phr-20260131
Table of Contents
UNITED STATES
SECURITIES AND EXCHANGE COMMISSION
Washington, DC 20549
(Mark One)
For the fiscal year ended January 31, 2026
OR
For the transition period from _ to _
Commission File Number: 001-38977
PHREESIA, INC.
(Exact Name of Registrant as Specified in Its Charter)
(Address of Principal Executive Offices) (Zip Code)
(888) 654-7473
(Registrant’s Telephone Number, Including Area Code)
Securities registered pursuant to Section 12(b) of the Act:
Title of each class Trading Symbol Name of each exchange on which registered
Common stock, $0.01 par value per share PHR The New York Stock Exchange
Securities registered pursuant to Section 12(g) of the Act:
None
Indicate by check mark if the registrant is a well-known seasoned issuer, as defined in Rule 405 of the Securities Act. Yes☒ No ☐
Indicate by check mark if the registrant is not required to file reports pursuant to Section 13 or Section 15(d) of the Act. Yes ☐No☒
Indicate by check mark whether the registrant (1) has filed all reports required to be filed by Section 13 or 15(d) of the Securities Exchange Act of 1934 during the preceding 12 months (or for such shorter period that the registrant was required to file such reports), and (2) has been subject to such filing requirements for the past 90 days. Yes☒ No ☐
Indicate by check mark whether the registrant has submitted electronically every Interactive Data File required to be submitted pursuant to Rule 405 of Regulation S-T (§ 232.405 of this chapter) during the preceding 12 months (or for such shorter period that the registrant was required to submit such files). Yes☒ No ☐
Indicate by check mark whether the registrant is a large accelerated filer, an accelerated filer, a non-accelerated filer, a smaller reporting company, or an emerging growth company. See the definitions of “large accelerated filer”, “accelerated filer”, “smaller reporting company”, and “emerging growth company” in Rule 12b-2 of the Exchange Act.
Emerging growth company ☐
If an emerging growth company, indicate by check mark if the registrant has elected not to use the extended transition period for complying with any new or revised financial accounting standards provided pursuant to Section 13(a) of the Exchange Act. ☐
Indicate by check mark whether the Registrant has filed a report on and attestation to its management’s assessment of the effectiveness of its internal controls over financial reporting under Section 404(b) of the Sarbanes-Oxley Act (15 U.S.C. 7262(b)) by the registered public accounting firm that prepared or issued its audit report.Yes☒ No☐
If securities are registered pursuant to Section 12(b) of the Act, indicate by check mark whether the financial statements of the registrant included in the filing reflect the correction of an error to previously issued financial statements.☐
Indicate by check mark whether any of those error corrections are restatements that required a recovery analysis of incentive-based compensation received by any of the registrant’s executive officers during the relevant recovery period pursuant to §240.10D-1(b). ☐
Indicate by check mark whether the registrant is a shell company (as defined in Rule 12b-2 of the Act). Yes ☐ No ☒
The aggregate market value of the common stock held by non-affiliates of the registrant, based on the closing price of a share of common stock on July 31, 2025, the last business day of the registrant’s most recently completed second fiscal quarter, as reported by the New York Stock Exchange on such date was approximately $1,541,348,304. This calculation does not reflect a determination that certain persons are affiliates of the registrant for any other purpose.
As of March 25, 2026, there were 60,763,065 shares of the registrant’s common stock, par value $0.01 per share, outstanding.
1 Phreesia, Inc. is a fully remote company and no longer maintains its principal executive office. The address listed here is the mailing address that we maintain. For purposes of compliance with applicable requirements of the Securities Act of 1933, as amended, and
Securities Exchange Act of 1934, as amended, stockholder communications required to be sent to our principal executive offices should
be directed to the email address set forth in our proxy materials and/or identified on our investor relations website.
DOCUMENTS INCORPORATED BY REFERENCE
Portions of the registrant’s Definitive Proxy Statement relating to its 2026 Annual Meeting of Stockholders to be filed hereafter are incorporated by reference into Part III of this Annual Report on Form 10-K where indicated.
1
Table of Contents
Table of Contents
PART I.
Item 1. Business 7
Item 1A. Risk Factors 14
Item 1B. Unresolved Staff Comments 48
Item 1C. Cybersecurity 48
Item 2. Properties 49
Item 3. Legal Proceedings 50
Item 4. Mine Safety Disclosures 50
PART II.
Item 6. Reserved 53
Item 7A. Quantitative and Qualitative Disclosures about Market Risk 73
Item 8. Financial Statements and Supplementary Data 75
Item 9A. Controls and Procedures 133
Item 9B. Other Information 134
Item 9C. Disclosure Regarding Foreign Jurisdictions that Prevent Inspections 135
PART III.
Item 10. Directors, Executive Officers and Corporate Governance 136
Item 11. Executive Compensation 136
Item 14. Principal Accountant Fees and Services 136
PART IV.
Item 15. Exhibits, Financial Statement Schedules 137
2
Table of Contents
Summary of Material Risks Associated with our Business
Our business is subject to numerous risks and uncertainties that you should be aware of in evaluating our business. These risks and uncertainties include, but are not limited to, the following:
•We operate in a highly competitive industry, and if we are not able to compete effectively, including with the electronic health records ("EHR") and practice management ("PM") systems with which we integrate, our business and results of operations may be harmed.
•If we fail to manage our future growth effectively, our revenue may not increase, and we may be unable to implement our business strategy.
•Our operating results have fluctuated and may continue to fluctuate significantly, and if we fail to meet the expectations of analysts or investors, our stock price and the value of your investment could decline substantially.
•Privacy concerns, cyber-attacks, data breaches or cybersecurity incidents relating to our solutions could result in economic loss, damage to our reputation, deterring users from using our products, and our exposure to legal penalties and liability.
•Our operations in India subject us to additional risks which could have an adverse effect on our business, operating results, and financial condition.
•We typically incur significant upfront costs in our client relationships, and if we are unable to develop or grow these relationships over time, we are unlikely to recover these costs and our operating results may suffer.
•As a result of our variable sales and implementation cycles, we may be unable to recognize revenue to offset expenditures, which could result in fluctuations in our quarterly results of operations or otherwise harm our future operating results.
•The estimates and assumptions we use to determine the size of our target market may prove to be inaccurate, and even if the markets in which we compete meet our size estimates and forecasted growth, our business may not grow at similar rates, or at all.
•We depend on our senior management team and certain key employees, and the loss of one or more of our executive officers or key employees or an inability to attract and retain highly skilled employees could adversely affect our business.
•We have made, and may in the future make, acquisitions and investments which may be difficult to integrate, divert management resources, result in unanticipated costs or dilute our stockholders.
•We are a fully remote company, which subjects us to unique operational risks.
•We are subject to healthcare laws and data privacy and security laws and regulations governing our collection, use, disclosure, storage and transmission of personally identifiable information, including protected health information and payment card data, which may impose restrictions on us and our operations, require us to change our business practices and put in place additional compliance mechanisms, and subject us to fines, penalties, lawsuits, adverse publicity, reputational harm, loss of client trust or government enforcement actions if we are unable to fully comply with such laws.
•We rely on our third-party contractors, vendors and partners, including some outside of the United States, to execute our business strategy. Replacing them could be difficult and disruptive to our business. If we are unsuccessful in forming or maintaining such relationships on terms favorable to us, our business may not succeed.
•Artificial intelligence presents risks and challenges that can impact our business, including by increasing competition, posing security risks to our confidential information, proprietary information and personal data, and increasing our regulatory and compliance burden.
•The growth of our business relies, in part, on the growth and success of our clients and certain revenues from our engagements, which is difficult to predict and is subject to factors outside of our control.
The summary risk factors described above should be read together with the text of the full risk factors below in the section titled "Risk Factors" and in the other information set forth in this Annual Report on Form 10-K, including our consolidated financial statements and the related notes, as well as in other documents that we file with the U.S. Securities and Exchange Commission (the "SEC"). If any such risks and uncertainties actually occur, our business, prospects, financial condition and results of operations could be materially and adversely affected. The risks summarized above or described in full below are not the only risks that we face. Additional risks and uncertainties not currently known to us, or that we currently deem to be immaterial may also materially adversely affect our business, prospects, financial condition and results of operations.
3
Table of Contents
SPECIAL NOTE REGARDING FORWARD-LOOKING STATEMENTS
This Annual Report on Form 10-K, including the sections entitled “Business,” “Risk Factors,” and “Management’s Discussion and Analysis of Financial Condition and Results of Operations,” contains express or implied statements that are not historical facts and are considered forward-looking statements within the meaning of Section 27A of the Securities Act of 1933, as amended, and Section 21E of the Securities Exchange Act of 1934, as amended (the “Exchange Act”). Forward-looking statements involve substantial risks and uncertainties. Forward-looking statements generally relate to future events or our future financial or operating performance and may contain projections of our future results of operations or of our financial information or state other forward-looking information. In some cases, you can identify forward-looking statements by the following words: “may,” “will,” “could,” “would,” “should,” “expect,” “intend,” “plan,” “anticipate,” “believe,” “estimate,” “predict,” “project,” “potential,” “continue,” “ongoing,” or the negative of these terms or other comparable terminology, although not all forward-looking statements contain these words.
Although we believe that the expectations reflected in these forward-looking statements are reasonable, these statements relate to future events or our future operational or financial performance, and involve known and unknown risks, uncertainties, and other factors that may cause our actual results, performance, or achievements to be materially different from any future results, performance, or achievements expressed or implied by these forward-looking statements. Forward-looking statements contained in this Annual Report on Form 10-K include, but are not limited to, statements about:
•our future financial performance, including our revenue, cash flows, costs of revenue and operating expenses;
•our ability to integrate operations or realize any anticipated operational or corporate synergies and other benefits of the AccessOne Acquisition;
•the rapidly evolving industry and the market for technology-enabled services in healthcare in the United States being relatively immature and unproven;
•our reliance on a limited number of clients for a substantial portion of our revenue;
•our anticipated growth and growth strategies and our ability to effectively manage that growth;
•our ability to maintain and grow positive net income and our ability to maintain and grow positive Adjusted EBITDA;
•the sufficiency of our cash, cash equivalents and investments to meet our liquidity needs;
•our potential competition with our customers or partners;
•our existing clients not renewing their existing contracts with us, renewing at lower fee levels or declining to purchase additional applications from us;
•our failure to adequately maintain our direct sales force, impeding our growth;
•our ability to recover the significant upfront costs in our customer relationships;
•liability arising from our collection, use, disclosure, or storage of sensitive data collected from or about patients;
•our reliance on third-party vendors, manufacturers and partners to execute our business strategy;
•the impact of privacy concerns, data breaches or other cybersecurity incidents on our business operations, financial performance and results of operations;
•the uncertainty and ongoing flux of the regulatory and political framework, including potential regulatory, judicial, and legislative changes or developments resulting from the U.S. federal government or other factors;
•our ability to comply with laws and regulations;
•our ability to determine the size of our target market;
•the impact of market volatility, including the inflationary and interest rate environment, economic slowdowns and recessions, and other global financial, economic and political events, on our business and our ability to attract, retain and cross-sell to healthcare services clients;
•our ability to obtain, maintain and enforce intellectual property for our technology and products;
•our ability to incorporate artificial intelligence (“AI”) into our operations and products, while protecting data privacy and against cybersecurity threats;
4
Table of Contents
•our inability to implement our solutions for clients resulting in loss of clients and reputation;
•our dependency on our key personnel, and our ability to attract, hire, integrate, and retain key personnel, including as a result of being a fully remote company;
•the possibility that we may become subject to future litigation and the expected outcome of any ongoing litigation matters;
•our indebtedness and contractual obligations;
•our expectations regarding trends in our key metrics and revenue from subscription fees from our healthcare services clients, payment solutions fees and fees charged to life sciences companies and other organizations for delivering direct communications to help activate, engage and educate patients about topics critical to their health;
•our ability to meet our objectives regarding our operations in India; and
•other risks and uncertainties, including those listed under the section titled "Risk Factors."
We caution you that the foregoing list may not contain all of the forward-looking statements made in this Annual Report on Form 10-K. You should not rely upon forward-looking statements as predictions of future events. We have based our forward-looking statements primarily on our current expectations and projections about future events and trends that we believe may affect our business, financial condition, results of operations and prospects. The outcome of the events described in these forward-looking statements is subject to risks, uncertainties and other factors, including, without limitation, those described in the section titled “Risk Factors” in this Annual Report on Form 10-K.
Moreover, we operate in a very competitive and rapidly changing environment. New risks and uncertainties emerge from time to time and it is not possible for us to predict all risks and uncertainties that could have an impact on the forward-looking statements contained in this Annual Report on Form 10-K. We cannot assure you that the results, events and circumstances reflected in these forward-looking statements will be achieved or occur, and actual results, events or circumstances could differ materially from those described in the forward-looking statements.
The forward-looking statements contained in this Annual Report on Form 10-K speak only as of the date on which the statements are made. We undertake no obligation to update, and expressly disclaim the obligation to update, any forward-looking statements made in this Annual Report on Form 10-K to reflect events or circumstances after the date of this Annual Report on Form 10-K or to reflect new information or the occurrence of unanticipated events, except as required by law. We may not actually achieve the plans, intentions or expectations disclosed in our forward-looking statements and you should not place undue reliance on our forward-looking statements.
This Annual Report on Form 10-K includes statistical and other industry and market data that we obtained from industry publications and research, surveys and studies conducted by third parties. Industry publications and third-party research, surveys and studies generally indicate that their information has been obtained from sources believed to be reliable, although they do not guarantee the accuracy or completeness of such information. We have not independently verified the information contained in such sources.
NOTE REGARDING COMPANY REFERENCES
Unless the context otherwise requires, the terms “Phreesia,” “the Company,” “we,” “us,” and “our” in this Annual Report on Form 10-K refer to Phreesia, Inc.
5
Table of Contents
6
Table of Contents
PART I
Item 1. Business
Overview
Phreesia, Inc. ("Phreesia," "we," "our," or the "Company") was founded in 2005 and completed its initial public offering in July 2019. Phreesia provides an integrated software, payments, and engagement platform designed to address three foundational challenges in healthcare delivery: access to care, affordability of care, and patient health outcomes. Our platform is embedded directly into provider workflows and patient interactions, enabling healthcare organizations to activate patients, streamline administrative processes, and improve financial performance across the care continuum.
We serve a diverse group of healthcare organizations including ambulatory practices, health systems, and hospitals, as well as life sciences companies, government entities, patient advocacy, public interest and not-for-profit and other organizations. Our solutions support the patient journey from care discovery and scheduling through intake, payment, and post-visit follow-up. In fiscal year 2026, our platform facilitated approximately 180 million patient visits, representing approximately one in six ambulatory patient visits in the United States.
In fiscal year 2026, we completed the acquisition (the “AccessOne Acquisition”) of AccessOne Parent Holdings, Inc. (together with its subsidiaries, “AccessOne”), which expands our addressable market for healthcare payments. Our payment solutions now offer healthcare providers a trusted, scalable, compliant and operationally efficient healthcare payment card that accelerates cash flow.
Revenue
We generate revenue through a diversified model that includes three revenue streams: subscription and related services; payment solutions (previously labeled payment processing fees), which include payment processing fees and financing fees; and Network Solutions, which provides a channel for life sciences companies and other organizations to deliver compliant, personalized engagement to patients and providers who use our solutions.
Our business model provides meaningful visibility into future revenue, as our revenue is primarily derived from recurring subscription fees and re-occurring payment processing fees and financing fees. Subscription and related services revenue is relatively consistent throughout the fiscal year due to the recurring nature of our contracts. Payment solutions revenue is typically higher during the first two to three months of the calendar year, driven in part by the resetting of patient deductibles. Network Solutions revenue is primarily generated through annual contracts priced on a per-engagement basis, supported by closed-loop reporting and third-party measurement, and is typically higher in the second half of our fiscal year, reflecting life sciences marketing budget cycles. Phreesia creates high-intent engagement opportunities delivered at critical moments in the care journey.
Our Platform and Solutions
Phreesia’s integrated platform is designed to address challenges patients and healthcare providers face in three core areas: Access, Affordability, and Outcomes.
Access
Phreesia’s solutions facilitate access to care by reducing friction in how patients find, schedule, and register for care, while enabling providers to improve capacity utilization and reduce administrative burden.
Key capabilities include care discovery and scheduling through MediFind, our online provider directory, and self-scheduling tools; appointment optimization and referral management using AI-enabled workflows; and our AI-based smart answering solution for patient communications supported by voice and messaging solutions.
Affordability
Phreesia’s solutions directly address affordability challenges and improve the patient experience while helping providers improve collections, accelerate cash flow, and reduce revenue cycle friction.
7
Table of Contents
Capabilities include eligibility and cost transparency tools, integrated payment solutions embedded in intake and post-visit workflows, and financing solutions that enable healthcare organizations to accelerate cash collections while offering flexible payment options to patients.
Outcomes
Phreesia’s solutions are designed to improve patient outcomes by promoting patient engagement, treatment adherence and satisfaction, while enabling healthcare stakeholders, including providers and life sciences organizations, to measure and influence patient behavior in a compliant and scalable manner.
Capabilities include digital intake and clinical data capture, patient engagement and activation tools, and measurement and analytics solutions.
Market Opportunity
We estimate our total addressable market at approximately $24 billion, consisting of the potential $6.3 billion of subscription and related services revenue generated from the approximately 1.4 million U.S.-based healthcare services organizations who take medical appointments in ambulatory care settings and healthcare service providers who work in hospital settings, (2) the estimated potential $9.1 billion of financing fees, consumer-related transaction and payment processing fees, which are based on a percentage of payments that we process through our platform and address approximately $95.0 billion of annual out of pocket patient spend in ambulatory healthcare related professional services, (3) an estimated potential $8.2 billion in Network solutions revenue, based on projections of healthcare provider marketing spend, direct-to-consumer point-of-care marketing spend and other digital, direct-to-consumer life sciences marketing spend. We believe several industry trends support continued growth in our addressable markets, including increased adoption of digital patient intake and administrative workflow solutions, the transition toward value-based care models that incentivize patient engagement, expanded use of technology solutions across healthcare specialties and provider settings, and increasing patient financial responsibility and related affordability challenges.
Technology and Artificial Intelligence
Our platform is built on a scalable, cloud-enabled architecture designed to support healthcare interoperability and security, and regulatory requirements. We integrate with most major electronic medical record and practice management systems.
We increasingly incorporate artificial intelligence (“AI”) into our solutions and leverage AI to support automation, personalization, analytics, and operational efficiency, including AI-enabled communications, data extraction, campaign forecasting, and software development productivity.
Privacy and security
Privacy and security are our top priorities. We maintain a comprehensive security program designed to safeguard the confidentiality, integrity and availability of our clients’ data. In particular, we deploy physical, administrative and technical controls to appropriately safeguard patient information. We use external security auditors and industry-leading vendors to ensure we have the controls and procedures in place to protect our clients’ sensitive information. We have industry certifications, including HITRUST, PCI-DSS Level 1 Service Provider, Systems and Organization Controls 2 ("SOC 2") and PCI Point-to-Point Encryption. As a PCI-DSS Level 1 Service Provider, we are committed to upholding industry security standards to cardholder data.
We are committed to protecting and safeguarding the information and privacy of our clients and their patients. Our publicly available privacy policies provide detailed information regarding how we protect consumers’ data and the data subject rights of consumers. For more information regarding the privacy and security laws to which we are subject, and information about our cybersecurity risk management strategy and oversight, refer to “—Regulatory Matters” below and Item 1C. Cybersecurity in Part I of this Annual Report on Form 10-K.
Sales and Marketing
We market and sell our solutions using a direct sales organization, with dedicated sales and marketing teams for our healthcare services clients and our Network Solutions clients. Our go-to-market strategy focuses on maximizing total customer enterprise value through an integrated sales and customer success model. Incentives are aligned to overall customer value rather than individual product commissions, supporting land-and-expand growth across our customer base.
Most of our healthcare services customer contracts are structured as annual, auto-renewing agreements, while most of our Network Solutions campaigns have a term of one year and must be resold each year. Sales cycles vary
8
Table of Contents
by customer size and complexity. For healthcare services clients, sales cycles typically range from three to twelve months, and up to 18 months for financing contracts with large health systems. Network Solutions sales cycles align with annual life sciences marketing budget cycles, with contracts typically negotiated during the fourth quarter of the calendar year.
Competition
We operate in a competitive and evolving healthcare technology market that includes point solutions and broader platform providers. We face increasing competition from both established vendors and newer market entrants that are incorporating AI into patient access, intake, clinical support, and administrative workflow solutions. Some of these competitors may be able to develop or deploy AI-enabled products rapidly, which may increase competitive pressure in certain areas of our business. We believe we compete effectively based on the breadth of our platform, interoperability, scale of our provider and patient network, compliance-first engagement model, and ability to deliver measurable value.
Regulatory Matters
Our business is subject to extensive, complex and rapidly changing federal and state laws and regulations. Various federal and state agencies have discretion to issue regulations and interpret and enforce privacy and other laws applicable to businesses such as ours. While we routinely evaluate our legal positions under applicable healthcare, data privacy, security and other laws and regulations, these regulations can vary significantly from jurisdiction to jurisdiction, and interpretation and enforcement of existing laws and regulations can be uncertain or may change periodically. We cannot be assured that a review of our business by courts or regulatory authorities will not result in determinations that could adversely affect our operations or that the regulatory environment will not change in a way that restricts our operations. Federal and state legislatures also may enact various legislative proposals that could materially impact certain aspects of our business.
U.S. state and federal health information privacy and security laws
There are numerous U.S. federal and state laws and regulations related to the privacy and security of personally identifiable information, including protected health information. In particular, HIPAA establishes privacy and security standards that limit the use and disclosure of PHI, and requires the implementation of administrative, physical, and technical safeguards to ensure the confidentiality, integrity and availability of individually identifiable health information in electronic form. Many of our customers are regulated as covered entities under HIPAA. As a service provider that creates, receives, maintains or transmits PHI on behalf of our covered entity customers, Phreesia is a “business associate” as defined under HIPAA, and certain HIPAA requirements are directly applicable to business associates.
Violations of HIPAA may result in civil and criminal penalties and a single data breach can result in violations of multiple standards. We must also comply with HIPAA’s breach notification rule. Under the breach notification rule, business associates must notify covered entities of a breach, and those covered entities must notify affected individuals without unreasonable delay in the case of a breach of unsecured PHI, which may compromise the privacy, security or integrity of the PHI. In addition, notification must be provided to the U.S. Department of Health and Human Services (“HHS”), and, in cases where a breach affects more than 500 individuals, the local media. Breaches affecting fewer than 500 individuals must be reported to HHS on an annual basis. In the event of a breach, our covered entity customers may require that we provide assistance or request that we make these notifications on behalf of the covered entity in the breach notification process and may seek indemnification and other contractual remedies.
State attorneys general also have the right to prosecute HIPAA violations in their states. While HIPAA does not create a private right of action that would allow individuals to sue in civil court, its standards have been used as the basis for the duty of care in state civil suits, such as those for negligence or recklessness in misusing personal information. In addition, HIPAA tasks HHS with establishing a methodology whereby harmed individuals who were the victims of breaches of unsecured PHI may receive a percentage of the Civil Monetary Penalty fine paid by the violator. We expect a continued or increased level of federal and state HIPAA privacy and security enforcement efforts.
In recent years, federal and state regulators have increased their focus on the application of HIPAA and other privacy laws to the digital space and to technology companies, and states have adopted new statutes applicable to this area.
Beyond HIPAA, it is important to note that additional federal and state laws restrict the use and disclosure of personally identifiable information, particularly sensitive information such as individually identifiable health
9
Table of Contents
information. For example, the Federal Trade Commission (“FTC”) has advised that failing to take appropriate steps to keep consumers’ personal information private and secure may constitute an unfair act or practice in or affecting commerce in violation of Section 5(a) of the Federal Trade Commission Act (the “FTCA”). The FTC expects a company’s data privacy and security policies and practices to be reasonable and appropriate in light of the sensitivity and volume of consumer information it holds, the size and complexity of its business and the cost of available tools to improve security and reduce vulnerabilities. The FTC has initiated enforcement actions against entities in the health space that mislead consumers, make false or misleading statements in privacy policies, fail to limit third-party use of personal health information, fail to implement policies to protect personal health information or engage in other unfair practices that harm customers. We regularly review our privacy program in light of FTC guidance and enforcement actions and believe that our privacy standards are fair and transparent under the FTCA. However, in such an evolving regulatory space, there can be no assurances as to how future interpretations of law may affect our business.
Regulators and legislators in the United States are also increasingly scrutinizing and restricting certain personal data transfers and transactions involving foreign countries. For example, the Department of Justice’s January 8, 2025 rule, “Preventing Access to U.S. Sensitive Personal Data and Government-Related Data by Countries of Concern or Covered Persons,” prohibits data brokerage transactions involving certain sensitive personal data categories, including health data, genetic data, and biospecimens, to countries of concern, including China. The regulations also restrict certain investment agreements, employment agreements and vendor agreements involving such data and countries of concern, absent specified cybersecurity controls. Actual or alleged violations of these regulations may be punishable by criminal and/or civil sanctions, and may result in exclusion from participation in federal and state programs.
Many states also have laws that protect the privacy and security of personal information, including health information, and are, in many cases, not preempted by HIPAA and may be subject to varying interpretations by courts and government agencies. For example, the California Consumer Privacy Act (“CCPA”), as amended by the California Privacy Rights Act (“CPRA”), created individual privacy rights for California consumers (as defined in the law) and placed increased privacy and security obligations on entities handling personal data of consumers or households. The CCPA requires covered companies to provide certain disclosures to consumers about its data collection, use and sharing practices, and provides consumers with additional rights in their personal data, such as to have their data deleted and to opt-out of certain sales or transfers of personal information. While any information we maintain in our role as a business associate may be exempt from the CCPA, other records and information we maintain may be subject to the CCPA.
In addition to the CCPA, privacy and data security laws have been enacted in numerous other states, reflecting a trend toward more stringent privacy legislation in the U.S. Many of these laws are similarly comprehensive in scope to the CCPA, while other state laws, such as Washington’s My Health My Data Act or U.S. state biometric privacy laws, apply to distinct subsets of sensitive personal data. While these laws contain similarities, they may also impose additional and different requirements on businesses, and grant distinct privacy rights to consumers.
We expect that there will continue to be new proposed and amended laws, regulations and industry standards concerning privacy, data protection and information security in the U.S. at the state and federal level. Already in the U.S. we have witnessed significant developments at the state level. These new laws and proposed legislation have added additional complexity, variation in requirements, restrictions and potential legal risk, and required additional investment of resources in compliance programs and impact strategies. While we continue to evaluate the potential impact of new and proposed laws on our business, the application of such laws and their potential impact on our business is difficult to predict. In certain cases, it may become necessary to modify our planned operations and procedures to comply with more stringent state laws. The existence of privacy laws in different states in the country has increasingly made compliance obligations more complex and costly and may increase the likelihood that we may be subject to enforcement actions or otherwise incur liability for noncompliance. Not only may some of these state laws impose fines and penalties upon violators, but also some state laws, unlike HIPAA, may afford private rights of action to individuals who believe their personal information has been misused. In addition, state laws are changing rapidly, and there is discussion of a new federal privacy law to which we may be subject.
All 50 states have enacted laws requiring holders of personal information to maintain safeguards and to take certain actions in response to a data breach, such as providing prompt notification of the breach to affected individuals and state officials. In addition, under HIPAA and pursuant to the related contracts with our business associates, we must report breaches of unsecured PHI to our contractual partners following discovery of the breach. Notification must also be made in certain circumstances to affected individuals, federal authorities and others.
U.S. federal and state telecommunications laws
10
Table of Contents
There are number of U.S. federal and state laws and regulations that concern telephone calls, text messages and other telephonic communications to patients, potential patients, clients and potential clients.For example, the Telephone Consumer Protection Act (“TCPA”) is a federal statute that restricts certain calls and text messages to individuals.Some states, including Florida and Oklahoma, have mini-TCPA laws that restrict certain calls and text messages to their residents and mini-TCPA laws have been proposed in other state legislatures.Our call and text communications are or may be (or may become) subject to these laws.
U.S. federal contracting laws
Our subsidiary, Insignia Health, receives a portion of its revenue from customers that are governmental agencies or funded by government programs. As a federal government contractor, Insignia’s government contracts and subcontracts subject Insignia to the Federal Acquisition Regulation (“FAR”) and, among other requirements, the following: (a) termination when appropriated funding for the current fiscal year is exhausted; (b) termination for the governmental customer’s convenience, subject to a negotiated settlement for costs incurred and profit on work completed, along with the right to place contracts out for bid before completion of the full contract term, as well as the right to make unilateral changes in contract requirements, subject to negotiated price adjustments; (c) compliance and reporting requirements related to, among other things, agency-specific policies and regulations, information security, subcontracting requirements, equal employment opportunity, affirmative action for veterans and workers with disabilities and accessibility for the disabled; (d) broad audit rights; (e) specialized remedies for breach and default, including setoff rights, retroactive price adjustments and civil or criminal fraud penalties under the False Claims Act (as described below), re-procurement expenses, as well as mandatory administrative dispute resolution procedures instead of state contract law remedies; and (f) requirements to calculate overhead rates in accordance with the accounting procedures and internal controls required under the FAR standards.
U.S. federal and state fraud and abuse laws
We are subject to additional healthcare regulation by the federal government and by authorities in the states and foreign jurisdictions in which we conduct our business that may constrain our financial arrangements with third parties. Such laws include, without limitation, state and federal anti-kickback, fraud and abuse, false claims, and transparency laws and regulations and other transfers of value made to physicians and other healthcare providers. If our operations are found to be in violation of any of such laws or any other governmental regulations that apply, we may be subject to penalties, including, without limitation, administrative, civil and criminal penalties, damages, fines, disgorgement, the curtailment or restructuring of operations, integrity oversight and reporting obligations, exclusion from participation in federal and state healthcare programs and responsible individuals may be subject to imprisonment. Such laws and regulations include:
•the federal Anti-Kickback Statute, which prohibits, among other things, persons or entities from knowingly and willfully soliciting, receiving, offering or paying any remuneration (including any kickback, bribe or rebate), directly or indirectly, overtly or covertly, in cash or in kind, to induce, or in return for, the purchase, lease, order, arrangement, or recommendation of any good, facility, item or service for which payment may be made, in whole or in part, under a federal healthcare program, such as the Medicare and Medicaid programs. A person or entity does not need to have actual knowledge of this statute or specific intent to violate it to have committed a violation. In addition to statutory exceptions, the U.S. Department of Health and Human Services Office of Inspector General, or OIG, has enacted safe-harbor regulations that outline categories of activities that are deemed protected from prosecution under the Anti-Kickback Statute provided all applicable criteria are met. The failure of a financial relationship to meet all of the applicable safe harbor criteria does not necessarily mean that the particular arrangement violates the Anti-Kickback Statute. Violations are subject to civil and criminal fines and penalties for each violation, imprisonment, and exclusion from government healthcare programs. Moreover, the government may assert that a claim including items or services resulting from a violation of the Anti-Kickback Statute constitutes a false or fraudulent claim for purposes of the False Claims Act or federal civil monetary penalty laws;
•the federal civil and criminal false claims laws and civil monetary penalty laws, such as the federal False Claims Act, which impose criminal and civil penalties and authorize civil whistleblower or qui tam actions, against individuals or entities for, among other things: knowingly presenting, or causing to be presented, to the federal government, claims for payment that are false or fraudulent; knowingly making, using or causing to be made or used, a false statement or record material to a false or fraudulent claim or obligation to pay or transmit money or property to the federal government or knowingly concealing or knowingly and improperly avoiding or decreasing an obligation to pay money to the federal government. Companies can be held liable under the federal False Claims Act even when they do not submit claims directly to government payors if they are deemed to “cause” the submission of false or fraudulent claims. The federal False Claims Act also
11
Table of Contents
permits a private individual acting as a “whistleblower” to bring actions on behalf of the federal government alleging violations of the federal False Claims Act and to share in any monetary recovery;
•HIPAA, which created new federal criminal statutes that prohibit a person from knowingly and willfully executing, or attempting to execute, a scheme to defraud any healthcare benefit program or obtain, by means of false or fraudulent pretenses, representations or promises, any of the money or property owned by, or under the custody or control of, any healthcare benefit program, regardless of the payor (e.g., public or private) and knowingly and willfully falsifying, concealing or covering up by any trick or device a material fact or making any materially false, fictitious, or fraudulent statements or representations in connection with the delivery of, or payment for, healthcare benefits, items or services relating to healthcare matters; similar to the federal Anti-Kickback Statute, a person or entity does not need to have actual knowledge of the statute or specific intent to violate it in order to have committed a violation; and
•federal consumer protection and unfair competition laws, which broadly regulate marketplace activities and activities that potentially harm consumers.
Additionally, we are subject to state and foreign equivalents of each of the healthcare laws and regulations described above, among others, some of which may be broader in scope and may apply regardless of the payor. Many U.S. states have adopted laws similar to the federal Anti-Kickback Statute and False Claims Act, and may apply to our business practices, including, but not limited to, arrangements involving healthcare items or services reimbursed by non-governmental payors, including private insurers. There are ambiguities as to what is required to comply with these state requirements and if we fail to comply with an applicable state law requirement we could be subject to penalties.
U.S. federal and state financial services laws
Our payment solutions are subject to certain financial services laws, regulations and rules, as well as self-regulatory standards such as the Payment Card Industry Data Security Standards. We also must comply with card network rules set by the various card networks with which we are registered as a service provider (payment facilitator or the equivalent) for acquiring member institutions. If we or a client fail to comply with the applicable requirements of card networks, we could be subject to a variety of fines or penalties that may be levied by card networks. A violation of the network rules may result in the termination or suspension of our registration with the affected network. The termination of our registration, including a card network barring us from acting as a payment facilitator, or any changes in card network rules that would impair our registration, could require us to stop providing payment processing services relating to the affected card network.
Our payment solutions must comply with certain laws, including the U.S. Bank Secrecy Act (“BSA”), as amended by the USA PATRIOT Act of 2001 (“PATRIOT Act”), the Customer Due Diligence Rule, and the Anti-Money Laundering Act of 2020 (“AMLA”), which, among other things, contain anti-money laundering and financial transparency laws and mandate the implementation of various regulations applicable to all financial institutions, including standards for verifying client identification at account opening, and obligations to monitor client transactions and report suspicious activities.
Additionally, our subsidiary, AccessOne MedCard, offers medical financing products, which are subject to extensive and evolving federal and state consumer protection, fair lending and other laws and regulations, including the Truth in Lending Act, the Equal Credit Opportunity Act, the Fair Credit Billing Act, the Military Lending Act and the Servicemembers’ Civil Relief Act, among others, and rules promulgated by the Consumer Financial Protection Bureau (the “CFPB”). AccessOne MedCard is licensed or registered to engage in consumer lending in multiple states in the United States, subjecting it to extensive state regulatory oversight. For example, AccessOne MedCard must comply with consumer lending laws and regulations governing aspects of its operations, including disclosures, interest and fee limitations, and reporting obligations in each relevant state, creating significant compliance complexity and costs. AccessOne MedCard is also subject to certain federal and state regulations applicable to financial institutions related to cybersecurity and privacy, including the New York Department of Financial Services 23 NYCRR Part 500 Cybersecurity Requirements for Financial Services Companies (the “NYDFS Part 500 Requirements”) and the Graham-Leach-Bliley Act (the “GLBA”) and its implementing regulations, including Regulation P and the FTC Safeguards Rule, as well as the FTC’s Identity Theft Red Flags Rule under the Fair Credit Reporting Act. These regulations, among other things, require financial institutions to explain their information sharing practices to their customers, safeguard sensitive data and maintain an identity theft prevention program. Failure to comply with applicable state or federal requirements could result in regulatory investigations, enforcement actions, civil or criminal penalties, license suspension or revocation. State attorneys general may also exercise enforcement authority under both state and federal law.
Intellectual property
12
Table of Contents
Our continued growth and success depend, in part, on our ability to protect our intellectual property and proprietary technology. We primarily protect our intellectual property through a combination of trademarks, trade secrets and other contractual rights, including confidentiality, non-disclosure and assignment-of-invention agreements with our employees, independent contractors, consultants and companies with which we conduct business.
However, these intellectual property rights and procedures may not prevent others from creating a competitive SaaS solution or otherwise competing with us. We may be unable to obtain, maintain and enforce the intellectual property rights on which our business depends, and assertions by third parties that we violate their intellectual property rights could have a material adverse effect on our business, financial condition and results of operations.
Human Capital Resources
As of January 31, 2026, we had 1,789 full-time employees, including 502 in sales and marketing, 542 in research and development, 551 in services and support and 194 in general and administrative. As of January 31, 2026, we had 756 full-time employees in the United States and 1,033 full-time employees internationally. We also supplement our workforce with contractors and consultants, including a number of contractors and consultants in international locations. None of our employees are represented by labor unions or covered by collective bargaining agreements. We consider our relationship with our employees to be good, and we have not experienced any work stoppages.
Talent and Culture: The success and continued evolution of our company has been due in large part to the talent and engagement of our entire team. Our team members are key pillars of our success and fostering and developing their talent is central to our culture. Attracting and retaining top talent is a high priority for us, and we look to hire smart, passionate and driven individuals who want to be a part of our mission. Our strong company culture and investment in long-term career growth for our people is evidenced by the long tenure of many of our team members with our organization. During our fiscal year ended January 31, 2026, Phreesia was named to the 2025 Deloitte Technology Fast 500TM.Phreesia was also recognized on TIME’s 2025 World’s Top HealthTech Companies list. Additionally, Phreesia was named to G2’s 2025 Best Software Awards. Phreesia was also named one of Becker’s 2026 Top Places to Work in Healthcare. Phreesia was named to the list of "The Top 50 Software Companies of 2025" by The Software Report, our fourth year in a row on the list. Phreesia has also had representation on The Software Report's Top 50 Women Leaders in Software for the past eight years. All of these achievements optimally position us to continue to attract top healthcare and technology talent.
Access and Equal Opportunity: We are committed to hiring, developing and supporting an inclusive workplace. We seek to recruit employees of all backgrounds and support their professional development. We strive to make career paths, career development opportunities and mentorships available to all employees. We are also committed to supporting gender equality in our organization, including through our inclusive culture, board representation, pathways to leadership for women, pay equity and strong family-leave policies.
Remote Workforce: We have operated as a fully remote company since 2020, as we believe this arrangement allows us access to the best talent and creates optimal flexibility for our employees. We are intentional about building a remote-only culture that gives our employees a sense of meaning, connection and belonging, including through our mentorship program, town halls, regular in-person offsites and virtual activities.
Corporate Information
We are a fully remote company and do not maintain principal executive offices. Our mailing address is 1521 Concord Pike, Suite 301, PMB 221, Wilmington, DE 19803, and our telephone number is (888) 654-7473. Our website address is http://www.phreesia.com. We do not incorporate the information on or accessible through our website into this report, and you should not consider any information on, or that can be accessed through, our website as part of this report.
Available Information
Our Annual Report on Form 10-K, Quarterly Reports on Form 10-Q, Current Reports on Form 8-K, and all amendments to these filings, are available free of charge from our investor relations website at https://ir.phreesia.com as soon as reasonably practicable following our filing with or furnishing to the Securities and Exchange Commission, or SEC, of any of these reports. The SEC maintains an Internet website at https://www.sec.gov that contains reports, proxy and information statements, and other information regarding issuers that file electronically with the SEC.
Phreesia investors and others should note that we announce material information to the public about our company, products and services and other issues through a variety of means, including our website at https://www.phreesia.com, our investor relations website at https://ir.phreesia.com, press releases, SEC filings and public
13
Table of Contents
conference calls, in order to achieve broad, non-exclusionary distribution of information to the public. We also use the following social media channels as a means of disclosing information about the company, our solutions, our planned financial and other announcements and attendance at upcoming investor and industry conferences, and other matters and for complying with our disclosure obligations under Regulation FD:
PHREESIA X Account (https://x.com/phreesia)
PHREESIA Facebook Page (https://www.facebook.com/phreesia/)
PHREESIA LinkedIn Page (https://www.linkedin.com/company/phreesia)
PHREESIA Instagram Account (https://www.instagram.com/phreesia.co)
PHREESIA News Page (https://www.phreesia.com/news/)
PHREESIA Network Solutions X Account (https://x.com/phreesianetwork)
PHREESIA Network Solutions Facebook Page (https://www.facebook.com/phreesianetworksolutions/)
PHREESIA Network Solutions LinkedIn Page (https://www.linkedin.com/company/phreesia-network-solutions/)
PHREESIA Network Solutions Page (https://networksolutions.phreesia.com)
INSIGNIA Health website (https://www.insigniahealth.com/)
MEDIFIND website (https://www.medifind.com/)
ACCESSONE website (https://accessonepay.com/)
ACCESSONE LinkedIn Page (https://www.linkedin.com/company/accessone/)
We encourage our investors and others to review the information we make public in these locations as such information could be deemed to be material information. Please note that this list may be updated from time to time.
The contents of any website or social media channel referred to in this Annual Report on Form 10-K are not intended to be incorporated into this Annual Report on Form 10-K or in any other report or document we file with the SEC, and any references to our websites are intended to be inactive textual references only.
Item 1A. Risk Factors
Risk factors
A description of the risks and uncertainties associated with our business and industry is set forth below. You should carefully consider the risks and uncertainties described below, together with all of the other information in this Annual Report on Form 10-K, including our consolidated financial statements and notes thereto and the “Management’s discussion and analysis of financial condition and results of operations” section of this Annual Report on Form 10-K, before deciding whether to purchase shares of our common stock. If any of the following risks are realized, our business, financial condition, operating results and prospects could be materially and adversely affected. In that event, the price of our common stock could decline, perhaps significantly. Additional risks and uncertainties not presently known to us or that we currently deem immaterial also may impair our business operations. Certain statements in this Annual Report on Form 10-K are forward-looking statements. See the section of this Annual Report on Form 10-K titled “Special Note Regarding Forward-Looking Statements.”
Risks relating to our business and industry
We operate in a highly competitive industry, and if we are not able to compete effectively, including with the EHR and PM systems with which we integrate, our business and results of operations may be harmed.
The market for our solutions and services is fragmented, competitive and characterized by rapidly evolving technology standards, evolving regulatory requirements, changes in client needs and the frequent introduction of new products and services, including as a result of AI technologies. Our competitors range from smaller niche companies to large, well-financed and technologically-sophisticated entities, including the EHR and PM systems with which we integrate. As costs fall and technology improves, increased market saturation may change the competitive landscape in favor of competitors with greater scale than we currently possess, including as a result of new or better use of evolving AI technologies.
In order to remain competitive, we are continually involved in a number of projects to compete with new market entrants by developing new services, expanding offerings to our existing client base, growing our client base and penetrating new markets. These projects carry risks, such as cost overruns, delays in delivery, performance problems and lack of acceptance by our clients.
The success of our business and growth strategy depend upon our continued ability to maintain and expand a network of healthcare services clients, which also requires us to provide and develop new high-quality products and services that are helpful to our clients and used and positively received by patients. If we are unable to attract and retain healthcare services clients, including because we are unable to adapt to new industry standards in
14
developing new solutions and services, it would have a material adverse effect on our business and ability to grow and would adversely affect our results of operations. Additionally, if we do not maintain our current client network, or if we have to renegotiate existing contracts on terms less favorable to us, our business, financial condition and results of operations may be harmed.
We believe demand for our solutions and services has been driven in large part by increasing patient responsibility, engagement and consumerism. Our ability to streamline critical workflows in order to improve healthcare services clients’ operations and patient engagement to allow for optimal allocation of resources will be critical to our business. Our success also depends on the ability of our solutions to increase patient engagement, and our ability to demonstrate the value of our solutions to healthcare services clients, patients and life sciences companies. If our existing clients do not recognize or acknowledge the benefits of our solutions or our solutions do not drive patient engagement, then the market for our products and services might develop more slowly than we expect, which could adversely affect our operating results.
In addition, as we and the EHR and PM solutions with which we integrate, grow and expand product offerings, the EHR and PM solutions with which we integrate could offer more competitive services or make it more cost prohibitive to do business with them. Some of these EHR and PM systems offer, or may begin to offer, services, including patient intake and engagement services, payment processing tools, patient financing options and direct patient communication services, in the same or similar manner as we do. Although there are many potential opportunities for, and applications of, these services, these EHR and PM systems may seek opportunities or target new clients in areas that may overlap with those that we have chosen to pursue. Such competition from these EHR and PM systems may adversely affect our business, market share and results from operations.
We compete on the basis of several factors. Some of our competitors have greater name recognition, longer operating histories and significantly greater resources than we do. As a result, our competitors may be able to respond more quickly and effectively than we can to new or changing opportunities, technologies (including evolving AI technologies), standards or client requirements or provide faster implementations. Additionally, AI technologies may make it easier for competitors to enter our market due to lower up-front costs. As a result, even if our solutions are more effective than the products and services that our competitors offer, potential clients might select competitive products and services in lieu of purchasing our solutions. In addition, current and potential competitors have established, and may in the future establish, cooperative relationships with vendors of complementary products, technologies or services to increase the availability of their products to the marketplace. Accordingly, new competitors or providers of EHR and PM solutions may emerge that have greater market share, larger client bases, more widely adopted proprietary technologies, greater marketing expertise, new or better AI technologies, greater financial resources and larger sales forces than we have, which could put us at a competitive disadvantage and could render our existing or future products less competitive or obsolete. We also may be subject to pricing pressures as a result of, among other things, competition within the industry, consolidation of healthcare industry participants, practices of managed care organizations, government action and financial stress experienced by our clients. If our pricing experiences significant downward pressure, our business will be less profitable and our results of operations will be adversely affected. We cannot be certain that we will be able to retain our current client base in this competitive environment. If we do not retain current clients or expand our client base, or if we have to renegotiate existing contracts unfavorably, our business, financial condition and results of operations will be harmed. Moreover, we expect that competition will continue to increase as a result of consolidation in both the healthcare information technology and healthcare industries. If one or more of our competitors or potential competitors were to merge or partner with another of our competitors, the change in the competitive landscape could also adversely affect our ability to compete effectively and could harm our business, financial condition and results of operations.
If we fail to manage our future growth effectively, our revenue may not increase, and we may be unable to implement our business strategy.
We have experienced significant growth in the past. Rapid expansion has historically placed, and may in the future place, strain on our business, operations and employees. We anticipate that our operations will continue to expand. As we continue to grow, both organically and through acquisitions, we must effectively integrate, develop, and manage an increasingly distributed employee base in a fully remote working environment. We may find it challenging to maintain the same level of employee productivity while executing our growth plan, fostering collaboration, and maintaining the beneficial aspects of our culture, and any such failures could negatively affect our future success, including our ability to attract and retain highly qualified employees and to achieve our business objectives. If we do not manage the demands of our growing operations effectively, our efficiency may decline, our operations could be disrupted, and we may not be able to meet our financial projections, which could adversely affect our business performance and stock price.
15
In addition, to manage our current and anticipated future growth effectively, we must continue to maintain and enhance our IT infrastructure, financial and accounting systems and controls and continue to build our qualified workforce in key areas of our company. A key element of how we manage our growth is our ability to scale our capabilities and satisfactorily implement solutions for our clients’ needs. Our healthcare services clients often require specific features or functions unique to their organizational structure, which, at a time of significant growth or during periods of high demand, may strain our implementation capacity and hinder our ability to successfully implement our solutions for our clients in a timely manner. If we are unable to address the needs of our healthcare services clients or our healthcare services clients are unsatisfied with the quality of our solutions or our services due to our inability to manage our rapid growth, they may not renew their contracts, seek to cancel or terminate their relationship with us or renew on less favorable terms, any of which could adversely affect our business. Additionally, our ability to grow our financing business is in part dependent on our access to capital for the securitization of cardholder receivables. If we are unable to maintain or expand our access to capital on favorable terms or at all, we may be unable to offer our financing solutions to a greater number of existing or potential healthcare services clients.
Failure to effectively manage our growth could also lead us to over-invest or under-invest in development and operations, result in weaknesses in our infrastructure, systems or controls, give rise to operational mistakes, financial losses, loss of productivity or business opportunities and result in loss of employees and reduced productivity of remaining employees. If our management is unable to effectively manage our growth, our revenue may not increase (including sufficiently to offset our expenses) or may grow more slowly than expected, and we may be unable to implement our business strategy.
Our operating results have fluctuated and may continue to fluctuate significantly and if we fail to meet the expectations of analysts or investors, our stock price and the value of your investment could decline substantially.
Our operating results are likely to fluctuate, and if we fail to meet or exceed the expectations of securities analysts or investors, the trading price of our common stock could decline. Moreover, our stock price may be based on expectations of our future performance that may be unrealistic or that may not be met. Some of the important factors that could cause our revenues and operating results to fluctuate from quarter to quarter include:
•the timing, size and integration success of recent and potential future acquisitions, including the AccessOne Acquisition;
•the extent to which our products and services achieve or maintain market acceptance;
•our ability to introduce new products and services and enhancements to our existing products and services on a timely basis;
•new competitors and the introduction of enhanced products and services from new or existing competitors;
•the extent to which developments in AI may reduce demand for our solutions;
•the length of our contracting and implementation cycles;
•the financial condition of our current and potential clients;
•our ability to integrate our solutions with the systems utilized by our healthcare services clients, including but not limited to, EHR and PM systems;
•changes in client budgets and procurement policies;
•patients' desires to receive communications from Phreesia and/or our partners, the extent to which they opt-in to such communications, and our ability to deliver a consistent volume of such communications;
•amount and timing of our investment in research and development activities and other areas of our business;
•technical difficulties or interruptions in our services, like the one we experienced with ConnectOnCall in 2024;
•our ability to hire and retain qualified personnel;
•changes in the healthcare regulatory and policy environment;
•changes in healthcare, utilization and spending trends, including as a result of changes to healthcare policy and the One Big Beautiful Bill Act (“OBBBA”);
•regulatory compliance costs;
•unforeseen legal expenses, including litigation and settlement costs; and
•buying patterns of our clients and the related seasonality impacts on our business.
Many of these factors are not within our control, and the occurrence of one or more of them might cause our operating results to vary widely. As such, we believe that quarter-to-quarter comparisons of our revenues and operating results may not be meaningful and should not be relied upon as an indication of future performance.
16
A significant portion of our operating expense is relatively fixed in nature, and planned expenditures are based in part on expectations regarding future revenue. Accordingly, unexpected revenue shortfalls may decrease our margins and could cause significant changes in our operating results from quarter to quarter.
Privacy concerns, cyber-attacks, data breaches or cybersecurity incidents relating to our solutions could result in economic loss, damage to our reputation, deterrence of users from using our products, and exposure to legal penalties and liability.
We collect, process and store significant amounts of sensitive, confidential and proprietary information, including personally identifiable information, such as payment data and protected health information, of patients received in connection with the utilization of our solutions. Attacks on information technology systems are increasing in their frequency, levels of persistence, sophistication and intensity, they are being conducted by increasingly sophisticated and organized groups and individuals with a wide range of motives and expertise, and they may remain undetected for an extended period of time. For instance, as AI technologies, including generative AI models, develop rapidly, threat actors are using these technologies to create sophisticated new attack methods that are increasingly automated, targeted, coordinated and difficult to defend against. Like other companies in our industry, we, and our third-party vendors, have experienced threats and cybersecurity incidents relating to our information technology systems and infrastructure. For example, in 2024, we experienced a cybersecurity incident which impacted our ConnectOnCall product. Although we do not believe this, or any other cybersecurity incident, has had a material impact on our business to date, any interruption in our business or disclosure, loss, processing or other compromise of personal information or individually identifiable health information (implicating certain privacy laws such as the federal Health Insurance Portability and Accountability Act of 1996, as amended by the Health Information and Technology for Economic and Clinical Health Act (“HITECH Act”) and their implementing regulations, collectively referred to as “HIPAA”) or confidential information, or event that jeopardizes the confidentiality, integrity, or availability of our solutions, could result in a material disruption to our solutions and our business operations, require us to expend significant resources and subject us to litigation, fines and penalties. In addition to extracting sensitive information, such attacks could include the deployment of harmful malware, ransomware, denial-of-service attacks, social engineering fraud (including phishing attacks), and other means to affect service reliability and threaten the confidentiality, integrity and availability of information. While we maintain a security program that is designed to protect our products and such data, techniques used to gain unauthorized access to data and systems, disable or degrade service, or sabotage systems, are constantly evolving, and may be the result of criminal groups, state sponsored or other malicious actors. We may be unable to anticipate such techniques or implement adequate preventative measures to avoid unauthorized access or other adverse impacts to such data or our systems.
In addition, some of our third-party service providers and partners, such as Change Healthcare and other clearinghouses or vendors, also collect and/or store our sensitive information and our clients' data on our behalf, and these service providers and partners have in the past, and may in the future be subject to similar threats of cyber-attacks and other malicious internet-based activities, which could also expose us to risk of loss, litigation, and potential liability. Even though we may have contractual protections with such vendors, contractors, or other organizations, notifications and follow-up actions related to a cybersecurity incident or data breach could impact our reputation, cause us to incur significant costs, including legal expenses, harm client confidence, expose us to government enforcement action, hurt our expansion into new markets, cause us to incur remediation costs, or cause us to lose existing clients. The risk of state-supported and geopolitical-related cyber-attacks may increase in connection with political unrest or wars and any related political or economic responses and counter-responses. We may not discover all such cybersecurity incidents, data breaches, or other activity or be able to respond or otherwise address them promptly, in sufficient respects or at all.
We are subject to state laws requiring notification of affected individuals and state regulators in the event of a cybersecurity incident or breach of personal information. Furthermore, certain health privacy laws, data breach notification laws, consumer protection laws and genetic testing laws may apply directly to our business and/or those of our collaborators and may impose restrictions on our collection, use and dissemination of individuals’ health information. Patients about whom we obtain health information, as well as the healthcare services clients who share this information with us, may have statutory or contractual rights that limit our ability to use and disclose the information. Additionally, our subsidiary, AccessOne MedCard, Inc. (“AccessOne MedCard”) is subject to regulation and supervision of cybersecurity and data privacy matters by state and federal regulators, including state financial regulatory agencies, the FTC and the CFPB, including the NYDFS Part 500 Requirements, and the GLBA and Regulation P and the FTC Safeguards Rule, as well as the FTC’s Identity Theft Red Flags Rule under the Fair Credit Reporting Act, which, among other things, require financial institutions to explain their information sharing practices to their customers, safeguard sensitive data and maintain an identity theft prevention program. We may be required to expend significant capital and other resources to ensure ongoing compliance with applicable privacy and data security laws and regulatory requirements. Claims that we have violated individuals’ privacy rights, violated
17
applicable privacy laws and regulations or breached our contractual obligations, even if we are not found liable, could be expensive and time-consuming to defend and could result in adverse publicity that could harm our business, or enforcement and other supervisory actions. Our contracts may not contain limitations of liability, and even where they do, there can be no assurance that limitations of liability in our contracts are sufficient to protect us from liabilities, damages, or claims related to our privacy and data security obligations. Further, although we maintain cyber liability insurance, this insurance may not provide adequate coverage against potential liabilities related to any experienced cybersecurity incident or breach.
Like all internet services, our service, and the services of our third-party service providers, are vulnerable to software bugs, computer viruses, internet worms, break-ins, phishing attacks, attempts to overload servers with denial-of-service, wrongful or inadvertent conduct by insider employees or vendors, or other attacks or similar disruptions from unauthorized use of our and third-party computer systems, any of which could lead to system interruptions, delays, or shutdowns, causing loss of critical data or the unauthorized access of data. Though it is difficult to determine what, if any, harm may directly result from any specific interruption or attack, any failure to maintain performance, reliability, security and availability of our products, or failure to prevent software bugs, to the satisfaction of our clients or the health and safety of their patients, may harm our reputation and our ability to retain existing clients, and negatively affect our clients and their patients. We have in place systems and processes that are designed to protect our data, prevent data loss, disable undesirable accounts and activities on our platform and prevent or detect cybersecurity incidents or data breaches, however, we cannot assure you that such measures will provide absolute security.
Further, the security systems in place at our employees’ and service providers’ offices and homes may be less secure than those used in a corporate office, and while we have implemented technical and administrative safeguards to help protect our systems as our employees and service providers work from their offices, homes and other remote locations, we may be subject to increased cybersecurity risk, which could expose us to risks of data or financial loss, and could disrupt our business operations. There is no guarantee that the data security and privacy safeguards we have put in place will be completely effective or that we will not encounter risks associated with employees and service providers accessing company data and systems remotely. If an actual or perceived cybersecurity incident or data breach occurs to our systems or a third-party’s systems, such as one that affected our ConnectOnCall product in 2024, we also could be required to expend significant resources to mitigate the breach of security, pay any applicable fines and address matters related to any such breach, including notifying users or regulators, defend against claims related to the breach and address reputational harm.
Our operations in India subject us to additional risks which could have an adverse effect on our business, operating results, and financial condition.
We have a subsidiary in India that performs a number of functions that were previously performed by outside contractors. While we believe our Indian operations are advantageous to our business, they also create risks that we must effectively manage. Conducting business abroad subjects us to increased legal and regulatory compliance and oversight. A failure to comply with applicable laws and regulations could result in regulatory enforcement actions, as well as substantial civil and criminal penalties assessed against us and our employees. The management of our Indian operations has, and will continue to, require significant management attention and financial resources that could adversely affect our operating performance. Wages in India are increasing at a faster rate than those in many countries, including the United States. In addition, with the significant increase in the numbers of foreign businesses that have established operations in India, the competition to attract and retain employees there has increased significantly. As a result, we may be unable to cost-effectively retain our current employee base in India or hire additional new talent. In addition, India has experienced, and may in the future experience, significant inflation, low growth in gross domestic product and shortages of foreign exchange. India also has experienced civil unrest and terrorism and, in the past, has been involved in conflicts with neighboring countries which may escalate in the future. The occurrence of any of these circumstances could result in disruptions to our India operations, which, if continued for an extended period of time, could have a material adverse effect on our business.
Our operating expenses incurred outside the United States and denominated in foreign currencies would increase to the extent we expand our operations in India. Transactions denominated in foreign currencies are subject to fluctuations due to changes in foreign currency exchange rates. If we are not able to successfully hedge against the risks associated with foreign currency fluctuations, our financial condition and operating results could be adversely affected.
18
We typically incur significant upfront costs in our client relationships, and if we are unable to develop or grow these relationships over time, we are unlikely to recover these costs and our operating results may suffer.
We devote significant resources to establish relationships with new clients and deepen relationships with existing clients. Our efforts involve educating our clients and patients about the use, technical capabilities and benefits of our products and services. We do not provide access to our solutions and do not charge fees during this initial sales period. For healthcare services clients that decide to enter into a software subscription contract with us, most of these contracts may provide for a preliminary trial period where a subset of the client’s healthcare services locations is granted access to our solutions. Following any such trial period, we aim to increase the number of the client’s healthcare services locations that utilize our solutions. Accordingly, our operating results depend in substantial part on our ability to deliver a successful client and patient experience and persuade our clients to continue and grow their relationship with us over time. If we are unable to do so, we are unlikely to recover these costs and our operating results may suffer.
As a result of our variable sales and implementation cycles, we may be unable to recognize revenue to offset expenditures, which could result in fluctuations in our quarterly results of operations or otherwise harm our future operating results.
The sales cycle for our solutions can be variable, typically ranging from three to twelve months from initial contact to contract execution for healthcare services clients, and up to 18 months for financing contracts with large health systems. Network Solutions sales cycles align with annual life sciences marketing budget cycles, with contracts typically negotiated during the fourth quarter of the calendar year. During the sales cycle, we expend time and resources, and we do not recognize any revenue to offset such expenditures. Our implementation cycle is also variable, typically ranging from one to 24 months from contract execution to completion of implementation. The variability of our sales and implementation cycle is dependent on numerous factors, including the discretionary nature of potential clients' purchasing and budget decisions and the size and complexity of the applicable client. Some of our new client set-up projects are complex and require a considerable time commitment and significant implementation work, including educating prospective clients about the uses and benefits of our solutions. Each client’s situation is different, and unanticipated difficulties and delays may arise as a result of failure by us or by the client to meet our respective implementation responsibilities. During the implementation cycle, we expend substantial time, effort and financial resources implementing our service, but accounting principles do not allow us to recognize the resulting revenue until the service has been implemented, at which time we begin recognition of subscription and related implementation revenue over the life of the contract. This could harm our future operating results. If implementation periods are extended, our revenue cycle will be delayed and our financial condition may be adversely affected. In addition, cancellation of any implementation after it has begun may involve loss to us of time, effort and expenses invested in the cancelled implementation process and lost opportunity for implementing paying clients in that same period of time.
These factors may contribute to substantial fluctuations in our quarterly operating results, particularly during any period in which our sales volume is relatively low. As a result, in future quarters our operating results could fall below the expectations of securities analysts or investors, in which event our stock price would likely decrease.
The growth of our business relies, in part, on the growth and success of our clients and certain revenues from our engagements, which is difficult to predict and is subject to factors outside of our control.
We primarily generate three revenue streams. For example, we enter into agreements with our healthcare services clients, under which a significant portion of our fees are variable, including fees which are dependent upon the number of add-on features subscribed for by our clients and the number of patients utilizing our payment processing tools or financing services offered by our subsidiary, AccessOne MedCard. If there is a general reduction in spending by healthcare services organizations on healthcare technology solutions, it may result in a reduction in fees generated from our healthcare services clients or a reduction in the number of add-on features subscribed for by our healthcare services clients. This could lead to a decrease in our revenue, which could harm our business, financial condition and results of operations.
In addition, we generate revenue from payment processing fees based on patient payment volume and from financing fees that primarily consist of finance charges and servicing fees on cardholder receivables. The number of patients utilizing our payment processing tools or financing options offered by our subsidiary, AccessOne MedCard, and the amounts those patients pay directly to our healthcare services clients for services or choose to finance with extended payment plans, are often impacted by factors outside of our control. For example, macroeconomic conditions and changes in healthcare policy may decrease the number of insured patients and result in reduced healthcare utilization and spending. In addition to economic trends impacting overall healthcare spending, the CFPB
19
and various state attorneys general, state legislatures and state agencies have increased scrutiny of third-party providers of financing for medical services. State governments or specific healthcare institutions may review and amend criteria for charity care eligibility and may enact debt mitigation policies that expand the pool of patients qualifying for free or discounted care, reducing the amount of patient payments processed through our solutions or the demand for extended financing options offered by AccessOne MedCard. Accordingly, revenue under these agreements can be uncertain and unpredictable. If the number of patients utilizing our payment systems, or the aggregate amounts paid by such patients directly to our healthcare services clients through our solutions or financed through AccessOne MedCard, were to be reduced by a material amount, such decrease would lead to a decrease in our revenue, which could harm our business, financial condition and results of operations.
We also generate network solutions revenue through fees charged to life sciences companies and other clients by delivering direct communications to help activate, engage and educate patients who provide consent for the delivery of such communications about topics critical to their health. The growth of our revenue stream from life sciences companies and other clients is driven, in part, by our ability to grow our network of healthcare services clients and available population of patients to engage, the desirability of optional communications to patients, the number of newly approved drugs, the success of newly launched drugs, and the continued success of certain types of drugs, each of which is impacted by factors outside of our control. For example, governmental actions taken by the U.S. federal government, such as changes in the leadership of the FDA, mass layoffs within the federal government, and executive orders, legislation or rulemaking initiatives related to drug pricing and pharmaceutical marketing and advertising, have affected the ability of life sciences companies to successfully develop and market drugs. If there is a reduction or delay in newly approved drugs, newly launched drugs are not successful, certain drugs’ popularity or profitability decreases (including as a result of loss of patent exclusivity), or the ability to engage in drug marketing and advertising is restricted or limited, this could negatively affect the ability of our life sciences clients to deliver relevant messages to patients. As a result, our life sciences clients have taken, and may continue to take, actions such as decreasing marketing budgets, redirecting spend to other marketing channels, seeking more flexible contract terms and increasing expectations regarding campaign performance. Any of these factors could lead to a decrease in our network solutions revenue, which could harm our business, financial condition and results of operations.
If our existing clients are not satisfied with our services, it could have a material adverse effect on our business, financial condition, results of operations and reputation.
We depend on our existing clients’ satisfaction with our products and services. We expect to derive a significant portion of our revenue from renewal of existing clients’ contracts and sales of additional solutions and services to existing clients. As part of our growth strategy, we have focused on expanding our services amongst current clients. As a result, achieving a high client retention rate and selling additional solutions and services to existing clients are critical to our future business, revenue growth and results of operations. We also believe that maintaining and enhancing our reputation and brand recognition is critical to our relationships with existing clients and the patients that they serve and to our ability to attract new clients. The promotion of our brand may require us to make substantial investments, and we anticipate that, as our market becomes increasingly competitive, these marketing initiatives may become increasingly difficult and expensive. In addition, the loss or dissatisfaction of any client could substantially harm our brand and reputation, inhibit widespread adoption of our solutions and impair our ability to attract new clients.
Factors that may affect our client satisfaction and our ability to sell additional applications and services include, but are not limited to, the following:
•the price, performance and functionality of our solutions;
•patient acceptance and adoption of services and utilization of our payment processing tools and payment plans;
•the availability, price, performance and functionality of competing solutions;
•our ability to develop and sell complimentary solutions and services;
•our access to capital;
•the stability, performance and security of our hosting infrastructure and hosting services;
•changes in healthcare laws, regulations or trends;
•the business environment of our clients including healthcare staffing shortages and headcount reductions by our clients; and
•our ability to maintain and enhance our reputation and brand recognition.
We typically enter into annual contracts for our software solutions with our healthcare services clients, which have a stated initial term of one year and automatically renew for one-year subsequent terms. For most of our software solutions, our clients have no obligation to renew their subscriptions after the initial term expires. In addition, we
20
typically enter into annual contracts with our network solutions clients with a term of one year, which do not auto-renew and must be renegotiated annually. Our clients may negotiate terms less advantageous to us upon renewal, which may reduce our revenue from these clients and may decrease our annual revenue. Additionally, our financing contracts with healthcare services clients are “evergreen” contracts that allow termination for convenience. If our clients fail to renew their contracts, renew their contracts upon less favorable terms or at lower fee levels, terminate their contracts or fail to purchase new products and services from us, our revenue may decline or our future revenue growth may be constrained. Should any of our clients terminate their relationship with us after implementation has begun, we would not only lose our time, effort and resources invested in that implementation, but we would also have lost the opportunity to leverage those resources to build a relationship with other clients over that same period of time.
The estimates and assumptions we use to determine the size of our target market may prove to be inaccurate, and even if the markets in which we compete meet our size estimates and forecasted growth, our business may not grow at similar rates, or at all.
Market estimates and growth forecasts that we disclose are subject to significant uncertainty and are based on assumptions and estimates that may not prove to be accurate. The estimates and forecasts relating to the size and expected growth of the markets for our services may prove to be inaccurate. These estimates and forecasts may be impacted by economic uncertainty that is outside our control, including international conflicts that may impact international trade and global economic performance and other macroeconomic trends, such as tariffs and other trade restrictions and trade protection measures, capital market disruptions, changes in governmental agencies, economic sanctions, economic slowdowns or recessions, international and domestic supply chain risks, inflationary pressure, interest rate increases and declines in consumer confidence that impact our clients.
The principal assumptions relating to our market opportunity include the number of healthcare services organizations currently taking appointments, the amount of annual out of pocket consumer spend and out of pocket financed consumer spend for healthcare-related services, and the amount of annual spend by life sciences companies and other organizations on direct communications to patients at the point of care and to healthcare providers. Our market opportunity is also based on the assumption that the strategic approach that Phreesia enables for our potential clients will be more attractive in creating efficiencies in patient care than competing solutions. If these assumptions prove inaccurate, our business, financial condition and results of operations could be adversely affected.
If we cannot implement our solutions for clients or resolve any technical issues in a timely manner, we may incur costs in the form of service credits or other remedial steps and/or lose clients, and our reputation may be harmed.
Our clients utilize a variety of data formats, applications and infrastructure and we must support our clients’ data formats. Furthermore, the healthcare industry has shifted towards digitalized record keeping, and accordingly, many of our healthcare services clients have developed their own software, or utilize third-party software, for practice management and secure storage of electronic medical records. Our ability to develop and maintain logic-based and scalable technology for patient intake management and engagement, payment processing and financing that successfully integrates with our clients’ software systems for practice management and storage of electronic medical records is critical. If we do not currently support a client’s required data format or appropriately integrate with clients’ systems, then we must configure our solutions to do so, which could increase our expenses. Additionally, we do not control our clients’ implementation schedules. As a result, if our clients do not allocate the internal resources necessary to meet their implementation responsibilities or if we face unanticipated implementation difficulties, the implementation may be delayed. If the client implementation process is not executed successfully or if execution is delayed, we could incur significant costs, clients could become dissatisfied and decide not to increase utilization of our services or not to implement our solutions beyond an initial period prior to their term commitment or, in some cases, revenue recognition could be delayed. In addition, competitors with more efficient operating models with lower implementation costs could jeopardize our client relationships.
Our clients and patients depend on our support services to resolve any technical issues relating to our solutions and our services, and we may be unable to respond quickly enough to accommodate short-term increases in demand for support services, particularly as we increase the size of our client bases (including healthcare services clients and the number of patients that they serve). In addition, we may experience unexpected service interruptions due to cyber-attacks or other cybersecurity incidents or data breaches, such as one that affected our ConnectOnCall product in 2024. In such cases, we may be unable to restore service in a timely manner, if at all. We also may be unable to modify the format of our support services to compete with changes in support services provided by competitors. It is difficult to predict client and patient demand for technical support services, and if client or patient demand increases significantly, we may be unable to provide satisfactory support services to our clients. Further, if
21
we are unable to address the needs of our clients and their patients in a timely fashion or further develop and enhance our solutions, or if a client or patient is not satisfied with the quality of work performed by us or with the technical support services rendered, then we could incur additional costs to address the situation or be required to issue credits or refunds for amounts related to unused services, and our profitability may be impaired and clients’ or patients’ dissatisfaction with our solutions could damage our ability to expand the number of applications and services purchased by such clients. These clients may not renew their contracts, seek to terminate their relationships with us or renew on less favorable terms. Moreover, negative publicity related to our client and patient relationships, or regarding patient confidentiality and privacy in the context of technology-enabled healthcare, regardless of its accuracy, may further damage our business by affecting our reputation or ability to compete for new business with current and prospective clients. If any of these were to occur, our revenue may decline and our business, financial condition and results of operations could be adversely affected.
We historically derive a significant portion of our revenues from our largest clients.
Historically, we have relied on a limited number of clients for a substantial portion of our total revenue and accounts receivable. The sudden loss of any of our larger clients, or the renegotiation of any of their contracts on less favorable terms, could adversely affect our operating results. Because we rely on a limited number of clients for a significant portion of our revenues, we depend on the creditworthiness of these clients. If the financial condition of our larger clients declines, our credit risk could increase. Should one or more of our significant clients declare bankruptcy, it could adversely affect the collectability of our accounts receivable and affect our bad debt reserves and net income.
We have experienced net losses in the past and we may not maintain positive net income in the future.
We have incurred significant operating losses for most of our history. For the years ended January 31, 2026 and January 31, 2025, we had net income of $2.3 million and net loss of $58.5 million, respectively, and losses from operations of $6.6 million and $58.1 million, respectively. Our operating expenses may increase in the foreseeable future as we continue to invest to grow our business, including through acquisitions, and build relationships with our clients and partners, develop new solutions and operate as a public company. In addition, to the extent we are successful in increasing our client base, we could incur increased losses because significant costs associated with entering into client agreements are generally incurred up front, while revenue is generally recognized ratably over the term of the agreement. As a result, we may need to raise additional capital through equity and debt financings in order to fund our operations, which may not be available to us on favorable terms or at all. If we are unable to effectively manage these risks and difficulties as we encounter them or effectively access the capital markets, our business, financial condition and results of operations may suffer.
We depend on our senior management team and certain key employees, and the loss of one or more of our executive officers or key employees or an inability to attract and retain highly skilled employees could adversely affect our business.
Our success depends, in part, on the skills, working relationships and continued services of our founders, Chaim Indig (Chief Executive Officer) and Evan Roberts (President, Provider Solutions), and our senior management team and other key personnel. From time to time, there may be changes in our senior management team resulting from the hiring or departure of executives, which could disrupt our business.
In addition, we must attract, train and retain a significant number of highly skilled employees in the U.S., India and Canada, including sales and marketing personnel, client support personnel, professional services personnel, software engineers, technical personnel and management personnel, and the availability of such personnel, in particular software engineers, may be constrained. We also believe that our future growth will depend on the continued development of our direct sales force and its ability to obtain new clients and to manage our existing client base. If we are unable to hire and develop sufficient numbers of productive direct sales personnel or if new direct sales personnel are unable to achieve desired productivity levels in a reasonable period of time, sales of our services will suffer and our growth will be impeded.
Competition for qualified management and employees in our industry is intense, and identifying and recruiting qualified personnel and training them requires significant time, expense and attention. Many of the companies with which we compete for personnel have greater financial and other resources than we do. Our North American employees are employed on a contract-employment basis or are “at-will” employees, and, in most cases, their employment can be terminated by us or them at any time, for any reason and without notice, subject, in certain cases, to severance payment rights. The departure and replacement of one or more of our executive officers or other key employees would likely involve significant time and costs, may significantly delay or prevent the achievement of our business objectives and could materially harm our business. In addition, volatility or lack of performance in our stock price may affect our ability to attract replacements should key personnel depart.
22
We have made, and may in the future make, acquisitions and investments which may be difficult to integrate, divert management resources, result in unanticipated costs or dilute our stockholders.
We have in the past acquired, and we may continue to acquire or invest in, businesses, products or technologies that we believe could complement or expand our products and services, enhance our market coverage or technical capabilities or otherwise offer growth opportunities, such as the AccessOne Acquisition. This may include acquiring or investing in companies, businesses, products or technologies that are tangential to our current business and/or in which we have limited or no prior operating experience.
There are inherent risks in integrating and managing acquisitions, and the pursuit of potential acquisitions may divert the attention of management and cause us to incur various expenses related to identifying, investigating and pursuing suitable acquisitions, whether or not they are consummated. We cannot assure you that we will realize the anticipated benefits of the AccessOne Acquisition or any future acquisitions. We also may not achieve the anticipated benefits from an acquired business due to a number of factors, including, without limitation:
•difficulty integrating the purchased operations, products or technologies and maintaining the quality and security standards consistent with our brand;
•the need to integrate or implement additional controls, procedures and policies;
•privacy concerns, cyber-attacks, data breaches or cybersecurity incidents relating to the acquired businesses, such as the security incident we experienced with ConnectOnCall in 2024;
•our inability to comply with legal and regulatory requirements applicable to the acquired business;
•assimilation of the acquired businesses, which may divert significant management attention and financial resources from our other operations and could disrupt our ongoing business;
•the use of substantial portions of our available cash, issuance of our equity securities or incurrence of debt to consummate the acquisition;
•the loss of key employees, particularly those of the acquired operations; difficulty retaining or developing the acquired business’ customers;
•adverse effects on our existing business relationships;
•failure to realize the potential cost savings or other financial benefits or the strategic benefits of the acquisitions, including failure to consummate any proposed or contemplated transaction; and
•liabilities from the acquired businesses for infringement of intellectual property rights or other claims and failure to obtain indemnification for such liabilities or claims.
Acquisitions also increase the risk of unforeseen legal liability, including for potential violations of applicable law or industry rules and regulations, arising from prior or ongoing acts or omissions by the acquired businesses which are not discovered by due diligence during the acquisition process. Acquisitions could also result in dilutive issuances of equity securities or the incurrence of debt, which could adversely affect our business, results of operations or financial condition. Even if we are successful in completing and integrating an acquired business, it may not perform as we expect or enhance the value of our business as a whole.
We may be unable to successfully integrate the business acquired in the AccessOne Acquisition, integration may be more difficult, costly or time-consuming than expected, and we may fail to realize all of the anticipated benefits of the AccessOne Acquisition on the anticipated time frame or at all.
We believe that there are significant benefits that may be realized through the AccessOne Acquisition. However, the efforts to realize these benefits is a complex process and may disrupt both companies’ existing operations if not implemented in a timely and efficient manner. The integration may be more difficult, costly or time-consuming than expected. We have incurred substantial expenses in connection with the AccessOne Acquisition, including legal, financial advisory, accounting, consulting, and other advisory fees, employee benefit-related costs, filing fees and other regulatory fees, closing, integration and other related costs. The anticipated benefits of the AccessOne Acquisition, including anticipated sales or growth opportunities and cross-selling opportunities, may not be realized as expected or may not be achieved within the anticipated time frame or at all. In addition, we are required to devote significant attention and resources to successfully integrate the operations of the acquired business. This process may disrupt the businesses and, if ineffective, would limit the anticipated benefits of the AccessOne Acquisition.
Additionally, the success of the AccessOne Acquisition will depend in part on our ability to retain key employees of the acquired business. If we are unable to retain key employees, including management, whose contributions are important to the successful integration and future operations of the companies, we could face disruptions in AccessOne’s operations, loss of existing clients, loss of key information, expertise or know-how and unanticipated additional recruitment costs. We may not be able to locate or retain suitable replacements for any key employees who decide not to remain employed with us.
23
Failure to successfully integrate or achieve the anticipated benefits of the AccessOne Acquisition could adversely affect our business, results of operations and financial condition, decrease or delay any accretive effects of the AccessOne Acquisition and negatively impact the price of our common stock.
Certain of our operating results and financial metrics, including the key metrics included in this report, may be difficult to predict as a result of seasonality.
We believe there are significant seasonal factors that may cause us to record higher revenue in some quarters compared with others. We believe this variability is largely due to our focus on the healthcare industry. For example, with respect to our healthcare services clients, we receive a disproportionate increase in payment solutions revenue from such clients during the first two to three months of the calendar year relative to the other months of the year, which is driven, in part, by the resetting of patient deductibles at the beginning of each calendar year. Sales for our network solutions are also seasonal, primarily due to the annual spending patterns of our clients. This portion of our sales is usually the highest in the fourth quarter of each calendar year. While we believe we have visibility into the seasonality of our business, our rapid growth rate over the last several years may have made seasonal fluctuations more difficult to detect, and market dynamics affecting our network solutions clients have resulted in shorter visibility into spending commitments, particularly for the second half of the fiscal year. If our rate of growth slows over time, seasonal or cyclical variations in our operations may become more pronounced, and our business, results of operations and financial position may be adversely affected.
Business or economic disruptions or global health concerns could harm our business and increase our costs and expenses.
Broad-based business or economic disruptions or global health concerns could materially and adversely impact our business and results of operations due to, among other factors:
•a general decline in business activity;
•a potentially disproportionate impact on the healthcare services clients with whom we contract;
•disruptions to our supply chains and our third-party vendors, partners, and suppliers;
•difficulty accessing the capital and credit markets on favorable terms, or at all, and a severe disruption and instability in the global financial markets, or deteriorations in credit and financing conditions that could affect our access to capital necessary to fund business operations or address maturing liabilities on a timely basis; and
•social, economic, and labor instability in the countries in which we or the third parties with whom we engage operate.
In addition, macroeconomic challenges (including tariffs and other trade restrictions and changes in inflation and interest rates) and a tight labor market have adversely affected, and may continue to adversely affect, workforces, organizations, governments, clients, economies, and financial markets globally and have disrupted the normal operations of many businesses, including our business, making it potentially very difficult for our clients and us to accurately forecast and plan future business activities. Additionally, increasing scrutiny of various aspects of the healthcare industry, such as drug pricing and advertising practices, the treatment of medical debt and charity care thresholds, and healthcare coverage eligibility and reimbursement practices, have resulted in, and may result in, changes to U.S. healthcare policy. These factors have and could further decrease healthcare industry spending, adversely affect demand for our products and services, impair the ability of our clients to pay for the products and services they have already purchased from us, cause one or more of our clients to file for bankruptcy protection or go out of business, cause one or more of our clients to fail to renew, terminate, or renegotiate their contracts, impact expected spending from new clients, negatively impact collections of accounts receivable, and harm our business, results of operations, and financial condition.
If our internal controls over financial reporting or our disclosure controls and procedures are not effective, we may not be able to accurately report our financial results, prevent fraud or file our periodic reports in a timely manner, which may cause investors to lose confidence in our reported financial information and may lead to a decline in our stock price.
As a public company, we are required to maintain internal control over financial reporting and disclosure controls and procedures. Section 404 of the Sarbanes-Oxley Act of 2002 (the "Sarbanes-Oxley Act") requires that we evaluate and determine the effectiveness of our internal control over financial reporting and provide a management report on the internal control over financial reporting. Our testing, or the subsequent testing by our independent public accounting firm, may reveal deficiencies in our internal control over financial reporting that are deemed to be
24
material weaknesses. If we are not able to comply with the requirements of Section 404 in a timely manner, or if we or our accounting firm identify deficiencies in our internal control over financial reporting that are deemed to be material weaknesses, the market price of our stock would likely decline and we could be subject to lawsuits, sanctions or investigations by regulatory authorities, including SEC enforcement actions, and we could be required to restate our financial results, any of which would require additional financial and management resources.
If material weaknesses in our internal control over financial reporting are discovered or occur in the future, our consolidated financial statements may contain material misstatements and we could be required to restate our financial results, which could materially and adversely affect our business, results of operations and financial condition, restrict our ability to access the capital markets, require us to expend significant resources to correct the material weakness, subject us to fines, penalties or judgments, harm our reputation or otherwise cause a decline in investor confidence.
We continue to invest in more robust technology and resources to manage our reporting requirements. Implementing the appropriate changes to our internal controls may distract our officers and employees, result in substantial costs and require significant time to complete. Any difficulties or delays in implementing these controls could impact our ability to timely report our financial results. For these reasons, we may encounter difficulties in the timely and accurate reporting of our financial results, which would impact our ability to provide our investors with information in a timely manner. As a result, our investors could lose confidence in our reported financial information, and our stock price could decline. In addition, any such changes do not guarantee that we will be effective in maintaining the adequacy of our internal controls, and any failure to maintain that adequacy could prevent us from accurately reporting our financial results. See Item 9A “Controls and Procedures” in this Annual Report on Form 10-K for more information.
From time to time, we are subject to various legal proceedings that could adversely affect our business, financial condition and results of operations.
From time to time, we are or may become involved in claims, lawsuits (whether class actions or individual lawsuits), arbitration proceedings, governmental investigations, and other legal or regulatory proceedings involving commercial, corporate and securities matters; privacy, marketing and communications practices; labor and employment matters; alleged infringement of third-party patents and other intellectual property rights; matters involving compliance with regulatory requirements on lending and consumer protection laws; and other matters. The results of any such claims, lawsuits, arbitration proceedings, government investigations, or other legal or regulatory proceedings cannot be predicted with any degree of certainty. Any claims against us, whether meritorious or not, could be time-consuming, result in costly litigation, require significant management attention, and divert significant resources. Determining reserves for our pending litigation is a complex and fact-intensive process that requires significant subjective judgment and speculation. It is possible that a resolution of one or more such proceedings could result in substantial damages, settlement costs, fines, and penalties. These proceedings could also result in harm to our reputation and brand, sanctions, consent decrees, injunctions, or other orders requiring a change in our business practices. Any of these consequences could adversely affect our business, financial condition, and results of operations. Further, under certain circumstances, we have contractual and other legal obligations to indemnify and to incur legal expenses on behalf of our business, clients, and commercial partners and current and former directors and officers. In addition, certain litigation or the resolution of certain litigation may affect the availability or cost of some of our insurance coverage, which could adversely impact our results of operations and cash flows, expose us to increased risks that would be uninsured, and adversely impact our ability to attract directors and officers. Notwithstanding the terms of our agreements with our clients, it is possible that one or more of our clients could breach their obligations, which in the aggregate, could adversely affect our business, financial condition, or results of operations. For example, if a client defaults on its obligations under a client agreement or terminates a client agreement prior to the contractual termination date, we may be required to assert a claim to acquire the amount in full due under the client agreement, which we may choose not to pursue. However, if we choose to pursue any such claim, we may incur substantial costs to resolve claims or enter into litigation or arbitration, and even if we were to prevail in the event of claims, litigation or arbitration, such claims, litigation, or arbitration could be costly and time-consuming and divert the attention of our management and other employees from our business operations.
We are a fully remote company, which subjects us to unique operational risks.
Being a fully remote company subjects us to unique operational risks. For example, technologies in our employees’ homes may not be as robust as in a corporate office and could cause the networks, information systems, applications, and other tools available to employees and service providers to be more limited or less reliable than in a corporate office. Further, the security systems in place at our employees’ homes may be less secure than those used in a corporate office, and while we have implemented technical and administrative safeguards to help protect
25
our systems as our employees and service providers work from home, we may be subject to increased cybersecurity risk, which could expose us to risks of data or financial loss and could disrupt our business operations. There is no guarantee that the data security and privacy safeguards we have put in place will be completely effective or that we will not encounter risks associated with employees accessing company data and systems remotely. In addition, operating remotely may negatively impact our corporate culture, including employee engagement and productivity.
Risks relating to our payment processing business
If our payment processing platform is limited, restricted, curtailed or degraded in any way, or if we fail to continue to grow and develop our payments platform, our business may be materially and adversely affected.
Our payment processing platform is a core element of our business. For each of the fiscal years ended January 31, 2026 and January 31, 2025, payment processing fees generated 24%of our total revenue. Our future success depends in part on the continued growth and development of our payment processing platform. If such activities are limited, restricted, curtailed or degraded in any way, or if we fail to continue to grow and develop our payment processing platform, our business may be materially and adversely affected. The utilization of our payment processing tools may be impacted by factors outside of our control, such as changes in laws governing medical bill payments or disruptions in the payment processing industry generally. If the number of patients utilizing our payments platform, the aggregate amounts paid by such patients directly to our healthcare services clients through our payments platform, or the credit card interchange fees we receive from such payments were to be reduced as a result of disruptions in the payment processing industry, laws discouraging the use of credit card payments for medical services or other factors, it could result in a decrease to our revenue. In addition, some potential or existing clients may not desire to use our payment processing services or to switch from their existing payment processing vendors for a variety of reasons, such as transition costs, business disruption, and loss of accustomed functionality. There can be no assurance that our efforts to overcome these factors will be successful, and this resistance may adversely affect our growth.
The attractiveness of our payment processing services may also depend on our ability to integrate emerging payment technologies, including crypto-currencies, other emerging or alternative payment methods, and credit card systems that we or our processing partners may not adequately support or for which we or they do not provide adequate processing rates. In the event such methods become popular among consumers, any failure to timely integrate emerging payment methods into our software, anticipate client behavior changes, or contract with payment processing partners that support such emerging payment technologies could reduce the attractiveness of our payment processing services, potentially resulting in a corresponding loss of revenue.
If we fail to comply with the applicable requirements of card networks, they could seek to fine us, suspend us or terminate our payment facilitator status. If our clients or sales partners incur fines or penalties that we cannot collect from them, we may have to bear the cost of such fines or penalties.
We provide a payments solution for the secure processing of patient payments. Our payment processing tools can connect to multiple clearinghouses and can also connect directly with patients. We have developed partnerships with primary credit card processors in the United States to facilitate payment processing, and we are registered with Visa, MasterCard, American Express, Discover and other card networks as a service provider (payment facilitator or the equivalent) for acquiring member institutions. These card networks set the operating rules and standards with which we must comply. The termination of our status as a certified service provider, a decision by the card networks to disallow payment facilitators or bar us from serving as such, or any changes in network rules or standards, including interpretation and implementation of the operating rules or standards, that increase the cost of doing business or limit our ability to provide transaction processing services to our clients or partners, could adversely affect our business, financial condition or results of operations.
We and our clients are subject to card network rules that could subject us or our clients to a variety of fines or penalties that may be levied by card networks for certain acts or omissions by us or our clients. If a client fails to comply with the applicable requirements of card networks, we could be subject to a variety of fines or penalties that may be levied by card networks. We may have to bear the cost of such fines or penalties if we cannot collect them from the applicable client, resulting in lower earnings or losses for us. A violation of the network rules may result in the termination or suspension of our registration with the affected network. The termination of our registration, including a card network barring us from acting as a payment facilitator, or any changes in card network rules that would impair our registration, could require us to stop providing payment processing services relating to the affected card network, which would adversely affect our ability to conduct our business.
26
In addition, the rules of card networks are set by their boards, which may be influenced by card issuers. Many banks directly or indirectly sell processing services to clients in competition with us. These banks could attempt, by virtue of their influence on the networks, to alter the networks’ rules or policies to the detriment of non-members, including us.
Changes in laws and regulations relating to interchange fees on payment card transactions, or increases in card network fees and other changes to fee arrangements, may result in the loss of clients who use our payment processing services and would adversely affect our revenue and results of operations.
We pay interchange fees to the card networks or the card issuers for each transaction we process. The card networks, including Visa, MasterCard, American Express and Discover, may increase, from time to time, the interchange fees that they charge members or service providers, or the fees that they charge acquirers, which would be passed down to processors, payment facilitators and merchants. Although we may attempt to pass these increases along to our clients, this may result in the loss of clients to our competitors that do not pass along the increases. If competitive practices prevent us from passing along the higher fees to our clients in the future, we may have to absorb all or a portion of such increases, which may increase our operating costs and reduce our earnings. Additionally, provision of the Dodd-Frank Wall Street Reform and Consumer Protection Act (the "Dodd-Frank Act") known as the Durbin Amendment empowered the Board of Governors of the Federal Reserve System ("FRS"), to establish and regulate a cap on the interchange fees that issuers (e.g. banks) may charge or receive for electronic clearing of debit card transactions. The original regulations implementing the Durbin Amendment established standards for assessing whether debit card interchange fees received by debit card issuers were reasonable and proportional to the costs incurred by issuers for electronic debit transactions, and it established a maximum permissible interchange fee that an issuer may receive for an electronic debit transaction, limiting the fee revenue to debit card issuers and payment processors. If the maximum permissible interchange fee for debit cards, credit cards, or other payment cards is changed or the exempt status of HSA-linked payment cards from such maximum interchange rate caps is lost as a result of amendment to Regulation II by the FRS or any other new rulemaking, legislation, or private litigation challenge, our revenue and profit from payment card transactions processed through our payments platform could decrease, and there could be a material adverse effect on our financial condition and results of operations.
Risk relating to our data and intellectual property
If our intellectual property is not adequately protected, we may not be able to build name recognition, protect our technology and products, and our business may be adversely affected.
Our business depends on proprietary technology and content, including software, databases, confidential information and know-how, the protection of which is crucial to the success of our business. We rely on a combination of trademark, trade-secret and copyright laws, confidentiality procedures and contractual provisions to protect our intellectual property rights in our proprietary technology, content and brand. We may, over time, increase our investment in protecting our intellectual property through additional trademark, patent and other intellectual property filings that could be expensive and time-consuming. Effective trademark, trade-secret and copyright protection is expensive to develop and maintain, both in terms of initial and ongoing registration requirements and the costs of defending our rights. These measures, however, may not be sufficient to offer us meaningful protection. If we are unable to protect our intellectual property and other proprietary rights, our brand, competitive position and business could be harmed, as third parties may be able to dilute our brand or commercialize and use technologies and software products that are substantially the same as ours without incurring the development and licensing costs that we have incurred. Any of our owned or licensed intellectual property rights could be challenged, invalidated, circumvented, infringed or misappropriated, our trade secrets and other confidential information could be disclosed in an unauthorized manner to third parties, or our intellectual property rights may not be sufficient to permit us to take advantage of current market trends or otherwise provide us with competitive advantages, which could result in costly redesign efforts, discontinuance of certain offerings or other competitive harm.
Monitoring unauthorized use of our intellectual property is difficult and costly. From time to time, we seek to analyze our competitors’ products and services, and may in the future seek to enforce our rights against potential infringement. However, the steps we have taken to protect our proprietary rights may not be adequate to prevent infringement or misappropriation of our intellectual property. We may not be able to detect unauthorized use of, or take appropriate steps to enforce, our intellectual property rights. Any inability to meaningfully protect our intellectual property rights could result in harm to our brand or our ability to compete and reduce demand for our technology and products. Moreover, our failure to develop and properly manage new intellectual property could adversely affect our market positions and business opportunities. Also, some of our products and services rely on technologies and software developed by or licensed from third parties. Any disruption or disturbance in such third-party products or services, which we have experienced in the past, could interrupt the operation of our solutions. We may not be able
27
to maintain our relationships with such third parties or enter into similar relationships in the future on reasonable terms or at all.
We may also be required to protect our proprietary technology and content in an increasing number of jurisdictions, a process that is expensive and may not be successful, or which we may not pursue in every location. In addition, effective intellectual property protection may not be available to us in every country, and the laws of some foreign countries may not be as protective of intellectual property rights as those in the United States. Additional uncertainty may result from changes to intellectual property legislation enacted in the United States and elsewhere, and from interpretations of intellectual property laws by applicable courts and agencies. Accordingly, despite our efforts, we may be unable to obtain and maintain the intellectual property rights necessary to provide us with a competitive advantage. Our failure to obtain, maintain and enforce our intellectual property rights could therefore have a material adverse effect on our business, financial condition and results of operations.
Any restrictions on our use of, or ability to license and integrate, third-party technologies could have a material adverse effect on our business, financial condition and results of operations.
We integrate into our proprietary applications and use third-party software to maintain and enhance, among other things, content generation and delivery, and to support our technology infrastructure. Some of this software is proprietary and some is open source software. Our use of third-party technologies and open source software exposes us to increased risks, including, but not limited to, risks associated with the integration of new technology into our solutions, the diversion of our resources from development of our own proprietary technology and our inability to generate revenue from licensed technology sufficient to offset associated acquisition and maintenance costs. These technologies may not be available to us in the future on commercially reasonable terms or at all and could be difficult to replace once integrated into our own proprietary applications. Most of these licenses can be renewed only by mutual consent and may be terminated if we breach the terms of the license and fail to cure the breach within a specified period of time. Our inability to obtain, maintain or comply with any of these licenses could delay development until equivalent technology can be identified, licensed and integrated, which would harm our business, financial condition and results of operations.
Most of our third-party licenses are non-exclusive and our competitors may obtain the right to use any of the technology covered by these licenses to compete directly with us. If our data suppliers choose to discontinue support of the licensed technology in the future, we might not be able to modify or adapt our own solutions.
Third parties may initiate legal proceedings alleging that we are infringing or otherwise violating their intellectual property rights, the outcome of which would be uncertain and could have a material adverse effect on our business, financial condition and results of operations.
Our commercial success depends on our ability to develop and commercialize our services and use our proprietary technology without infringing the intellectual property or proprietary rights of third parties. Intellectual property disputes can be costly to defend and may cause our business, operating results and financial condition to suffer. As the market for healthcare in the United States expands and more patents are issued, the risk increases that there may be patents issued to third parties that relate to our products and technology of which we are not aware or that we must challenge to continue our operations as currently contemplated. Whether merited or not, we may face allegations that we, our partners, our licensees or parties indemnified by us have infringed or otherwise violated the patents, trademarks, copyrights or other intellectual property rights of third parties. Such claims may be made by competitors seeking to obtain a competitive advantage or by other parties. Additionally, in recent years, individuals and groups have begun purchasing intellectual property assets for the purpose of making claims of infringement and attempting to extract settlements from companies like ours. We may also face allegations that our employees have misappropriated the intellectual property or proprietary rights of their former employers or other third parties. It may be necessary for us to initiate litigation to defend ourselves in order to determine the scope, enforceability and validity of third-party intellectual property or proprietary rights, or to establish our respective rights. Additionally, the intellectual property ownership and license rights, including copyright, surrounding AI technologies, which we are increasingly incorporating into our product offerings, has not been fully addressed by U.S. courts or other federal or state laws or regulations, and the use or adoption of AI technologies in our products and services may expose us to copyright infringement or other intellectual property misappropriation claims related to AI training or output. Regardless of whether claims that we are infringing patents or other intellectual property rights have merit, such claims can be time-consuming, divert management’s attention and financial resources and can be costly to evaluate and defend. Results of any such litigation are difficult to predict and may require us to stop commercializing or using our products or technology, obtain licenses, modify our services and technology while we develop non-infringing substitutes or incur substantial damages, settlement costs or face a temporary or permanent injunction prohibiting us from marketing or providing the affected products and services. If we require a third-party license, it may not be available on reasonable terms or at all, and we may have to pay substantial royalties, upfront fees or grant cross-
28
licenses to intellectual property rights for our products and services. We may also have to redesign our products or services so they do not infringe third-party intellectual property rights, which may not be possible or may require substantial monetary expenditures and time, during which our technology and products may not be available for commercialization or use. Even if we have an agreement to indemnify us against such costs, the indemnifying party may be unable to uphold its contractual obligations. If we cannot or do not obtain a third-party license to the infringed technology, license the technology on reasonable terms or obtain similar technology from another source, our revenue and earnings could be adversely impacted.
From time to time, we may be subject to legal proceedings and claims in the ordinary course of business with respect to intellectual property. We are not currently subject to any claims from third parties asserting infringement of their intellectual property rights. Some third parties may be able to sustain the costs of complex litigation more effectively than we can because they have substantially greater resources. Even if resolved in our favor, litigation or other legal proceedings relating to intellectual property claims may cause us to incur significant expenses and could distract our technical and management personnel from their normal responsibilities. In addition, there could be public announcements of the results of hearings, motions or other interim proceedings or developments, and if securities analysts or investors perceive these results to be negative, it could have a material adverse effect on the price of our common stock. Moreover, any uncertainties resulting from the initiation and continuation of any legal proceedings could have a material adverse effect on our ability to raise the funds necessary to continue our operations. Assertions by third parties that we violate their intellectual property rights could therefore have a material adverse effect on our business, financial condition and results of operations.
Interruption or failure of our information technology and communications systems could impair our ability to effectively deliver our products and services, which could cause us to lose clients and harm our operating results.
Our business depends on the continuing operation of our technology infrastructure and systems. Proprietary software development is time-consuming, expensive and complex, and may involve unforeseen difficulties. We may encounter technical obstacles in enhancing our existing software and developing new software, and it is possible that we may discover additional problems that prevent our proprietary applications from operating properly. In addition, any damage to or failure of our existing systems, or the systems of our third-party providers, could result in interruptions in our ability to deliver our products and services. Interruptions in our service, such as one that affected our ConnectOnCall product in 2024, have in the past and could in the future reduce our revenue and profits, and our reputation could be damaged if people believe our systems are unreliable.
Our systems and operations, and those of our third-party providers, are vulnerable to damage or interruption from natural disasters or man-made problems, such as earthquakes, floods, fires, political unrest, acts of terrorism, armed conflict or war (such as the ongoing Russian invasion of Ukraine and the conflict in the Middle East), power loss, break-ins, hardware or software failures, telecommunications failures, computer viruses, cyber-attacks or other attempts to harm our systems and similar events. Any unscheduled interruption in our service would result in an immediate loss of revenue. Frequent or persistent system failures that result in the unavailability of our solutions or slower response times could reduce our clients’ ability to access our solutions, impair our delivery of our products and services and harm the perception of our solutions as reliable, trustworthy and consistent. Our insurance policies provide only limited coverage for service interruptions and may not adequately compensate us for any losses that may occur due to any failures or interruptions in our systems.
If our solutions fail to provide accurate and timely information, or if the content delivered to clients and patients or any other element of our service is associated with errors or malfunctions, we could have liability to clients or patients which could adversely affect our results of operations.
Our solutions are used to help healthcare organizations and patients streamline the process of finding, scheduling, receiving and paying for care, and to empower patients and healthcare organizations as they navigate the challenges of an evolving healthcare system. If our solutions or the content delivered to clients and patients fail to provide accurate and timely information or are associated with errors or malfunctions, then healthcare services clients or patients could assert claims against us that could result in substantial costs to us, harm our reputation in the industry and cause demand for our services to decline.
We attempt to limit by contract our liability for damages and to require that our clients assume responsibility for medical care and approve key system rules, protocols and data. Despite these precautions, the allocations of responsibility and limitations of liability set forth in our contracts may not be enforceable, may not be binding upon patients or may not otherwise protect us from liability for damages.
Our proprietary software may contain errors or failures that are not detected until after the software is introduced or updates and new versions are released. It is challenging for us to test our software for all potential problems
29
because it is difficult to simulate the wide variety of computing environments or methodologies that our clients may deploy or rely upon. From time to time we have discovered defects or errors in our software, and such defects or errors can be expected to appear in the future. Defects and errors that are not timely detected and remedied could expose us to risk of liability to healthcare services clients and patients and cause delays in introduction of new services, result in increased costs and diversion of development resources, require design modifications or decrease market acceptance or client satisfaction with our services. If any of these risks occur, they could materially and adversely affect our business, financial condition or results of operations.
We may be liable for use of incorrect or incomplete data we provide, which could harm our business, financial condition and results of operations.
We collect, store and display data, including patient health information, for use by healthcare services clients in handling patient intake, payments and engagement and to deliver clinically relevant content to patients. Our clients, their patients, or third parties provide us with most of this data. If this data is incorrect or incomplete, or if we make mistakes in the capture or input of this data, adverse consequences may occur and give rise to product liability and other claims against us. In addition, a court or government agency may take the position that our storage and display of health information exposes us to liability arising out of our intake, storage and display of erroneous health information. While we maintain insurance coverage, we cannot be certain that this coverage will prove to be adequate or will continue to be available on acceptable terms, if at all. Even unsuccessful claims could result in substantial costs and diversion of management resources. A claim brought against us that is uninsured or under-insured could harm our business, financial condition and results of operations.
Our use of “open source” software could adversely affect our ability to offer our services and subject us to possible litigation.
We may use open source software in connection with our products and services. Companies that incorporate open source software into their products have, from time to time, faced claims challenging the use of open source software and/or compliance with open source license terms. As a result, we could be subject to suits by parties claiming ownership of what we believe to be open source software or claiming noncompliance with open source licensing terms. Some open source software licenses require users who distribute software containing open source software to publicly disclose all or part of the source code to such software and/or make available any derivative works of the open source code, which could include valuable proprietary code of the user, on unfavorable terms or at no cost. While we monitor the use of open source software and try to ensure that none is used in a manner that would require us to disclose our proprietary source code or that would otherwise breach the terms of an open source agreement, such use could inadvertently occur, in part because open source license terms are often ambiguous. Any requirement to disclose our proprietary source code or pay damages for breach of contract could have a material adverse effect on our business, financial condition and results of operations and could help our competitors develop products and services that are similar to or better than ours.
Risks relating to laws and regulations applicable to our industry
We are subject to healthcare laws and data privacy and security laws and regulations governing our collection, use, disclosure, storage and transmission of personally identifiable information, including protected health information and payment card data, which may impose restrictions on us and our operations, require us to change our business practices and put in place additional compliance mechanisms, and subject us to fines, penalties, lawsuits, adverse publicity, reputational harm, loss of client trust or government enforcement actions if we are unable to fully comply with such laws.