WAY 10-K & 10-Q changes, risk factors and insider trading
Waystar Holding Corp. · Nasdaq · Services-Computer Integrated Systems Design · CIK 1990354 · All filings on SEC.gov
At a glance
What changed in the latest 10-K
Risk Factors
New heading “The development, deployment, and use of AI in our products and solutions subjects us to risks that could adversely affect our business.”
Removed heading “We are an “emerging growth company” and we cannot be certain if the reduced disclosure requirements applicable to “emerging growth companies” will make our common stock less attractive to investors.”
Largest changes
“Geopolitical instability, including the conflict between Russia and Ukraine, actual and potential shifts in U.S. and foreign, trade, economic, and other policies, and rising trade tensions between the United States and other countries as well as other global events, have significantly increased macroeconomic uncertainty at a global level. The current U.S. …”see in full comparison
“Geopolitical instability, including the conflict between Russia and Ukraine, actual and potential shifts in U.S. and foreign, trade, economic, and other policies, and rising trade tensions between the United States and China, as well as other global events, have significantly increased macroeconomic uncertainty at a global level. The current U.S. macroeconomic environment is characterized by recent record-high inflation, supply chain challenges, labor shortages, high interest rates, foreign currency exchange volatility, volatility in global capital markets, and growing recession risk. …”see in full comparison
We are a “covered entity” as defined under HIPAA when we provide our clearinghouse services, and we also are a “business associate” as defined under HIPAA for other covered entities when we provide revenue cycle management and other solutions. HHS OCR may impose civil penalties on both covered entities and business associates for their failure to comply with HIPAA requirements. These requirements are subject to change. In December 2024, HHS OCR issued a notice of proposed rulemaking on the HIPAA Security Rule, which is specifically aimed at strengthening cybersecurity of electronic PHI, and we are monitoring this proposed rulemaking. The U.S. Department of Justice is responsible for criminal prosecutions under HIPAA. Penalties can vary significantly depending on a number of factors, such as whether the covered entity’s or business associate’s failure to comply was due to willful neglect. Violations of HIPAA could result in substantial criminalsee in full comparisonpenaltiesand civil penalties, including up to$250,000 and ten10 years in prisonand civil penalties of up to $68,928for eachviolation, with a cap of $2,067,813 for violations of the same standard per calendar year, administrative fines and penalties, and/or additional reporting and oversight obligations if we are required to enter into a resolution agreement and corrective action plan. A single breach incident can result in violations of multiple standards over many years, resulting in potential penalties in excess of $2,067,813 per year. For example, HIPAA violations at one covered entity resulted in total penalties of $16 million in 2018.violation. HIPAA also authorizes state attorneys general to file suit on behalf of the residents of their states. While HIPAA does not create a private right of action that would allow individuals to sue in civil court for HIPAA violations, its standards have been used as the basis for the duty of care in state civil suits, such as those for recklessness in misusing individuals’ health information. If we are subject to investigation or litigation related to an alleged violation of HIPAA, then we may elect to resolve the matter through additional reporting and oversight obligations through a resolution agreement and corrective action plan with HHS to settle allegations of HIPAA non-compliance. Such settlement could require payment of a civil penalty or damages, corrective action, and/or monitoring of our business by a third party.
Our business relies in part on our ability to obtain, process, monetize, use, disclose, and distribute highly regulated data in the healthcare and technology industries in a manner that complies with applicable laws, regulations, and contractual and technological restrictions. The failure by us or our data suppliers, processors, partners, and vendors to obtain, provide, maintain, use, and disclose data in a compliant manner could have a harmful effect on our ability to use and disclose data which in turn could impair our functions and operations, including our ability to share data with third parties or incorporate it into our product offerings. In addition, the processing, use, disclosure, and distribution of data may require us or our data suppliers, processors, partners, and vendors to obtain consent from third parties or follow additional laws, regulations, or contractual and technological restrictions that apply to the healthcare industry. These requirements could interfere with or prevent creation or use of rules and analyses or limit other data-driven activities that benefit us. Moreover, due to lack of valid notice, permission, authorization, consent, or waiver, we may be subject to claims or liability for use or disclosure of information. We have policies and procedures in place designed to address the proper handling, use, and disclosure of data, but could face claims that our practices occur in a manner not permitted under applicable laws or our agreements with or obligations to data providers, individuals, or other third parties. These claims or liabilities and other failures to comply with applicable requirements could damage our reputation, subject us to unexpected costs, and could have a material adverse impact on our business, results of operations, or financial condition. See Part I, Item 1A, “Risk Factors—Risks Related to Information Technology Systems, Cybersecurity, Data Privacy, and Intellectual Property—see in full comparisonPrivacyOurconcernsbusinessorissecurity breaches or incidents relatingsubject toour platform could result in economic loss, damage to our reputation, deter users from using our products, expose us to legal penaltiescomplex andliability,evolving laws andotherwiseregulationsadverselyregardingaffectprivacy,ourdatabusiness”protection, and cybersecurity and Part I, Item 1A, “Risk Factors—Risks Related to Legal and Governmental Regulation—We are subject to health care laws and data privacy and security laws and regulations governing our Processing of personal information, including PHI, personal health records, and payment card data.”
“Moreover, AI is subject to a dynamic and rapidly evolving legal and regulatory environment, and our efforts, including the introduction of new products or changes to existing products, may result in new or enhanced governmental or regulatory scrutiny, litigation, ethical concerns, or other complications and liabilities. We may not be able to successfully respond to these rapidly evolving frameworks, laws, regulations and other requirements, and we may need to expend significant resources to adjust our operations or offerings in response.”see in full comparison
“•announcements, claims and/or allegations relating to litigation, governmental investigations, or compliance with applicable laws and regulations;”see in full comparison
Full comparison: every changed paragraph (127)
•the performance and functionality of our platform;
•our ability to deliver a high-quality client experience;
•our ability to develop and sell complementary products and solutions;
•the stability, performance, and security of our hosting infrastructure;
•our ability to attract, retain, and effectively train sales and marketing personnel;
•the delivery of products that are easy to use and deliver tangible value to clients;
•changes in healthcare laws, regulations, or trends, and our ability to quickly adapt;
•the business environment of our clients, including healthcare staffing shortages and headcount reductions by our clients;
•the price of our products and solutions relative to our competitors;
•our ability to integrate with EHR or PM systems; and
•our ability to maintain and enhance our reputation and brand recognition.
•our ability to maintain relationships with the clients and suppliers of the acquired business;
•our ability to retain or replace key personnel of the acquired business;
•potential conflicts in payer, client, partner, vendor, or marketing relationships;
•our ability to coordinate organizations that are geographically diverse and may have different business cultures;
•the acceptance of acquired company clients of product upgrades and platform changes;
•the diversion of management’s attention to the integration of the operations of businesses or other assets we have acquired;
•difficulties in the integration or migration of IT systems, including securely sharing data across networks, and maintaining the security of the IT systems;
•incurrence of debt or assumption of known and unknown liabilities;
•write-off of goodwill, client lists, and amortization of expenses related to intangible assets; and
•compliance with regulatory, contracting, and other requirements, including internal control over financial reporting.
Many healthcare provider organizations are consolidating to create integrated healthcare delivery systems with greater market power. As provider networks and managed care organizations consolidate, thus decreasing the number of market participants, competition to provide products and solutions like ours will become more intense, and the importance of establishing and maintaining relationships with key industry participants will increase. These industry participants may try to use their market power to negotiate price reductions for our products and solutions or otherwise exert downward pressure on prices of our products and solutions. Further, consolidation of management and billing services through integrated delivery systems may decrease demand for our products. Such consolidation may also lead integrated delivery systems to require newly acquired physician practices to replace our product with that already in use in the larger enterprise. In addition, vertical integration whereby healthcare provider organizations acquire EHR, PM, revenue management cycle, or similar systems may make it more challenging to establish new relationships with such providers or may lead to such provider organizations replacing our solutions with those offered by systems that they acquire. Any of these factors could materially and adversely impact our business, financial condition, and operating results.
Competition for qualified management and employees in our industry is intenseintense, especially for employees with expertise in AI and software, and identifying and recruiting qualified personnel and training them requires significant time, expense, and attention. Many of the companies with which we compete for personnel have greater financial and other resources than we do. While we have entered into offer letters or employment agreements with certain of our executive officers, all of our employees are “at-will” employees, and their employment can be terminated by us or them at any time, for any reason, and without notice, subject, in certain cases, to severance payment rights. The departure and replacement of one or more of our executive officers or other key employees would likely involve significant time and costs, may significantly delay or prevent the achievement of our business objectives, and could materially harm our business. In addition, volatility or lack of performance in our stock price may affect our ability to attract replacements should key personnel depart.
Market estimates and growth forecasts that we disclose are subject to significant uncertainty and are based on assumptions and estimates that may not prove to be accurate. The estimates and forecasts relating to the size and expected growth of the market for our products and solutions may prove to be inaccurate. These estimates and forecasts may be impacted by economic uncertainty that is outside our control, including macroeconomic trends such as domestic supply chain risks, tariffs, inflationary pressure, interest rate increases, and declines in consumer confidence that impact our clients. While we believe the information on which we base our total addressable market and the underlying estimates and assumptions is generally reliable, such information is inherently imprecise. We cannot assure you that these assumptions will prove to be accurate.
Our solutions must interoperate, connect, and integrate with our clients’ and their vendors’ existing infrastructures, which often have different specifications, utilize multiple protocol standards, deploy products and solutions from multiple vendors, and contain multiple generations of products that have been added to that infrastructure over time. Some of the technologies supporting our clients and their vendors are constantly evolvingevolving, and we must continue to adapt to these changes in a timely and effective manner at an acceptable cost. In addition, our clients and their vendors may implement new technologies into their existing networks and systems infrastructures that may not immediately interoperate with our solutions. Our continued success will depend on our ability to adapt to changing technologies, manage, and process ever- increasing amounts of data and information and improve the performance, features, and reliability of our solutions in response to changing client and industry demands. If we encounter complications related to network configurations or settings, we may have to modify our solutions to enable them to interoperate with our clients’ and their vendors’ networks and manage clients’ transactions in the manner intended. For example, if clients or their vendors implement new encryption protocols, it may be necessary for us to obtain a license to implement or interoperate with such protocols, and there can be no assurance that we will be able to obtain such a license on acceptable terms, if at all. On the other hand, any new or enhanced technologies that we employ must be accepted by our clients’ and their vendors’ existing infrastructures and be able to be integrated with their platforms and solutions. For example, we use automated software applications or “bot” technology and Application Interface (“API”) technology in a number of our solutions. Certain of our clients’ platforms may not support those technologies or functionalities for various reasons, which would adversely impact connectivity of our solutions. Any of these difficulties could delay or prevent the successful design, development, testing, introduction, or marketing of our solutions.
We serve our clients primarily from third-party data-hosting facilities. These facilities are vulnerable to damage or interruption from climate change or extraordinary events, including adverse weather, earthquakes, floods, fires, power loss, telecommunications failures, and similar events. They are also subject to break-ins, sabotage, intentional acts of vandalism, terrorism, and similar misconduct. Their systems and servers could also be subject to software and hardware errors, hacking, ransomware, viruses, and other disruptive problems or vulnerabilities. Despite precautions taken at these facilities, the occurrence of a natural disaster or an act of terrorism, a decision to close the facilities without adequate notice, or other unanticipated problems at the facilities could result in lengthy interruptions in our solutions. Although we have instituted disaster recovery arrangements, in certain cases, we do not maintain redundant systems or facilities. In the event of a catastrophic event, we may experience an extended period of system unavailability, which could negatively impact our relationship with users or clients.
Our business relies in part on our ability to obtain, process, monetize, use, disclose, and distribute highly regulated data in the healthcare and technology industries in a manner that complies with applicable laws, regulations, and contractual and technological restrictions. The failure by us or our data suppliers, processors, partners, and vendors to obtain, provide, maintain, use, and disclose data in a compliant manner could have a harmful effect on our ability to use and disclose data which in turn could impair our functions and operations, including our ability to share data with third parties or incorporate it into our product offerings. In addition, the processing, use, disclosure, and distribution of data may require us or our data suppliers, processors, partners, and vendors to obtain consent from third parties or follow additional laws, regulations, or contractual and technological restrictions that apply to the healthcare industry. These requirements could interfere with or prevent creation or use of rules and analyses or limit other data-driven activities that benefit us. Moreover, due to lack of valid notice, permission, authorization, consent, or waiver, we may be subject to claims or liability for use or disclosure of information. We have policies and procedures in place designed to address the proper handling, use, and disclosure of data, but could face claims that our practices occur in a manner not permitted under applicable laws or our agreements with or obligations to data providers, individuals, or other third parties. These claims or liabilities and other failures to comply with applicable requirements could damage our reputation, subject us to unexpected costs, and could have a material adverse impact on our business, results of operations, or financial condition. See Part I, Item 1A, “Risk Factors—Risks Related to Information Technology Systems, Cybersecurity, Data Privacy, and Intellectual Property—PrivacyOur concernsbusiness oris security breaches or incidents relatingsubject to our platform could result in economic loss, damage to our reputation, deter users from using our products, expose us to legal penaltiescomplex and liability,evolving laws and otherwiseregulations adverselyregarding affectprivacy, ourdata business”protection, and cybersecurity and Part I, Item 1A, “Risk Factors—Risks Related to Legal and Governmental Regulation—We are subject to health care laws and data privacy and security laws and regulations governing our Processing of personal information, including PHI, personal health records, and payment card data.”
Our reputation and our clients’ willingness to purchase our products and partners’ willingness to use our products depend, in part, on our third-party providers’ compliance with ethical employment practices, such as with respect to child labor, wages and benefits, forced labor, discrimination, safe and healthy working conditions, and with all legal and regulatory requirements relating to the conduct of their businesses. If our third-party providers fail to comply with applicable laws, regulations, safety codes, employment practices, human rights standards, quality standards, environmental standards, production practices, or other obligations, norms, or ethical standards, our reputation and brand image could be harmedharmed, and we could be exposed to litigation and additional costs that would harm our business, reputation, and results of operations. The ability of our third-party providers to effectively satisfy our business requirements could also be impacted by financial difficulty of our third-party providers or damage to their operations caused by fire, terrorist attack, natural disaster, or other events.
Our products and solutions are used to help simplify the payment process for healthcare providers. If our products and solutions fail to provide accurate and timely information or are associated with errors or malfunctions, then our clients could assert claims against us that could result in substantial costs to us, harm our reputation in the industry, and cause demand for our products and solutions to decline. Although we attempt to limit by contract our liability for damages, the allocations of responsibility and limitations of liability set forth in our contracts may not be enforceable or may not otherwise sufficiently protect us from liability for damages. In certain circumstances, we may also be liable for the acts or omissions of others, such as our vendors or suppliers. On occasion, we enter into standard indemnification arrangements in the ordinary course of business. Pursuant to these arrangements, we indemnify, hold harmless, and agree to reimburse the indemnified parties for losses suffered or incurred by the indemnified party, in connection with any trade secret, copyright, patent, or other intellectual property infringement claim by any third-partythird party with respect to its technology. The terms of these indemnification agreements are generally perpetual. See Part I, Item 1, “Business—Indemnification and Insurance.”
We collect, create, receive, maintain, process, use, transmit, disclose, transfer, alter, and store (collectively, “Process”) significant amounts of patients' personal information of(including patientsPHI) received in connection with the utilization of our platform and otherwise in connection with the operation of our business, andas well as other sensitive, confidential, and proprietary information such as payment data and PHI.data. Attacks on information technology systems are increasing in their frequency, levels of persistence, sophistication, and intensity, and they are being conducted by increasingly sophisticated and organized groups and individuals, including state- sponsored organizations, with a wide range of motives and expertise. In addition to extracting personal information and other sensitive or confidential information, such attacks could include the deployment of harmful malware, ransomware, denial-of-service attacks, social engineering, and other means to affect service reliability and threaten the confidentiality, integrity, security, and availability of our information or information technology systems. The prevalent use of mobile devices also increases the risk of data security incidents. Further, like all internet-based solutions, our solutions are vulnerable to software bugs, computer viruses, malware, internet worms, break-ins, phishing attacks, attempts to overload servers with denial-of- service, or other attacks or similar disruptions from unauthorized use of our and third-party computer systems, any of which could lead to system interruptions, delays,delays or shutdowns, causing loss of critical data, or the unauthorized acquisition of or access to data. While we believe we have taken reasonable steps to protect such data, techniquesor the compromise of our information technology systems. Techniques used to gain unauthorized access to or acquisitions of data and systems, disable or degrade service, or sabotage systems, are constantly evolving,evolving (including through the use of AI), and we may be unable to anticipate such techniques or implement adequate preventative measures to avoid unauthorized access, acquisitions of, or other adverse impacts to such data or our systems. The risk of state-supported and geopolitical-related cyber-attacks may increase in connection with the war in Ukraine and any related political or economic responses and counter-responses.conflicts. In addition, competitors in our industry have suffered successful cyberattacks in the past, which may lead to us facing additional scrutiny, and we may face similar attacks ourselves. We may not discover all such incidents or activity or be able to respond or otherwise address them promptly, in sufficient respects or at all. Any specific interruption or attack, any failure to maintain performance, reliability, security, and availability of our products, or failure to prevent software bugs and other corruptants such as those listed above, to the satisfaction of our clients or their patients, may harm our reputation and our ability to retain existing clients, negatively affect our clients and their patients, and adversely impact our business, results of operations, and financial condition.
Further, the security systems in place at our employees’, vendors’, and service providers’ offices and homes may be less secure than those used in our offices, and while we have implemented technical, physical, and administrative safeguards to help protect our systems when our employees, vendors, and service providers work from their offices, homes, and other remote locations, we may be subject to increased cybersecurity risk, which could expose us to risks of data or financial loss, and could disrupt our business operations. There is no guarantee that the data security and privacy safeguards we have put in place will ultimately be effective or that we will not encounter risks associated with employees, vendors, and service providers accessing company data and systems remotely. If an actual or perceived breach of security occurs to our systems or a third-party’s systems, we could be required to expend significant resources to mitigate the breach of security, pay any applicable fines, and address matters related to any such breach, including notifying impacted individuals, the media, or regulators, making public disclosures, and addressing reputational harm.
Any adverse impact to the availability, integrity, or confidentiality of our information technology systems or data, or the information technology systems or data of third parties upon which we rely, could require us to expend significant resources to mitigate the breach of security, pay any applicable fines, and address matters related to any such breach, including notifying impacted individuals, the media, or regulators, making public disclosures, and addressing reputational harm.
AnyAdditionally, theft,any loss,such or misappropriation of, or access to, clients’, or other proprietary data, or other breach of our third-party service providers’ or vendors’ information technology systemsevent could result in fines, legal claims, or proceedings, including regulatory investigations and class actions, or liability for failure to comply with privacy and information security laws, which could disrupt our operations, damage our reputation, and expose us to claims from clients, individuals, and others, any of which could have a material adverse effect on our business, financial condition, and results of operations.
The costs of mitigating data security risks are significant and are likely to increase in the future. Although we carry cybersecurity insurance, we cannot ensure our limits are sufficient to cover us against all potential losses for damages or fines in an amount exceeding our policy.policy, or that applicable insurance will be available to us in the future on economically reasonable terms or at all.
For example, the CCPA took effect on January 1, 2020,2020 whichand was amended in 2022. The law broadly defines personal information, gives California residents expanded privacy rights and protections, and provides for civil penalties for certain violations. Furthermore, in November 2020, California voters passed the CPRA, which amended and expanded the CCPA with additional data privacy compliance requirements and established a regulatory agency dedicated to enforcing those requirements. Many other states, such as Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginiastates have since also passedenacted comprehensive state privacy laws that may impose additional obligations and requirements on our business. Additionally, we may be subject to new laws governing the privacy of certain specific types of data, including, most notably, consumer health data. For example, Washington’s My Health My Data Act broadly defines consumer health data, creates a private right of action to allow individuals to sue for violations of the law, imposes stringent consent requirements, and grants consumers certain rights with respect to their health data, including to request deletion of their information.
Monitoring unauthorized use of our intellectual property is difficult and costly. From time to time, we seek to analyze our competitors’ products and solutions, and may in the future seek to enforce our rights against potential infringement. However, the steps we have taken to protect our proprietary rights may not be adequate to prevent infringement or misappropriation of our intellectual property. We may not be able to detect unauthorized use of, or take appropriate steps to enforce, our intellectual property rights. Additionally, the intellectual property ownership and license rights surrounding AI technologies, which we are increasingly incorporating into our product offerings, have not been fully addressed by U.S. courts or other federal or state laws or regulations, and the use or adoption of AI technologies in our products and services may expose us to intellectual infringement or other intellectual property misappropriation claims related to AI training or output. Any inability to meaningfully protect or enforce our intellectual property rights could result in harm to our brand or our ability to compete and reduce demand for our technology and products. Moreover, our failure to develop and properly manage new intellectual property could adversely affect our market positions and business opportunities. Also, some of our products and solutions rely on technologies and software developed by or licensed from third parties. Any disruption or disturbance in such third-party products or services, which we have experienced in the past and may experience again in the future, could interrupt the operation of our platform, and could cause us to be in breach of contracts with our clients. We may not be able to maintain our relationships with such third parties or enter into similar relationships in the future on reasonable terms or at all.
The development, deployment, and use of AI in our products and solutions subjects us to risks that could adversely affect our business.
We have integrated AI and machine learning technologies into our products and solutions, and our future success will depend, in part, on our ability to leverage these technologies responsibly and effectively. The development and use of AI subjects us to risks that could adversely affect our business, financial condition and results of operations, and use of such technologies may not enhance our products or solutions, allow us to keep pace with competitors or benefit our business as intended. As these technologies are rapidly developing, it is not possible to predict all of the legal, operational, competitive, security, technological and other risks that may arise relating to the use of such technologies.
Our AI-enabled solutions depend on the quality and completeness of training data, and deficiencies could result in inaccurate, misleading, unreliable, or biased outputs that could harm our clients or expose us to liability. AI technologies are inherently complex, and our AI systems may not perform as intended, or may degrade in performance over time due to changes in underlying data, payer requirements, market conditions or for other reasons. Validating AI outputs requires substantial resources and consistent, reliable performance across diverse client environments and use cases is difficult. Any actual or perceived failures of our AI-enabled solutions could result in client dissatisfaction, claims against us, regulatory scrutiny, or reputational harm.
Our clients may impose contractual restrictions on our use of AI, or seek indemnification for AI-related errors, any of which could limit the value of our AI-enabled solutions or expose us to liability. Client reluctance to adopt AI features due to accuracy, liability, or regulatory concerns could also slow our ability to realize returns on our AI investments.
Moreover, AI is subject to a dynamic and rapidly evolving legal and regulatory environment, and our efforts, including the introduction of new products or changes to existing products, may result in new or enhanced governmental or regulatory scrutiny, litigation, ethical concerns, or other complications and liabilities. We may not be able to successfully respond to these rapidly evolving frameworks, laws, regulations and other requirements, and we may need to expend significant resources to adjust our operations or offerings in response.
The rapid advancement of generative and agentic AI also poses competitive risks. Large technology companies with significantly greater resources are deploying AI tools that could commoditize revenue cycle management functions core to our platform, and competitors may also adopt or deploy AI more quickly or effectively than we do. Agentic AI systems could automate workflows our clients currently rely on us to perform, and EHR and PM vendors may integrate AI capabilities directly into their platforms, reducing demand for our solutions. Generative AI may also lower barriers to entry, enabling new competitors to emerge more quickly. If we fail to keep pace with AI advancements or our AI-enabled solutions do not achieve market acceptance, our competitive position could be materially harmed.
We receive confidential and proprietary information from third parties in connection with the operation of our business. In addition, we may employ individuals who were previously employed at other technology companies, including our competitors. We may be subject to claims that uswe or our employees, consultants, or independent contractors have inadvertently or otherwise improperly used or disclosed confidential information of these third parties or our employees’ or contractors’ former employers. Further, we may be subject to ownership disputes in the future arising, for example, from conflicting obligations of employees, consultants, or others who are involved in developing our solutions. We may also be subject to claims that former employees, consultants, independent contractors or other third parties have an ownership interest in our patents or other intellectual property. Litigation may be necessary to defend against these and other claims challenging our right to and use of confidential and proprietary information. In addition to paying monetary damages, if we fail in defending against any such claims we may lose our rights therein, which could have a material adverse effect on our business. Even if we are successful in defending against these claims, litigation could result in substantial cost and be a distraction to our management and employees.
These laws are complex, may change rapidly, and the scope and enforcement and application of each of these laws to our specific services and relationships may not be clear and may be applied to our business in ways we do not anticipate. Federal and state regulatory and law enforcement authorities continue to focus on enforcement activities with respect to Medicare, Medicaid, other government and third-party payor programs, and other healthcare reimbursement laws and rules in an effort to reduce overall healthcare spending. Federal and state enforcement bodies have recently increased their scrutiny of interactions between healthcare companies and healthcare providers, which has led to a number of investigations, prosecutions, convictions, and settlements in the healthcare industry. Because of the breadth of these laws and the narrowness of their statutory or regulatory exceptions and safe harbors, some of our business activities may be subject to challenge under one or more of them. Recent federalFederal government healthcare reforms, cost-cutting, efficiency, and fraud and abuse initiativesinitiatives, and other proposed or future changes may also result in reductions in healthcare reimbursement, healthcare spending, and the federal workforce that oversees healthcare programs, which may have a significant adverse impact on our business. In addition, new and evolving payment structures, for example, such as accountable care organizations and other arrangements involving combinations of healthcare providers who share savings, potentially implicate anti-kickback and other fraud and abuse laws. The government has prosecuted revenue cycle management service providers for causing the submission of false or fraudulent claims in violation of the FCA, and vendors of EHR software for, among other things, misrepresenting the capabilities of their software and payment of kickbacks to certain customers in exchange for promoting their products in violation of the AKS and the FCA. Errors created by our platform and our proprietary products and solutions that relate to entry, formatting, preparation, or transmission of claims, reporting of quality or other data pursuant to value-based purchasing initiatives, or cost report information may be alleged or determined to cause the submission of false claims or otherwise be in violation of these laws. As we continue to build new and evolving technologies, such as AI, machine learning, analytics, and biometrics, into our products and solutions, our business may become subject to additional complex and evolving regulatory requirements pertaining to the sale or use of these technologies. The sale of these technologies, or their use by us or by our clients or partners, may also subject us to additional risks, including reputational harm, competitive harm, or legal liabilities.
Almost all of our revenue is derived from the healthcare industry, which is subject to changing political, legislative, regulatory, and other influences. Healthcare laws and regulations are rapidly evolvingevolving, including as a result of changes in the U.S. administration resulting in changes in federal law and enforcement, and may change significantly in the future, which could adversely affect our financial condition and results of operations. For example, in March 2010, the Patient Protection and Affordable Care Act (the “ACA”) was adopted, which is a healthcare reform measure that provides healthcare insurance for millions of Americans. The ACA includes a variety of healthcare reform provisions and requirements that substantially changed the way healthcare is financed by both governmental and private insurers, which significantly impact our industry and our business. We are unable to predict the full impact of any health reform initiatives or legislative updates to current healthcare laws on our operations in light of the uncertainty regarding whether, when, and how alternative reforms, if any, may be enacted, the timing of enactment and implementation of alternative provisions and the impact of alternative provisions on various healthcare industry participants.
We are also unable to predict how recent regulatory reforms regarding information blocking, algorithm transparency, interoperability, and health data will impact our business and whether the new presidential administration will continue to enforce or implement past reforms. For example, President Trump’s Administration revoked President Biden’s executive order on AI and it is unclear how the new Administration will implement final rules on Health Data, Technology and Interoperability (HTI-1, HTI-2, and HTI-3) that took effect in 2024. Future legislative, executive, and regulatory proposals may constitute a significant departure from previous regulations regarding patient data. While certain of these rules benefit us in that certain EHR vendors will no longer be permitted to interfere with our attempts at integration, they may also make it easier for other similar companies to enter the market, creating increased competition and reducing our market share.share.Changes to the legal, regulatory or political environment may require management’s attention, divert resources from other areas, and expose us to potential liability.
We are a “covered entity” as defined under HIPAA when we provide our clearinghouse services, and we also are a “business associate” as defined under HIPAA for other covered entities when we provide revenue cycle management and other solutions. HHS OCR may impose civil penalties on both covered entities and business associates for their failure to comply with HIPAA requirements. These requirements are subject to change. In December 2024, HHS OCR issued a notice of proposed rulemaking on the HIPAA Security Rule, which is specifically aimed at strengthening cybersecurity of electronic PHI, and we are monitoring this proposed rulemaking. The U.S. Department of Justice is responsible for criminal prosecutions under HIPAA. Penalties can vary significantly depending on a number of factors, such as whether the covered entity’s or business associate’s failure to comply was due to willful neglect. Violations of HIPAA could result in substantial criminal penaltiesand civil penalties, including up to $250,000 and ten10 years in prison and civil penalties of up to $68,928 for each violation, with a cap of $2,067,813 for violations of the same standard per calendar year, administrative fines and penalties, and/or additional reporting and oversight obligations if we are required to enter into a resolution agreement and corrective action plan. A single breach incident can result in violations of multiple standards over many years, resulting in potential penalties in excess of $2,067,813 per year. For example, HIPAA violations at one covered entity resulted in total penalties of $16 million in 2018.violation. HIPAA also authorizes state attorneys general to file suit on behalf of the residents of their states. While HIPAA does not create a private right of action that would allow individuals to sue in civil court for HIPAA violations, its standards have been used as the basis for the duty of care in state civil suits, such as those for recklessness in misusing individuals’ health information. If we are subject to investigation or litigation related to an alleged violation of HIPAA, then we may elect to resolve the matter through additional reporting and oversight obligations through a resolution agreement and corrective action plan with HHS to settle allegations of HIPAA non-compliance. Such settlement could require payment of a civil penalty or damages, corrective action, and/or monitoring of our business by a third party.
The security measures that we and our third-party vendors and subcontractors have in place designed to ensure compliancecomply with privacy and data protection laws may not protect our facilities and systems from security breaches or incidents, including acts of vandalism or theft, computer viruses, misplaced or lost data, malfeasance, programming, and human errors or other similar events. We may also be liable for privacy and security breaches and failures of our business associates and subcontractors. Even though we provide for appropriatecertain protections through our agreements with our subcontractors, we still have limited control over their actions and practices. A breach of privacy or security of individually identifiable health information by a subcontractor may result in an enforcement action, including criminal and civil liability, against us. We are not able to predict the extent of the impact such incidents may have on our business. Our failure to comply with HIPAA and other health privacy laws may also result in criminal and civil liability. Enforcement actions against us could be costly and could interrupt regular operations, which may adversely affect our business. While we have not received any notices of violation of the applicable privacy and data protection laws and believe we are in compliance with such laws, there can be no assurance that we will not receive such notices in the future.
Many states are also enacting legislation on the use, creation, and deployment of AI. For example, in March 2024, Utah enacted the Artificial Intelligence Policy Act, which requires disclosures to consumers about the use of AI in certain circumstances, including advance AI use disclosures by physicians and individuals in other regulated occupations. In Connecticut,Colorado, proposedthe legislationColorado wouldAI Act will regulate the development, deployment, and use of certain AI systems.systems, Theincluding Connecticutwith billrespect would addressto algorithmic discrimination,discrimination and decisions with respect to healthcare services, and studies on the use of AI by healthcare providers.services. Developers of generative AI systems would be required to complete impact assessments and disclose measures the developer has taken to mitigate any known or reasonably foreseeable risks of algorithmic discrimination that may arise from deployment of certain “high-risk” AI systems that are developed and marketed to make consequential decisions, such as decisions that have a material legal or similarly significant effect on consumer access to certain services, including healthcare and financial services. Other states have introduced similar bills.
Other federal and state laws that restrict the use and protect the privacy and security of personally identifiable information are, in many cases, not preempted by HIPAA and may be subject to varying interpretations by the courts and government agencies. These varying interpretations can create complex compliance issues for us and our partners and potentially expose us to additional expense, adverse publicity, and liability, any of which could adversely affect our business. Recently, several states have enacted consumer health data laws, which generally require consent for the collection, use, or sharing of any “consumer health data,” which is typically defined as personal information that is linked or reasonably linkable to a consumer and that identifies a consumer’s past, present, or future physical or mental health. Other states have enacted similar bills.
Any failure or perceived failure by us to comply with domestic laws or regulations, industry standards, or other legal obligations, or any actual or suspected breach or privacy or security incident, whether or not resulting in unauthorized access to, or acquisition, release or transfer of personally identifiable information or other data, may result in governmental enforcement actions and prosecutions, private litigation,litigation (including class actions), fines, and penalties or adverse publicity and could cause our clients to lose trust in us, which could have an adverse effect on our reputation and business. We may be unable to make such changes and modifications in a commercially reasonable manner or at all, and our ability to develop new products and features could be limited. Any of these developments could harm our business, financial condition, and results of operations. Privacy and data security concerns, whether valid or not valid, may inhibit retention of our platform or services by existing clients or adoption of our platform or services by new clients.
We are contractually required to comply with the Bank Secrecy Act and Anti-Money Laundering (“BSA/AML”) laws and regulations as a payment facilitator in certain instances.
•underperformance relative to historical or projected future operating results;
•changes in the manner of our use of acquired assets or the strategy for our overall business;
•negative industry or economic trends; or
•decline in our market capitalization relative to net book value for a sustained period.
As of December 31, 2024,2025, we had outstanding indebtedness of approximately $1.2$1.5 billion, consisting of $1.2$1.4 billion outstanding under our First Lien Credit Facility and $80 million outstanding under our Receivables Facility and not including $12 million of finance lease obligations.Facility. Additionally, we had $400$500 million of availability under our Revolving Credit Facility as of December 31, 2024.2025. As of December 31, 2024,2025, there is no outstanding balance on our Revolving Credit Facility.
•make it difficult for us to satisfy our financial obligations, including with respect to our indebtedness;
•limit our ability to borrow additional funds for working capital, capital expenditures, acquisitions, or other general business purposes;
•require us to use a substantial portion of our cash flow from operations to make debt service payments instead of other purposes, thereby reducing the amount of cash flow available for future working capital, capital expenditures, acquisitions, or other general business purposes;
Management's Discussion & Analysis (MD&A)
New heading “Secondary Offerings”
New heading “Iodine Acquisition”
New heading “Business Combinations”
Removed heading “JOBS Act Election”
Largest changes
“The results of businesses acquired in business combinations are included in our consolidated financial statements from the date of the acquisition. Purchase accounting results in assets and liabilities of an acquired business being recorded at their estimated fair values on the acquisition date. Any excess consideration over the fair value of assets acquired and liabilities assumed is recognized as goodwill. …”see in full comparison
“We are currently an “emerging growth company,” as defined in the JOBS Act. Under the JOBS Act, emerging growth companies can delay adopting new or revised accounting standards until such time as those standards apply to private companies. …”see in full comparison
“Cash flows provided by operating activities were $51.5 million for the year ended December 31, 2023 as compared to $102.6 million for the year ended December 31, 2022. The decrease was primarily driven by the change in deferred income taxes and income tax receivable resulting in a decrease of $43.4 million and by an impairment expense of $10.9 million recognized in 2022 related to leasehold improvements and right-of-use assets at closed office locations.”see in full comparison
Full comparison: every changed paragraph (83)
The following discussion and analysis of the financial condition and results of operations of Waystar Holding Corp. (“Waystar”, the “Company”, “we”, “us”, and “our”) financial condition and results of operations should be read in conjunction with our consolidated financial statements and the related notes included elsewhere in this Form 10-K. In addition to historical information, this discussion and analysis contains forward-looking statements based on current expectations that involve risks, uncertainties, and other factors outside the Company’sour control, as well as assumptions, such as our plans, objectives, expectations, and intentions. Our actual results may differ materially from those expressed or implied in the forward-looking statements as a result of various factors, including those described under the section entitled “Cautionary Statement Concerning Forward-Looking Statements” above and Part I, Item 1A, “Risk Factors” in this Form 10-K and our other filings with the SEC.
Waystar provides healthcare organizations with mission-critical cloudAI-powered software that simplifies healthcare payments.payments for providers across the continuum of care. Our enterprise-grade platform streamlines the complex and disparate processes our healthcare provider clientsproviders must manage to beensure reimbursedaccurate correctly,reimbursement whileand improvingimproves the payments experience for providers, patients, and payers. We leverage AI as well as proprietary, advanced algorithms to automate payment-related workflow tasks and drive continuous improvement, which enhances claim and billing accuracy, enrichesstrengthens data integrity, and reduces labor costs for providers.
Our software is used daily by providers of all types and sizes across the continuum of care, including physician practices, clinics, surgical centers, and laboratories, as well as large hospitals and health systems. We currently serve over 30,000 clients of various sizes, representing over one million distinct providers practicing across a variety of care sites, including 16 of the top 20 institutions on the U.S. News Best Hospitals Honor Roll.list. Our business model isaligns designed such that aswith our clients growgrowth; as they to serve more patients, their claims and transactional volumes increase, resulting indriving corresponding growth in our business. In addition, our clients frequently adopt a greater number of our solutions over time and introduce our solutions across new sites of care. In 2024,2025, we facilitated over six7.5 billion healthcare payments transactions, including over $1.8$2.4 trillion in gross claims volume. As of 2023, we facilitated healthcare payments transactionsvolume spanning approximately 50%60% of patients and one-in-three hospital discharges in the United States.
Our platform benefits from powerful network effects. Our cloud-based software is driven by a sophisticated, automated, and curatedAI-powered rules engine, employing AIengine to generate and incorporate real-time feedback from millions of network transactions processed through our platform each day. Every transaction we process provides additional data insights across providers, patients, and payers, which are embedded in updates that are deployed efficiently across our client base.platform. This results in cumulative benefits to us over timetime. —asAs we capture more data from each transaction we process, we leverage thatthose datainsights to continue tocontinuously improve the Waystar platform through embeddedWaystar AltitudeAI, our proprietary AI engine. Waystar AltitudeAI utilizes a multi-model approach that incorporates machine learning, advancedlarge algorithms,language models, and othergenerative in-houseand agentic AI technologiesto toautomate complex workflows and deliver added value to our clients. In turn, the more value we create for our clients, the more likely it is that they will continue to use our products, allowing us to continue to capture more data that results in tangible improvements to our platform. As a result, our clients benefit from faster and more efficient performance from software that is evolving to meet ever-changing regulatory and payer requirements, enabling accurate and timely reimbursement.
We have demonstrated an ability to drive recurring, predictable, and profitable growth. Over 99% of our revenue is either recurring subscription or based on highly predictable volumes. For the twelve12 months ended December 31, 2024,2025, our Net Revenue Retention Rate was 110.1%112.0% and we have 1,2031,391 clients as of December 31, 20242025 generating over $100,000 over the same twelve-month12-month period. For the year ended December 31, 2024,2025, we generated revenue of $943.5$1,099.3 million (reflecting a 19.3%16.5% increase compared to revenue of $791.0$943.5 million for the same period in the prior year), net lossincome of $19.1$$112.1 million (compared to net loss of $51.3$19.1 million for the same period in the prior year), and Adjusted EBITDA of $383.5$462.1 million (reflecting a 14.9%20.5% increase compared to Adjusted EBITDA of $333.7$383.5 million for the same period in the prior year).
Secondary Offerings
On February 24, 2025, the Institutional Investors closed an underwritten public offering of 23,000,000 shares of our common stock (inclusive of the underwriters’ option to purchase additional shares) (the “First Secondary Offering”). On May 15, 2025, the Institutional Investors closed another underwritten public offering of 14,375,000 shares of our common stock (inclusive of the underwriters' option to purchase additional shares) (the "Second Secondary Offering"). Additionally, on September 10, 2025, the Institutional Investors closed another underwritten public offering of 18,000,000 shares of our common stock (the "Third Secondary Offering"). We did not sell any shares in these offerings or receive any proceeds from these offerings. Pursuant to the terms of the Amended and Restated Registration Rights Agreement, dated as of June 10, 2024, by and among Waystar, the Institutional Investors, and certain other parties thereto, we paid $4.6 million in certain expenses on behalf of the selling stockholders related to these offerings for the year ended December 31, 2025, while the selling stockholders paid all applicable underwriting discounts and commissions.
Iodine Acquisition
On July 23, 2025, we entered into an Agreement and Plan of Merger (the "Merger Agreement") to acquire Iodine through a series of mergers. Iodine is a trusted leader in AI-powered clinical intelligence, enhancing clinical documentation and accuracy, streamlining utilization management, and preventing revenue leakage before billing. This strategic move is expected to bolster our AI leadership, automate manual work, and improve financial performance for providers. The acquisition was completed on October 1, 2025 for a total purchase price of $1.26 billion. The consideration paid was approximately $638.9 million in cash consideration and 16,639,920 shares of common stock having a value of $37.31 per share, and certain adjustments as outlined in the Merger Agreement.
Since 2018, we have completed and successfully integrated nineten acquisitions, twoone of which was Iodine that closed in the secondfourth halfquarter of 2023; HealthPay24 on August 3, 2023; and certain assets of Olive AI, Inc.’s Clearinghouse and Patient Access business on October 31, 2023.2025. The historical results of operations of our acquisitions are only included starting from the date of closing of such acquisition. As a result, our consolidated statements of operations for any given period during which an acquisition closed may not be comparable to future periods, which would include the results of operations of such acquisition for the entirety of such future period.
Following the February 2024 cybersecurity incident involving one of our competitors, more than 30,000 providers, including a significant number of large health systems and ambulatory providers, began adopting our solutions, and we were able to implement our solutions for many of these new clients in as little as 48 hours. This incident and our response to it generated approximately $11 million in additional revenue in the year ended December 31, 2025 and $34 million in additional revenue in the year ended December 31, 2024 due to increased win rates above our historically competitive rates and associated accelerated implementation timeline.
•Debt Repayment. In connection with the closing of the IPO, we repaid $909.1 million outstanding principal amount and $2.8 million accrued interest on our First Lien Credit Facility and incurred debt extinguishment costs of $9.8 million related to the write-off of unamortized debt issuance costs. On July 12, 2024, we utilized the additional proceeds from the underwriters’ exercise of the overallotment option, as well as cash on hand, to repay $110.9 million outstanding principal and $0.4 million accrued interest on our First Lien Credit Facility. The debt repayments will result in lower interest expense moving forward, partially offset by losses on extinguishment of debt in the period the debt repayment is made.
•Stock-Based Compensation Expenses. We expect to recognize stock-based compensation expense of $17.9 million per year over the applicable vesting periods in connection with equity awards granted in connection with the IPO. Such stock-based compensation expense will be reflected in our results of operations from the closing date of the IPO through the applicable vesting periods of such awards. Additionally, we recognized $33.1 million of stock-based compensation expense during the year ended December 31, 2024 as the vesting of our performance condition options became probable upon the closing of the IPO as the implicit service period for the awards established at the grant date had elapsed.
•Incremental Public Company Expenses. Following the IPO, we have begun to incur significant expenses on an ongoing basis that we did not incur as a private company. Those costs include additional director and officer liability insurance expenses, as well as third-party and internal resources related to accounting, auditing, Sarbanes-Oxley Act compliance, legal, and investor and public relation expenses. These costs will generally be expensed under general and administrative expenses.
Revenue
•Subscription revenue. Reflects recurring monthly provider count fees and minimum amounts owed. The vast majority of subscription revenue is generated by provider solutions, which constitute approximately 70% of total revenue for the periods presented.
•Volume-based revenue. Represents recurring fees associated with transaction count or dollar volumes in excess of minimums. Generally, approximately half of our volume-based revenue is generated from provider solutions that are based on transaction count, with the other half from patient payments solutions that are based on either dollar volumes or transaction count.
Income Tax Expense/(Benefit)
Income tax expense/(benefit) includes current income tax and income tax credits from deferred taxes. Income tax expense/(benefit) is recognized in profit and loss except to the extent that it relates to items recognized in equity or other comprehensive income, in which case the income tax expense is also recognized in equity or other comprehensive income.
Results of Operations for the Years Ended December 31, 2024, 20232025 and 20222024
The following discussion and analysis is for the year ended December 31, 2025, compared to the same period in 2024, unless otherwise stated. For a discussion and analysis of the year ended December 31, 2024, compared to the same period in 2023, please refer to the Management's Discussion and Analysis of Financial Condition and Results of Operations included in Part II, Item 7 of our Annual Report on Form 10-K for the year ended December 31, 2024, filed with the SEC on February 18, 2025.
Revenue
Revenue was $943.5 million for the year ended December 31, 2024 as compared to $791.0 million for the year ended December 31, 2023, an increase of $152.5 million, or 19.3%, of which $57.0 million was attributed to subscription revenue from new and existing clients, with $54.8 million generated by provider solutions, and $2.2 million generated from patient payments solutions. Another $93.6 million was attributed to volume-based revenue primarily related to expansion of existing client usage and acquired clients, of which $36.5 million was generated by provider solutions and $57.1 million by patient payments solutions.
Included within the revenue increases over the period is an estimated $34 million increase due to our heightened win rates above our historically high rates and accelerated implementation timelines as well as increased volume-based revenue from existing clients related to the cybersecurity incident involving one of our competitors in February 2024.
Revenue was $791.0$1,099.3 million for the year ended December 31, 20232025 as compared to $704.9$943.5 million for the year ended December 31, 2022,2024, an increase of $86.1$155.7 million, or 12.2%,16.5%, of which $34.3$100.4 million was attributed to subscription revenue primarilyfrom fromnew and existing clients, withalmost $31.9all millionof which is generated by provider solutions,solutions. andIncluded $2.4within this $100.4 million generatedincrease fromin patientsubscription paymentsrevenue solutions.was approximately $30 million of post-acquisition Iodine revenue. Another $50.8$54.8 million of the increase in revenues was attributed to volume-based revenuerevenue, primarily related to expansion of existing client usage and acquired clients, of which $20.9$21.2 million of the volume-based increase was generated by provider solutions and $29.9$33.6 million by patient payments solutions.
Cost of revenue was $315.7 million for the year ended December 31, 2024 as compared to $249.8 million for the year ended December 31, 2023, an increase of $66.0 million, or 26.4%. The increase was primarily driven by $52.3 million in increased costs stemming from higher transaction volume and associated third-party costs, including higher platform usage, of which approximately $13.1 million was from costs associated with provider solutions and $39.2 million from patient payments solutions. In addition, there was an $8.0 million increase in personnel costs and a $2.3 million increase in stock-based compensation expense primarily related to the recognition of performance condition options and new option and RSU grants related to the June IPO.
Cost of revenue was $249.8$348.2 million for the year ended December 31, 20232025 as compared to $214.9$315.7 million for the year ended December 31, 2022,2024, an increase of $34.9$32.4 million, or 16.2%.10.3%. The increase was primarily driven by $28.5revenue growth. The increase consists of $19.7 million in increased costs stemming from higher transaction volume and associated third-party costs, including higher platform usage, of which approximately $9.5$23.0 million was fromthird-party costs associated with provider solutions and $19.0 million from patient paymentspayment solutions. In addition, there was aan $4.6$11.0 million increase in personnel costs.costs, net of capitalized expenses.
Sales and marketing expense was $156.9 million for the year ended December 31, 2024 as compared to $124.4 million for the year ended December 31, 2023, an increase of $32.5 million, or 26.1%. The increase was driven by an increase in channel partner fees and amortization of the internal sales commission deferred contract costs assets of $16.3 million associated with revenue growth. Additionally, there was an increase of $10.6 million in stock-based compensation expense related to the recognition of performance condition options and new option and RSU grants related to the June IPO.
Sales and marketing expense was $124.4$178.0 million for the year ended December 31, 20232025 as compared to $111.5$156.9 million for the year ended December 31, 2022,2024, an increase of $13.0$21.1 million, or 11.6%.13.4%. The increase was primarily driven by an increase in channel partner fees and internal commissionsamortization of $9.1the million,internal ansales increasecommission indeferred marketingcontract expensescosts assets of $0.8$15.1 million andassociated anwith increaserevenue in third-party professional fees of $0.7 million.growth.
General and administrative expense was $111.8 million for the year ended December 31, 2024 as compared to $62.9 million for the year ended December 31, 2023, an increase of $48.8 million, or 77.6%. The increase was driven by a $26.3 million increase in stock-based compensation expense primarily related to the recognition of performance condition options and new option and RSU grants related to the June IPO. Additionally, there was an increase in third party fees of $14.1 million expensed as incurred, of which $10.3 million related to the debt modification related to the refinancing of the First Lien Credit Facility in February, $2.4 million related to the debt re-pricing in June, $1.3 million related to the debt re-pricing in December and $0.1 million relates to the payoff of the Second Lien Credit Facility in February.
General and administrative expense was $62.9$128.6 million for the year ended December 31, 20232025 as compared to $73.1$111.8 million for the year ended December 31, 2022,2024, aan decreaseincrease of $10.2$16.9 million, or 13.9%.15.1%. The decreaseincrease was primarily driven by an impairment expense recognizedincrease in 2022third party professional fees, including $14.7 million in costs related to leaseholdthe improvements and right-of-use assets at closed office locationsacquisition of $10.9 million.Iodine.
Research and development expense was $48.8 million for the year ended December 31, 2024 as compared to $35.3 million for the year ended December 31, 2023, an increase of $13.4 million, or 38.0%. The increase was driven by higher personnel costs, net of capitalized expenses, of $7.3 million increase and increased third party consulting and engineering efforts. Additionally, there was increased stock-based compensation expense of $7.0 million primarily related to the recognition of performance condition options and new option and RSU grants related to the June IPO.
Research and development expense was $35.3$54.6 million for the year ended December 31, 20232025 as compared to $32.8$48.8 million for the year ended December 31, 2022,2024, an increase of $2.5$5.8 million, or 7.7%.12.0%. The increase was primarily driven by higher personnel costs, net of capitalized expenses, of $1.5 million and increased third party consulting and engineering efforts, net of capitalized amounts, of $0.4$5.0 million.
Depreciation and amortization expense was $140.5 million for the year ended December 31, 2025, as compared to $186.6 million for the year ended December 31, 2024, asa compared to $176.5 million for the year ended December 31, 2023, an increasedecrease of $10.2$46.1 million, or 5.8%.24.7%. Due to the relocation of one of our offices, we reduced the useful life of the related finance lease and leasehold improvement assetsassets, which represented $17.9 million of accelerated depreciation for the year ended December 31, 2024. ThisAdditionally, due to several intangible assets fully maturing in 2024, amortization decreased by $37.3 million, which was offset by several$8.5 intangiblesmillion fullyof maturedamortization inof 2024,the drivingnew a decrease inIodine intangible amortization.assets acquired on October 1, 2025.
Depreciation and amortization expense was $176.5 million for the year ended December 31, 2023 as compared to $183.2 million for the year ended December 31, 2022, a decrease of $6.7 million, or 3.7%. The decrease was primarily driven by $6.3 million of amortization in 2022 related to intangible assets that were fully amortized as of January 1, 2023.
OtherInterest Expense
Total interest expense was $205.9 million for the year ended December 31, 2023 as compared to $155.3 million for the year ended December 31, 2022, an increase of $50.6 million, or 32.6%, of which $48.6 million was primarily related to higher interest expense driven by higher interest rates with respect to our First Lien Credit Facility and Second Lien Credit Facility, which is net of the impact of interest rate swaps.
Income tax expense was $59.7 million for the year ended December 31, 2025, as compared to an income tax benefit wasof $3.4 million for the year ended December 31, 2024, as compared to an income tax benefitincrease of $12.5 million for the year ended December 31, 2023, a decrease of $9.1$63.1 million. The decreaseincrease was primarily driven by our net income/(loss) has decreasedincrease year over year, which iswas driven by an increase in operating net income and a decrease in interest expense for the year ended December 31, 2024.2025. See explanations above for details.
Income tax benefit was $12.5 million for the year ended December 31, 2023 as compared to $14.4 million for the year ended December 31, 2022, a decrease of $1.9 million, or 13.3%. The decrease was primarily driven by decrease in pre-tax loss.
We present adjusted EBITDA, adjusted EBITDA margin, non-GAAP net income/(loss),income, and non-GAAP net income/(loss) per share as supplemental measures of financial performance that are not required by, or presented in accordance with, GAAP. We believe they assist investors and analysts in comparing our operating performance across reporting periods on a consistent basis by excluding items that we do not believe are indicative of our core operating performance. Management believes these non-GAAP financial measures are useful to investors in highlighting trends in our operating performance, while other measures can differ significantly depending on long-term strategic decisions regarding capital structure, the tax jurisdictions in which we operate, and capital investments. Management uses these non-GAAP financial measures to supplement GAAP measures of performance in the evaluation of the effectiveness of our business strategies, to make budgeting decisions, to establish discretionary annual incentive compensation, and to compare our performance against that of other peer companies using similar measures. Management supplements GAAP results with non-GAAP financial measures to provide a more complete understanding of the factors and trends affecting the business than GAAP results alone provide.
Adjusted EBITDA, adjusted EBITDA margin, non-GAAP net income / (loss),income, and non-GAAP net income / (loss) per share are not recognized terms under GAAP and should not be considered as an alternative to net income /(loss), net income/(loss) per share or net income /(loss) margin as measures of financial performance or cash provided by operating activities as a measure of liquidity, or any other performance measure derived in accordance with GAAP. Additionally, these measures are not intended to be a measure of free cash flow available for management’s discretionary use, as they do not consider certain cash requirements such as interest payments, tax payments, and debt service requirements. The presentations of these measures have limitations as analytical tools and should not be considered in isolation, or as a substitute for analysis of our results as reported under GAAP. Because not all companies use identical calculations, the presentations of these measures may not be comparable to other similarly titled measures of other companies and can differ significantly from company to company. A reconciliation is provided below for our non-GAAP financial measures to the most directly comparable financial measure stated in accordance with GAAP. Investors are encouraged to review the related GAAP financial measures and the reconciliation of non-GAAP financial measures to their most directly comparable GAAP financial measures, and not to rely on any single financial measure to evaluate our business.
We define adjusted EBITDA as net income/(loss) before interest expense, net, income tax benefit,expense/(benefit), depreciation and amortization, and as further adjusted for stock-based compensation expense, acquisition and integration costs, asset and lease impairments, costs related to amended debt agreements, and IPOcosts related costs.to our IPO and the Secondary Offerings. Adjusted EBITDA margin represents adjusted EBITDA as a percentage of revenue.
The following table presents a reconciliation of net income / (loss) to adjusted EBITDA and net income / (loss) margin to adjusted EBITDA margin for the years ended December 31, 2024, 20232025 and 20222024:
____________________________________ (a)For the year ended December 31, 2025, adjustments relate to additional lease costs due to the relocation of our Louisville office totaling $1.3 million and executive severance totaling $0.6 million. For the year ended December 31, 2024, adjustments relate to additional lease costs due to the relocation of our Louisville office.
We define non-GAAP net income as GAAP net income excluding the impact of stock-based compensation, acquisition and integration costs, asset and lease impairments, IPOcosts related costs,to our IPO and Secondary Offerings, costs related to amended debt agreements and amortization of intangibles. We updated the definition of non-GAAP net income to include amortization of intangibles to align with a more common definition used by our peers. We have revised prior year disclosures to align with this updated definition. The tax effects of the adjustments are calculated using a management estimated annual effective non-GAAP tax rate of 21%.21%, which is based on our statutory federal tax rate and provides consistency across reporting periods by eliminating the effects of non-recurring and period specific items. Due to the differences in the tax treatment of items excluded from non-GAAP net income/(loss), our estimated tax rate on non-GAAP net income/(loss) may differ from GAAP tax rate.
The following table presents a reconciliation of net income / (loss) to non-GAAP net income / (loss) and non-GAAP net income / (loss) per share for the years ended December 31, 2024, 20232025 and 20222024:
____________________________________ (a)For the year ended December 31, 2025, adjustments relate to additional lease costs due to the relocation of our Louisville office totaling $1.3 million and executive severance totaling $0.6 million. For the year ended December 31, 2024, adjustments relate to additional lease costs of $1.6 million and accelerated depreciation of $17.9 million due to the relocation of our Louisville office.
The following table presents our Net Revenue Retention Rate for December 31, 2024, 20232025 and 2022,2024, respectively:
Our Net Revenue Retention Rate compares twelve12 months of client invoices for our solutions at two period end dates. To calculate our Net Revenue Retention Rate, we first accumulate the total amount invoiced during the twelve12 months ending with the prior period-end, or Prior Period Invoices. We then calculate the total amount invoiced to those same clients for the twelve12 months ending with the current period-end, or Current Period Invoices. Current Period Invoices are inclusive of upsell, downsell, pricing changes, clients that cancel or chose not to renew, and discontinued solutions with continuing clients. The Net Revenue Retention Rate is then calculated by dividing the Current Period Invoices by the Prior Period Invoices. Our total invoices included in the analysis are greater than 98% of reported revenue. We use Net Revenue Retention Rate to evaluate our ongoing operations and for internal planning and forecasting purposes. Acquired businesses are included in the last-twelvelast-12 month Net Revenue Retention Rate in the ninth quarter after acquisition, which is the earliest point that comparable post-acquisition invoices are available for both the current and prior twelve-month12-month period. Included within our 2025 net revenue retention rate is the impact from the heightened win rates above our historically high rates and accelerated implementation timelines related to the cybersecurity incident of one of our competitors in February 2024.
Our count of clients who generate more than $100,000 of revenue is based on an accumulation of the amounts invoiced to clients over the preceding twelve12 months. The invoices for acquired clients are included starting in the first full calendar quarter after the date of acquisition. Our customer count as of December 31, 2025 includes 44 clients from the Iodine acquisition.
Cash flows from operating, investing, and financing activities for the years ended December 31, 2024, 20232025 and 2022,2024, are summarized in the following table:
Net Cash Flows Provided by Operating Activities
Cash flows provided by operating activities were $309.7 million for the year ended December 31, 2025 as compared to $169.8 million for the year ended December 31, 2024 as compared to $51.5 million for the year ended December 31, 2023.2024. This increase was largely driven by the changes in working capital, increases in revenue and profits, and decreases in the cash paid for interest due to the multiple paydowns on our First Lien Credit Facility in 2024.2024, and changes in working capital.
Cash flows provided by operating activities were $51.5 million for the year ended December 31, 2023 as compared to $102.6 million for the year ended December 31, 2022. The decrease was primarily driven by the change in deferred income taxes and income tax receivable resulting in a decrease of $43.4 million and by an impairment expense of $10.9 million recognized in 2022 related to leasehold improvements and right-of-use assets at closed office locations.
Net Cash Flows Used in Investing Activities
Cash flows used in investing activities were $27.3 million for the year ended December 31, 2024 as compared to $61.5 million for the year ended December 31, 2023. Cash flows used in investing activities decreased due to the $40.0 million of cash used in the 2023 acquisitions of HealthPay24 and certain assets of Olive AI (see Part II, Item 8, “Financial Statements—Note 6”).
Cash flows used in investing activities were $61.5$680.9 million for the year ended December 31, 20232025 as compared to $17.4$27.3 million for the year ended December 31, 2022.2024. CashThis flowsincrease was primarily due to the $629.5 million of cash used in investingthe activitiesIodine acquisition during the year ended December 31, 2025 (see Part II, Item 8, “Financial Statements—Note 7”). Additionally, they also increased in 2023 relativedue to 2022the asnet weimpact usedof $40.0purchases millionand forsales acquisitionsof completedinvestment insecurities 2023.during the year ended December 31, 2025.
Net Cash Flows Provided By (Used In) Financing Activities
Cash flows provided by financing activities were $243.5 million for the year ended December 31, 2025 as compared to $16.7 million for the year ended December 31, 2024 as compared to cash flows used of $17.2 million for the year ended December 31, 2023.2024. The increase was due to the decrease in number of payments on our debt compared to the prior period (see Part II, Item 8, “Financial Statements—Note 13”), as well as an increase in proceeds from issuance of common stock from employee equity plans. These increases were partially offset by a decrease due to the proceeds from our IPO net of third-party IPO issuance costs (see Part II, Item 8, “Financial Statements—Note 1”), during the year ended December 31, 2024, as well as the issuance of debt, net of creditor fees (see Part II, Item 8, “Financial Statements—Note 1113). Thesein increasesthe wereprior offsetperiod. byAlso increaseddriving paymentsa decrease is the settlement on our debtLouisville comparedoffice tolease during the prioryear periodended December 31, 2025 (see Part II, Item 8, “Financial Statements—Note 11”10).
Cash flows used in financing activities were $17.2 million for the year ended December 31, 2023 as compared to $67.1 million for the year ended December 31, 2022. Cash flows used in financing activities decreased in 2023 relative to 2022 primarily due to the $47.0 million partial pay down in principal of the Second Lien Credit Facility in April 2022.
What changed in the latest 10-Q
Risk Factors
New heading “Our business, results of operations, prospects, and financial condition may be materially adversely affected by a number of factors, whether currently known or unknown, including those described in Part I, Item 1A "Risk Factors" of the 2025 Form 10-K. Except as set forth below, there have been no material changes to the risk factors disclosed in the 2025 Form 10-K.”
New heading “Risks Related to Information Technology Systems, Cybersecurity, Data Privacy, and Intellectual Property”
New heading “We and our vendors are subject to attacks of such information technology systems, including cyber-attacks, security breaches, or other incidents impacting the information processed through our platform.”
Largest changes
“Additionally, any such event could result in fines, legal claims, or proceedings, including regulatory investigations and class actions, or liability for failure to comply with privacy and information security laws, which could disrupt our operations, damage our reputation, and expose us to claims from clients, individuals, and others, any of which could have a material adverse effect on our business, financial condition, and results of operations.”see in full comparison
“In addition, some of our third-party service providers and vendors also Process confidential and sensitive information such as our clients’ data on our behalf. These service providers and vendors are subject to similar threats, including cyber-attacks, security incidents, and other malicious internet-based activities, which could also expose us to risk of loss, litigation, potential liability, and/or other costs. We have limited insight into the data privacy or security practices of third-party vendors and providers, including as it relates to our AI algorithms. …”see in full comparison
“We and our vendors are subject to attacks of such information technology systems, including cyber-attacks, security breaches, or other incidents impacting the information processed through our platform.”see in full comparison
“A substantially adverse impact to the availability, integrity, or confidentiality of our information technology systems or data, or the information technology systems or data of third parties upon which we rely, could require us to expend significant resources to mitigate the breach of security, pay any applicable fines, and address matters related to any such breach, including notifying impacted individuals, the media, or regulators, making public disclosures, and addressing reputational harm.”see in full comparison
“Our business, results of operations, prospects, and financial condition may be materially adversely affected by a number of factors, whether currently known or unknown, including those described in Part I, Item 1A "Risk Factors" of the 2025 Form 10-K. Except as set forth below, there have been no material changes to the risk factors disclosed in the 2025 Form 10-K.”see in full comparison
“We and certain of our third-party providers have experienced cyber-attacks and other incidents, and we expect such attacks and incidents to continue in varying degrees in the future. For example, in early June 2026, we identified the unauthorized acquisition of point-in-time copies of source code, primarily used for testing purposes, from a cloud-based repository hosted by a third-party provider and the unauthorized acquisition of four files of inactive data from a single application, which had been written to cloud-based storage pending its scheduled destruction. …”see in full comparison
Full comparison: every changed paragraph (12)
Our business, results of operations, prospects, and financial condition may be materially adversely affected by a number of factors, whether currently known or unknown, including those described in Part I, Item 1A "Risk Factors" of the 2025 Form 10-K. Except as set forth below, there have been no material changes to the risk factors disclosed in the 2025 Form 10-K.
Risks Related to Information Technology Systems, Cybersecurity, Data Privacy, and Intellectual Property
We and our vendors are subject to attacks of such information technology systems, including cyber-attacks, security breaches, or other incidents impacting the information processed through our platform.
We collect, create, receive, maintain, process, use, transmit, disclose, transfer, alter, and store (collectively, “Process”) significant amounts of patients' personal information (including PHI) received in connection with the utilization of our platform and otherwise in connection with the operation of our business, as well as other sensitive, confidential, and proprietary information such as trade secrets, source code and payment data. Attacks on information technology systems are increasing in frequency, levels of persistence, sophistication, and intensity, and they are being conducted by increasingly sophisticated and organized groups and individuals, including state- sponsored organizations, with a wide range of motives and expertise. In addition to extracting personal information and other sensitive or confidential information, such attacks involve the deployment of harmful malware, ransomware, denial-of-service attacks, social engineering, and other means to affect service reliability and threaten the confidentiality, integrity, security, and availability of our information or information technology systems. The prevalent use of mobile devices also increases the risk of data security incidents. Further, like all internet-based solutions, our solutions are vulnerable to software bugs, computer viruses, malware, internet worms, break-ins, phishing attacks, attempts to overload servers with denial-of- service, or other attacks or similar disruptions from unauthorized use of our and third-party computer systems, any of which could lead to system interruptions, delays or shutdowns, loss of critical data, unauthorized acquisition of or access to data, or the compromise of our information technology systems.
We and certain of our third-party providers have experienced cyber-attacks and other incidents, and we expect such attacks and incidents to continue in varying degrees in the future. For example, in early June 2026, we identified the unauthorized acquisition of point-in-time copies of source code, primarily used for testing purposes, from a cloud-based repository hosted by a third-party provider and the unauthorized acquisition of four files of inactive data from a single application, which had been written to cloud-based storage pending its scheduled destruction. The incident was promptly contained and did not involve any access to active production systems or client data being processed by any active Waystar products. The application-related data and, we believe, the subset of source code in the third-party code repository platform used for testing purposes prior to 2023 included PHI and personally identifiable information associated with fewer than 1% of Waystar clients. We immediately activated incident response procedures, initiated an investigation, engaged leading external cybersecurity experts, notified law enforcement, and took steps to contain, assess, and remediate the incident. We are also in the process of communicating with the relevant clients and will comply with any applicable legal obligations. The incident did not impact the operation of our software solutions, the ability of clients to access our cloud-based software platform, or any functions of our financial and operating reporting systems. While to date, we have no evidence that the affected information has been misused, the threat actor may use or disclose the information that was subject to unauthorized access and acquisition in a manner that adversely affects our business. We may also discover additional impacts of this or other incidents as part of that investigation. While our response efforts are ongoing, we believe this incident has not had, and is not reasonably likely to have, any material adverse effect on our operations or financial condition, and we expect that a portion of costs incurred relating to containing, investigating and remediating the incident will be reimbursed through insurance recoveries. Despite these expectations, there can be no assurances as to the ultimate impact of this incident, which may result in harm to our reputation and client relationships.
Techniques used to gain unauthorized access to or acquisitions of data and systems, disable or degrade service, or sabotage systems, are constantly evolving (including through the use of AI), and we are unable to anticipate all techniques or comprehensively avoid unauthorized access, acquisitions of, or other adverse impacts to our data or our systems. AI-enabled tools provide threat actors with greater scale, efficiency and effectiveness than is possible through human action alone. Such tools are used to produce highly customized phishing campaigns through generative AI, polymorphic malware that adapts in real-time to a victim environment during deployment, and automated vulnerability identification and reconnaissance, among other things. We may not discover all such incidents or activity or be able to respond or otherwise address them promptly, in sufficient respects or at all. Any specific interruption or attack, any failure to maintain performance, reliability, security, and availability of our products, or failure to prevent software bugs and other corruptants such as those listed above, to the satisfaction of our clients or their patients, may harm our reputation and our ability to retain existing clients, negatively affect our clients and their patients, and adversely impact our business, results of operations, and financial condition.
In addition, some of our third-party service providers and vendors also Process confidential and sensitive information such as our clients’ data on our behalf. These service providers and vendors are subject to similar threats, including cyber-attacks, security incidents, and other malicious internet-based activities, which could also expose us to risk of loss, litigation, potential liability, and/or other costs. We have limited insight into the data privacy or security practices of third-party vendors and providers, including as it relates to our AI algorithms. We have also acquired and may continue to acquire companies that are vulnerable to cyber-attacks and security incidents and breaches, and we may be responsible for any such attacks, incidents, and breaches of these newly acquired companies.
Further, the security systems in place at our employees’, vendors’, and service providers’ offices and homes may be less secure than those used in our offices, and while we have implemented technical, physical, and administrative safeguards to help protect our systems when our employees, vendors, and service providers work from their offices, homes, and other remote locations, we may be subject to increased cybersecurity risk, which could expose us to risks of data or financial loss, and could disrupt our business operations. There is no guarantee that the data security and privacy safeguards we have put in place will ultimately be effective or that we will not encounter risks associated with employees, vendors, and service providers accessing company data and systems remotely.
A substantially adverse impact to the availability, integrity, or confidentiality of our information technology systems or data, or the information technology systems or data of third parties upon which we rely, could require us to expend significant resources to mitigate the breach of security, pay any applicable fines, and address matters related to any such breach, including notifying impacted individuals, the media, or regulators, making public disclosures, and addressing reputational harm.
Additionally, any such event could result in fines, legal claims, or proceedings, including regulatory investigations and class actions, or liability for failure to comply with privacy and information security laws, which could disrupt our operations, damage our reputation, and expose us to claims from clients, individuals, and others, any of which could have a material adverse effect on our business, financial condition, and results of operations.
The costs of mitigating data security risks are significant and are likely to increase in the future. Although we carry cybersecurity insurance, we cannot ensure our limits are sufficient to cover us against all potential losses for damages or fines in an amount exceeding our policy limits, or that applicable insurance will be available to us in the future on economically reasonable terms or at all.
There have been no material changes to the risk factors disclosed in the 2025 Form 10-K.
Management's Discussion & Analysis (MD&A)
New heading “Results of Operations for the Six Months Ended June 30, 2026 and 2025”
New heading “Cost of Revenue (Exclusive of Depreciation and Amortization)”
New heading “Sales and Marketing”
New heading “General and Administrative”
New heading “Research and Development”
New heading “Depreciation and Amortization”
New heading “Interest Expense, net”
New heading “Income Tax Expense”
New heading “Stock Repurchase Plan”
Removed heading “Impacts of Our Competitor’s Cybersecurity Attack”
Largest changes
“On May 19, 2026, we announced that our Board of Directors authorized a stock repurchase plan pursuant to which we may repurchase up to $200 million of shares of its outstanding common stock. Under the plan, we may repurchase shares from time to time using a variety of methods, which may include open market purchases or other methods, in accordance with applicable securities laws and regulations. …”see in full comparison
“Results of Operations for the Six Months Ended June 30, 2026 and 2025”see in full comparison
“Following the February 2024 cybersecurity incident involving one of our competitors, more than 30,000 providers, including a significant number of large health systems and ambulatory providers, began adopting our solutions, and we were able to implement our solutions for many of these new clients in as little as 48 hours. This incident and our response to it generated approximately $11 million in additional revenue in the three months ended March 31, 2025 due to increased win rates above our historically competitive rates and associated accelerated implementation timeline.”see in full comparison
Full comparison: every changed paragraph (52)
Our software is used daily by providers of all types and sizes across the continuum of care, including physician practices, clinics, surgical centers, and laboratories, as well as large hospitals and health systems. We currently serve over 30,000 clients of various sizes, representing over one million distinct providers practicing across a variety of care sites, including 16 of the top 20 U.S. News Best Hospitals. Our business model aligns with our clients' growth; as they serve more patients, claims and transaction volumes increase, driving corresponding growth in our business. In addition, our clients frequently adopt a greater number of our solutions over time and introduce our solutions across new sites of care. In 2025, we facilitated over 7.5 billion healthcare paymentspayment transactions, including over $2.4 trillion in gross claims volume spanning approximately 60% of patients and one-in-three hospital discharges in the United States.
We have demonstrated an ability to drive recurring, predictable, and profitable growth. Over 99% of our revenue is either recurring subscription or based on highly predictable volumes. For the 12 months ended MarchJune 31,30, 2026, our Net Revenue Retention Rate was 110.5%,108.3%, and we have 1,4331,453 clients as of MarchJune 31,30, 2026 generating over $100,000 over the same 12-month period. For the threesix months ended MarchJune 31,30, 2026, we generated revenue of $313.9$633.5 million (reflecting a 22.4%20.2% increase compared to revenue of $256.4$527.1 million for the same period in the prior year), net income of $43.3$84.2 million (reflecting a 36.9% increase compared to net income of $29.3$61.5 million for the same period in the prior year,year), and Adjusted EBITDA of $135.4$272.1 million (reflecting a 25.7%23.5% increase compared to Adjusted EBITDA of $107.7$220.3 million for the same period in the prior year).
On February 24, 2025, the Institutional Investors closed an underwritten public offering of 23,000,000 shares of our common stock (inclusive of the underwriters’ option to purchase additional shares) (the “First Secondary Offering”). On May 15, 2025, the Institutional Investors closed another underwritten public offering of 14,375,000 shares of our common stock (inclusive of the underwriters’ option to purchase additional shares) (the “Second Secondary Offering”). Additionally, on September 10, 2025, the Institutional Investors closed another underwritten public offering of 18,000,000 shares of our common stock (the “Third Secondary Offering”). We did not sell any shares in these offerings or receive any proceeds from these offerings. Pursuant to the terms of the Amended and Restated Registration Rights Agreement, dated as of June 10, 2024, by and among Waystar, the Institutional Investors, and certain other parties thereto, we paid $1.4 million in certain expenses on behalf of the selling stockholders related to these offerings for the three months ended March 31, 2025, while the selling stockholders paid all applicable underwriting discounts and commissions.
Additionally, on September 10, 2025, the Institutional Investors closed another underwritten public offering of 18,000,000 shares of our common stock (the “Third Secondary Offering”). We did not sell any shares in these offerings or receive any proceeds from these offerings. Pursuant to the terms of the Amended and Restated Registration Rights Agreement, dated as of June 10, 2024, by and among Waystar, the Institutional Investors, and certain other parties thereto, we paid $1.8 million and $3.2 million in certain expenses on behalf of the selling stockholders related to these offerings for the three and six months ended June 30, 2025, while the selling stockholders paid all applicable underwriting discounts and commissions.
Impacts of Our Competitor’s Cybersecurity Attack
Following the February 2024 cybersecurity incident involving one of our competitors, more than 30,000 providers, including a significant number of large health systems and ambulatory providers, began adopting our solutions, and we were able to implement our solutions for many of these new clients in as little as 48 hours. This incident and our response to it generated approximately $11 million in additional revenue in the three months ended March 31, 2025 due to increased win rates above our historically competitive rates and associated accelerated implementation timeline.
We primarily generate two types of revenue: (i) subscription revenue and (ii) volume-based revenue, which account for 99% of total revenue for all periods presented. We believe we have high visibility into our volume-based and subscription revenue from existing clients. We refer to the solutions our clients use to better process and understand their payment workflows from payers as provider solutions, and we refer to the products that assist healthcare providers in collecting payments from patients as patient paymentpayments solutions. We expect provider solutions will continue to generate the substantial majority of our total revenue, although the revenue mix attributable to patient paymentpayments solutions is expected to increase slightly over time.
•Subscription revenue. Reflects recurring monthly provider count fees and minimum amounts owed. The vast majority of subscription revenue is generated by provider solutions, which constituted approximately 70% of total revenue in each of the three and six months ended MarchJune 31,30, 2026 and 2025.
Cost of revenue includes salaries, stock-based compensation, and benefits (“personnel costs”) for our team members who are focused on implementation, support, and other client-focused operations, as well as team members focused on enhancing and developing our platform. Cost of revenue also includes costs for third-party technology such as interchange fees and infrastructure related to the operations of our platform, including communicating and processing patient payments, and services to support the delivery of our solutions. Third-party costs for patient payments solutions are approximately 60% of the revenue generated from these solutions, while third-party costs for provider solutions are approximately 6% to 7% of the associated revenue, in each case, for botheach of the three and six months ended MarchJune 31,30, 2026 and 2025.
Results of Operations for the Three Months Ended MarchJune 31,30, 2026 and 2025
Revenue was $313.9$319.7 million for the three months ended MarchJune 31,30, 2026 as compared to $256.4$270.7 million for the three months ended MarchJune 31,30, 2025, an increase of $57.4$49.0 million, or 22.4%,18.1%, of which $47.1$45.2 million was attributed to increased subscription revenue from existing and acquired clients, almost all of which iswas generated by provider solutions. Another $9.5$3.9 million was attributed to increased volume-based revenue,revenue primarily related to the expansion of existing client usage, of which $6.4$5.9 million of the volume-based increase was generated by providerpatient solutionspayments andsolutions, $3.2partially offset by a decrease of $2.1 million by patient paymentprovider solutions.
Cost of revenue (exclusive of depreciation and amortization) was $97.0$97.7 million for the three months ended MarchJune 31,30, 2026 as compared to $83.3$87.0 million for the three months ended MarchJune 31,30, 2025, an increase of $13.7$10.6 million, or 16.4%.12.2%. The increase was primarily driven by $6.7$5.1 million in increased costs stemming from higher transaction volumevolumes and associated third-party costs, including higher platform usage,usage of which approximately $4.7 million was from third-party costs associated with provider solutions and $2.0$5.6 million was third-party costs associated with paymentprovider solutions, partially offset by a decrease of $0.5 million from third-party costs associated with patient solutions. Additionally, there was a $4.8$4.0 million increaseof inincreased personnel costs, net of capitalized expenses.expense.
Sales and marketing expense was $45.8$50.4 million for the three months ended MarchJune 31,30, 2026 as compared to $40.1$43.5 million for the three months ended MarchJune 31,30, 2025, an increase of $5.7$6.9 million, or 14.2%.15.7%. The increase was primarily driven by an increase in channel partner fees and amortization of the internal commission deferred contract costs asset of $3.6 million associated with revenue growth as well asand increased personnel costs of $3.4$2.5 million.
General and administrative expense was $30.7$36.4 million for the three months ended MarchJune 31,30, 2026 as compared to $23.3$29.2 million for the three months ended MarchJune 31,30, 2025, an increase of $7.4$7.2 million, or 31.9%.24.6%. The increase was primarily due to an increase in stock-based compensation expense of $4.6$2.5 million as well as an increase inincreased personnel costs of $1.6$1.4 million. In addition, there was an impairment expense related to a right-of-use asset and leasehold improvements at an office we plan to exit (see Note 7) driving a $2.0 million increase.
Research and development expense was $18.4$17.7 million for the three months ended MarchJune 31,30, 2026 as compared to $11.1$12.6 million for the three months ended MarchJune 31,30, 2025, an increase of $7.3$5.1 million, or 65.8%.40.4%. The increase was primarily drivendue byto an increase inincreased personnel costs, net of capitalized expenses, of $3.4 million, as well as an increase in stock-based compensation expense of $1.6$4.5 million.
Depreciation and amortization expense was $41.5 million for the three months ended MarchJune 31,30, 2026, as compared to $33.4 million for the three months ended MarchJune 31,30, 2025, an increase of $8.1$8.0 million, or 24.2%.24.1%. The increase is primarily due to additional amortization from new Iodine intangible assets acquired on October 1, 2025.
Total interest expense, net (including related party interest expense) was $20.6$19.6 million for the three months ended MarchJune 31,30, 2026 as compared to $18.9$18.3 million for the three months ended MarchJune 31,30, 2025, an increase of $1.7$1.4 million, or 9.2%.7.6%. The increase was primarily driven by the additional balance takenborrowed out onunder our First Lien Credit Facility to help fund the Iodine acquisition completed on October 1, 2025, resulting in an increase to the corresponding interest expense. This increase was partially offset by interest earned in our investment securities.
Income tax expense ofwas $16.5$15.5 million for the three months ended MarchJune 31,30, 20262026, was relatively flatas compared to an income tax expense of $17.0$14.4 million for the three months ended MarchJune 31,30, 2025, aan decreaseincrease of $0.5$1.1 million. The increase was primarily driven by the increase in pre-tax income.
Results of Operations for the Six Months Ended June 30, 2026 and 2025
The following table provides consolidated operating results for the periods indicated and percentage of revenue for each line item:
Revenue
Revenue was $633.5 million for the six months ended June 30, 2026 as compared to $527.1 million for the six months ended June 30, 2025, an increase of $106.5 million, or 20.2%, of which $92.3 million was attributed to increased subscription revenue from existing and acquired clients, almost all of which is generated by provider solutions. Another $13.4 million was attributed to increased volume-based revenue, primarily related to the expansion of existing client usage, of which $4.3 million of the volume-based increase was generated by provider solutions and $9.1 million by patient payments solutions.
Cost of Revenue (Exclusive of Depreciation and Amortization)
Cost of revenue (exclusive of depreciation and amortization) was $194.7 million for the six months ended June 30, 2026 as compared to $170.4 million for the six months ended June 30, 2025, an increase of $24.3 million, or 14.3%. The increase was driven by $11.7 million in increased costs stemming from higher transaction volume and associated third-party costs, including higher platform usage, of which approximately $10.2 million was from third-party costs associated with provider solutions and $1.5 million was from third-party costs associated with payment solutions. Additionally, there was an $8.8 million increase in personnel costs, net of capitalized expenses.
Sales and Marketing
Sales and marketing expense was $96.2 million for the six months ended June 30, 2026 as compared to $83.6 million for the six months ended June 30, 2025, an increase of $12.6 million, or 15.0%. The increase was primarily driven by an increase in channel partner fees and amortization of the internal commission deferred contract costs asset totaling $7.2 million associated with revenue growth as well as increased personnel costs of $5.8 million.
General and Administrative
General and administrative expense was $67.1 million for the six months ended June 30, 2026 as compared to $52.5 million for the six months ended June 30, 2025, an increase of $14.6 million, or 27.8%. The increase was primarily due to an increase in stock-based compensation expense of $7.1 million as well as increased personnel costs of $3.0 million. In addition, there was an impairment expense related to a right-of-use asset and leasehold improvements at an office we plan to exit (see Note 7) driving a $2.0 million increase.
Research and Development
Research and development expense was $36.1 million for the six months ended June 30, 2026 as compared to $23.7 million for the six months ended June 30, 2025, an increase of $12.4 million, or 52.3%. The increase was primarily driven by increased personnel costs, net of capitalized expenses, of $7.9 million, as well as increased software license expense of $1.5 million.
Depreciation and Amortization
Depreciation and amortization expense was $82.9 million for the six months ended June 30, 2026, as compared to $66.8 million for the six months ended June 30, 2025, an increase of $16.1 million, or 24.1%. The increase is primarily due to additional amortization from new Iodine intangible assets acquired on October 1, 2025.
Interest Expense, net
Total interest expense, net (including related party interest expense) was $40.3 million for the six months ended June 30, 2026 as compared to $37.2 million for the six months ended June 30, 2025, an increase of $3.1 million, or 8.4%. The increase was primarily driven by the additional balance borrowed on our First Lien Credit Facility to help fund the Iodine acquisition completed on October 1, 2025, resulting in an increase to the corresponding interest expense. This increase was partially offset by interest earned on our investment securities.
Income Tax Expense
Income tax expense of $32.1 million for the six months ended June 30, 2026 was relatively flat compared to income tax expense of $31.4 million for the six months ended June 30, 2025, an increase of $0.6 million.
We define adjusted EBITDA as net income before interest expense, net, income tax expense, depreciation and amortization, and as further adjusted for stock-based compensation expense, acquisition and integration costs, asset and lease impairments, costs related to amended debt agreements, and costs related to our IPO and the Secondary Offerings.Offerings, and costs related to other unusual, non-recurring or otherwise notable items. Adjusted EBITDA margin represents adjusted EBITDA as a percentage of revenue.
The following table presents a reconciliation of net income to adjusted EBITDA and net income margin to adjusted EBITDA margin for the three and six months ended MarchJune 31,30, 2026 and 2025:
_______________________________________________________________ (a)AdjustmentsFor relatethe three and six months ended June 30, 2026, adjustments related to costs for the cybersecurity incident (see Item 1A below). For the three and six months ended June 30, 2025, adjustments related to additional lease costs due to the relocation of our Louisville office totaling $0.2 million and $0.4 million, respectively, and executive severance totaling $0.5$0.0 million forand the$0.5 threemillion, months ended March 31, 2025.respectively.
We define non-GAAP net income as GAAP net income excluding the impact of stock-based compensation, acquisition and integration costs, asset and lease impairments, costs related to our IPO and the Secondary Offerings, costs related to amended debt agreements and amortization of intangibles.intangibles, and costs related to other unusual, non-recurring or otherwise notable items. The tax effects of the adjustments are calculated using a management estimated annual effective non-GAAP tax rate of 21%, which is based on our statutory federal tax rate and provides consistency across interim reporting periods by eliminating the effects of non-recurring and period specific items. Due to the differences in the tax treatment of items excluded from non-GAAP net income, our estimated tax rate on non-GAAP net income may differ from our GAAP tax rate.
The following table presents a reconciliation of net income to non-GAAP net income and non-GAAP net income per share for the three and six months ended MarchJune 31,30, 2026 and 2025:
(a)AdjustmentsFor relatethe three and six months ended June 30, 2026, adjustments related to costs for the cybersecurity incident (see Item 1A below). For the three and six months ended June 30, 2025, adjustments related to additional lease costs due to the relocation of our Louisville office totaling $0.2 million and $0.4 million, respectively, and executive severance totaling $0.5$0.0 million forand the$0.5 threemillion, months ended March 31, 2025.respectively.
The following table presents our Net Revenue Retention Rate for MarchJune 31,30, 2026 and 2025, respectively:
Our Net Revenue Retention Rate compares 12 months of client invoices for our solutions at two period end dates. To calculate our Net Revenue Retention Rate, we first accumulate the total amount invoiced during the 12 months ending with the prior period-end, or Prior Period Invoices. We then calculate the total amount invoiced to those same clients for the 12 months ending with the current period-end, or Current Period Invoices. Current Period Invoices are inclusive of upsell, downsell, pricing changes, clients that cancel or choose not to renew, and discontinued solutions with continuing clients. The Net Revenue Retention Rate is then calculated by dividing the Current Period Invoices by the Prior Period Invoices. Our total invoices included in the analysis are greater than 98% of reported revenue. We use Net Revenue Retention Rate to evaluate our ongoing operations and for internal planning and forecasting purposes. Acquired businesses are included in the last-12 month Net Revenue Retention Rate in the ninth quarter after acquisition, which is the earliest point that comparable post-acquisition invoices are available for both the current and prior 12-month period. Included within our net revenue retention rates for the twelve12 months ended MarchJune 31,30, 2026 and 2025 is the impact from the heightened win rates above our historically high rates and accelerated implementation timelines related to the cybersecurity incident of one of our competitors in February 2024.
On MarchJune 31,30, 2026 and December 31, 2025, we had restricted cash of $28.4$32.8 million and $15.5 million, respectively, which consists of cash deposited in lockbox accounts owned by us which are contractually required to be disbursed to participating clients on the following day, as well as cash collected on behalf of healthcare providers from patients that have not yet been remitted to providers. These funds payable are not available for our use and liquidity, and are offset on our balance sheet by an aggregated funds payable liability.
Our liquidity is influenced by many factors, including timing of revenue and corresponding cash collections, the amount and timing of investments in strategic initiatives, our investments in property, equipment, and software, share repurchases, as well as other factors described under “Risk Factors” in the 2025 Form 10-K. Depending on the severity and direct impact of these factors on us, we may not be able to secure additional financing on acceptable terms, or at all.
Cash flows from operating, investing, and financing activities for the threesix months ended MarchJune 31,30, 2026 and MarchJune 31,30, 2025, are summarized in the following table:
Net cash provided by operating activities was $84.9$144.3 million for the threesix months ended MarchJune 31,30, 2026 as compared to $64.2$161.0 million for the threesix months ended MarchJune 31,30, 2025, ana increasedecrease of $20.7$16.7 million. This increasedecrease was largely driven by deferred federal tax payments in 2025 as allowed by the IRS, as well changes in working capital. These decreases were partially offset by increases in revenue and profits and changes in working capital.profits.
Net cash used in investing activities was $112.5$182.1 million for the threesix months ended MarchJune 31,30, 2026 as compared to $29.9$61.7 million for the threesix months ended MarchJune 31,30, 2025, an increase of cash used of $82.6$120.4 million. Net cash used in investing activities increased primarily due to an increase innet investment securityactivity purchases,for our securities, as well as more purchases of property and equipment during the threesix months ended MarchJune 31,30, 2026 compared to the threesix months ended MarchJune 31,30, 2025.
Net cash flows provided by financing activities was $13.5$6.4 million for the threesix months ended MarchJune 31,30, 2026 as compared to $10.7$7.6 million for the threesix months ended MarchJune 31,30, 2025, ana increasedecrease of $2.7$1.2 million. The primary driver of the increasedecrease was due to common stock repurchased during the quarter (see Note 15), as well as a decrease in proceeds from issuance of common stock from employee equity plans. Also driving the decrease was the net impact of proceeds from amendment ro our Receivables Facility (see Note 11) and the corresponding paydown on our First Lien Credit Facility (see Note 12). These decreases were partially offset by an increase in restricted cash related to customers' cash deposited into our lockbox but contractually required to be disbursed to the participating clients (see Note 2 in our 2025 Form 10-K for details on restricted cash accounting policies). This increase was offset by a decrease in proceeds from issuance of common stock from employee equity plans, as well as the net impact of proceeds from amendment to our Receivables Facility (see Note 11) and the corresponding paydown on our First Lien Credit Facility (see Note 12).
Stock Repurchase Plan
On May 19, 2026, we announced that our Board of Directors authorized a stock repurchase plan pursuant to which we may repurchase up to $200 million of shares of its outstanding common stock. Under the plan, we may repurchase shares from time to time using a variety of methods, which may include open market purchases or other methods, in accordance with applicable securities laws and regulations. The timing, price, and size of repurchases will depend on a number of factors, including the market price of our common stock, our financial performance and liquidity, general economic and market conditions, and other considerations. The stock repurchase plan does not obligate us to acquire any particular amount of common stock and may be suspended or discontinued at any time. The repurchase plan will be funded using our working capital.
WAY insider buying and selling (Form 4)
Since 2026-04-11, insiders reported open-market purchases in 0 Form 4 filings and open-market sales in 4 filings (1 insider, 6 trade dates, 317,500 shares, about $8.0M; 4 of these filings say the sales were made under a Rule 10b5-1 trading plan). Net open-market shares: -317,500 (purchases minus sales); net value about -$8.0M.Totals add up every open-market (code P and S) line in those filings, using the prices reported in the filings. Awards, option exercises, tax withholding and gifts are listed below but not counted.
| Trade date | Insider | Transaction | Shares | Price | Value |
|---|---|---|---|---|---|
| 2026-10-06 | Hawkins Matthew J. |
Option exercise |
82,500 | $4.14 | $341.6K |
| 2026-10-06 | Hawkins Matthew J. |
Open-market sale |
82,500 | $26.23 | $2.2M |
| 2026-10-05 | Chan William |
Shares withheld for tax | 9,560 | $26.07 | $249.2K |
| 2026-09-02 | Hawkins Matthew J. |
Open-market sale |
82,500 | $25.97 | $2.1M |
| 2026-09-02 | Hawkins Matthew J. |
Option exercise |
82,500 | $4.14 | $341.6K |
| 2026-09-01 | Packer Gregory R |
Shares withheld for tax | 6,754 | $25.73 | $173.8K |
| 2026-09-01 | Bridge T. Craig |
Shares withheld for tax | 30,792 | $25.73 | $792.3K |
| 2026-09-01 | Hawkins Matthew J. |
Shares withheld for tax |
30,287 | $25.73 | $779.3K |
| 2026-08-17 | Khanna Amit |
Grant/award | 390,625 | — | — |
| 2026-08-13 | Hawkins Matthew J. |
Open-market sale |
60,038 | $25.01 | $1.5M |
| 2026-08-13 | Hawkins Matthew J. |
Option exercise |
60,038 | $4.14 | $248.6K |
| 2026-08-11 | Hawkins Matthew J. |
Option exercise |
22,462 | $4.14 | $93.0K |
| 2026-08-11 | Hawkins Matthew J. |
Open-market sale |
22,462 | $25.04 | $562.4K |
| 2026-08-01 | Woods Todd Charles |
Grant/award | 90,827 | — | — |
| 2026-08-01 | Packer Gregory R |
Grant/award | 232,061 | — | — |
| 2026-08-01 | Hawkins Matthew J. |
Grant/award | 908,265 | — | — |
| 2026-08-01 | Bridge T. Craig |
Grant/award | 205,470 | — | — |
| 2026-07-24 | Wegner Alpana |
Grant/award | 162,112 | — | — |
| 2026-07-16 | Hawkins Matthew J. |
Option exercise |
36,901 | $4.14 | $152.8K |
| 2026-07-16 | Hawkins Matthew J. |
Open-market sale |
36,901 | $23.09 | $852.0K |
| 2026-07-15 | Hawkins Matthew J. |
Open-market sale |
33,099 | $23.02 | $761.9K |
| 2026-07-15 | Hawkins Matthew J. |
Option exercise |
33,099 | $4.14 | $137.0K |
| 2026-06-09 | Hawkins Matthew J. |
Shares withheld for tax | 47,754 | $19.23 | $918.3K |
| 2026-06-09 | Wittman Kimberly S. |
Shares withheld for tax | 2,731 | $19.23 | $52.5K |
| 2026-06-09 | Bridge T. Craig |
Shares withheld for tax | 12,212 | $19.23 | $234.8K |
| 2026-06-09 | Oreskovich Steven M |
Shares withheld for tax | 12,583 | $19.23 | $242.0K |
| 2026-06-09 | Miller Melissa F. (Missy) |
Shares withheld for tax | 2,887 | $19.23 | $55.5K |
| 2026-06-09 | Schremser Christopher L. |
Shares withheld for tax | 14,751 | $19.23 | $283.7K |
| 2026-06-03 | Driscoll John Patrick |
Grant/award | 10,446 | — | — |
| 2026-06-03 | Gupta Aashima |
Grant/award | 10,446 | — | — |
| 2026-06-03 | Demichiei Robert |
Grant/award | 10,446 | — | — |
| 2026-06-03 | Riefberg Vivian E. |
Grant/award | 10,446 | — | — |
| 2026-06-03 | Miller Heidi |
Grant/award | 10,446 | — | — |
| 2026-06-03 | Roman Michael F |
Grant/award | 10,446 | — | — |
| 2026-06-03 | Hung Priscilla |
Grant/award | 10,446 | — | — |
| 2026-06-03 | Demichiei Robert |
Grant/award | 9,303 | — | — |
| 2026-06-03 | Gupta Aashima |
Grant/award | 9,303 | — | — |
| 2026-06-03 | Roman Michael F |
Grant/award | 9,303 | — | — |
| 2026-06-03 | Riefberg Vivian E. |
Grant/award | 9,303 | — | — |
| 2026-06-03 | Miller Heidi |
Grant/award | 9,303 | — | — |
| 2026-06-03 | Hung Priscilla |
Grant/award | 9,303 | — | — |
| 2026-06-03 | Driscoll John Patrick |
Grant/award | 9,303 | — | — |
| 2026-04-06 | Packer Gregory R |
Shares withheld for tax | 4,016 | $23.69 | $95.1K |
Well-known investors holding WAY (13F)
None of the 59 investors we track reported a position in their latest 13F.