Fiscal period ending 2025-12-31 versus 2024-12-31
— view filing on EDGAR →
Cybersecurity risk concretized via the Change Healthcare incident, confirming supply-chain exposure as an operational reality rather than a theoretical threat. Offsetting this, the court vacatur of the Final RADV Rule materially reduces near-term compliance and financial risk, though the government's appeal preserves residual uncertainty. Net picture is modestly mixed with no severe or pervasive shift in either direction.
1 company-specific
· 1 eased/removed
Company-specific changes
Revised
Added concrete example of Change Healthcare February 2024 incident affecting company operations, demonstrating realized cybersecurity risk materialized in supply chain.
If we, and the third-party service providers on whom we rely, are unable to defend our information technology systems against cybersecurity attacks, contain such attacks when they occur, or prevent…
Eased / removed
Revised
Court vacated Final RADV Rule on APA grounds; government appealing. Materially reduces near-term regulatory risk despite pending appeal.
As a government contractor, we are exposed to risks that may materially adversely affect our business or our willingness or ability to participate in government health care programs. A significant…