−Removed: i3 Verticals builds, acquires and grows software solutions in the Public Sector and Healthcare vertical markets.
−Removed: Our broad array of enterprise solutions deeply integrate within customers’ operations, which leads to long-term partnerships.
−Removed: Since our founding in 2012, we have compounded cash flow through a combination of organic growth and acquisitions.
−Removed: Our cash flow generation and strong recurring revenue model has positioned us with an ideal financial structure to capitalize on strategic growth opportunities for years to come.
+Added: i3 Verticals provides mission-critical enterprise software solutions to public sector entities.
+Added: These comprehensive cloud-native solutions address a broad range of government functions, including courts and public safety, public administration, utilities, transportation and schools.
+Added: The Company’s mission is to enable state and local governments and related agencies to perform their functions and serve their constituents as effectively and efficiently as possible.
+Added: With thousands of software installations across all 50 states and Canada, i3 Verticals is a leader in the public sector vertical.
Sale of Merchant Services Business
−Removed: On September 20, 2024, i3 Verticals, LLC, and i3 Holdings Sub, Inc., a wholly-owned subsidiary of i3 Verticals, LLC (“Corporation Seller,” and collectively with i3 Verticals, LLC, the “Sellers”) completed the transactions (such closing, the “Closing”) contemplated by that certain Securities Purchase Agreement dated as of June 26, 2024 (the “Purchase Agreement”), by and among i3 Verticals, LLC, Corporation Seller, the Company (solely for the purpose of providing a guaranty of the obligations of Sellers as set forth in the Purchase Agreement), Payroc Buyer, LLC (“Buyer”), and Payroc WorldAccess, LLC (solely for the purpose of providing a guaranty of the obligations of Buyer as set forth in the Purchase Agreement), the entry into which Purchase Agreement was previously disclosed in a Current Report on Form 8-K filed by the Company on June 26, 2024.
−Removed: Pursuant to the terms of the Purchase Agreement, the Sellers sold to Buyer the equity interests of certain direct and indirect wholly-owned subsidiaries of Sellers (the “Acquired Entities”) primarily comprising the Company’s merchant services business, including its associated proprietary technology (the “Merchant Services Business”), after giving effect to the contribution of certain assets and the assignment of certain liabilities associated with the Merchant Services Business from i3 Verticals, LLC and certain affiliates to the Acquired Entities pursuant to a contribution agreement which was entered into immediately prior to the Closing.
−Removed: Pursuant to the terms of the Purchase Agreement, Buyer paid to Sellers an aggregate purchase price of approximately $438 million (after giving effect to estimated net working capital, indebtedness and cash adjustments), payable in cash at the Closing, subject to post-closing purchase price adjustments.
−Removed: Organic Growth in Strategic Vertical Markets
+Added: On September 20, 2024, i3 Verticals, LLC, and i3 Holdings Sub, Inc., a wholly-owned subsidiary of i3 Verticals, LLC (“Corporation Seller,” and collectively with i3 Verticals, LLC, the “Sellers”) completed the transactions (such closing, the “Closing”) contemplated by that certain Securities Purchase Agreement dated as of June 26, 2024 (the “Merchant Services Purchase Agreement”), by and among i3 Verticals, LLC, Corporation Seller, the Company (solely for the purpose of providing a guaranty of the obligations of Sellers as set forth in the Purchase Agreement), Payroc Buyer, LLC (“Buyer”), and Payroc WorldAccess, LLC (solely for the purpose of providing a guaranty of the obligations of Buyer as set forth in the Merchant Services Purchase Agreement), the entry into which Merchant Services Purchase Agreement was previously disclosed in a Current Report on Form 8-K filed by the Company on June 26, 2024.
+Added: Pursuant to the terms of the Merchant Services Purchase Agreement, the Sellers sold to Buyer the equity interests of certain direct and indirect wholly-owned subsidiaries of Sellers (the “Merchant Services Acquired Entities”) primarily comprising the Company’s merchant services business, including its associated proprietary technology (the “Merchant Services Business”), after giving effect to the contribution of certain assets and the assignment of certain liabilities associated with the Merchant Services Business from i3 Verticals, LLC and certain affiliates to the Merchant Services Acquired Entities pursuant to a contribution agreement which was entered into immediately prior to the Closing.
+Added: Pursuant to the terms of the Merchant Services Purchase Agreement, Buyer paid to Sellers an aggregate purchase price of approximately $439.5 million paid in cash at the Closing, after giving effect to post-closing net working capital, indebtedness and cash adjustments.
+Added: Sale of Healthcare RCM Business
+Added: On May 5, 2025, i3 Verticals, LLC and i3 Healthcare Solutions, LLC, a wholly-owned subsidiary of i3 Verticals, LLC (“Seller,” and collectively with i3 Verticals, LLC, the “Seller Parties”), completed the sale of the equity interests of certain wholly-owned subsidiaries of the Seller (the “Healthcare RCM Acquired Entities”) which owned and operated the Company's healthcare revenue cycle management business, including its associated proprietary technology (the “Healthcare RCM Business”), to Infinx, Inc.
+Added: (“Healthcare RCM Buyer”), a Texas corporation, pursuant to the terms of that certain Securities Purchase Agreement dated as of May 5, 2025, by and among Healthcare RCM Buyer and the Seller Parties (the “Healthcare RCM Purchase Agreement;” the transactions contemplated by the Healthcare RCM Purchase Agreement, the “Healthcare RCM Transactions”).
+Added: In addition, immediately prior to the sale of the equity interests of the Healthcare RCM Acquired Entities pursuant to the Healthcare RCM Purchase Agreement, i3 Verticals, LLC and certain of its subsidiaries contributed and/or assigned certain assets and certain liabilities related to the Healthcare RCM Business to the Healthcare RCM Acquired Entities.
+Added: The purchase price payable by Healthcare RCM Buyer to Seller for the equity interests of the Healthcare RCM Acquired Entities was $96.3 million, paid in cash at closing, after giving effect to post-closing net working capital, indebtedness and cash adjustments.
+Added: Organic Growth
The ability to organically grow revenue over the long term is the result of expanding recurring revenue streams, strategic selection of markets and continued investment in our products.
Approximately 76% of our revenue from continuing operations is considered recurring.
−Removed: We earn the majority of our revenue from software and related services.
−Removed: We also earn revenue from volume and transaction-based fees for payment processing services, all of which is integrated into our software.
+Added: We earn most of our revenue from software and related services.
+Added: We also earn revenue from volume and transaction-based fees for payment processing services, all of which are integrated into our software.
Our proprietary payment facilitator platform seamlessly integrates into our software solutions, unlocking additional value.
−Removed: We focus on solutions in the Public Sector and Healthcare vertical and sub-vertical markets because of the following characteristics:
+Added: We focus on solutions in Public Sector markets because of the following characteristics:
• Technologically underserved markets
6 unchanged sentences
Ability to Use Acquisitions to Drive Growth
−Removed: A core component of our growth strategy includes a disciplined approach to acquisitions of companies and technology, evidenced by 50 acquisitions since our inception in 2012.
−Removed: Our management team has significant
−Removed: experience acquiring and integrating vertical market software businesses that complement our existing suite of products and solutions.
−Removed: Acquisitions have extended our product offerings and capabilities, thereby allowing us to enhance our value proposition to our customers.
−Removed: They have also increased our addressable markets.
−Removed: Target businesses are generally founder lead, growing, generating cash flow, and have been in our core vertical markets.
+Added: A core component of our growth strategy includes a disciplined approach to acquisitions of both companies and technology.
+Added: Our leadership team has decades of experience acquiring and integrating software businesses.
+Added: Acquisitions have extended our product offerings and capabilities, thereby enhancing our value proposition to customers and increasing our addressable markets.
+Added: Target businesses are generally founder lead, growing, generating cash flow, and augmenting our existing solutions.
Through our proprietary payment facilitator platform, we have scale, pricing and expertise in payments.
As a result, we often identify targets who lack integrated payment functionality within their solutions or have under-monetized the opportunity.
−Removed: We maintain a strong pipeline of acquisition targets and are constantly evaluating businesses against our acquisition criteria.
−Removed: As a result of the sale of the Merchant Services Business as described above, our entire former Merchant Services segment and a small portion of the historical Software and Services segment which were included in the Merchant Services Business have been reflected in discontinued operations in the Company's consolidated financial statements.
−Removed: After giving effect to these developments, the Company has two reportable segments, Public Sector and Healthcare, and an Other category.
−Removed: For additional information on our segments, see Note 18 to our consolidated financial statements and “Management's Discussion and Analysis of Financial Condition and Results of Operations.”
−Removed: Public Sector
+Added: We maintain a strong pipeline of acquisition targets and regularly evaluate businesses against our acquisition criteria.
+Added: Segment Presentation
+Added: As a result of the sale of the Merchant Services Business in 2024 and the Healthcare RCM Business in 2025, the results of operations for the Merchant Services Business and Healthcare RCM Business have been reflected as discontinued operations in our consolidated statements of operations for all periods presented.
+Added: After giving effect to these developments, we have one operating segment and reportable segment.
+Added: We provide mission-critical enterprise software and services solutions to our public sector customers at the state, county, and local levels of public entities.
+Added: Our solutions deliver end-to-end digital transformation, streamlining complex government operations and enhancing citizen engagement.
+Added: For additional information, see Note 19 to our consolidated financial statements and “Management's Discussion and Analysis of Financial Condition and Results of Operations.”
We have products and solutions that create an efficient flow of information throughout a variety of public sector entities.
1 unchanged sentence
Our solutions help our customers provide more responsive and efficient services to their citizens and stakeholders.
−Removed: There are five sub-verticals within the Public Sector vertical:
−Removed: • JusticeTech and Public Safety:
−Removed: Product categories include (1) fully integrated digital solutions offering dynamic processes to plan, coordinate, evaluate, record, and provide up to date information within court systems, (2) E-Filing and revenue cycle management solutions for courts, and (4) Solutions for computer aided dispatch, law records management, evidence management, jail management, mobile solutions, and livescan.
−Removed: • Transportation:
−Removed: Products include comprehensive solutions for driver license, vehicle title and registration and motor carrier compliance for departments of transportation in the United States and Canada.
−Removed: Product categories include (1) digital customer engagement platform, including web, mobile, chat, and voice options, enables intuitive self-service options for customers to manage their data and accounts, and (2) complete suite of billing and back-office management software solutions and services to enhance enterprise applications, improve customer experience, and increase efficiency of utility operations.
−Removed: • Enterprise Resource Planning (“ERP”):
−Removed: Product categories include (1) solutions that connect the organization and its data to create a flow of information providing insight across multiple departments, (2) digital land records solutions that boost proficiency and maintain records to enable submission of index information, scanning of document images and secure instantaneous retrieval of information, (3) licensing and permitting solutions that automate every step of the application, renewal and payment process, and (4) digital solutions designed for appraisal information, tax collection management, revenue collection, and Computer Assisted Mass Appraisal.
+Added: We primarily serve the following markets:
+Added: • JusticeTech:
+Added: Product categories include (1) fully integrated digital solutions offering dynamic processes to plan, coordinate, evaluate, record, and provide up to date information within court systems, (2) E-Filing and revenue cycle management solutions for courts and (3) solutions for computer aided dispatch, records management, evidence management, jail management, mobile solutions, and livescan.
+Added: Product categories include (1) a digital customer engagement platform, including web, mobile, chat, and voice options, intuitive self-service options and (2) billing and back-office management software solutions and services to enhance enterprise applications, improve customer experience, and increase efficiency of utility operations.
+Added: • Public Administration:
+Added: Product categories include (1) government fund accounting software, (2) digital land records solutions including AI indexing of information, (3) computer assisted mass appraisal solutions, (4) licensing and permitting solutions including automation every step of the application, renewal and payment process and (5) tax and revenue collection management solutions.
Products include (1) comprehensive solutions for school lunch programs, including meal account management, point of sale, menu planning, nutritional analysis, food inventory and free and reduced meal applications and (2) school event solutions, including ticketing and concessions.
+Added: • Transportation:
+Added: Products include (1) vehicle title and registration software (2) driver's license and permit management software and (3) motor carrier compliance for departments of transportation in the United States and Canada.
We deliver integrated payments with our proprietary payment facilitator platform throughout many of these products.
These solutions allow our customers to efficiently process court, tax, registration, utility, school and other payments.
−Removed: Our Healthcare segment is dedicated to delivering integrated solutions across the healthcare ecosystem, catering to providers and payers, with a strong emphasis on enhancing process efficiency and ensuring compliance.
−Removed: There are two sub-verticals within the Healthcare vertical:
−Removed: • Provider Software Solutions:
−Removed: Products include our versatile care delivery platform, which encompasses a range of solutions, including EHR, practice management tools, patient engagement applications, and patient payment solutions.
−Removed: These solutions are designed to adapt to the diverse needs of healthcare organizations, from small physician practices to large academic medical institutions and multi-location health systems.
−Removed: By providing flexible and scalable technology solutions, we empower our clients to navigate the evolving landscape of healthcare.
−Removed: Complementing our technology platform, we offer a comprehensive portfolio of revenue cycle management services.
−Removed: These services provide our clients with a full end-to-end experience, covering all aspects of their financial operations.
−Removed: From revenue optimization and billing to claims processing and coding, our services are designed to streamline financial processes and maximize revenue performance for healthcare organizations.
−Removed: • Payer Software Solutions:
−Removed: Products include (1) tailored solutions for managing compliance requirements, including appeals & grievances and (2) our network management platform assists payers in provider contracting, credentialing, and outreach, enabling them to expand and adapt to changing market dynamics.
−Removed: The Other category includes corporate overhead expenses, technology resources shared across segments and inter-segment eliminations.
Our Technology
−Removed: We are committed to agile delivery, scalable platforms, and secure solutions, intended to bring our customers the best possible mission critical software.
Our team of highly skilled and experienced technologists is dedicated to implementing software products that cater to the diverse and evolving needs of our customers.
−Removed: We continuously refine and expand our software offerings to stay aligned with the latest industry and current market trends.
+Added: We develop and refine our technology to ensure that our market-leading solutions solve relevant pain points for our client base.
+Added: At i3 Verticals, our focus is on delivering agile, scalable, and secure technology platforms to each customer.
Agile Development
5 unchanged sentences
Our development is supported by streamlined back-office technology to increase efficiency.
−Removed: This includes consolidated instant messaging, file sharing, and telephony solutions.
−Removed: We have reduced dependency on multiple vendors across the enterprise while creating efficiency and reducing expense.
+Added: This includes unified systems for team communication, work management, and software delivery reducing dependency on multiple vendors across the enterprise while creating efficiency and reducing expenses.
+Added: We have been endeavoring to thoughtfully incorporate AI capabilities into our platforms and workflows-enhancing automation, decision-making, and customer experience without adding unnecessary complexity.
Together, these initiatives support our commitment to operational efficiency and exceptional service delivery.
4 unchanged sentences
We are a scaled partner of both Amazon Web Services ("AWS") and Microsoft Azure ("Azure") cloud services.
−Removed: Our AWS cloud consolidation initiative is nearing successful completion, with collocated and on-premises data centers successfully migrated to the cloud and unifying disparate subscriptions into an enterprise account.
−Removed: Our strategic partnerships with multiple cloud providers give us flexibility, as well as capabilities beyond that of many of our competitors.
+Added: We have continued to make strong progress in our cloud transformation, with the vast majority of our collocated assets already migrated into the cloud.
+Added: At the same time, we have consolidated previously separate cloud subscriptions into a unified enterprise platform, improving efficiency, enhancing security, and optimizing cost.
+Added: Our multi-cloud partnerships further provide flexibility and access to advanced capabilities that set us apart from many competitors.
Secure Solutions
1 unchanged sentence
Payment Technology
−Removed: In addition to our broad suite of vertical market software, we have developed a proprietary payment facilitation platform.
−Removed: We have centralized our payment solutions onto our proprietary gateway, providing us excellent scale and pricing with our processing partner.
−Removed: Consolidation of the payments platform also reduces our overall PCI scope and increases margins by lowering expenses.Capabilities include:
+Added: In addition to our broad suite of enterprise software solutions, we have developed a proprietary payment facilitation platform.
+Added: We have centralized our payment solutions onto our proprietary gateway, providing us with excellent scale and pricing with our processing partner.
+Added: Consolidation of the payments platform also reduces our overall PCI scope and increases margins by lowering expenses.
+Added: Capabilities include:
• integration with customer business management systems,
3 unchanged sentences
• PCI-compliant security and extensive reporting tools.
−Removed: We offer our customers a single point of access through our powerful but simple proprietary core platform.
+Added: We offer our customers a single point of access through our powerful intuitive proprietary core platform.
From there we offer a suite of proprietary payment and software solutions spanning brick and mortar locations, web-based and mobile-based payments.
−Removed: Our payment technology platforms include an unified application programming interface that provides access to ACH processing and payment facilitator merchant processing capabilities.
+Added: Our payment technology platforms include a unified application programming interface that provides access to ACH processing and payment facilitator merchant processing capabilities.
The platform APIs allow access to Europay, Mastercard and Visa (“EMV”) devices using an implementation that shields software providers from the requirements of PCI or payment application data security standard certifications.
1 unchanged sentence
Our Sales and Marketing
−Removed: We utilize our direct sales team to sell our proprietary software and payment technology solutions directly to customers in our vertical markets.
−Removed: Sales teams are organized and coordinated by vertical and sub-vertical market, leading to extensive cross-selling opportunities across our broad array of solutions.
−Removed: Leveraging our vertically focused suite of products and services, we are able to maximize the performance of our employee sales force as we continue to attract new customers.
−Removed: Our product marketing are delivered through a shared-services model which is coordinated with each vertical market.
−Removed: Marketing is tightly aligned with our sales efforts by providing event coordination, demand-generation resources, physical and electronic marketing campaigns and collateral.
−Removed: Our enterprise marketing function establishes our overall corporate marketing strategy to enhance brand awareness and demand generation.
−Removed: We use a broad variety of traditional and digital marketing mediums to engage prospective customers.
+Added: At i3 Verticals, we prioritize keeping our sales, operations, and marketing activities close to our customers—ensuring every decision is informed by their needs, preferences, and feedback.
+Added: While our Sales Team members are experts in their primary markets, they sell cross-market to ensure that the customer is getting the solution needed.
+Added: We have approximately 30 employees devoted to sales and an additional 30 employees in supporting sales roles as of September 30, 2025.
+Added: Our corporate marketing team operates as a shared services model within i3 Verticals, working in cooperation with market-embedded RFP and marketing resources.
+Added: The team sets and executes the strategy for delivering our story through various channels.
+Added: Additionally, the team works closely with sales staff to keep a pulse on customer needs and adjust quickly when necessary.
Our Operations
Our operations team is uniquely structured to optimize the experience of our customers.
−Removed: These vertically focused business support teams allow us to establish expertise that delivers a scalable support structure and enables us to align our services with the economic goals of our company.
+Added: These market focused business support teams deliver a scalable support structure that aligns our services with the economic goals of our company.
Each operations team is positioned to support the functions of their customer base.
−Removed: Key performance indicators mark their progress toward achieving the goals established by each vertical and sub-vertical.
−Removed: A strong network of shared services, such as marketing, legal, finance and HR, support our vertical and sub-vertical units and ensure they are focused on providing best in-class service to our customers.
−Removed: Our operations team is structured to effectively support the individual needs of our customers.
+Added: Key performance indicators mark their progress toward achieving the goals established by each market.
+Added: A strong network of shared services, such as marketing, legal, finance and HR, support our individual markets and ensure they are focused on providing best in-class service to our customers.
+Added: Our operations team is structured to effectively meet the individual needs of our customers.
This includes:
8 unchanged sentences
• end-user customer support.
−Removed: Our technical operations team oversees the execution of development, quality control, delivery and support for our vertical software solutions and proprietary payment facilitator platform.
+Added: Our technical operations team oversees the execution of development, quality control, delivery and support for our enterprise software solutions and proprietary payment facilitator platform.
Products are developed and tested according to the software development lifecycle, composed of iterative backlog refinement, feature prioritization, development and testing with a dedicated focus on planning and execution.
2 unchanged sentences
Our hosted solutions are managed within dedicated environments within AWS and Azure that align with various compliance standards specific to each industry.
−Removed: This includes, but is not limited to PCI, Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) and National Institute of Standards and Technology ("NIST"), ensuring the protection of all personal and transactional data.
Our Competition
−Removed: We compete with a variety of vertical market software providers that have different business models, go-to-market strategies and technical capabilities.
+Added: We compete with a variety of public sector software providers that have different business models, go-to-market strategies and technical capabilities.
We believe the most significant competitive factors in our markets are:
3 unchanged sentences
Convenience, such as speed in customer onboarding and approving applications;
+Added: Certainty of execution and delivery;
+Added: Modernization of legacy systems;
+Added: Pricing flexibility due to unique funding models;
+Added: Compliance requirements;
+Added: Talent retention;
+Added: Enhanced constituent accessibility;
+Added: Cybersecurity and privacy.
Our competitors range from large and well-established companies to smaller, earlier-stage businesses.
−Removed: See “Risk Factors—Risks Related to Our Business and Industry— The vertical market software and payment processing industries are competitive.
+Added: See “Risk Factors—Risks Related to Our Business and Industry— The enterprise software industry is competitive.
Such competition could adversely affect the revenue we receive, and as a result, our margins, business, financial condition and results of operations.” in Part I, Item 1A of this Annual Report on Form 10-K.
Human Capital
−Removed: To facilitate talent attraction and retention, we strive to make i3 Verticals a safe and healthy workplace, with opportunities for our employees to grow and develop in their careers, supported by competitive compensation and benefits programs and opportunities for advancement.
+Added: To facilitate talent attraction and retention, we strive to make i3 Verticals a safe and healthy workplace, with opportunities for our employees to grow and develop in their careers, supported by competitive compensation and benefits programs.
The success of our business is fundamentally connected to the well-being of our people.
2 unchanged sentences
For our non-U.S.
−Removed: employees, in addition to standard medical coverage, we offer benefits that are consistent with local practices for similarly situated companies.
+Added: employees, in addition to standard medical coverage, we offer benefits that we believe are consistent with local practices for similarly situated companies.
We provide competitive compensation and benefits programs to help meet the needs of our employees.
−Removed: In addition to salaries, these programs (which vary across our businesses) include bonus opportunities and, for our
−Removed: domestic employees, a 401(k) Plan.
+Added: In addition to salaries, these programs (which vary across our businesses) include bonus opportunities and, for our domestic employees, a 401(k) Plan.
We use targeted stock option grants and restricted stock units ("RSUs") with vesting conditions to facilitate retention of personnel, and we are proud that a large percentage of our workforce owns i3 Verticals shares, RSUs or options to purchase i3 Verticals shares.
We believe this dynamic aligns important economic incentives and encourages an entrepreneurial spirit.
−Removed: We have built a collaborative culture that recognizes and rewards innovation and offers employees a variety of opportunities and experiences.
+Added: We have built a collaborative culture that recognizes and rewards innovation as well as offering employees a variety of opportunities and experiences.
We believe that our culture is critical to our success.
1 unchanged sentence
We encourage our employees to take advantage of our flexible work arrangements to meet their individual circumstances.
−Removed: We are an acquisitive company and have regularly added new employees and locations as a result of our acquisition activity.
−Removed: As of November 22, 2024, after giving effect to the disposition of our Merchant Services Business which was completed on September 20, 2024, we had approximately 1,480 employees in 44 states and two countries.
+Added: We are an acquisitive company and have regularly added new employees and locations because of our acquisition activity.
+Added: As of November 20, 2025, we had approximately 1,202 employees in 49 states and two countries.
No employees are represented by unions.
We believe that our employee retention rates are competitive and we think this is a result of strong emphasis on workforce culture in our acquisition process and in our operational decision making.
−Removed: As of September 30, 2024, after giving effect to the completion of the sale of our Merchant Services Business, the Company's workforce was 54% female and 46% male.
−Removed: In addition, our workforce ethnicity, as of September 30, 2024, was as follows:
−Removed: 62% White, 22% Asian, 8% Black or African American, 4% Hispanic or Latino and 4% Other.
−Removed: Race and gender disclosures are based on information self-reported by employees.
+Added: We have experienced in the past, and may continue to experience, seasonal fluctuations in our revenues as a result of consumer and business spending patterns.
+Added: The number of business days in a month or quarter also may affect seasonal fluctuations.
+Added: Certain revenues fluctuate with the fiscal calendars of our customers.
+Added: Transactional revenue for our Education customers is strongest in August, September, October, January and February, at the start of each semester, and generally weakens throughout the semester, with little revenue in the summer months of June and July.
+Added: Operating expenses show less seasonal fluctuation, with the result that net income is subject to the same seasonal factors as our revenues.
+Added: The growth in our business may have partially overshadowed seasonal trends to date, and seasonal impacts on our business may be more pronounced in the future.
Government Regulation
7 unchanged sentences
Federal Reserve approval of a final rule effective October 1, 2021 permit debit card issuers to receive a fraud-prevention adjustment to the interchange fee standards.
−Removed: New rules effective July, 2023 contain certain prohibitions on payment network exclusivity and merchant routing restrictions of debit card transactions.
+Added: Rules effective July 2023 contain certain prohibitions on payment network exclusivity and merchant routing restrictions of debit card transactions.
The Dodd-Frank Act also created the Consumer Financial Protection Bureau (the "CFPB"), which has assumed responsibility for most federal consumer protection laws of a financial nature, and the Financial Stability Oversight Council, which has the authority to determine whether any non-bank financial company, such as us, should be supervised by the Board of Governors of the Federal Reserve System because it is systemically important to the U.S.
4 unchanged sentences
Relevant federal privacy laws include the Gramm-Leach-Bliley Act of 1999, which applies directly to a broad range of financial institutions and indirectly, or in some instances directly, to companies that provide services to financial institutions.
−Removed: These laws and regulations restrict the collection, processing, storage, use and disclosure of personal information, require notice to individuals of privacy practices and provide individuals with certain rights to prevent
−Removed: the use and disclosure of certain nonpublic or otherwise legally protected information.
+Added: These laws and regulations restrict the collection, processing, storage, use and disclosure of personal information, require notice to individuals of privacy practices and provide individuals with certain rights to prevent the use and disclosure of certain nonpublic or otherwise legally protected information.
These laws also impose requirements for safeguarding and proper destruction of personal information through the issuance of data security standards or guidelines.
3 unchanged sentences
Many states have implemented comprehensive data privacy and security laws.
−Removed: Certain of these laws restrict the ability to collect and utilize certain types of personal information, such as Social Security and driver’s license numbers, impose secure disposal requirements for personal data and contain regulations surrounding data protection and information security.
+Added: Certain of these laws restrict the ability to collect and
+Added: utilize certain types of personal information, such as Social Security and driver’s license numbers, impose secure disposal requirements for personal data and contain regulations surrounding data protection and information security.
For example, Massachusetts requires any business that processes the personal information of a Massachusetts resident to adopt and implement a written information security program.
4 unchanged sentences
These laws require companies that process personal information of certain residents of those states to make disclosures to consumers about data practices, grants consumers specific rights to their data, and allow consumers to opt out of certain data sharing activities, and the California Consumer Privacy Act of 2018 (the “CCPA”), as amended by the California Privacy Rights Act of 2020 (the “CPRA”), creates a private right of action for data breaches.
+Added: In addition, various jurisdictions (both in the U.S.
+Added: and in foreign jurisdictions) have enacted and/or have been considering laws and regulations applicable to the use of artificial intelligence ("AI") and machine learning applications and tools, particularly on the use of artificial intelligence to facilitate healthcare, education, employment, or hiring decisions.
To the extent we are subject to such legislation, the potential effects on our business are often far-reaching and may require us to modify our data processing practices and policies and to incur substantial costs and expenses in an effort to comply.
4 unchanged sentences
As an entity that provides services to educational institutions, we are indirectly subject to the Family Educational Rights and Privacy Act ("FERPA") or Protection of Pupil Rights Amendment ("PPRA"), and we may not transfer or otherwise disclose or use any personally identifiable information from a student record to another party other than on a basis and in a manner permitted under the statutes.
−Removed: See “Risk Factors—If we violate the FERPA or PPRA, it could result in a material breach of contract with one or more of our customers in our Education sub-vertical and could harm our reputation.
+Added: See “Risk Factors—If we violate the FERPA or PPRA, it could result in a material breach of contract with one or more of our Education customers and could harm our reputation.
Further, if we disclose student information in violation of FERPA or PPRA, our access to student information could be suspended."
Healthcare Regulatory Matters
−Removed: Our Healthcare vertical business provides services to healthcare providers who are highly regulated and subject to frequently changing political, legislative, regulatory and other influences.
−Removed: Although some regulatory requirements do not directly apply to our operations, these requirements affect the business of our healthcare customers and the demand for our services.
−Removed: Failure to satisfy those legal and regulatory requirements, or the adoption of new laws or regulations, could have a significant negative impact on our Healthcare vertical operations and financial condition.
−Removed: federal, state, local laws and regulations are evolving and can be subject to significant change.
−Removed: In addition, the application and interpretation of these laws and regulations are often uncertain.
−Removed: These laws are enforced by federal, state and local regulatory agencies in the jurisdictions where we operate, and in some instances also through private civil litigation.
−Removed: Examples of the most significant of these laws include, but are not limited to, the following:
−Removed: HIPAA Privacy and Security Requirements
−Removed: There are numerous federal and state laws and regulations related to the privacy and security of health information.
−Removed: In particular, regulations promulgated pursuant to the Health Insurance Portability and Accountability Act of 1996, as amended by the Health Information Technology for Economic Clinical Health Act of 2009 ("HITECH") and other laws (collectively "HIPAA") establish privacy and security standards that limit the use and disclosure of certain individually identifiable health information (known as “protected health information”) and require covered entities, including health plans and most healthcare providers, to implement administrative, physical and technical safeguards to protect the privacy of PHI and ensure the confidentiality, integrity and availability of electronic PHI.
−Removed: Currently, a Notice of Proposed Rulemaking to strengthen the HIPAA security rule is under review by the U.S.
−Removed: Office of Management and Budget and is expected to be published before the end of 2024.
−Removed: Although the specific requirements of this proposed rule have not been published, we would expect the proposed rule to modernize requirements for protecting PHI against healthcare cybersecurity threats, which have dramatically increased over the past few years.
−Removed: In addition, the HIPAA administrative simplification provisions require the use of uniform electronic data transmission standards of healthcare claims and payment transactions submitted or received electronically.
−Removed: Certain provisions of the security and privacy regulations promulgated pursuant to HIPAA apply to business associates (entities that handle PHI on behalf of covered entities), and business associates are subject to direct liability for violation of these provisions.
−Removed: As a provider of services to entities subject to HIPAA, we are a “business associate” of our customers and must safeguard the PHI we handle.
−Removed: To the extent permitted by applicable regulations and contracts and associated business associate agreements with our customers, we are permitted to use and disclose PHI to perform our services and for other limited purposes, but other uses and disclosures, such as marketing communications, require written authorization from the patient or must meet an exception specified under the privacy regulations.
−Removed: Violations of the HIPAA privacy and security regulations may result in substantial civil monetary penalties and, in certain circumstances, criminal penalties.
−Removed: Department of Health and Human Services (“HHS”) enforces the privacy and security regulations, and state attorneys general may also enforce the regulations in response to violations that threaten the privacy of state residents.
−Removed: To the extent we are permitted under our customer contracts, we may de-identify PHI and use de-identified information for our purposes without obtaining patient authorization or further complying with HIPAA.
−Removed: Determining whether PHI has been sufficiently de-identified to comply with the HIPAA privacy standards and our contractual obligations may require complex factual and statistical analyses.
−Removed: Any failure by us to meet HIPAA requirements with respect to de-identification could subject us to penalties and harm our reputation.
−Removed: Other Privacy and Security Requirements
−Removed: In addition to HIPAA, numerous other U.S.
−Removed: federal and state laws govern the collection, dissemination, use, access to and confidentiality of personal information, including certain demographic information, such as social security numbers, financial information, health and wellness data that is not protected health information.
−Removed: In many cases, state laws are more restrictive than, and not preempted by, HIPAA, and may allow personal rights of action with respect to privacy or security breaches, as well as fines.
−Removed: State laws are contributing to increased enforcement activity and are subject to interpretation by various courts and other governmental authorities.
−Removed: Further, a number of states have introduced or passed legislation relating to the collection, storage, handling and transfer of personal data, as discussed above.
−Removed: Also, the Substance Abuse Confidentiality Regulations, restrict the use and disclosure of certain information that relates to substance abuse disorders.
−Removed: Data Protection and Breaches
−Removed: Most states require holders of personal information to maintain safeguards, and all states have laws that require such holders to take certain actions in response to a data breach, such as providing prompt notification of the breach to affected individuals or the state’s attorney general.
−Removed: In some states, these laws are limited to electronic data, but states increasingly are enacting or considering stricter and broader requirements.
−Removed: The laws are inconsistent across states, which can increase the costs of compliance.
−Removed: Additionally, HIPAA imposes certain notification requirements on business associates.
−Removed: In certain circumstances involving large breaches, media notice is required.
−Removed: A non-permitted use or disclosure of PHI is presumed to be a breach under HIPAA unless the business associate or covered entity establishes that there is a low probability the information has been compromised consistent with the risk assessment requirements enumerated under HIPAA.
−Removed: Further, the FTC regulations require creditors, which may include some of our customers, to implement identity theft prevention programs to detect, prevent and mitigate identity theft in connection with customer accounts.
−Removed: Although Congress passed legislation that restricts the definition of “creditor” and exempts many healthcare providers from complying with this identity theft prevention rule, we may be required to apply additional resources to our existing processes to assist our affected customers in complying with this rule.
−Removed: Information Blocking and Interoperability Requirements
−Removed: Government initiatives promoting interoperability of electronic health information ("EHI") have driven increasing demand among customers, industry groups, and patients for health information technology ("HIT") products that are compatible with one another and capable of facilitating access, exchange, and use of EHI without delay or other interference.
−Removed: For example, the 21st Century Cures Act ("The Cures Act") and implementing regulations (the "Information Blocking Rule"), prohibit information blocking by health care providers, health information exchanges ("HIEs"), and developers that offer or develop one or more HIT modules certified through the Office of the National Coordinator of Health Information Technology ("ONC") Certification Program ("Certified Health Information Technology").
−Removed: One of our subsidiaries is considered to be a HIT developer since its product, iMed EMR, is Certified Health Information Technology and is, therefore, subject to these restrictions.
−Removed: Information blocking by an HIT developer or HIE is any practice that the actor knows or should know is likely to interfere with, prevent or materially discourage access, exchange or use of EHI, unless it is required by law or meets an exception.
−Removed: Under the Cures Act and a final rule published in July 2023 by the HHS Office of the Inspector General (“OIG”), developers of Certified Health Information Technology that commit information blocking may be subject to civil penalties of up to $1 million per violation.
−Removed: In 2020, ONC published a final rule that imposes HIT technology standards, implementation specifications, certification criteria, and conditions and maintenance of certification requirements that apply to HIT developers (“HIT Standards and Certification Criteria Final Rule”).
−Removed: The HIT Standards and Certification Criteria Final Rule includes new criteria related to EHI export and standardized APIs for patient services.
−Removed: As a result of this rule, HIT developers of certified HIT must ensure that their products and services meet the requisite technical standards by the relevant deadlines, most of which rolled out, and that their HIT continues to evolve as developers and other stakeholders release revised versions of these standards.
−Removed: In addition, to participate in the ONC Health IT Certification Program, HIT developers must make various certifications regarding their HIT, and attest to compliance with applicable conditions of certification, including those related to information blocking.
−Removed: In 2020, the Centers for Medicare & Medicaid Services ("CMS") published the Interoperability and Patient Access Final Rule, which, among other things, requires hospitals with certain EHR capabilities to send admission, discharge, and transfer notifications to other providers, and imposes requirements on certain payors to support Patient Access and Provider Directory APIs.
−Removed: While not directly applicable to HIT developers, the Interoperability and Patient Access Final Rule further demonstrates the government’s drive toward interoperability of EHI and the resulting need of healthcare providers and other consumers of HIT for tools that meet these requirements.
−Removed: In January 2022, ONC published the Trusted Exchange Framework, Common Agreement - Version 1 ("TEFCA") and Qualified Health Information Network ("QHIN") Technical Framework - Version 1.
−Removed: In November 2023, ONC published TEFCA Version 1.1.
−Removed: The overall goal of the TEFCA is to establish a universal floor for interoperability across the country.
−Removed: The TEFCA will establish the infrastructure model and governing approach for users in different networks to securely share basic clinical information with each other—all under commonly agreed-to expectations and rules, agnostic to the network in which they participate.
−Removed: The Trusted Exchange Framework describes a common set of non-binding, foundational principles for trust policies and practices that can help facilitate exchange among HINs.
−Removed: Although implementation of the Trusted Exchange Framework is not mandatory, the federal government encourages its adoption through the establishment of a publicly available directory of networks that are capable of trusted exchange and by permitting federal agencies to require implementation of the Trusted Exchange Framework by network contractors as the contractors update their health IT or operational practices.
−Removed: In February 2023, ONC approved the first group of networks to implement the TEFCA as prospective QHINs, and currently there are seven QHINs that are live.
−Removed: ONC, now known as the Assistant Secretary for Technology Policy/Office of the National Coordinator for Health IT, or “ASTP ONC,” has finalized one update to the HIT Standards and Certification Criteria Final Rule since 2020, and has another one pending.
−Removed: The finalized update, a Final Rule entitled “Health Data, Technology,
−Removed: and Interoperability:
−Removed: Certification Program Updates, Algorithm Transparency, and Information Sharing,” or “HTI-1,” became effective February 8, 2024.
−Removed: HTI-1 further advances health IT interoperability by updating health IT standards, establishing transparency requirements for artificial intelligence and other predictive algorithms that are part of Certified Health Information Technology, and revising and adding Information Blocking Rule exceptions (including one for TEFCA).
−Removed: The other update is a rule proposed by ASTP ONC called “Health Data, Technology, and Interoperability:
−Removed: Patient Engagement, Information Sharing, and Public Health Interoperability,” or “HTI-2.” HTI-2 proposes two sets of new certification criteria (to enable public health as well as health IT for payors), continues to build off HTI-1 in terms of technology and standards updates, proposes additional Information Blocking Rule exceptions, and establishes governance rules for TEFCA.
−Removed: Public comments closed on HTI-2 October 4, 2024, and the Final Rule for HTI-2 has not yet been released.
−Removed: Anti-Kickback Laws
−Removed: A number of federal and state laws govern patient referrals, financial relationships with physicians and other referral sources and inducements to providers and patients, including restrictions commonly known as the federal Anti-Kickback Statute (“AKS”).
−Removed: The AKS prohibits any person or entity from offering, paying, soliciting or receiving, directly or indirectly, anything of value with the intent of generating referrals of items or services covered by Medicare, Medicaid or other federal healthcare programs.
−Removed: Courts have interpreted the law broadly and held that there is violation of the statute if any one of the purposes of an arrangement is to encourage patient referrals or other federal healthcare program business, regardless of whether there are other legitimate purposes for the arrangement.
−Removed: Actual knowledge of the statute or specific intent to violate it is not required to commit a violation.
−Removed: Violation of the AKS is a felony, and penalties for AKS violations can be severe, and include imprisonment, criminal fines, civil penalties with treble damages and exclusion from participation in federal healthcare programs.
−Removed: In addition, submission of a claim or services or items generated in violation of the AKS may be subject to additional penalties under the federal False Claims Act ("FCA").
−Removed: The AKS contains a limited number of exceptions, and the OIG has created regulatory safe harbors to the AKS.
−Removed: Activities that comply with a safe harbor are deemed protected from prosecution under the AKS.
−Removed: Failure to meet a safe harbor does not automatically render an arrangement illegal under the AKS.
−Removed: The arrangement, however, does risk increased scrutiny by government enforcement authorities, based on our particular facts and circumstances.
−Removed: Our contracts and other arrangements may not meet an exception or a safe harbor.
−Removed: Additionally, many states have similar anti-kickback laws or laws that otherwise prohibit fraudulent or abusive arrangements within the healthcare industry.
−Removed: These laws are often broad in scope and may apply regardless of the source of payment for care.
−Removed: Although we believe that our relationships with referral sources and recipients have been structured to comply with current law and available interpretations, we cannot provide assurance that regulatory authorities enforcing these laws will determine these financial arrangements comply with the AKS or other applicable laws.
−Removed: False or Fraudulent Claim Laws;
−Removed: Medical Billing and Coding
−Removed: Medical billing, coding and collection activities are governed by numerous federal and state civil and criminal laws, regulations, and sub-regulatory guidance.
−Removed: We provide billing and coding services, claims processing and other solutions to providers that relate to, or directly involve, the reimbursement of health services covered by Medicare, Medicaid, other federal and state healthcare programs and private payers.
−Removed: These services may subject us to, or we may be contractually required to comply with, numerous federal and state laws that prohibit false or fraudulent claims including but not limited to the FCA, the federal Civil Monetary Penalties Law ("CMP Law"), and state equivalents.
−Removed: We rely on our customers to provide us with accurate and complete information and to appropriately use the solutions we provide to them, but they may not always do so.
−Removed: The FCA prohibits the knowing submission of false claims or statements to the federal government, including to the Medicare and Medicaid programs.
−Removed: The FCA defines the term “knowingly” broadly to include not only actual knowledge of a claim’s falsity, but also reckless disregard of the truth of the information, or deliberate ignorance of the truth or falsity of a claim.
−Removed: Specific intent to defraud is not required.
−Removed: The FCA may be enforced by the federal government directly or by a qui tam plaintiff, or whistleblower, on the government's behalf.
−Removed: The government may use the FCA to prosecute Medicare and other government program fraud in areas such as coding errors and billing for services not rendered.
−Removed: Further, submission of a claim for an item or service generated in violation of the AKS constitutes a false or fraudulent claim for purposes of the FCA.
−Removed: When an entity is determined to have violated the FCA, it may be required to pay three times the actual damages sustained by the government, plus
−Removed: substantial civil penalties for each false claim, and may be excluded from participation in federal healthcare programs.
−Removed: Exclusion from Participation in Government Healthcare Programs
−Removed: The OIG is required to or may choose to exclude individuals and entities involved in misconduct related to federal healthcare programs, including Medicare and Medicaid, from participation in those programs.
−Removed: Federal law prohibits federal healthcare programs from paying for items or services furnished, ordered, or prescribed by an individual or entity excluded from participation.
−Removed: The prohibition against federal program payment extends to payment for administrative and management services not directly related to patient care.
−Removed: Civil penalties may be imposed against providers and entities that employ or enter into contracts with excluded individuals or entities to provide items or services to federal healthcare program beneficiaries and submit a claim for reimbursement to a federal healthcare program, or cause such a claim to be submitted.
−Removed: In addition to civil monetary penalties, violations may result in exclusion and treble damages, for each item or service furnished during the period in which the individual or entity was excluded.
−Removed: Our customers have an affirmative duty to check the exclusion status of individuals and entities prior to entering into contractual relationships and periodically re-check thereafter.
−Removed: We have implemented compliance policies and procedures to screen for excluded individuals at our entities subject to these laws.
−Removed: However, if we employ or contract with an excluded individual or entity, we could face significant consequences as outlined above.
−Removed: In addition, we could be liable under our customer contracts if we are excluded by the OIG or employ or contract with an excluded individual or entity.
+Added: While we no longer provide revenue cycle management software to customers in the healthcare industry following the sale of our Healthcare RCM business, we continue to offer enterprise software solutions for a limited number of healthcare-adjacent customers.
+Added: Participants in the healthcare industry are subject to extensive and complex federal, state and local laws and regulations, including those relating to privacy and security of health and other personal information, interoperability and information blocking, billing and coding for services and fraud and abuse.
+Added: Although many of these regulatory requirements do not directly apply to our operations, these requirements may affect the businesses of certain of our customers and may impact our services.
+Added: The potential consequences for violating applicable laws or regulations may include administrative, civil and criminal sanctions and penalties, including exclusion from participation in Medicare, Medicaid and other federal and state healthcare programs.
+Added: For example, regulations promulgated pursuant to the Health Insurance Portability and Accountability Act of 1996 (collectively "HIPAA"), which establish privacy and security standards that limit the use and disclosure of certain individually identifiable health information, require safeguards to ensure the confidentiality, integrity and availability of such information, and require notifying affected individuals and the government of breaches.
+Added: Prior to the sale of our Healthcare RCM Business, we provided billing and coding services, claims processing and other solutions to providers.
+Added: Medical billing, coding and collection activities that were governed by numerous federal and state laws, regulations, including laws prohibiting false or fraudulent claims, the federal Anti-Kickback Statute (“AKS”), and the Civil Monetary Penalties Law.
+Added: Although we believe that our business relationships were structured to comply with applicable laws, we cannot provide assurance that regulatory authorities enforcing these laws would determine these financial arrangements complied with applicable laws.
+Added: In addition, we relied on our customers to provide us with accurate and complete information and to appropriately use the solutions we provided to them, but they may have not always done so.
Anti-Money Laundering and Counter-Terrorism Regulation
39 unchanged sentences
These rules and standards, including the PCI DSS, govern a variety of areas of the payments industry, including how we can process transactions, how consumers and customers may use their cards, how our customers may conduct their business regarding the acceptance of payments (including the types and amounts of fees that can be assessed for the acceptance of payments), the security features of cards, security standards for processing, data security and allocation of liability for certain acts or omissions including liability in the event of a data breach.
−Removed: The payment networks may change these rules and standards from time to time as they may determine in their sole discretion and with or without advance notice to
−Removed: their participants.
+Added: The payment networks may change these rules and standards from time to time as they may determine in their sole discretion and with or without advance notice to their participants.
These changes may be made for any number of reasons, including as a result of changes in the regulatory environment, to maintain or attract new participants, or to serve the strategic initiatives of the networks and may impose additional costs and expenses on or be disadvantageous to certain participants.
10 unchanged sentences
We are registered with certain payment networks, including Visa and Mastercard, through a sponsor bank.
−Removed: The agreements with our bank sponsor gives them substantial discretion in approving certain aspects of our business practices including our solicitation, application and qualification procedures for customers and the terms of our agreements with customers.
+Added: The agreements with our bank sponsor give them substantial discretion in approving certain aspects of our business practices including our solicitation, application and qualification procedures for customers and the terms of our agreements with customers.
We are also subject to network operating rules and guidelines promulgated by the National Automated Clearing House Association (“NACHA”) relating to payment transactions we process using the ACH Network.
34 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.