Loading...
Loading...
Chat is set up on each filing report page.
Ask about this filing, its industry, or sector trends.
AI responses are generated from filing and peer context and may contain errors.
Item 1A. Risk Factors
Except as set forth below or as subsequently disclosed in our periodic reports, there have been no material changes in our risk factors from those disclosed in Part I, Item 1A of the 2025 Form 10-K. In the course of conducting our business operations, we are exposed to a variety of recurring and new risks, any of which have affected or could materially adversely affect our business, financial condition, and results of operations. The market price of our Class A common stock could decline, possibly significantly or permanently, if one or more of these risks and uncertainties occurs. Any factor described in this report or in any of our other SEC filings could by itself, or together with other factors, adversely affect our financial results and condition. For a discussion of risk factors that could adversely affect our financial results and condition, and the value of, and return on, an investment in the Company, please see the "Item 1A. Risk Factors" section included in the 2025 Form 10-K, as wupdated by the risk factor set forth below, as well as the factors identified under "Cautionary Note Regarding Forward-Looking Statements" at the beginning of Part I, Item 1 of this Form 10-Q and as may be updated in subsequent filings with the SEC.
Our failure to protect our sites, networks, and systems against security breaches, or otherwise to protect our confidential or health information or the confidential or health information of our members, providers, or other third parties, could damage our reputation and brands, and substantially harm our business and results of operations.
Breaches of our security measures or those of our third-party service providers or other cybersecurity incidents could result in unauthorized access to our sites, networks, systems and accounts; unauthorized access to, and misappropriation of, individuals' personally identifiable information (PII), protected health information (PHI) or other confidential or proprietary information of ourselves, our members or other third parties; viruses, worms, spyware or other malware being served from our platform, networks or systems; deletion or modification of content or the display of unauthorized content on our platform; the loss of access to critical data or systems through ransomware, destructive attacks or other means; and business delays, service or system disruptions or denials of service. Healthcare organizations are frequent targets of increasingly sophisticated cyberattacks, including phishing, social engineering, ransomware, credential compromise and other attempts to gain unauthorized access to systems and sensitive information. Such attacks are increasing in their frequency, levels of persistence, sophistication and intensity, and they are being conducted by increasingly sophisticated and organized groups and individuals with a wide range of motives and expertise, including through the use of artificial intelligence and other technologies (including generative AI models). Threat actors are using these technologies to create sophisticated new attack methods that are increasingly automated, targeted, coordinated and difficult to defend against. This may increase the effectiveness of social engineering and other attacks and make detection more difficult. Such attacks may remain undetected for an extended period of time.
If any of these breaches of security should occur, whether involving our systems or those of our vendors, business partners or other third parties, we cannot guarantee that recovery protocols and backup systems will be sufficient to prevent data loss or the interruption, disruption or malfunction of our operations, including with respect to telehealth services. As a result, we could face regulatory investigations or enforcement actions, litigation, indemnification obligations, contractual disputes, and other liabilities. We could also incur costs relating to breach remediation, deployment of additional personnel and protection technologies, and response to governmental investigations and media inquiries and coverage; be required to engage third-party experts and consultants; and face litigation, regulatory action, notification obligations, operational disruptions, and other potential liabilities. Our reputation and brand could be damaged, and our business may suffer. We could face loss of business, reputational harm, reduced member, provider or broker confidence and be required to expend significant capital and other resources to alleviate problems caused by such breaches. Actual or anticipated security breaches or attacks may cause us to incur increasing costs, including costs to respond to and remediate cybersecurity incidents, deploy additional personnel and protection technologies, train employees, engage third-party experts and consultants, enhance our security measures and comply with applicable legal and regulatory requirements.
37
For example, as previously disclosed, on July 4, 2026, we identified unauthorized access to certain of our information systems resulting from a social engineering attack involving three non-managerial employee accounts. Based on our investigation to date, the affected accounts were associated with member visit-scheduling and broker-facing sales functions and had access to certain PII and PHI, but did not have access to our corporate financial or claims systems. Although we believe our prompt response successfully contained and terminated this unauthorized access and, based on information currently available, we do not believe this incident has had, or is reasonably likely to have, a material impact on our business, financial condition or results of operations, our investigation remains ongoing and the ultimate scope, nature and extent of any unauthorized access to or acquisition of data has not been fully determined. For a discussion of litigation arising from this incident, see Note 12 Commitments and Contingencies Legal Actions in the accompanying notes to the condensed consolidated financial statements included in this Form 10-Q.
Moreover, certain of our third-party service providers provide technology-related services and/or store or have access to our data and may not have effective controls, processes or practices to protect our information from loss, unauthorized disclosure, unauthorized use or misappropriation, cyberattacks or other data security incidents. A vulnerability in such service providers software or systems, a failure in their safeguards, policies or procedures, or a cyberattack or other data security incident affecting any of these third parties could result in harm to our business. For example, in 2024, one of our vendors, UnitedHealth Groups Change Healthcare, experienced a ransomware attack that compromised certain of our members personal information (including PHI). Although the Change Healthcare incident did not have a material impact on our business, financial condition or results of operations, it illustrates the ongoing and evolving nature of cybersecurity threats facing the Company and its service providers.
While we maintain administrative, technical and physical safeguards designed to protect our systems and information, including employee training, incident response procedures and other security controls, these measures may not be effective in preventing or detecting all cybersecurity incidents or mitigating all related risks. Any compromise could violate applicable privacy, data protection, data security, network and information systems security and other laws, and cause significant legal and financial exposure, adverse publicity and a loss of confidence in our security measures. We devote significant resources to protect against security breaches, and we may need to devote significantly more resources in the future to address problems caused by breaches, including notifying affected subscribers and responding to any resulting litigation, which would divert resources from the growth and expansion of our business. Any future cybersecurity incident could have a material effect on our business, financial condition or results of operations.