Item 4. Controls and Procedures
Item
4. Controls and Procedures
Evaluation
of Disclosure Controls and Procedures
We
maintain disclosure controls and procedures (as that term is defined in Rules 13a-15(e) and 15d-15(e) under the Securities Exchange Act
of 1934, as amended (the “Exchange Act”)) that are designed to provide reasonable assurance that information required to
be disclosed in our reports that we file or submit under the Exchange Act is recorded, processed, summarized, and reported within the
time periods specified in the SEC’s rules and forms, and that such information is accumulated and communicated to our management,
including our chief executive officer and chief financial officer, as appropriate, to allow timely decisions regarding required disclosures.
In designing disclosure controls and procedures, our management is required to apply its judgment in evaluating the cost-benefit relationship
of possible disclosure controls and procedures. The design of any disclosure controls and procedures also is based in part upon certain
assumptions about the likelihood of future events, and there can be no assurance that any design will succeed in achieving its stated
goals under all potential future conditions. Any controls and procedures, no matter how well designed and operated, can provide only
reasonable, not absolute, assurance of achieving the desired control objectives.
Our
management, with the participation of our chief executive officer and chief financial officer, has evaluated the effectiveness of our disclosure controls and procedures as of September 30, 2025. Based upon that evaluation and subject to the
foregoing, our chief executive officer and chief financial officer concluded that, our disclosure controls and procedures were not effective
as of such date due to the material weaknesses in internal control over financial reporting described below.
Material
Weaknesses in Internal Control over Financial Reporting
As
previously disclosed in our Annual Report on Form 10-K for the fiscal year ended December 31, 2024, we identified material weaknesses
in our internal control over financial reporting related to: (i) our information technology general controls (“ITGCs”), particularly
in the areas of user access, change management and computer operations within certain of our information systems and review of key third-party
service provider Systems and Organizational Controls (“SOC”) reports and (ii) business process controls related to Information
Produced by the Entity (“IPE”) and system generated IPE and insufficient evidence of formal review and approval procedures
of key information utilized in the performance of the control. These material weaknesses did not result in a misstatement of the Company’s
financial statements.
39
Additionally
during the three months ended September 30, 2025, the Company identified a material weakness related to the lack of effectively designed
controls related to the recording of net revenue as agent in certain arrangements with the Company’s third-party pharmacy providers.
Management has concluded the material weakness existed as of December 31, 2024 and in the subsequent interim periods in 2025. The material
weakness resulted in immaterial misstatements of revenue, deferred revenue, accounts receivable and accrued expenses in the 2023 annual
and the Q3 and Q4 interim financial statements, the 2024 annual and interim financial statements, and the Q1 and Q2 2025 interim financial
statements that resulted in the revision of the previously issued annual and interim financial statements.
Additionally,
these material weaknesses could result in the misstatement of the interim or annual consolidated financial statements that would result
in a material misstatement to the financial statements that would not be prevented or detected.
Management’s
Plan to Remediate the Material Weaknesses
To
remediate the identified material weaknesses, our management, with oversight from our audit committee, implemented a remediation plan.
The Company has taken the following steps to further our remediation:
(i)
documented
and maintained evidence of the completeness and accuracy of manually generated IPE and system generated IPE and review of controls,
including focused training for process owners;
(ii)
formalized
user access, change management and computer operations controls of our internal information systems as well as SOC report reviews
for in-scope third-party systems;
(iii)
implemented
focused ITGC training for key system owners;
(iv)
increased
the frequency of user access reviews of our internal information systems;
(v)
modified
system reporting over revenue to increase completeness and accuracy over information used in the calculation of revenue, deferred revenue,
accounts receivable and accrued expenses for customers of a specific contract; and
(vi)
designing
and implementing a reconciliation process over such contract reporting to ensure completeness and accuracy of information.
We
continue to evaluate and refine the design of certain key controls in the areas of user access, change management and computer operations.
We may take additional measures to address control deficiencies, or we may modify certain of the remediation efforts described above.
Changes
in Internal Control over Financial Reporting
As it specifically relates to (v) and (vi) above, there have been changes in our internal control over financial reporting (as
defined in Rule 13a-15(f) and 15d-15(f) under the Exchange Act) during the three months ended September 30, 2025 that have
materially affected, or are reasonably likely to materially affect, our internal control over financial reporting.
40
PART
II – OTHER INFORMATION
ITEM
1. LEGAL PROCEEDINGS
In
the ordinary course of our operations, we become involved in ordinary routine litigation incidental to the business. Material proceedings
are described under Note 11, “Commitments and Contingencies” to the unaudited condensed consolidated financial statements
included in this Quarterly Report on Form 10-Q.
Text extracted from the filing as submitted to EDGAR. Formatting, tables and exhibits are simplified for reading; the original document is authoritative for anything you rely on.