Item 1A. Risk Factors
17K characters. Original on sec.gov · Markdown
Item 1A. Risk Factors
Our significant business risks are described in Item 1A to Form 10-K for the fiscal year ended September 30, 2022 to which reference is made herein. The information presented below describes updates and additions to such risk factors and should be read in conjunction with the risk factors and information disclosed in our Form 10-K.
Business and Operational Risks
Our results of operations and financial condition may be adversely affected if we undertake acquisitions of or investments in businesses that do not perform as we expect or that are difficult for us to integrate.
As part of our strategy we seek to pursue acquisitions of and investments in other companies. At any particular time, we may be in various stages of assessment, discussion, and negotiation with regard to one or more potential acquisitions or investments, not all of which will be consummated. We make public disclosure of pending and completed acquisitions when appropriate and required by applicable securities laws and regulations. On June 1, 2021, we completed our acquisition of Alliance Healthcare from WBA for $5,596.7 million in net cash, $229.1 million of our common stock, and $6.1 million of other equity consideration. On January 1, 2023, we completed our acquisition of PharmaLex Holding GmbH (“PharmaLex”) from AUCTUS Capital Partners AG for $1.473 billion in cash, which includes cash acquired and a cash holdback. Alliance Healthcare and PharmaLex operate in the United Kingdom, Germany, a number of other countries in the European Union, and in select other markets. On April 20, 2023, we announced our intent to acquire OneOncology (“OneOncology”) through a joint venture with TPG, a global alternative asset management firm, in which we committed to purchase an approximately 35% minority equity interest in OneOncology for approximately $685 million in cash. The OneOncology transaction is expected to close by the end of September 2023, and is subject to the satisfaction of customary closing conditions, including receipt of required regulatory approvals.
We may find that our ability to integrate and control Alliance Healthcare and PharmaLex is more difficult, time consuming or costly than expected, especially in certain countries where our investment is not wholly-owned, such as our 50%-owned Alliance Healthcare Egypt subsidiary. Each of Alliance Healthcare, PharmaLex and OneOncology may fail to achieve its expected future financial and operating performance and results and the transactions may have the effect of disrupting relationships with employees, suppliers, and other business partners.
Acquisitions involve numerous risks and uncertainties and may be of businesses or in regions in which we lack operational or market experience. Acquired companies may have business practices that we are not accustomed to or have unique terms and conditions with their business partners. As a result of the acquisition of Alliance Healthcare, PharmaLex and other future acquisitions or investments, including OneOncology, our results of operations and financial condition may be adversely affected by a number of factors, including: regulatory or compliance issues that could arise; changes in regulations and laws; the failure of the acquired businesses to achieve the results we have projected in either the near or long term; the assumption of unknown liabilities, including litigation risks; the fair value of assets acquired and liabilities assumed not being properly estimated; the difficulties of imposing adequate financial and operating controls on the acquired companies and their management and the potential liabilities that might arise pending the imposition of adequate controls; the difficulties in the integration of the operations, technologies, services and products of the acquired companies; and the failure to achieve the strategic objectives of these acquisitions.
Our businesses operate in a number of jurisdictions, including Egypt and other locations, that have a higher business, operating and regulatory risk profile than the United States and European Union jurisdictions. Such risks may include risks of violation of United States, United Kingdom and other anti-corruption, anti-bribery and international trade laws. Our results of operations and financial condition may be adversely affected if we are not able to effectively put in place effective financial controls and compliance policies to safeguard against such risks as part of our integration of businesses, including Alliance Healthcare and PharmaLex.
We are subject to operational and logistical risks that might not be covered by insurance.
We have distribution centers and facilities located in the United States, the United Kingdom, the European Union and throughout the world. Our business exposes us to risks that are inherent in the distribution of pharmaceuticals and the provision of related services, including cold chain storage and shipping. The volume of cold chain storage and shipping has increased in part due to the COVID-19 pandemic and the requirements for distribution of COVID-19 vaccines and certain treatments. We
expect this trend to continue. Although we seek to maintain adequate insurance coverage, coverage on acceptable terms might be unavailable, coverage might not cover our losses, coverage might be significantly more costly or may require large deductibles.
Additionally, we seek to maintain coverage for risks associated with cybersecurity, but such insurance has become increasingly difficult to secure, comes with increasingly high self-insured retentions and, in some cases, policies may not provide adequate coverage for possible losses. Further, both as a result of a cybersecurity event one of our foreign business units experienced in March 2023 and industry trends generally, we may incur higher costs for future cybersecurity insurance coverage. Uninsured losses or operational losses that result from large deductible payments under commercial insurance coverage might have an adverse impact on our business operations and our financial position or results of operations.
Litigation and Regulatory Risks
Our actual or perceived failure to adequately protect personal data could result in claims of liability against us, damage our reputation or otherwise materially harm our business.
Given the nature of our business, we, together with third parties acting on our behalf, receive, collect, process, use, and retain sensitive and confidential customer and employee data, in addition to proprietary business information. Some of our third-party service providers, such as identity verification and payment processing providers, also regularly have access to customer data. Additionally, we maintain other confidential, proprietary, or otherwise sensitive information relating to our business and from third parties.
Global privacy, cybersecurity and data protection-related laws and regulations are evolving, extensive, and complex. Compliance with these laws and regulations is difficult and costly. The interpretation and application of these laws in some instances is uncertain, and our legal and regulatory obligations are subject to frequent changes. We are required to comply with increasingly complex and changing data privacy regulations both in the United States and beyond that regulate the collection, use, security, processing, and transfer of personal data, including particularly the transfer of personal data between or among countries. Many of these regulations also grant rights to individuals. Many foreign data privacy regulations (including, without limitation, GDPR in the European Union, UK GDPR, Brazil’s General Data Protection Law, LGPD, and the Personal Information Protection and Electronic Documents Act in Canada) and certain state laws and regulations (including California’s CCPA and recently enacted consumer privacy laws in Colorado, Connecticut, Utah, and Virginia) impose requirements beyond those enacted under United States federal law including, in some instances, private rights of action. For example, the EU GDPR imposes more stringent data protection requirements, including a broader scope of protected data, restrictions on cross-border transfers of personal data and more onerous breach reporting requirements, and the EU GDPR imposes greater penalties for non-compliance than the federal data protection laws in the United States. Other states and countries continue to enact similar legislation. We are also required to comply with expanding and increasingly complex cybersecurity regulations in the United States and abroad with respect to reporting adverse events and additional requirements for avoiding or responding to an adverse event. We may also face audits or investigations by domestic or foreign government agencies relating to our compliance with these regulations. An adverse outcome under any such investigation or audit could subject us to fines or other penalties. We also have contractual obligations to our customers related to the protection of personal data and compliance with privacy laws.
Despite the security measures we have in place to ensure compliance with applicable laws and rules, our facilities and systems, and those of our third-party service providers, may be vulnerable to security breaches, acts of cyber terrorism, vandalism or theft, computer viruses, misplaced or lost data, programming and/or human errors or other similar events. A party who is able to compromise the security measures of our networks, or those of our third-party service providers, could misappropriate either proprietary business information or the personal information of our customers or employees. In March 2023, one of the Company’s foreign business units experienced a cybersecurity event that impacted a standalone legacy information technology platform in one country and the foreign business unit’s ability to operate in that country for approximately two weeks. The Company made an initial notification to the relevant regulator and is continuing to comply with applicable requirements to notify relevant regulators and any impacted parties or individuals. Any actual or perceived breach of confidential information could expose us to increased risk of lawsuits, regulatory penalties, loss of existing or potential customers, damage relating to loss of proprietary information, harm to our reputation and increases in our security costs. The foregoing or other circumstances related to our collection, use, and transfer of personal data could cause a loss of reputation in the market and/or adversely affect our business and financial position.
Other Risks
The loss or disruption of information systems could disrupt our operations and have a material adverse effect on our business.
Our businesses rely on sophisticated information systems to obtain, rapidly process, analyze, and manage data to facilitate the purchase and distribution of thousands of inventory items from numerous distribution centers; to receive, process,
and ship orders on a timely basis; to account for other product and service transactions with customers; to manage the accurate billing and collections for thousands of customers; and to process payments to suppliers. We continue to make substantial investments in data centers and information systems, including, but not limited to, those relating to our acquisition of Alliance Healthcare. To the extent our information systems are not successfully implemented or fail, or to the extent there are data center interruptions or outages, our business and results of operations may be materially adversely affected. Our business and results of operations may also be adversely affected if a third-party service provider does not perform satisfactorily, or if the information systems are interrupted or damaged by unforeseen events, including due to the actions of third parties.
Information security risks have generally increased in recent years because of the proliferation of cloud-based infrastructure and other services, new technologies, and the increased sophistication and activities of perpetrators of cyberattacks. Security incidents such as ransomware attacks are becoming increasingly prevalent and severe, as well as increasingly difficult to detect. These risks have increased with the growth of our business, including as we integrate the information systems of acquired businesses, such as Alliance Healthcare, into our enterprise.
In addition, security incidents may disrupt our businesses and require that we expend substantial additional resources related to the security of information systems. We, and our third-party service providers, may experience cyberattacks aimed at disrupting services. In March 2023, one of the Company’s foreign business units became aware of a cybersecurity event. Upon detection, we undertook steps to address the event, including engaging a cybersecurity forensic firm, outside counsel and other incident response professionals, and notifying law enforcement and relevant government authorities. The ensuing investigation revealed that the event resulted in the unavailability of certain data stored on a standalone legacy information technology platform and was isolated to one country, which disrupted operations of the Company’s foreign business unit in that country. The investigation determined that systems and operations in other countries were not impacted. Over a period of approximately two weeks, the foreign business unit’s systems were substantially restored and operations in the effected country resumed. While we believe that the March 2023 cybersecurity event did not have a material adverse effect on our business, financial position, or results of operations, no assurances can be given as we continue to assess the full impact from the event. We are continuing to build and execute plans to further improve our existing systems and invest in our cybersecurity defenses and technology resiliency. Security breaches can also occur as a result of non-technical issues, including intentional or inadvertent actions by our employees, third-party service providers or their personnel or other parties. A failure, interruption, or breach of our operational or information security systems, or those of our third-party service providers, as a result of cyberattacks or information security breaches could disrupt our business, result in the disclosure or misuse of confidential or proprietary information or personal data, damage our reputation, cause loss of customers or revenue, increase our costs, result in litigation and/or regulatory action, and/or cause other losses, any of which might have a materially adverse impact on our business operations and our financial position or results of operations. As a result, cybersecurity and the continued development and enhancement of the controls and processes designed to protect our systems, computers, software, data, and networks from attack, damage, or unauthorized access remain a priority for us. Although we believe that we have robust information security procedures, controls and other safeguards in place, both as a result of the March 2023 cybersecurity event and as cyber threats continue to evolve, we may be required to expend additional resources and incur greater costs to continue to enhance our information security measures and/or to investigate and remediate information security vulnerabilities.
ITEM 2. Unregistered Sales of Equity Securities and Use of Proceeds
(c) Issuer Purchases of Equity Securities
The following table sets forth the number of shares purchased, the average price paid per share, the total number of shares purchased as part of publicly announced programs, and the approximate dollar value of shares that may yet be purchased under the programs during each month in the second fiscal quarter ended March 31, 2023. See Note 7, "Stockholders' Equity and Earnings per Share," contained in "Notes to Condensed Consolidated Financial Statements" in Part I, Item 1 of this Quarterly Report on Form 10-Q for additional information.
| Period | Total Number of Shares Purchased | Average Price Paid per Share | Total Number of Shares Purchased as Part of Publicly Announced Programs | Approximate Dollar Value of Shares that May Yet Be Purchased Under the Programs | ||||||||||||||||||||||
| January 1 to January 31 | 85 | $ | 164.29 | — | $ | 182,525,290 | ||||||||||||||||||||
| February 1 to February 28 | 16,710 | $ | 156.79 | — | $ | 182,525,290 | ||||||||||||||||||||
| March 1 to March 31 | 672 | $ | 153.52 | — | $ | 1,182,525,290 | ||||||||||||||||||||
| Total | 17,467 | — |
ITEM 3. Defaults Upon Senior Securities
None.
ITEM 4. Mine Safety Disclosures
Not applicable.
Previous: Item 1. Legal Proceedings · Next: Item 5. Other Information