Item 1. Business
Item 1. Business
Our Company
i3 Verticals builds, acquires and grows software solutions in the Public Sector and Healthcare vertical markets. Our broad array of enterprise solutions deeply integrate within customers’ operations, which leads to long-term partnerships. Since our founding in 2012, we have compounded cash flow through a combination of organic growth and acquisitions. Our cash flow generation and strong recurring revenue model has positioned us with an ideal financial structure to capitalize on strategic growth opportunities for years to come.
Sale of Merchant Services Business
On September 20, 2024, i3 Verticals, LLC, and i3 Holdings Sub, Inc., a wholly-owned subsidiary of i3 Verticals, LLC (“Corporation Seller,” and collectively with i3 Verticals, LLC, the “Sellers”) completed the transactions (such closing, the “Closing”) contemplated by that certain Securities Purchase Agreement dated as of June 26, 2024 (the “Purchase Agreement”), by and among i3 Verticals, LLC, Corporation Seller, the Company (solely for the purpose of providing a guaranty of the obligations of Sellers as set forth in the Purchase Agreement), Payroc Buyer, LLC (“Buyer”), and Payroc WorldAccess, LLC (solely for the purpose of providing a guaranty of the obligations of Buyer as set forth in the Purchase Agreement), the entry into which Purchase Agreement was previously disclosed in a Current Report on Form 8-K filed by the Company on June 26, 2024. Pursuant to the terms of the Purchase Agreement, the Sellers sold to Buyer the equity interests of certain direct and indirect wholly-owned subsidiaries of Sellers (the “Acquired Entities”) primarily comprising the Company’s merchant services business, including its associated proprietary technology (the “Merchant Services Business”), after giving effect to the contribution of certain assets and the assignment of certain liabilities associated with the Merchant Services Business from i3 Verticals, LLC and certain affiliates to the Acquired Entities pursuant to a contribution agreement which was entered into immediately prior to the Closing. Pursuant to the terms of the Purchase Agreement, Buyer paid to Sellers an aggregate purchase price of approximately $438 million (after giving effect to estimated net working capital, indebtedness and cash adjustments), payable in cash at the Closing, subject to post-closing purchase price adjustments.
Organic Growth in Strategic Vertical Markets
The ability to organically grow revenue over the long term is the result of expanding recurring revenue streams, strategic selection of markets and continued investment in our products.
Approximately 80% of our revenue from continuing operations is considered recurring. We earn the majority of our revenue from software and related services. We also earn revenue from volume and transaction-based fees for payment processing services, all of which is integrated into our software. Our proprietary payment facilitator platform seamlessly integrates into our software solutions, unlocking additional value.
We focus on solutions in the Public Sector and Healthcare vertical and sub-vertical markets because of the following characteristics:
• Technologically underserved markets
• Large and growing total addressable markets
• Fragmented competitive landscape
• Ample opportunity for transaction-based revenues
• Insulation from market cycles
With deep integration into our customers’ operations, we believe that we are well positioned to conceive and build products that meet their growing needs. Ongoing investment into improving existing platforms and strategically creating new platforms and products is an essential part of our long-term strategy.
Ability to Use Acquisitions to Drive Growth
A core component of our growth strategy includes a disciplined approach to acquisitions of companies and technology, evidenced by 50 acquisitions since our inception in 2012. Our management team has significant
8
experience acquiring and integrating vertical market software businesses that complement our existing suite of products and solutions. Acquisitions have extended our product offerings and capabilities, thereby allowing us to enhance our value proposition to our customers. They have also increased our addressable markets. Target businesses are generally founder lead, growing, generating cash flow, and have been in our core vertical markets. Through our proprietary payment facilitator platform we have scale, pricing and expertise in payments. As a result, we often identify targets who lack integrated payment functionality within their solutions or have under-monetized the opportunity. We maintain a strong pipeline of acquisition targets and are constantly evaluating businesses against our acquisition criteria.
Our Segments
As a result of the sale of the Merchant Services Business as described above, our entire former Merchant Services segment and a small portion of the historical Software and Services segment which were included in the Merchant Services Business have been reflected in discontinued operations in the Company's consolidated financial statements. After giving effect to these developments, the Company has two reportable segments, Public Sector and Healthcare, and an Other category. For additional information on our segments, see Note 18 to our consolidated financial statements and “Management's Discussion and Analysis of Financial Condition and Results of Operations.”
Public Sector
We have products and solutions that create an efficient flow of information throughout a variety of public sector entities. We serve customers at both the state and local level and our geographic reach covers most of the United States and some of Canada. Our solutions help our customers provide more responsive and efficient services to their citizens and stakeholders.
There are five sub-verticals within the Public Sector vertical:
• JusticeTech and Public Safety: Product categories include (1) fully integrated digital solutions offering dynamic processes to plan, coordinate, evaluate, record, and provide up to date information within court systems, (2) E-Filing and revenue cycle management solutions for courts, and (4) Solutions for computer aided dispatch, law records management, evidence management, jail management, mobile solutions, and livescan.
• Transportation: Products include comprehensive solutions for driver license, vehicle title and registration and motor carrier compliance for departments of transportation in the United States and Canada.
• Utilities: Product categories include (1) digital customer engagement platform, including web, mobile, chat, and voice options, enables intuitive self-service options for customers to manage their data and accounts, and (2) complete suite of billing and back-office management software solutions and services to enhance enterprise applications, improve customer experience, and increase efficiency of utility operations.
• Enterprise Resource Planning (“ERP”): Product categories include (1) solutions that connect the organization and its data to create a flow of information providing insight across multiple departments, (2) digital land records solutions that boost proficiency and maintain records to enable submission of index information, scanning of document images and secure instantaneous retrieval of information, (3) licensing and permitting solutions that automate every step of the application, renewal and payment process, and (4) digital solutions designed for appraisal information, tax collection management, revenue collection, and Computer Assisted Mass Appraisal.
• Education: Products include (1) comprehensive solutions for school lunch programs, including meal account management, point of sale, menu planning, nutritional analysis, food inventory and free and reduced meal applications and (2) school event solutions, including ticketing and concessions.
We deliver integrated payments with our proprietary payment facilitator platform throughout many of these products. These solutions allow our customers to efficiently process court, tax, registration, utility, school and other payments.
9
Healthcare
Our Healthcare segment is dedicated to delivering integrated solutions across the healthcare ecosystem, catering to providers and payers, with a strong emphasis on enhancing process efficiency and ensuring compliance.
There are two sub-verticals within the Healthcare vertical:
• Provider Software Solutions: Products include our versatile care delivery platform, which encompasses a range of solutions, including EHR, practice management tools, patient engagement applications, and patient payment solutions. These solutions are designed to adapt to the diverse needs of healthcare organizations, from small physician practices to large academic medical institutions and multi-location health systems. By providing flexible and scalable technology solutions, we empower our clients to navigate the evolving landscape of healthcare. Complementing our technology platform, we offer a comprehensive portfolio of revenue cycle management services. These services provide our clients with a full end-to-end experience, covering all aspects of their financial operations. From revenue optimization and billing to claims processing and coding, our services are designed to streamline financial processes and maximize revenue performance for healthcare organizations.
• Payer Software Solutions: Products include (1) tailored solutions for managing compliance requirements, including appeals & grievances and (2) our network management platform assists payers in provider contracting, credentialing, and outreach, enabling them to expand and adapt to changing market dynamics.
Other
The Other category includes corporate overhead expenses, technology resources shared across segments and inter-segment eliminations.
Our Technology
We are committed to agile delivery, scalable platforms, and secure solutions, intended to bring our customers the best possible mission critical software. Our team of highly skilled and experienced technologists is dedicated to implementing software products that cater to the diverse and evolving needs of our customers. We continuously refine and expand our software offerings to stay aligned with the latest industry and current market trends.
Agile Development
Our flexible approach to digital delivery is centered around agility. We prioritize rapid development, continuous improvement, and dynamic responsiveness in our ever-changing environment. This means our customers receive software solutions that evolve with their needs as well as the market. Our product management life cycle ensures our products remain robust and flexible. Product roadmaps drive our investments.
Our development is supported by streamlined back office technology to increase efficiency. This includes consolidated instant messaging, file sharing, and telephony solutions. We have reduced dependency on multiple vendors across the enterprise while creating efficiency and reducing expense. Together, these initiatives support our commitment to operational efficiency and exceptional service delivery.
Scalable Platforms
We understand that scalability is critical to meeting the growing demands of the digital landscape. Our cloud-first strategy drives solutions that are designed to expand seamlessly, empowering our systems to adapt, grow, and thrive without constraints. New development is always cloud-native SaaS solutions.
We are a scaled partner of both Amazon Web Services ("AWS") and Microsoft Azure ("Azure") cloud services. Our AWS cloud consolidation initiative is nearing successful completion, with collocated and on-premises data centers successfully migrated to the cloud and unifying disparate subscriptions into an enterprise account. Our strategic partnerships with multiple cloud providers give us flexibility, as well as capabilities beyond that of many of our competitors.
10
Secure Solutions
Further strengthening our technology infrastructure, we have centralized cybersecurity measures using fully integrated Microsoft tools, including endpoint detection and response, mobile device management, and identity and access management solutions.
Payment Technology
In addition to our broad suite of vertical market software, we have developed a proprietary payment facilitation platform. We have centralized our payment solutions onto our proprietary gateway, providing us excellent scale and pricing with our processing partner. Consolidation of the payments platform also reduces our overall PCI scope and increases margins by lowering expenses.Capabilities include:
• integration with customer business management systems,
• integration with EMV/contactless devices,
• unified reporting for our customers across ACH, card, etc.,
• risk management, and
• PCI-compliant security and extensive reporting tools.
We offer our customers a single point of access through our powerful but simple proprietary core platform. From there we offer a suite of proprietary payment and software solutions spanning brick and mortar locations, web-based and mobile-based payments.
Our payment technology platforms include an unified application programming interface that provides access to ACH processing and payment facilitator merchant processing capabilities. The platform APIs allow access to Europay, Mastercard and Visa (“EMV”) devices using an implementation that shields software providers from the requirements of PCI or payment application data security standard certifications. We also support Paypal and Venmo payments.
Our Sales and Marketing
We utilize our direct sales team to sell our proprietary software and payment technology solutions directly to customers in our vertical markets. Sales teams are organized and coordinated by vertical and sub-vertical market, leading to extensive cross-selling opportunities across our broad array of solutions. Leveraging our vertically focused suite of products and services, we are able to maximize the performance of our employee sales force as we continue to attract new customers.
Our product marketing are delivered through a shared-services model which is coordinated with each vertical market. Marketing is tightly aligned with our sales efforts by providing event coordination, demand-generation resources, physical and electronic marketing campaigns and collateral. Our enterprise marketing function establishes our overall corporate marketing strategy to enhance brand awareness and demand generation. We use a broad variety of traditional and digital marketing mediums to engage prospective customers.
Our Operations
Our operations team is uniquely structured to optimize the experience of our customers. These vertically focused business support teams allow us to establish expertise that delivers a scalable support structure and enables us to align our services with the economic goals of our company. Each operations team is positioned to support the functions of their customer base. Key performance indicators mark their progress toward achieving the goals established by each vertical and sub-vertical. A strong network of shared services, such as marketing, legal, finance and HR, support our vertical and sub-vertical units and ensure they are focused on providing best in-class service to our customers.
11
Our operations team is structured to effectively support the individual needs of our customers. This includes:
• customer onboarding;
• data conversions and migrations;
• software configurations and integrations;
• customer support and retention;
• customer training and activations;
• contract renewals, billing and financial review;
• credit underwriting and risk management;
• payment facilitator processing support; and
• end-user customer support.
Our technical operations team oversees the execution of development, quality control, delivery and support for our vertical software solutions and proprietary payment facilitator platform. Products are developed and tested according to the software development lifecycle, composed of iterative backlog refinement, feature prioritization, development and testing with a dedicated focus on planning and execution. Releases are modeled on continuous deployment and added to the live environment on a routine basis. Each application is built with redundancy to foster resiliency and built to be easily managed during a disaster recovery scenario. Our hosted solutions are managed within dedicated environments within AWS and Azure that align with various compliance standards specific to each industry. This includes, but is not limited to PCI, Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) and National Institute of Standards and Technology ("NIST"), ensuring the protection of all personal and transactional data.
Our Competition
We compete with a variety of vertical market software providers that have different business models, go-to-market strategies and technical capabilities. We believe the most significant competitive factors in our markets are:
1. quality, including the ability of our products and solutions to address the specific needs of our customers;
2. service, including our ability to bring value-added solutions and strong customer support;
3. trust, including a strong reputation for quality service;
4. convenience, such as speed in customer onboarding and approving applications;
Our competitors range from large and well-established companies to smaller, earlier-stage businesses. See “Risk Factors—Risks Related to Our Business and Industry— The vertical market software and payment processing industries are competitive. Such competition could adversely affect the revenue we receive, and as a result, our margins, business, financial condition and results of operations.” in Part I, Item 1A of this Annual Report on Form 10-K.
Human Capital
To facilitate talent attraction and retention, we strive to make i3 Verticals a safe and healthy workplace, with opportunities for our employees to grow and develop in their careers, supported by competitive compensation and benefits programs and opportunities for advancement.
The success of our business is fundamentally connected to the well-being of our people. Accordingly, we provide our eligible employees with access to flexible and convenient medical programs intended to meet their needs and the needs of their families. In addition to standard medical coverage, for our domestic employees, we offer dental and vision coverage, health savings and flexible spending accounts, paid time off, flexible work schedules on a case-by-case basis, employee assistance programs, voluntary short term and long-term disability insurance and term life insurance. For our non-U.S. employees, in addition to standard medical coverage, we offer benefits that are consistent with local practices for similarly situated companies.
We provide competitive compensation and benefits programs to help meet the needs of our employees. In addition to salaries, these programs (which vary across our businesses) include bonus opportunities and, for our
12
domestic employees, a 401(k) Plan. We use targeted stock option grants and restricted stock units ("RSUs") with vesting conditions to facilitate retention of personnel, and we are proud that a large percentage of our workforce owns i3 Verticals shares, RSUs or options to purchase i3 Verticals shares. We believe this dynamic aligns important economic incentives and encourages an entrepreneurial spirit.
We have built a collaborative culture that recognizes and rewards innovation and offers employees a variety of opportunities and experiences. We believe that our culture is critical to our success. As of September 30, 2024, 60% of our employees work in one of our 25 offices and 40% of our employees are fully remote or hybrid. We encourage our employees to take advantage of our flexible work arrangements to meet their individual circumstances. We are an acquisitive company and have regularly added new employees and locations as a result of our acquisition activity. As of November 22, 2024, after giving effect to the disposition of our Merchant Services Business which was completed on September 20, 2024, we had approximately 1,480 employees in 44 states and two countries. No employees are represented by unions. We believe that our employee retention rates are competitive and we think this is a result of strong emphasis on workforce culture in our acquisition process and in our operational decision making.
As of September 30, 2024, after giving effect to the completion of the sale of our Merchant Services Business, the Company's workforce was 54% female and 46% male. In addition, our workforce ethnicity, as of September 30, 2024, was as follows: 62% White, 22% Asian, 8% Black or African American, 4% Hispanic or Latino and 4% Other. Race and gender disclosures are based on information self-reported by employees.
Government Regulation
We operate in an increasingly complex legal and regulatory environment. Our business and the products and services that we offer are subject to a variety of federal, state and local laws and regulations and the rules and standards of the payment networks that we utilize to provide our electronic payment services, as more fully described below.
Dodd-Frank Act
The 2010 Dodd-Frank Wall Street Reform and Consumer Protection Act (the "Dodd-Frank Act") and the related rules and regulations have resulted in significant changes to the regulation of the financial services industry. Changes impacting the electronic payment industry include providing merchants with the ability to set minimum dollar amounts for the acceptance of credit cards and to offer discounts or incentives to entice consumers to pay with cash, checks, debit cards or credit cards, as the merchant prefers. The Durbin Amendment to the Dodd-Frank Act provides that the Federal Reserve regulate interchange fees that certain issuers charge merchants for debit transactions and these fees must be “reasonable and proportional” to the cost incurred by the issuer in authorizing, clearing and settling the transactions. Rules released by the Federal Reserve in July 2011 to implement the Durbin Amendment mandate a cap on debit transaction interchange fees for issuers with assets of $10 billion or greater. Federal Reserve approval of a final rule effective October 1, 2021 permit debit card issuers to receive a fraud-prevention adjustment to the interchange fee standards. New rules effective July, 2023 contain certain prohibitions on payment network exclusivity and merchant routing restrictions of debit card transactions.
The Dodd-Frank Act also created the Consumer Financial Protection Bureau (the "CFPB"), which has assumed responsibility for most federal consumer protection laws of a financial nature, and the Financial Stability Oversight Council, which has the authority to determine whether any non-bank financial company, such as us, should be supervised by the Board of Governors of the Federal Reserve System because it is systemically important to the U.S. financial system. Any new rules or regulations implemented by the CFPB or the Financial Stability Oversight Council or in connection with the Dodd-Frank Act that are applicable to us, or any changes that are adverse to us resulting from litigation brought by third parties challenging such rules and regulations, could increase our cost of doing business or limit permissible activities.
Privacy and Information Security Regulations
We provide services that are subject to privacy laws and regulations of a variety of jurisdictions. Relevant federal privacy laws include the Gramm-Leach-Bliley Act of 1999, which applies directly to a broad range of financial institutions and indirectly, or in some instances directly, to companies that provide services to financial institutions. These laws and regulations restrict the collection, processing, storage, use and disclosure of personal information, require notice to individuals of privacy practices and provide individuals with certain rights to prevent
13
the use and disclosure of certain nonpublic or otherwise legally protected information. These laws also impose requirements for safeguarding and proper destruction of personal information through the issuance of data security standards or guidelines. Our business also may be subject to the Fair Credit Reporting Act and the Fair and Accurate Credit Transactions Act of 2003, which regulate the use and reporting of consumer credit information and impose disclosure requirements on entities who take adverse action based on information obtained from credit reporting agencies.
All fifty states, Puerto Rico, and the U.S. Virgin Islands have enacted data breach notification laws requiring businesses that experience a security breach of their computer databases that contain personal information to notify affected individuals, consumer reporting agencies and governmental agencies. Many states have implemented comprehensive data privacy and security laws. Certain of these laws restrict the ability to collect and utilize certain types of personal information, such as Social Security and driver’s license numbers, impose secure disposal requirements for personal data and contain regulations surrounding data protection and information security. For example, Massachusetts requires any business that processes the personal information of a Massachusetts resident to adopt and implement a written information security program. In addition, states are increasingly legislating data protection requirements for a broader list of personal data and are strengthening protections for students' personal information. Illinois regulates the collection of biometric information under its Biometric Information Privacy Act. Texas and Washington have also passed legislation regulating the collection of biometric information, and additional states have legislation pending regarding the collection of biometric data. Additionally, many states have passed comprehensive consumer privacy laws, that are either currently in effect or are set to become effective in the near term including California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Rhode Island, Oregon, Tennessee, Texas, Utah, and Virginia. These laws require companies that process personal information of certain residents of those states to make disclosures to consumers about data practices, grants consumers specific rights to their data, and allow consumers to opt out of certain data sharing activities, and the California Consumer Privacy Act of 2018 (the “CCPA”), as amended by the California Privacy Rights Act of 2020 (the “CPRA”), creates a private right of action for data breaches.
To the extent we are subject to such legislation, the potential effects on our business are often far-reaching and may require us to modify our data processing practices and policies and to incur substantial costs and expenses in an effort to comply. Such laws often provide for civil penalties or fines for violations. Each privacy law and regulation that applies to us could increase our cost of doing business or limit permissible activities. We are also subject to numerous federal and state laws and regulations related to the privacy and security of health information. See “—Healthcare Regulatory Matters” below.
As an entity that provides services to educational institutions, we are indirectly subject to the Family Educational Rights and Privacy Act ("FERPA") or Protection of Pupil Rights Amendment ("PPRA"), and we may not transfer or otherwise disclose or use any personally identifiable information from a student record to another party other than on a basis and in a manner permitted under the statutes. See “Risk Factors—If we violate the FERPA or PPRA, it could result in a material breach of contract with one or more of our customers in our Education sub-vertical and could harm our reputation. Further, if we disclose student information in violation of FERPA or PPRA, our access to student information could be suspended."
Healthcare Regulatory Matters
Our Healthcare vertical business provides services to healthcare providers who are highly regulated and subject to frequently changing political, legislative, regulatory and other influences. Although some regulatory requirements do not directly apply to our operations, these requirements affect the business of our healthcare customers and the demand for our services.
Failure to satisfy those legal and regulatory requirements, or the adoption of new laws or regulations, could have a significant negative impact on our Healthcare vertical operations and financial condition. U.S. federal, state, local laws and regulations are evolving and can be subject to significant change.
In addition, the application and interpretation of these laws and regulations are often uncertain. These laws are enforced by federal, state and local regulatory agencies in the jurisdictions where we operate, and in some instances also through private civil litigation.
14
Examples of the most significant of these laws include, but are not limited to, the following:
HIPAA Privacy and Security Requirements
There are numerous federal and state laws and regulations related to the privacy and security of health information. In particular, regulations promulgated pursuant to the Health Insurance Portability and Accountability Act of 1996, as amended by the Health Information Technology for Economic Clinical Health Act of 2009 ("HITECH") and other laws (collectively "HIPAA") establish privacy and security standards that limit the use and disclosure of certain individually identifiable health information (known as “protected health information”) and require covered entities, including health plans and most healthcare providers, to implement administrative, physical and technical safeguards to protect the privacy of PHI and ensure the confidentiality, integrity and availability of electronic PHI. Currently, a Notice of Proposed Rulemaking to strengthen the HIPAA security rule is under review by the U.S. Office of Management and Budget and is expected to be published before the end of 2024. Although the specific requirements of this proposed rule have not been published, we would expect the proposed rule to modernize requirements for protecting PHI against healthcare cybersecurity threats, which have dramatically increased over the past few years. In addition, the HIPAA administrative simplification provisions require the use of uniform electronic data transmission standards of healthcare claims and payment transactions submitted or received electronically.
Certain provisions of the security and privacy regulations promulgated pursuant to HIPAA apply to business associates (entities that handle PHI on behalf of covered entities), and business associates are subject to direct liability for violation of these provisions. As a provider of services to entities subject to HIPAA, we are a “business associate” of our customers and must safeguard the PHI we handle. To the extent permitted by applicable regulations and contracts and associated business associate agreements with our customers, we are permitted to use and disclose PHI to perform our services and for other limited purposes, but other uses and disclosures, such as marketing communications, require written authorization from the patient or must meet an exception specified under the privacy regulations. Violations of the HIPAA privacy and security regulations may result in substantial civil monetary penalties and, in certain circumstances, criminal penalties. The U.S. Department of Health and Human Services (“HHS”) enforces the privacy and security regulations, and state attorneys general may also enforce the regulations in response to violations that threaten the privacy of state residents. To the extent we are permitted under our customer contracts, we may de-identify PHI and use de-identified information for our purposes without obtaining patient authorization or further complying with HIPAA. Determining whether PHI has been sufficiently de-identified to comply with the HIPAA privacy standards and our contractual obligations may require complex factual and statistical analyses. Any failure by us to meet HIPAA requirements with respect to de-identification could subject us to penalties and harm our reputation.
Other Privacy and Security Requirements
In addition to HIPAA, numerous other U.S. federal and state laws govern the collection, dissemination, use, access to and confidentiality of personal information, including certain demographic information, such as social security numbers, financial information, health and wellness data that is not protected health information. In many cases, state laws are more restrictive than, and not preempted by, HIPAA, and may allow personal rights of action with respect to privacy or security breaches, as well as fines. State laws are contributing to increased enforcement activity and are subject to interpretation by various courts and other governmental authorities. Further, a number of states have introduced or passed legislation relating to the collection, storage, handling and transfer of personal data, as discussed above. Also, the Substance Abuse Confidentiality Regulations, restrict the use and disclosure of certain information that relates to substance abuse disorders.
Data Protection and Breaches
Most states require holders of personal information to maintain safeguards, and all states have laws that require such holders to take certain actions in response to a data breach, such as providing prompt notification of the breach to affected individuals or the state’s attorney general. In some states, these laws are limited to electronic data, but states increasingly are enacting or considering stricter and broader requirements. The laws are inconsistent across states, which can increase the costs of compliance. Additionally, HIPAA imposes certain notification requirements on business associates. In certain circumstances involving large breaches, media notice is required. A non-permitted use or disclosure of PHI is presumed to be a breach under HIPAA unless the business associate or covered entity establishes that there is a low probability the information has been compromised consistent with the risk assessment requirements enumerated under HIPAA.
15
Further, the FTC regulations require creditors, which may include some of our customers, to implement identity theft prevention programs to detect, prevent and mitigate identity theft in connection with customer accounts. Although Congress passed legislation that restricts the definition of “creditor” and exempts many healthcare providers from complying with this identity theft prevention rule, we may be required to apply additional resources to our existing processes to assist our affected customers in complying with this rule.
Information Blocking and Interoperability Requirements
Government initiatives promoting interoperability of electronic health information ("EHI") have driven increasing demand among customers, industry groups, and patients for health information technology ("HIT") products that are compatible with one another and capable of facilitating access, exchange, and use of EHI without delay or other interference. For example, the 21st Century Cures Act ("The Cures Act") and implementing regulations (the "Information Blocking Rule"), prohibit information blocking by health care providers, health information exchanges ("HIEs"), and developers that offer or develop one or more HIT modules certified through the Office of the National Coordinator of Health Information Technology ("ONC") Certification Program ("Certified Health Information Technology"). One of our subsidiaries is considered to be a HIT developer since its product, iMed EMR, is Certified Health Information Technology and is, therefore, subject to these restrictions.
Information blocking by an HIT developer or HIE is any practice that the actor knows or should know is likely to interfere with, prevent or materially discourage access, exchange or use of EHI, unless it is required by law or meets an exception. Under the Cures Act and a final rule published in July 2023 by the HHS Office of the Inspector General (“OIG”), developers of Certified Health Information Technology that commit information blocking may be subject to civil penalties of up to $1 million per violation.
In 2020, ONC published a final rule that imposes HIT technology standards, implementation specifications, certification criteria, and conditions and maintenance of certification requirements that apply to HIT developers (“HIT Standards and Certification Criteria Final Rule”). The HIT Standards and Certification Criteria Final Rule includes new criteria related to EHI export and standardized APIs for patient services. As a result of this rule, HIT developers of certified HIT must ensure that their products and services meet the requisite technical standards by the relevant deadlines, most of which rolled out, and that their HIT continues to evolve as developers and other stakeholders release revised versions of these standards. In addition, to participate in the ONC Health IT Certification Program, HIT developers must make various certifications regarding their HIT, and attest to compliance with applicable conditions of certification, including those related to information blocking.
In 2020, the Centers for Medicare & Medicaid Services ("CMS") published the Interoperability and Patient Access Final Rule, which, among other things, requires hospitals with certain EHR capabilities to send admission, discharge, and transfer notifications to other providers, and imposes requirements on certain payors to support Patient Access and Provider Directory APIs. While not directly applicable to HIT developers, the Interoperability and Patient Access Final Rule further demonstrates the government’s drive toward interoperability of EHI and the resulting need of healthcare providers and other consumers of HIT for tools that meet these requirements.
In January 2022, ONC published the Trusted Exchange Framework, Common Agreement - Version 1 ("TEFCA") and Qualified Health Information Network ("QHIN") Technical Framework - Version 1. In November 2023, ONC published TEFCA Version 1.1. The overall goal of the TEFCA is to establish a universal floor for interoperability across the country. The TEFCA will establish the infrastructure model and governing approach for users in different networks to securely share basic clinical information with each other—all under commonly agreed-to expectations and rules, agnostic to the network in which they participate. The Trusted Exchange Framework describes a common set of non-binding, foundational principles for trust policies and practices that can help facilitate exchange among HINs. Although implementation of the Trusted Exchange Framework is not mandatory, the federal government encourages its adoption through the establishment of a publicly available directory of networks that are capable of trusted exchange and by permitting federal agencies to require implementation of the Trusted Exchange Framework by network contractors as the contractors update their health IT or operational practices. In February 2023, ONC approved the first group of networks to implement the TEFCA as prospective QHINs, and currently there are seven QHINs that are live.
ONC, now known as the Assistant Secretary for Technology Policy/Office of the National Coordinator for Health IT, or “ASTP ONC,” has finalized one update to the HIT Standards and Certification Criteria Final Rule since 2020, and has another one pending. The finalized update, a Final Rule entitled “Health Data, Technology,
16
and Interoperability: Certification Program Updates, Algorithm Transparency, and Information Sharing,” or “HTI-1,” became effective February 8, 2024. HTI-1 further advances health IT interoperability by updating health IT standards, establishing transparency requirements for artificial intelligence and other predictive algorithms that are part of Certified Health Information Technology, and revising and adding Information Blocking Rule exceptions (including one for TEFCA). The other update is a rule proposed by ASTP ONC called “Health Data, Technology, and Interoperability: Patient Engagement, Information Sharing, and Public Health Interoperability,” or “HTI-2.” HTI-2 proposes two sets of new certification criteria (to enable public health as well as health IT for payors), continues to build off HTI-1 in terms of technology and standards updates, proposes additional Information Blocking Rule exceptions, and establishes governance rules for TEFCA. Public comments closed on HTI-2 October 4, 2024, and the Final Rule for HTI-2 has not yet been released.
Anti-Kickback Laws
A number of federal and state laws govern patient referrals, financial relationships with physicians and other referral sources and inducements to providers and patients, including restrictions commonly known as the federal Anti-Kickback Statute (“AKS”). The AKS prohibits any person or entity from offering, paying, soliciting or receiving, directly or indirectly, anything of value with the intent of generating referrals of items or services covered by Medicare, Medicaid or other federal healthcare programs. Courts have interpreted the law broadly and held that there is violation of the statute if any one of the purposes of an arrangement is to encourage patient referrals or other federal healthcare program business, regardless of whether there are other legitimate purposes for the arrangement. Actual knowledge of the statute or specific intent to violate it is not required to commit a violation. Violation of the AKS is a felony, and penalties for AKS violations can be severe, and include imprisonment, criminal fines, civil penalties with treble damages and exclusion from participation in federal healthcare programs. In addition, submission of a claim or services or items generated in violation of the AKS may be subject to additional penalties under the federal False Claims Act ("FCA").
The AKS contains a limited number of exceptions, and the OIG has created regulatory safe harbors to the AKS. Activities that comply with a safe harbor are deemed protected from prosecution under the AKS. Failure to meet a safe harbor does not automatically render an arrangement illegal under the AKS. The arrangement, however, does risk increased scrutiny by government enforcement authorities, based on our particular facts and circumstances. Our contracts and other arrangements may not meet an exception or a safe harbor. Additionally, many states have similar anti-kickback laws or laws that otherwise prohibit fraudulent or abusive arrangements within the healthcare industry. These laws are often broad in scope and may apply regardless of the source of payment for care.
Although we believe that our relationships with referral sources and recipients have been structured to comply with current law and available interpretations, we cannot provide assurance that regulatory authorities enforcing these laws will determine these financial arrangements comply with the AKS or other applicable laws.
False or Fraudulent Claim Laws; Medical Billing and Coding
Medical billing, coding and collection activities are governed by numerous federal and state civil and criminal laws, regulations, and sub-regulatory guidance. We provide billing and coding services, claims processing and other solutions to providers that relate to, or directly involve, the reimbursement of health services covered by Medicare, Medicaid, other federal and state healthcare programs and private payers. These services may subject us to, or we may be contractually required to comply with, numerous federal and state laws that prohibit false or fraudulent claims including but not limited to the FCA, the federal Civil Monetary Penalties Law ("CMP Law"), and state equivalents. We rely on our customers to provide us with accurate and complete information and to appropriately use the solutions we provide to them, but they may not always do so.
The FCA prohibits the knowing submission of false claims or statements to the federal government, including to the Medicare and Medicaid programs. The FCA defines the term “knowingly” broadly to include not only actual knowledge of a claim’s falsity, but also reckless disregard of the truth of the information, or deliberate ignorance of the truth or falsity of a claim. Specific intent to defraud is not required. The FCA may be enforced by the federal government directly or by a qui tam plaintiff, or whistleblower, on the government's behalf. The government may use the FCA to prosecute Medicare and other government program fraud in areas such as coding errors and billing for services not rendered. Further, submission of a claim for an item or service generated in violation of the AKS constitutes a false or fraudulent claim for purposes of the FCA. When an entity is determined to have violated the FCA, it may be required to pay three times the actual damages sustained by the government, plus
17
substantial civil penalties for each false claim, and may be excluded from participation in federal healthcare programs.
Exclusion from Participation in Government Healthcare Programs
The OIG is required to or may choose to exclude individuals and entities involved in misconduct related to federal healthcare programs, including Medicare and Medicaid, from participation in those programs. Federal law prohibits federal healthcare programs from paying for items or services furnished, ordered, or prescribed by an individual or entity excluded from participation. The prohibition against federal program payment extends to payment for administrative and management services not directly related to patient care. Civil penalties may be imposed against providers and entities that employ or enter into contracts with excluded individuals or entities to provide items or services to federal healthcare program beneficiaries and submit a claim for reimbursement to a federal healthcare program, or cause such a claim to be submitted. In addition to civil monetary penalties, violations may result in exclusion and treble damages, for each item or service furnished during the period in which the individual or entity was excluded. Our customers have an affirmative duty to check the exclusion status of individuals and entities prior to entering into contractual relationships and periodically re-check thereafter. We have implemented compliance policies and procedures to screen for excluded individuals at our entities subject to these laws. However, if we employ or contract with an excluded individual or entity, we could face significant consequences as outlined above. In addition, we could be liable under our customer contracts if we are excluded by the OIG or employ or contract with an excluded individual or entity.
Anti-Money Laundering and Counter-Terrorism Regulation
Our business is subject to U.S. federal anti-money laundering laws and regulations, including the Bank Secrecy Act of 1970, as amended by the USA PATRIOT Act of 2001, which we refer to collectively as the “BSA.” The BSA, among other things, requires money services businesses to develop and implement risk-based anti-money laundering programs, report large cash transactions and suspicious activity and maintain transaction records. We are also subject to certain economic and trade sanctions programs that are administered by the Office of Foreign Assets Control (“OFAC”) that prohibit or restrict transactions to or from (or transactions dealing with) specified countries, their governments and, in certain circumstances, their nationals, such as those who might be narcotics traffickers and terrorists or terrorist organizations. Similar anti-money laundering, counter terrorist financing and proceeds of crime laws apply to movements of currency and payments through electronic transactions and to dealings with persons specified on lists maintained by organizations similar to OFAC in several other countries and which may impose specific data retention obligations or prohibitions on intermediaries in the payment process. We have developed and continue to enhance compliance programs and policies to monitor and address related legal and regulatory requirements and developments.
Unfair or Deceptive Acts or Practices
We and many of our customers are subject to Section 5 of the Federal Trade Commission Act prohibiting unfair or deceptive acts or practices. In addition, laws prohibiting these activities and other laws, rules and or regulations, including the Telemarketing Sales Act, may directly impact the activities of certain of our customers, and in some cases may subject us, as the customer’s payment processor or provider of certain services, to investigations, fees, fines and disgorgement of funds if we are deemed to have aided and abetted or otherwise provided the means and instrumentalities to facilitate the illegal or improper activities of the customer through our services. Various federal and state regulatory enforcement agencies, including the Federal Trade Commission and the states attorneys general, have authority to take action against non-banks that engage in unfair or deceptive acts or practices or violate other laws, rules and regulations and to the extent we are processing payments or providing services for a customer that may be in violation of laws, rules and regulations, we may be subject to enforcement actions and as a result may incur losses and liabilities that may impact our business.
In addition, the CFPB has recently attempted to extend certain provisions of the Dodd-Frank Act that prevent the employment of unfair, deceptive or abusive acts or practices (“UDAAP”) to payment processors. Though there is still litigation involving whether payment processing companies are subject to these requirements (and the extent of their application), these requirements may apply or be applicable in the future. UDAAPs could involve omissions or misrepresentations of important information to consumers or practices that take advantage of vulnerable consumers, such as elderly or low-income consumers.
18
Prepaid Products
Prepaid products, such as store gift cards, are subject to various federal and state laws and regulations, which may include laws and regulations related to consumer and data protection, licensing, consumer disclosures, escheat, anti-money laundering, banking, trade practices and competition. The customers who utilize prepaid products and services that we may sell may be subject to these laws and regulations. In the future, if we seek to expand these prepaid card products and services, or as a result of regulatory changes, we may be subject to additional regulation and may be required to obtain additional licenses and registrations which we may not be able to obtain.
The Credit Card Accountability Responsibility and Disclosure Act of 2009 (the “Card Act”) gift card provisions created requirements applicable to general-use prepaid cards, store gift cards and gift certificates. The Card Act, along with the Federal Reserve’s amended Regulation E, created new requirements with respect to general-use prepaid cards, store gift cards and gift certificates. These include restrictions to impose dormancy, inactivity or service fees, expiration date not less than five years from the date of issuance and revised pre-purchase disclosure obligations. Products offered on a prepaid basis may also be subject to the rules and regulations of Visa, Mastercard, Discover and American Express and other payment networks with which our customers and the card issuers do business. The customers who utilize the gift card processing products and services that we may sell are responsible for compliance with all applicable rules and requirements relating to their gift product program.
Additionally, the Financial Crimes Enforcement Network of the U.S. Department of the Treasury (“FinCEN”), issued a final rule in July 2011 regarding the applicability of the BSA’s regulations to “prepaid access” products and services. This rulemaking clarifies the anti-money laundering obligations for entities engaged in the provision and sale of prepaid access including prepaid gift cards. We are not registered with FinCEN based on our determination that our current products and services do not constitute a “prepaid program” as defined in the BSA and we are not a “provider” of prepaid access. We may in the future need to register with FinCEN as a “money services business-provider of prepaid access” in accordance with the rule based on changes to our products or services.
Indirect Regulatory Requirements
Certain of our partners are financial institutions that are directly subject to various regulations and compliance obligations issued by the CFPB, the Federal Reserve System, the Office of the Comptroller of the Currency, the Federal Deposit Insurance Corporation, the National Credit Union Administration and other agencies responsible for regulating financial institutions, which includes state financial institution regulators. While these regulatory requirements and compliance obligations do not apply directly to us, many of these requirements materially affect the services we provide to our customers and us overall. The financial institution regulators have imposed requirements on regulated financial institutions to manage their third-party service providers. Among other things, these requirements include performing appropriate due diligence when selecting third-party service providers; evaluating the risk management, information security, and information management systems of third-party service providers; imposing contractual protections in agreements with third-party service providers (such as performance measures, audit and remediation rights, indemnification, compliance requirements, confidentiality and information security obligations, insurance requirements, and limits on liability); and conducting ongoing monitoring, diligence and audits of the performance of third-party service providers. Additionally, certain of our customers are governmental entities, which may be subject to further federal, state or local requirements. Accommodating these requirements applicable to our customers imposes additional costs and risks in connection with both our operations and our financial institution relationships. We expect to expend significant resources on an ongoing basis in an effort to assist our customers in meeting their legal requirements.
Payment Network Rules and Standards
Payment networks establish their own rules and standards that allocate liabilities and responsibilities among the payment networks and their participants. These rules and standards, including the PCI DSS, govern a variety of areas of the payments industry, including how we can process transactions, how consumers and customers may use their cards, how our customers may conduct their business regarding the acceptance of payments (including the types and amounts of fees that can be assessed for the acceptance of payments), the security features of cards, security standards for processing, data security and allocation of liability for certain acts or omissions including liability in the event of a data breach. The payment networks may change these rules and standards from time to time as they may determine in their sole discretion and with or without advance notice to
19
their participants. These changes may be made for any number of reasons, including as a result of changes in the regulatory environment, to maintain or attract new participants, or to serve the strategic initiatives of the networks and may impose additional costs and expenses on or be disadvantageous to certain participants. Changes to these rules and standards could alter or prohibit certain current industry business practices which could impact our ability to provide services to various market segments we service. Participants are subject to audit by the payment networks to ensure compliance with applicable rules and standards. The networks may fine, penalize or suspend the registration of participants for certain acts or omissions or the failure of the participants to comply with applicable rules and standards.
A significant network rule is the “chip and pin” or “chip and signature” card requirement, known as EMV, which was mandated by Visa, Mastercard, American Express and Discover to be supported by payment processors by April 2013 and merchants by October 2015. This mandate set new requirements and technical standards, including requiring integrated point of sale systems to be capable of accepting the more secure “chip” enabled cards that utilize the EMV standard and setting new rules for data handling and security. Processors and customers that do not comply with the mandate or do not use systems that are EMV compliant risk fines and liability for fraud-related charges. We have invested significant resources to ensure our systems’ compliance with the mandate, and to assist our customers in fulfilling their EMV compliance responsibilities.
To provide our electronic payment services, we must be registered with each of the payment networks that we utilize. Because we are not a bank, we are not eligible for primary membership in certain payment networks, including Visa and Mastercard, and are therefore unable to directly access these networks. The operating regulations of certain payment networks, including Visa and Mastercard, require us to be sponsored by a member bank . We are registered with certain payment networks, including Visa and Mastercard, through a sponsor bank. The agreements with our bank sponsor gives them substantial discretion in approving certain aspects of our business practices including our solicitation, application and qualification procedures for customers and the terms of our agreements with customers. We are also subject to network operating rules and guidelines promulgated by the National Automated Clearing House Association (“NACHA”) relating to payment transactions we process using the ACH Network. Like the card networks, NACHA may update its operating rules and guidelines at any time and we will be subject to these changes. For example, NACHA's Micro-Entry Rule to improve the means of account validation was implemented in two stages effective September 16, 2022 and March 17, 2023, and requires originators of ACH transaction to use commercially reasonable fraud detection and to monitor forward and return micro-entry volumes. The NACHA Operating Rules and Guidelines allocate responsibility and liabilities to the various participants in the payment network, including us and our partner financial institutions. NACHA continues to focus on data security and privacy and delegation of responsibilities. We are subject to audit by our partner financial institutions for compliance with the rules and guidelines. Our sponsor financial institutions have substantial discretion in approving certain aspects of our business practices, including the terms of our agreements with our ACH processing customers.
Money Transmitter Regulation
We are subject to various U.S. federal, state, and foreign laws and regulations governing money transmission and the issuance and sale of payment instruments, including various prepaid access products we may sell.
In the United States, each state besides Montana has money transmitter license requirements and many have licenses for issuers of payment instruments and stored value. These states not only regulate and control money transmitters, but they also license entities engaged in the transmission of funds. Many states exercise authority over the operations of our services related to money transmission and payment instruments and, as part of this authority, subject us to periodic examinations. Many states require, among other things, that proceeds from money transmission activity and payment instrument sales be invested in high-quality marketable securities before the settlement of the transactions or otherwise restrict the use and safekeeping of such funds. Such licensing laws may cover matters including regulatory approval of consumer forms, required consumer disclosures, the filing of periodic and updated reports by the licensee and require the licensee to demonstrate and maintain specified levels of net worth. Many states also require money transmitters, issuers of payment instruments and stored value, and their agents to comply with federal and/or state anti-money laundering laws and regulations.
20
Other Regulation
We are subject to U.S. federal and state unclaimed or abandoned property (escheat) laws which require us to remit to certain government authorities property of others we hold that has been unclaimed for a specified period of time such as account balances due to a customer following discontinuation of its relationship with us. The Housing Assistance Tax Act of 2008 requires certain merchant acquiring entities and third-party settlement organizations to provide information returns for each calendar year with respect to payments made in settlement of electronic payment transactions and third-party payment network transactions occurring in that calendar year. Reportable transactions are also subject to backup withholding requirements.
The foregoing is not an exhaustive list of the laws and regulations to which we are subject and the regulatory framework governing our business is changing continuously. See “Risk Factors—Risks Related to Our Business and Industry” in Part I, Item 1A of this Annual Report on Form 10-K.
Our Intellectual Property
Certain of our products and services are based on proprietary software and related payment systems solutions. We rely on a combination of copyright, trademark, and trade secret laws, as well as employee and third-party non-disclosure, confidentiality, and contractual arrangements to establish, maintain, and enforce our intellectual property rights in our technology, including with respect to our proprietary rights related to our products and services. In addition, we license technology from third parties that is integrated into some of our solutions.
We own a number of registered federal service marks, including, without limitation, i3 Verticals®, i3 Education®, ImageSoft®, JusticeTech®, TrueSign®, Milestone® and PaySchools®. We also own a number of domain names, including, without limitation, www.i3verticals.com.
Available Information
Our Annual Report on Form 10-K, Quarterly Reports on Form 10-Q, Current Reports on Form 8-K, and amendments to reports filed pursuant to Sections 13(a) and 15(d) of the Securities Exchange Act of 1934, as amended (the “Exchange Act”), are filed with the Securities and Exchange Commission (the “SEC”). We are subject to the informational requirements of the Exchange Act and file or furnish reports, proxy statements and other information with the SEC. The SEC maintains an Internet site that contains reports, proxy and information statements and other information regarding issuers that file electronically with the SEC at www.sec.gov. We also maintain a website at www.i3verticals.com, through which you may access these materials free of charge as soon as reasonably practicable after they are electronically filed with, or furnished to, the SEC. Information contained on our website is not a part of this Annual Report on Form 10-K and the inclusion of our website address in this report is an inactive textual reference only.