Item 1. Business
Item 1. Business
The description of our business and operations below reflect the exits from the somatic tumor testing and the reproductive and women’s health testing businesses during the fourth quarter of 2022 and the first quarter of 2023, respectively.
Unless otherwise stated in this Annual Report or the context otherwise requires, references to:
• “GeneDx Holdings” refer to GeneDx Holdings Corp., a Delaware corporation (f/k/a Sema4 Holdings Corp. (“Sema4 Holdings”));
• “Legacy GeneDx” refer to GeneDx, LLC, a Delaware limited liability company (formerly, GeneDx, Inc., a New Jersey corporation), which we acquired on April 29, 2022 (the “Acquisition”);
• “Legacy Sema4” refer to Mount Sinai Genomics, Inc. d/b/a as Sema4, a Delaware corporation, which consummated the business combination with CM Life Sciences, Inc. (“CMLS”) on July 22, 2021 (the “Business Combination”); and
• “we,” “us” and “our,” the “Company” and “GeneDx” refer, as the context requires, to:
◦ Legacy Sema4 prior to the Business Combination, and GeneDx Holdings and its consolidated subsidiaries following the consummation of the Business Combination; and
◦ Legacy GeneDx prior to the Acquisition, and GeneDx Holdings and its consolidated subsidiaries following the consummation of the Acquisition.
• “Company,” or “GeneDx” refer to (i) Legacy Sema4 prior to the consummation of the Business Combination; and (ii) GeneDx Holdings and its subsidiaries following the consummation of the Business Combination (including, following the consummation of the Acquisition, Legacy GeneDx).
On January 9, 2023, Sema4 Holdings Corp. changed its name to GeneDx Holdings Corp. The Company’s Class A common stock and public warrants are listed on the Nasdaq under the symbols “WGS” and “WGSWW,” respectively.
Purpose
We operate with conviction that what is best for patients must be embedded in every aspect of our work. In support of these beliefs, we value equitability, simplicity and transparency. Through this value system, we aim to deliver personalized and actionable health insights to inform diagnosis, direct treatment and improve drug discovery, bringing better health from genomics to patients around the world.
Overview
GeneDx sits at the intersection of diagnostics and data science, pairing decades of genomic expertise with an ability to interpret clinical data at scale. We believe we are well-positioned to accelerate the use of genomics to enable precision medicine as the standard of care. Our initial focus is in pediatric and rare diseases, two areas in which we believe we have competitive advantages and can deliver on our vision today.
GeneDx was founded in 2000 by scientists from the National Institutes of Health whose mission was making genetic testing accessible for patients with rare diseases. The company quickly became a leader in genomics, creating the foundation for how to provide genomic information at scale and pioneering exome and genome sequencing for rare and ultra-rare genetic pediatric disorders. More than 20 years later, we have amassed one of the world’s largest rare disease data sets and remain a leader in genomics.
Today, we are powered by our industry-leading genomic interpretation platform, and we believe exome and genome testing will become the standard for diagnosis of genetic disease, with the potential to transform healthcare and improve patients’ quality of life.
Industry Background
Targeted genetic tests and panel testing make up the vast majority of diagnostics tests ordered today. While panel testing can be immensely valuable, it has an increasing limitation as we move towards genetic-based healthcare. Panels only allow you to test for insights that physicians predefine based on symptoms, which can lead to inconclusive results and an inefficient process. It is hypothesis-based medicine based on symptoms that may overlap across diseases. We firmly believe that an affordable, scalable and actionable genome is the future of medicine. The barrier to having actionable information from a genomic sequence is significant—and not just due to costs, which are coming down. The less-discussed barrier to having actionable information lies in the ability to process a genome’s worth of information—quickly and scalably—and to deliver
4
Table of Contents
both a result that a clinician can easily act upon to help a patient and a robust dataset that enables clinicians to drive precise diagnosis and researchers to develop and advance therapeutics.
Most companies in today’s genetics industry are taking a test-by-test approach to cross the chasm from genetics early adopters to genome-guided healthcare in the mainstream market. We believe that driving clinician and patient awareness and influencing policy decisions may facilitate uptake within the industry. In addition, making genetics part of mainstream medicine requires advancing the technology to provide personalized and actionable health insights. It also requires having a robust, well-characterized dataset that can maximize answers and minimize unknowns to drive a new era of discovery.
Exome and whole genome sequencing provide the broadest view into the genomic variant—we are looking comprehensively into over 20,000 genes, while panels look at anywhere from two to a few hundred genes. While most of the industry has focused on panels, we have focused on exome and whole genome developing structured gene-disease knowledge curated by our team of experts to power automated interpretation and reporting.
One Test
The genome is composed of 3 billion “letters”, or base pairs, of DNA. The exome is a portion of the genome that encodes proteins, which are involved in many different types of cellular functions. Changes in a genome or exome can change the way proteins are formed or utilized by the cell, potentially causing disease.
When patients present with complex issues, a genetic diagnosis may be available, but a traditional genetic panel test may be too narrow to identify the cause. Some genetic disorders present with very specific symptoms, so tests that read the “letters” of a single gene or a small panel of genes, may make sense for physicians to use in diagnosis. But for many other genetic diseases, patients can present with overlapping symptoms so finding the correct diagnosis is not always straightforward and may require multiple tests, costly evaluations, invasive procedures, and long hospital stays. Exome and genome sequencing can find different genetic alterations, or variants, that more targeted tests miss and are especially useful when the timing is critical to directing or altering medical management.
With over 20 years of operation, GeneDx has a proven track record of expertise in genetic testing. We launched the industry’s first commercially available next generation sequencing panels in 2008, pioneered exome sequencing in 2012 and have sequenced over 500,000 exomes to date. We have performed over a million genetic tests and worked tirelessly to develop:
• A curated database of disease-associated genomic variants;
• Proprietary bioinformatics and variant interpretation pipelines; and
• Rapid exome and whole genome sequencing testing options.
The status quo of genetic testing requires repeated and fragmented testing which, in many cases, is conducted too late for physicians to use in treatment of patients. Targeted genetic tests and panels have been largely commoditized leaving physicians, healthcare partners and patients searching for deeper answers and enhanced utility. The scalable exome and whole genome interpretation that we can deliver at speed do not require a long, complex, expensive, expert-guided search and may make most other genetic tests obsolete. In addition, using whole genome testing is incredibly simple: it’s designed to be Just One Test.
Advanced Technology with a Human Touch
Our team includes approximately 250 genetic counselors, physicians, scientists, and clinical and molecular genomics specialists. We believe we are one of the industry’s leading genetic testing experts. We share the same goal as healthcare providers, patients, and families: to provide personalized and actionable health insights.
Our years of exome and genome sequencing experience have provided us with a substantial dataset, including over 2.7 million structured phenotypes with nearly 60% of all exomes to date processed as parent-child trios. We have invested resources over time to annotate the phenotypes and sequence the parents of patients, because their genetic sequences can often provide additional diagnostic information, potentially improving the precision of genetic analysis. In addition, the data from more families allows us to continually improve interpretation of genetic code and variants that may cause disease. We believe we have more expertly annotated disease-causing variants than the largest public archive.
Internally developed with over one million sequenced specimens, our database is designed to lead to increasingly reliable diagnostic test results. The structured gene-disease knowledge curated by our team of experts is powering automated interpretation and reporting built to handle genomic data at scale. Combined with our proprietary, state-of-the-art variant identification software, our ability to deliver highly accurate test results makes finding definitive diagnoses, even in complex cases, possible. Implemented with expert oversight, our advanced interpretation methods incorporate automation,
5
Table of Contents
bioinformatics, and cloud-based machine learning, enabling efficient discovery of genetic differences at previously undetectable levels.
As the number of new patients we test grows, so does our database, as new data increases the potential for greater insights. As we capture more genomic and phenotypic data, we hope to fuel a positive feedback cycle of discovery that continuously delivers more value for patients, providers and healthcare partners.
Market Opportunity
Our primary growth engine in the short term will be expanding our current market-leading exome sequencing capabilities in the outpatient setting, including geneticists, pediatric development specialists, and other pediatric specialists, as well as the in-patient setting, also referred to as Neonatal Intensive Care Units (“NICU”). As we plan for longer-term growth, we believe there is a large data partnership opportunity with biopharmaceutical (“biopharma”) companies, international testing opportunities, as well as a market to provide interpretation and information services for customers that sequence locally but look to GeneDx for analysis and interpretation.
We believe we are particularly well-suited for helping rare disease and pediatric developmental disorder patients, their care teams and biopharma companies today. This is a large market with immense unmet medical need. There are nearly 7,000 individual diseases affecting nearly 10% of the total population in the United States, of which 50% are children. As a result, there are over 700 medicines in development for these diseases, with a regulatory pathway facilitated by the Orphan Drug Act of 1983. By providing the precise genetic diagnosis of patients with rare disease, our expertise and technology may provide researchers and biopharma companies with the information needed to develop and commercialize a new treatment for the disease.
Our longer-term growth strategy is the expansion into whole genome testing for Adult Disorders and Newborn Screening, supported with the launch of a new customer experience platform for non-geneticists, patients and caregivers, and evidence generation to establish the clinical and economic benefits of screening.
By unlocking the value of the products, our knowledge base, network of relationships, and expertise, our team is well positioned to lead what we believe is a nearly $30 billion global market opportunity.
Our Strategy
We believe that the span and depth of our experience and dataset allows us to return more positive findings and thus clinical utility both immediately and over time through reanalysis. Importantly, we believe that we return fewer uncertain findings compared to public data sets, which makes our analysis easier to interpret outside of the medical genetics community.
At the same time, we have improved quality and speed to delivery of exome and genome tests and have significantly lowered exome sequencing costs since 2013. Much of this decline was driven by reduced sequencing costs shared across the industry; however, we have reduced costs in the interpretation layer through accumulating data and experience, and we expect further decline in costs going forward.
Leveraging these capabilities, we aim to be the global market leader in the development and delivery of reliable, actionable, scalable exome and genome sequencing and interpretation and information services. Our strategy focuses on the following objectives:
• Expand the utilization of exome and genome sequencing as the first- or second-tier test over most other genetically targeted tests by leveraging decades of earned trust amongst expert geneticists; and
• Expand the utilization of industry-leading exome and genome sequencing beyond the genetic experts into the non-expert setting, potentially creating a new standard of care which enables faster diagnoses, reduces suffering, and helps healthcare systems save money. In the near term, our principal target markets will be settings with the most vulnerable patients who can benefit the most including, but not limited to, NICU and patients with Pediatric Developmental Disorders.
To achieve these objectives, we:
• Deploy our team of approximately 70 field-based sales representatives and medical science liaisons, and plan to construct an industry-leading brand, product, marketing, communications and market access platform by leveraging decades of earned trust across the genetics community.
• Partner with leaders across health systems, manufacturers, commercial and governmental payors and advocacy groups. We aim to collaborate on programs to establish definitive clinical and economic case for broad use of genomic-guided medicine. Such programs will focus on:
6
Table of Contents
◦ support for rapid whole genome sequencing in the NICU and Pediatric Developmental Disorder settings;
◦ diagnosis of disease and prevention of chronic conditions in adults; and
◦ use of rapid whole genome sequencing for broad newborn screening.
• Plan to open new markets and geographies and unlock the value of our dataset with independently scalable cloud-based interpretation and information service offerings. This will enable healthcare partners to incorporate genetics into clinical care by accessing our analysis and interpretation capabilities remotely while sequencing locally to reduce complexity, logistics cost and wait times, and align to local restrictions where applicable;
• Plan to launch a new provider and patient experience with the eventual goal of providing lifelong access and portability of genomic information. At initial sequence, rapid results provide clinicians simple, actionable, easy to understand results for non-geneticists and tailored resources for patients and caregivers. On an ongoing basis, reanalysis unlocks a renewable source of insight, replacing any future germline screening. We will sequence once, and analyze for life.
• Plan to optimize our services to become a solutions provider of choice for biopharma. Such solutions will focus on three value-added services:
◦ FIND: Finding rare disease patients for clinical trial recruitment and/or delivery of targeted therapeutics.
◦ UNDERSTAND: Supporting research and development for targeted therapies with analytic reports leveraging clinicogenomics data across multiple therapeutic areas with an initial emphasis in rare disease.
◦ PLATFORM: In the long term, providing a therapeutic area agnostic platform to access to data, patients and insights for real world evidence and data to support end-to-end drug discovery pipeline.
Research and Development
Our research and development activities include information technology, product development, customer experience, medical affairs, collaborations and research. These activities are principally focused on our efforts to develop and improve the software we use to analyze data, process genomic test orders, deliver reports, and improve customer experience.
We are also participating in certain collaborative studies aimed to provide evidence of the clinical and economic benefit for exome and whole genome sequencing. Two such studies currently underway include the SeqFirst study—in collaboration with Seattle Children’s Hospital and University of Washington—which is designed to demonstrate the broad utility of rapid whole genome sequencing for critically ill newborns and, the Genomic Uniform-Screening Against Rare Diseases In All Newborns (“GUARDIAN”) study—in collaboration with New York-Presbyterian, Columbia University, New York State Department of Health and Illumina—which is designed to assess whole genome sequencing to screen newborns for more conditions than those currently included in standard newborn screening in the United States. The goals of these studies are to drive earlier diagnosis and treatment to improve the health of the newborns who participate in such studies, generate evidence to support the expansion of newborn screening through genomic sequencing, and characterize the prevalence and natural history of rare genetic conditions.
Competition
Our competitors include companies that offer molecular genetic testing and consulting services, including specialty and reference laboratories that offer traditional single- and multi-gene tests and biopharmaceutical companies. In addition, there are a large number of new entrants into the market for genetic information ranging from informatics and analysis pipeline developers to focused, integrated providers of genetic tools and services for health and wellness, including Illumina, Inc., which is also one of our suppliers. In addition to the companies that currently offer traditional genetic testing services and research centers, other established and emerging healthcare, information technology and service companies may commercialize competitive products including informatics, analysis, integrated genetic tools and services for health and wellness. Principal competitors include companies such as Baylor, Centogene, Exact Sciences, Rady Children’s Hospital as well as other commercial and academic labs.
Customers and Seasonality
We receive payment for our products and services from third-party payors, patients, business-to-business clients, and from other healthcare partners. Substantially all of our revenue for the year ended December 31, 2023 has been primarily derived from diagnostic test reports and we expect this trend to continue in the near-term. We expect over time to achieve a mix of revenue from diagnostic tests, data and information solutions, newborn screening products and information and interpretation services.
Less than 5% of our revenues today are derived from referral sources outside of the United States. We expect over time to increase rest of world revenue as knowledge and understanding of the benefits of exome and whole genome sequencing continue to expand.
7
Table of Contents
We have historically experienced higher revenue in our fourth quarter compared to other quarters in our fiscal year due in part to seasonal demand of our tests from patients who have met their annual insurance deductible. However, changes in our product and payor mix might cause these historical seasonal patterns to be different than future patterns of revenue or financial performance.
For information regarding our customer concentration in relation to certain of the Company’s third-party payors, see Note 2, “ Summary of Significant Accounting Policies ” in the notes to our consolidated financial statements. We have experienced incrementally less concentration among third-party payors following the exits from reproductive health and somatic tumor testing in 2022.
Raw Materials and Suppliers
We rely on a limited number of suppliers, including Illumina, Inc., Integrated DNA Technologies Incorporated, Agilent Technologies, Roche Holdings Ltd., QIAGEN, Inc. and Twist Biosciences, for certain laboratory reagents, as well as sequencers and other equipment and materials, which we use in our laboratory operations. Our operations could be interrupted if we encounter delays or difficulties in securing reagents, sequencers or other equipment or materials, and if we cannot obtain an acceptable substitute. Any such interruption could significantly affect our business, financial condition, results of operations and reputation. We believe that there are only a few other manufacturers that are currently capable of supplying and servicing the equipment necessary for our operations, including sequencers and various associated reagents and enzymes. The use of equipment or materials provided by these replacement suppliers would require us to alter our operations. Transitioning to a new supplier would be time consuming and expensive, may result in interruptions in operations, could affect the performance specifications of our laboratory operations or could require that we revalidate our tests. We cannot be certain that we will be able to secure alternative equipment, reagents and other materials, or bring such equipment, reagents and materials online and revalidate them without experiencing interruptions in our workflow. If we encounter delays or difficulties in securing, reconfiguring or revalidating equipment and materials, our business and reputation could be adversely affected.
Intellectual Property
We rely on a combination of intellectual property rights, including trade secrets, copyrights, trademarks, customary contractual protections to protect our core technology and intellectual property.
Patents
The fields of genomic and health information analysis present limited opportunities for patent protection, based on current legal precedents. Our patent protection strategy has focused on seeking protection for certain of our non-gene specific technology and our specific biomarkers. In this regard, we have three pending U.S. non-provisional utility patent applications and one patent application pending in the European Patent Office. The utility patent applications include a U.S. patent application related to identifying cancer diagnosis from electronic health records using a cancer diagnosis analysis system, a U.S. patent application related to providing a homologous recombination DNA repair deficiency score for a cancer patient, and U.S. and European patent applications related to therapeutic treatment for subjects having certain polymorphic markers associated with specific human leukocyte antigen alleles. If patents are issued from the currently pending applications, the earliest patents will begin expiring in the early 2040s, subject to potential extensions of the patent term that will be calculated based on the length of the patent examination process. The claim scope of any potentially issued patents stemming from the present applications may be narrowed from initial filings due to any amendments that may arise throughout their prosecution.
We do not presently have any patents or patent applications directed to the sequences of specific genes or variants of such genes, nor do we currently rely on any in-licensed gene patent rights of any third party. We may, in time, seek additional patent protection to protect technology that is not gene-specific and that provides us with a potential competitive advantage as we focus on making comprehensive genetic information less expensive and more broadly available to our customers.
Trade secrets
We rely on trade secrets, including unpatented know-how, technology and other proprietary information, to maintain and develop our competitive position. We have a trade secrecy program to prevent disclosure of our trade secrets to others, except under stringent conditions of confidentiality when disclosure is critical to our business. We protect trade secrets and know-how by establishing confidentiality agreements and invention assignment agreements with our employees, consultants, scientific advisors, contractors, and collaborators. These agreements also provide that all inventions resulting from work performed for us or relating to our business and conceived or completed during the period of employment or assignment, as applicable, will be our exclusive property. In addition, we take other appropriate precautions, such as physical and technological security measures, to guard against misappropriation of our proprietary information by third parties.
8
Table of Contents
Our valuable trade secrets relate to proprietary bioinformatic tools such as:
• custom data processing methods and analytical pipelines for NGS, aCGH, MLPA, Sanger, and other genomic data, optimized and validated to the highest performance standards;
• a novel detection method to uncover notoriously difficult to detect sequence variants called mobile element insertions and partial-exon deletions; and
• custom variant analysis platforms built from the ground up for exome and genome-scale data interpretation.
Although we take steps to protect our proprietary information and trade secrets, including through contractual means with our employees and consultants, these steps may be circumvented, or third parties may independently develop substantially equivalent proprietary information and techniques or otherwise gain access to our trade secrets or disclose our technology. Accordingly, we may not be able to meaningfully protect our trade secrets.
Trademarks
We own or are applying for various trademarks, service marks, trade names, and product service names in the U.S and other commercially important markets. We intend to invest significant resources in the growth and protection of our reputation and trademarks. Our trademark portfolio is designed to protect the brands for our products and services, both current and in the pipeline.
Human Capital Resources
We aim to recruit, develop, and retain diverse, high-quality talent and are committed to creating a workplace that supports the success of its people by investing in their personal development and career growth. Our team of nearly 1,000 individuals are champions of not only our organization, but our patients, providers and partners.
Our values
Our values guide our interactions. Our model represents the interconnectedness of sometimes opposing values, where both are required to accomplish our mission. These values are:
• Bravery & Humility
• Openness & Accountability
• Equitability & Integrity
• Rigorous & Efficient Development
• Simplicity & Curiosity
Talent Development
We are committed to developing our workforce. Our talent development programs provide employees with the resources they need to achieve their career goals, build management skills and lead their teams. Managers coach and hold conversations with employees’ regarding their career and development plans, thereby staying true to our belief in accountability and openness.
Total Rewards
We offer competitive compensation to attract and retain high quality talent, and we care for our people so they can focus on our mission. Our employees' total compensation package includes competitive salary, bonuses or sales incentives, equity and a 401(K) plan with matching opportunities. Equity participation is provided for certain positions because ownership in the company drives commitment to our long-term success. We provide programs including healthcare and insurance benefits, health savings and flexible spending accounts, paid time off, family leave, flexible work schedules, fertility, adoption and surrogacy assistance, employee assistance and wellness support, among many others.
Government Regulation
Our business and the services (both current and in the pipeline) we provide are subject to and impacted by extensive and frequently changing laws and regulations in the United States (at both the federal and state levels) and internationally. Failure to comply with the applicable laws and regulations can subject us to repayment of amounts previously paid to us, significant civil and criminal penalties, loss of licensure, certification, or accreditation, or exclusion from state and federal health care programs. The significant areas of regulation are summarized below:
9
Table of Contents
Clinical Laboratory Improvement Amendments of 1988 and State Regulation
Our clinical laboratories must hold certain federal , state and local licenses, certifications and permits to conduct our business. Laboratories in the United States that perform testing on human specimens for the purpose of providing information for the diagnosis, prevention, or treatment of disease or impairment, or the assessment of health are subject to the Clinical Laboratory Improvement Amendments of 1988, as amended, and its implementing regulations (“CLIA”). CLIA requires such laboratories to be certified by the federal government and mandates compliance with various operational, personnel, facilities administration, inspections, quality control, quality assessment and proficiency testing requirements intended to ensure that testing services are accurate, reliable and timely. CLIA certification also is a prerequisite to be eligible to bill state and federal health care programs, as well as many commercial third-party payors, for laboratory testing services. Our laboratory located in Gaithersburg, Maryland is CLIA certified to perform high complexity tests. Laboratories performing high complexity testing are required to meet more stringent requirements than laboratories performing less complex tests. The regulatory and compliance standards applicable to the testing we perform may change over time, and any such changes could have a material effect on our business.
As a condition of CLIA certification, our laboratory is subject to survey and inspection every two years to assess compliance with program standards, in addition to being subject to additional random inspections. The biennial survey is conducted by the Centers for Medicare & Medicaid Services (“CMS”), a CMS agent (typically a state agency), or a CMS-approved accreditation organization. Our Gaithersburg laboratory has been accredited by the College of American Pathologists (“CAP”), which means that our laboratory has been certified as following CAP guidelines in operating the laboratory and in performing tests that ensure the quality of our results. Because our laboratory is accredited by CAP, which is a CMS-approved accreditation organization, CMS does not perform these biennial surveys and inspections and relies on our CAP surveys and inspections. We may also be subject to additional unannounced inspections.
CLIA provides that a state may adopt laboratory regulations that are not inconsistent with those under federal law, and a number of states have implemented their own (sometimes more stringent) laboratory regulatory requirements. CLIA does not preempt state laws that have established laboratory quality standards that are at least as stringent as the federal law requirements under CLIA. State laws may require that nonresident laboratories, or out-of-state laboratories, maintain a laboratory license to perform tests on samples from patients who reside in that state. As a condition of state licensure, these state laws may require that laboratory personnel meet certain qualifications, specify certain quality control procedures or facility requirements, or prescribe record maintenance requirements. We maintain state laboratory licenses for our Gaithersburg facility in Maryland, New York, California, Pennsylvania and Rhode Island. In addition to having a laboratory license in New York, our laboratory is also required to obtain approval on a test-specific basis for the tests it runs as laboratory developed tests (“LDTs”) by the New York Department of Health before specific testing is performed on samples from New York. If any states currently have or adopt similar licensure requirements in the future, we may be required to modify, delay or stop our operations in those states.
If a laboratory is out of compliance with state laws or regulations governing licensed laboratories or with CLIA, penalties may include suspension, limitation or revocation of the license or CLIA certificate, assessment of civil monetary penalties or fines, civil injunctive suit or criminal penalties. Failure to comply with CLIA could also result in a directed plan of correction and state on-site monitoring. Loss of a laboratory’s CLIA certificate or state license may also result in the inability to receive payments from state and federal health care programs as well as private third-party payors. We believe that we are in material compliance with CLIA and all applicable licensing laws and regulations.
CLIA and state laws and regulations, operating together, sometimes limit the ability of laboratories to offer consumer-initiated testing (also known as “direct access testing”). CLIA certified laboratories are permitted to perform testing only upon the order of an “authorized person,” defined as an individual authorized under state law to order tests or receive test results, or both. Many states do not permit persons other than licensed healthcare providers to order tests. We currently do not offer direct access testing and our CLIA tests may only be ordered by authorized healthcare providers.
Diagnostic Products and FDA Oversight of Laboratory Developed Tests
FDA Oversight of Laboratory Developed Tests
We provide our tests as LDTs. Under the FDA’s regulatory framework, in vitro diagnostic devices (IVDs) are a type of medical device, including tests that can be used in the diagnosis or detection of diseases, such as cancer, or other conditions. The FDA considers LDTs to be a subset of IVDs that are intended for clinical use and are designed, manufactured, and used within a single laboratory that is certified under CLIA. Such LDT testing is primarily under the purview of CMS and state agencies that provide oversight over clinical laboratory operations. Although the FDA has taken the position that it has statutory authority to assure that medical devices, including certain LDTs, are safe and effective for their intended use, the
10
Table of Contents
FDA has historically exercised enforcement discretion with respect to most LDTs and has not required laboratories that furnish LDTs to comply with the agency's requirements for medical devices (e.g., establishment registration, device listing, premarket clearance or approval, quality systems regulations, and post-market controls). In recent years, the FDA has stated it intends to end its policy of general enforcement discretion and regulate certain LDTs as medical devices. For example, in 2014 the FDA issued two draft guidance documents that set forth a proposed risk-based regulatory framework that would apply varying levels of FDA oversight to LDTs. These documents have not been finalized to date. Subsequently, in August 2020, the U.S. Department of Health and Human Services – the parent agency of the FDA – announced that the FDA will not require premarket review of LDTs absent notice-and-comment rulemaking, as opposed to through guidance documents and other informal issuances. In November 2021, the Biden Administration rescinded this policy. At this time, it is unclear when, or if, the FDA will finalize its plans to end enforcement discretion, and even then, the new regulatory requirements are expected to be phased-in over time. Nevertheless, the FDA may decide to regulate certain LDTs on a case-by-case basis at any time.
Legislative proposals addressing the FDA's oversight of LDTs have also been introduced in previous Congresses, and we expect that new legislative proposals will be introduced from time- to- time. For example, versions of the Verifying Accurate Leading-edge IVCT Development (“VALID”) Act have been introduced in Congress several times in recent years, but the VALID Act has not been enacted. The VALID Act, as most recently proposed, would create a new category of medical products separate from medical devices called “in vitro clinical tests,” or IVCTs. As most recently proposed, the VALID Act would modify the Federal Food, Drug, and Cosmetic Act (the “FDCA”) and establish a risk-based approach to imposing requirements related to premarket review, quality systems, and labeling requirements on all IVCTs, including LDTs, but a grandfathering provision would create exemptions from certain requirements for certain LDTs offered for clinical use within 45 days of enactment of the bill. The likelihood that Congress will pass such legislation and the extent to which such legislation may affect the FDA's plans to regulate certain LDTs as medical devices is difficult to predict at this time.
If the FDA ultimately regulates certain LDTs as medical devices, whether via final guidance, final regulation, or as instructed by Congress, our tests may be subject to certain additional regulatory requirements. Complying with the FDA's requirements for medical devices can be expensive, time-consuming, and subject us to significant or unanticipated delays. Insofar as we may be required to obtain premarket clearance or approval to perform or continue performing an LDT, we cannot be sure that we will be able to obtain such authorization. Even if we obtain regulatory clearance or approval where required, such authorization may not be for the intended uses that we believe are commercially attractive or are critical to the commercial success of our tests. As a result, the application of the FDA's oversight to our tests could materially and adversely affect our business, financial condition, and results of operations.
We will continue to monitor changes to all LDT regulatory policy so as to ensure compliance with the current regulatory scheme. The FDA in the course of enforcing the FDCA may subject a company to various sanctions for violating FDA regulations or provisions of the FDCA, including requiring recalls, issuing Warning Letters, seeking to impose civil money penalties, seizing devices that the agency believes are non-compliant, seeking to enjoin distribution of a specific device, seeking to revoke a clearance or approval, seeking disgorgement of profits and/or seeking to criminally prosecute a company and its officers and other responsible parties.
Additionally, certain of our diagnostic products in development may be subject to regulation by the FDA and similar international health authorities. For these products, we would have an obligation to adhere to the FDA’s current Good Manufacturing Practices (“cGMP”) and diagnostic product regulations, including providing for an establishment and product listing with the FDA. Additionally, we would be subject to periodic FDA inspections, quality control procedures, and other detailed validation procedures. If the FDA finds deficiencies in the validation of our manufacturing and quality control practices, it may impose restrictions on marketing specific products until corrected. Regulation by governmental authorities in the U.S. and other countries may be a significant factor in how we develop, test, produce and market our diagnostic test products.
Corporate Practice of Medicine
Numerous states prohibit business organizations from practicing medicine or employing or engaging physicians to practice medicine, which prohibitions are generally referred to as the prohibition against the corporate practice of medicine. These laws are intended to prevent interference in the medical decision-making process by anyone who is not a licensed physician. For example, California's Medical Board has indicated that determining what diagnostic tests are appropriate for a particular condition and taking responsibility for the ultimate overall care of the patient, including providing treatment options available to the patient, would constitute the unlicensed practice of medicine if performed by an unlicensed person. Violation of these corporate practice of medicine prohibitions may result in civil or criminal fines, as well as sanctions imposed against us and/or the professional through licensure proceedings.
11
Table of Contents
Other Regulatory Requirements
We are subject to laws and regulations related to the protection of the environment, the health and safety of employees and the handling, transportation and disposal of regulated medical waste, hazardous waste and biohazardous waste, including chemical, biological agents and compounds, blood and bone marrow samples and other human tissue, and radioactive materials. For example, the U.S. Occupational Safety and Health Administration (“OSHA”) has established extensive requirements relating specifically to workplace safety for healthcare employers in the United States. For purposes of transportation, some biological materials and laboratory supplies are classified as hazardous materials and are subject to regulation by one or more of the following: the U.S. Department of Transportation, the U.S. Public Health Service, the U.S. Postal Service, the Office of Foreign Assets Control and the International Air Transport Association. We generally use third-party vendors to dispose of regulated medical waste, hazardous waste and radioactive materials and contractually require them to comply with applicable laws and regulations. These vendors are licensed or otherwise qualified to handle and dispose of such wastes.
Federal and State Healthcare Fraud & Abuse Laws
Federal and State Physician Self-Referral Prohibitions
We are subject to the federal physician self-referral prohibitions, commonly known as the Stark Law. These restrictions generally prohibit a physician who has (or whose immediate family member has) a financial relationship, such as an ownership or investment interest in or compensation arrangement with us, from making referrals for “designated health services”, including clinical laboratory services, if payment for the services may be made under Medicare. If such a financial relationship exists, referrals are prohibited unless a statutory or regulatory exception applies. The Stark Law also prohibits us from billing for any such prohibited referral. These prohibitions apply regardless of any intent by the parties to induce or reward referrals or the reasons for the financial relationship and the referral. Several Stark Law exceptions are relevant to many common financial relationships involving clinical laboratories and referring physicians and may be relied upon if all of the elements of the applicable exception are satisfied. Penalties for violating the Stark Law include the return of funds received for all prohibited referrals, fines, civil monetary penalties and possible exclusion from federal health care programs. In addition, violations of the Stark Law may also serve as the basis for liability under the federal False Claims Act (the “FCA”), which can result in additional civil and criminal penalties. Several states have enacted comparable self-referral laws which may be broader in scope and apply regardless of payor.
Federal and State Anti-Kickback Laws
The federal Anti-Kickback Statute (the “AKS”), makes it a felony for a person or entity, including a clinical laboratory, to, among other things, knowingly and willfully offer, pay, solicit or receive any remuneration, directly or indirectly, overtly or covertly, in cash or in kind, in order to induce or reward either the referral of an individual for, or the purchase, order or recommendation of, any good or service, for which payment may be made under federal health care programs. The government may also assert that a claim that includes items or services resulting from a violation of the AKS constitutes a false or fraudulent claim under the FCA, which is discussed in greater detail below. Additionally, a person or entity does not need to have actual knowledge of the statute or specific intent to violate it in order to have committed a violation. Although the AKS applies only to items and services reimbursable under any federal health care program, a number of states have passed statutes substantially similar to the AKS that apply to all payors or to state program payors. Penalties for violations of such laws include imprisonment and significant monetary fines and, in the case of the AKS, exclusion from federal health care programs. Federal and state law enforcement authorities scrutinize arrangements between health care providers and potential referral sources to ensure that the arrangements are not designed as a mechanism to induce patient care referrals or induce the purchase or prescribing of particular products or services. Generally, courts have taken a broad interpretation of the scope of the AKS, holding that the statute may be violated if merely one purpose of a payment arrangement is to induce referrals or purchases. In addition to statutory exceptions to the AKS, regulations provide for a number of safe harbors. If an arrangement meets the conditions of an applicable exception or safe harbor, it is deemed not to violate the AKS. An arrangement must fully meet each condition of an applicable exception or safe harbor in order to qualify for protection. Failure to meet the conditions of a safe harbor, however, does not render an arrangement illegal. Rather, the government may evaluate such arrangements on a case-by-case basis, taking into account all facts and circumstances.
In addition, the federal Eliminating Kickbacks in Recovery Act (the “EKRA”), prohibits knowingly and willfully soliciting or receiving any remuneration (including any kickback, bribe or rebate) directly or indirectly, overtly or covertly, in cash or in kind, in return for referring a patient or patronage to a laboratory; or paying or offering any remuneration (including any kickback, bribe or rebate) directly or indirectly, overtly or covertly, in cash or in kind, to induce a referral of an individual to a laboratory and certain other entities or in exchange for an individual using the services of such entities. The EKRA applies to all payors including commercial payors and government payors, and EKRA violations result in significant fines and/or up
12
Table of Contents
to 10 years in jail, separate and apart from existing AKS liability. Several EKRA exceptions are relevant to many common financial relationships involving clinical laboratories and may be relied upon if all of the elements of the applicable exception are satisfied. Failure to meet the requirements of an exception, however, does not render an arrangement illegal. Rather, the government may evaluate such arrangements on a case-by-case basis, taking into account all facts and circumstances.
Other Federal and State Fraud & Abuse Healthcare Laws
In addition to the requirements discussed above, several other health care fraud and abuse laws could have an effect on our business.
The FCA prohibits, among other things, a person from knowingly presenting, or causing to be presented, a false or fraudulent claim for payment or approval and from, making, using, or causing to be made or used, a false record or statement material to a false or fraudulent claim in order to secure payment or retaining an overpayment by the federal government. Under the FCA, a person acts knowingly if he or she has actual knowledge of the information or acts in deliberate ignorance or in reckless disregard of the truth or falsity of the information. Specific intent to defraud is not required. FCA violations can result in penalties of up to three times the actual damages sustained by the government, plus civil penalties for each false claim. In addition to actions initiated by the government itself, the statute authorizes actions to be brought on behalf of the federal government by a private party having knowledge of the alleged fraud. Because the complaint is initially filed under seal, the action may be pending for some time before the defendant is even aware of the action. If the government intervenes and is ultimately successful in obtaining redress in the matter or if the plaintiff succeeds in obtaining redress without the government’s involvement, then the plaintiff will receive a percentage of the recovery. Several states have enacted comparable false claims laws which may be broader in scope and apply regardless of payor.
The Social Security Act includes civil monetary penalty provisions that impose penalties against any person or entity that, among other things, is determined to have presented or caused to be presented a claim to a federal health program that the person knows or should know is for an item or service that was not provided as claimed or is false or fraudulent. Several states have enacted comparable laws which may be broader in scope and apply regardless of payor. In addition, a person who offers or provides to a Medicare or Medicaid beneficiary any remuneration, including waivers of co-payments and deductible amounts (or any part thereof), that the person knows or should know is likely to influence the beneficiary’s selection of a particular provider, practitioner or supplier of Medicare or Medicaid payable items or services may be liable under the civil monetary penalties law. Moreover, in certain cases, providers who routinely waive copayments and deductibles for Medicare and Medicaid beneficiaries, can also be held liable under the civil monetary penalty provisions and certain other laws, such as the AKS and FCA. One of the statutory exceptions to the civil monetary penalty prohibition is non-routine, unadvertised waivers of copayments or deductible amounts based on individualized determinations of financial need or exhaustion of reasonable collection efforts. The Office of Inspector General of the U.S. Department of Health and Human Services (“HHS”), emphasizes, however, that this exception should only be used occasionally to address special financial needs of a particular patient. States may have similar prohibitions.
Other Federal and State Healthcare Laws
In addition to the fraud and abuse laws discussed above, our business potentially is subject to the following additional healthcare regulatory laws:
Laws Governing Genetic Counseling Services
Our genetic counseling partner may provide services via electronic means that could subject it to various federal, state and local certification and licensing laws, regulations and approvals, relating to, among other things, the adequacy of health care, the practice of medicine and other health professions (including the provision of remote care and cross-coverage practice), equipment, personnel, operating policies and procedures and the prerequisites for ordering laboratory tests. Some states have enacted regulations specific to providing services to patients via telehealth. Such regulations include, among other things, informed consent requirements that some states require providers to obtain from their patients before providing telehealth services. Health professionals who provide professional services using telehealth modalities must, in most instances, hold a valid license to practice the applicable health profession in the state in which the patient is located. In addition, certain states require a physician providing telehealth to be physically located in the same state as the patient. Any failure to comply with these laws and regulations could result in civil or criminal penalties against telehealth providers.
Clinical and Human Subjects Research Regulations
We may collaborate or support ongoing clinical or other human subjects research that could subject us to a number of laws and regulations pertaining to such research, including, but not limited to the Federal Policy for Protection of Human Subjects (as set forth in the implementing regulations of any signatory federal department or agency), the FDCA and its applicable
13
Table of Contents
implementing regulations at 21 C.F.R. Parts 11, 50, 54, 56, 58 and 812 and all equivalent legal requirements in other jurisdictions.
Privacy and Security Laws
Health Insurance Portability and Accountability Act
Under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), as amended by the Health Information Technology for Economic and Clinical Health Act (“HITECH”), HHS has issued regulations to protect the privacy and provide for the security of protected health information (“PHI”) used or disclosed by covered entities, including most health care providers and their respective business associates, as well as the business associates’ subcontractors. HIPAA also regulates standardization of data content, codes, and formats used in certain health care transactions and standardization of identifiers for health plans and providers. Four principal regulations with which we are required to comply have been issued in final form under HIPAA and HITECH: privacy regulations, security regulations, breach notification regulations, and standards for electronic transactions, which establish standards for common healthcare transactions.
The privacy regulations cover the use and disclosure of PHI by covered entities as well as business associates, which are persons or entities that perform certain functions for or on behalf of a covered entity that involve the creation, receipt, maintenance, or transmission of PHI. Business associates are defined to include a subcontractor to whom a business associate delegates a function, activity, or service, other than in the capacity of the business associate’s workforce. As a general rule, a covered entity or business associate may not use or disclose PHI except as permitted or required under the privacy regulations. The privacy regulations also set forth certain rights that an individual has with respect to his or her PHI maintained by a covered entity or business associate, including the right to access or amend certain records containing his, her or their PHI, request restrictions on the use or disclosure of his, her or their PHI, or request an accounting of disclosures of his or her PHI.
Covered entities and business associates also must comply with the security regulations, which establish requirements for safeguarding the confidentiality, integrity, and availability of PHI that is electronically transmitted or electronically stored. In addition, HITECH, among other things, established certain PHI breach notification requirements with which covered entities and business associates must comply. In particular, a covered entity must notify any individual whose unsecured PHI is breached according to the specifications set forth in the breach notification rule. A covered entity must also notify the Secretary of HHS and, under certain circumstances, the media of a breach of unsecured PHI.
The HIPAA privacy, security, and breach notification regulations establish a uniform federal “floor” and do not preempt state laws that are more stringent or provide individuals with greater rights with respect to the privacy or security of, and access to, their records containing PHI or insofar as such state laws apply to personal information that is broader in scope than PHI. In addition, individuals (or their personal representatives, as applicable) generally have the right to access test reports directly from laboratories and to direct that copies of those reports be transmitted to persons or entities designated by the individual.
HIPAA authorizes state attorneys general to file suit on behalf of their residents for violations. Courts are able to award damages, costs, and attorneys’ fees related to violations of HIPAA in such cases. While HIPAA does not create a private right of action allowing individuals to file suit against us in civil court for violations of HIPAA, its standards have been used as the basis for duty of care cases in state civil suits such as those for negligence or recklessness in the misuse or breach of PHI. In addition, violations of HIPAA could result in significant penalties imposed by the HHS’s Office for Civil Rights. HIPAA also mandates that the Secretary of HHS conduct periodic compliance audits of HIPAA covered entities, such as us, and their business associates for compliance with the HIPAA privacy and security standards. It also tasks HHS with establishing a methodology whereby harmed individuals who were the victims of breaches of unsecured PHI may receive a percentage of the civil monetary penalty paid by the violator.
Further, there are a number of state laws regarding the privacy and security of health information and personal data that are applicable to our clinical laboratories. We believe that we have taken the steps required of us to comply with health information privacy and security statutes and regulations in all jurisdictions, both state and federal, and we intend to continue to comprehensively protect all personal information and to comply with all applicable laws regarding the protection of such information. However, these laws constantly change, and we may not be able to maintain compliance in all jurisdictions where we do business. Failure to maintain compliance, including in connection with changes in state or federal laws regarding privacy or security, could result in civil and/or criminal penalties as well as significant reputational damage and could also have a material adverse effect on our business.
14
Table of Contents
California Consumer Privacy Act
The California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CPRA,” and together with the California Consumer Privacy Act, the “CCPA”), confers to California consumers, among other things, the right to receive notice of the categories of personal information that will be collected by a business, how the business will use and share the personal information, and the categories of third parties who will receive the personal information. The CCPA also confers rights to access, delete, correct, or request a portable data set, the right to limit processing of “sensitive personal information,” and the right to receive equal service and pricing from a business after exercising a consumer right granted by the CCPA. In addition, the CCPA allows California consumers the right to opt out of the “sale” of their personal information, which the CCPA defines broadly as any disclosure of personal information to a third party in exchange for monetary or other valuable consideration. The CCPA also allows California consumers to opt out of the “sharing” of information, which restricts a company’s use of personal information for cross-context behavioral advertising. The CCPA also requires a business to implement reasonable security procedures to safeguard personal information against unauthorized access, use, or disclosure and imposes purpose limitation, data minimization, data retention and other security compliance obligations on regulated businesses. The CCPA requires businesses to include specific provisions in contracts with third parties that process data on a business’s behalf regarding the third party’s processing and management of such data.
The CCPA does not apply to personal information that is PHI under HIPAA and that is collected by a business associate or covered entity under HIPAA. The CCPA also exempts patient information that is processed by a covered entity and maintained in the same manner as PHI. Accordingly, the CCPA will not apply to much of the genetic testing and patient information we collect and process. However, we are required to comply with the CCPA insofar as we collect other categories of California consumers’ personal information, such as information about California-based employees, contractors, business contacts and website visitors.
The CCPA is enforceable through administrative fines of up to $2,500 for each violation, or $7,500 for intentional violations or where we have actual knowledge that the personal information relates to an individual under 16 years of age.
In addition to the CCPA, four new state privacy laws went into effect in 2023, including the Virginia Consumer Data Protection Act, the Utah Consumer Privacy Act, the Colorado Privacy Act, and the Connecticut Personal Data Privacy and Online Monitoring Act. In 2023, seven other states passed comprehensive consumer data privacy laws, and many others have introduced similar consumer privacy laws. These new state privacy laws and any potential federal consumer privacy law will and would impose additional data protection obligations on covered businesses, including additional consumer rights, limitations on data uses, new audit requirements for higher risk data and opt outs for certain uses of sensitive data. The new and proposed privacy laws may result in further uncertainty and may require us to incur additional expenditures to comply. These regulations and legislative developments have potentially far-reaching consequences and may require us to modify our data management and data use practices and incur substantial compliance expense. Our failure to comply with applicable laws and regulations or other obligations to which we may be subject relating to personal data, or to protect personal data from unauthorized access, use, or other processing, could result in enforcement actions and regulatory investigations against us, claims for damages by customers and other affected individuals, fines, damage to our reputation, and loss of goodwill, any of which could have a material adverse effect on our operations, financial performance, and business.
Genetic Privacy and Testing Laws
We are subject to myriad laws that require us to establish safeguards for the conduct of genomic testing and analysis and to protect against the misuse of genetic information and human biological specimens (“samples”) from which genetic information can be derived. These laws vary in their scope and in the nature of their requirements and restrictions. For example, certain genetic privacy laws prohibit the retention of samples after performing a genomic analysis and prohibit the collection, use or disclosure of genetic information or samples for certain purposes, such as research, without appropriate informed consent from the individual or unless the genetic information or samples are appropriately de-identified. Other laws may impose additional requirements, including requirements regarding institutional review board review and approval for certain research uses of genetic information or samples or requirements to implement certain security controls in connection with the transfer of genetic information. We must comply with such genetic privacy and testing laws in our collection, use, disclosure and retention of genetic information and samples.
Other Data Protection Laws
There are a growing number of jurisdictions around the globe that have privacy and data protection laws that may apply to us as we enter or expand our business in jurisdictions outside of the U.S. These laws are typically triggered by a company’s establishment or physical location in the jurisdiction, data processing activities that take place in the jurisdiction, and/or the processing of personal information about individuals located in that jurisdiction that are targeted, for example, by an offer of
15
Table of Contents
goods or services. Certain data protection laws, such as those in the European Union, (the “EU”) and United Kingdom, are comprehensive in nature and include significant requirements around the processing of personal information, while other jurisdictions may have laws less restrictive or prescriptive than those in the U.S. Enforcement of these laws varies from jurisdiction to jurisdiction, with a variety of consequences, including civil or criminal penalties, litigation private rights of action, or damage to our reputation.
For example, the EU’s General Data Protection Regulation (“GDPR”), including as implemented and amended through the UK Data Protection Act 2018 (“UK GDPR”), applies to any data collection, use and sharing in the context of an establishment in the EU or UK as well as extraterritorially to any entity outside the EU and UK when they process personal information related to an offer of goods or services to, or monitoring the behavior of, individuals who are located in the EU or UK. The GDPR and UK GDPR impose requirements on controllers and processors of personal data, including when personal information is transferred outside of the EU or the UK to another country and enhanced protections for “special categories” of personal data, which include sensitive information such as health and genetic information of data subjects. The GDPR and UK GDPR also grant individuals various rights in relation to their personal data including the rights of access, rectification, objection to certain processing and deletion. The GDPR and UK GDPR provide an individual with an express right to seek legal remedies if the individual believes his or her rights have been violated. Failure to comply with the requirements of the GDPR or the related national data protection laws of the member states of the EU, which may deviate from or be more restrictive than the GDPR, or a failure to comply with the UK GDPR may result in significant administrative fines issued by EU or UK regulators.
Information Blocking Prohibition
On May 1, 2020, the Office of the National Coordinator for Health Information Technology promulgated final regulations under the authority of the 21st Century Cures Act to impose new conditions to obtain and maintain certification of certified health information technology and prohibit certain covered actors, including developers of certified health information technology, health information networks/health information exchanges, and health care providers, from engaging in activities that are likely to interfere with the access, exchange, or use of electronic health information (information blocking). The final regulations further defined exceptions for activities that are permissible, even though they may have the effect of interfering with the access, exchange, or use of electronic health information. The information blocking regulations became effective on April 5, 2021. Under the 21st Century Cures Act, health care providers that violate the information blocking prohibition will be subject to appropriate disincentives, which the HHS has yet to establish through required rulemaking. Developers of certified information technology and health information networks/health information exchanges, however, may be subject to civil monetary penalties of up to $1 million per violation. The HHS Office of Inspector General has the authority to impose such penalties and on April 24, 2020, published a proposed rule to codify new authority in regulation, which the agency proposed would be effective 60 days after it issues a final rule but in no event before November 2, 2020. The HHS Office of Inspector General has not yet issued a final rule.
Federal and State Consumer Protection Laws
The Federal Trade Commission (the “FTC”) is an independent U.S. law enforcement agency charged with protecting consumers and enhancing competition across broad sectors of the economy. The FTC’s primary legal authority with respect to data privacy and security comes from Section 5 of the FTC Act, which prohibits unfair or deceptive acts or practices in the marketplace. The FTC has increasingly used this broad authority to police data privacy and security, using its powers to investigate and bring lawsuits. Where appropriate, the FTC can seek a variety of remedies, such as but not limited to requiring the implementation of comprehensive privacy and security programs, biennial assessments by independent experts, monetary redress to consumers, and provision of robust notice and choice mechanisms to consumers. In addition to its enforcement mechanisms, the FTC uses a variety of tools to protect consumers’ privacy and personal information, including pursuing enforcement actions to stop violations of law, conducting studies and issuing reports, hosting public workshops, developing educational materials and testifying before the U.S. Congress on issues that affect consumer privacy. Recently, the FTC has issued guidance emphasizing that their authority to prevent unfair or deceptive acts or practices extends to advertising and marketing claims for health care and health-related products.
The majority of data privacy cases brought by the FTC fall under the “deceptive” acts prong of Section 5. These cases often involve a failure on the part of a company to adhere to its own privacy and data protection principles set forth in its policies or other statements made to consumers. To avoid Section 5 violations, the FTC encourages companies to build privacy protections and safeguards into relevant portions of their business, and to consider privacy and data protection as the company grows and evolves. In addition, privacy notices should clearly and accurately disclose the type(s) of personal information the company collects, how the company uses and shares that information, and the security measures used by the company to protect that information.
16
Table of Contents
In recent years, the FTC’s enforcement under Section 5 related to data security has included alleged violations of the “unfairness” prong. Many of these cases have alleged that companies were unfair to consumers because they failed to take reasonable and necessary measures to protect consumer data. The FTC has not provided bright line rules defining what constitutes “reasonable and necessary measures” for implementing a cybersecurity program, but it has provided guidance, tips and advice for companies. The FTC has also published past complaints and consent orders, which it urges companies use as guidance to help avoid an FTC enforcement action, even if a data breach or loss occurs.
In addition to the FTC Act, most U.S. states have unfair and deceptive acts and practices statutes, known as Unfair Deceptive Acts and Practices ("UDAP") statutes, that substantially mirror the FTC Act and have been applied in the privacy and data security context. These vary in substance and strength from state to state. Many have broad prohibitions against unfair and deceptive acts and practices. These statutes generally allow for private rights of action and are enforced by the states’ Attorneys General.
Reimbursement and Billing
In April 2014, Congress passed the Protecting Access to Medicare Act of 2014 (“PAMA”), which included substantial changes to the way in which clinical laboratory services are paid under Medicare. Under PAMA (as amended) and its implementing regulations, laboratories that realize at least $12,500 in Medicare Clinical Laboratory Fee Schedule (“CLFS”) revenues during the six month reporting period and that receive the majority of their Medicare revenue from payments made under the CLFS or the Physician Fee Schedule must report, beginning in 2017, and then in 2024 and every three years thereafter (or annually for “advanced diagnostic laboratory tests”), private payor payment rates and volumes for their tests. None of our tests meet the current definition of advanced diagnostic laboratory tests, and therefore we believe we are required to report private payor rates for our tests on an every-three-years basis, starting next in 2024. CMS uses the rates and volumes reported by laboratories to develop Medicare payment rates for the tests equal to the volume-weighted median of the private payor payment rates for the tests. Laboratories that fail to report the required payment information may be subject to substantial civil money penalties.
As set forth under the regulations implementing PAMA, for tests furnished on or after January 1, 2018, Medicare payments for clinical diagnostic laboratory tests are paid based upon these reported private payor rates. For clinical diagnostic laboratory tests that are assigned a new or substantially revised code, initial payment rates for clinical diagnostic laboratory tests that are not advanced diagnostic laboratory tests will be assigned by the cross-walk or gap-fill methodology, as under prior law. Initial payment rates for new advanced diagnostic laboratory tests will be based on the actual list charge for the laboratory test.
The payment rates calculated under PAMA went into effect starting January 1, 2018. Where applicable, reductions to payment rates resulting from the new methodology were limited to 10% per test per year in each of the years 2018 through 2020. Rates were held at 2020 levels during 2021 and 2022 and will continue to be held at such levels in 2023. Then, where applicable based upon median private payor rates reported in 2017 or 2024, reduced by up to 15% per test per year in each of 2024 through 2026 (with a second round of private payor rate reporting in 2024 to establish rates for 2025 through 2027).
PAMA codified Medicare coverage rules for laboratory tests by requiring any local coverage determination to be made following the local coverage determination process. PAMA also authorizes CMS to consolidate coverage policies for clinical laboratory tests among one to four laboratory-specific Medicare Administrative Contractors (“MACs”). These same contractors may also be designated to process claims if CMS determines that such a model is appropriate. It is unclear whether CMS will proceed with contractor consolidation under this authorization.
PAMA also authorized the adoption of new, temporary billing codes and/or unique test identifiers for FDA-cleared or approved tests as well as advanced diagnostic laboratory tests. The American Medical Association has created a section of billing codes, Proprietary Laboratory Analyses (“PLA”), to facilitate implementation of this section of PAMA. These codes may apply to one or more of our tests if we apply for PLA coding.
Reimbursement and billing for diagnostic services is highly complex, and errors in billing potentially can result denied claims and/or in substantial obligations to repay overpayments to payors. Laboratories must bill various payors, such as private third-party payors, including managed care organizations (“MCO”), and state and federal health care programs, such as Medicare and Medicaid, and each may have different billing requirements. Additionally, the audit requirements we must meet to ensure compliance with applicable laws and regulations, as well as our internal compliance policies and procedures, add further complexity to the billing process. Other factors that complicate billing include:
• variability in coverage and information requirements among various payors;
• patient financial assistance programs;
17
Table of Contents
• missing, incomplete or inaccurate billing information provided by ordering physicians;
• billings to payors with whom we do not have contracts;
• disputes with payors as to which party is responsible for payment; and
• disputes with payors as to the appropriate level of reimbursement.
Depending on the reimbursement arrangement and applicable law, the party that reimburses us for our services may be:
• a third party who provides coverage to the patient, such as an insurance company or MCO;
• a state or federal healthcare program; or
• the patient.
Available Information
We make our annual reports on Form 10-K, quarterly reports on Form 10-Q, current reports on Form 8-K and amendments to these reports, as well as our other SEC filings, available on our website, free of charge, as soon as reasonably practicable after they are electronically filed with or furnished to the SEC. Our website address is www.genedx.com. The information contained on our website is not incorporated by reference in this document.
18
Table of Contents