Skip to content
KStart free
AI InfrastructureDefenseQuantumAll studies →

PSNL US Equity

Personalis, Inc.Health Care · Services-Medical Laboratories · CIK 1527753 · FY ends Dec 31
$15.81
+1.90 (+13.66%)
USD · as of 2026-08-19 · marketstack

PSNL · 10-K · period ended 2021-12-31

← all PSNL documents
filed 2022-02-24 · EDGAR original ↗

Our rendering of the filing — original pagination and typography are not reproduced, and tables are reduced to their short label cells (the figures live on FA). Nothing is summarized: every line below is the filing's own text.

blocks 294485 of 1,319487k characters rendered

Item 1A. Risk Factors.

Summary of Risk Factors

The following is a summary of the principal risks and uncertainties that could materially adversely affect our business, financial condition, or results of operations. You should read this summary together with the more detailed description of risk factors below under the heading “Risk Factors”.

Operational, Strategic and Business Risks

Regulatory, Legal and Cybersecurity Risks

22

Intellectual Property Risks

Financial and Market Risks and Risks Related to Owning Our Common Stock

23

Risk Factors.

Our operations and financial results are subject to various risks and uncertainties including those described below. You should consider carefully the risks and uncertainties described below, in addition to other information contained in this Annual Report on Form 10-K, including our audited consolidated financial statements and related notes. The risks and uncertainties described below are not the only ones we face. Additional risks and uncertainties that we are unaware of, or that we currently believe are not material, may also become important factors that adversely affect our business. If any of the following risks or others not specified below materialize, our business, financial condition, and results of operations could be materially and adversely affected. In that case, the trading price of our common stock could decline.

Operational, Strategic and Business Risks

We have a history of losses, and as our costs increase, we expect to incur significant losses for the foreseeable future and may not be able to generate sufficient revenue to achieve or sustain profitability.

We have incurred net losses since our inception. For the years ended December 31, 2021, 2020, and 2019 we had net losses of $65.2 million, $41.3 million, and $25.1 million, respectively. As of December 31, 2021, we had an accumulated deficit of $247.1 million. To date, we have not generated sufficient revenue to achieve profitability, and we may never achieve or sustain profitability. In addition, we expect to continue to incur net losses for the foreseeable future, and we expect our accumulated deficit to continue to increase as we focus on scaling our business and operations. Our efforts to sustain and grow our business may be more costly than we expect, and we may not be able to increase our revenue sufficiently to offset our higher operating expenses. Our prior losses and expected future losses have had and will continue to have an adverse effect on our stockholders’ equity and working capital. Our failure to achieve and sustain profitability in the future would negatively affect our business, financial condition, results of operations, and cash flows, and could cause the market price of our common stock to decline.

If we are unable to increase sales of our current services or successfully develop and commercialize other services or products, or if we are unable to execute our sales and marketing strategy for our services or unable to gain sufficient acceptance in the market, we may fail to generate sufficient revenue to achieve profitability and sustain our business.

We currently derive substantially all of our revenue from sales of our services. We began offering our services through our CLIA-certified, CAP-accredited, and state-licensed laboratory in 2013. We are in varying stages of research and development for other services and products that we may offer. If we are unable to increase sales of our existing services or successfully develop and commercialize other services and products, we will not generate sufficient revenue to become profitable.

In addition, as a growing genomics company, we have engaged in targeted sales and marketing activities for our services. Although we have had revenue from sales of our services since 2013, our services may never gain significant acceptance in the marketplace and therefore may never generate substantial revenue or permit us to become profitable. We will need to further establish and grow the market for our services through the expansion of our current relationships and development of new relationships with biopharmaceutical customers. Gaining acceptance in medical communities can be supported by, among other things, publications in leading peer-reviewed journals of results from studies using our services. The process of publication in leading medical journals is subject to a peer review process and peer reviewers may not consider the results of our studies sufficiently novel or worthy of publication. Failure to have our studies published in peer-reviewed journals would limit the adoption of our services.

Our ability to successfully market our services that we have developed, and may develop in the future, will depend on numerous factors, including:

• the recruitment, hiring, and retention of our commercial team personnel;

• our ability to continue to fund sales and marketing activities;

• whether our services are considered superior to those of our competitors;

• our success enforcing and defending intellectual property rights and claims.

Failure to achieve broad market acceptance of our services would materially harm our business, financial condition, and results of operations.

24

Our operations and employees face risks related to health crises, such as the ongoing COVID-19 pandemic, that could adversely affect our operations, our financial condition, and the business or operations of our customers or other third parties with whom we conduct business.

Our business could be adversely impacted by the effects of a health crisis, such as the ongoing COVID-19 pandemic, that could cause significant disruption in the operations of our customers and third-party suppliers upon whom we rely. Our laboratory facilities (other than the facilities being developed for our use in Shanghai, China), executive team, and most of our employees are located in the San Francisco Bay Area. In the event of a health crisis that becomes widespread in or around the San Francisco Bay Area, we may proactively, or be ordered by government officials to, take precautionary measures such as suspending our lab operations, implementing alternative work arrangements for our employees, and limiting our employees’ travel activities.

Our operations have been impacted by the ongoing COVID-19 pandemic. For example, the previous shelter-in-place order and health orders have negatively impacted productivity, disrupted our business, and slowed research and development activities due to us limiting access to our laboratory space that would otherwise be used by our research and development group, and, to the extent such orders return in similar or more stringent form, they may continue to cause such effects on our operations. The COVID-19 pandemic has disrupted, and may continue to disrupt, the ability of our suppliers to fulfill our purchase orders in a timely manner or at all. Additionally, we are aware of increased demand in the market for certain consumables used in COVID-19 test kits and vaccines. We use such consumables in our operations, and we have faced, and may face in the future, difficulties in acquiring such consumables if our suppliers prioritize orders related to COVID-19 or if other supply chain issues arise as a result of the COVID-19 pandemic. Several of our customers, including the VA MVP, have been delayed in sending us samples due to the inability to collect or ship samples during the COVID-19 pandemic, and these and additional customers may be disrupted from collecting samples or sending purchase orders or samples to us in the future.

While authorities in many areas have lifted or relaxed pandemic-related restrictions, in some cases they have subsequently re-imposed various restrictions after observing an increased rate of COVID-19 cases as the global COVID-19 pandemic continues to rapidly evolve and to present serious health risks. There is no guarantee when or if all such restrictions and recommendations will be eliminated, such that we and our customers, manufacturers and suppliers will be able to safely resume operations consistent with our pre-COVID-19 operations. The full extent of the impact of the COVID-19 pandemic on our business, operations and plans remains uncertain and will depend on future developments that cannot be predicted at this time. Such developments include the continued spread of the Delta and Omicron variants in the U.S. and other countries and the potential emergence of other SARS-CoV-2 variants that may prove especially contagious or virulent, the ultimate duration of the pandemic and the resulting impact on our business and other third parties with whom we do business, and the effectiveness of actions taken globally to contain and treat the disease.

While vaccines for COVID-19 have been developed and administered, and the spread of COVID-19 may eventually be contained or mitigated, we cannot predict the timing of the vaccine roll-out globally (including boosters to vaccinations), the percentage of the population that becomes vaccinated, or the efficacy of such vaccines against Delta, Omicron or other variants, and we do not yet know how businesses, advertisers, or our partners will operate in a post COVID-19 environment. In addition, there is no guarantee that a future outbreak of this or any other widespread epidemics will not occur, or that the global economy will recover, either of which could seriously harm our business. The ultimate impact of the COVID-19 pandemic or a similar health epidemic on our business, operations, or the global economy as a whole remains highly uncertain, but a continued and prolonged public health crisis could have a material negative impact on our business, financial condition, and operating results.

If we cannot compete successfully with our competitors, we may be unable to increase or sustain our revenue or achieve and sustain profitability.

Our principal competition comes from commercial and academic organizations using established and new laboratory tests to produce information that is similar to the information that we generate for our customers. These commercial and academic organizations may not utilize our services or may not believe them to be superior to those tests that they currently use or others that are developed. Further, it may be difficult to convince our customers and potential customers to use our comprehensive test rather than simpler panels provided by our competitors. For example, the information that we provide may be more challenging or require additional resources for our customers to interpret than the information provided by our competitors’ less comprehensive assays. In addition, our suppliers or competitors may announce the development of new products, services or features that result in our customers or potential customers deciding to reduce, postpone or cancel orders from us while they wait to determine which products, services or features are or will be perceived as technologically superior, more commercially successful or adopted as standards in the industry; such decisions by our customers or potential customers may be influenced by their concerns regarding the potential obsolescence of data generated using our services and features if our services or features are or will not be perceived as technologically superior, commercially successful or adopted as standards in the industry.

Some of our present or potential competitors, including Adaptive Biotechnologies Corporation, Adela, Inc., ArcherDx, Inc., which was acquired by Invitae Corporation in October 2020, C2i Genomics, Inc., Caris Life Sciences, Inc., Covance Inc., which was acquired by Laboratory Corporation of America Holdings in February 2015, Foundation Medicine, Inc., which was acquired by Roche Holdings, Inc. in July 2018, Freenome, Inc., Geneseeq Technology Inc., Genosity, Inc., which was acquired by Invitae Corporation in April 2021, GRAIL, which Illumina announced that it had acquired in August 2021, Guardant Health, Inc., Inivata Limited, which was acquired by NeoGenomics, Inc. in June 2021, Invitae Corporation, Mount Sinai Genomics, Inc. which does business under the name Sema4, Natera, NanoString Technologies, Inc., NeoGenomics, Inc., Personal Genome Diagnostics, Inc., Predicine, Inc., Roche Molecular Systems, Inc., and Tempus, Inc., may have more widespread brand recognition or substantially greater financial or technical resources, development or production capacities, or marketing capabilities than we do. They may be able to devote greater resources

25

to the development, promotion and sale of their products and services than we do or sell their products and services at prices designed to win more significant levels of market share. Also, we have had, and may have in the future, customer or supply relationships with our present or potential competitors. For example, we have an agreement with Natera to provide advanced tumor analysis for use in Natera’s MRD testing offerings. During 2021, revenue under our agreement accounted for 10% of our total revenue. See “—We currently derive a substantial portion of our revenue from DNA sequencing and data analysis services that we provide to Natera. If Natera’s demand for our DNA sequencing and data analysis services were to be substantially reduced,our business, financial condition, revenue and other operating results, and cash flows may be materially harmed.” In addition, our present or potential competitors may be acquired by, receive investments from, or enter into other commercial relationships with larger, more well-established and well-financed companies. For example, in August 2021, Illumina announced it completed its acquisition of GRAIL, a company focused on early cancer detection and potentially other forms of cancer analysis using next-generation sequencing technology, which we view as a potential competitor. Illumina is also one of our significant suppliers. See “—We rely on a limited number of suppliers, or in some cases, a sole supplier, for some of our laboratory instruments and materials, and we may not be able to find replacements or immediately transition to alternative suppliers should we need to do so.” Others may develop lower-priced, less complex products and services that pharmaceutical companies could view as functionally equivalent to our current or planned future services, which could force us to lower the price of our services and impact our operating margins and our ability to achieve and maintain profitability. In addition, companies or governments that control access to genetic testing and related services through umbrella contracts or regional preferences could promote our competitors or prevent us from performing certain services. In addition, technological innovations that result in the creation of enhanced products or diagnostic tools that are more sensitive or specific than ours may enable other clinical laboratories, hospitals, physicians, or medical providers to provide specialized products or services similar to ours in a more patient-friendly, efficient, or cost-effective manner than is currently possible. If we cannot compete successfully against current or future competitors, or if we cannot maintain successful customer or supply relationships with Natera, Illumina or other present or potential competitors, we may be unable to ensure or increase market acceptance and sales of our current or planned future services, which could prevent us from increasing or sustaining our revenue or achieving or sustaining profitability.

We expect that biopharmaceutical companies will increasingly focus attention and resources on the targeted and personalized cancer diagnostic sector as the potential and prevalence of molecularly targeted oncology therapies approved by the U.S. Food and Drug Administration (the “FDA”) along with companion diagnostics increases. For example, the FDA has approved several such targeted oncology therapies that use companion diagnostics, including the anaplastic lymphoma kinase FISH test from Abbott Laboratories, Inc. for use with Xalkori® from Pfizer Inc., the BRAF kinase V600 mutation test from Roche Molecular Systems, Inc. for use with Zelboraf® from Daiichi-Sankyo/Genentech/Roche, and the BRAF kinase V600 mutation test from bioMerieux for use with Tafinlar® from GlaxoSmithKline. Since companion diagnostic tests are part of FDA labeling, non-FDA cleared tests, such as the ones we currently offer as part of our services, would be considered an off-label use and this may limit our access to this market segment. Our customers and potential customers may request, or in some cases have requested, that we consider developing and seeking FDA approval for companion diagnostic tests to accompany those customers’ therapeutic product candidates, and it may be necessary for us to do so in order to successfully compete for the business of these customers. If we do not successfully develop FDA-approved companion diagnostics, we may be at a competitive disadvantage and may be unable to increase market acceptance and sales of our other product offerings, which would prevent us from increasing or sustaining our revenue or achieving or sustaining profitability. If we were to develop one or more FDA-approved companion diagnostics, we would incur increased research and development expenses, and such activities may also divert our resources or the attention of our management and may create competing internal priorities for us. In addition, we have limited experience developing diagnostics, have never developed an FDA-approved companion diagnostic, and may be unable to successfully compete against companies with more experience developing and commercializing companion diagnostics.

Additionally, projects related to cancer diagnostics and particularly genomics have received increased government funding, both in the United States of America (the “U.S.”) and internationally. As more information regarding cancer genomics becomes available to the public, we anticipate that more products and services aimed at identifying treatment options will be developed and that these products and services may compete with our services. In addition, competitors may develop their own versions of our current or planned future services in countries where we did not apply for or receive patents and compete with us in those countries, including encouraging the use of their products or services by biopharmaceutical companies in other countries.

We have substantial customer concentration, with a limited number of customers accounting for a substantial portion of our revenue and accounts receivable; in particular, we currently derive a substantial portion of our revenue from our largest customers, the VA MVP and Natera.

Like other genomic profiling companies that sell to the pharmaceutical industry, we have substantial customer concentration. We currently derive a significant portion of our revenue from the VA MVP, which accounted for 53%, 71% and 67% of our revenue for the years ended December 31, 2021, 2020 and 2019, respectively. Our top five customers, including the VA MVP, accounted for 84%, 87% and 90% of our revenue for the years ended December 31, 2021, 2020 and 2019, respectively. There are inherent risks whenever a large percentage of revenue is concentrated with a limited number of customers. While we have attempted to grow our customer base and diversify our revenue concentration beyond the VA MVP and Natera, we may not be able to successfully do so in the future. Our predictions regarding the future level of demand for our services that will be generated by these customers may be wrong. In addition, revenue from our larger customers have historically fluctuated and may continue to fluctuate based on the commencement and completion of clinical trials or other projects, the timing of which may be affected by market conditions or other factors, some of which may be outside of our control. Further, while we have long-term contractual arrangements with certain of our customers, including Natera, these customers are not required to purchase a minimum number of analyses. Some of our customers have in the past suspended or terminated clinical trials or projects, received less funding than expected, experienced declining or delayed sales, or otherwise decided to reduce or eliminate their use of our services, and these and other customers may also do so in the future. As a

26

result, we could be pressured to reduce the prices we charge for our services, which would have an adverse effect on our margins and financial position, and which would likely negatively affect our revenue and results of operations. In particular, if the VA MVP terminates our services for convenience, which it is permitted to do, such termination would have a material adverse effect on our revenue, cash position, and results of operations. Similarly, if the VA MVP was eliminated, awarded its contract to one of our competitors, further reduced the size of our contract or failed to renew our contract in the future, then our revenue, cash position, and results of operations would be materially adversely impacted. Likewise, if Natera or any of our other significant customers were to reduce or cease their use of our services, then our revenue, cash position, and results of operations may be materially adversely impacted. Further, if any of our significant customers were to stop payment for our services, it would have a material adverse effect on our accounts receivable, increasing our credit risk. The failure of these customers to pay their balances, or any customer to pay future outstanding balances, would result in an operating expense and reduce our cash flows.

We have derived a substantial portion of our current revenue from DNA sequencing and data analysis services that we provided to our largest customer, the VA MVP. If the VA MVP’s demand for and/or funding for our DNA sequencing and data analysis services continues to be substantially reduced, if the VA MVP conducts a competitive bid process for the next contract and we do not win, or if the VA MVP does not award any such contract on a timely basis or at all, our business, financial condition, revenue and other operating results, and cash flows will be materially harmed.

We currently derive a substantial portion of our revenue from sales of our DNA sequencing and data analysis services to the VA MVP. In September 2017, we entered into a one-year contract with three one-year optional renewal periods with the VA for the VA MVP, pursuant to which we received contracted orders from the VA MVP in September 2017, 2018, 2019, 2020, and 2021. The current contract does not include a renewal option. For us to provide additional services to the VA MVP after completion of the current contract, we would need to receive an additional task order and/or enter into a new services agreement with the VA MVP, neither of which had occurred as of the date of filing this annual report.

The VA MVP may initiate a competitive bidding process for its next DNA sequencing and data analysis services contract, if any. However, there may not be any such potential bidding process or new contract awarded on a timely basis or at all, we may not win any such potential new contract in any such potential bidding process, the value of any such potential new contract or the VA MVP contracted orders thereunder may be lower than our current contract and historical contracted orders from the VA MVP, and/or the scope or nature of the services required under such new contract may change such that we are unable to serve the VA MVP in the future.

The VA MVP’s contracted orders for DNA sequencing and data analysis services have fluctuated significantly in value over time and are subject to the availability of funding, enrollment of veterans in the VA MVP study, and the VA MVP’s continued demand for our services among other factors. For example, the VA MVP contracted order received in September 2020 had a value of up to approximately $31 million, whereas the VA MVP contracted order received in September 2021 has a value of up to approximately $9.7 million, which represents a substantial decline. Unless we receive an additional task order and/or enter into a new services agreement with the VA MVP with a value comparable to that of our current contract and historical contracted orders, our revenue from the VA MVP will decline significantly in the future.

We have no certainty that funding will be made available for our services, or that the VA MVP will award any future contracts, contract renewals or contracted orders to us. If the priorities of the VA, the VA MVP, or the U.S. government have changed or change in the future, including in response to the COVID-19 pandemic for example, funding for our services may be limited or not available, and our business, financial condition, and operating results and cash flows will be materially harmed. Similarly, if we do not win future VA MVP contracts and renewals (whether due to being outbid by a competitor or the VA MVP’s decision not to award a future contract on a timely basis or at all, or to terminate for convenience or failure to renew any contract, for whatever reason), our business, financial condition, revenue and other operating results and cash flows will be materially harmed. The success of our business and our future operating results are significantly dependent on the VA MVP’s continued demand and receipt of funding for use of our services and the terms of our sales to the VA MVP, including the price per sample, the number of samples and the timing of the VA MVP’s deliveries of samples. Furthermore, we only recognize revenue under our VA MVP contract upon the receipt and processing of samples, and the timing and number of VA MVP samples we receive has been and could in the future be negatively affected by factors beyond our control, which has resulted, and may result in the future, in delaying our ability to process and recognize revenue for such samples. For example, the revenue we recognized during the contract year that began in September 2020 significantly exceeded the value of the VA MVP contracted order we received in September 2020 because we continued to receive after such date, and subsequently processed, samples under VA MVP contracted orders that remained unfulfilled as of September 2020 due to the time required for the VA to select optimal samples from its collection for research and then provide us those samples. Therefore, period-to-period comparisons of our operating results relating to VA MVP contracted orders may not be meaningful and, even if we win a potential new VA MVP contract and order with a value comparable to that of the September 2020 contracted order, the revenue we recognize under such potential new contract and order may be less than the revenue we recognized during the 2020-2021 contract year. The timing and number of VA MVP samples may also have been or be negatively affected by the current COVID-19 pandemic. For example, in March 2020, the VA MVP announced that it was suspending sample collection due to the COVID-19 pandemic. In addition, we believe the COVID-19 pandemic may have been a contributing factor to the reduction in value of the September 2021 VA MVP contracted order compared to the September 2020 contracted order, as the VA MVP delayed new enrollment and also may have needed to divert resources to respond to the pandemic, and the COVID-19 pandemic may also negatively impact the value of any potential new VA MVP contract or order.

27

We currently derive a substantial portion of our revenue from DNA sequencing and data analysis services that we provide to Natera. If Natera’s demand for our DNA sequencing and data analysis services were to be substantially reduced, our business, financial condition, revenue and other operating results, and cash flows may be materially harmed.

On February 17, 2021, we announced that we had entered into a partnership in the field of personalized oncology with Natera, pairing our NeXT tumor profiling and diagnostic products with Natera’s personalized ctDNA platform SignateraTM for treatment monitoring and MRD assessment. Under this non-exclusive agreement, Natera is responsible for validating the design of, and commercialization of, Signatera personalized ctDNA assays using matched tumor and normal exome sequence data from us. The agreement covers MRD testing for both clinical use and research use. Since that time, Natera’s sample volumes have increased such that we currently derive a significant portion of our revenue from sales of our DNA sequencing and data analysis services to Natera under our agreement. For example, during 2021, revenue under our agreement accounted for 10% of our total revenue. While our agreement with Natera is a long-term contractual arrangement, Natera is not required to purchase a minimum number of analyses from us under the agreement, and we have only limited visibility to Natera’s forecasted sample volumes for future periods. We are aware that Natera has at least one third party supplier of DNA sequencing and analysis services, such that Natera has elected, and may continue to elect in the future, to send a portion (or all) of its samples to its other supplier(s) instead of us, which it is not contractually prohibited from doing, given the non-exclusive nature of our agreement. Natera may also bring a portion (or all) of such services in-house in the future, which may result in them purchasing fewer (or no) such services from us, or none from us at all. Our agreement with Natera requires us to achieve certain quality and turnaround time metrics for Natera samples. Recently, the volumes of samples sent to us by Natera have fluctuated significantly and may continue to do so in the future, which could cause us to experience difficulty in achieving such metrics from time to time, or to meet our other obligations under our agreement. If we consistently fail to achieve such metrics, or any of our other obligations under our agreement with Natera, Natera may elect to send a portion (or all) of its samples to its other supplier(s) and/or bring such services in-house.

Additionally, Natera may allege that such failures to achieve the required metrics are a breach of our agreement and seek to terminate our agreement and/or pursue any remedies available to it under the agreement, at law or in equity. Relatedly, we have incurred expenses in connection with our scale-up activities under our agreement with Natera, and we may incur additional expenses to increase our laboratory’s capacity to process increased sample volumes from Natera, in addition to those from our other customers, in the future. Our activities under our agreement with Natera have had, and may continue to have, an impact on our business, including diversion of our resources and the attention of our management, including with respect to our internal research and development objectives and projects for our other customers, collaborators and/or partners. If we are unable to successfully increase our laboratory’s capacity and manage any such competing objectives and/or projects for other customers, we may be unable to meet the quality and timing requirements of our agreement with Natera or our other customers, collaborators and/or partners. We may also be unable to successfully research, develop, launch and/or commercialize our services or service capabilities. Furthermore, we recently announced the launch of NeXT Personal, a next-generation, tumor-informed liquid biopsy assay designed to detect and quantify MRD and recurrence in patients previously diagnosed with cancer. If NeXT Personal or any of our other services is seen as competing with Signatera or any of Natera’s other services, we will still be required to fulfill our obligations to Natera under our agreement, although Natera may elect to send a portion (or all) of its samples to its other supplier(s) and/or bring such services in-house. If the volume of samples received under our agreement with Natera were to be significantly reduced or eliminated, or if our agreement with Natera were to be terminated, for these or other reasons, or if we are unable to successfully research, develop, launch and/or commercialize our services or service capabilities, including NeXT Personal, our business, financial condition, revenue and other operating results, and cash flows may be materially harmed.

If we cannot maintain our current customer relationships, or fail to acquire new customers, our revenue prospects will be reduced. Many of our customers are biopharmaceutical companies engaged in clinical trials of new drug candidates, which trials are expensive, can take many years to complete, and have inherently uncertain outcomes.

Our customers other than the VA MVP and Natera are primarily biopharmaceutical companies that use our services to support clinical trials. Our future success is substantially dependent on our ability to maintain our customer relationships and to establish new ones. Many factors have the potential to impact our customer relations, including the type of support our customers and potential customers require and our ability to deliver it, our customers’ satisfaction with our services, and other factors that may be beyond our control. Furthermore, our customers may decide to decrease or discontinue their use of our services due to changes in research and product development plans (including as a result of the COVID-19 pandemic), failures in their clinical trials, financial constraints, or utilization of internal testing resources or tests performed by other parties, or other circumstances outside of our control.

We engage in conversations with customers regarding potential commercial opportunities on an ongoing basis in the event that one of these customers’ drug candidates is approved. There is no assurance that any of these conversations will result in a commercial agreement, or if an agreement is reached, that the resulting relationship will be successful or that clinical studies conducted as part of the engagement will produce successful outcomes. Speculation in the industry about our existing or potential relationships with biopharmaceutical companies could be a catalyst for adverse speculation about us, our services, and our technology, which can adversely affect our reputation and our business. In addition, the termination of these relationships could result in a temporary or permanent loss of revenue.

Our customers’ clinical trials are expensive, can take many years to complete, and their outcome is inherently uncertain. Failure can occur at any time during the clinical trial process. Product candidates in later stages of clinical trials may fail to show the desired safety and efficacy traits despite having progressed through pre-clinical studies and early clinical trials. Many of the biopharmaceutical companies that are our customers do not have products approved for commercial sale and are not profitable. These customers must continue to raise capital in order to continue their development programs and to potentially continue as our customers. If our customers’ clinical trials fail or they are unable to raise sufficient capital to continue investing in their clinical programs, our revenue from these customers may decrease or cease entirely, and our business may be harmed. Furthermore, even if these customers have a drug approved for commercial sale, they may not choose to use our services as a companion diagnostic with their drug, thereby limiting our potential revenue.

28

We rely on a limited number of suppliers, or in some cases, a sole supplier, for some of our laboratory instruments and materials, and we may not be able to find replacements or immediately transition to alternative suppliers should we need to do so.

We rely on a limited number of suppliers for sequencers and other equipment and materials that we use in our laboratory operations. For example, we rely on Illumina as the sole supplier of sequencers and various associated reagents and other materials used in our routine laboratory operations, and as the sole provider of maintenance and repair services for these sequencers. Our Subcontract Agreement with Illumina is set to expire in March 2022, and our various pricing agreements with Illumina are set to expire on various dates up to December 2022. In August 2021, Illumina completed its acquisition of GRAIL, a company focused on early cancer detection and potentially other forms of cancer analysis using next-generation sequencing technology. Any disruption in Illumina’s operations, or our inability to negotiate an extension to our agreements with Illumina on acceptable terms, or at all, or any competitive pressure resulting from Illumina’s acquisition of GRAIL, could negatively impact our supply chain and laboratory operations and our ability to conduct our business and generate revenue. Additionally, the COVID-19 pandemic has disrupted, and may continue to disrupt, Illumina’s ability to perform under our Subcontract Agreement and fulfill our purchase orders for reagents or other materials in a timely manner and the pandemic has also disrupted, and may continue to disrupt, the ability of our other suppliers to fulfill our purchase orders in a timely manner or at all. Our suppliers could cease supplying these materials and equipment at any time, or fail to provide us with sufficient quantities of materials or equipment that meet our specifications. Our laboratory operations have been and in the future could be interrupted if we encounter delays or difficulties in securing sequencers or other equipment or materials, or if we cannot obtain an acceptable substitute. Any such interruption could significantly affect our business, financial condition, results of operations, and reputation.

We believe that there are only a few manufacturers other than Illumina that are currently capable of supplying and servicing the equipment necessary for our laboratory operations, including sequencers and various associated reagents. Likewise, we believe that there are a limited number of manufacturers and suppliers for other reagents and materials necessary for our laboratory operations, such as the sample preparation reagents required for our ACE technology, which enables our NeXT Platform to provide more comprehensive sequencing coverage, as well as those required to create personalized liquid biopsy panels for each patient as part of our NeXT Personal assay. Although we have evaluated and may continue in the future to evaluate equipment and materials from other suppliers, the use of equipment or materials provided by these replacement suppliers would require us to alter our laboratory operations. Transitioning to a new supplier would be time-consuming and expensive, would likely result in interruptions in our laboratory operations, could affect the performance specifications of our laboratory operations, or could require that we revalidate our tests. Additionally, an existing supplier of ours may allege that such activities constitute a breach of its agreement with us and may cease supplying us with sufficient quantities of materials or equipment that meet our specifications, in a timely manner or at all. Moreover, an existing supplier or third party may allege that such activities, replacement equipment or materials infringe, misappropriate or otherwise violate its intellectual property, and may bring infringement or other intellectual property-related claims against us. See “—Litigation or other proceedings or third-party claims of intellectual property infringement, misappropriation or other violations may require us to spend significant time and money, and could in the future prevent us from selling our tests or impact our stock price, any of which could have a material adverse effect.” We cannot assure you that, if we were forced to replace Illumina or another supplier on which we rely, we would be able to secure alternative equipment, reagents, and other materials, and bring such equipment, reagents, and other materials on-line and revalidate them without experiencing interruptions in our workflow. If we encounter delays or difficulties in securing, reconfiguring, or revalidating the equipment and reagents we require for our services, our business, financial condition, results of operations, and reputation could be adversely affected.

In addition, the Device Master File that we have filed with the FDA, which is focused on the technology, quality management, and validation of our platform, specifically on its use for the development of personalized immunotherapies, is predicated on our use of specified equipment and processes, including Illumina sequencers and related equipment. The detailed information in the Device Master File is not shared with our customers, but with our permission they can reference our FDA file number in their Investigational New Drug filings with the FDA. If we were required to transition to a new supplier of sequencers or certain other equipment or processes in our laboratory, our Device Master File would need to be replaced or updated, and until such time as that occurred, customers for which we deliver services after the transition would not be able to reference our Device Master File, which would cause us to lose a competitive advantage.

We will need to invest in our infrastructure in advance of increased demand for our services; our failure to accurately forecast demand would have a negative impact on our business and our ability to achieve and sustain profitability.

In order to execute our business model, we need to invest in scaling our infrastructure, including hiring additional personnel and expanding laboratory capacity. We will also need to purchase additional equipment, some of which can take several months or more to procure, setup, and validate, and increase our software and computing capacity to meet increased demand. There is no assurance that any of these increases in scale, expansion of personnel, equipment, software, and computing capacities, or process enhancements will be successfully implemented, or that we will have adequate space in our laboratory facilities to accommodate such required expansion. We expect that much of this growth will be in advance of increased demand for our services. Our current and projected future expense levels are to a large extent fixed and are largely based on our current investment plans and our estimates of future test volume. As a result, if revenue does not meet our expectations we may not be able to promptly adjust or reduce our spending to levels commensurate with our revenue. If we fail to generate demand commensurate with our infrastructure growth or if we fail to scale our infrastructure sufficiently in advance of demand to successfully meet such demand, our business, prospects, financial condition, and results of operations could be adversely affected.

29

As we commercialize additional services or products, we may need to incorporate new equipment, implement new technology systems and laboratory processes, or hire new personnel with different qualifications. Failure to manage this growth or transition could result in turnaround time delays, higher costs, declining service and/or product quality, deteriorating customer service, and slower responses to competitive challenges. A failure in any one of these areas could make it difficult for us to meet market expectations for our services, and could damage our reputation and the prospects for our business.

If our facilities become damaged or inoperable, or we are required to vacate the facilities, our ability to sell and provide our services and pursue our research and development efforts may be jeopardized.

We currently derive our revenue from our genomic analysis conducted in our laboratories. Currently, we do not have any clinical reference or research and development laboratory facilities other than our facilities in Menlo Park, California and the facilities being developed for our use in Shanghai, China and planned future facilities in Fremont, California. Our facilities and equipment could be harmed or rendered inoperable by natural or man-made disasters, including fires, earthquakes, flooding, and power outages, which may render it difficult or impossible for us to sell or perform our services for some period of time. Additionally, as a result of the ongoing COVID-19 pandemic, we have limited access to our office and laboratory facilities in Menlo Park to protect the health and safety of our employees and to comply with applicable state and local orders. Northern California has recently experienced serious fires and the San Francisco Bay Area is considered to lie in an area with earthquake risk. The inability to sell or to perform our sequencing and analysis services, disruptions in our operations, or the backlog of samples that could develop if our facilities are inoperable for even a short period of time, may result in the loss of customers or harm to our reputation or relationships with scientific or clinical collaborators, and we may be unable to regain those customers or repair our reputation or such relationships in the future. The limited access to our laboratory facilities as a result of the COVID-19 pandemic has resulted, and may in the future result, in a loss in productivity, including delays to research and development programs. Furthermore, our facilities and the equipment we use to perform our services and our research and development work could be costly and time-consuming to repair or replace.

Additionally, a key component of our research and development process involves using biological samples as the basis for the development of our services. In some cases, these samples are difficult to obtain. If the parts of our laboratory facilities where we store these biological samples were damaged or compromised, our ability to pursue our research and development projects, as well as our reputation, could be jeopardized. We carry insurance for damage to our property and the disruption of our business, but this insurance may not be sufficient to cover all of our potential losses and may not continue to be available to us on acceptable terms, if at all.

Further, if our laboratory facilities became inoperable, we would likely not be able to license or transfer our technology to other facilities with the qualifications, including state licensure and CLIA certification, that would be necessary to cover the scope of our current and our planned future services. Even if we were to find facilities with such qualifications to perform our services, they may not be available to us on commercially reasonable terms.

Our planned opening of our new headquarters and laboratory facilities in Fremont, California could divert management’s attention and disrupt our ongoing business.

We plan to relocate our corporate headquarters to an existing building located in Fremont, California that was leased in August 2021. We also plan to build and operate new laboratory facilities in the building. These efforts will involve significant tenant improvements, construction and regulatory compliance activities to be undertaken, including state licensure and CLIA certification for such laboratory facilities. Such efforts may distract management from current operations, disrupt planned research, development or regulatory compliance activities, and result in greater than expected liabilities and expenses, any of which could result in a material adverse effect on our business prospects, financial condition, or results of operations.

Our success depends on our ability to provide reliable and timely, high-quality genomic data and analyses and to rapidly evolve to meet our customers’ needs.

Errors, including if our tests fail to accurately detect gene variants, or mistakes, including if we fail to or incompletely or incorrectly identify the significance of gene variants, could have a significant adverse impact on our business. We classify variants in accordance with guidelines that are subject to change and subject to our interpretation. There have also been and could in the future be flaws in the databases, third-party tools or algorithms we use, or in the software that handles automated parts of our classification protocol. If we receive poor quality or degraded samples, our tests may be unable to accurately detect gene variants or we may fail to or incompletely or incorrectly identify the significance of gene variants, which could have a significant adverse impact on our business. In addition, our customers require timely turnaround of high-quality genomic data and analyses, and if we were not able to meet our customers’ specific requirements, it could also have a significant adverse effect on our business.

Inaccurate results or misunderstandings of, or inappropriate reliance on, the information we provide to our customers could lead to, or be associated with, lack of efficacy, side effects or adverse events in patients who use our tests, or who rely on our tests to determine therapies to develop, select or monitor, including treatment-related death, and could lead to termination of our services or result in claims against us. A product liability or professional liability claim could result in substantial damages and be costly and time-consuming for us to defend.

Although we maintain liability insurance, including for errors and omissions and professional liability, we cannot assure you that our insurance would be sufficient to protect us from the financial impact of defending against these types of claims, or any judgments, fines, or settlement costs arising out of any such claims. Any liability claim, including an errors and omissions liability claim, brought against us, with or without merit, could increase our insurance rates or prevent us from securing insurance coverage in the future. Additionally, any liability lawsuit could cause injury to our reputation or cause us to suspend sales of our tests or cause a suspension of our license to operate. The occurrence of any of these events could have an adverse effect on our business, reputation, and results of operations.

30

If we cannot develop services and products to keep pace with rapid advances in technology, medicine, and science, or if we experience delays in developing such services and products, our operating results and competitive position could be harmed.

In recent years, there have been numerous advances in technologies relating to the diagnosis and treatment of cancer. Several new cancer drugs have been approved, and a number of new drugs are in pre-clinical and clinical development. There have also been advances in methods used to identify patients likely to benefit from these drugs based on analysis of biomarkers. We must continuously develop new services and products, enhance any existing services, and avoid delays in such developments and enhancements to keep pace with evolving technologies on a timely and cost-effective basis. Our current services and our planned future services and products could become obsolete unless we continually innovate and expand them to demonstrate benefit in the diagnosis, monitoring, or prognosis of patients with cancer. New cancer therapies typically have only a few years of clinical data associated with them, and much of that data may not be disclosed by the pharmaceutical company that conducted the clinical trials. This could limit our ability to develop services and products based on, for example, biomarker analysis related to the appearance or development of resistance to those therapies. If we cannot adequately demonstrate the clinical utility of our services and our planned future services and products to new treatments, sales of our services could decline, which would have a material adverse effect on our business, financial condition, and results of operations.

We are researching and developing improvements to our tests and test features on a continuous basis, but we may not be able to make these improvements on a timely basis, and even if we do, we may not realize the benefits of these efforts in our financial results.

To remain competitive, we must continually research and develop improvements to our tests or test features. However, we cannot assure you that we will be able to develop and commercialize the improvements to our tests or test features on a timely basis. Our competitors may develop and commercialize competing or alternative tests and improvements faster than we are able to do so. In addition, we must expend significant time and funds in order to conduct research and development, further develop and scale our laboratory processes, and further develop and scale our infrastructure. We may never realize a return on investment on this effort and expense, especially if our improvements fail to perform as expected. If we are not able to realize the benefits of our efforts to improve our tests or test features, it could have an adverse effect on our business, financial condition, and results of operations.

Personalized cancer therapies represent new therapeutic approaches that could result in heightened regulatory scrutiny, delays in clinical development, or delays in or inability to achieve regulatory approval, commercialization, or payor coverage, any of which could adversely affect our business.

We currently work with certain companies developing personalized cancer therapies, and our future success will in part depend on our personalized cancer customers obtaining regulatory approval for and commercializing their product candidates. Because personalized cancer therapies represent a new approach to immunotherapy for the treatment of cancer and other diseases, developing and commercializing personalized cancer therapies is subject to a number of challenges.

Actual or perceived safety issues, including adoption of new therapeutics or novel approaches to treatment, may adversely influence the willingness of subjects to participate in clinical studies, or if approved by applicable regulatory authorities, of physicians to subscribe to the novel treatment mechanics. The FDA or other applicable regulatory authorities may ask for specific post-market requirements, and additional information regarding benefits or risks of our services may emerge at any time prior to or after regulatory approval.

In the EEA (and Northern Ireland) the new European Union (“EU”) In Vitro Diagnostic Device Regulation (the “IVDR”) entered into force on May 25, 2017, replacing the In-Vitro Diagnostic Directive (the “IVDD”) (and national legislation that implemented the IVDD in member states) as the primary legislation governing IVDs. Most requirements under the IVDR will not apply until the end of a transition period which is expected to occur on May 26, 2022. The IVDR broadens the scope of the regulation of IVDs and, among other things, tightens the requirements for clinical evidence and conformity assessment, increases transparency requirements, and introduces a requirement for a unique device identifier for every IVD. Under the IVDR there are four classes of IVDs, referred to as classes A, B, C, and D. IVDs are placed into a class based on their perceived risk to the patient and wider public. The main requirements of the IVDR apply regardless of the class which the relevant device falls into, and class A devices (including instruments and specimen receptacles) are the only devices that can be self-certified as meeting the requirements of the IVDR. The IVDR explicitly includes software used for diagnostic purposes in its scope. The IVDR requires pre-registration and post-market data collection to ensure that the device meets the relevant requirements. It is also notable that diagnostic and therapeutic services offered to customers in the EEA (and Northern Ireland) (whether directly or via intermediaries) by providers that are based outside the EEA will be covered by the IVDR. The IVDR will not apply to Great Britain (England, Wales and Scotland). These additional regulatory requirements are likely to increase the cost and time required in order to obtain regulatory approval for products in the EEA where such approval was already necessary, and in certain cases will introduce a new requirement to obtain regulatory approval where one did not exist under the IVDD arrangements. Further, the IVDR may result in devices being classified in a higher risk category than would have been the case under the existing IVDD arrangements.

Our ability, and the ability of our customers, to commercialize diagnostic tests based on our technology will depend in part on the extent to which coverage and reimbursement for these tests will be available from third-party payors. Coverage and reimbursement of new products and services is uncertain, and whether the companies that use our instruments to develop their own products or services will attain coverage and adequate reimbursement is unknown. In the U.S., there is no uniform policy for determining coverage and reimbursement. Coverage can differ from payor to payor, and the process for determining whether a payor will provide coverage may be separate from the process for setting the reimbursement rate. In addition, the U.S. government, state legislatures and foreign governments have shown significant interest in implementing cost containment programs to limit the growth of government-paid healthcare costs, including price controls and restrictions on reimbursement.

31

Physicians, hospitals, and third-party payors often are slow to adopt new products, technologies, and treatment practices that require additional upfront costs and training. Physicians may not be willing to undergo training to adopt personalized cancer therapies, may decide that such therapies are too complex to adopt without appropriate training or not cost-efficient, and may choose not to administer these therapies. Based on these and other factors, hospitals and payors may decide that the benefits of personalized cancer therapies do not or will not outweigh their costs.

The loss of key members of our executive management team could adversely affect our business.

Our success in implementing our business strategy depends largely on the skills, experience, and performance of key members of our executive management team and others in key management positions, including John West, our Chief Executive Officer, Richard Chen, our Chief Medical Officer, and Aaron Tachibana, our Chief Financial Officer. The collective efforts of each of these persons and others working with them as a team are critical to us as we continue to develop our technologies, services, products, and research and development programs. As a result of the difficulty in locating qualified new management, the loss or incapacity of existing members of our executive management team could adversely affect our operations. If we were to lose one or more of these key employees, or if one or more of these key employees were to become unable to perform his or her duties due to contracting COVID-19, we could experience difficulties in finding qualified successors, competing effectively, developing our technologies, and implementing our business strategy. Each member of our executive management team has an employment agreement; however, the existence of an employment agreement does not guarantee retention of members of our executive management team, and we may not be able to retain those individuals. We do not maintain “key person” life insurance on any of our employees.

In addition, we rely on collaborators, consultants, and advisors, including scientific and clinical advisors, to assist us in formulating our research and development and commercialization strategy. Our collaborators, consultants, and advisors are generally employed by employers other than us and may have commitments under agreements with other entities that may limit their availability to us.

The loss or extended illness of a key employee, the failure of a key employee to perform in his or her current position, or our inability to attract and retain skilled employees could result in our inability to continue to grow our business or to implement our business strategy.

We rely on highly skilled personnel in a broad array of disciplines and if we are unable to hire, retain, or motivate these individuals, or maintain our corporate culture, we may not be able to maintain the quality of our services or grow effectively.

Our performance, including our research and development programs and laboratory operations, largely depends on our continuing ability to identify, hire, develop, motivate, and retain highly skilled personnel for all areas of our organization. Competition in our industry for qualified employees is intense, and we may not be able to attract or retain qualified personnel in the future, including bioinformatic scientists, bioinformatic engineers, software engineers, statisticians, variant curators, clinical laboratory scientists (“CLS”), and genetic counselors, due to the competition for qualified personnel among life science businesses, technology companies, as well as universities and public and private research institutions, particularly in the San Francisco Bay Area. For example, California has a shortage of qualified CLS, who must be licensed by the California Department of Public Health to perform clinical testing in laboratories located in California such as our CLIA-certified and CAP-accredited laboratory. We face intense competition for, and we have experienced and may in the future experience difficulty attracting and retaining, sufficient numbers of licensed and qualified CLS to support the needs of our business and our laboratory capacity expansion efforts. All of our U.S. employees are at-will, which means that either we or the employee may terminate their employment at any time. In addition, our compensation arrangements, such as our equity award programs, may not always be successful in attracting new employees and retaining and motivating our existing employees for reasons that may include movements in our stock price. If we are not able to attract and retain the necessary personnel, including licensed and qualified CLS, to accomplish our business objectives, we may experience constraints that could adversely affect our ability to scale our business and support our research and development efforts and our laboratory operations. We believe that our corporate culture fosters innovation, creativity, and teamwork. However, as our organization grows, we may find it increasingly difficult to maintain the beneficial aspects of our corporate culture. This could negatively impact our ability to retain and attract employees and our future success.

We may not be able to manage our future growth effectively, which could make it difficult to execute our business strategy.

Our expected future growth could create a strain on our organizational, administrative, and operational infrastructure, including facilities (such as our planned future facilities in Fremont, California), laboratory operations, quality control, customer service, marketing and sales, and management. We may not be able to maintain the quality of or expected turnaround times for our tests, or satisfy customer demand as our test volume grows. Our ability to manage our growth properly will require us to continue to improve our operational, financial, and management controls, as well as our reporting systems and procedures. As a result of our growth, our operating costs may escalate even faster than planned, and some of our internal systems may need to be enhanced or replaced. If we are unable to manage our growth effectively, it may be difficult for us to execute our business strategy and our business could be harmed.

32

We may acquire businesses or assets, form joint ventures, or make investments in other companies or technologies that could harm our operating results, dilute our stockholders’ ownership, or cause us to incur debt or significant expense.

As part of our business strategy, we may pursue acquisitions of complementary businesses or assets, as well as technology licensing arrangements. We may also pursue strategic alliances that leverage our core technology and industry experience to expand our offerings or distribution, or make investments in other companies. As an organization, we have limited experience with respect to acquisitions as well as the formation of strategic alliances and joint ventures. We may not identify or complete these transactions in a timely manner, on a cost-effective basis, or at all, and we may not realize the anticipated benefits of any acquisition, technology license, strategic alliance, joint venture or investment, and their consideration may be distracting to our management or prevent us from pursuing other opportunities. In addition, we may not be able to find suitable partners or acquisition candidates, and we may not be able to complete such transactions on favorable terms, if at all. Any future such transactions by us also could result in significant write-offs, the incurrence of debt and contingent liabilities, exposure to additional liability, exposure to additional revenue concentration, additional regulatory obligations and exposure to additional potential liability, any of which could harm our operating results and future prospects. If we make any acquisitions in the future, we may not be able to integrate these acquisitions successfully into our existing business, and we could assume unknown or contingent liabilities. Integration of an acquired company or business also may require management resources that otherwise would be available for ongoing development of our existing business.

To finance any acquisitions or investments, we may choose to raise additional funds. The various ways we could raise additional funds carry potential risks. See “—Financial and Market Risks and Risks Related to Owning Our Common Stock—Our inability to raise additional capital on acceptable terms in the future may limit our ability to continue to operate our business and further expand our operations.” If the price of our common stock is low or volatile, we may not be able to acquire other companies using stock as consideration. Alternatively, it may be necessary for us to raise additional funds for these activities through public or private financings. Additional funds may not be available on terms that are favorable to us, or at all.

Ethical, legal, and social concerns related to the use of genetic information could reduce demand for our tests.

Genetic testing has raised ethical, legal, and social concerns regarding privacy and the appropriate uses of the resulting information. Governmental authorities have, through the Genetic Information Nondisclosure Act, and could further, for social or other purposes, limit or regulate the use of genetic information or genetic testing or prohibit testing for genetic predisposition to certain conditions, particularly for those that have no known cure. Ethical and social concerns may also influence governmental authorities to deny or delay the issuance of patents for technology relevant to our business. Similarly, these concerns may lead patients to refuse to use, or clinicians to be reluctant to order, genetic tests even if permissible. These and other ethical, legal, and social concerns may limit market acceptance of our tests or reduce the potential markets for our tests, either of which could have an adverse effect on our business, financial condition, or results of operations.

Any collaboration arrangements that we have entered into or may enter into in the future may not be successful, which could adversely affect our ability to develop and commercialize our services and products.

Any current or future collaborations, including any strategic alliances or any collaborations to develop companion diagnostic tests, that we have entered (for example, our collaborations with the Mayo Clinic, MapKure, LLC (“MapKure”), which is jointly-owned by BeiGene, Ltd. and SpringWorks Therapeutics, Inc., and Moores Cancer Center at UC San Diego Health) or may enter into may not be successful. The success of our collaboration arrangements will depend heavily on the efforts and activities of our collaborators. Collaborations are subject to numerous risks, which include that:

33

If we are unable to successfully obtain rights to required third-party intellectual property rights or maintain the existing intellectual property rights we have, we may have to abandon development of that program and our business and financial condition could suffer.

Our planned expansion into China entails substantial risks.

In June 2020, we announced a partnership with a clinical genomics and life sciences company headquartered in China as a means to expand business operations into China in the near term. Our first wholly owned subsidiary was formed in Shanghai in October 2020. Our expansion and investment plans are subject to substantial risks which may include, but are not limited to: the inability to protect our intellectual property rights under Chinese law, which may not offer as high a level of protection as U.S. law; unexpectedly long negotiation periods with Chinese suppliers and customers; quality issues related to supplies sourced from local vendors; unexpectedly high labor costs due to a tight labor supply; foreign investment restrictions, including those that restrict foreign investment in the development and application of gene diagnosis and treatment technologies (which we believe prevent us from directly offering our NeXT Dx test, or other diagnostic tests based on our NeXT Platform, to patients in China); and difficulty in repatriating funds and selling or transferring assets. Our investments in China also expose us to additional foreign currency exchange risk. In addition, as tensions have escalated between the U.S. and China, we believe there is an enhanced risk that our planned investments in China may be subject to unforeseen risks or restrictions, which may include expropriation of the investments by the Chinese government or new restrictions imposed by the U.S. government on the export of necessary goods or technologies to our Shanghai subsidiary. These and other risks may result in our not realizing a return on, or losing some, or all, of our planned investments in China, which could have a material adverse effect on our financial condition and financial performance.

Personal privacy, cyber security, and data protection are becoming increasingly significant issues in China. For example, the State Council of the People’s Republic of China adopted the Regulations of the People’s Republic of China on Administration of Human Genetic Resources, which went into effect on July 1, 2019. The regulations establish a framework for the collection, preservation, utilization, and supply abroad of human genetic resources of China. The regulations also establish a framework for the use of data and other information generated from use of human genetic resources of China. The regulations also provide that foreign organizations, individuals and entities established or controlled by them are prohibited to collect or preserve China’s human genetic resources or transport them abroad. Due to the lack of detailed interpretations and implementations, it is not clear whether the agency in China responsible for enforcing the regulations will grant the necessary approvals for use by us and our partners of our NeXT Platform or our other current or future products in research or clinical projects involving China’s human genetic resources or information generated therefrom. For example, we understand that the initial application by one of our pharmaceutical customers for such a project approval was previously rejected by such agency in China for reasons relating to data retention by our customer and sharing of rights to research results with our customer’s collaborator in China. Although it is our understanding that the agency’s decision was not based on the use of our NeXT Platform in the project, and that the agency subsequently approved applications by our customer for this project and another project also involving the use of our NeXT Platform, we are supporting and expect in the future to support the preparation of multiple such applications, and there is no guarantee that any such additional applications will be approved by such agency in the future. The Chinese government separately has various regulations relating to the collection, use, storage, disclosure, and security of data, among other things, including the new Personal Information Protection Law (“PIPL”) passed by the Standing Committee of China’s National People’s Congress on August 20, 2021, which took effect on November 1, 2021 and contains provisions similar to those of the General Data Protection Regulation (EU) 2016/679 (“GDPR”) adopted by the EU, including extraterritorial reach, restrictions on data transfer, compliance obligations and sanctions for non-compliance. We cannot assure you that we will be able to comply with all these regulatory requirements. Any failure to comply with relevant regulations and policies could result in significant cost and liability to us and could adversely affect our business and results of operations. For example, the consequences for failing to comply with the PIPL could potentially include monetary penalties, business suspension and revocation of business licenses. Any additional new regulations or the amendment or modification of previously implemented regulations, or the failure to receive any necessary approvals for use of our products in connection with such projects, could require us and our partners to change our business plans and incur additional costs, and could limit our ability to generate revenue in China.

34

Expansion into international markets would subject us to increased regulatory oversight and regulatory, economic, social, health and political uncertainties, which could cause a material adverse effect on our business, financial position, and results of operations.

We may in the future expand our business and operations into international jurisdictions in which we have limited operating experience, including with respect to seeking regulatory approvals and marketing and selling products and services. For example, in June 2020, we announced our intention to expand into China. As we expand internationally, our operations in these jurisdictions may be adversely affected by general economic conditions and economic and fiscal policy, including changes in exchange rates and controls, interest rates and taxation policies, increased government regulation, social instability, local or regional health crises, and political, economic or diplomatic developments in the future. Certain jurisdictions have, from time to time, experienced instances of civil unrest and hostilities, both internally and with neighboring countries. Rioting, military activity, terrorist attacks, or armed hostilities could cause our operations in such jurisdictions to be adversely affected or suspended. We generally do not have insurance for losses and interruptions caused by terrorist attacks, military conflicts and wars. In addition, anti-bribery and anti-corruption laws may conflict with some local customs and practices in foreign jurisdictions. Our international operations may subject us to heightened scrutiny under the FCPA, the United Kingdom (the “U.K.”) Bribery Act and similar anti-bribery laws, and could subject us to liability under such laws despite our best efforts to comply with such laws. As a result of our policy to comply with the FCPA, the U.K. Bribery Act and similar anti-bribery laws, we may be at a competitive disadvantage to competitors that are not subject to, or do not comply with, such laws. Further, notwithstanding our compliance programs, there can be no assurances that our policies will prevent our employees or agents from violating these laws or protect us from any such violations. Additionally, we cannot predict the nature, scope or impact of any future regulatory requirements that may apply to our international operations or how foreign governments will interpret existing or new laws. Alleged, perceived, or actual violations of any such existing or future laws by us or due to the acts of others, may result in criminal or civil sanctions, including contract cancellations or debarment, and damage to our reputation, any of which could have a material adverse effect on our business.

Regulatory, Legal and Cybersecurity Risks

Our tests may be subject to regulatory action if regulatory agencies determine that our tests do not appropriately comply with statutory and regulatory requirements enforced by the U.S. Food and Drug Administration, and/or CLIA requirements for quality laboratory testing.

The laws and regulations governing the marketing of clinical laboratory tests are extremely complex and in many instances there are no significant regulatory or judicial interpretations of these laws and regulations. The Federal Food, Drug and Cosmetic Act (the “FDC Act”) defines a medical device to include any instrument, apparatus, implement, machine, contrivance, implant, in vitro reagent or other similar or related article, including a component, part, or accessory, intended for use in the diagnosis of disease or other conditions, or in the cure, mitigation, treatment or prevention of disease, in man or other animals. Some of our tests may be considered by the FDA to be in vitro diagnostic products that are subject to regulation as medical devices. Among other things, pursuant to the FDC Act and its implementing regulations, the FDA regulates the research, testing, manufacturing, safety, labeling, storage, recordkeeping, premarket clearance or approval, marketing and promotion, and sales and distribution of medical devices in the U.S. to ensure that medical products distributed domestically are safe and effective for their intended uses. In addition, the FDA regulates the import and export of medical devices.

Although the FDA has statutory authority to assure that medical devices are safe and effective for their intended uses, the FDA has generally exercised its enforcement discretion and not enforced applicable regulations with respect to laboratory developed tests (“LDTs”), which are a subset of in vitro diagnostic devices that are intended for clinical use and designed, manufactured, and used entirely within a single laboratory. We currently market our tests as LDTs and, therefore, we believe that they are not currently subject to the FDA’s enforcement of its medical device regulations and the applicable FDC Act provisions. Despite the FDA’s historic enforcement discretion policy with respect to LDTs, in November 2017, the FDA finalized a classification order setting out the regulatory requirements that apply to certain genetic health risk tests and revised a separate classification order exempting certain carrier screening tests from FDA premarket clearance and approval requirements when certain regulatory requirements are met. None of our tests comply with these classification orders because we market our tests as LDTs that are subject to the FDA’s policy of enforcement discretion. However, the FDA may find that our tests do not fall within the definition of an LDT, and may determine that our tests are subject to the FDA’s enforcement of its medical device regulations, including the recent classification orders, and the applicable FDC Act provisions. While we believe that we are currently in material compliance with applicable laws and regulations, we cannot assure you that the FDA or other regulatory agencies would agree with our determination, and a determination that we have violated these laws, or a public announcement that we are being investigated for possible violations of these laws, could adversely affect our business, prospects, results of operations or financial condition. If the FDA determines that our tests are subject to enforcement as medical devices, we could be subject to enforcement action, including administrative and judicial sanctions, and additional regulatory controls and submissions for our tests, all of which could be burdensome. We and/or our collaborators may also voluntarily submit one or more of our tests for premarket notification, review, clearance or approval by the FDA as medical devices. For example, under our collaboration with MapKure, we expect to develop new, advanced biomarkers selected by MapKure for regulatory submission and approval as a companion diagnostic, in which case we would also be subject to potentially burdensome additional regulatory controls and submissions for one or more of our tests. See “—Failure to comply with federal, state, and foreign laboratory licensing requirements and the applicable requirements of the FDA or any other regulatory authority, could cause us to lose the ability to perform our tests, experience disruptions to our business or become subject to administrative or judicial sanctions.”

Moreover, LDTs may in the future become subject to more onerous regulation by the FDA. A significant change in any of the laws, regulations, or policies may require us to change our business model in order to maintain regulatory compliance. At various times since 2006, the FDA has issued documents outlining its intent to require varying levels of FDA oversight of many types of LDTs. In October 2014, the FDA issued two non-binding draft guidance documents that set forth a proposed risk-based regulatory framework that would apply varying levels of FDA oversight to LDTs. The FDA indicated that it did not intend to implement its proposed framework until the draft guidance documents are finalized. The FDA was expected to finalize its proposal for the oversight of LDTs before the end

35

of 2016, but in November 2016, the FDA announced that it would halt finalizing of the guidance documents and continue to work with stakeholders, the incoming administration, and Congress on the approach to LDT regulation. This announcement was followed by the issuance of an information discussion paper on January 13, 2017, in which the FDA outlined a substantially revised “possible approach” to the oversight of LDTs. The discussion paper explicitly states that it is not a final version of the 2014 draft guidance and that it is not enforceable and does not represent the FDA’s “formal position.” It is unclear at this time if or when the FDA will finalize its plans to end enforcement discretion for LDTs, and even then, whether the new regulatory requirements are expected to be phased-in over time. However, the FDA may decide to regulate certain LDTs on a case-by-case basis at any time, which could result in delay or additional expense in offering our tests and tests that we may develop in the future.

Legislative proposals addressing oversight of genetic testing and LDTs have been introduced in previous Congresses, and we expect that new legislative proposals will be introduced from time to time in the future. We cannot provide any assurance that FDA regulation, including pre-market review, will not be required in the future for our tests, whether through finalization of guidance issued by the FDA, new enforcement policies adopted by the FDA or new legislation enacted by Congress. It is possible that legislation will be enacted into law or guidance could be issued by the FDA that may result in increased regulatory burdens for us to continue to offer our tests or to develop and introduce new tests. This legislative and regulatory uncertainty exposes us to the possibility of enforcement action or additional regulatory controls and submissions for our tests, both of which could be burdensome. We cannot be certain that the FDA will not enact rules or guidance documents that could impact our ability to purchase certain materials necessary for the performance of our tests, such as products labeled for research use only. Should any of the reagents obtained by us from suppliers and used in conducting our tests be affected by future regulatory actions, our business could be adversely affected by those actions, including increasing the cost of testing or delaying, limiting, or prohibiting the purchase of reagents necessary to perform testing.

Additionally, the Centers for Medicare & Medicaid Services (“CMS”), and certain state agencies regulate the performance of LDTs (as authorized under CLIA and state law, respectively). Our tests are developed in compliance with CLIA requirements. However, if our laboratory fails to comply with the prescribed quality requirements for laboratory testing or other requirements for CLIA, we could lose CLIA certification. That in turn would impact our ability to operate our laboratory and provide results to our customers, which could negatively impact our business operations. The IVDR includes limited exemptions for LDTs, but such exemptions only apply to laboratories that are part of health institutions established in the EEA, and so any services undertaken outside of the EEA (for example at our facilities in the U.S.) will not be covered by such exemptions. In any event, such exemptions are limited in their scope, and only apply if a number of conditions are met, including that the health institution justifies that the “target patient group’s specific needs cannot be met, or cannot be met at the appropriate level of performance by an equivalent device available on the market” and do not cover devices that are manufactured on an “industrial scale”. Even where an exemption is applicable, such IVDs will still be subject to certain requirements under the IVDR. It is therefore unlikely that our tests will benefit from any exemption on the basis of being LDTs and will have to comply with the IVDR in full if we offer such tests to customers in the EEA (and Northern Ireland) (whether directly or via intermediaries).

If the FDA determines that our services are subject to enforcement as medical devices, we could incur substantial costs and time delays associated with satisfying statutory and regulatory requirements such as pre-market clearance or approval and we could incur additional expense in offering our tests and tests that we may develop in the future.

If the FDA determines that our tests and associated software do not fall within the definition of an LDT, or there are regulatory or legislative changes, or if we voluntarily submit one or more of our tests for premarket notification, review, clearance or approval by the FDA as medical devices, we may be required to obtain premarket clearance for our tests and associated software under Section 510(k) of the FDC Act or approval of a PMA. We would also be subject to ongoing regulatory requirements such as registration and listing requirements, medical device reporting requirements, and quality control requirements. If our tests are considered medical devices not subject to enforcement discretion, or if we voluntarily submit one or more of our tests for premarket notification, review, clearance or approval by the FDA as medical devices, the regulatory requirements to which our tests are subject would depend on the FDA’s classification of our tests. The FDA has issued regulations classifying generic types of medical devices into one of three regulatory control categories (Class I, Class II, or Class III) depending on the degree of regulation that the FDA finds necessary to provide reasonable assurance of their safety and effectiveness. The class into which a device is placed determines the requirements that a medical device manufacturer must meet both pre- and post-market.

Generally, Class I devices do not require premarket authorization, but are subject to a comprehensive set of regulatory authorities referred to as general controls. Class II devices, in addition to general controls, generally require special controls and premarket clearance through the submission of a section 510(k) premarket notification. Class III devices are subject to general controls and special controls, and also require premarket approval prior to commercial distribution, which is a more rigorous process than premarket clearance. Under the FDC Act, a device that is first marketed after May 28, 1976 is by default a Class III device requiring premarket approval unless it is within a type of generic device class that has been classified as Class I or Class II. Even if a device falls under an existing Class II, non-exempt, device classification, the product must also be shown to be “substantially equivalent” to a legally marketed predicate device through submission of a section 510(k) premarket notification. If after reviewing a firm’s 510(k) premarket notification, the FDA determines that a device is not substantially equivalent to a legally marketed predicate device, the new device is classified into Class III, requiring premarket approval. It is possible for a manufacturer to obtain a Class I or Class II designation without an appropriate predicate by submitting a de novo request for reclassification.

The process for submitting a 510(k) premarket notification and receiving FDA clearance usually takes from three to 12 months, but it can take significantly longer and clearance is never guaranteed. The process for submitting and obtaining FDA approval of a PMA is much more costly, lengthy, and uncertain. It generally takes from one to three years or even longer and approval is not guaranteed. PMA approval typically requires extensive clinical data and can be significantly longer, more expensive and more uncertain than the 510(k) clearance process. Despite the time, effort and expense expended, there can be no assurance that a particular device ultimately will be cleared or approved by the FDA through either the 510(k) clearance process or the PMA process on a timely basis, or at all.

36

If our tests are considered medical devices not subject to enforcement discretion, or if we voluntarily submit one or more of our tests for premarket notification, review, clearance or approval by the FDA as medical devices, one classification regulation that could be relevant to one or more of our tests is a classification for GHR assessment tests, codified at 21 C.F.R. § 866.5950. If our tests are considered medical devices that are not subject to enforcement discretion, or if we voluntarily submit one or more of our tests for premarket notification, review, clearance or approval by the FDA as medical devices, and one or more of our tests is considered to fall under the 21 C.F.R. § 866.5950 classification regulation for GHR tests, or under another Class II classification that is subject to a premarket notification requirement, we would be required to obtain marketing clearance for such tests. Further, if considered to fall under the 21 C.F.R. § 866.5950 classification for GHR tests, our tests would be required to adhere to specified special controls, such as labeling and testing specifications and information about the test to be posted on the manufacturer’s website. If any of our current or pipeline tests are not considered by the FDA to be GHR tests or do not qualify for the limited exemption for a sponsor’s subsequent GHR tests once the assessment system has been reviewed and cleared by FDA, or if any of our tests fall under a different non-exempt classification or are unclassified, we could be required to obtain 510(k) clearance or approval of a PMA for such test in the future.

If premarket review of our tests is required, the premarket review process may involve, among other things, successfully completing additional clinical trials. If we are required to conduct premarket clinical trials, whether using prospectively acquired samples or archival samples, delays in the commencement or completion of clinical testing could significantly increase our product development costs, delay commercialization of any future products, and interrupt sales of our current products. Many of the factors that may cause or lead to a delay in the commencement or completion of clinical trials may also ultimately lead to delay or denial of regulatory clearance or approval. The commencement of clinical trials may be delayed due to insufficient patient enrollment, which is a function of many factors, including the size of the patient population, the concerns around genetic testing, the nature of the protocol, the proximity of patients to clinical sites, and the eligibility criteria for the clinical trial.

If we are required to conduct clinical trials, we and any third-party contractors we engage would be required to comply with GCPs, which are regulations and guidelines enforced by the FDA, for products in clinical development. The FDA enforces these GCPs through periodic inspections of trial sponsors, principal investigators, and trial sites. If we or any third-party contractor fails to comply with applicable GCPs, the clinical data generated in clinical trials may be deemed unreliable and the FDA may require us to perform additional clinical trials before clearing or approving our marketing applications. A failure to comply with these regulations may require us to repeat clinical trials, which would delay the regulatory clearance or approval process. In addition, if these parties do not successfully carry out their contractual duties or obligations or meet expected deadlines, or if the quality, completeness or accuracy of the clinical data they obtain is compromised due to the failure to adhere to our clinical protocols or for other reasons, our clinical trials may have to be extended, delayed or terminated. Many of these factors would be beyond our control. We may not be able to enter into replacement arrangements without undue delays or considerable expenditures. If there are delays in testing or approvals as a result of the failure to perform by third parties, our research and development costs would increase, and we may not be able to obtain regulatory clearance or approval for our tests. In addition, we may not be able to establish or maintain relationships with these parties on favorable terms, if at all. Each of these outcomes would harm our ability to market our tests or to achieve or sustain profitability.

The FDA requires medical device manufacturers to comply with, among other things, current good manufacturing practices for medical devices, set forth in the Quality System Regulation at 21 C.F.R. Part 820, which requires manufacturers to follow elaborate design, testing, control, documentation, and other quality assurance procedures during the manufacturing process; the medical device reporting regulation, which requires that manufacturers report to the FDA if their device or a similar device they market may have caused or contributed to a death or serious injury or malfunctioned in a way that would likely cause or contribute to a death or serious injury if it were to recur; labeling regulations, including the FDA’s general prohibition against promoting products for unapproved or “off-label” uses; the reports of corrections and removals regulation, which requires manufacturers to report to the FDA if a device correction or removal was initiated to reduce a risk to health posed by the device or to remedy a violation of the FDC Act caused by the device which may present a risk to health; and the establishment registration and device listing regulation.

Moreover, there can be no assurance that any cleared or approved labeling claims will be consistent with our current claims or adequate to support continued adoption of our products. If premarket review is required for some or all of our products, the FDA may require that we stop selling our products pending clearance or approval, which would negatively impact our business. Even if our products are allowed to remain on the market prior to clearance or approval, demand for our products may decline if there is uncertainty about our products, if we are required to label our products as investigational by the FDA, or if the FDA limits the labeling claims we are permitted to make for our products. As a result, we could experience significantly increased development costs and a delay in generating additional revenue from our services, or from other services or products now in development.

In addition, any clearance or approval we obtain for our products may contain requirements for costly post-market testing and surveillance to monitor the safety or efficacy of the product. The FDA has broad post-market enforcement powers, and if unanticipated problems with our products arise, or if we or our suppliers fail to comply with regulatory requirements following FDA clearance or approval, we may become subject to enforcement actions such as:

• restrictions on manufacturing processes;

• restrictions on product marketing;

• warning letters;

• withdrawal or recall of products from the market;

37

• fines, restitution, or disgorgement of profits or revenue;

• suspension or withdrawal of regulatory clearances or approvals;

• limitation on, or refusal to permit, import or export of our products;

• product seizures;

• injunctions; or

• imposition of civil or criminal penalties.

Moreover, the FDA strictly regulates the promotional claims that may be made about medical devices. In particular, a medical device may not be promoted for uses that are not approved by the FDA as reflected in the device’s approved labeling. However, companies may share truthful and not misleading information that is otherwise consistent with the product’s FDA approved labeling. The FDA and other agencies actively enforce the laws and regulations prohibiting the promotion of off-label uses, and a company that is found to have improperly promoted off-label uses may be subject to significant civil, criminal, and administrative penalties.

In addition, many of the products we use to perform our tests, including sequencers and various associated reagents supplied to us by Illumina, are labeled as RUO in the U.S. RUO products are exempt from FDA medical device requirements provided their manufacturers comply with specified labeling and restrictions on distribution. The products must bear the statement: “For Research Use Only. Not for Use in Diagnostic Procedures.” Manufacturers of RUO products cannot make any claims related to safety, effectiveness or diagnostic utility, and RUO products cannot be intended by the manufacturer for clinical diagnostic use. A product promoted for diagnostic use may be viewed by the FDA as adulterated and misbranded under the FDC Act and is subject to FDA enforcement activities, including requiring the manufacturer to seek marketing authorization for the products. We currently use Illumina and other RUO products for our clinical diagnostic tests. If the FDA were to require clearance, approval or authorization for the sale of Illumina’s RUO products and if Illumina does not obtain such clearance, approval or authorization, we would have to find an alternative sequencing platform for some or all of our clinical diagnostic tests. We currently have not validated an alternative sequencing platform on which our tests could be run in a commercially viable manner. If we were not successful in selecting, acquiring on commercially reasonable terms and implementing an alternative platform on a timely basis, our business, financial condition and results of operations would be adversely affected. Similarly, a finding that any of our other suppliers failed to comply with applicable requirements could result in interruptions in our ability to supply our services to the market and adversely affect our operations.

Failure to comply with federal, state, and foreign laboratory licensing requirements and the applicable requirements of the FDA or any other regulatory authority, could cause us to lose the ability to perform our tests, experience disruptions to our business, or become subject to administrative or judicial sanctions.

We are subject to CLIA, a federal law that regulates clinical laboratories that perform testing on specimens derived from humans for the purpose of providing information for the diagnosis, prevention, or treatment of disease. CLIA regulations establish specific standards with respect to personnel qualifications, facility administration, proficiency testing, quality control, quality assurance, and inspections. We have a current CLIA certificate to conduct our tests at our laboratory in Menlo Park, California. To renew this certificate, we are subject to survey and inspection every two years. Moreover, CLIA inspectors may make random inspections of our clinical reference laboratory.

We are also required to maintain a license to conduct testing in California. California laws establish standards for day-to-day operation of our clinical reference laboratory in Menlo Park, including the training and skills required of personnel and quality control. Several other states in which we operate also require that we hold licenses to test specimens from patients in those states, under certain circumstances. For example, our clinical reference laboratory is required to be licensed on a product-specific basis by New York as an out-of-state laboratory, and our products, as LDTs, must be approved by the New York State Department of Health (the “NYDOH”) on a product-by-product basis before they are offered in New York. We are subject to periodic inspection by the NYDOH and are required to demonstrate ongoing compliance with NYDOH regulations and standards. To the extent NYDOH identified any non-compliance and we are unable to implement satisfactory corrective actions to remedy such non-compliance, the State of New York could withdraw approval for our tests. Additionally, states such as Maryland, Pennsylvania, and Rhode Island may also require us to maintain out-of-state licenses. Other states may have similar requirements or may adopt similar requirements in the future. Although we have obtained licenses from states where we believe we are required to be licensed, we may become aware of other states that require out-of-state laboratories to obtain licensure in order to accept specimens from the state, and it is possible that other states currently have such requirements or will have such requirements in the future. We may also be subject to regulation in foreign jurisdictions as we seek to expand international utilization of our tests or such jurisdictions adopt new licensure requirements, which may require review of our tests in order to offer them or may have other limitations such as restrictions on the transport of human blood necessary for us to perform our tests that may limit our ability to make our tests available outside of the U.S. Complying with licensure requirements in new jurisdictions may be expensive and/or time-consuming, may subject us to significant and unanticipated delays, or may be in conflict with other applicable requirements.

Failure to comply with applicable clinical laboratory licensure requirements may result in a range of enforcement actions, including license suspension, limitation, or revocation, directed plan of action, onsite monitoring, civil monetary penalties, and criminal sanctions as well as significant adverse publicity. Any sanction imposed under CLIA, its implementing regulations or state or foreign laws or regulations governing clinical laboratory licensure, or our failure to renew our CLIA certificate, a state or foreign license or accreditation, could have a material adverse effect on our business, financial condition, and results of operations. Even if we were able to bring our laboratory back into compliance, we could incur significant expenses and potentially lose revenue in doing so.

38

Failure to comply with the IVDR may result in a range of enforcement actions. Penalties under the IVDR are devolved to national governments, but the IVDR requires that such measures are “effective, proportionate, and dissuasive.” Initial indications suggest that penalties for breaches of the IVDR are likely to include fines and, potentially, prison sentences.

Although we market our tests as LDTs that are currently subject to the FDA’s exercise of enforcement discretion, if we fail to operate within the conditions of that exercise of enforcement discretion, if any of our products otherwise fail to comply with FDA regulatory requirements as enforced, or if we voluntarily submit one or more of our tests for premarket notification, review, clearance or approval by the FDA as medical devices, we would be subject to the applicable requirements of the FDC Act and the FDA’s implementing regulations. The FDA is empowered to impose sanctions for violations of the FDC Act and the FDA’s implementing regulations, including warning letters, civil and criminal penalties, injunctions, product seizure or recall, import bans, restrictions on the conduct of our operations and total or partial suspension of production. Any of the aforementioned sanctions could cause reputational damage, undermine our ability to maintain and increase our revenue, and harm our business, financial condition, and results of operations. In particular, if we or the FDA discover that any of our products have defects that call into question the accuracy of their results, we may be required to undertake a retest of all results and analyses provided during the period relevant to the defect, or recall the affected products. The direct costs incurred in connection with such a recall in terms of management time, administrative, and legal expenses and lost revenue, together with the indirect costs to our reputation could harm our business, financial condition, and results of operations, and our ability to execute our business strategy. While we believe that we are currently in material compliance with applicable laws and regulations as currently enforced, the FDA or other regulatory agencies may not agree, and a determination that we have violated these laws or a public announcement that we are being investigated for possible violations of these laws could adversely affect our business, financial condition, results of operations, and prospects.

If our security measures are compromised, or our information technology systems or those of our vendors, and other relevant third parties fail or suffer security breaches, loss or leakage of data, and other disruptions, this could result in a material disruption of our services, compromise sensitive information related to our business, harm our reputation, trigger breach notification obligations, prevent us from accessing critical information, and expose us to liability or other adverse effects to our business.

In the ordinary course of our business, we collect, process, receive, generate, use, transfer, disclose, make accessible, protect, secure, dispose of, transmit, share and store proprietary, confidential, and sensitive information, including PHI, personally identifiable information (“PII”), credit card and other financial information, intellectual property, trade secrets, and proprietary business information owned or controlled by ourselves or our customers, payors, and other parties. It is critical that we do so in a secure manner to maintain the confidentiality, integrity, and availability of such information. We depend on information technology and telecommunications systems for significant elements of our operations and we have installed, and expect to expand, a number of enterprise software systems that affect a broad range of business processes and functional areas, including, for example, systems handling human resources, financial reporting and controls, customer relationship management, regulatory compliance, and other infrastructure operations. We face a number of risks relative to protecting this critical information, including loss of access risk, inappropriate use or disclosure, inappropriate modification, and the risk of our being unable to adequately monitor, audit, and modify our controls over our critical information. This risk extends to the third-party vendors and subcontractors, as we have outsourced elements of our operations to third parties and as a result a number of third-party vendors and other contractors and consultants have access to our proprietary, confidential, and sensitive information. Our ability to monitor these third parties’ security practices is limited, and these third parties may not have adequate security measures in place.

We manage and maintain our applications and data utilizing a combination of on-site systems and cloud-based data centers. We utilize external security and infrastructure vendors to manage parts of our data centers. We also communicate sensitive data, including patient data, electronically, and through relationships with multiple third-party vendors and their subcontractors. These applications and data encompass a wide variety of business-critical information, including research and development information, patient data, commercial information, and business and financial information. Despite the precautionary measures we have taken to prevent unanticipated problems that could affect our information technology and telecommunications systems, failures or significant downtime of our information technology or telecommunications systems or those used by our third-party service providers could prevent us from conducting tests, preparing and providing reports to our customers, billing customers, collecting revenue, handling inquiries from our customers, conducting research and development activities, and managing the administrative aspects of our business. For example, in the first quarter of 2018, we experienced downtime in our information technology systems in connection with the adoption of certain new information technology, and our results of operations in the first and second quarters of 2018 were adversely affected as a result. Any disruption or loss of information technology or telecommunications systems on which critical aspects of our operations depend could have an adverse effect on our business.

Notwithstanding the implementation of security measures, given the size and complexity of our internal information technology systems and those of our third-party vendors and other contractors and consultants, and the increasing amounts of proprietary, confidential, and sensitive information that they maintain, such information technology systems are potentially vulnerable to breakdown, service interruptions, system malfunction, natural disasters, terrorism, war, and telecommunication and electrical failures, as well as security breaches from inadvertent or intentional actions by our personnel, third-party vendors, contractors, consultants, business partners, and/or other third parties, or from cyber-attacks by malicious third parties, which may compromise our system infrastructure, or that of our third-party partners, or lead to data leakage. Cyberattacks, malicious internet-based activity, and online and offline fraud are prevalent and continue to increase. These threats are becoming increasingly difficult to detect. We and the third parties upon which we rely may be subject to a variety of evolving threats, including but not limited to social-engineering attacks (including through phishing attacks), malicious code (such as viruses and worms), malware (including as a result of advanced persistent threat intrusions), denial-of-service attacks (such as credential stuffing), personnel misconduct or error, ransomware attacks, supply-chain attacks, software

39

bugs, server malfunctions, software or hardware failures, loss of data or other informationtechnology assets, adware, and other similar threats. Ransomware attacks, including by organized criminal threat actors,nation-states, and nation-state-supported actors, are becoming increasingly prevalent and severe and can lead to significantinterruptions in our operations, loss of data and income, reputational harm, and diversion of funds. Extortion payments may alleviatethe negative impact of a ransomware attack, but we may be unwilling or unable to make such payments due to, for example,applicable laws or regulations prohibiting such payments. Similarly, supply-chain attacks have increased in frequency and severity,and we cannot guarantee that third parties and infrastructure in our supply chain or our third-party partners’ supply chains have notbeen compromised or that they do not contain exploitable defects or bugs that could result in a breach of or disruption to ourinformation technology systems or the third-party information technology systems that support us and our services.

The risk of a security breach or disruption, particularly through accidental actions or omissions by trusted insiders, cyber-attacks or cyber intrusions, including by computer hackers, threat actors, viruses, sophisticated nation states, and nation-state-supported actors, has generally increased as the number, intensity, and sophistication of attempted attacks and intrusions from around the world have increased; in particular, during the COVID-19 pandemic we have observed an increase in attempted attacks against our data systems. Additionally, in connection with the ongoing COVID-19 pandemic, most of our personnel are working remotely, which may increase the risk of security breaches, loss of data, and other disruptions as a consequence of more personnel accessing sensitive and critical information from remote locations.

We may not be able to anticipate all types of security threats, and we may not be able to implement preventive measures effective against all such security threats. The techniques used by cyber criminals change frequently, may not be recognized until launched, and can originate from a wide variety of sources, including outside groups such as external service providers, organized crime affiliates, terrorist organizations, hostile foreign governments or agencies, or cybersecurity researchers. To the extent that any disruption or security breach were to result in a loss of, or damage to, our data or applications, or those of our third-party vendors and other contractors and consultants, or inappropriate disclosure of confidential or proprietary information, we could incur liability and reputational damage and the further development and commercialization of our services and technologies could be delayed. The costs related to significant security breaches or disruptions could be material and exceed the limits of the cybersecurity insurance we maintain against such risks. Additionally, we cannot be sure that such coverage will continue to be available on commercially reasonable terms or at all, or that such coverage will pay future claims. If the information technology systems of our third-party vendors and other contractors and consultants become subject to disruptions or security breaches, we may have insufficient recourse against such third parties and we may have to expend significant resources to mitigate the impact of such an event, and to develop and implement protections to prevent future events of this nature from occurring.

Although we take measures to protect sensitive data from unauthorized access, use or disclosure, our information technology and infrastructure may be vulnerable to attacks by hackers or viruses or breached due to personnel error, malfeasance, or other malicious or inadvertent disruptions. Any such breach or interruption could compromise our networks and the information stored there could be accessed by unauthorized parties, manipulated, publicly disclosed, lost, or stolen. Any of the previously identified or similar threats could cause a security incident or other interruption, which could result in unauthorized, unlawful, or accidental acquisition, modification, destruction, loss, alteration, encryption, disclosure of, or access to our proprietary, confidential, or sensitive information. A security incident or other interruption could disrupt our ability (and that of third parties upon whom we rely) to provide our platform, products, and services. We may expend significant resources or modify our business activities (including our clinical trial activities) to try to protect against security incidents. Additionally, certain privacy, data protection, or data security obligations may require us to implement and maintain certain measures to protect our information technology systems and sensitive information.

We cannot assure you that our data protection efforts and our investment in information technology will prevent significant breakdowns, data leakages, breaches in our systems, or those of our third-party vendors and other contractors and consultants, or other cyber incidents that could have a material adverse effect upon our reputation, business, operations, or financial condition. We may be unable in the future to detect vulnerabilities in our information technology systems because such threats and techniques change frequently, are often sophisticated in nature, and may not be detected until after a security incident has occurred. For example, if such an event were to occur and cause interruptions in our operations, or those of our third-party vendors and other contractors and consultants, it could result in a material disruption of our programs and the development of our services and technologies could be delayed. Furthermore, significant disruptions of our internal information technology systems or those of our third-party vendors and other contractors and consultants, or security breaches could result in the loss, misappropriation, and/or unauthorized access, use, or disclosure of, or the prevention of access to, confidential information (including trade secrets or other intellectual property, proprietary business information, and personal information), which could result in financial, legal, business, and reputational harm to us. For example, any such event that leads to unauthorized access, use, or disclosure of personal information, including personal information regarding our customers or employees, could harm our reputation directly, compel us to comply with federal and/or state breach notification laws and foreign law equivalents, subject us to mandatory corrective action, and otherwise subject us to liability under laws and regulations that protect the privacy and security of personal information, which could result in significant legal and financial exposure and reputational damages that could potentially have an adverse effect on our business.

Any such access, breach, or other loss of information could result in legal claims or proceedings, liability under domestic or foreign privacy, data protection, and data security laws such as HIPAA and HITECH, and penalties. Applicable privacy, data protection, or data security obligations may require us to notify relevant stakeholders of security incidents. Such disclosures are costly, and the disclosure or the failure to comply with such requirements could lead to adverse consequences. Notice of certain security breaches must be made to affected individuals, the Secretary of HHS, and for extensive breaches, notice may need to be made to the media or state attorneys general. Such a notice could harm our reputation and our ability to compete. Although we have implemented security measures and a formal, dedicated enterprise security program to prevent unauthorized access to patient data, such data is currently accessible through multiple channels, and there is no guarantee we can protect our data from breach. Unauthorized access, loss, or dissemination could also damage our reputation or disrupt our operations, including our ability to conduct our analyses, deliver test results, process claims and appeals, provide customer assistance, conduct research and development activities, collect, process, and prepare company financial information, provide information about our tests and other patient and physician education and outreach efforts through our website, and manage the administrative aspects of our business.

40

Penalties for violations of these laws vary. For instance, penalties for failure to comply with a requirement of HIPAA and HITECH vary significantly, and include significant civil monetary penalties and, in certain circumstances, criminal penalties with fines up to $250,000 per violation and/or imprisonment. A person who knowingly obtains or discloses individually identifiable health information in violation of HIPAA may face a criminal penalty of up to $50,000 and up to one-year imprisonment. The criminal penalties increase if the wrongful conduct involves false pretenses or the intent to sell, transfer or use identifiable health information for commercial advantage, personal gain or malicious harm.

Further, various states, such as California and Massachusetts, have implemented similar privacy laws and regulations, such as the California Confidentiality of Medical Information Act, that impose restrictive requirements regulating the use and disclosure of health information and other personally identifiable information. These laws and regulations are not necessarily preempted by HIPAA, particularly if a state affords greater protection to individuals than HIPAA. Where state laws are more protective, we have to comply with the stricter provisions. In addition to fines and penalties imposed upon violators, some of these state laws also afford private rights of action to individuals who believe their personal information has been misused. California’s patient privacy laws, for example, provide for penalties of up to $250,000 and permit injured parties to sue for damages. Similarly, the California Consumer Privacy Act (“CCPA”) allows consumers a private right of action when certain personal information is subject to unauthorized access and exfiltration, theft or disclosure due to a business’ failure to implement and maintain reasonable security procedures. The CCPA also allows for statutory fines for noncompliance of up to $7,500 per violation. The interplay of federal and state laws may be subject to varying interpretations by courts and government agencies, creating complex compliance issues for us and data we receive, use and share, potentially exposing us to additional expense, adverse publicity and liability. Further, as regulatory focus on privacy issues continues to increase and laws and regulations concerning the protection of personal information expand and become more complex, these potential risks to our business could intensify. Changes in laws or regulations associated with the enhanced protection of certain types of sensitive data, such as PHI or PII, for the treatment of genetic data, along with increased customer demands for enhanced data security infrastructure, could greatly increase our cost of providing our services, decrease demand for our services, reduce our revenue and/or subject us to additional liabilities.

The actual or perceived failure by us, our customers, or vendors to comply with increasingly stringent laws, regulations and contractual obligations relating to privacy, data protection, and data security could harm our reputation, and subject us to significant fines and liability.

We are subject to numerous domestic and foreign laws and regulations regarding privacy, data protection, and data security, the scope of which is changing, subject to differing applications and interpretations and may be inconsistent among countries, or conflict with other rules. We are also subject to policies, industry standards, and the terms of our contractual obligations to customers and third parties related to privacy, data protection, and data security. The actual or perceived failure by us, our customers, our vendors, or other relevant third parties to address or comply with these laws, regulations, and obligations could increase our compliance and operational costs, expose us to regulatory scrutiny, actions, fines and penalties, result in reputational harm, lead to a loss of customers, reduce the use of our services, result in litigation and liability, and otherwise cause a material adverse effect on our business, financial condition, and results of operations.

For example, the EU adopted the GDPR, which imposes onerous and comprehensive privacy, data protection, and data security obligations onto data controllers and processors, including, as applicable, contractual privacy, data protection, and data security commitments, expanded disclosures to data subjects about how their personal information is used, honoring individuals’ data protection rights, limitations on retention of personal information, additional requirements pertaining to sensitive information (such as health data) and pseudonymized (i.e., key-coded) data, data breach notification requirements, and higher standards for obtaining consent from data subjects. Penalties for non-compliance with the GDPR can be significant and include fines in the amount of the greater of €20 million or 4% of global turnover and restrictions or prohibitions on data processing, which could limit our ability to do business in the EU, reduce demand for our services, and adversely impact our business and results of operations. The GDPR also provides that EU member states may introduce further conditions, including limitations, to make their own further laws and regulations limiting the processing of genetic, biometric, or health data, which could limit our ability to collect, use and share European data, or could cause our compliance costs to increase, require us to change our practices, adversely impact our business, and harm our financial condition. Assisting our customers, partners, and vendors in complying with the GDPR, or complying with the GDPR ourselves, may cause us to incur substantial operational costs or require us to change our business practices.

In addition, in January 2021, following its exit from the EU, the UK implemented its own version of the GDPR (the “UK GDPR”), which currently imposes substantively similar obligations as the GDPR and provides for fines of up £17.5 million or 4% of global turnover, whichever is greater, for non-compliance. In addition, an actual or asserted violation of the GDPR or UK GDPR could result in regulatory investigations, reputational damage, orders to cease or change our processing of our data, enforcement notices and/or assessment notices (for a compulsory audit). We also may face civil claims, including representative actions and other class action-type litigation (where individuals have suffered harm), potentially resulting in our paying significant compensation or damages, or incurring other significant liabilities, as well as associated costs, diversion of internal resources, and reputational harm.

The relationship between the UK and the EU in relation to certain aspects of privacy, data protection, and data security laws is subject to some uncertainty. For example, on June 28, 2021, the European Commission announced a decision of “adequacy” concluding that the UK ensures an equivalent level of data protection to the GDPR, which provides some relief regarding the legality of continued personal information flows from the European Economic Area (“EEA”) to the UK. This adequacy determination will automatically expire in June 2025 unless the European Commission renews or extends it and may be modified or revoked in the interim. We cannot predict how the UK GDPR and other UK data protection laws or regulations may develop, including as compared to the GDPR, nor can we predict the effects of divergent laws and related guidance. Changes with respect to any of these matters may lead to additional costs and increase our overall risk exposure, particularly if the GDPR and UK GDPR develop in conflicting or otherwise divergent ways.

41

Further, European and UK privacy, data protection, and data security laws, including the GDPR and the UK GDPR, generally restrict the transfer of personal information from the UK, EEA and Switzerland to the U.S. and most other countries unless the parties to the transfer have implemented specific safeguards to protect the transferred personal information. There is uncertainty on how to implement such safeguards and how to conduct such transfers in compliance with the GDPR and UK GDPR, and certain safeguards may not be available or applicable with respect to some or all of the personal information processing activities necessary to research, develop and market our products and services. The European Commission recently released a set of Standard Contractual Clauses (“SCCs”) that is designed to be a valid mechanism by which entities can transfer personal data out of the EEA to jurisdictions that the European Commission has not found to provide an adequate level of protection.Currently, the SCCsare a valid mechanism to transfer personal data outside of the EEA. The SCCs, however, require parties that rely upon that legalmechanism to comply with additional obligations, such as conducting transfer impact assessments to determine whether additionalsecurity measures are necessary to protect the transferred personal information. Moreover, due to potential legal challenges, there isuncertainty regarding whether the SCCs will remain a valid mechanism for transfers of personal information out of the EEA. Similarly,the UK’s Information Commissioner’s Office has released a draft international data transfer agreement (“IDTA”) governing datatransfers much like the SCCs.If we are unable to implement a valid solution for personal information transfers to the U.S. and other countries, we will face increased exposure to regulatory actions, substantial fines, and injunctions against processing or transferring personal information from Europe, and we may be required to increase our data processing capabilities in Europe at significant expense. Inability to import personal information from Europe to the U.S. or other countries may decrease demand for our products and services as our customers that are subject to the GDPR or UK GDPR may seek alternatives that do not involve personal information transfers out of Europe. At present, there are few, if any, viable alternatives to the Standard Contractual Clauses and the IDTA.

Similar laws have been proposed in other foreign jurisdictions in which we do, or expect to do, business. For example, the PIPL was adopted in China on August 20, 2021, and it went into effect on November 1, 2021. The PIPL shares certain similarities with the GDPR, including extraterritorial application, requirements for data minimization, data localization, and purpose limitation, and obligations to provide certain notices to and honor data subject rights from individuals located in the PRC. The PIPL allows for fines of up to 50 million yuan or 5% of a covered company’s revenue in the prior year. The PIPL, and other new and evolving laws and regulations relating to privacy, data protection, and data security in China and other relevant foreign jurisdictions, increase our risk exposure, and may require us to modify our operations, may limit our ability to collect, retain, store, use, share, disclose, transfer, disseminate, and otherwise process personal information, may require additional investment of resources in compliance programs, and could result in increased compliance costs or changes in our ongoing or planned business practices, policies or strategies.

In the United States, federal, state, and local governments have enacted numerous privacy, data protection, and data security laws, including data breach notification laws, personal data privacy laws, and consumer protection laws. For example, HIPAA, as amended by HITECH, imposes specific requirements relating to the privacy, security, and transmission of individually identifiable health information. The CCPA, which took effect on January 1, 2020, gives California residents expanded rights to access and delete their personal information, opt out of certain personal information sharing, and receive detailed information about how their personal information is used. The CCPA provides for civil penalties for violations, as well as a private right of action for data breaches that is expected to increase data breach litigation. It allows for statutory fines for noncompliance (up to $7,500 per violation). Although the CCPA exempts some data processed in the context of clinical trials, the CCPA may increase our compliance costs and potential liability with respect to other personal information we maintain about California residents. Some observers have noted that the CCPA could mark the beginning of a trend toward more stringent state privacy, data protection and data security legislation in the U.S., which could increase our potential liability and adversely affect our business. The CCPA will be expanded substantially on January 1, 2023, when the California Privacy Rights Act of 2020 (“CPRA”) becomes fully operative. The CPRA imposes additional obligations relating to consumer data on companies doing business in California beginning January 1, 2022 and enforcement beginning July 1, 2023. The CPRA significantly modifies the CCPA and will, among other things, give California residents the ability to limit use of certain sensitive personal information, further restrict the use of cross-contextual advertising, establish restrictions on the retention of personal information, expand the types of data breaches subject to the CCPA’s private right of action, provide for increased penalties for CPRA violations concerning California residents under the age of 16, and establish a new California Privacy Protection Agency to implement and enforce the new law.

The enactment of the CCPA has led a wave of similar legislative developments in other states in the U.S., which creates the potential for a patchwork of overlapping but different state laws and could mark the beginning of a trend toward more stringent privacy legislation in the U.S., which could increase our potential liability and adversely affect our business, financial condition and results of operations. For example, in March 2021, Virginia enacted the Virginia Consumer Data Protection Act, a comprehensive privacy, data protection, and data security statute that becomes effective on January 1, 2023 (at the same time as the CPRA) and shares similarities with the CCPA, the CPRA, and legislation proposed in other states. In June 2021, Colorado enacted a similar law, the Colorado Privacy Act, which becomes effective on July 1, 2023. Many other states are considering proposed comprehensive data privacy legislation and all 50 states have passed some form of legislation relating to privacy or cybersecurity (for example, all 50 states have enacted laws requiring disclosure of certain personal information breaches). Additionally, several states and localities have enacted statutes banning or restricting the collection of biometric information. At the federal level, the United States Congress is considering various proposals for comprehensive federal privacy, data protection, and data security legislation and, while no such law currently exists, we are subject to applicable existing federal laws and regulations, such as the rules and regulations promulgated under the authority of the Federal Trade Commission, which regulates unfair or deceptive acts or practices, including with respect to privacy, data protection, and data security. These state statutes, and other similar state or federal laws, may require us to modify our data processing practices and policies and incur substantial compliance-related costs and expenses. Additionally, many laws and regulations relating to privacy and the collection, storing, sharing, use, disclosure, and other processing or protection of certain types of data are subject to varying degrees of enforcement and new and changing interpretations by courts. These laws and other changes in laws or regulations relating to privacy, data protection, and data security, particularly any new or modified laws or regulations, or changes to the interpretation or enforcement of such laws or regulations, that require enhanced protection of certain types of data or new obligations with regard to data retention, transfer, or disclosure, could greatly increase our operating costs, or require changes to our operations.

42

Compliance with U.S. and foreign privacy, data protection, and data security laws and regulations could cause us to incur substantial costs or require us to change our business practices and compliance procedures in a manner adverse to our business. Moreover, complying with these various laws could require us to take on more onerous obligations in our contracts, restrict our ability to collect, use and disclose data, or in some cases, impact our ability to operate in certain jurisdictions. We typically rely on our customers to obtain valid and appropriate consents from data subjects whose genetic samples and data we process on such customers’ behalf. Given that we do not typically obtain direct consent from such data subjects and we do not audit our customers to ensure that they have obtained the necessary consents required by law, the failure of our customers to obtain consents that are valid under applicable law could result in our own non-compliance with privacy laws. Such failure to comply with U.S. and foreign privacy, data protection, and data security laws and regulations could result in government enforcement actions (which could include civil or criminal penalties), private litigation and/or adverse publicity and could negatively affect our operating results and business. Claims that we have violated individuals’ privacy rights, failed to comply with privacy, data protection, and data security laws, or breached our contractual obligations, even if we are not found liable, could be expensive and time consuming to defend, could result in adverse publicity and could have a material adverse effect on our business, financial condition, and results of operations.

Our employees may engage in misconduct or other improper activities, including noncompliance with regulatory standards and requirements, which could cause significant liability for us and harm our reputation.

We are exposed to the risk of employee fraud or other misconduct, including intentional failures to comply with government regulations, including federal and state healthcare fraud and abuse laws and regulations, to misuse information, including patient information, and to report financial information or data accurately or disclose unauthorized activities to us. Such misconduct could also involve the improper use of information obtained in the course of clinical studies, which could result in regulatory sanctions and cause serious harm to our reputation.

We have a code of conduct and ethics for our directors, officers and employees, but it is not always possible to identify and deter employee misconduct, and the precautions we take to detect and prevent this activity may not be effective in controlling risks or losses or in protecting us from governmental investigations or other actions or lawsuits stemming from a failure to be in compliance with such laws or regulations. If any such actions are instituted against us, and we are not successful in defending ourselves or asserting our rights, those actions could have a significant impact on our business and results of operations, including the imposition of significant administrative, civil and criminal penalties, damages, fines, imprisonment, exclusion from government healthcare programs, contractual damages, refunding of payments received by us, reputational harm, additional reporting, or oversight obligations if we become subject to a corporate integrity agreement or other agreement to resolve allegations of non-compliance with the law and curtailment or restructuring of our operations. Whether or not we are successful in defending against such actions or investigations, we could incur substantial costs, including legal fees, and divert the attention of management in defending ourselves against any of these claims or investigations.

Complying with numerous statutes and regulations pertaining to our business is an expensive and time-consuming process, and any failure to comply could result in substantial penalties.

Our operations are or may be subject to other extensive federal, state, local, and foreign laws and regulations, all of which are subject to change. These laws and regulations currently include, among others:

43

44

As a clinical laboratory, our business practices may face additional scrutiny from government regulatory agencies such as the Department of Justice, the HHS OIG, and CMS. Certain arrangements between clinical laboratories and referring physicians have been identified in fraud alerts issued by the OIG as implicating the Anti-Kickback Statute. The OIG has stated that it is particularly concerned about these types of arrangements because the choice of laboratory, as well as the decision to order laboratory tests, typically are made or strongly influenced by the physician, with little or no input from patients. Moreover, the provision of payments or other items of value by a clinical laboratory to a referral source could be prohibited under the Stark Law unless the arrangement meets all criteria of an applicable exception. The government has been active in enforcement of these laws as they apply to clinical laboratories.

The growth of our business, including services we provide under our agreement with Natera, and our expansion outside of the U.S. may increase the potential of violating these laws or our internal policies and procedures. The risk of our being found in violation of these or other laws and regulations is further increased by the fact that many have not been fully interpreted by the regulatory authorities or the courts, and their provisions are open to a variety of interpretations. Any action brought against us for violation of these or other laws or regulations, even if we successfully defend against it, could cause us to incur significant legal expenses and reputational harm and divert our management’s attention from the operation of our business. If our operations are found to be in violation of any of these laws and regulations, we may be subject to any applicable penalty associated with the violation, including significant administrative, civil and criminal penalties, damages, fines, imprisonment, exclusion from participation in federal healthcare programs, refunding of payments received by us, integrity oversight and reporting obligations, and curtailment or cessation of our operations. Any of the foregoing consequences could seriously harm our business and our financial results.

We could be adversely affected by violations of the Foreign Corrupt Practices Act of 1977, as amended (the “FCPA”), and other worldwide anti-bribery laws.

We are subject to the FCPA, which prohibits companies and their intermediaries from making payments in violation of law to non-U.S. government officials for the purpose of obtaining or retaining business or securing any other improper advantage. Other U.S. companies in the medical device and pharmaceutical fields have faced criminal penalties under the FCPA for allowing their agents to deviate from appropriate practices in doing business with these individuals. We are also subject to similar anti-bribery laws in the jurisdictions in which we operate, including the U.K.’s Bribery Act of 2010, which also prohibits commercial bribery and makes it a crime for companies to fail to prevent bribery. These laws are complex and far-reaching in nature, and, as a result, we cannot assure you that we would not be required in the future to alter one or more of our practices to be in compliance with these laws or any changes in these laws or the interpretation thereof. Any violations of these laws, or allegations of such violations, could disrupt our operations, involve significant management distraction, involve significant costs and expenses, including legal fees, and could result in a material adverse effect on our business, prospects, financial condition or results of operations. We could also incur severe penalties, including criminal and civil penalties, disgorgement, and other remedial measures.

If we decide to grow our business by developing in vitro diagnostic tests, we may be subject to reimbursement challenges.

The coverage and reimbursement status of newly approved or cleared laboratory tests, including our NeXT Dx test, is uncertain. If we decide to seek reimbursement for our NeXT Dx test or other in vitro diagnostic tests we may develop, and if such tests are inadequately covered by insurance or ineligible for such reimbursement, this could limit our ability to market any such future tests. The commercial success of future products in both domestic and international markets may depend in part on the availability of coverage and adequate reimbursement from third-party payors, including government payors, such as the Medicare and Medicaid programs, managed care organizations, and other third-party payors. The government and other third-party payors are increasingly attempting to contain health care costs by limiting both insurance coverage and the level of reimbursement for new diagnostic tests. As a result, they may not cover or provide adequate payment for any future in vitro diagnostic tests that we develop. These payors may conclude that our products are less safe, less effective, or less cost-effective than existing or later-introduced products. These payors may also conclude that the overall cost of using one of our tests exceeds the overall cost of using a competing test, and third-party payors may not approve any future in vitro diagnostic tests we develop for insurance coverage and adequate reimbursement.

Changes in health care policy could increase our costs, decrease our revenue, and impact sales of and reimbursement for our tests.

In March 2010, the Patient Protection and Affordable Care Act, as amended by the Health Care and Education Reconciliation Act (the “ACA”), became law. This law substantially changed the way health care is financed by both commercial payers and government payers, and significantly impacts our industry. The ACA contains a number of provisions that are expected to impact the business and operations of our customers, some of which in ways we cannot currently predict, including those governing enrollment in state and federal health care programs, reimbursement changes, and fraud and abuse, which will impact existing state and federal health care programs and will result in the development of new programs.

Among other things, the ACA:

45

There remain judicial and Congressional challenges to certain aspects of the ACA, as well as efforts by the former Trump administration to repeal or replace certain aspects of the ACA. Since January 2017, former President Trump signed several Executive Orders and other directives to delay the implementation of certain requirements of the ACA. Concurrently, Congress considered legislation that would repeal, or repeal and replace, all or part of the ACA. While Congress has not passed comprehensive repeal legislation, it has enacted laws that modify certain provisions of the ACA such as removing penalties, starting January 1, 2019, for not complying with the ACA’s “individual mandate” to carry health insurance and eliminating the implementation of certain ACA-mandated fees. On June 17, 2021 the U.S. Supreme Court dismissed a challenge on procedural grounds that argued the ACA is unconstitutional in its entirety because the “individual mandate” was repealed by Congress. Thus, the ACA will remain in effect in its current form. Further, prior to the U.S. Supreme Court ruling, on January 28, 2021, President Biden issued an executive order that initiated a special enrollment period for purposes of obtaining health insurance coverage through the ACA marketplace The executive order also instructed certain governmental agencies to review and reconsider their existing policies and rules that limit access to healthcare, including among others, reexamining Medicaid demonstration projects and waiver programs that include work requirements, and policies that create unnecessary barriers to obtaining access to health insurance coverage through Medicaid or the ACA. It is possible that the ACA will be subject to judicial or Congressional challenges in the future. Efforts to repeal, substantially modify or invalidate some or all of the provisions of the ACA create considerable uncertainties for all businesses involved in healthcare, including our own. It is unclear how such efforts to repeal and replace the ACA will impact the ACA and our business. Additional legislation may be enacted that further amends, or repeals, the ACA, which could result in lower numbers of insured individuals, reduced coverage for insured individuals and adversely affect our and our customers’ business.

Source: SEC EDGAR (public domain) · 10-K for the period ended 2021-12-31, filed 2022-02-24 · accession 0001564590-22-006722

Filing HTML rendered to line-structured narrative text by the shipped reducer (datafeeds.edgar_fulltext.visible_text, keep_table_headers=True): scripts and inline-XBRL headers are dropped, and table content is reduced to its short label cells — numeric table data is not rendered and is therefore not counted. The same rendering is used for every year, so a year-over-year comparison is like for like.

The text is our rendering of the filing, not a facsimile: original pagination, typography and tables are not reproduced, and the numbers live in the financial statements (FA).

The outline locates item HEADINGS in this document. Only Items 1A and 7 have certified boundaries elsewhere in the terminal (the redline and the narrative-overlap number); every span here runs from one heading found to the next heading found.

How the outline was chosen. It is the longest chain of item headings that runs forward through both the document and the standard item order: 22 headings are on that chain and 16 further heading-shaped lines are not — the table-of-contents echo of every item, cross-references and exhibit-list mentions. Each entry's length is measured from its heading to the next heading on the chain.