Item 4. Controls and Procedures
Item
4. Controls and Procedures
Evaluation
of Disclosure Controls and Procedures
We
maintain disclosure controls and procedures (as that term is defined in Rules 13a-15(e) and 15d-15(e) under the Securities Exchange Act
of 1934, as amended (the “Exchange Act”)) that are designed to provide reasonable assurance that information required to
be disclosed in our reports that we file or submit under the Exchange Act is recorded, processed, summarized, and reported within the
time periods specified in the SEC’s rules and forms, and that such information is accumulated and communicated to our management,
including our chief executive officer and chief financial officer, as appropriate, to allow timely decisions regarding required disclosures.
Based on that evaluation, our chief executive officer and chief financial officer concluded that our disclosure controls and procedures
were not effective as of June 30, 2026 due to the material weaknesses in our internal control over financial reporting described below.
In
designing disclosure controls and procedures, our management is required to apply its judgment in evaluating the cost-benefit relationship
of possible disclosure controls and procedures. The design of any disclosure controls and procedures also is based in part upon certain
assumptions about the likelihood of future events, and there can be no assurance that any design will succeed in achieving its stated
goals under all potential future conditions. Any controls and procedures, no matter how well designed and operated, can provide only
reasonable, not absolute, assurance of achieving the desired control objectives.
Material
Weaknesses in Internal Control over Financial Reporting
As
previously disclosed in our Annual Report on Form 10-K for the fiscal year ended December 31, 2025, we identified material weaknesses
in our internal control over financial reporting. A material weakness is a deficiency, or combination of deficiencies, in internal control
over financial reporting, such that there is a reasonable possibility that a material misstatement of a company’s annual or interim
financial statements will not be detected or prevented on a timely basis.
We
identified material weaknesses in our internal control over financial reporting as we did not:
(i)
design
and maintain effective controls related to the recording of net revenue as agent in certain arrangements with the Company’s
third-party pharmacy providers. This material weakness resulted in immaterial misstatements of revenue, deferred revenue, accounts
receivable and accrued expenses in the 2023 annual and the Q3 and Q4 interim financial statements. The immaterial misstatements in
the 2024 annual and interim financial statements, and the Q1 and Q2 2025 interim financial statements resulted in the revision of
the previously issued annual and interim consolidated financial statements.
(ii)
design
and maintain effective controls to verify the appropriateness of segregation of duties, including assessment of incompatible duties,
identification of instances where incompatible duties were assigned to individuals, and addressing conflicts on a timely basis. This
material weakness did not result in a misstatement to our interim or annual consolidated financial statements.
(iii)
design
and maintain effective business process controls related to Information Produced by the Entity (“IPE”) and system generated
IPE. Specifically, we did not design effective controls to review and approve procedures over key information utilized in the performance
of the control. This material weakness did not result in a misstatement to our interim or annual consolidated financial statements.
(iv)
design
and maintain effective controls over information technology (“IT”) general controls for information systems that are
relevant to the preparation of our consolidated financial statements and the effectiveness of IT-dependent controls. Specifically,
we did not design and maintain: (a) user access controls to ensure appropriate segregation of duties and to adequately restrict user
and privileged access to appropriate personnel; (b) program change management controls to ensure that program and data changes are
identified, tested, authorized and implemented appropriately; (c) computer operations controls to ensure that processing and transfer
of data, and data backups and recovery are monitored; (d) program development controls to ensure that new software development is
tested, authorized and implemented appropriately, and (e) review of key third-party service provider Systems and Organizational Controls
(“SOC”) reports. These material weaknesses did not result in a misstatement to our interim or annual consolidated financial
statements.
Additionally,
these material weaknesses could result in the misstatement of the interim or annual consolidated financial statements that would result
in a material misstatement to the interim or annual consolidated financial statements that would not be prevented or detected.
38
Management’s
Plan to Remediate the Material Weaknesses
To
remediate the material weaknesses, our management, with oversight from our audit committee, implemented a remediation plan. The Company
has taken the following steps to further our remediation:
Actions
taken to date:
(i)
documented
and maintained evidence of the completeness and accuracy of manually generated IPE and system generated IPE and review of controls,
including focused training for process owners;
(ii)
formalized
user access, change management and computer operations controls of our internal information systems as well as SOC report reviews
for in-scope third-party systems;
(iii)
implemented
focused ITGC training for key system owners;
(iv)
increased
the frequency of user access reviews of our internal information systems; and
(v)
designed
and implemented computer operations controls to ensure that processing and transfer of data, and data backups and recovery are monitored
including: (a) updated policies and test plans for backup monitoring controls, (b) controls over database backup restoration and
backup jobs monitoring, (c) controls over critical batch jobs monitoring, and (d) implemented monthly reviews over users with access
to modify batch and backup jobs.
Actions
still to be taken:
(i)
modifying
system reporting over revenue to ensure completeness and accuracy of information used in the calculation of revenue, deferred revenue,
accounts receivable and accrued expenses for customers of a specific contract;
(ii)
designing
and implementing a reconciliation process over the recording of net revenue as agent in certain arrangements with the Company’s
third-party pharmacy providers to ensure completeness and accuracy of information;
(iii)
implementing
focused user access deprovisioning training for key system owners particularly for external contractor deprovisioning;
(iv)
designing
and implementing policies, procedures and controls related to program development to ensure new software programs are tested, authorized
and implemented appropriately, including focused training for key system owners; and
(v)
designing
and implementing controls over segregation of duties, including: (a) modifying and validating the journal entry approval process
within the general ledger system; (b) reassigning preparation and review responsibilities over certain account reconciliations and
financial statement variance analyses to ensure appropriate segregation of duties; (c) implementing controls related to the opening
and closing of accounting periods to ensure there are independent reviews and approvals in place; (d) implementing independent review
controls over vendor master data, and (e) implementing review controls over chart of account modifications.
These
material weaknesses will not be remediated until all of the related control activities have been fully designed, implemented and operating
effectively for a sufficient period of time.
The
Company has invested significantly in our IT environment, enhanced key ITGCs, improved documentation and review of IPE, strengthened
oversight of third-party service providers, and implemented additional monitoring activities across several control areas. Management
believes these efforts will support the continued execution of the remediation plan in 2026.
Changes
in Internal Control over Financial Reporting
There
have been no changes in our internal control over financial reporting (as defined in Rules 13a-15(f) and 15d-15(f) under the Exchange
Act) during the quarter ended June 30, 2026 that have materially affected, or are reasonably likely to materially affect, our internal
control over financial reporting.
39
PART
II – OTHER INFORMATION
ITEM
1. LEGAL PROCEEDINGS
In
the ordinary course of our operations, we become involved in ordinary routine litigation incidental to the business. Material proceedings
are described under Note 12, “Commitments and Contingencies” to the unaudited consolidated financial statements included
in this Quarterly Report on Form 10-Q.