm our reputation in the industry and cause demand for our services to decline, which could adversely affect our business, results of operations and financial condition.
Technology - Risk 9
Real or perceived errors, failures or bugs in our solutions could adversely affect our business, results of operations, financial condition, and growth prospects.
Our solutions are complex, and therefore, undetected errors, failures or bugs have occurred in the past and may occur in the future. Our solutions are used in information technology environments with different operating systems, system management software, applications, devices, databases, servers, storage, middleware, custom and third-party applications and equipment and networking configurations, which has in the past caused, and may in the future cause, errors or failures in the information technology environment into which our solutions are deployed. This diversity increases the likelihood of errors or failures in those information technology environments. Despite testing by us, real or perceived errors, failures or bugs may not be found until our customers use our solutions. Real or perceived errors, failures or bugs in our products could result in negative publicity, loss of or delay in market acceptance of our solutions and harm our brand, weakening of our competitive position, claims by customers for losses sustained by them or failure to meet the stated service level commitments in our customer agreements. In such an event, we may be required, or may choose (and have in the past chosen), for customer relations or other reasons, to expend significant additional resources in order to help correct the problem. Any errors, failures or bugs in our software could impair our ability to attract new customers, retain existing customers or expand their use of our software, which would adversely affect our business, results of operations and financial condition.
Technology - Risk 10
Interruptions or performance problems associated with our technology and infrastructure may adversely affect our business, results of operations and financial condition.
Our continued growth depends in part on the ability of our existing customers and new customers to access our solutions at any time and within an acceptable amount of time. We have in the past, and may in the future, experience service disruptions, outages and other performance problems due to a variety of factors, including infrastructure changes or failures, human or software errors, malicious acts, terrorism or capacity constraints. Capacity constraints could be due to a number of potential causes including technical failures, natural disasters, fraud or security attacks. In some instances, we may not be able to identify and/or remedy the cause or causes of these performance problems within an acceptable period of time. It may become increasingly difficult to maintain and improve our performance as our solutions and customer implementations become more complex. If our solutions are unavailable or if our customers are unable to access features of our solutions within a reasonable amount of time or at all, or if other performance problems occur, our business, results of operations and financial conditions may be adversely affected.
Technology - Risk 11
We depend and rely upon SaaS technologies from third parties to operate our business, and interruptions or performance problems with these technologies may adversely affect our business and results of operations.
We rely on hosted SaaS applications from third parties in order to operate critical functions of our business, including enterprise resource planning, order management, contract management billing, project management, accounting and other operational activities. Some of these applications have in the past, and may in the future, become unavailable due to extended outages or interruptions and may also be no longer available on commercially reasonable terms. If that happens, our expenses could increase, our ability to manage finances could be interrupted and our processes for managing sales of our solutions and supporting our customers could be impaired until equivalent services, if available, are identified, obtained and implemented, all of which could adversely affect our business.
Technology - Risk 12
Our business could be harmed if we fail to manage our infrastructure to support future growth.
The rapid growth we have experienced in our business places significant demands on our operational infrastructure. The scalability and flexibility of our solutions depend on the functionality of our technology and network infrastructure and its ability to handle increased traffic and demand for bandwidth. The growth in the number of customers and their clients using our solutions has increased the amount of data that we process. Any problems with the transmission of increased data could result in harm to our brand or reputation. Moreover, as our business grows, we will need to devote additional resources to improving our operational infrastructure and continuing to enhance its scalability in order to maintain the performance of our solutions, including customer support, risk and compliance operations, and other SaaS solutions services. Any failure of or delay in these efforts could result in service interruptions, impaired system performance, and reduced customer and client satisfaction. If sustained or repeated, these performance issues could reduce the attractiveness of our solutions to our customers and could result in lost customer opportunities and higher attrition rates, any of which could hurt our revenue growth, customer loyalty and our reputation. Even if our efforts to scale our business are successful, they will be expensive and complex, and require the dedication of significant management time and attention. We could also face inefficiencies or service disruptions as a result of our efforts to scale our internal infrastructure. We cannot be sure that the expansion and improvements to our internal infrastructure will be effectively implemented on a timely basis, if at all, and such failures could adversely affect our business, operating results, and financial condition.
Moreover, our rapid growth has placed, and will likely continue to place, a significant strain on our managerial, administrative, operational, financial, and other resources. We grew from 592 employees as of December 31, 2020 to 971 employees as of December 31, 2022, substantially all of which were employed on a full-time basis. We intend to further expand our overall business, including headcount, with no assurance that our revenue will continue to grow or grow sufficiently to offset the costs associated with increased headcount. As we grow, we will be required to continue to improve our operational and financial controls and reporting procedures, and we may not be able to do so effectively. Furthermore, some members of our management do not have significant experience managing a large public company, so our management may not be able to manage such growth effectively. In managing our growing operations, we are also subject to the risks of over-hiring, over-compensating our employees, and over-expanding our operating infrastructure. As a result, we may be unable to manage our expenses effectively in the future, which may negatively impact our gross profit or operating income.
In addition, we believe that an important contributor to our success has been our corporate culture, which we believe fosters innovation and is rooted in a philosophy of aligning our success with that of our customers. As a result of our rapid growth, a significant portion of our employees have been with us for fewer than three years. As we continue to grow and develop the infrastructure of a public company, we must effectively integrate, develop and motivate a growing number of new employees, who are dispersed geographically, primarily in the U.S. Our geographically dispersed workforce may make it more difficult for our management to manage our growth effectively and preserve our corporate culture. In addition, we must preserve our ability to execute quickly in further developing our solutions and implementing new features and tools. As a result, we may find it difficult to maintain our corporate culture, which could limit our ability to innovate and operate effectively. Any failure to preserve our culture could also negatively affect our ability to recruit and retain personnel, to continue to perform at current levels, or to execute our business strategy effectively and efficiently.
Legal & Regulatory
Total Risks: 15/78 (19%)Above Sector Average
Regulation5 | 6.4%
Regulation - Risk 1
We are required to comply with payment network operating rules, procedures and standards, and changes to such rules, procedures or standards, or payment network fees, could harm our business.
Payment networks establish their own Payment Network Rules, that allocate liabilities and responsibilities among the payment networks and their participants. These rules, procedures and standards, including the PCI-DSS, govern a variety of areas, including how consumers may use their cards, the security features of cards, security standards for processing, data protection, information security, and allocation of liability for certain acts or omissions, including liability in the event of a data breach. Participants are subject to audits by the payment networks to ensure compliance with applicable rules and standards.
Pursuant to our agreements with third-party payment processors we are required to comply with Payment Network Rules and have agreed to reimburse our third-party payment processors for any fines they are assessed by payment networks as a result of any Payment Network Rule violations by us. We may also be directly liable to the payment networks for any Payment Network Rule violations by us. The payment networks set and interpret the Payment Network Rules, and could adopt new operating rules, procedures or standards or interpret or reinterpret existing rules, procedures and standards that we or our processors might find difficult or even impossible to follow or comply with or costly to implement. These changes may be made for any number of reasons, including as a result of changes in the regulatory environment, to maintain or attract new participants or to serve the strategic initiatives of the networks, and may impose additional costs and expenses on or be disadvantageous to certain participants. For example, changes in the Payment Network Rules regarding chargebacks may affect our ability to dispute chargebacks and the amount of losses we incur from chargebacks. If we fail to make such changes or otherwise resolve the issue with the payment networks, the networks could pass on fines and assessments in respect of fraud or chargebacks related to our customers or disqualify the processing of transactions through our platform if satisfactory controls are not maintained, which could have a material adverse effect on our business, operating results and financial condition. We also may seek to introduce new payment-related products in the future, which may entail additional compliance with the Payment Network Rules. As a result of any violations of the current Payment Network Rules or new rules being implemented, the networks may fine, penalize, or suspend the registration of participants for certain acts or omissions or the failure of the participants to comply with applicable rules, procedures and standards, existing customers, partners or other third parties may cease using or referring our services, prospective customers, partners or other third parties may choose to terminate negotiations with us, or delay or choose not to consider the use of our platform for their processing needs, and the networks could refuse to allow the processing of payments through our platform through their networks. Any of the foregoing could materially adversely impact our business, operating results and financial condition.
From time to time, these networks increase the fees that they charge third-party payment processors. Our third-party payment processors have, in the past, and may, in the future, pass those fees onto us. We could attempt to pass these increases along to our customers, but this strategy might result in the loss of customers to competing solutions. If competitive practices prevent us from passing along the higher fees to our customers in the future, we may have to absorb all or a portion of such increases, which may reduce our revenue and earnings. In addition, interchange and other fees are subject to increased scrutiny by governmental agencies, and new laws or regulations could require greater pricing transparency of the breakdown in fees or fee limitations, which could lead to increased price-based competition, lower margins and higher rates of customer attrition and negatively affect our business, operating results and financial condition. As a result of any increased fees, such payments could become prohibitively expensive for us or for our customers.
Regulation - Risk 2
We are subject to anti-corruption, anti-bribery and similar laws, and non-compliance with such laws can subject us to criminal or civil liability and harm our business.
We are subject to the FCPA, U.S. domestic bribery laws and other anti-corruption laws. Anti-corruption and anti-bribery laws have been enforced aggressively in recent years and are interpreted broadly to generally prohibit companies, their employees and their third-party intermediaries from authorizing, offering or providing, directly or indirectly, improper payments or benefits to recipients in the public sector. These laws also require that we keep accurate books and records and maintain internal controls and compliance procedures designed to prevent any such actions. Although we currently only maintain operations in the United States, we utilize contractors outside of the United States and if we increase our international cross-border operations abroad, we may engage with business partners and third-party intermediaries to market our services and to obtain necessary permits, licenses and other regulatory approvals. Our operations are dependent in part upon transmission bandwidth provided by third-party network providers and access to co-location facilities to house our servers, which in some countries may be state owned. Similarly, some of our customers may be state-owned, in each case exposing us to potential risks. In addition, we or our third-party intermediaries may have direct or indirect interactions with officials and employees of government agencies or state-owned or affiliated entities. We can be held liable for the corrupt or other illegal activities of these third-party intermediaries, our employees, representatives, contractors, partners and agents, even if we do not explicitly authorize such activities. We cannot assure you that all of our employees and agents will not take actions in violation of our policies and applicable law, for which we may be ultimately held responsible. As we increase our international operations, our risks under these laws may increase.
Detecting, investigating and resolving actual or alleged violations of anti-corruption laws can require a significant diversion of time, resources and attention from management. In addition, noncompliance with anti-corruption or anti-bribery laws could subject us to whistleblower complaints, investigations, sanctions, settlements, prosecution, enforcement actions, fines, damages, other civil or criminal penalties, injunctions, suspension or debarment from contracting with certain persons, reputational harm, adverse media coverage and other collateral consequences. If any subpoenas are received or investigations are launched, or governmental or other sanctions are imposed, or if we do not prevail in any possible civil or criminal proceeding, our business, operating results and financial condition could be materially harmed.
Regulation - Risk 3
We are subject to laws and regulations regarding export control, import, economic and trade sanctions, anti-money laundering, and counter-terror financing that could impair our ability to compete in international markets or subject us to criminal or civil liability if we violate them.
Our solutions are subject to export control laws and regulations, including the Export Administration Regulations administered by the U.S. Department of Commerce, and our activities may be subject to trade and economic sanctions, including U.S. economic and trade sanctions administered by the U.S. Department of Treasury's Office of Foreign Assets Control ("OFAC"), which we collectively refer to as trade controls. As such, a license may be required to export or re-export our products, or provide related services, to certain countries and customers. Further, our products incorporating encryption functionality may be subject to special controls applying to encryption items or certain reporting requirements. The process for obtaining necessary licenses may be time-consuming or unsuccessful, potentially causing delays in sales or losses of sales opportunities.
If our solutions are accessed from a sanctioned country in violation of trade and economic sanctions, we could be subject to fines or other enforcement action. Although we have no knowledge that our activities have resulted in violations of trade controls, any failure by us or our partners to comply with applicable laws and regulations would have negative consequences for us, including reputational harm, government investigations and penalties.
In addition, various countries regulate the import of certain encryption technology, including through import permit and license requirements, and have enacted laws that could limit our ability to distribute our products or could limit customers' ability to implement our products in those countries. Changes in our products or changes in export and import regulations in such countries may create delays in the introduction of our products into international markets, prevent customers with international operations from deploying our products globally or, in some cases, prevent or delay the export or import of our products to certain countries, governments or persons altogether. Any change in export or import laws or regulations, economic sanctions or related legislation, shift in the enforcement or scope of existing export, import or sanctions laws or regulations, or change in the countries, governments, persons or technologies targeted by such export, import or sanctions laws or regulations, could result in decreased use of our products by, or in our decreased ability to export or sell our products to, existing or potential customers with international operations. Any decreased use of our products or limitation on our ability to export to or sell our products in international markets could adversely affect our business, operating results and financial condition.
Pursuant to agreements with certain of our third-party payment processors, we also have obligations under anti-money laundering and counter-terrorist financing laws and regulations. There has been increased scrutiny in the United States and globally regarding compliance with these laws and regulations, which may require us to further revise or expand our compliance program, including the procedures we use to verify the identity of our customers, to comply with our contractual obligations.
Regulation - Risk 4
Our business is subject to a wide variety of laws and regulations. Liabilities or loss of business resulting from any actual or perceived failure to comply with laws and regulations, and regulatory or judicial interpretations thereof, including payments and other financial services-related laws and regulations, and increased costs or loss of business associated with compliance with those laws and regulations, could have an adverse effect on our business.
We are subject to a wide variety of local, state, federal, and international laws, rules, regulations, licensing and other authorization schemes, and industry standards in the United States and in other countries in which we operate. These laws, rules, regulations, licensing and other authorization schemes, and industry standards govern numerous areas that are important and material to our business. In addition to privacy, data protection and information security, export control, import, economic and trade sanctions, and anti-money laundering and counter-terror financing-related laws, rules, and regulations, our business is also subject to, without limitation, laws, rules, and regulations applicable to securities, labor and employment, immigration, competition, and marketing and communications practices.
In addition, the laws, rules, regulations, licensing and other authorization schemes, and industry standards that govern our business, both directly and through our relationships with banks, payment networks, payment processors, and other financial services partners, include, or may in the future include, those relating to payments services, such as payment processing and settlement services, escheatment, and compliance with PCI-DSS, a set of requirements designed to ensure that all companies that process, store or transmit payment card information maintain a secure environment to protect cardholder data. These laws, rules, regulations, licensing and other authorization schemes, and industry standards are administered and enforced by multiple authorities and governing bodies in the United States, including the Department of the Treasury, self-regulatory organizations, and numerous state and local governmental authorities and regulatory agencies.
Laws, rules, regulations, licensing and other authorization schemes, and industry standards applicable to our business are increasing in number and subject to change and evolving interpretations and application, including by means of legislative changes, executive orders, and regulatory and judicial interpretations, and it can be difficult to predict how they may be applied to our business and the way we conduct our operations, particularly as we introduce new solutions and expand into new geographies.
We may not be able to respond quickly or effectively to regulatory, legislative, judicial, and other developments, and these changes may in turn impair our ability to offer our existing or planned solutions and increase our cost of doing business.
There can be no assurance that we and our employees and/or contractors will not violate or fail to comply with applicable laws, rules, regulations, licensing and other authorization schemes, and industry standards, or interpretations thereof, or will not otherwise face regulatory scrutiny for our historical and/or ongoing compliance with such laws, rules, regulations, or interpretations. Any failure or perceived failure by us or our employees or contractors to comply with existing or new laws, rules, regulations, licensing or other authorization schemes, industry standards, or orders of any governmental or regulatory authority (including changes to or expansion of the interpretation of those laws, regulations, standards or orders), may, among other things:
- subject us to significant fines, penalties, criminal and civil lawsuits, license suspension or revocation, forfeiture of significant assets, audits, inquiries, whistleblower complaints, adverse media coverage, investigations and enforcement actions in one or more jurisdictions levied by federal, state, local, or foreign regulators, state attorneys general and private plaintiffs who may be acting as private attorneys general pursuant to various applicable federal, state, and local laws;- result in additional compliance and licensure or other authorization requirements;- increase regulatory scrutiny of our business;- restrict our operations, product features, quality, and breadth and depth of functionality; and - force us to restrict or change our business practices or compliance program, make product or operational changes, or delay planned product launches or improvements.
Further, the complexity of U.S. federal and state regulatory and enforcement regimes could result in a single event giving rise to many overlapping investigations and legal and regulatory proceedings by multiple government authorities in different jurisdictions.
Any of the foregoing could, individually or in the aggregate, harm our reputation as a trusted provider, damage our brand and business, cause us to lose existing customers and partners, prevent us from obtaining new customers and partners, require us to expend significant funds to remedy problems caused by breaches and to avert further breaches, expose us to legal risk and potential liability, and adversely affect our business, operating results and financial condition.
Currently, we do not possess any permits, licenses or other authorizations from financial regulators. We believe the licensing and authorization requirements of federal and state regulatory agencies that regulate or supervise banks, payment processors, or other financial institutions or providers of payment services do not apply to us. While our business itself, and our related activities, are not currently subject to financial services-related regulation, the banks and payment processors that we partner with operate in a highly regulated landscape and there is a risk that those laws and regulations could become directly applicable to us and/or our contractual compliance with certain legal and regulatory obligations could become increasingly difficult and costly. As we expand into new jurisdictions, the number of foreign laws, rules, regulations, licensing and other authorization schemes and standards governing our business and activities will expand as well. In addition, as our business and products and services continue to develop and expand, we may become subject to additional laws, rules, regulations, licensing and other authorization schemes and standards. We may not always be able to accurately predict the scope or applicability of certain laws, rules, regulations, licensing and other authorization schemes or standards to our business and related activities, particularly as we expand into new areas of operations, which could have a significant negative effect on our existing business and our ability to pursue future plans.
In the future, as a result of the laws, rules and regulations that are or may become applicable to our business, we could be subject to investigations, inspections, examinations, and supervision, and resulting liability, including governmental fines, restrictions on our business, or other sanctions, and we could be forced to cease conducting certain aspects of our business with residents of certain jurisdictions, be forced to change our business practices in certain jurisdictions or be required to obtain additional licenses, certifications or regulatory approvals. There can be no assurance that we will be able to successfully implement changes to our business practices or obtain or maintain any such licenses, certifications or regulatory approvals, and, even if we were able to do so, there could be substantial costs and potential product changes involved in obtaining, maintaining and renewing such licenses, certifications and approvals, which could have a material and adverse effect on our business. In addition, we could be subject to fines or other enforcement action if we are found to violate disclosure, reporting, anti-money laundering, capitalization, corporate governance or other requirements of such licenses, certifications or approvals. These factors could impose substantial additional costs, involve considerable delay to the development or provision of our products or services, require significant and costly operational changes or prevent us from providing our products or services in any given market.
Regulation - Risk 5
Our and our customers' and partners' communications with existing and potential clients are subject to laws regulating telephone and email marketing practices, and our or their failure to comply with such communications laws could adversely affect our business, operating results, and financial condition and significantly harm our reputation.
Our solutions enable our customers and partners to communicate directly with their clients, including via email, text messages and telephone calls. Our solutions also enable recording and monitoring of calls between our customers and partners and their clients for training and quality assurance purposes. On occasion, we also send communications directly to clients. These activities are subject to a variety of U.S. state and federal laws, rules, and regulations, such as the TCPA, the CAN-SPAM Act of 2003 (the "CAN-SPAM Act"), and others related to telemarketing, recording, and monitoring of communications. The TCPA prohibits companies from making telemarketing calls to numbers listed in the Federal Do-Not-Call Registry and imposes other obligations and limitations on making phone calls and sending text messages to consumers. The CAN-SPAM Act regulates commercial email messages and specifies penalties for the transmission of commercial email messages that do not comply with certain requirements, such as providing an opt-out mechanism for stopping future emails from senders. The TCPA, the CAN-SPAM Act and other communications laws, rules, and regulations are subject to varying interpretations by courts and governmental authorities and often require subjective interpretation, making it difficult to predict their application and therefore making compliance efforts more challenging. We and our customers and partners may be required to comply with these and similar laws, rules, and regulations. To comply with these laws, rules, and regulations, in some cases we rely on our customers and partners to obtain legally required consents from their consumers to receive communications sent using our solutions. We cannot, however, be certain that our or their efforts to comply will always be successful. Our business could be adversely affected by changes to the application or interpretation of existing laws, rules and regulations governing our solution's communication capabilities, or the enactment of new laws, rules and regulations, and by our and our customers' and partners' failure to comply with such laws, rules and regulations in using our solutions. If any of these laws, rules or regulations were to significantly restrict our or our customers' or partners' ability to use our solutions to communicate with existing and potential clients, we may not be able to develop adequate alternative communication modules for our solutions. Further, our or our customers' or partners' non-compliance with these laws, rules, and regulations could result in significant financial penalties, litigation, including class action litigation, consent decrees and injunctions, adverse publicity, and other negative consequences, any of which could adversely affect our business, operating results, and financial condition and significantly harm our reputation.
Litigation & Legal Liabilities3 | 3.8%
Litigation & Legal Liabilities - Risk 1
If we or our healthcare practitioner customers fail to comply with federal and state laws governing submission of false or fraudulent claims to government healthcare programs or financial relationships among healthcare providers, we or our healthcare provider customers may be subject to civil and criminal penalties or loss of eligibility to participate in government healthcare programs.
As a participant in the healthcare industry, our operations and relationships, and those of our healthcare and wellness practitioner customers, are regulated by a number of federal, state, and local governmental agencies. The impact of these laws and regulations can adversely affect us. In addition, the inability of our healthcare practitioner customers to use our technology solutions in a manner that complies with those laws and regulations could affect the marketability of our technology solutions or even expose us to claims, litigation and substantial liability. A number of federal and state laws, including anti-kickback restrictions and laws prohibiting the submission of false or fraudulent claims, apply to healthcare providers and others that make, offer, seek or receive referrals or payments for items or services that may be paid for by any federal or state healthcare program and, in some instances, any private program. These laws are complex, and their application to our specific healthcare solutions, services, and relationships may not be clear and may be applied to our business in ways that we do not anticipate. Of particular importance are the following:
- the federal AKS, which prohibits the knowing and willful offer, payment, solicitation or receipt of any bribe, kickback, rebate or other remuneration (other than those that satisfy specific "safe harbors") in return for referring, ordering, leasing, purchasing, recommending or arranging for or to induce the referral of an individual or the ordering, purchasing or leasing of items or services covered, in whole or in part, by any government healthcare program, such as Medicare and Medicaid. A person or entity does not need to have actual knowledge of the statute or specific intent to violate it to have committed a violation;- the federal FCA, which imposes civil and criminal liability on individuals or entities that knowingly submit false or fraudulent claims for payment to the government or knowingly make, or cause to be made, a false statement in order to have a false claim paid. In addition, the government may assert that a claim including items or services resulting from a violation of the federal AKS constitutes a false or fraudulent claim for purposes of the FCA. The government has prosecuted practice management service providers for causing the submission of false or fraudulent claims in violation of the FCA, and vendors of EHR software for, among other things, misrepresenting the capabilities of their software and payment of kickbacks to certain customers in exchange for promoting their products in violation of the federal AKS and FCA. Moreover, suits filed under the FCA, known as qui tam actions, can be brought by any individual on behalf of the government and such individuals, commonly known as "whistleblowers," may share in any amounts paid by the entity to the government in fines or settlement;- the criminal healthcare fraud provisions under HIPAA and related rules that prohibit knowingly and willfully executing a scheme or artifice to defraud any healthcare benefit program or falsifying, concealing or covering up a material fact or making any material false, fictitious or fraudulent statement in connection with the delivery of or payment for healthcare benefits, items or services. Similar to the AKS, a person or entity does not need to have actual knowledge of the statute or specific intent to violate it to have committed a violation;- similar state law provisions pertaining to anti-kickback and false claims issues, some of which may apply to items or services reimbursed by any payor, including patients and commercial insurers; and - state laws prohibiting fee-splitting or the sharing of professional services income with nonprofessional or business interests.
Because of the breadth of these laws and the narrowness of the statutory exceptions and safe harbors available, it is possible that some of our business activities could be subject to challenge under one or more of such laws. These laws are complex and may change rapidly, and their application to our specific healthcare-related solutions, services, and relationships may not be clear and may be applied to our business in ways we do not anticipate. New payment structures and other arrangements involving combinations of healthcare providers who share savings, potentially implicate anti-kickback and other fraud and abuse laws. In addition, errors created by our proprietary solutions that relate to entry, formatting, preparation or transmission of claims or reporting of quality or other data pursuant to value-based purchasing initiatives may be alleged or determined to cause the submission of false claims or otherwise be in violation of these laws.
If our EHR software, technology, practice management solutions or billing, coding, claims submission and other solutions, our marketing activities, or our financial arrangements with physicians and other licensed healthcare professionals in the position to refer business to us are found to be in violation of any of the government regulations that apply to us, we may be subject to substantial penalties, including administrative, civil and criminal penalties, damages, fines, disgorgement, the curtailment or restructuring of operations, additional integrity oversight and reporting obligations, exclusion from participation in federal and state healthcare programs and imprisonment, any of which could adversely affect our business, results of operations or financial condition. Any action against us or our practitioner customers for violation of these laws or regulations, even if we successfully defend against it, could cause us to incur significant legal expenses, divert our management's attention from the operation of our business and result in adverse publicity, any of which could adversely affect demand for our solutions, invalidate all or portions of some of our contracts with our practitioner customers, require us to change or terminate some portions of our business, require us to refund portions of our revenue, cause us to be disqualified from serving practitioner customers doing business with government payors, and give our customers the right to terminate our contracts with them, any one of which could have an adverse effect on our business.
Litigation & Legal Liabilities - Risk 2
We may be subject to securities litigation, which is expensive and could divert management attention.
The market price of our common stock may be volatile and, in the past, companies that have experienced volatility in the market price of their stock have been subject to securities class action litigation. We may be the target of this type of litigation in the future. Securities litigation against us could result in substantial costs and divert our management's attention from other business concerns, which could seriously harm our business.
Litigation & Legal Liabilities - Risk 3
Any future litigation, investigations or similar matters, or adverse facts and developments related thereto, could adversely affect our business, operating results and financial condition.
We have in the past and/or may in the future become subject to legal proceedings, claims, investigations, regulatory proceedings, or similar matters or actions that arise in the ordinary course of business, such as claims brought by our customers or their clients in connection with commercial disputes, employment claims made by our current or former employees, or claims regarding misappropriation of client data. In addition, the payment networks could impose fines on us or our third-party payment processor(s). Further, state or federal regulators could make inquiries and/or conduct investigations with respect to one or more of our solutions. Even if such claims do not have merit, litigation, investigations, regulatory proceedings, or similar matters might result in substantial costs and may divert management's attention and resources, which might seriously harm our business, operating results and financial condition. Insurance might not cover such matters, might not provide sufficient payments to cover all the costs to resolve one or more such matters and might not continue to be available on terms acceptable to us. A claim brought against us that is uninsured or underinsured could result in unanticipated costs, thereby reducing our operating results and leading analysts or potential investors to reduce their expectations of our performance, which could reduce the market price of our common stock.
Taxation & Government Incentives3 | 3.8%
Taxation & Government Incentives - Risk 1
Taxing authorities may successfully assert that we should have collected or in the future should collect sales and use, value added or similar taxes, and any such assessments could adversely affect our business, financial condition, and results of operations.
Sales and use, value added and similar tax laws and rates vary greatly by jurisdiction. Certain jurisdictions in which we do not collect such taxes may assert that such taxes are applicable or that our presence in such jurisdictions is sufficient to require us to collect taxes, which could result in tax assessments, penalties and interest, and we may be required to collect such taxes in the future. Such tax assessments, penalties and interest or future requirements may adversely affect our financial condition and results of operations. Further, in June 2018, the Supreme Court held in South Dakota v. Wayfair, Inc. that states could impose sales tax collection obligations on out-of-state sellers even if those sellers lack any physical presence within the states imposing the sales taxes. Under the Wayfair decision, a person requires only a "substantial nexus" with the taxing state before the state may subject the person to sales tax collection obligations therein. An increasing number of states (both before and after the publication of the Wayfair decision) have considered or adopted laws that attempt to impose sales tax collection obligations on out-of-state sellers. The Supreme Court's Wayfair decision has removed a significant impediment to the enactment and enforcement of these laws, and it is possible that states may seek to tax out-of-state sellers on sales that occurred in prior tax years, which could create additional administrative burdens for us, put us at a competitive disadvantage if such states do not impose similar obligations on our competitors, and decrease our future sales, which could adversely affect our business, financial condition, and results of operations.
Taxation & Government Incentives - Risk 2
New tax legislation may impact our results of operations and financial condition.
The recently enacted Inflation Reduction Act introduced, among other changes, a 15% corporate minimum tax on certain United States corporations and a 1% excise tax on certain stock redemptions by United States corporations. The U.S. government may enact further significant changes to the taxation of business entities. The likelihood of these changes being enacted or implemented is unclear. We are currently unable to predict the ultimate impact of the Inflation Reduction Act or any such further changes on our business.
Taxation & Government Incentives - Risk 3
Changes in our effective tax rate or tax liability may have an adverse effect on our results of operations.
We are subject to income taxes in the United States. Our effective tax rate could be adversely affected due to several factors, including:
- changes in the relative amounts of income before taxes in the various jurisdictions in which we operate that have differing statutory tax rates;- changes in the United States tax laws and regulations or the interpretation of them, including the Tax Act, as modified by the CARES Act;- changes to our assessment about our ability to realize our deferred tax assets that are based on estimates of our future results, the prudence and feasibility of possible tax planning strategies, and the economic and political environments in which we do business;- the outcome of current and future tax audits, examinations, or administrative appeals; and - limitations or adverse findings regarding our ability to do business in some jurisdictions.
New income or other tax laws or regulations could be enacted at any time, which could adversely affect our business operations and financial performance. Further, existing tax laws and regulations could be interpreted, modified, or applied adversely to us. For example, the Tax Act enacted many significant changes to the U.S. tax laws. Future guidance from the IRS and other tax authorities with respect to the Tax Act may affect us, and certain aspects of the Tax Act could be repealed or modified in future legislation. For example, the CARES Act modified certain provisions of the Tax Act. Changes in corporate tax rates, the realization of net operating losses, and other deferred tax assets relating to our operations, the taxation of foreign earnings, and the deductibility of expenses under the Tax Act or future reform legislation could have a material impact on the value of our deferred tax assets and could increase our future U.S. tax expense.
Environmental / Social4 | 5.1%
Environmental / Social - Risk 1
The increasing focus on environmental, social and governance practices ("ESG") could increase our costs, harm our reputation and adversely impact our financial results.
There has been increasing public focus by investors, customers environmental activists, the media and governmental and nongovernmental organizations on a variety of environmental, social and other sustainability matters. We experience pressure to make commitments relating to ESG matters that affect us, including the design and implementation of specific risk mitigation strategic initiatives relating to ESG. If we are not effective in addressing environmental, social and other sustainability matters affecting our business, or setting and meeting relevant sustainability goals, our reputation and financial results may suffer. We may experience increased costs in order to develop and execute upon our sustainability goals and measure achievement of those goals, which could have an adverse impact on our business and financial condition.
In addition, this emphasis on environmental, social and other sustainability matters has resulted and may result in the adoption of new laws and regulations, including new reporting requirements. If we fail to comply with new laws, regulations or reporting requirements, our reputation and business could be adversely impacted.
Environmental / Social - Risk 2
We and our customers and partners and their clients and other third parties that use our solutions obtain, provide and process a large amount of sensitive and personal data. Any real or perceived improper or unauthorized use of, disclosure of or access to such data could harm our reputation as a trusted brand, as well as have a material adverse effect on our business, operating results and financial condition.
We and our customers and partners and their clients and the third-party vendors and data centers that we use obtain, provide and process large amounts of sensitive and personal data, including data provided by and related to clients and their transactions, as well as other data of the counterparties to their payments. We face risks, including to our reputation as a trusted brand, in the handling and protection of this data, and these risks will increase as our business continues to expand to include new products and technologies.
Cybersecurity threats and attacks, privacy and security breaches, insider threats or other incidents and malicious internet-based activity continue to increase generally, evolve in nature and become more sophisticated, and providers of cloud-based services have frequently been targeted by such attacks, particularly in the financial technology sector. These cybersecurity challenges, including threats to our own information technology infrastructure or those of our customers or partners or their clients or third-party service providers, may take a variety of forms ranging from stolen bank accounts, business email compromise, customer employee fraud, account takeover, check fraud or cybersecurity attacks, to "mega breaches" targeted against cloud-based services and other hosted software, which could be initiated by individual or groups of hackers or sophisticated cyber criminals. A cybersecurity incident or breach could result in loss, compromise, corruption or disclosure of confidential information, intellectual property and sensitive and personal data or data we rely on to provide our solutions and impair our ability to provide our solutions and meet our customers' or partners' or their clients' requirements, or cause production downtimes and compromised data. We may be unable to anticipate or prevent techniques used in the future to obtain unauthorized access or to sabotage systems because they change frequently and often are not detected until after an incident has occurred. As we increase our customer base and our brand becomes more widely known and recognized, third parties may increasingly seek to compromise our security controls or gain unauthorized access to our sensitive corporate information or our customers' or partners' or their clients' sensitive and personal data. Information security risks for technology companies such as ours have significantly increased in recent years in part because of the proliferation of new technologies, the use of the internet and telecommunications technologies to conduct financial transactions, and the increased sophistication and activities of organized crime, hackers, terrorists and other external parties as well as nation-state and nation-state-supported actors. Additionally, geopolitical events and resulting government activity could lead to information security threats and attacks by affected jurisdictions and their sympathizers. Given our business and the industries in which we operate, we believe that we are likely to continue to be a target of such threats and attacks.
We have administrative, technical and physical security measures in place, and we have policies and procedures in place to contractually require service providers to whom we disclose data to implement and maintain reasonable privacy, data protection and information security measures. However, if our privacy protection, data protection or information security measures or those of the previously mentioned third parties are inadequate or are breached as a result of third-party action, employee or contractor error, malfeasance, malware, phishing, hacking attacks, system error, software bugs or defects in our products, trickery, process failure, or otherwise, and, as a result, there is improper disclosure of, or someone obtains unauthorized access to or exfiltrates funds or sensitive and personal data, including personally identifiable information, on our systems or our partners' systems, or if we suffer a ransomware or advanced persistent threat attack, or if any of the foregoing is reported or perceived to have occurred, our reputation and business could be damaged. Recent high-profile security breaches and related disclosures of sensitive and personal data suggest that the risk of such events is significant, even if privacy, data protection and information security measures are implemented and enforced. If sensitive and personal data is lost or improperly disclosed or threatened to be disclosed, we could incur significant costs associated with remediation and the implementation of additional security measures, and may incur significant liability and financial loss and be subject to regulatory scrutiny, investigations, proceedings and penalties.
In addition, because we leverage third-party service providers, including cloud, software, data center and other critical technology vendors to deliver our solutions to our customers, partners or clients and their customers, we rely heavily on the data security technology practices and policies adopted by these third-party service providers. Such third-party service providers have access to sensitive and personal data and other data about our customers, partners and employees, as well as clients using our solutions to pay the bills of our customers, and some of these providers in turn subcontract with other third-party service providers. Our ability to monitor our third-party service providers' data security is limited. There have been and may continue to be significant supply chain attacks, and we cannot guarantee that our or our third-party service providers' software or systems have not been breached or that they do not contain exploitable defects or bugs that could result in a breach of or disruption to our systems or the systems of third parties that support us and our services. A vulnerability in our third-party service providers' software or systems, a failure of our third-party service providers' safeguards, policies or procedures, or a breach of a third-party service provider's software or systems could result in the compromise of the confidentiality, integrity or availability of our systems or the data housed in our third-party solutions. Techniques used to sabotage or obtain unauthorized access to systems are constantly evolving and our third-party service providers may face difficulties or delays in identifying breaches and compromises, and notifying us of any such breaches and compromises. This could cause us to face delays in responding to any such breach or compromise and providing any required notifications to clients or other third parties.
In addition, certain of our partners conduct regular audits of our cybersecurity program, and if any of them were to conclude that our systems and procedures are insufficiently rigorous, they could terminate their relationships with us, and our financial results and business would be adversely affected. Under our terms of service and our contracts with strategic partners, if there is a breach of payment information that we store, we could be liable to the partner for their losses and related expenses. Additionally, if our own confidential business information were improperly disclosed, our business could be materially and adversely affected. A core aspect of our business is the reliability and security of our solutions. Any perceived or actual breach of security, regardless of how it occurs or the extent of the breach, could have a significant impact on our reputation as a trusted brand, cause us to lose existing customers, partners and clients, prevent us from obtaining new customers, partners and clients, require us to expend significant funds to remedy problems caused by breaches and implement measures to prevent further breaches, and expose us to legal risk and potential liability including those resulting from governmental or regulatory investigations, class action litigation, indemnity obligations, damages for contract breach or penalties for violation of security obligations and costs associated with remediation, such as fraud monitoring and forensics, all of which could divert resources and attention of our management and key personnel away from our business operations and materially and adversely affect our business, operating results and financial condition. Any actual or perceived security breach at a third-party service provider providing services to us or our customers, partners or clients could have similar effects. Further, as the current COVID-19 pandemic continues to result in a significant number of people working from home, these cybersecurity risks may be heightened by an increased attack surface across our business and those of our partners and service providers. We cannot guarantee that our efforts, or the efforts of those upon whom we rely and partner with, will be successful in preventing any such information security incidents or protecting sensitive and personal data that they obtain and process on our behalf.
Federal and state regulations may require us or our customers or partners to notify governmental entities and individuals of data security incidents involving certain types of personal and sensitive data or information technology systems. Security compromises experienced by others in our industry, our customers or partners or their clients, our third-party service providers or us may lead to public disclosures and widespread negative publicity. Any security compromise in our industry, whether actual or perceived, could erode client, customer or partner confidence in the effectiveness of our security measures, negatively impact our ability to attract new customers, partners and clients, cause existing customers, partners and clients to elect not to renew or expand their use of our solutions or subject us to third-party lawsuits, regulatory fines or other actions or liabilities, which could materially and adversely affect our business, operating results and financial condition.
In addition, some of our customers and partners contractually require notification of data security compromises and include representations and warranties in their contracts with us that our solutions comply with certain legal and technical standards related to data security and privacy and meet certain service levels. In our contracts, a data security compromise or operational disruption impacting us or one of our critical vendors, or system unavailability or damage due to other circumstances, may constitute a material breach and give rise to a customer's or partner's right to terminate their contract with us. In these circumstances, it may be difficult or impossible to cure such a breach in order to prevent customers or partners from potentially terminating their contracts with us. Furthermore, although our contracts typically include limitations on our potential liability, we cannot ensure that such limitations of liability would be adequate or apply to data security compromises.
While we maintain cybersecurity insurance, our insurance may be insufficient or may not cover all liabilities incurred by such attacks. We also cannot be certain that our insurance coverage will be adequate for data handling or data security liabilities actually incurred, that insurance will continue to be available to us on economically reasonable terms, or at all, or that any insurer will not deny coverage as to any future claim. The successful assertion of one or more large claims against us that exceed available insurance coverage, litigation to pursue claims under our insurance policies or the occurrence of changes in our insurance policies, including premium increases or the imposition of large deductible or co-insurance requirements, or denials of coverage, could have a material adverse effect on our business, reputation, operating results and financial condition.
Environmental / Social - Risk 3
The adoption of interoperability standards and regulations regarding information blocking could have unexpected consequences for our business.
With the passing of the MACRA in 2015, the U.S. Congress declared it a national objective to achieve widespread exchange of health information through interoperable certified EHR technology nationwide by December 31, 2018. The 21st Century Cures Act ("Cures Act"), which was passed and signed into law in December 2016, includes provisions related to data interoperability, information blocking and patient access. In May 2020, ONC and CMS finalized and issued complementary rules that are intended to clarify provisions of the Cures Act regarding interoperability and information blocking, and include, among other things, requirements surrounding information blocking, changes to ONC's health IT certification program and requirements that CMS-regulated payors make relevant claims/care data and provider directory information available through standardized patient access and provider directory application programming interfaces ("APIs") that connect to provider EHRs. The companion rules will transform the way in which healthcare providers, health IT developers, health information exchanges/health information networks ("HIEs/HINs"), and health plans share patient information, and create significant new requirements for healthcare industry participants. For example, the ONC rule, which went into effect on April 5, 2021, prohibits healthcare providers, health IT developers of certified health IT, and HIEs/HINs from engaging in practices that are likely to interfere with, prevent, materially discourage, or otherwise inhibit the access, exchange or use of electronic health information ("EHI"), also known as "information blocking." To further support access and exchange of EHI, the ONC rule identifies eight "reasonable and necessary activities" as exceptions to information blocking activities, as long as specific conditions are met. From April 5, 2021, developers of EHRs and other health IT products, such as us, are subject to the "information blocking" condition of certification under the ONC rule, which includes a number of new certification and maintenance of certification requirements that have to be met in order to maintain approved federal government certification status. Meeting and maintaining this certification status will require additional development costs. We have made and continue to make investments in building data interoperability capabilities, and continue to evaluate the potential impact of the CMS and ONC final rules, and we anticipate significant impacts from the new information blocking rules. We also expect expanded surveillance by federal agencies of certified HIT and its use by our customers. Under the Cures Act, the HHS has the regulatory authority to investigate and assess civil monetary penalties of up to $1,000,000 against certified health IT developers found to be in violation of "information blocking." Any failure to comply with these rules could have a material adverse effect on our business, results of operations and financial condition.
Environmental / Social - Risk 4
In connection with the operation of our business, we may collect, store, transfer, and otherwise process certain personal information and other sensitive and confidential data. As a result, our business is subject to a variety of governmental and industry regulations, as well as other obligations related to privacy, data protection and information security. Any actual or perceived failure to comply with such obligations could result in litigation, fines, penalties, increased costs or adverse publicity and reputational damage that may negatively affect the value of our business and decrease the market price of our common stock.
We receive, store and process personal information and other sensitive or confidential customer data. In addition, we receive, store, handle, transmit, use and otherwise process personal and business information and other data from and about actual and prospective customers, as well as our employees and service providers. A wide variety of state, national, and international laws and regulations apply to our collection, use, retention, protection, disclosure, transfer, and other processing of personal information, with oversight by governmental authorities, including the U.S. Federal Trade Commission ("FTC") and various state local and foreign agencies Our data processing activities are also subject to contractual obligations and industry standard requirements. The legislative and regulatory landscapes for privacy, data protection and information security continue to evolve in jurisdictions worldwide which could affect our business. Failure to comply with any of these laws or regulations could result in litigation, enforcement actions, damages, fines, penalties or adverse publicity and reputational damage, any of which could have a material adverse effect on our business, operating results and financial condition.
In the United States, various laws and regulations apply to the security, collection, processing, storage, use, disclosure and other processing of certain types of data, including, among others, the Electronic Communications Privacy Act, the Computer Fraud and Abuse Act, HIPAA, and state laws relating to privacy and data security. Additionally, the FTC and many state attorneys general have interpreted and are continuing to interpret federal and state consumer protection laws to impose standards for the online collection, use, dissemination, processing and security of data.
All states in which we operate have laws that protect the privacy and security of sensitive and personal data. Certain U.S. state laws may be more stringent or broader in scope, or offer greater individual rights, with respect to sensitive and personal information than international, federal, or other state laws, and such laws may differ from each other, which may complicate compliance efforts. For example, the CCPA, which came into force in 2020, gives California consumers expanded privacy rights and protections, including the right to access and delete certain personal information, opt-out of certain sales of personal information and receive detailed information about how their personal information is collected, used and shared. The CCPA provides for civil penalties for violations and a private right of action for data breaches. This private right of action has increased the likelihood of, and risks associated with, data breach litigation. While certain information that we maintain in our role as a "business associate" under HIPAA may be exempt from the CCPA, other personal information that we process outside of our role as a HIPAA business associate for or about California consumers may be subject to the CCPA. The expiration of the moratorium on January 1, 2023 on certain of the CCPA's requirements as applied to personal information of a business's employees and related individuals may increase our compliance costs and our exposure to public and regulatory scrutiny, costly litigation, fines and penalties.
Additionally, the California Privacy Rights Act (the "CPRA") came into force on January 1, 2023 and imposes additional obligations on companies covered by the legislation and significantly modifies the CCPA, including by expanding California residents' rights with respect to certain sensitive personal information. The CPRA also creates a new state agency that will be vested with authority to implement and enforce the CCPA and the CPRA. The interpretation and enforcement of the CCPA and many aspects of the CPRA remain unclear, and the effects of the CCPA and the CPRA are potentially significant. Provisions of the CCPA and CPRA may require us to modify our data collection or processing practices and policies and to incur substantial costs and expenses in an effort to comply and increase our potential exposure to regulatory enforcement and sanctions and litigation.
Certain other state laws impose similar privacy obligations, and all 50 states have laws including obligations to provide notification to affected individuals, state officers, and others in the event of security breaches involving unauthorized access to personal information. Further, the CCPA has prompted the enactment of several new state laws or amendments of existing state laws, which could mark the beginning of a trend toward more stringent privacy legislation in other U.S. states and which have prompted a number of proposals for new federal and state-level privacy legislation. This legislation, if passed, may add additional complexity, require additional investment of resources in compliance programs, adversely impact our business strategies and increase our potential liability. To the extent multiple state-level laws are introduced with inconsistent or conflicting standards and there is no federal law to preempt such laws, compliance with such laws could be difficult and costly to achieve and we could be subject to fines and penalties in the event of non-compliance.
We are also subject to certain obligations under HIPAA, as well as certain state laws and related contractual obligations concerning the privacy and security of medical or health-related information. Among other provisions, HIPAA imposes obligations on certain healthcare providers, health plans and healthcare clearing houses ("covered entities") relating to the privacy and security of PHI. Under HIPAA, before disclosing PHI to a service provider for a business purpose, the covered entity must enter into a written agreement with the service provider ("business associate") relating to HIPAA privacy and security requirements. In addition to our obligations under these agreements with our covered entity customers, we may also be directly liable for compliance with certain HIPAA provisions. Among other things, HIPAA requires business associates to: (1) maintain physical and technical and administrative safeguards to prevent PHI from misuse, (2) report security incidents and other inappropriate uses or disclosures of the information to the covered entity and (3) assist covered entities with certain of their duties under HIPAA, including responding to an individual's request to access, correct, restrict, or provide accounting of disclosures related to PHI that a covered entity, and an associated business associate, maintains about that individual. We have policies and safeguards in place intended to protect health information as required by HIPAA and have processes in place to assist us in complying with applicable laws and regulations regarding the protection of this data and responding to any security incidents. Ongoing implementation and oversight of these measures involves significant time, effort and expense and we may have to dedicate additional time and resources to ensure compliance with HIPAA requirements. In addition, HIPAA requirements, and enforcement priorities, are subject to change, which may expose us to additional regulatory scrutiny and increase our costs for compliance. For example, on December 10, 2020, the Office of Civil Rights ("OCR") within the Department of Health and Human Services ("HHS"), issued a Notice of Proposed Rulemaking ("NPRM"), which would, among other things, reduce the length of time for a covered entity to respond to an individual's right of access request.
For covered entities (i.e., certain of our customers), HIPAA mandates individual notification in instances of breaches of PHI and specifies that such notifications must be made "without unreasonable delay and in no case later than 60 calendar days after discovery of the breach," though many state breach notification laws require notifications to be provided sooner. If a breach affects 500 patients or more, it must be reported to HHS, without unreasonable delay, and HHS will post the name of the breaching entity on its public website. Breaches affecting 500 individuals or more in the same state or jurisdiction must also be reported to the local media. If a breach involves fewer than 500 people, the covered entity must record it in a log and notify HHS at least annually. In our role as a business associate, although HIPAA mandates only that the business associate provide notice of the breach of PHI to the covered entity, some of our customer agreements may require that we provide notifications to the affected individuals and regulators on the covered entity's behalf. Any notifications, including notifications to the public, could harm our business, financial condition, results of operations, and prospects.
Penalties for failure to comply with a requirement of HIPAA vary significantly depending on the failure and could include requiring corrective actions, resolution agreements, and/or imposing civil monetary or criminal penalties. HIPAA also authorizes state attorneys general to file suit under HIPAA on behalf of state residents. Courts can award damages, costs and attorneys' fees related to violations of HIPAA in such cases. While HIPAA does not create a private right of action allowing individuals to sue us in civil court for HIPAA violations, its standards have been used as the basis for a duty of care claim in state civil suits such as those for negligence or recklessness in the misuse or breach of PHI. In addition, many states in which we operate and in which our customers are located also have laws that protect the privacy and security of health information, many of which differ from each other in significant ways and often are not preempted by HIPAA, thus complicating compliance efforts. Where state laws are more protective, we have to comply with the stricter provisions. In addition to imposing fines and penalties upon violators, some of these state laws also afford private rights of action to individuals who believe their personal information has been misused, such as the CCPA.
Internationally, virtually every jurisdiction in which we operate has established its own data security, privacy and data protection legal frameworks with which our clients and partners must comply. For our clients and partners to comply with these various laws, rules, and regulations, our clients and partners may require us to enter into data processing agreements that may require us to implement certain privacy and data protection obligations. Failure to comply with and implement these contractual data protection obligations could result in breach of contract claims.
In particular, the EU General Data Protection Regulation and UK General Data Protection Regulation and UK Data Protection Act 2018 (together, the "GDPR") regulates transfers of personal data subject to the GDPR to third countries that have not been found to provide adequate protection for such personal data, including the United States. Under the GDPR, a data exporter must implement appropriate safeguards such as the Standard Contractual Clauses ("SCCs") approved by the European Commission (in the case of transfers from the European Economic Area ("EEA")) or by the Information Commissioner's Office (in the case of transfers from the UK) unless a specific derogation applies. Our clients or partners subject to the GDPR will need to comply with these requirements and may require us to enter into SCCs which require us to implement certain privacy obligations. Failure to implement these contractual obligations could result in breach of contract claims, expose us to third party beneficiary claims from data subjects, and to regulatory action by European data protection authorities. In July 2020 the European Court of Justice invalidated the EU-US Privacy Shield framework (an adequacy decision approved by the European Commission for transfers to the United States), which provided a mechanism for the transfer of data from European Union member states to the United States, on the grounds that the EU-US Privacy Shield failed to offer adequate protections to EU personal information transferred to the United States. The European Court also advised that SCCs were not alone sufficient to protect personal data transferred to the third countries such as the United States. Use of the data transfer mechanisms such as SCCs must now be assessed on a case-by-case basis by data exporters, with the assistance of data importers where required, taking into account the legal regime applicable in the destination country, in particular applicable surveillance laws and rights of individuals. Further, on June 4, 2021 the European Commission finalized new versions of the SCCs, which came into effect under the Implementing Decision on June 27, 2021 (the "New SCCs"). Under the Implementing Decision, organizations that rely on SCCs to transfer data had until December 27, 2022 to update any existing agreements, and must incorporate the New SCCs into new agreements. As a result of this continued legislative activity and to comply with the Implementing Decision and the new Standard Contractual Clauses, our clients and partners may require us to enter into the New SCCs which will require us to implement additional safeguards to further enhance the security of data transferred out of the EEA/UK, which could increase our compliance costs, expose us to further liability for any breach of contract claims and therefore adversely affect our business. We may also experience hesitancy, reluctance, or refusal by European or multi-national customers to continue to use our products due to the potential risk exposure to such customers as a result of shifting business sentiment in the EEA regarding international data transfers and the data protection obligations imposed on them. We may find it necessary to establish systems to maintain personal data originating from the EEA in the EEA, which may involve substantial expense and may cause us to need to divert resources from other aspects of our business, all of which may adversely affect our business. We and our customers may face a risk of enforcement actions taken by European data protection authorities until the time, if any, that personal data transfers to us and by us from the EEA are legitimized under European law.
Changing definitions of personal information and information may also limit or inhibit our ability to operate or expand our business, including limiting strategic partnerships that may involve the sharing of data. Also, some jurisdictions require that certain types of data be retained on servers within these jurisdictions. Our failure to comply with applicable laws, directives, and regulations may result in enforcement action against us, including fines, and damage to our reputation, any of which may have an adverse effect on our business and operating results. The scope and interpretation of the laws and regulations relating to privacy, data protection and information security that are or may be applicable to us are often uncertain and may be conflicting, as a result of the rapidly evolving regulatory framework for privacy issues worldwide. It is possible that these laws may be interpreted and applied in a manner that is inconsistent with our existing data management practices, solutions or capabilities. As a result of the laws that are or may be applicable to us, and due to the sensitive nature of the information we collect, we have implemented policies and procedures to preserve and protect our data and our platform users' data against loss, misuse, corruption, misappropriation caused by systems failures or unauthorized access. If our policies, procedures or measures relating to privacy, data protection, information security or the processing of data for marketing purposes or consumer communications fail to comply with laws, regulations, policies, legal obligations or industry standards, we may be subject to governmental enforcement actions, litigation, regulatory investigations, fines, penalties and negative publicity, and could cause our application providers, clients and partners to lose trust in us, and have an adverse effect on our business, operating results and financial condition.
In addition to government regulation, privacy advocates and industry groups may propose new and different self-regulatory standards that may apply to us. One example of such a self-regulatory standard is the PCI-DSS, which relates to the processing of payment card information. In the event we are required to comply with the PCI-DSS but fail to do so, fines and other penalties could result, and we may suffer reputational harm and damage to our business. Further, our customers may expect us to comply with more stringent privacy and data security requirements than those imposed by laws, regulations or self-regulatory requirements, and we may be obligated contractually to comply with additional or different standards relating to our handling or protection of data on or by our offerings. Because the interpretation and application of privacy, data protection and information security laws, regulations, rules and other standards are still uncertain, it is possible that these laws, rules, regulations and other actual or alleged legal obligations, such as contractual or self-regulatory obligations, may be interpreted and applied in a manner that is inconsistent with our existing data management practices or the functionality of our platform. If so, in addition to the possibility of fines, lawsuits and other claims, we could be required to fundamentally change our business activities and practices or modify our software, which could have an adverse effect on our business.
Further, any failure or perceived failure by us, or any third parties with which we do business, to comply with laws, regulations, policies (including our publicly posted privacy policies), procedures, measures, legal or contractual obligations, industry standards or regulatory guidance relating to privacy, data protection or information security may result in governmental investigations and enforcement actions, litigation, fines and penalties, or adverse publicity, and could cause our clients and partners to lose trust in us, which could have an adverse effect on our reputation, business, operating results and financial condition. We expect that there will continue to be new proposed laws, regulations and industry standards relating to privacy, data protection, information security, marketing and consumer communications, and we cannot predict the impact such future laws, regulations and standards may have on our business. Future laws, regulations, standards and other obligations or any changed interpretation of existing laws or regulations may be inconsistent among jurisdictions and may conflict with our current or future practices, which could impair our ability to develop and market new functionality and maintain and grow our client base and increase revenue. Future restrictions on the collection, use, processing, storage, sharing or disclosure of various types of data, including financial information and other personal data, or additional requirements for express or implied consent of our clients, partners or consumers for the collection, use, processing, storage, sharing and disclosure of such information could require us to incur additional costs or modify our platform, possibly in a material manner, and could limit our ability to develop new functionality. Complying with these requirements and changing our policies and practices may be onerous and costly, and we may not be able to respond quickly or effectively to regulatory, legislative and other developments.
If we are not able to comply with these laws or regulations, or if we become liable under these laws or regulations, we could be directly harmed, including through fines and litigation, and we may be forced to implement new measures to reduce our exposure to this liability. This may require us to expend substantial resources or to discontinue certain products, which would negatively affect our business, operating results and financial condition. In addition, the increased attention focused upon liability issues as a result of lawsuits and legislative proposals could harm our reputation or otherwise adversely affect the growth of our business. Furthermore, any costs incurred as a result of this potential liability could harm our operating results.
Ability to Sell
Total Risks: 9/78 (12%)Above Sector Average
Competition1 | 1.3%
Competition - Risk 1
We may face intense competition, which could limit our ability to maintain or expand market share within our industry, and if we do not maintain or expand our market share, our business, financial condition, and operating results will be harmed.
We may face intense competition, which could limit our ability to maintain or expand market share within our industry, and if we do not maintain or expand our market share our business, financial condition, and operating results will be harmed. The market for vertically tailored, customer engagement software and integrated payments is highly fragmented. We primarily compete with manual processes, point solution vendors, and legacy and modern solution providers. As costs fall and technology improves, increased market saturation may change the competitive landscape in favor of competitors with greater scale than we currently possess.
For our SimplePractice solution, we primarily compete against pen and paper, point solution vendors, and a number of horizontal and vertically specialized solutions, including practice management software providers. For our solutions in our Enterprise Solutions segment, we primarily compete against bill presentment and payment systems internally developed by financial institutions, as well as legacy and modern solution providers. Some of our competitors have greater name recognition, longer operating histories and significantly greater resources than we do. As a result, our competitors may be able to respond more quickly and effectively than we can to new or changing opportunities, technologies, standards, or customer requirements. In addition, current and potential competitors have established, and may in the future establish, cooperative relationships with vendors of complementary products, technologies or services to increase the availability of their products to the marketplace. Accordingly, new competitors or alliances may emerge that have greater market share, larger customer bases, more widely adopted proprietary technologies, greater marketing expertise, greater financial resources and larger sales forces than we have, which could put us at a competitive disadvantage.
Further, in light of these advantages, even if our solutions are more effective than the offerings of our competitors, current or potential customers might accept our competitors' offerings in lieu of purchasing our solutions.
We also compete on the basis of price. We may be subject to pricing pressures as a result of, among other things, competition within the industry, consolidation of our customers, government action, and financial stress experienced by our customers. If our pricing experiences significant downward pressure or clients acquire or develop competing solutions and services, our business will be less profitable and our results of operations will be adversely affected.
We cannot be certain that we will be able to retain our current customers or expand our customer base in this competitive environment. If we do not retain current customers or expand our customer base, or if we have to renegotiate existing contracts, our business, financial condition, and results of operations will be harmed. If one or more of our competitors or potential competitors were to merge or partner with another of our competitors, the change in the competitive landscape could also adversely affect our ability to compete effectively and could harm our business, financial condition, and results of operations.
Demand1 | 1.3%
Demand - Risk 1
Our business, financial condition, and results of operations depend substantially on our customers renewing their contracts for our solutions with us and expanding their use of our solutions. Any decline in our customer renewals or failure to convince our customers to broaden their use of solutions and related services would harm our business, results of operations, and financial condition.
Our solutions are term-based. In our Enterprise Solutions segment, the majority of our contracts are for three-year terms, but we have many contracts which must be renewed on a quarterly basis. In our SMB Solutions segment, substantially all of our contracts must be renewed on a monthly basis. In order for us to maintain or improve our results of operations, it is important that our customers do not terminate their contracts with us, renew their contracts with us when their terms expire, and renew on the same or more favorable terms. For our transaction-based arrangements, it is important that our customers process significant volume with us. Our customers have no obligation to renew their contracts with us, and we may not be able to accurately predict customer renewal rates. In addition, the growth of our business depends in part on our customers expanding their use of solutions. Historically, some of our customers have elected not to renew their contracts with us for a variety of reasons, including as a result of changes in their strategic information technology priorities, budgets, costs and, in some instances, due to competing offerings. Our renewal rates may also decline or fluctuate as a result of a number of other factors, including our customers' satisfaction or dissatisfaction with our solutions or our pricing, the effectiveness of our customer support services, mergers, acquisitions, dispositions, and other strategic transactions affecting our customer base, global economic conditions, and the other risk factors described herein. Our ability to sell additional functionality to our existing customers may require more sophisticated and costly sales efforts, especially for our larger customers with more senior management and established procurement functions. As a result, we cannot assure you that customers will renew their contracts with us or increase their usage of our solutions. If our customers do not renew their contracts with us or renew on less favorable terms or if we are unable to expand our customers' use of our solutions, our business, results of operations, and financial condition may be adversely affected.
Sales & Marketing6 | 7.7%
Sales & Marketing - Risk 1
If we are unable to attract new customers or convert trial customers into paying customers, our revenue growth and operating results will be adversely affected.
To increase our revenue, we must continue to attract new customers and increase sales to those customers. As our market matures, our solutions evolve, and competitors introduce lower cost or differentiated products or services that are perceived to compete with our solutions, our ability to sell our solutions could be impaired.
Similarly, our sales could be adversely affected if customers or users perceive that features incorporated into alternative products reduce the need for our solutions or if they prefer to purchase products that are bundled with offerings by other companies. Further, in an effort to attract new customers, we may offer simpler, lower-priced solutions, which may reduce our profitability.
We rely upon our marketing strategy, most significantly in our SimplePractice solution, of offering risk-free trials of our solutions, and other inbound, digital marketing strategies to generate sales opportunities. Converting these trial customers to paid customers often requires extensive follow-up and engagement. Many prospective customers never convert from the trial version of our solutions to a paid version of our solutions. Further, we often depend on individuals within an organization who initiate the trial versions of our solutions being able to convince decision makers within their organization to convert to a paid version. To the extent that these users do not become, or are unable to convince others to become, paying customers, we will not realize the intended benefits of this marketing strategy, and our ability to grow our revenue, particularly in our SMB Solutions segment, will be adversely affected. As a result of these and other factors, we may be unable to attract new customers, which would have an adverse effect on our business, revenue, gross margins, and operating results.
Sales & Marketing - Risk 2
We derive most of our revenue from InvoiceCloud and SimplePractice.
We derive most of our revenue from our InvoiceCloud and SimplePractice solutions, which comprised, in the aggregate, over 90% and 88% of our revenue for the years ended December 31, 2022 and 2021, respectively. Our InvoiceCloud and SimplePractice solutions are sold in the highly competitive markets of billing/payments and healthcare, respectively, and there can be no assurance that we will be able to continue to compete effectively in such markets in the future. Because we derive a significant majority of our revenue from our InvoiceCloud and SimplePractice solutions, any material decline in revenue derived from those solutions would have a material adverse impact on our business, results of operations and financial condition.
Sales & Marketing - Risk 3
If we fail to offer high-quality customer support, if we experience complaints regarding our customer support or if our support is more expensive than anticipated, our business and reputation could suffer.
Customers rely on our customer support services to resolve issues and realize the full benefits provided by our solutions. High-quality support is also important to maintain and drive further adoption by our existing customers and their clients. Certain of our solutions provide customer support to customers primarily over email, with some additional support provided over chat and through our solutions. If we do not help our customers and their clients quickly resolve issues and provide effective ongoing support, or if our support personnel or methods of providing support are insufficient to meet the needs of our customers and their clients, our ability to retain customers, increase adoption by our existing customers and acquire new customers could suffer, and our reputation with existing or potential customers could be harmed. In addition, customer and client complaints or negative publicity about our customer service could diminish confidence in and use of our products or services. Effective customer service requires significant expenses, which, if not managed properly, could negatively impact our profitability. If we are not able to meet the customer support needs of our customers and their clients during the hours that we currently provide support, we may need to increase our support coverage and provide additional support by other means and methods, which may reduce our profitability.
Sales & Marketing - Risk 4
The healthcare industry, which we primarily serve through our SimplePractice and HealthPay24 solutions, is rapidly evolving and the market for technology-enabled services that empower healthcare consumers is relatively immature and unproven. If we are not successful in promoting the benefits of our solutions in this industry, our growth may be limited.
The market for our healthcare-related solutions, which we primarily serve through our SimplePractice and HealthPay24 solutions, is subject to rapid and significant changes. The market for technology-enabled services that empower healthcare consumers is characterized by rapid technological change, new product and service introductions, increasing patient financial responsibility, consumerism and engagement, the ongoing shift to value-based care and reimbursement models, and the entrance of non-traditional competitors. In addition, there may be a limited-time opportunity to achieve and maintain a significant share of this market due in part to the rapidly evolving nature of the healthcare and technology industries and the substantial resources available to our existing and potential competitors. The market for technology-enabled services that empower healthcare consumers is relatively new and unproven, and it is uncertain whether this market will achieve and sustain high levels of demand and market adoption.
In order to remain competitive, we are continually involved in a number of projects to compete with new market entrants by developing new services, growing our customer base and penetrating new markets. Some of these projects include the expansion of our integration capabilities with additional solutions. These projects carry risks, such as cost overruns, delays in delivery, performance problems and lack of acceptance by our customers. Our integration partners may also decide to develop and offer their own solutions that are similar to our own.
Our success depends on providing high-quality solutions that healthcare providers use to improve clinical, financial and operational performance and which are used and positively received by patients. If we cannot adapt to rapidly evolving industry standards, technology and increasingly sophisticated and varied healthcare provider and patient needs, our existing technology could become undesirable, obsolete or harm our reputation. For example, the COVID-19 pandemic rapidly accelerated the adoption of telehealth technology by healthcare providers, patients, employers, health plans and other health industry participants, and we expect the regulatory environment for virtual healthcare solutions to continue to evolve. We must continue to invest significant resources in our personnel and technology in a timely and cost-effective manner in order to enhance our existing solutions and introduce new high-quality solutions that existing customers and potential new customers will want. Our operating results would also suffer if our innovations are not responsive to the needs of our existing customers or potential new customers, are not appropriately timed with market opportunity, are not effectively brought to market or significantly increase our operating costs. If our new or modified product and service innovations are not responsive to the preferences of healthcare providers and their patients, emerging industry standards or regulatory changes, are not appropriately timed with market opportunity or are not effectively brought to market, we may lose existing customers or be unable to obtain new customers and our results of operations may suffer.
In addition, we have limited insight into trends that might develop and affect our business. We might make errors in predicting and reacting to relevant business, legal and regulatory trends and healthcare changes, which could harm our business. If any of these events occur, it could materially adversely affect our business, financial condition or results of operations.
Finally, our competitors may have the ability to devote more financial and operational resources than we can to developing new technologies and services, including services that provide improved operating functionality, and adding features to their existing service offerings. If successful, their development efforts could render our services less desirable, resulting in the loss of our existing customers or a reduction in the fees we generate from our solutions.
Sales & Marketing - Risk 5
If we fail to meet our service level commitments, we could be obligated to provide credits or refunds or face contract terminations, which could adversely affect our business, operating results and financial condition.
Certain of our agreements with our customers and partners contain service level commitments, including commitments regarding the accuracy of information and data we provide and how quickly we will respond to support inquiries. We have in the past, and may in the future, be unable to meet our stated service level commitments and/or suffer extended periods of unavailability or downtime. If we are unable to meet our stated service level commitments and/or suffer extended periods of unavailability or downtime, we may have to provide our customers and partners with service credits or refunds. In addition, certain customers could shift to using a different solution such that we would no longer be their exclusive payment provider and we could also face contract terminations, either of which would adversely affect our future revenue. Further, any extended service outages could adversely affect our reputation, revenue and operating results.
Sales & Marketing - Risk 6
Our revenue is sensitive to shifts in payment methods.
A majority of our revenue is derived from transaction and usage-based fees from our Enterprise and SMB Solutions segments, which are either absorbed by customers or paid by their clients, and the majority of bills paid through our solutions are paid via credit or debit cards. In general, we receive more revenue for card-based payments than for electronic check and ACH payments. Accordingly, if more clients start paying their bills through our solutions by electronic check, ACH or other payment methods with lower transaction fees, it could materially impact our operating results.
Brand / Reputation1 | 1.3%
Brand / Reputation - Risk 1
If we are not able to develop, maintain and enhance awareness of our brands, our business, results of operations and financial condition may be adversely affected.
We believe that developing, maintaining, and enhancing awareness of our brands in a cost-effective manner, particularly among existing partners and new partners who refer customers to us, is critical to achieving acceptance of our solutions and attracting new customers. Brand promotion activities may not generate customer awareness or increase revenue, and even if such activities do, any increase in revenue may not offset the expenses we incur in building our brands. For instance, our investments in our brands, particularly our relationships with our referral partners, and customer engagement and education may not generate a sufficient financial return. If we fail to successfully promote and maintain our brands, or continue to incur substantial expenses, we may fail to attract or retain customers necessary to realize a sufficient return on our brand-building efforts, or to achieve the widespread brand awareness that is critical for broad customer adoption of our solutions.
Production
Total Risks: 5/78 (6%)Above Sector Average
Employment / Personnel1 | 1.3%
Employment / Personnel - Risk 1
We rely on the performance of senior management team and highly skilled personnel; if we are unable to retain or motivate key personnel or hire, retain and motivate qualified personnel, our business would be harmed.
We believe our success has depended, and continues to depend, on the efforts and talents of our senior management team, and our highly skilled team members, including our sales personnel, customer services personnel and software engineers. We do not maintain key man insurance on any of our executive officers or key employees, except for our Chief Executive Officer. From time to time, there may be changes in our senior management team resulting from the termination or departure of our executive officers and key employees. Many members of our senior management team are employed on an at-will basis, which means that they could terminate their employment with us at any time. The loss of any of our senior management could adversely affect our ability to build on the efforts they have undertaken and to execute our business plan, and we may not be able to find adequate replacements. We cannot ensure that we will be able to retain the services of any members of our senior management.
Our ability to successfully pursue our growth strategy also depends on our ability to attract, motivate, retain and train other personnel. Competition for well-qualified personnel in all aspects of our business, including sales personnel, customer services personnel and software engineers, is intense. Our recruiting efforts focus on elite organizations and our primary recruiting competitors are well-known, high-paying technology companies. Our continued ability to compete effectively depends on our ability to attract new employees and to retain and motivate existing employees, and we may be unable to achieve our hiring or integration goals due to a number of factors, including, but not limited to, the challenge in remotely recruiting employees and adequately training them. New hires require significant training and time before they achieve full productivity, particularly in new or developing sales territories. Our recent hires and planned hires may not become as productive as quickly as we expect, and we may be unable to hire or retain sufficient numbers of qualified individuals in the future in the markets where we do business. If we fail to effectively manage our hiring needs and successfully integrate our new hires, or if we fail to effectively manage remote work arrangements, our efficiency and ability to meet our forecasts and our ability to maintain our culture, employee morale, productivity and retention could suffer, and our business, financial condition and results of operations could be materially adversely affected. If we do not succeed in attracting well-qualified employees or retaining and motivating existing employees, our business would be adversely affected.
Supply Chain3 | 3.8%
Supply Chain - Risk 1
We rely on Microsoft Azure and Amazon Web Services for a substantial portion of our computing, storage, data processing, networking, and other services. Any disruption of or interference with our use of Microsoft Azure, Amazon Web Services or other third-party services could adversely affect our business, financial condition, and results of operations.
We rely on Microsoft Azure and Amazon Web Services for a substantial portion of our computing, storage, data processing, networking, and other services. Any significant disruption of, or interference with, our use of Microsoft Azure or Amazon Web Services could adversely affect our business, financial condition, and results of operations. Microsoft Azure and Amazon Web Services have broad discretion to change and interpret the terms of service and other policies with respect to us, and those actions may be unfavorable to our business operations. Microsoft Azure and Amazon Web Services may also take actions beyond our control that could seriously harm our business, including discontinuing or limiting our access to one or more services, increasing pricing terms, terminating or seeking to terminate our contractual relationship altogether, or altering how we are able to process data in a way that is unfavorable or costly to us. Although we expect that we could obtain similar services from other third parties, if our arrangements with Microsoft Azure or Amazon Web Services were terminated, we could experience interruptions on our platform and in our ability to make our content available to users, as well as delays and additional expenses in arranging for alternative cloud infrastructure services. Any transition of the cloud services currently provided by Microsoft Azure or Amazon Web Services to another cloud provider would be difficult to implement and will cause us to incur significant time and expense.
Additionally, we are vulnerable to service interruptions experienced by Microsoft Azure, Amazon Web Services, and other providers, and we have in the past, and expect in the future, to experience interruptions, delays, or outages in service availability in the future due to a variety of factors, including infrastructure changes, human, hardware or software errors, hosting disruptions, and capacity constraints. Outages and capacity constraints could arise from a number of causes such as technical failures, natural disasters, fraud or security attacks. The level of service provided by these providers, or regular or prolonged interruptions in that service, could also affect the use of, and our users' satisfaction with, our solutions and could harm our business and reputation. In addition, hosting costs will increase as user engagement grows, which could harm our business if we are unable to grow our revenue faster than the cost of using these services or the services of other providers. Any of these factors could further reduce our revenue or subject us to liability, any of which could adversely affect our business, financial condition, and results of operations.
Supply Chain - Risk 2
Our use of international contractors subjects us to additional risks which could have an adverse effect on our business, operating results and financial condition.
While primarily all of our employees are based in the United States, we have attempted to control our operating expenses by utilizing lower cost contractors and third-parties in foreign locations such as Ukraine, Jamaica, South America, the European Union and Costa Rica and we may in the future expand our reliance on offshore labor to other countries. For example, we outsource certain of our call center operations to a third-party company in Jamaica. Countries outside of the United States may be subject to relatively higher degrees of political and social instability and may lack the infrastructure to withstand political unrest, such as the current situation with Ukraine and Russia or natural disasters. The occurrence of natural disasters, pandemics, such as COVID-19, or political or economic instability in these countries, including in light of the developing conflict between Russian and Ukraine, which has, on occasion, caused certain of our contractors to be displaced, could interfere with work performed by these labor sources, or could result in our having to replace or reduce these labor sources. Our vendors in other countries could potentially shut down suddenly for any reason, including financial problems or personnel issues. Such disruptions could decrease efficiency, increase our costs and have an adverse effect on our business or results of operations.
In addition, as a result of the ongoing conflict between Russia and Ukraine, we may experience other risks, difficulties and challenges in the way we conduct our business and operations generally. For example, there may be an increased risk of cybersecurity attacks due to the current conflict between Russia and Ukraine, including cybersecurity attacks perpetrated by Russia or others at its direction in response to economic sanctions and other actions taken against Russia as a result of its invasion of Ukraine. Any increase in such attacks on us or our third-party providers or other systems could adversely affect our network systems or other operations.
The practice of utilizing contractors based in foreign locations has come under increased scrutiny in the United States. Governmental authorities could seek to impose financial costs or restrictions on foreign companies providing services to customers or companies in the United States. Governmental authorities may attempt to prohibit or otherwise discourage us from sourcing services from offshore labor.
The U.S. Foreign Corrupt Practices Act of 1977, as amended, and other applicable anti-corruption laws and regulations prohibit certain types of payments by our employees, vendors and agents. Any violation of the applicable anti-corruption laws or regulations by us, our subsidiaries or our local agents could expose us to significant penalties, fines, settlements, costs and consent orders that may curtail or restrict our business as it is currently conducted and could have an adverse effect on our business, financial condition or results of operations.
Supply Chain - Risk 3
We depend on third-party payment processors to process bill payments made through our solutions and our business, operating results and reputation could be harmed if we experience service interruptions related to our payment processors or additional consolidation among payment processors increases prices.
We depend on third-party payment processors to process bill payments made through our solutions, including payments made by or though credit and debit cards, ACH transfers, eChecks and PayPal. The per-transaction settlement fees we pay under our agreements are significant. Rapid industry consolidation and reduced competition among payment processors could lead to higher settlement fees that we are not able to pass along to our customers. We also rely on payment processors to collect and store payment card information and provide certain fraud detection services. Our multi-year agreements with payment processors contain industry-standard terms and conditions, including technical requirements for the facilitation of payments and the settlement of transactions and chargebacks. These agreements also obligate us to comply with payment networks' security standards and guidelines, and to reimburse the payment processors for any fines they are assessed by payment networks as a result of any violations by us of the operating rules, procedures, and standards established by payment networks, such as Visa, Mastercard American Express, NACHA and INTERAC (the "Payment Network Rules").
If any of our third-party payment processors were to terminate their relationship with us or cease providing us or our customers with payment processing services, whether as a result of a failure by us to meet our contractual obligations or for other reasons, or if any of them were to refuse to renew its agreement with us on commercially reasonable terms, we would need to engage one or more alternate payment processors. In that case, we could experience service interruptions and incur significant expenses in transitioning to or arranging for replacement payment processing services. Such interruptions could also negatively impact our reputation and our relationships with existing or potential customers and partners, as well as, under certain contracts with our customers, cause us to become obligated to provide service credits or refunds under our service level commitments. Likewise, our third-party payment processors have in the past and may in the future experience outages that have and may cause the temporary loss of the ability to process transactions through our solutions. If any of our third-party payment processors fails to meet our standards and expectations, becomes compromised or suffers errors, outages or vulnerabilities, the ability to process transactions through our solutions may be interrupted or suspended until such issues have been remedied or we have engaged one or more alternate payment processors.
Costs1 | 1.3%
Costs - Risk 1
If the fees we charge are unacceptable to our customers or their clients, our business, operating results and financial condition could be harmed.
We generate a significant majority of our revenue by either charging customers fees on a per-transaction basis or on a subscription basis. As the market for our solutions mature, or as new or existing competitors introduce new solutions that compete with ours, we may experience pricing pressure and be unable to renew our agreements with existing customers or attract new customers at fee levels that are consistent with our pricing models and operating budget. Our pricing strategies for new products we introduce may prove to be unappealing to our customers, and our competitors could choose to bundle certain offerings that are competitive with ours and offer them at lower prices. If this were to occur, it is possible that we would have to change our pricing strategies or reduce our prices, which could harm our business, operating results and financial condition.
Further, particularly in our Enterprise Solutions segment, a portion of our revenue is generated from customers that elect to pass on transaction fees to clients in the form of convenience fees. In certain markets, such as utilities and municipalities, convenience fees are commonplace. Despite the fact that such fees are relatively standard, they are often met with negative client perception, which could lead to heightened regulatory scrutiny and further pricing pressure or the use of our service or revenue may decline if alternative payment approaches with lower costs to the customer and equal or better convenience emerge than our existing online bill payment and convenience fee monetization model.
Macro & Political
Total Risks: 3/78 (4%)Above Sector Average
Economy & Political Environment2 | 2.6%
Economy & Political Environment - Risk 1
We are subject to economic risk, the business cycles and credit risk of our customers, partners and their clients, and the overall level of consumer, business and government spending, which could negatively affect our business, operating results and financial condition.
Industries in which we operate depend heavily on the overall level of consumer, business and government spending. We are exposed to general economic conditions that affect consumer confidence, consumer spending, consumer discretionary income and changes in consumer purchasing habits. Global market and economic conditions have been and continue to be, disrupted and unstable. A sustained deterioration in general economic conditions in the markets in which we operate or increases in interest rates may adversely affect our financial performance by reducing the number or average payment amounts of transactions made using electronic bill payments, reducing the number of customers that use our SimplePractice solution, and reducing other types of transactions through our solutions. Relatedly, a reduction in the amount of consumer spending could result in a decrease in our revenue and profit. For example, if our customers present fewer bills to clients using electronic billing or clients making electronic bill payments spend less per transaction, we will have fewer transactions relying on our solutions or lower transaction amounts, each of which would contribute to lower revenue. Additionally, in our SimplePractice solution, despite the cost benefits that we believe our practice management solutions provide, prospective practitioner customers may delay contract decisions or be reluctant to make any material changes in their established business methods based upon the economic climate. With a reduction in tax revenue, state and federal government healthcare programs, including reimbursement programs such as Medicaid or initiatives under the ACA, may be reduced or eliminated, which could negatively impact the payments that our practitioner customers receive. These developments could have a material adverse impact on our business, operating results and financial condition.
Further downturns in the economy could force our customers or partners or their clients to close or declare bankruptcy, resulting in lower revenue and earnings for us and greater exposure to potential credit losses and future transaction declines. We have a certain amount of fixed and other costs, including rent and salaries, which limits our ability to quickly adjust costs and respond to changes in our business and the economy. We are also subject to the risks of inflation, which may increase our costs, and we may not be able to charge more for our solutions to offset the increase in costs. Changes in economic conditions could also adversely affect our future revenue and profit and cause a materially adverse effect on our business, operating results and financial condition.
Economy & Political Environment - Risk 2
Healthcare reform efforts in the U.S. are highly dynamic, subject to frequent change, and can be interpreted and enforced differently by new administrations, which can adversely affect our business.
Many of the federal healthcare reform initiatives of the last decade have impacted us and our healthcare practitioner customers and continue to evolve. The American Reinvestment & Recovery Act ("ARRA"), passed in 2009, included the Health Information Technology for Economic and Clinical Health ("HITECH Act"). The HITECH Act introduced an incentive program linked to the "meaningful use" of EHR technology, an effort led by the CMS and the Office of the National Coordinator for Health IT ("ONC"). The ACA, passed in 2010, extended these incentive payments.
Currently, our SimplePractice solution includes an electronic medical records service that is not certified as EHR technology and we do not have a current intention to cause the certification of such solution. If we decide in the future to certify our EHR technology, we will need to comply with various standards and specifications that will be subject to change and to interpretation by the entities designated to certify our electronic healthcare technology. Additionally, if our services are not compliant with these evolving regulatory requirements, our market position and sales could be impaired, and we may have to invest significantly in changes to our solutions. Further, we could bear financial risk if we are alleged to have not appropriately complied with these regulations, even if the allegations are untrue.
The MACRA, enacted on April 16, 2015, established a new payment framework, called the Quality Payment Program, which modifies certain Medicare payments under the Medicare Physician Fee Schedule to "eligible clinicians," including physicians and other practitioners. Under MACRA, eligible clinicians must participate in either the Merit-Based Incentive Payment System ("MIPS") or Advanced Alternative Payment Model ("Advanced APM"). MIPS generally consolidates three programs: the Physician Quality Reporting System, the Value-based Payment Modifier program, and the Medicare EHR incentive program. Under this consolidated system, eligible clinicians report on metrics related to quality, clinical practice improvement activities and the use of certified EHR technology. Eligible clinicians may receive a positive or negative payment adjustment based on their reported metrics as compared to their peers. Eligible clinicians are not required to participate in MIPS if they are part of an Advanced APM, which can include certain accountable care organizations and other new payment models. CMS has structured these programs to incentivize clinicians to join Advanced APMs instead of participating in MIPS, though its results to date have been mixed. As such, the implications of MACRA and MIPS are uncertain and will depend on future regulatory activity and healthcare provider activity in the marketplace. If in the future we decide to position our solutions for MACRA and MIPS, compliance with applicable standards will need to be continuously monitored, and there can be no assurances that we will be able to maintain such standards and compliance. Any failure to successfully adapt our solutions either to MACRA and MIPS, or to the shift towards Advanced APMs and other value-based payment models, could have a material effect on our business, results of operations and financial condition.
Government programs, such as MIPS, have been implemented to accelerate the adoption and utilization of EHRs. Changes to government incentive programs related to EHRs could materially impact healthcare providers' decisions to implement EHR systems or have other impacts that would be unfavorable to our business.
There have been and continue to be a number of legislative initiatives to contain healthcare costs. By way of example, the ACA made a number of substantial changes in the way healthcare is financed by both governmental and private insurers. Since its enactment, there have been judicial, executive and Congressional challenges to certain aspects of the ACA, and on June 17, 2021, the U.S. Supreme Court dismissed the most recent judicial challenge to the ACA brought by several states without specifically ruling on the constitutionality of the ACA. Prior to the Supreme Court's decision, President Biden had issued an executive order relating to the ACA, including an instruction to certain governmental agencies to review and reconsider their existing policies and rules that limit access to healthcare. It remains unclear how healthcare reform measures enacted by Congress or implemented by the Biden administration or other challenges to the ACA, if any, will impact the ACA. Additional state and federal healthcare policies and reform measures adopted in the future could have a material adverse impact on our customers and, as a result, our operational results or the manner in which we operate our business.
Natural and Human Disruptions1 | 1.3%
Natural and Human Disruptions - Risk 1
The COVID-19 pandemic could have a material adverse impact on our employees, customers, partners, clients and other key stakeholders, which could materially and adversely impact our business, operating results and financial condition.
The COVID-19 pandemic continues to evolve, with pockets of resurgence and the emergence of variant strains contributing to continued uncertainty about its scope, duration, severity, trajectory, and lasting impact. The COVID-19 pandemic and efforts to control its spread have significantly curtailed the movement of people, goods and services in the United States, where we generate substantially all of our revenue, and worldwide, where we may target future growth. It has also caused extreme societal, economic and financial market volatility, resulting in business shutdowns and a global economic downturn. The magnitude and duration of the COVID-19 pandemic and the magnitude and duration of its effect on business activity cannot be predicted with any certainty. In addition, as the COVID-19 pandemic subsides, we cannot predict how our business may be impacted.
In light of the uncertainty relating to the spread of COVID-19, we have taken precautionary measures intended to reduce the risk of the virus spreading to our employees, customers and partners, such as implementing remote working capabilities and previously temporarily eliminated corporate travel to comply with various state policies and restrictions, and we may take further precautionary measures as needed. These precautionary measures and policies could negatively impact employee productivity, training and collaboration or otherwise disrupt our business operations. In addition, such restrictions could impact certain of our sales efforts, marketing efforts and implementations, adversely affecting the effectiveness of such efforts in some cases and potentially inhibiting future growth.
Our customers and partners were impacted and will continue to be impacted by the COVID-19 pandemic, which ultimately affects our business operations and results. The impact of COVID-19 differed across the verticals we serve. For our solutions in our SMB Solutions segment, practitioners accelerated adoption of our practice management software as they transitioned to virtual healthcare. Our pre-built features like telehealth, online scheduling, AutoPay, and secure messaging proved to be invaluable to our customers. For our solutions in our Enterprise Solutions segment, COVID-19 accelerated adoption of our online and automatic payment features, and we were able to provide customers the digital engagement and electronic payment capabilities they needed to serve their clients. On the other hand, certain solutions experienced a slowdown in usage at the onset of the COVID-19 pandemic. For example, elective procedures and nonessential hospital visits were delayed or canceled, and charities and nonprofits were unable to host large, in-person events given shelter-in-place policies. These headwinds were partially offset by our ability to offer digital engagement, such as virtual fundraising and online donations, which enabled our customers to continue hosting events.
Further, the extent and duration of working remotely exposes us, customers, partners and others with whom we have business relationships to increased risks of security breaches or incidents. The increase in remote working may also result in privacy, data protection, data security, and fraud risks, and our understanding of applicable legal and regulatory requirements, as well as the latest guidance from regulatory authorities in connection with the COVID-19 pandemic, may be subject to legal or regulatory challenge, particularly as regulatory guidance evolves in response to pandemic-related developments. Furthermore, we may need to enhance the security of our solutions, our data and our internal information technology infrastructure, which may require us to expend additional resources and may not be successful.
More generally, the COVID-19 pandemic has adversely affected economies and financial markets globally, potentially leading to a prolonged economic downturn, which could decrease technology spending, lengthen sales and implementation cycles, and adversely affect demand for our products and harm our business and operating results. The COVID-19 pandemic may delay, or prevent us from making collections and disrupt our ability to develop or enhance offerings. As the COVID-19 pandemic persists, government authorities and companies may continue to implement or reimpose restrictions or policies that could adversely impact consumer spending and payment volumes, global capital markets, the global economy and the market price of our common stock.
See a full breakdown of risk according to category and subcategory. The list starts with the category with the most risk. Click on subcategories to read relevant extracts from the most recent report.
FAQ
What are “Risk Factors”?
Risk factors are any situations or occurrences that could make investing in a company risky.
The Securities and Exchange Commission (SEC) requires that publicly traded companies disclose their most significant risk factors. This is so that potential investors can consider any risks before they make an investment.
They also offer companies protection, as a company can use risk factors as liability protection. This could happen if a company underperforms and investors take legal action as a result.
It is worth noting that smaller companies, that is those with a public float of under $75 million on the last business day, do not have to include risk factors in their 10-K and 10-Q forms, although some may choose to do so.
How do companies disclose their risk factors?
Publicly traded companies initially disclose their risk factors to the SEC through their S-1 filings as part of the IPO process.
Additionally, companies must provide a complete list of risk factors in their Annual Reports (Form 10-K) or (Form 20-F) for “foreign private issuers”.
Quarterly Reports also include a section on risk factors (Form 10-Q) where companies are only required to update any changes since the previous report.
According to the SEC, risk factors should be reported concisely, logically and in “plain English” so investors can understand them.
How can I use TipRanks risk factors in my stock research?
Use the Risk Factors tab to get data about the risk factors of any company in which you are considering investing.
You can easily see the most significant risks a company is facing. Additionally, you can find out which risk factors a company has added, removed or adjusted since its previous disclosure. You can also see how a company’s risk factors compare to others in its sector.
Without reading company reports or participating in conference calls, you would most likely not have access to this sort of information, which is usually not included in press releases or other public announcements.
A simplified analysis of risk factors is unique to TipRanks.
What are all the risk factor categories?
TipRanks has identified 6 major categories of risk factors and a number of subcategories for each. You can see how these categories are broken down in the list below.
1. Financial & Corporate
Accounting & Financial Operations - risks related to accounting loss, value of intangible assets, financial statements, value of intangible assets, financial reporting, estimates, guidance, company profitability, dividends, fluctuating results.
Share Price & Shareholder Rights – risks related to things that impact share prices and the rights of shareholders, including analyst ratings, major shareholder activity, trade volatility, liquidity of shares, anti-takeover provisions, international listing, dual listing.
Debt & Financing – risks related to debt, funding, financing and interest rates, financial investments.
Corporate Activity and Growth – risks related to restructuring, M&As, joint ventures, execution of corporate strategy, strategic alliances.
2. Legal & Regulatory
Litigation and Legal Liabilities – risks related to litigation/ lawsuits against the company.
Regulation – risks related to compliance, GDPR, and new legislation.
Environmental / Social – risks related to environmental regulation and to data privacy.
Taxation & Government Incentives – risks related to taxation and changes in government incentives.
3. Production
Costs – risks related to costs of production including commodity prices, future contracts, inventory.
Supply Chain – risks related to the company’s suppliers.
Manufacturing – risks related to the company’s manufacturing process including product quality and product recalls.
Human Capital – risks related to recruitment, training and retention of key employees, employee relationships & unions labor disputes, pension, and post retirement benefits, medical, health and welfare benefits, employee misconduct, employee litigation.
4. Technology & Innovation
Innovation / R&D – risks related to innovation and new product development.
Technology – risks related to the company’s reliance on technology.
Cyber Security – risks related to securing the company’s digital assets and from cyber attacks.
Trade Secrets & Patents – risks related to the company’s ability to protect its intellectual property and to infringement claims against the company as well as piracy and unlicensed copying.
5. Ability to Sell
Demand – risks related to the demand of the company’s goods and services including seasonality, reliance on key customers.
Competition – risks related to the company’s competition including substitutes.
Sales & Marketing – risks related to sales, marketing, and distribution channels, pricing, and market penetration.
Brand & Reputation – risks related to the company’s brand and reputation.
6. Macro & Political
Economy & Political Environment – risks related to changes in economic and political conditions.
Natural and Human Disruptions – risks related to catastrophes, floods, storms, terror, earthquakes, coronavirus pandemic/COVID-19.
International Operations – risks related to the global nature of the company.
Capital Markets – risks related to exchange rates and trade, cryptocurrency.