Item 1A. RISK FACTORS
In the course of conducting our business operations, we are exposed to a variety of risks. These risks are generally inherent to the healthcare industry or otherwise generally impact virtual behavioral health companies like us. Any of the risk factors we describe below have affected or could materially adversely affect our business, financial condition and results of operations. The market price of shares of our common stock could decline, possibly significantly or permanently, if one or more of these risks and uncertainties occurs. Certain statements in “Risk Factors” are forward-looking statements. See “Forward-Looking Statements.”
Unless the context otherwise requires, all references in this subsection to the “Company,” “we,” “us” or “our” refer to the business of Talkspace, Inc. and its subsidiaries.
RISKS RELATED TO OUR OPERATING RESULTS AND EARLY STAGE OF GROWTH
We have a history of losses, which we expect to continue, and we may never achieve or sustain profitability.
We have incurred significant losses in each period since our inception. We incurred net losses of $62.7 million and $22.4 million for the years ended December 31, 2021 and 2020, respectively. As of December 31, 2021, we had an accumulated deficit of $171.5 million. These losses and accumulated deficit reflect the substantial investments we made to acquire new clients and members and to develop our technology platform. To date, we have derived a substantial majority of our revenue from clients and members who pay for access to our virtual behavioral health platform, and our longer-term results of operations and continued growth will depend on our ability to successfully develop and market new virtual behavioral health products and services that our clients and members want and are willing to purchase. We intend to continue scaling our business to increase our client, member and provider bases, broaden the scope of services we offer, invest in research and development and expand the applications of our technology through which clients and members can access our services. Accordingly, we anticipate that cost of revenue and operating expenses will continue to increase in the foreseeable future. These efforts may prove more expensive than we currently anticipate, and we may not succeed in increasing our revenue sufficiently to offset these higher expenses. In addition, our results of operations would also suffer if our innovations are not responsive to the needs of our clients and members, appropriately timed with market opportunity, effectively brought to market or do not achieve market acceptance. We cannot assure you that we will achieve profitability in the future or that, if we do become profitable, we will be able to sustain or increase profitability. Our prior losses, combined with our expected future losses, have had and will continue to have an adverse effect on our stockholders’ equity and working capital. As a result of these factors, we may need to raise additional capital through debt or equity financings in order to fund our operations, and such capital may not be available on reasonable terms, if at all.
Our business and the markets we operate in are new and rapidly evolving, which makes it difficult to evaluate our future prospects and the risks and challenges we may encounter.
Our business and the markets we operate in are new and rapidly evolving whichmake it difficult to evaluate and assess the success of our business to date, our future prospects and the risks and challenges that we may encounter. These risks and challenges include our ability to:
●
attract new clients and members to our platform and position our platform as a convenient and accepted way to access therapy and psychiatry;
●
retain our clients and members and encourage them to continue to utilize our platform and services;
●
attract new and existing clients and members to rapidly adopt new offerings on our platform;
●
increase the number of clients and members that use our subscription offerings or the number of subscription programs that we manage;
●
retain our clients and members that subscribe to our subscription offerings;
●
gain market acceptance of our services and products with clients and members and maintain and expand such relationships;
●
attract and retain providers for inclusion in our platform;
19
Table of Contents
●
comply with existing and new laws and regulations applicable to our business and in our industry;
●
anticipate and respond to macroeconomic changes, and industry pricing benchmarks and changes in the markets in which we operate;
●
react to challenges from existing and new competitors;
●
maintain and enhance the value of our reputation and brand;
●
effectively manage our growth and business operations;
●
forecast our revenue and budget for, and manage, our expenses and capital expenditures;
●
hire, integrate and retain talented people at all levels of our organization;
●
maintain and improve the infrastructure underlying our platform, including our apps and websites and with respect to data protection, intellectual property and cybersecurity; and
●
successfully update our platform, including expanding our platform and offerings into different healthcare products and services, develop and update our software, apps, features, offerings and services to benefit our clients and members and enhance their experience.
If we fail to understand fully or adequately address the challenges that we are currently encountering or that we may encounter in the future, including those challenges described here and elsewhere in this “Risk Factors” section, our business, financial condition and results of operations could be adversely affected. If the risks and uncertainties that we plan for when operating our business are incorrect or change, or if we fail to manage these risks successfully, our results of operations could differ materially from our expectations and our business, financial condition and results of operations could be adversely affected.
We may not grow at the rates we historically have achieved or at all, even if our key metrics may indicate growth, which could have a material adverse effect on the market price of our common stock.
We have experienced significant growth in the last several years, and therefore our recent revenue growth rate and financial performance should not be considered indicative of our future performance. For the year ended December 31, 2021 and 2020, our revenue was $113.7 million and $76.2 million, respectively, representing a 49.2% growth rate. In addition, as a result of the COVID-19 pandemic, we have experienced a significant increase in revenue. The circumstances that have accelerated the growth of our business stemming from the effects of the COVID-19 pandemic may not continue in the future, and future revenues may not grow at these same rates or may decline. For example, during the quarter ended December 31, 2021, revenues from our B2C business declined compared to the previous quarter. You should not rely on our revenue or key business metrics for any previous quarterly or annual period as any indication of our revenue, revenue growth, key business metrics, or key business metrics growth in future periods. In particular, our revenue growth rate has fluctuated in prior periods. Our future growth will depend, in part, on our ability to grow our revenue from existing clients and members, to acquire potential future clients and members, to expand our client, member and provider bases, to develop new products and services and to expand internationally. We can provide no assurances that we will be successful in executing on these growth strategies or that, even if our key metrics would indicate future growth, we will continue to grow our revenue or to generate net income. Our ability to execute on our existing sales pipeline, create additional sales pipelines, and expand our client and member bases depends on, among other things, the attractiveness of our services relative to those offered by our competitors, our ability to demonstrate the value of our existing and future services, and our ability to attract and retain a sufficient number of qualified sales and marketing leadership and support personnel. In addition, our existing clients and members may be slower to adopt our services than we currently anticipate, which could adversely affect our results of operations and growth prospects.
We may experience difficulties in managing our growth and expanding our operations.
We expect to experience significant growth in the scope of our operations. Our ability to manage our operations and future growth will require us to continue to improve our operational, financial and management controls, compliance programs and reporting systems. We may not be able to implement improvements in an efficient or timely manner and may discover deficiencies in existing controls, programs, systems and procedures, which could have an adverse effect on our business, reputation and financial results. Additionally, rapid growth in our business may place a strain on our human and capital resources.
20
Table of Contents
RISKS RELATED TO OUR BUSINESS AND INDUSTRY
The virtual behavioral health market is immature and volatile, and if it does not develop, if it develops more slowly than we expect, if we encounter negative publicity or if our services are not competitive, the growth of our business will be harmed.
The virtual behavioral health market is relatively new and unproven, and it is uncertain whether it will achieve and sustain high levels of demand, consumer acceptance and market adoption. Our success will depend to a substantial extent on the willingness of our clients and members to use, and to increase the frequency and extent of their utilization of, our services and products, as well as on our ability to demonstrate the value of virtual behavioral healthcare to employers, health plans, government agencies and other purchasers of healthcare for beneficiaries. Our market may depend on our clients and members’ ability to obtain reimbursement from third-party payors, such as health plans and government agencies, as well as our ability to expand our B2B business and contract for direct reimbursement of our services from employers and health plan clients. Third-party payors in the United States may decline or reduce reimbursement for telehealth and teletherapy services, especially those provided through text messaging or other means via technology, and compliance with administrative procedures or requirements of third-party payors may result in delays in processing approvals by those payors for members to obtain coverage for our services. Failure by our members to obtain or maintain coverage or our inability to secure adequate reimbursement for our services could have an adverse effect on our business, results of operations, and financial conditions. We derive a portion of our revenues from third-party payors, and we expect that this amount will continue to increase, so any reductions in reimbursement by third-party payors could have a material and adverse impact on our projected growth. In addition, negative publicity concerning our services or the virtual behavioral health market as a whole could limit market acceptance of our services. If our clients and members do not perceive the benefits of our services and drive member engagement, or if our services are not competitive, then our market may not develop at all, or it may develop more slowly than we expect. Similarly, individual and healthcare industry concerns or negative publicity regarding patient confidentiality and privacy in the context of virtual behavioral healthcare could limit market acceptance of our services. If any of these events occurs, it could have a material adverse effect on our business, financial condition or results of operations.
The outbreak of the novel coronavirus (COVID-19) and its impact on business and economic conditions could adversely affect our business, results of operations and financial condition, and the extent and duration of those effects will be uncertain.
In March 2020, the World Health Organization declared COVID-19 a global pandemic. This contagious outbreak, which has continued to spread, and the related adverse public health developments, including orders to shelter-in-place, travel restrictions and mandated business closures, have adversely affected workforces, organizations, consumers, economies and financial markets globally, leading to an economic downturn and increased market volatility. It has also disrupted the normal operations of many businesses, including ours.
As a result of the COVID-19 pandemic, our personnel are working remotely, and it is possible that this could have a negative impact on the execution of our business plans and operations. If a natural disaster, power outage, connectivity issue, or other event occurred that impacted our employees’ ability to work remotely, it may be difficult or, in certain cases, impossible, for us to continue our business for a substantial period of time. The increase in remote working may also result in consumer privacy, IT security and fraud concerns as well as increase our exposure to potential wage and hour issues.
We cannot predict with any certainty whether and to what degree the impact caused by the COVID-19 pandemic and reactions thereto will continue which may contribute to difficulty accurately predicting our internal financial forecasts.
The outbreak also presents challenges as our workforce is working remotely in helping new and existing clients, members and other consumers, many of whom are also generally working remotely.
It is not possible for us to accurately predict the duration or magnitude of the results of the COVID-19 and its effects on our business, results of operations or financial condition at this time, but such effects may be material. The COVID-19 pandemic may also have the effect of heightening many of the other risks identified elsewhere in this section.
Rapid technological change in our industry presents us with significant risks and challenges.
The virtual behavioral health market is characterized by rapid technological change, changing consumer requirements, short product lifecycles and evolving industry standards. Our success will depend on our ability to enhance our solution with next-generation technologies and to develop or to acquire and market new services to access new client and member populations. There is no guarantee that we will possess the resources, either financial or personnel, for the research, design and development of new applications or services, or that we will be able to utilize these resources successfully and avoid technological or market
21
Table of Contents
obsolescence. Further, there can be no assurance that technological advances by one or more of our competitors or future competitors will not result in our present or future software-based products and services becoming uncompetitive or obsolete.
We operate in a competitive industry, and if we are not able to compete effectively, our business, financial condition and results of operations will be harmed.
While the virtual behavioral health market is in an early stage of development, it is competitive and we expect it to attract increased competition, which could make it difficult for us to succeed. We currently face competition from a range of companies, including specialized software and solution providers that offer similar solutions and that are continuing to develop additional products and becoming more sophisticated and effective. These competitors include American Well Corporation, Teladoc, Included Health, MDLive, BetterHelp, Lyra Health and Headspace. In addition, large, well-financed health systems and health plans have in some cases developed their own telehealth and teletherapy tools and may provide these solutions to their consumer at discounted prices. Competition may also increase from large technology companies, such as Apple, Amazon, Meta, Google, Verizon, or Microsoft, who may wish to develop their own virtual behavioral health solutions, as well as from large retailers like Amazon or Walmart. The surge in interest in virtual behavioral healthcare, including as a result of the COVID-19 pandemic, and in particular the relaxation of HIPAA privacy and security requirements, has also attracted new competition from providers who utilize consumer-grade video conferencing platforms such as Zoom and Twilio. Competition from large software companies or other specialized solution providers, health systems and health plans, communication tools and other parties could result in continued pricing pressures, which is likely to lead to price declines in certain product segments, which could negatively impact our sales, profitability and market share.
Some of our competitors may have greater name recognition, longer operating histories and significantly greater resources than we do. Further, our current or potential competitors may be acquired by third parties with greater available resources. As a result, our competitors may be able to respond more quickly and effectively than we can to new or changing opportunities, technologies, standards or consumer requirements and may have the ability to initiate or withstand substantial price competition. In addition, current and potential competitors have established, and may in the future establish, cooperative relationships with vendors of complementary products, technologies or services to increase the availability of their solutions in the marketplace. Accordingly, new competitors or alliances may emerge that have greater market share, a larger consumer base, more widely adopted proprietary technologies, greater marketing expertise, greater financial resources and larger sales forces than we have, which could put us at a competitive disadvantage.
Our competitors could also be better positioned to serve certain segments of the virtual behavioral health market, which could create additional price pressure. In addition, many healthcare provider organizations are consolidating to create integrated healthcare delivery systems with greater market power. As provider networks and managed care organizations consolidate, thus decreasing the number of market participants, competition to provide products and services like ours could become more intense, and the importance of establishing and maintaining relationships with key industry participants could increase. These industry participants may try to use their market power to negotiate price reductions for our products and services. In light of these factors, even if our solution is more effective than those of our competitors, current or potential clients and members may accept competitive solutions in lieu of purchasing our solution. If we are unable to successfully compete in the virtual behavioral health market, our business, financial condition and results of operations could be materially adversely affected.
If growth in the number of clients and members or providers on our platform decreases, or the number of products or services that we are able to sell to our clients and members decreases, due to legal, economic or business developments, our business, financial condition and results of operations will be harmed.
We currently generate most of our revenues from members who purchase subscription access to our platform. These subscriptions generally have stated initial terms of one-to-six months. We also generate revenues from our enterprise clients, which contracts generally have stated initial terms of one year, unless earlier terminated subject to notice and other requirements. Most of our clients and members have no obligation to renew their subscriptions for our services after the initial term expires. In addition, our clients may negotiate terms less advantageous to us upon renewal, which may reduce our revenue from these clients. Additionally, as we grow our client and member bases, we will need to maintain and grow our network of providers. Certain of our providers are permitted to provide services on other platforms, and therefore, our success will be dependent on our ability to retain and recruit highly trained and licensed therapists, psychiatrists and other providers to our platform. Additionally, our future results of operations depend, in part, on our ability to expand our services and offerings, including broadening our continuum of care. If our clients and members fail to renew their contracts, renew their contracts upon less favorable terms or at lower fee levels or fail to purchase new products and services from us, our revenue may decline or our future revenue growth may be constrained.
22
Table of Contents
Additional factors that could affect our ability to sell products and services include, but are not limited to:
●
price, performance and functionality of our solution;
●
availability, price, performance and functionality of competing solutions;
●
our ability to develop and sell complementary products and services;
●
stability, performance and security of our hosting infrastructure and hosting services; and
●
changes in healthcare laws, regulations or trends.
Any of these consequences could lower retention and have a material adverse effect on our business, financial condition and results of operations.
Our future growth and profitability of our business will depend in large part upon the effectiveness and efficiency of our marketing efforts, and our ability to develop brand awareness cost-effectively.
Our business success depends on our ability to attract and retain clients and members, which significantly depends on our marketing practices. Our future growth and profitability will depend in large part upon the effectiveness and efficiency of our marketing efforts, including our ability to:
●
create greater awareness of our brand;
●
identify the most effective and efficient levels of spending in each market, media and specific media vehicle;
●
determine the appropriate creative messages and media mix for advertising, marketing and promotional expenditures;
●
effectively manage marketing costs (including creative and media) to maintain acceptable consumer acquisition costs;
●
select the most effective markets, media and specific media vehicles in which to advertise; and
●
convert consumer inquiries into clients and members.
We believe that developing and maintaining widespread awareness of our brand in a cost-effective manner is critical to achieving widespread adoption of our solution and attracting new clients and members. Our brand promotion activities may not generate consumer awareness or increase revenue, and even if they do, any increase in revenue may not offset the expenses we incur in building our brand. If we fail to successfully promote and maintain our brand, or incur substantial expenses in doing so, we may fail to attract or retain clients and members necessary to realize a sufficient return on our brand-building efforts or to achieve the widespread brand awareness that is critical for broad adoption of our brands.
We may be unsuccessful in achieving broad market education and changing consumer purchasing habits.
Our success and future growth largely depend on our ability to increase consumer awareness of our platform and offerings, and on the willingness of current and potential clients and members to utilize our platform to access information and behavioral health services. We believe the vast majority of consumers make purchasing decisions for behavioral health services on the basis of traditional factors, such as insurance coverage. This traditional decision-making process does not always account for restrictive and complex insurance plans, high deductibles, expensive co-pays and other factors, such as discounts or savings available at alternative therapists or practices. To effectively market our platform, we must educate consumers about the various purchase options and the benefits of using Talkspace for behavioral healthcare, including when such services may not be covered by their health insurance benefits. We focus our marketing and education efforts on potential clients, members and other consumers, but also aim to educate and inform healthcare providers and other participants that interact with consumers, including at the point of purchase. However, we cannot assure you that we will be successful in changing consumer purchasing habits or that we will achieve broad market education or awareness among consumers. Even if we are able to raise awareness among consumers, they may be slow in changing their habits and may be hesitant to use our platform for a variety of reasons, including:
●
lack of experience with our company and platform, and concerns that we are relatively new to the industry;
●
perceived health, safety or quality risks associated with the use of a new platform and applications for therapy and psychiatry;
●
traditional or existing relationships with therapists, psychiatrists or other providers;
●
concerns about the privacy and security of the data that consumers and providers share with or through our platform;
23
Table of Contents
●
competition and negative selling efforts from competitors, including competing platforms and price matching programs; and
●
perception regarding the time and complexity of using our platform.
If we fail to achieve broad market education of our platform and/or the options for purchasing healthcare products and services, or if we are unsuccessful in changing consumer purchasing habits, our business, financial condition and results of operations would be adversely affected.
Our growth depends in part on the success of our strategic relationships with third parties that we provide services to.
In order to grow our business, we anticipate that we will continue to depend on our existing and future relationships with third parties, such as third-party payors, including health plans and government agencies, as well as our ability to expand our B2B business with employers and health plan clients that we provide services to. Identifying potential clients, and negotiating and documenting relationships with them, requires significant time and resources. Our competitors may be effective in providing incentives to third parties to favor their products or services or to prevent or reduce subscriptions to, or utilization of, our products and services. In addition, acquisitions of our clients by our competitors could result in a decrease in the number of our current and potential clients and members, as our clients may no longer facilitate the adoption of our applications by potential members. If we are unsuccessful in establishing or maintaining our relationships with third parties that we provide services to, our ability to compete in the marketplace or to grow our revenue could be impaired and our results of operations may suffer. Even if we are successful, we cannot assure you that these relationships will result in increased client use of our services or increased revenue.
Our virtual behavioral healthcare strategies depend on our ability to maintain and expand our network of therapists, psychiatrists and other providers. If we are unable to do so, our future growth would be limited and our business, financial condition and results of operations would be harmed.
Our success is dependent upon our continued ability to maintain a network of highly trained and qualified therapists, psychiatrists and other providers. If we are unable to recruit and retain licensed therapists, psychiatrists and other providers, it would have a material adverse effect on our business and ability to grow and would adversely affect our results of operations.
In any particular market, providers could demand higher payments or take other actions that could result in higher medical costs, less attractive service for our clients or members or difficulty meeting regulatory or accreditation requirements.
The ability to develop and maintain satisfactory relationships with providers also may be negatively impacted by other factors not associated with us, such as changes in Medicare and/or Medicaid reimbursement levels, state therapist or psychiatrist licensing laws and standard of care requirements, and other pressures on healthcare providers and consolidation activity among hospitals, physician groups and healthcare providers. Our failure to maintain or to secure new cost-effective provider contracts may result in a loss of or inability to grow our client and member bases, higher costs, less attractive services for our clients and members and/or difficulty in meeting regulatory or accreditation requirements, any of which could have a material adverse effect on our business, financial condition and results of operations.
Developments affecting spending by the healthcare industry could adversely affect our business.
The U.S. healthcare industry has changed significantly in recent years, and we expect that significant changes will continue to occur. General reductions in expenditures by healthcare industry participants could result from, among other things:
●
government regulations or private initiatives that affect the manner in which healthcare providers interact with patients, payors or other healthcare industry participants, including changes in pricing or means of delivery of healthcare products and services;
●
consolidation of healthcare industry participants;
●
federal amendments to, lack of enforcement or development of applicable regulations for, or repeal of The Patient Protection and Affordable Care Act, as amended by the Health Care and Education Reconciliation Act (the “Affordable Care Act” or the “ACA”);
●
reductions in government funding for healthcare; and
●
adverse changes in business or economic conditions affecting healthcare payors or providers or other healthcare industry participants.
24
Table of Contents
Any of these changes in healthcare spending could adversely affect our revenue. Even if general expenditures by industry participants remain the same or increase, developments in the healthcare industry may result in reduced spending in some or all of the specific market segments that we serve now or in the future. However, the timing and impact of developments in the healthcare industry are difficult to predict. We cannot assure you that the demand for our solutions and services will continue to exist at current levels or that we will have adequate technical, financial, and marketing resources to react to changes in the healthcare industry.
Our estimated addressable market is subject to inherent challenges and uncertainties. If we have overestimated the size of our addressable market or the various markets in which we operate, our future growth opportunities may be limited.
Our total addressable market (“TAM”) is based on internal estimates and third-party estimates regarding the size of each of the U.S. and international behavioral health markets and is subject to significant uncertainty and is based on assumptions that may not prove to be accurate. These estimates, as well as the estimates and forecasts we have previously disclosed relating to the size and expected growth of the markets in which we operate, may change or prove to be inaccurate. While we believe the information on which we base our TAM is generally reliable, such information is inherently imprecise. In addition, our expectations, assumptions and estimates of future opportunities are necessarily subject to a high degree of uncertainty and risk due to a variety of factors, including those described herein. If third-party or internally generated data prove to be inaccurate or we make errors in our assumptions based on that data, our future growth opportunities may be affected. If our TAM, or the size of any of the various markets in which we operate, proves to be inaccurate, our future growth opportunities may be limited and there could be a material adverse effect on our prospects, business, financial condition and results of operations.
Negative media coverage could adversely affect our business.
We receive a substantial amount of media coverage in the United States. Unfavorable publicity regarding, among others, the healthcare industry, litigation or regulatory activity, the actions of the entities included or otherwise involved in our platform, virtual behavioral health services included on our platform or by other industry participants, our data privacy or data security practices, our platform or our revenue could materially adversely affect our reputation. For example, prior to the COVID-19 pandemic and the resulting shift towards the acceptance of telehealth solutions, therapists advocacy groups have lobbied the American Psychological Association to reexamine its stance on telemental health, including challenging our contracts with healthcare providers and the efficacy of telemental health, including the use of text messaging. Therapy services are subject to state law requirements, and some states may prohibit the use of text messaging or other forms of technological modalities in delivering telemental health services. With advice of regulatory counsel, we aim to structure our contracts with healthcare providers and deliver telemental health services in compliance with applicable state laws. However, in response to the COVID-19 pandemic and the limitations it created in delivering behavioral health services through in-person interactions, state and federal regulatory authorities loosened or removed a number of regulatory requirements in order to increase the availability of telehealth and teletherapy services, and both providers and patients have increasingly accepted telemental health as an alternative means of delivering and receiving behavioral health services. In addition, from time to time, news media outlets have provided negative coverage regarding our platform and privacy practices and any such negative media coverage, regardless of the accuracy of such reporting, may have an adverse impact on our business and reputation, as well as have an adverse effect on our ability to attract and retain clients, members, other consumers, or employees, and result in decreased revenue, which would materially adversely affect our business, financial condition and results of operations.
Use of social media may adversely impact our reputation, subject us to fines or other penalties or be an ineffective source to market our offerings.
We use social media as part of our omnichannel approach to marketing and outreach to clients, members and other consumers. Changes to these social networking services’ terms of use or terms of service that limit promotional communications, restrictions that would limit our ability or our clients’ ability to send communications through their services, disruptions or downtime experienced by these social networking services or reductions in the use of or engagement with social networking services by current and potential clients and members could also harm our business. As laws and regulations rapidly evolve to govern the use of these channels, the failure by us, our employees or third parties acting at our direction to abide by applicable laws and regulations in the use of these channels could adversely affect our reputation or subject us to fines or other penalties. In addition, our employees or third parties acting at our direction may knowingly or inadvertently make use of social media in ways that could lead to the loss or infringement of intellectual property, as well as the public disclosure of proprietary, confidential or sensitive personal information of our business, employees, clients, members or others. Any such inappropriate use of social media could also cause reputational damage and adversely affect our business.
25
Table of Contents
Our clients and members may engage with us online through our social media pages, including, for example, our presence on Facebook, Instagram and Twitter, by providing feedback and public commentary about all aspects of our business. Information concerning us or our platform and offerings, whether accurate or not, may be posted on social media pages at any time and may have a disproportionately adverse impact on our brand, reputation or business. The harm may be immediate without affording us an opportunity for redress or correction and could have a material adverse effect on our business, financial condition, results of operations and prospects.
With respect to our plans for expansion of international operations, we may face political, legal and compliance, operational, regulatory, economic and other risks that we do not face or that are more significant than in our domestic operations.
With respect to our plans for expansion of international operations, we may face political, legal and compliance, operational, regulatory, economic and other risks that we do not face or that are more significant than in our domestic operations. These risks may vary widely by country and include varying regional and geopolitical business conditions and demands, government intervention and censorship, discriminatory regulation, nationalization or expropriation of assets and pricing constraints. Our future international services and products may need to meet country-specific client and member preferences as well as country-specific legal requirements, including those related to healthcare regulatory laws governing telemedicine and teletherapy services, licensing, privacy, data storage, location, protection and security. The interpretation of these laws is evolving and varies significantly from country to county and are enforced by governmental, judicial and regulatory authorities with broad discretion. We cannot be certain that our interpretation of such laws and regulations will be correct in how we plan to structure our international operations, and our arrangements with locally-licensed therapists, psychiatrists or other providers, as well as our international services agreements and client arrangements. Our plans to expand our international operations will require us to overcome logistical and other challenges based on differing languages, cultures, legal and regulatory schemes and time zones. Our international operations may encounter labor laws, customs and employee relationships that can be difficult, less flexible than in our domestic operations and expensive to modify or terminate. In some countries we are required to, or choose to, operate with local business partners, which will require us to manage our partner relationships and may reduce our operational flexibility and ability to quickly respond to business challenges.
Our planned international operations may be subject to particular risks in addition to those faced by our domestic operations, including:
●
the need to localize and adapt our solution for specific countries, including translation into foreign languages and associated expenses;
●
potential loss of proprietary information due to misappropriation or laws that may be less protective of our intellectual property rights than U.S. laws or that may not be adequately enforced;
●
requirements of foreign laws and other governmental controls, including cross-border compliance challenges related to the complexity of multiple, conflicting and changing governmental laws and regulations, including employment, healthcare, tax, privacy and data protection laws and regulations;
●
requirements of foreign laws and other governmental controls applicable to our ability to conduct telehealth and teletherapy services internationally, specifically laws governing remote care and the practice of medicine in such locations;
●
data privacy laws that require that client data be stored and processed in a designated territory;
●
new and different sources of competition and laws and business practices favoring local competitors;
●
local business and cultural factors that differ from our normal standards and practices, including business practices that we are prohibited from engaging in by the U.S. Foreign Corrupt Practices Act of 1977 (“FCPA”) and other anti-corruption laws and regulations;
●
changes to export controls and economic sanctions laws and regulations;
●
central bank and other restrictions on our ability to repatriate cash from international subsidiaries;
●
adverse tax consequences;
●
fluctuations in currency exchange rates, economic instability and inflationary conditions, which could make our solution more expensive or increase our costs of doing business in certain countries;
●
limitations on future growth or inability to maintain current levels of revenues from international sales if we do not invest sufficiently in our international operations;
26
Table of Contents
●
different pricing environments, longer sales cycles and longer accounts receivable payment cycles and collections issues;
●
difficulties in staffing, managing and operating our international operations, including difficulties related to administering our stock plans in some foreign countries and increased financial accounting and reporting requirements and complexities;
●
difficulties in coordinating the activities of our geographically dispersed and culturally diverse operations; and
●
political unrest, war, terrorism or regional natural disasters, particularly in areas in which we have facilities.
Our overall success regarding our planned expansion in international markets will depend, in part, on our ability to anticipate and effectively manage these risks and there can be no assurance that we will be able to do so without incurring unexpected costs. If we are not able to manage the risks related to expansion of our international operations, we may not achieve the expected benefits of this expansion and our business, financial condition and results of operations may be harmed.
We may become subject to medical liability claims, which could cause us to incur significant expenses and may require us to pay significant damages if not covered by insurance.
Our overall business entails the risk of medical liability claims. Although Talkspace Provider Network, PA (“TPN”) and our affiliated professionals carry or will carry insurance covering medical malpractice claims in amounts that we believe are appropriate in light of the risks attendant to the services rendered, successful medical liability claims could result in substantial damage awards that exceed the limits of TPN’s and those affiliated professionals’ insurance coverage. TPN carries or will carry professional liability insurance for itself and each of its healthcare professionals (our providers). Additionally, all of our network providers that contract or will contract with TPN separately carry or will carry professional liability insurance for itself and its healthcare professionals. Professional liability insurance is expensive and insurance premiums may increase significantly in the future, particularly as we expand our services through TPN and our affiliated professionals. As a result, adequate professional liability insurance may not be available to TPN and our affiliated professionals in the future at acceptable costs or at all, which may negatively impact TPN and our affiliated professionals to provide services to our members, and thereby adversely affect our overall business and operations.
Any claims made against TPN or our affiliated professionals that are not fully covered by insurance could be costly to defend against, result in substantial damage awards, and divert the attention of our management and our affiliated professional entities from our operations, which could have a material adverse effect on our business, financial condition and results of operations. In addition, any claims may adversely affect our business or reputation.
A decline in the prevalence of employer-sponsored healthcare or the emergence of new technologies may adversely impact our business-to-business segment or require us to expend significant resources in order to remain competitive.
The U.S. healthcare industry is massive, with a number of large market participants with conflicting agendas, and it is subject to significant government regulation and is currently undergoing significant change. Changes in our industry, for example, such as the emergence of new technologies as more competitors enter our market, could adversely impact our business-to business segment where companies provide Talkspace to their employees as a benefit.
Some experts have predicted that future healthcare reform will encourage employer-sponsored health insurance to become significantly less prevalent as employees migrate to obtaining their own insurance over the state-sponsored insurance marketplaces. Were this to occur, there is no guarantee that we would be able to compensate for the loss in revenue from employers by increasing sales of our solution to health insurance companies or to individuals or government agencies. In such a case, our results of operations would be adversely impacted.
If healthcare benefits trends shift or entirely new technologies are developed that replace existing solutions, our existing or future solutions could be adversely impacted and our business could be adversely affected. In addition, we may experience difficulties with industry standards, design or marketing that could delay or prevent our development, introduction or implementation of new applications and enhancements.
We rely on third-party platforms such as the Apple App Store and Google Play App Store, to distribute our platform and offerings.
Our apps are accessed and operate through third-party platforms or marketplaces, including the Apple App Store and Google Play App Store, which also serve as significant online distribution platforms for our apps. As a result, the expansion and prospects of our business and our apps depend on our continued relationships with these providers and any other emerging platform
27
Table of Contents
providers that are widely adopted by consumers. We are subject to the standard terms and conditions that these providers have for application developers, which govern the content, promotion, distribution and operation of apps on their platforms or marketplaces, and which the providers can change unilaterally on short or no notice.
Thus, our business could suffer materially if platform providers change their standard terms and conditions, interpretations or other policies and practices in a way that is detrimental to us or if platform providers determine that we are in violation of their standard terms and conditions and prohibit us from distributing our apps on their platforms. In addition, our business would be harmed if the providers discontinue or limit our access to their platforms or marketplaces; the platforms or marketplaces decline in popularity; the platforms modify their algorithms, communication channels available to developers, respective terms of service or other policies, including fees; the providers adopt changes or updates to their technology that impede integration with other software systems or otherwise require us to modify our technology or update our apps in order to ensure that consumers can continue to access and use our virtual behavioral health services.
If alternative providers increase in popularity, we could be adversely impacted if we fail to create compatible versions of our apps in a timely manner, or if we fail to establish a relationship with such alternative providers. Likewise, if our current providers alter their operating platforms, we could be adversely impacted as our offerings may not be compatible with the altered platforms or may require significant and costly modifications in order to become compatible. If our providers do not perform their obligations in accordance with our platform agreements, we could be adversely impacted.
In the past, some of these platforms or marketplaces have been unavailable for short periods of time. If this or a similar event were to occur on a short- or long-term basis, or if these platforms or marketplaces otherwise experience issues that impact the ability of consumers to download or access our apps and other information, it could have a material adverse effect on our brand and reputation, as well as our business, financial condition and operating results.
We rely on data center providers, Internet infrastructure, bandwidth providers, third-party computer hardware and software, other third parties and our own systems for providing services to our clients and members, and any failure or interruption in the services provided by these third parties or our own systems could expose us to litigation and negatively impact our relationships with clients and members, adversely affecting our brand and our business.
We serve all of our clients and members from third party interconnection and data centers, such as Amazon Web Services. While we control and have access to our servers, we do not control the operation of these facilities. The cloud vendors and the owners of our data center facilities have no obligation to renew their agreements with us on commercially reasonable terms, or at all. If we are unable to renew these agreements on commercially reasonable terms, or if one of our cloud vendors or data center operators is acquired, we may be required to transfer our servers and other infrastructure to a new vendor or a new data center facility, and we may incur significant costs and possible service interruption in connection with doing so. Problems faced by our cloud vendors or third-party data center locations with the telecommunications network providers with whom we or they contract, or with the systems by which our telecommunications providers allocate capacity among their clients, including us, could adversely affect the experience of our clients and members. Our third-party data center operators could decide to close their facilities without adequate notice. In addition, any financial difficulties, such as bankruptcy faced by our cloud vendors or third-party data centers operators or any of the service providers with whom we or they contract may have negative effects on our business, the nature and extent of which are difficult to predict.
Additionally, if our cloud or data center vendors are unable to keep up with our growing needs for capacity, this could have an adverse effect on our business. For example, a rapid expansion of our business could affect the service levels at our cloud vendors or data centers or cause such data centers and systems to fail. Any changes in third-party service levels at our data centers or any disruptions or other performance problems with our solution could adversely affect our reputation and may damage our clients and members’ stored files or result in lengthy interruptions in our services. Interruptions in our services may reduce our revenue, cause us to issue refunds to clients and members for prepaid and unused subscriptions, as well as loss of revenue related to service level credits and uptime, subject us to potential liability or adversely affect client retention.
In addition, our ability to deliver our Internet-based services depends on the development and maintenance of the infrastructure of the Internet by third parties. This includes maintenance of a reliable network backbone with the necessary speed, data capacity, bandwidth capacity and security. Our services are designed to operate without interruption in accordance with our service level commitments. However, we have experienced, including during the period immediately following the beginning of the COVID-19 pandemic, and expect that we may experience in the future, interruptions and delays in services and availability from time to time. In the event of a catastrophic event with respect to one or more of our systems, we may experience an extended period of
28
Table of Contents
system unavailability, which could negatively impact our relationship with clients and members. To operate without interruption, both we and our service providers must guard against:
●
damage from fire, power loss, natural disasters and other force majeure events outside our control;
●
communications failures;
●
software and hardware errors, failures and crashes;
●
security breaches, computer viruses, hacking, denial-of-service attacks and similar disruptive problems; and
●
other potential interruptions.
We also rely on computer hardware purchased and software licensed from third parties in order to offer our services. These licenses are generally commercially available on varying terms. However, it is possible that this hardware and software may not continue to be available on commercially reasonable terms, or at all. Any loss of the right to use any of this hardware or software could result in delays in the provisioning of our services until equivalent technology is either developed by us, or, if available from third parties, is identified, obtained and integrated.
We exercise limited control over third-party vendors, which increases our vulnerability to problems with technology and information services they provide. Interruptions in our network access and services may in connection with third-party technology and information services reduce our revenue, cause us to issue refunds to clients and members, subject us to potential liability or adversely affect client retention. Although we maintain a security and privacy damages insurance policy, the coverage under our policies may not be adequate to compensate us for all losses that may occur related to the services provided by our third-party vendors. In addition, we may not be able to continue to obtain adequate insurance coverage at an acceptable cost, if at all.
Our ability to rely on these services of third-party vendors could be impaired as a result of the failure of such providers to comply with applicable laws, regulations and contractual covenants, or as a result of events affecting such providers, such as power loss, telecommunication failures, software or hardware errors, computer viruses, cyber incidents and similar disruptive problems, fire, flood and natural disasters. Any such failure or event could adversely affect our relationships with our clients and members and damage our reputation. This could materially and adversely impact our business, financial condition and operating results.
If our or our vendors’ security measures fail or are breached and unauthorized access to a client’s data or information systems is obtained, our services may be perceived as insecure, we may incur significant liabilities, our reputation may be harmed, and we could lose sales, clients and members.
Our services involve the storage and transmission of clients’ and our clients and members’ proprietary information, sensitive or confidential data, including valuable intellectual property and personal information of employees, clients, members and others, as well as the protected health information (“PHI”), of our clients and members. We are subject to laws and regulations relating to the collection, use, retention, security and transfer of this information. Because of the extreme sensitivity of the information we store and transmit, the security features of our and our third-party vendors’ computer, network, and communications systems infrastructure are critical to the success of our business. A breach or failure of our or our third-party vendors’ network, hosted service providers or vendor systems could result from a variety of circumstances and events, including third-party action, employee negligence or error, malfeasance, computer viruses, cyber-attacks by computer hackers such as denial-of-service and phishing attacks, failures during the process of upgrading or replacing software and databases, power outages, hardware failures, telecommunication failures, user errors, or catastrophic events. Information security risks have generally increased in recent years because of the proliferation of new technologies and the increased sophistication and activities of perpetrators of cyber-attacks. Hackers and data thieves are increasingly sophisticated and operating large-scale and complex automated attacks, including on companies within the healthcare industry. As cyber threats continue to evolve, we may be required to expend additional resources to further enhance our information security measures and/or to investigate and remediate any information security vulnerabilities. If our or our third-party vendors’ security measures fail or are breached, it could result in unauthorized persons accessing sensitive client or member data (including PHI), a loss of or damage to our data, an inability to access data sources, or process data or provide our services to our clients and members. Such failures or breaches of our or our third-party vendors’ security measures, or our or our third-party vendors’ inability to effectively resolve such failures or breaches in a timely manner, could severely damage our reputation, adversely affect client, patient, member or investor confidence in us, and reduce the demand for our services from existing and potential clients and members. In addition, we could face litigation, damages for contract breach, monetary penalties, or regulatory actions for violation of applicable laws or regulations and incur significant costs for remedial measures to prevent future occurrences and mitigate past violations. Although we maintain insurance covering certain security
29
Table of Contents
and privacy damages and claim expenses, we may not carry insurance or maintain coverage sufficient to compensate for all liability and in any event, insurance coverage would not address the reputational damage that could result from a security incident.
Data privacy is also subject to frequently changing laws, rules and regulations in the various jurisdictions in which we operate. Such initiatives around the country could increase the cost of developing, implementing or securing our servers and require us to allocate more resources to improved technologies, adding to our IT and compliance costs. Our Board of Directors is briefed periodically on cybersecurity and risk management issues and we have implemented a number of processes to avoid cyber threats and to protect privacy. However, the processes we have implemented in connection with such initiatives may be insufficient to prevent or detect improper access to confidential, proprietary or sensitive data, including personal data. In addition, the competition for talent in the data privacy and cybersecurity space is intense, and we may be unable to hire, develop or retain suitable talent capable of adequately detecting, mitigating or remediating these risks. Our failure to adhere to, or successfully implement processes in response to, changing legal or regulatory requirements in this area could result in legal liability or damage to our reputation in the marketplace.
Should an attacker gain access to our network, including by way of example, using compromised credentials of an authorized user, we are at risk that the attacker might successfully leverage that access to compromise additional systems and data. Certain measures that we currently have in place in order to increase the security of our systems, such as data encryption (including data at rest encryption), heightened monitoring and logging, scanning for source code errors or deployment of multi-factor authentication, take significant time and resources to deploy broadly, and such measures may not be deployed in a timely manner or be effective against an attack. As cybersecurity threats continue to evolve, we may be required to expend significant additional resources to continue to modify or enhance our protective measures or to investigate and remediate any information security vulnerabilities. The inability to implement, maintain and upgrade adequate safeguards could have a material adverse effect on our business.
Our information systems must be continually updated, patched and upgraded to protect against known vulnerabilities. The volume of new vulnerabilities has increased markedly, as has the criticality of patches and other remedial measures. In addition to remediating newly identified vulnerabilities, previously identified vulnerabilities must also be continuously addressed. Accordingly, we are at risk that cyber-attackers exploit these known vulnerabilities before they have been addressed. Any failure related to these activities and any breach of our information systems could result in significant liability and/or have a material adverse effect on our business, reputation and financial condition.
We could experience losses or liability not covered by insurance.
Our business exposes us to risks that are inherent in the provision of virtual behavioral healthcare and access to remote, virtual healthcare and therapy. If clients, members or other individuals assert liability claims against us, any ensuing litigation, regardless of outcome, could result in a substantial cost to us, divert management’s attention from operations, and decrease market acceptance of our solution. We attempt to limit our liability to clients and members by contract; however, the limitations of liability set forth in the contracts may not be enforceable or may not otherwise protect us from liability for damages. Additionally, we may be subject to claims that are not explicitly covered by contract. We also maintain general liability coverage; however, this coverage may not continue to be available on acceptable terms, may not be available in sufficient amounts to cover one or more large claims against us, and may include larger self-insured retentions or exclusions for certain products. In addition, the insurer might disclaim coverage as to any future claim. A successful claim not fully covered by our insurance could have a material adverse impact on our liquidity, financial condition, and results of operations.
There may be adverse tax, legal and other consequences if the employment status of providers on our platform is challenged.
There is often uncertainty in the application of worker classification laws, especially in the medical field where individuals are required to hold professional licenses, and, consequently, there is risk that providers could be deemed to be misclassified under applicable law. We and TPN structure our relationships with the majority of our respective providers in a manner that we believe results in an independent contractor relationship, not an employee relationship. The tests governing whether a service provider is an independent contractor, or an employee are typically highly fact sensitive and vary by governing law. An independent contractor is generally distinguished from an employee by his or her degree of autonomy and independence in providing services. A high degree of autonomy and independence is generally indicative of a contractor relationship, while a high degree of control is generally indicative of an employment relationship. Although we believe that our and TPN’s providers are properly characterized as independent contractors, tax or other regulatory authorities may in the future challenge our characterization of these relationships. A misclassification determination or allegation creates potential exposure for us, including but not limited to: monetary exposure arising from or relating to failure to withhold and remit taxes, unpaid wages and wage and hour laws and requirements (such as those pertaining to minimum wage and overtime); claims for employee benefits, social security, Medicare,
30
Table of Contents
workers’ compensation and unemployment; claims of discrimination, harassment and retaliation under civil rights laws; claims under laws pertaining to unionizing, collective bargaining and other concerted activity; and other claims, charges, or other proceedings under laws and regulations applicable to employers and employees, including risks relating to allegations of joint employer liability. Such claims could result in monetary damages or other liability, and any adverse determination, including potentially the requirement for us to indemnify a user, could also harm our brand, which could materially and adversely affect our business, prospects, financial condition and results of operations. While these risks are mitigated, in part, by our contractual rights of indemnification against third-party claims, such indemnification agreements could be determined to be unenforceable or costly to enforce and indemnification under such agreements may otherwise prove inadequate. As a result, any determination that our and/or TPN’s providers are employees could have a material adverse effect on our business, financial condition and results of operations.
Any future litigation against us could be costly and time-consuming to defend.
We may become subject, from time to time, to legal proceedings, payer audits, investigations, and claims that arise in the ordinary course of business such as claims brought by our clients in connection with commercial disputes or employment claims made by our current or former associates. Litigation and audits may result in substantial costs and may divert management’s attention and resources, which may substantially harm our business, financial condition and results of operations. Insurance may not cover such claims, may not provide sufficient payments to cover all of the costs to resolve one or more such claims and may not continue to be available on terms acceptable to us. A claim brought against us that is uninsured or underinsured could result in unanticipated costs, thereby reducing our earnings and leading analysts or potential investors to reduce their expectations of our performance, which could reduce the market price of our stock.
Changes in consumer sentiment or laws, rules or regulations regarding the use of cookies and other tracking technologies and other privacy matters could have a material adverse effect on our ability to generate net revenues and could adversely affect our ability to collect proprietary data on consumer behavior.
Consumers may become increasingly resistant to the collection, use and sharing of information online, including information used to deliver and optimize advertising, and take steps to prevent such collection, use and sharing of information. For example, consumer complaints and/or lawsuits regarding online advertising or the use of cookies or other tracking technologies in general and our practices specifically could adversely impact our business.
Consumers can currently opt out of the placement or use of most cookies for online advertising purposes by either deleting or disabling cookies on their browsers, visiting websites that allow consumers to place an opt-out cookie on their browsers, which instructs participating entities not to use certain data about consumers’ online activity for the delivery of targeted advertising, or by downloading browser plug-ins and other tools that can be set to: identify cookies and other tracking technologies used on websites; prevent websites from placing third-party cookies and other tracking technologies on the consumer’s browser; or block the delivery of online advertisements on apps and websites.
We are subject to evolving EU and UK privacy laws on cookies and e-marketing. In the EU and the UK, under national laws derived from the ePrivacy Directive, informed consent is required for the placement of a cookie or similar technologies on a user’s device and generally for direct electronic marketing to consumers. The General Data Protection Regulation (“GDPR”) also imposes conditions on obtaining valid consent, such as a prohibition on pre-checked consents and a requirement to ensure separate consents are sought for each type of cookie or similar technology. The current national laws that implement the ePrivacy Directive are highly likely to be replaced across the EU (but not directly in the UK) by an EU regulation known as the ePrivacy Regulation which will significantly increase fines for non-compliance. While the text of the ePrivacy Regulation is still under development, recent European court decisions regarding the consent requirements and regulators’ recent guidance are driving increased attention to cookies and tracking technologies. For example, in December 2020 the French data protection regulator (the CNIL) imposed fines of EUR 100M and EUR 35M respectively against certain Google and Amazon entities for alleged breaches of cookies consent and transparency requirements; and in December 2021, the CNIL imposed fines of EUR 150M and EUR 60M respectively against certain Google and Meta entities for alleged failures to allow users to easily reject cookies. In addition, NYOB (a not for profit organization led by Max Schrems) has recently issued approximately 500 complaints to European website operators regarding their cookie banners and referred 422 of these to relevant national regulators and has said that it aims to scan, warn and seek enforcement on up to 10,000 websites in Europe. If the trend of increasing enforcement by regulators of the strict approach in recent guidance and decisions continues, this could lead to substantial costs, require significant systems changes, limit the effectiveness of our marketing activities, divert the attention of our technology personnel, adversely affect our margins, increase costs and subject us to additional liabilities. Regulation of cookies and similar technologies, and any decline of cookies or similar online tracking technologies as a means to identify and potentially target users, may lead to broader
31
Table of Contents
restrictions and impairments on our marketing and personalization activities and may negatively impact our efforts to understand users.
In response to marketplace concerns about the usage of third-party cookies and web beacons to track user behaviors, providers of major browsers have included features that allow users to limit the collection of certain data generally or from specified websites. In addition, various software tools and applications have been developed that can block advertisements from a consumer’s screen or allow consumers to shift the location in which advertising appears on webpages or opt out of display, search and internet-based advertising entirely. In particular, Apple’s mobile operating system permits these technologies to work in its mobile Safari browser. In addition, changes in device and software features could make it easier for internet users to prevent the placement of cookies or to block other tracking technologies. In particular, the default settings of consumer devices and software may be set to prevent the placement of cookies unless the user actively elects to allow them. For example, Apple’s Safari browser currently has a default setting under which third-party cookies are not accepted and users must activate a browser setting to enable cookies to be set, and Apple has announced that its new mobile operating system will require consumers to opt in to the use of Apple’s resettable device identifier for advertising purposes. Various industry participants have worked to develop and finalize standards relating to a mechanism in which consumers choose whether to allow the tracking of their online search and browsing activities, and such standards may be implemented and adopted by industry participants at any time. These developments could impair our ability to collect user information, including personal data and usage information, that helps us provide more targeted advertising to our current and prospective consumers, which could adversely affect our business, given our use of cookies and similar technologies to target our marketing and personalize the consumer experience.
If consumer sentiment regarding privacy issues or the development and deployment of new browser solutions or other Do Not Track mechanisms result in a material increase in the number of consumers who choose to opt out or block cookies and other tracking technologies or who are otherwise using browsers where they need to, and fail to, allow the browser to accept cookies, or otherwise result in cookies or other tracking technologies not functioning properly, our ability to advertise effectively and conduct our business, and our results of operations and financial condition would be adversely affected.
Changes in U.S. tax laws could adversely affect our operating results and financial condition.
The United States enacted tax reform legislation in 2017 (the “Tax Cuts and Jobs Act of 2017”) that, among other things, reduces the U.S. federal corporate income tax rate to 21%, imposes significant limitations on the deductibility of interest and executive compensation, allows for the expensing of capital expenditures, limits the deduction for net operating losses (“NOLs”) to 80% of current year taxable income in respect of losses arising in taxable years beginning after 2017, and modifies or repeals many business deductions and credits. The reduction in the U.S. federal corporate income tax rate is expected to be beneficial to us in future years in which we have net income subject to U.S. tax. The reduction in the U.S. federal corporate income tax rate also resulted in a remeasurement of our deferred tax assets and liabilities. There was no net impact on our deferred tax assets as we maintain a full valuation allowance. On March 27, 2020, the Coronavirus Aid, Relief, and Economic Security Act (the “CARES Act”) was enacted in response to the COVID-19 pandemic. The CARES Act contains certain tax provisions, including provisions that retroactively and/or temporarily suspend or relax in certain respects the application of certain provisions, such as the limitations on the deduction of NOLs and interest, in the Tax Cuts and Jobs Act of 2017.
There are a number of uncertainties and ambiguities as to the interpretation and application of many of the provisions in the Tax Cuts and Jobs Act of 2017 and the CARES Act. In the absence of guidance on these issues, we will use what we believe are reasonable interpretations and assumptions in interpreting and applying the Tax Cuts and Jobs Act of 2017 and the CARES Act, which may change as we receive additional clarification and implementation guidance. It is also possible that the Internal Revenue Service could issue subsequent guidance or take positions that differ from the interpretations and assumptions that we previously made, which could have a material adverse effect on our cash tax liabilities, results of operations and financial condition.
Certain U.S. state and local tax authorities may assert that we have a nexus with such states or localities and may seek to impose state and local income taxes on our income allocated to such state and localities.
There is a risk that certain state tax authorities where we do not currently file a state income tax return could assert that we are liable for state and local income taxes based upon income or gross receipts allocable to such states or localities. States and localities are becoming increasingly aggressive in asserting nexus for state and local income tax purposes. We could be subject to additional state and local income taxation, including penalties and interest attributable to prior periods, if a state or local tax authority in a state or locality where we do not currently file an income tax return successfully asserts that our activities give rise to nexus for state income tax purposes. Such tax assessments, penalties and interest may adversely affect our cash tax liabilities, results of operations and financial condition.
32
Table of Contents
Taxing authorities may successfully assert that we should have collected or in the future should collect sales and use or similar taxes for virtual behavioral health services which could adversely affect our results of operations.
State taxing authorities may assert that we had economic nexus with their state and were required to collect sales and use or similar taxes with respect to past or future services that we have provided or will provide, which could result in tax assessments and penalties and interest. The assertion of such taxes against us for past services, or any requirement that we collect sales taxes on its provision of future services, could have a material adverse effect on our business, cash tax liabilities, results of operations, and financial condition.
Our ability to use our net operating losses and certain other attributes may be subject to certain limitations.
At December 31, 2021, the Company has federal and state net operating loss carryovers (“NOL”) of approximately $194.0 million and $180.6 million, respectively, which are available to reduce future taxable income. The NOL carryforwards begin to expire in 2032 and may become subject to annual limitation in the event of certain cumulative changes in the ownership interest of significant stockholders over a three-year period in excess of 50%, as defined under I.R.C. Section 382. This could limit the amount of tax attributes that can be utilized annually to offset future taxable income or future tax liabilities. The federal losses generated from 2018 onward do not expire.
It is possible that we will not generate taxable income in time to use these net operating loss carryforwards before their expiration (or that we will not generate taxable income at all). Under the Tax Cuts and Jobs Act of 2017, U.S. federal net operating losses incurred in 2018 and in future years may be carried forward indefinitely, but the deductibility of such net operating losses is limited. It is uncertain if and to what extent various states will conform to these in federal tax laws. In addition, the federal and state net operating loss carryforwards and certain tax credits may be subject to significant limitations under Section 382 and Section 383 of the Internal Revenue Code, respectively, and similar provisions of state law. Under those sections of the Internal Revenue Code, if a corporation undergoes an “ownership change,” the corporation’s ability to use its pre-change net operating loss carryforwards and other pre-change attributes, such as research tax credits, to offset its post-change income or tax may be limited. In general, an “ownership change” will occur if there is a cumulative change in our ownership by “5-percent shareholders” that exceeds 50 percentage points over a rolling three-year period. Similar rules may apply under state tax laws. We have not undertaken an analysis of whether we have experienced an “ownership change” for purposes of Section 382 and Section 383 of the Internal Revenue Code or whether there are any limitations on use with respect to our net operating losses and other tax attributes.
Our quarterly results may fluctuate significantly, which could adversely impact the value of our common stock.
Our quarterly results of operations, including our revenue, net loss and cash flows, has varied and may vary significantly in the future, and period-to-period comparisons of our results of operations may not be meaningful. Accordingly, our quarterly results should not be relied upon as an indication of future performance. Our quarterly financial results may fluctuate as a result of a variety of factors, many of which are outside of our control, including, without limitation, the following:
●
our ability to maintain and grow the number of clients and members on our platform;
●
the demand for and types of services that are offered on our platform by providers;
●
the timing of recognition of revenue, including possible delays in the recognition of revenue due to sometimes unpredictable implementation timelines;
●
the amount and timing of operating expenses related to the maintenance and expansion of our business, operations and infrastructure;
●
our ability to effectively manage the size and composition of our network of healthcare providers relative to the level of demand for services from our members and our clients’ members and patients;
●
our ability to respond to competitive developments, including pricing changes and the introduction of new products and services by our competitors;
●
client and member retention and the timing and terms of client and member renewals;
●
changes to our pricing model;
●
our ability to introduce new features and services and enhance our existing platform and our ability to generate significant revenue from new features and services;
33
Table of Contents
●
the mix of products and services sold during a period;
●
the impact of outages of our platform and associated reputational harm;
●
security or data privacy breaches and associated remediation costs;
●
the timing of expenses related to the development or acquisition of technologies or businesses and potential future charges for impairment of goodwill from acquired companies;
●
changes in the fair values of our financial instruments (including, but not limited to, certain warrants assumed in connection with the Business Combination); and
●
the COVID-19 pandemic.
Most of our revenue in any given quarter is derived from contracts entered into with our clients during previous quarters. Consequently, a decline in new or renewed contracts in any one quarter may not be fully reflected in our revenue for that quarter. Such declines, however, would negatively affect our revenue in future periods and the effect of significant downturns in sales of and market demand for our solution, and potential changes in our renewals or renewal terms, may not be fully reflected in our results of operations until future periods. Our subscription model also makes it difficult for us to rapidly increase our total revenue through additional sales in any period, as revenue from new clients must be recognized over the applicable term of the contract. Accordingly, the effect of changes in the industry impacting our business or changes we experience in our new sales may not be reflected in our short-term results of operations. Any fluctuation in our quarterly results may not accurately reflect the underlying performance of our business and could cause a decline in the trading price of our securities.
We depend on our senior management team, and the loss of one or more of our executive officers or key employees or an inability to attract and retain highly skilled and diverse employees could adversely affect our business.
Our success depends largely upon the continued services of our key members of senior management. These members of senior management are at-will employees and therefore they may terminate employment with us at any time with no advance notice. We also rely on our leadership team in the areas of research and development, marketing, services and general and administrative functions. From time to time, there may be changes in our management team resulting from the hiring or departure of executives, which could disrupt our business. For instance, in November 2021 we announced the departure of Oren Frank, our former Chief Executive Officer and Roni Frank, our former Head of Clinical Services and the appointment of Douglas Braunstein as our interim Chief Executive Officer. We are in the process of searching for a permanent replacement to serve as Chief Executive Officer. The replacement of one or more of our executive officers or other key employees will likely involve significant time and costs and may significantly delay or prevent the achievement of our business objectives. Our business would also be adversely affected if we fail to adequately plan for succession of our executives and senior management; or if we fail to effectively recruit, integrate, retain and develop key talent and/or align our talent with our business needs, in light of the current rapidly changing environment. While we have employment arrangements with a limited number of key executives, these do not guarantee that the services of these or suitable successor executives will continue to be available to us.
Our success is dependent on our ability to align our talent with our business needs, engage our employees and inspire our employees to be open to change, to innovate and to maintain member- and client-focus when delivering our services. To continue to execute our growth strategy, we also must attract and retain highly skilled personnel. Competition is intense for qualified professionals. We may not be successful in continuing to attract and retain qualified personnel. We have from time to time in the past experienced, and we expect to continue to experience in the future, difficulty in hiring and retaining highly skilled personnel with appropriate qualifications. The pool of qualified personnel with experience working in the healthcare market is limited overall. In addition, many of the companies with which we compete for experienced personnel have greater resources than we have. In addition, as we expand internationally, we face the challenge of recruiting, integrating, educating, managing, retaining and developing a more culturally diverse workforce.
In addition, in making employment decisions, particularly in high-technology industries, job candidates often consider the value of the stock options or other equity instruments they are to receive in connection with their employment. Volatility in the price of our stock may, therefore, adversely affect our ability to attract or retain highly skilled personnel. Further, the requirement to expense stock options and other equity instruments may discourage us from granting the size or type of stock option or equity awards that job candidates require to join our company. Failure to attract new personnel or failure to retain and motivate our current personnel, could have a material adverse effect on our business, financial condition and results of operations.
34
Table of Contents
We may acquire other companies or technologies, which could divert our management’s attention, result in dilution to our stockholders and otherwise disrupt our operations and we may have difficulty integrating any such acquisitions successfully or realizing the anticipated benefits therefrom, any of which could have a material adverse effect on our business, financial condition and results of operations.
We intend to seek to acquire or invest in businesses, software-based products and services or technologies that we believe could complement or expand our solution, enhance our technical capabilities or otherwise offer growth opportunities. To pursue this strategy successfully, we must identify attractive acquisition or investment opportunities and successfully complete transactions, some of which may be large and complex. We may not be able to identify or complete attractive acquisition or investment opportunities due to, among other things, the intense competition for these transactions. If we are not able to identify and complete such acquisition or investment opportunities, our future results of operations and financial condition may be adversely affected. Additionally, the pursuit of potential acquisitions may divert the attention of management and cause us to incur various expenses in identifying, investigating and pursuing suitable acquisitions, whether or not they are consummated.
If we acquire additional businesses, we may not be able to integrate the acquired personnel, operations and technologies successfully, or effectively manage the combined business following the acquisition. We also may not achieve the anticipated benefits from the acquired business due to a number of factors, including, but not limited to:
●
an inability to integrate or benefit from acquired technologies or services in a profitable manner;
●
unanticipated costs or liabilities associated with the acquisition;
●
difficulty integrating the accounting systems, operations and personnel of the acquired business;
●
difficulties and additional expenses associated with supporting legacy products and hosting infrastructure of the acquired business;
●
difficulty converting the clients of the acquired business onto our platform and contract terms, including disparities in the revenue, licensing, support or professional services model of the acquired company;
●
diversion of management’s attention from other business concerns;
●
adverse effects to our existing business relationships with business partners and clients as a result of the acquisition;
●
the potential loss of key employees;
●
use of resources that are needed in other parts of our business; and
●
use of substantial portions of our available cash to consummate the acquisition.
In addition, a significant portion of the purchase price of companies we acquire may be allocated to acquired goodwill and other intangible assets, which generally must be assessed for impairment at least annually. In the future, if our acquisitions do not yield expected returns, we may be required to take charges to our results of operations based on this impairment assessment process, which could adversely affect our results of operations.
Acquisitions could also result in dilutive issuances of equity securities or the incurrence of debt, which could adversely affect our results of operations. In addition, if an acquired business fails to meet our expectations, our business, financial condition and results of operations may suffer.
Economic uncertainties or downturns in the general economy or the industries in which our clients operate could disproportionately affect the demand for our solution and negatively impact our results of operations.
General worldwide economic conditions have experienced significant downturns during the last ten years, and market volatility and uncertainty remain widespread, making it potentially very difficult for our clients and us to accurately forecast and plan future business activities. During challenging economic times, our clients may have difficulty gaining timely access to sufficient credit or obtaining credit on reasonable terms, which could impair their ability to make timely payments to us and adversely affect our revenue. If that were to occur, our financial results could be harmed. Further, challenging economic conditions may impair the ability of our clients to pay for the software-based products and services they already have purchased from us and, as a result, our write-offs of accounts receivable could increase. We cannot predict the timing, strength or duration of any economic slowdown or recovery. If the condition of the general economy or markets in which we operate worsens, our business could be harmed.
35
Table of Contents
RISKS RELATED TO OUR LEGAL AND REGULATORY ENVIRONMENT
Our business could be adversely affected by legal challenges to our business model or by actions restricting our ability to provide the full range of our services in certain jurisdictions.
Our ability to conduct telehealth and teletherapy services through our network of providers in a particular jurisdiction is directly dependent upon the applicable laws governing remote care, the practice of medicine and healthcare delivery in general in such location, which are subject to changing political, regulatory and other influences. With respect to telehealth and teletherapy services, in the past, state medical boards have established new rules or interpreted existing rules in a manner that has limited or restricted our ability to conduct our business as it was conducted in other states. Some of these actions have resulted in the suspension or modification of our telehealth and teletherapy operations in certain states. However, the extent to which a jurisdiction considers particular actions or relationships to comply with the applicable standard of care is subject to change and to evolving interpretations by (in the case of U.S. states) medical boards and state attorneys general, among others, each with broad discretion. Accordingly, we must monitor our compliance with the law in every jurisdiction in which we operate, on an ongoing basis, and we cannot provide assurance that our activities and arrangements, if challenged, will be found to be in compliance with the law. Although the COVID-19 pandemic has led to the relaxation of certain Medicare, Medicaid and state licensure restrictions on the delivery of telehealth and teletherapy services, it is uncertain how long the relaxed policies will remain in effect, and, there can be no guarantee that once the COVID-19 pandemic is over that such restrictions will not be reinstated or changed in a way that adversely affects our business.
Additionally, it is possible that the laws and rules governing the practice of medicine, including remote care and prescribing medication online, in one or more jurisdictions may change in a manner deleterious to our business. For instance, a few states have imposed different, and, in some cases, additional, standards regarding the provision of services via telehealth and teletherapy. Some states impose strict standards on using telehealth and teletherapy to prescribe certain classes of controlled substances that can be commonly used to treat behavioral health disorders. The unpredictability of this regulatory landscape means that sudden changes in policy regarding standards of care and reimbursement are possible. If a successful legal challenge or an adverse change in the relevant laws were to occur, and we or our affiliated medical group were unable to adapt our business model accordingly, our operations in the affected jurisdictions would be disrupted, which could have a material adverse effect on our business, financial condition and results of operations.
Evolving government regulations may result in increased costs or adversely affect our results of operations.
In a regulatory climate that is uncertain, our operations may be subject to direct and indirect adoption, expansion or reinterpretation of various laws and regulations. Compliance with these future laws and regulations may require us to change our practices at an undeterminable and possibly significant initial monetary and recurring expense. These additional monetary expenditures may increase future overhead, which could have a material adverse effect on our results of operations. We have identified what we believe are the areas of government regulation that, if changed, would be costly to us. These include rules governing the practice of medicine by physicians and other licensed professionals; laws relating to licensure requirements for physicians and other licensed health professionals; laws limiting the corporate practice of medicine and professional fee-splitting; laws governing the issuances of prescriptions in an online setting; cybersecurity and privacy laws; and laws and rules relating to the distinction between independent contractors and employees. There could be laws and regulations applicable to our business that we have not identified or that, if changed, may be costly to us, and we cannot predict all the ways in which implementation of such laws and regulations may affect us.
In the jurisdictions in which we operate, even where we believe we are in compliance with all applicable laws, due to the uncertain regulatory environment, certain jurisdictions may determine that we are in violation of their laws. In the event that we must remedy such violations, we may be required to modify our services and products in a manner that undermines our solution’s attractiveness to our clients, members or providers or experts, we may become subject to fines or other penalties or, if we determine that the requirements to operate in compliance in such jurisdictions are overly burdensome, we may elect to terminate our operations in such places. In each case, our revenue may decline and our business, financial condition and results of operations could be materially adversely affected.
Additionally, the introduction of new services may require us to comply with additional, yet undetermined, laws and regulations. Compliance may require obtaining appropriate licenses or certificates, increasing our security measures and expending additional resources to monitor developments in applicable rules and ensure compliance. The failure to adequately comply with these future laws and regulations may delay or possibly prevent some of our products or services from being offered to members and clients, or their members and patients, which could have a material adverse effect on our business, financial condition and results of operations.
36
Table of Contents
We are dependent on our relationships with affiliated professional entities, which we do not own, to provide physician and other professional services, and our business, financial condition and our ability to operate in certain jurisdictions would be adversely affected if those relationships were disrupted or if our arrangements with our providers or clients are found to violate state laws prohibiting the corporate practice of medicine or fee splitting.
We are in the process of transitioning to a structure where we will enter into various agreements with a Texas professional association entity, TPN, which in turn will contract with our affiliated professional entities and physicians, therapists, and other licensed professionals for clinical and professional services provided to our members. Once this structure is implemented, there is a risk that U.S. state authorities in some jurisdictions may find that these contractual relationships with professional entities, physicians and other healthcare providers providing telehealth and teletherapy violate laws prohibiting the corporate practice of medicine and professional fee splitting. These laws generally prohibit the practice of medicine by lay persons or entities and prohibit us from employing physicians and certain licensed professionals, directing the clinical practice of physicians and certain licensed professionals, holding an ownership interest in an entity that employs physicians and certain licensed professionals or from engaging in certain financial arrangements, such as splitting professional fees with physicians and certain licensed professionals. The laws are intended to prevent unlicensed persons or entities from interfering with or inappropriately influencing a healthcare provider’s professional judgment. The extent to which each state considers particular actions or contractual relationships to constitute improper influence of professional judgment varies across the states and is subject to change and to evolving interpretations by state boards of medicine and professional counselors and therapists, and state attorneys general, among others. As such, we must monitor our compliance with applicable laws in every jurisdiction in which we operate on an ongoing basis and we cannot guarantee that subsequent interpretation of the corporate practice of medicine or fee splitting laws will not circumscribe our business operations.
TPN will contract with therapists and other licensed professionals or enter into agreements with our affiliated professional entities, physicians, therapists and other licensed professionals for the clinical and professional services provided to our members. We do not own TPN or the professional entities with which it will contract. TPN is 100% owned by an independent Texas-licensed physician, and the other professional entities will be owned by physicians qualified to own such professional entities in the respective states. Once fully implemented, we expect that these relationships will continue, however, we cannot guarantee that they will. A material change in our relationship with TPN or among TPN and the contracted professional entities, whether resulting from a dispute among the entities, a change in government regulation, or the loss of these affiliations, could impair our ability to provide services to members as we intend under the transitioned structure and could have a material adverse effect on our business, financial condition, and results of operations.
State corporate practice of medicine doctrines also often impose penalties on physicians themselves for aiding the corporate practice of medicine, which could discourage physicians from participating in our network of providers. Due to the prevalence of the corporate practice of medicine doctrine, including in states where we conduct our business, we are in the process of finalizing certain agreements with TPN. One such agreement is a management services agreement with TPN, pursuant to which TPN reserves exclusive control and responsibility for all aspects of the practice of medicine and the delivery of medical services and we provide non-clinical management and administrative services in exchange for a management fee. The other professional entities, physicians, therapists and other licensed professionals who will provide clinical and professional services to our members through contracts with TPN will also retain exclusive control and responsibility for all aspects of medical services provided to our members. Although we seek to substantially comply with applicable state prohibitions on the corporate practice of medicine and fee splitting, state officials who administer these laws or other third parties may successfully challenge our organization and contractual arrangements with our providers once implemented. If such a claim were successful, we could be subject to civil and criminal penalties and could be required to restructure or terminate the applicable contractual arrangements. A determination that these arrangements violate state statutes, or our inability to successfully restructure our relationships with our providers to comply with these statutes, could eliminate clients located in certain states from the market for our services. Furthermore, the arrangements we are in the process of finalizing or will enter into to comply with state corporate practice of medicine doctrines and fee splitting laws could subject us to additional scrutiny by federal and state regulatory bodies regarding federal and state fraud and abuse laws. Any scrutiny, investigation, adverse determination or litigation with regard to our arrangements with TPN and our affiliated professional entities could have a material adverse effect on our business, financial condition, and results of operations.
The impact on us of recent healthcare legislation and other changes in the healthcare industry and in healthcare spending is currently unknown, but may adversely affect our business, financial condition and results of operations.
The impact on us of healthcare reform legislation and other changes in the healthcare industry and in healthcare spending is currently unknown, but may adversely affect our business, financial condition and results of operations. Our revenue is dependent on the healthcare industry and could be affected by changes in healthcare spending, reimbursement and policy. The healthcare
37
Table of Contents
industry is subject to changing political, regulatory and other influences. The ACA made major changes in how healthcare is delivered and reimbursed, and it increased access to health insurance benefits to the uninsured and underinsured population of the United States.
Since its enactment, there have been judicial and Congressional challenges to certain aspects of the ACA. For example, the Tax Cuts and Jobs Act of 2017 was enacted, which includes a provision repealing, effective January 1, 2019, the tax-based shared responsibility payment imposed by the ACA on certain individuals who fail to maintain qualifying health coverage for all or part of a year that is commonly referred to as the “individual mandate.” Since the enactment of the Tax Cuts and Jobs Act of 2017, there have been additional amendments to certain provisions of the ACA. President Joe Biden and Congress may consider other legislation to change elements of the ACA. In December 2019, a federal appeals court held that the individual mandate portion of the ACA was unconstitutional and left open the question whether the remaining provisions of the ACA would be valid without the individual mandate. On June 17, 2021, the U.S. Supreme Court dismissed a case in Texas challenging the ACA without specifically ruling on the constitutionality of the ACA. Prior to the Supreme Court’s decision, President Biden issued an executive order to initiate a special enrollment period from February 15, 2021 through August 15, 2021 for purposes of obtaining health insurance coverage through the ACA marketplace. The executive order also instructed certain governmental agencies to review and reconsider their existing policies and rules that limit access to healthcare, including among others, reexamining Medicaid demonstration projects and waiver programs that include work requirements, and policies that create unnecessary barriers to obtaining access to health insurance coverage through Medicaid or the ACA. We continue to evaluate the effect that the ACA and its possible modification or repeal and replacement has on our business. It is uncertain the extent to which any such changes may impact our business or financial condition.
Other legislative changes have been proposed and adopted since the ACA was enacted. These changes include aggregate reductions to Medicare payments to providers of up to 2% per fiscal year pursuant to the Budget Control Act of 2011 and subsequent laws, which began in 2013 and will remain in effect through 2030, with the exception of a temporary suspension from May 1, 2020 through March 31, 2022, unless additional Congressional action is taken. In January 2013, the American Taxpayer Relief Act of 2012 was signed into law, which, among other things, further reduced Medicare payments to several types of providers, including hospitals, imaging centers and cancer treatment centers, and increased the statute of limitations period for the government to recover overpayments to providers from three to five years. New laws may result in additional reductions in Medicare and other healthcare funding, which may materially adversely affect consumer demand and affordability for our products and services and, accordingly, the results of our financial operations. Additional changes that may affect our business include the expansion of new programs such as Medicare payment for performance initiatives for physicians under the Medicare Access and CHIP Reauthorization Act of 2015 (MACRA) which first affected physician payment in 2019. At this time, it is unclear how the introduction of the Medicare quality payment program will impact overall physician reimbursement.
In addition, in 2022, the No Surprises Act went into effect to prevent surprise medical bills to non-federal healthcare program patients. For patients who receive health coverage through their employer, the Marketplace, or an individual health insurance plan, healthcare providers, including psychiatrists and psychologists, are required to give notice explaining applicable billing protections. In addition, in the outpatient setting, beginning January 1, 2022 providers are required to give new and established patients who are uninsured or self-pay a good faith estimate of predicted costs for the services that they provide.
Such changes in the regulatory environment may also result in changes to our payer mix that may affect our operations and revenue. In addition, certain provisions of the ACA authorize voluntary demonstration projects, which include the development of bundling payments for acute, inpatient hospital services, physician services and post-acute services for episodes of hospital care. Further, the ACA may adversely affect payers by increasing medical costs generally, which could have an effect on the industry and potentially impact our business and revenue as payers seek to offset these increases by reducing costs in other areas. Certain of these provisions are still being implemented and the full impact of these changes on us cannot be determined at this time.
Uncertainty regarding future amendments to the ACA as well as new legislative proposals to reform healthcare and government insurance programs, along with the trend toward managed healthcare in the United States, could result in reduced demand and prices for our services. We expect that additional state and federal healthcare reform measures will be adopted in the future, any of which could limit the amounts that federal and state governments and other third party payers will pay for healthcare products and services, which could adversely affect our business, financial condition and results of operations.
38
Table of Contents
We conduct business in a heavily regulated industry and if we fail to comply with these laws and government regulations, we could incur penalties or be required to make significant changes to our operations or experience adverse publicity, which could have a material adverse effect on our business, financial condition, and results of operations.
Although our services are not currently reimbursed by government healthcare programs such as Medicare or Medicaid, any future reimbursement from federal and/or state healthcare programs could expose our business to broadly applicable fraud and abuse laws and other healthcare laws and regulations that would regulate the business. The U.S. healthcare industry is heavily regulated and closely scrutinized by federal and state governments. Comprehensive statutes and regulations govern the manner in which we and our affiliated professional entities may provide and bill for services and collect reimbursement from governmental programs and private payers, our contractual relationships with TPN and its corresponding relationship with its contracted providers, vendors and clients, our marketing activities and other aspects of our operations. Applicable and potentially applicable U.S. federal and state healthcare laws and regulations include, but are not limited, to the following:
●
the federal physician self-referral law, commonly referred to as the Stark Law, that, unless one of the statutory or regulatory exceptions apply, prohibits physicians from referring Medicare or Medicaid patients to an entity for the provision of certain “designated health services” if the physician or a member of such physician’s immediate family has a direct or indirect financial relationship (including an ownership interest or a compensation arrangement) with the entity, and prohibit the entity from billing Medicare or Medicaid for such designated health services. Sanctions for violating the Stark Law include denial of payment, civil monetary penalties of up to $26,125 per claim submitted and exclusion from the federal health care programs. Failure to refund amounts received as a result of a prohibited referral on a timely basis may constitute a false or fraudulent claim and may result in civil penalties and additional penalties under the FCA. The statute also provides for a penalty of up to $174,172 for a circumvention scheme;
●
the federal Anti-Kickback Statute that prohibits the knowing and willful offer, payment, solicitation or receipt of any bribe, kickback, rebate or other remuneration for referring an individual, in return for ordering, leasing, purchasing or recommending or arranging for or to induce the referral of an individual or the ordering, purchasing or leasing of items or services covered, in whole or in part, by any federal healthcare program, such as Medicare and Medicaid. Remuneration has been interpreted broadly to be anything of value, and could include compensation, discounts, or free marketing services. A person or entity does not need to have actual knowledge of the statute or specific intent to violate it to have committed a violation. In addition, the government may assert that a claim including items or services resulting from a violation of the federal Anti-Kickback Statute constitutes a false or fraudulent claim for purposes of the False Claims Act. Violations of the federal Anti-Kickback Statute may result in civil monetary penalties up to $105,563 for each violation, plus up to three times the remuneration involved. Civil penalties for such conduct can further be assessed under the federal False Claims Act. Violations can also result in criminal penalties, including criminal fines of up to $100,000 and imprisonment of up to 10 years. Similarly, violations can result in exclusion from participation in government healthcare programs, including Medicare and Medicaid;
●
the criminal healthcare fraud provisions of the federal Health Insurance Portability and Accountability Act of 1996, as amended by the Health Information Technology for Economic and Clinical Health Act (“HITECH”), and their implementing regulations, which we collectively refer to as HIPAA, and related rules that prohibit knowingly and willfully executing a scheme or artifice to defraud any healthcare benefit program or falsifying, concealing or covering up a material fact or making any material false, fictitious or fraudulent statement in connection with the delivery of or payment for healthcare benefits, items or services. Similar to the federal Anti-Kickback Statute, a person or entity does not need to have actual knowledge of the statute or specific intent to violate it to have committed a violation;
●
HIPAA, which also imposes certain regulatory and contractual requirements regarding the privacy, security and transmission of PHI;
●
the federal False Claims Act that imposes civil and criminal liability, including treble damages and mandatory minimum penalties of $11,803 to $23,607 per false claim or statement, on individuals or entities that knowingly submit false or fraudulent claims for payment to the government or knowingly making, or causing to be made, a false statement in order to have a false claim paid, including qui tam or whistleblower suits. A claim including items or services resulting from a violation of the federal Anti-Kickback Statute constitutes a false or fraudulent claim for purposes of the False Claims Act;
●
the federal Civil Monetary Law prohibits, among other things, the offering or transfer of remuneration to a Medicare or state healthcare program beneficiary if the person knows or should know it is likely to influence the beneficiary’s selection of a particular provider, practitioner, or supplier of services reimbursable by Medicare or a state healthcare program, unless an exception applies;
39
Table of Contents
●
similar state law provisions pertaining to Anti-Kickback, self-referral and false claims issues, some of which may apply to items or services reimbursed by any third party payer, including commercial insurers or services paid out-of-pocket by patients;
●
state laws that prohibit general business corporations, such as us, from practicing medicine, controlling physicians’ medical decisions or engaging in some practices such as splitting fees with physicians;
●
the Federal Trade Commission Act and federal and state consumer protection, advertisement and unfair competition laws, which broadly regulate marketplace activities and activities that could potentially harm consumers, including information practices;
●
laws that regulate debt collection practices as applied to our debt collection practices;
●
a provision of the Social Security Act that imposes criminal penalties on healthcare providers who fail to disclose or refund known overpayments; and
●
federal and state laws and policies that require healthcare providers to maintain licensure, certification or accreditation to provide physician and other professional services, to enroll and participate in the Medicare and Medicaid programs, to report certain changes in their operations to the agencies that administer these programs, as well as state insurance laws.
Because of the breadth of these laws and the need to fit certain activities within one of the statutory exceptions and safe harbors available, it is possible that some of our business activities could be subject to challenge under one or more of such laws. Achieving and sustaining compliance with these laws may prove costly. Failure to comply with these laws and other laws can result in civil and criminal penalties such as fines, damages, overpayment recoupment, loss of enrollment status and, if in the future we provide services reimbursable by government healthcare programs, exclusion from the Medicare and Medicaid programs. The risk of our being found in violation of these laws and regulations is increased by the fact that many of them have not been fully interpreted by the regulatory authorities or the courts, and their provisions are sometimes open to a variety of interpretations. Our failure to accurately anticipate the application of these laws and regulations to our business or any other failure to comply with regulatory requirements could create liability for us and negatively affect our business. Any action against us for violation of these laws or regulations, even if we successfully defend against it, could cause us to incur significant legal expenses, divert our management’s attention from the operation of our business and result in adverse publicity.
The laws, regulations and standards governing the provision of healthcare services may change significantly in the future. We cannot assure you that any new or changed healthcare laws, regulations or standards will not materially adversely affect our business. We cannot assure you that a review of our business by judicial, law enforcement, regulatory or accreditation authorities will not result in a determination that could adversely affect our operations.
Our use and disclosure of personal information, including PHI, personal data, and other health information, is subject to state, federal or other privacy and security regulations, and our failure to comply with those regulations or to adequately secure the information we hold could result in significant liability or reputational harm and, in turn, a material adverse effect on our client base and member bases and revenue.
The privacy and security of personal information stored, maintained, received or transmitted electronically is an enforcement priority in the United States and internationally. While we strive to comply with all applicable privacy and security laws and regulations, as well as our own posted privacy policies, legal standards for privacy, including but not limited to “unfairness” and “deception,” as enforced by the FTC and state attorneys general, any failure or perceived failure to comply with such requirements may result in proceedings or actions against us by government entities or private parties, or could cause us to lose clients or members, any of which could have a material adverse effect on our business. Recently, there has been an increase in public awareness of privacy issues in the wake of revelations about the activities of various government agencies and in the number of private privacy-related lawsuits filed against companies. Any allegations about our practices with regard to the collection, use, disclosure, or security of personal information or other privacy-related matters, even if unfounded and even if we are in compliance with applicable laws, could damage our reputation and harm our business.
In the United States, numerous federal and state laws and regulations govern collection, storage, dissemination, use, retention, transfer, disposal, security and confidentiality of personal information, including HIPAA; U.S. state privacy, security and breach notification and healthcare information laws; the California Consumer Protection Act (“CCPA”); and other data protection laws.
HIPAA establishes a set of basic national privacy and security standards for the protection of PHI, to covered entities, including certain types of health care providers and their service providers that access PHI, known as business associates. When acting as a service provider to licensed therapists or employee assistance programs (group health plans), we are considered a business
40
Table of Contents
associate under HIPAA. In some instances we may be considered a covered entity under HIPAA where our own employees are providing direct therapeutic care. As such, HIPAA requires us to maintain policies and procedures governing PHI that is used or disclosed, and to implement administrative, physical and technical safeguards to protect PHI, including PHI maintained, used and disclosed in electronic form. These safeguards include employee training, identifying business associates (and subcontractor business associates) with whom we need to enter into HIPAA-compliant contractual arrangements and various other measures. Ongoing implementation and oversight of these measures involves significant time, effort and expense.
HIPAA also implemented the use of standard transaction code sets and standard identifiers that covered entities must use when submitting or receiving certain electronic healthcare transactions, including activities associated with the billing and collection of healthcare claims.
HIPAA also requires that patients be notified of any unauthorized acquisition, access, use or disclosure of their unsecured PHI that compromises the privacy or security of such information, with certain exceptions related to unintentional or inadvertent use or disclosure by employees or authorized individuals. HIPAA specifies that such notifications must be made “without unreasonable delay and in no case later than 60 calendar days after discovery of the breach.” If a breach affects 500 patients or more, it must be reported to the U.S. Department of Health and Human Services Office (“HHS”) without unreasonable delay, and HHS will post the name of the breaching entity on its public web site. Breaches affecting 500 patients or more in the same state or jurisdiction must also be reported to the local media. If a breach involves fewer than 500 people, the covered entity must record it in a log and notify HHS at least annually.
Entities that are found to be in violation of HIPAA as the result of a breach of unsecured PHI or following a complaint about privacy practices or an audit by HHS, may be subject to significant civil, criminal and administrative fines and penalties and/or additional reporting and oversight obligations if required to enter into a resolution agreement and corrective action plan with HHS to settle allegations of HIPAA non-compliance. HIPAA also authorizes state attorneys general to file suit on behalf of their residents. Courts may award damages, costs and attorneys’ fees related to violations of HIPAA in such cases. While HIPAA does not create a private right of action allowing individuals to sue us in civil court for violations of HIPAA, its standards have been used as the basis for duty of care in state civil suits such as those for negligence or recklessness in the misuse or breach of PHI. Any such penalties or lawsuits could harm our business, financial condition, results of operations and prospects.
In addition to HIPAA, the U.S. federal government and various states and governmental agencies have adopted or are considering adopting various laws, regulations and standards regarding the collection, use, retention, security, disclosure, transfer and other processing of sensitive and personal information, to which we are or may become subject. For example, California implemented the California Consumer Privacy Act, or CCPA, which came into effect in 2020, and to which we are subject. The CCPA imposes obligations and restrictions on businesses regarding their collection, use, processing, retaining and sharing of personal information and provides new and enhanced data privacy rights to California residents. Specifically, the CCPA mandates that covered companies provide new disclosures to California consumers and afford such consumers new data privacy rights that include, among other things, the right to request a copy from a covered company of the personal information collected about them, the right to request deletion of such personal information, and the right to request to opt-out of certain sales of such personal information. The CCPA provides for civil penalties for violations, which could result in statutory penalties of up to $2,500 per violation, or up to $7,500 per violation if the violation is intentional. The CCPA also provides a private right of action for certain data breaches that result in the loss of personal information. This private right of action may increase the likelihood of, and risks associated with, data breach litigation. Protected health information that is subject to HIPAA is excluded from the CCPA; however, information we hold about individual residents of California that is not subject to HIPAA would be subject to the CCPA. Furthermore, California voters approved the California Privacy Rights Act (“CPRA”) in November 2020, which will significantly amend and expand the CCPA, including by providing consumers with additional rights with respect to their personal information. The CPRA also creates a new state agency that will be vested with authority to implement and enforce the CCPA and the CPRA. The CPRA will come into effect on January 1, 2023, applying to information collected by businesses on or after January 1, 2022. We expect states to continue to enact legislation similar to the CCPA and CPRA that provides consumers with new privacy rights and increases the privacy and security obligations of entities handling certain personal information of such consumers. Laws similar to the CCPA and CPRA have passed in Virginia and Colorado, and have been proposed in other states and at the federal level, reflecting a trend toward more stringent privacy legislation in the United States.
Moreover, we are subject to certain other state laws such as the California Confidentiality of Medical Information Act, which imposes restrictive requirements regulating the use and disclosure of health information and other personal information. Such laws and regulations are not necessarily preempted by HIPAA, particularly if a state affords greater protection to individuals than HIPAA. Where state laws are more protective, we have to comply with the stricter provisions. Further, in addition to fines and penalties imposed upon violators, some of these state laws, such as the CCPA, also afford private rights of action to individuals who believe their personal information has been misused.
41
Table of Contents
In the aggregate, state-based data privacy and security laws and regulations may impact our business. All of these evolving compliance and operational requirements impose significant costs that are likely to increase over time, may require us to modify our data processing practices and policies, divert resources from other initiatives and projects could restrict the way services involving data are offered and could subject us to additional liabilities, all of which may adversely affect our results of operations, business, and financial condition.
In addition, the interplay of federal and state laws may be subject to varying interpretations by courts and government agencies, creating complex compliance issues for us and our clients and potentially exposing us to additional expense, adverse publicity and liability. Further, as regulatory focus on privacy issues continues to increase and laws and regulations concerning the protection of personal information expand and become more complex, these potential risks to our business could intensify. Changes in laws or regulations associated with the enhanced protection of certain types of sensitive data, such as PHI or personal information, along with increased customer demands for enhanced data security infrastructure, could greatly increase our cost of providing our services, decrease demand for our services, reduce our revenue and/or subject us to additional liabilities.
Furthermore, there are numerous foreign laws, regulations and directives regarding privacy and the collection, storage, transmission, use, processing, disclosure and protection of personal information, the scope of which is continually evolving and subject to differing interpretations. If we provide services to users outside the United States, we may be subject to such laws, regulations, directives and obligations in relation to processing of personal information, and we may be subject to significant consequences, including penalties, fines and contractual liability, for our failure to comply. We are subject to the EU GDPR and the UK data privacy regime consisting primarily of the UK General Data Protection Regulation and the UK Data Protection Act 2018 (the “UK GDPR”) (the EU GDPR and the UK GDPR, collectively the “GDPR”), which impose a strict data protection compliance regime including stringent data protection requirements, such as detailed disclosures about how personal information is collected and processed, enhanced obligations on the processing of sensitive data, including information that relates to mental health, granting rights for data subjects in regard to their personal information (including data access rights, the right to be “forgotten” and the right to data portability), the obligation to notify data protection authorities (and in certain cases, affected individuals) of significant data breaches, complying with the principal of accountability and the obligation to demonstrate compliance through policies, procedures, training and audit, and provides for significant penalties for breach (as detailed below). EU Member States and the UK are also able to legislate separately on sensitive data (i.e. mental health), and we must comply with these local laws where we offer our services.
The GDPR also imposes strict rules on the transfer of personal data out of the EEA and the UK, including to the United States. Recent legal developments in Europe have created complexity and uncertainty regarding transfers of personal from the EEA and the UK to the United States. Most recently, on July 16, 2020, the Court of Justice of the European Union (“CJEU”) invalidated the EU-US Privacy Shield Framework (“Privacy Shield”) under which personal information could be transferred from the EEA to US entities who had self-certified under the Privacy Shield scheme. While the CJEU upheld the adequacy of the standard contractual clauses (a standard form of contract approved by the European Commission as an adequate personal data transfer mechanism, and potential alternative to the Privacy Shield), it made clear that reliance on them alone may not necessarily be sufficient in all circumstances. Use of the standard contractual clauses must now be assessed on a case-by-case basis taking into account the legal regime applicable in the destination country, in particular applicable surveillance laws and rights of individuals and additional measures and/or contractual provisions may need to be put in place, however, the nature of these additional measures is currently uncertain. The CJEU went on to state that if a competent supervisory authority believes that the standard contractual clauses cannot be complied with in the destination country and the required level of protection cannot be secured by other means, such supervisory authority is under an obligation to suspend or prohibit that transfer. The European Commission has published revised standard contractual clauses for data transfers from the EEA: the revised clauses must be used for relevant new data transfers from September 27, 2021; existing standard contractual clauses arrangements must be migrated to the revised clauses by December 27, 2022. We will be required to implement the revised standard contractual clauses within the relevant time frames. The revised standard contractual clauses apply only to the transfer of personal data outside of the EEA and not the UK; the UK’s Information Commissioner’s Office launched a public consultation on its draft revised data transfers mechanisms in August 2021. We are monitoring the outcome of this, and we may be required to implement new or revised documentation and processes in relation to our data transfers subject to the UK GDPR, within the relevant time frames. As supervisory authorities issue further guidance on data export mechanisms, including circumstances where the standard contractual clauses cannot be used, and/or start taking enforcement action, we could suffer additional costs, complaints and/or regulatory investigations or fines, and/or if we are otherwise unable to transfer personal information between and among countries and regions in which we operate, it could affect the manner in which we provide our services, the geographical location or segregation of our relevant systems and operations, and could adversely affect our financial results.
The relationship between the UK and the EU in relation to certain aspects of data protection law, particularly transfers of personal data, remains unclear following the UK’s departure from the EU on January 1, 2021. The European Commission has adopted an
42
Table of Contents
adequacy decision in favor of the UK, enabling data transfers from EU member states to the UK without additional safeguards. However, the UK adequacy decision will automatically expire in June 2025 unless the European Commission re-assesses and renews/ extends that decision, and remains under review by the Commission during this period. In September 2021, the UK government launched a consultation on its proposals for wide-ranging reform of UK data protection laws following Brexit. There is a risk that any material changes which are made to the UK data protection regime could result in the Commission reviewing the UK adequacy decision, and the UK losing its adequacy decision if the Commission deems the UK to no longer provide adequate protection for personal data. The relationship between the UK and the EU in relation to certain aspects of data protection law remains unclear, and it is unclear how UK data protection laws and regulations will develop in the medium to longer term, and how data transfers to and from the UK will be regulated in the long term. These changes will lead to additional costs and increase our overall risk exposure.
Failure to comply with the requirements of the GDPR may result in fines of up to €20,000,000/ £17.5 million or up to 4% of our total worldwide annual revenue for the preceding financial year, whichever is higher. In addition, a breach of the GDPR could result in regulatory investigations, reputational damage, orders to cease/ change our processing of our data, enforcement notices, and/ or assessment notices (for a compulsory audit). We may also face civil claims including representative actions and other class action type litigation (where individuals have suffered harm), potentially amounting to significant compensation or damages liabilities, as well as associated costs, diversion of internal resources, and reputational harm.
We also publish statements to our clients and members that describe how we handle and protect personal information. If federal or state regulatory authorities or private litigants consider any portion of these statements to be inaccurate, incomplete, or not fully implemented, we may be subject to claims of deceptive practices or other violation of law, which could lead to significant liabilities and consequences, including, without limitation, costs of responding to investigations, defending against litigation, settling claims and complying with regulatory or court orders.
Furthermore, any failure, or perceived failure, by us to comply with or make effective modifications to our policies, or to comply with any federal, state, or international privacy, data-retention or data-protection-related laws, regulations, orders or industry self-regulatory principles could result in proceedings or actions against us by governmental entities or others, a loss of client and member confidence, damage to our brand and reputation, and a loss of clients and/or members, any of which could have an adverse effect on our business.
Because of the breadth of these laws and the narrowness of their exceptions and safe harbors, it is possible that our business activities can be subject to challenge under one or more of such laws. The applicability, scope and enforcement of each of these laws is uncertain and subject to rapid change in the current environment of healthcare reform. Federal, state and foreign enforcement bodies have recently increased their scrutiny of interactions between healthcare companies and healthcare providers and of processing of health data generally, which has led to a number of investigations, prosecutions, convictions and settlements in the healthcare industry. Any such investigations, prosecutions, convictions or settlements could result in significant financial penalties, damage to our brand and reputation, and a loss of clients and/or members, any of which could have an adverse effect on our business.
In addition, any significant change to applicable laws, regulations or industry practices regarding the collection, use, retention, security or disclosure of our users’ personal information content, or regarding the manner in which the express or implied consent of users for the collection, use, retention or disclosure of such content is obtained, could increase our costs and require us to modify our services and features, possibly in a material manner, which we may be unable to complete and may limit our ability to store and process users' personal information data or develop new services and features. Any of the foregoing could harm our competitive position, business, financial condition, results of operations and prospects.
Security breaches, loss of data and other disruptions could compromise personal information, including sensitive information, related to our business or prevent us from accessing critical information and expose us to liability, which could adversely affect our business and our reputation.
Because of the extreme sensitivity of the information which we receive, store and transmit on behalf of therapists, clients, and others, the security features of our technology platform are very important. Information security risks have generally increased in recent years because of the proliferation of new technologies and the increased sophistication and activities of perpetrators of cyber-attacks. Hackers and data thieves are increasingly sophisticated and operating large-scale and complex automated attacks.
In particular, ransomware attacks, including those from organized criminal threat actors, nation-states, and nation-state supported actors, are becoming increasingly prevalent and severe, and can lead to significant interruptions in our operations, loss of data and income, reputational loss, diversion of funds, and may result in fines, litigation and unwanted media attention. As cyber
43
Table of Contents
threats continue to evolve, we may be required to expend additional resources to further enhance our information security measures, develop additional protocols and/or to investigate and remediate any information security vulnerabilities.
If our security measures, some of which are managed by third parties, are breached or fail, unauthorized persons may be able to obtain access to sensitive client and member data, including personal information and PHI. As a result, our reputation could be severely damaged, adversely affecting client and member confidence. Members may curtail their use of or stop using our services or our client base could decrease, which would cause our business to suffer. In addition, we could face litigation, damages for contract breach, penalties and regulatory actions for violation of HIPAA and other applicable laws or regulations and significant costs for remediation, notification to individuals and for measures to prevent future occurrences. Any potential security breach could also result in increased costs associated with liability for stolen assets or information, repairing system damage that may have been caused by such breaches, incentives offered to clients or other business partners in an effort to maintain our business relationships after a breach and implementing measures to prevent future occurrences, including organizational changes, deploying additional personnel and protection technologies, training employees and engaging third-party experts and consultants. While we maintain insurance covering certain security and privacy damages and claim expenses, we cannot be certain that our insurance coverage will be adequate for data security liabilities actually incurred, will cover any indemnification claims against us relating to any incident, will continue to be available to us on economically reasonable terms, or at all, or that any insurer will not deny coverage as to any future claim. The successful assertion of one or more large claims against us that exceed available insurance coverage, or the occurrence of changes in our insurance policies, including premium increases or the imposition of large deductible or co-insurance requirements, could adversely affect our reputation, business, financial condition and results of operations.
We outsource important aspects of the storage and transmission of client and member information, and thus rely on third parties to manage functions that have material cyber-security risks. We attempt to address these risks by requiring outsourcing subcontractors who handle client and member information to sign agreements contractually requiring those subcontractors to adequately safeguard personal information and PHI to the same extent that applies to us and in some cases by requiring such outsourcing subcontractors to undergo third-party security examinations. In addition, we periodically hire third-party security experts to assess and test our security posture. However, we cannot assure you that these contractual measures and other safeguards will adequately protect us from the risks associated with the storage and transmission of client and members’ proprietary and protected health information.
Due to applicable laws and regulations or contractual obligations, we may be held responsible for any information security failure or cyber-attack attributed to our vendors as they relate to the information we share with them. In addition, because we do not control our vendors and our ability to monitor their data security is limited, we cannot ensure the security measures they take will be sufficient to protect confidential, proprietary, or sensitive data, including personal data. We are at risk of a cyber-attack involving a vendor or other third party, which could result in a breakdown of such third party’s data protection processes or the cyber-attackers gaining access to our information systems or data through the third party. Regardless of whether an actual or perceived cyber-attack is attributable to us or our vendors, such an incident could, among other things, result in improper disclosure of information, harm our reputation and brand, reduce the demand for our products and services, lead to loss of client confidence in the effectiveness of our security measures, disrupt normal business operations or result in our systems or products and services being unavailable. In addition, it may require us to spend material resources to investigate or correct the breach and to prevent future security breaches and incidents, expose us to uninsured liability, increase our risk of regulatory scrutiny, expose us to legal liabilities, including litigation, regulatory enforcement, indemnity obligations or damages for contract breach, divert the attention of management from the operation of our business and cause us to incur significant costs, any of which could affect our financial condition, operating results and our reputation. Moreover, there could be public announcements regarding any such incidents and any steps we take to respond to or remediate such incidents, and if securities analysts or investors perceive these announcements to be negative, it could, among other things, have a substantial adverse effect on the price of our common stock. In addition, our remediation efforts may not be successful and any failure related to these activities could result in significant liability and/or have a material adverse effect on our business, reputation and financial condition.
We may be exposed to compliance obligations and risks under anti-corruption, export controls and economic sanctions laws and regulations of the United States and applicable non-U.S. jurisdictions, and any instances of noncompliance could have a material adverse effect on our reputation and the results of our operations.
Expansion of our operations into markets outside the United States is one of our strategies for the future growth of our business. In connection with those plans, we may be or may become subject to compliance obligations under anti-corruption laws and regulations imposed by governmental authorities around the world with jurisdiction over our operations, which may include the FCPA, as well as the anti-corruption laws and regulations of other jurisdictions where we conduct business. These laws and regulations apply to companies, directors, officers, employees and agents, and may impact the way we conduct our operations,
44
Table of Contents
trade practices, investment decisions and partnering activities. Where they apply, the FCPA and the U.K. Bribery Act of 2010 (the “UK Bribery Act”) prohibit us and our officers, directors and employees, as well as any third parties acting on our behalf, including joint venture partners and agents, from corruptly offering, promising, authorizing or providing anything of value to public officials or other persons for the purpose of influencing official decisions or obtaining or retaining business or otherwise obtaining an improper business benefit. As part of our business, we may deal with non-U.S. governments and state-owned business enterprises, the employees and representatives of which may be considered foreign officials for purposes of the FCPA.
In connection with our planned expansion of our international operations, we will become subject to the jurisdiction of various governments and regulatory agencies around the world, which may bring our personnel and agents into contact with public officials responsible for issuing or renewing permits, licenses or approvals or for enforcing other governmental regulations. Our business also will need to be conducted in compliance with applicable export controls and economic sanctions laws and regulations, including those of the U.S. government, the governments of other countries in which we operate or plan to operate in or conduct business and various multilateral organizations. Such laws and regulations include, without limitation, those administered and enforced by the U.S. Department of the Treasury’s Office of Foreign Assets Control (“OFAC”), the U.S. Department of State, the U.S. Department of Commerce, the United Nations Security Council and other relevant sanctions authorities. Our provision of services to persons located outside the United States may be subject to certain regulatory prohibitions, restrictions or other requirements, including certain licensing or reporting requirements pursuant to export controls and economic sanctions laws and regulations. Our provision of services outside of the United States exposes us to the risk of violating, or being accused of violating, anti-corruption, exports controls and economic sanctions laws and regulations. Though we have implemented an anti-corruption policy, as well as formal training and monitoring programs, we cannot ensure that our policies and procedures will always protect us from risks associated with any unlawful acts carried out by our employees or agents. Violations of anti-corruption, exports controls or economic sanctions laws and regulations may expose us to reputational harm, as well as significant civil and criminal penalties, including monetary fines, imprisonment, disgorgement of profits, injunctions, suspension or debarment from government contracts, and other remedial measures. Investigations of alleged violations can be expensive and disruptive to our operations. Violations could have a material adverse effect on our reputation, business, financial condition and results of operations.
RISKS RELATED TO OUR INTELLECTUAL PROPERTY
Any failure to protect, enforce or defend our intellectual property rights could impair our ability to protect our technology and our brand.
Our success depends in part on our ability to maintain, protect and enforce our intellectual property and other proprietary rights. We rely upon a combination of trademark, patent and trade secret laws, as well as license and access agreements and other contractual provisions, to protect our intellectual property rights. These laws, procedures and agreements provide only limited protection and any of our intellectual property rights may be challenged, invalidated, circumvented, infringed, diluted or misappropriated.