← Back to WAY filing summaryThis is the extracted source text from the SEC filing. Formatting may differ from the original document.
Our business, results of operations, prospects, and financial condition may be materially adversely affected by a number of factors, whether currently known or unknown, including those described in Part I, Item 1A "Risk Factors" of the 2025 Form 10-K. Except as set forth below, there have been no material changes to the risk factors disclosed in the 2025 Form 10-K.
Risks Related to Information Technology Systems, Cybersecurity, Data Privacy, and Intellectual Property
We and our vendors are subject to attacks of such information technology systems, including cyber-attacks, security breaches, or other incidents impacting the information processed through our platform.
We collect, create, receive, maintain, process, use, transmit, disclose, transfer, alter, and store (collectively, “Process”) significant amounts of patients' personal information (including PHI) received in connection with the utilization of our platform and otherwise in connection with the operation of our business, as well as other sensitive, confidential, and proprietary information such as trade secrets, source code and payment data. Attacks on information technology systems are increasing in frequency, levels of persistence, sophistication, and intensity, and they are being conducted by increasingly sophisticated and organized groups and individuals, including state- sponsored organizations, with a wide range of motives and expertise. In addition to extracting personal information and other sensitive or confidential information, such attacks involve the deployment of harmful malware, ransomware, denial-of-service attacks, social engineering, and other means to affect service reliability and threaten the confidentiality, integrity, security, and availability of our information or information technology systems. The prevalent use of mobile devices also increases the risk of data security incidents. Further, like all internet-based solutions, our solutions are vulnerable to software bugs, computer viruses, malware, internet worms, break-ins, phishing attacks, attempts to overload servers with denial-of- service, or other attacks or similar disruptions from unauthorized use of our and third-party computer systems, any of which could lead to system interruptions, delays or shutdowns, loss of critical data, unauthorized acquisition of or access to data, or the compromise of our information technology systems.
We and certain of our third-party providers have experienced cyber-attacks and other incidents, and we expect such attacks and incidents to continue in varying degrees in the future. For example, in early June 2026, we identified the unauthorized acquisition of point-in-time copies of source code, primarily used for testing purposes, from a cloud-based repository hosted by a third-party provider and the unauthorized acquisition of four files of inactive data from a single application, which had been written to cloud-based storage pending its scheduled destruction. The incident was promptly contained and did not involve any access to active production systems or client data being processed by any active Waystar products. The application-related data and, we believe, the subset of source code in the third-party code repository platform used for testing purposes prior to 2023 included PHI and personally identifiable information associated with fewer than 1% of Waystar clients. We immediately activated incident response procedures, initiated an investigation, engaged leading external cybersecurity experts, notified law enforcement, and took steps to contain, assess, and remediate the incident. We are also in the process of communicating with the relevant clients and will comply with any applicable legal obligations. The incident did not impact the operation of our software solutions, the ability of clients to access our cloud-based software platform, or any functions of our financial and operating reporting systems. While to date, we have no evidence that the affected information has been misused, the threat actor may use or disclose the information that was subject to unauthorized access and acquisition in a manner that adversely affects our business. We may also discover additional impacts of this or other incidents as part of that investigation. While our response efforts are ongoing, we believe this incident has not had, and is not reasonably likely to have, any material adverse effect on our operations or financial condition, and we expect that a portion of costs incurred relating to containing, investigating and remediating the incident will be reimbursed through insurance recoveries. Despite these expectations, there can be no assurances as to the ultimate impact of this incident, which may result in harm to our reputation and client relationships.
Techniques used to gain unauthorized access to or acquisitions of data and systems, disable or degrade service, or sabotage systems, are constantly evolving (including through the use of AI), and we are unable to anticipate all techniques or comprehensively avoid unauthorized access, acquisitions of, or other adverse impacts to our data or our systems. AI-enabled tools provide threat actors with greater scale, efficiency and effectiveness than is possible through human action
42
Table of Contents
alone. Such tools are used to produce highly customized phishing campaigns through generative AI, polymorphic malware that adapts in real-time to a victim environment during deployment, and automated vulnerability identification and reconnaissance, among other things. We may not discover all such incidents or activity or be able to respond or otherwise address them promptly, in sufficient respects or at all. Any specific interruption or attack, any failure to maintain performance, reliability, security, and availability of our products, or failure to prevent software bugs and other corruptants such as those listed above, to the satisfaction of our clients or their patients, may harm our reputation and our ability to retain existing clients, negatively affect our clients and their patients, and adversely impact our business, results of operations, and financial condition.
In addition, some of our third-party service providers and vendors also Process confidential and sensitive information such as our clients’ data on our behalf. These service providers and vendors are subject to similar threats, including cyber-attacks, security incidents, and other malicious internet-based activities, which could also expose us to risk of loss, litigation, potential liability, and/or other costs. We have limited insight into the data privacy or security practices of third-party vendors and providers, including as it relates to our AI algorithms. We have also acquired and may continue to acquire companies that are vulnerable to cyber-attacks and security incidents and breaches, and we may be responsible for any such attacks, incidents, and breaches of these newly acquired companies.
Further, the security systems in place at our employees’, vendors’, and service providers’ offices and homes may be less secure than those used in our offices, and while we have implemented technical, physical, and administrative safeguards to help protect our systems when our employees, vendors, and service providers work from their offices, homes, and other remote locations, we may be subject to increased cybersecurity risk, which could expose us to risks of data or financial loss, and could disrupt our business operations. There is no guarantee that the data security and privacy safeguards we have put in place will ultimately be effective or that we will not encounter risks associated with employees, vendors, and service providers accessing company data and systems remotely.
A substantially adverse impact to the availability, integrity, or confidentiality of our information technology systems or data, or the information technology systems or data of third parties upon which we rely, could require us to expend significant resources to mitigate the breach of security, pay any applicable fines, and address matters related to any such breach, including notifying impacted individuals, the media, or regulators, making public disclosures, and addressing reputational harm.
Additionally, any such event could result in fines, legal claims, or proceedings, including regulatory investigations and class actions, or liability for failure to comply with privacy and information security laws, which could disrupt our operations, damage our reputation, and expose us to claims from clients, individuals, and others, any of which could have a material adverse effect on our business, financial condition, and results of operations.
The costs of mitigating data security risks are significant and are likely to increase in the future. Although we carry cybersecurity insurance, we cannot ensure our limits are sufficient to cover us against all potential losses for damages or fines in an amount exceeding our policy limits, or that applicable insurance will be available to us in the future on economically reasonable terms or at all.