{"url_path":"/sec/hsic/10-k/2026/item-1a","section_key":"item-1a","section_title":"Item 1A Risk Factors","topic":"sec","document":{"doc_type":"10-K","doc_date":"2026-02-24","source_url":"https://www.sec.gov/Archives/edgar/data/1000228/0001000228-26-000013-index.html","accession_number":"0001000228-26-000013","cik":"0001000228","ticker":"HSIC","issuer_name":"HENRY SCHEIN INC","edgar_url":"https://www.sec.gov/Archives/edgar/data/1000228/0001000228-26-000013-index.html","primary_entity_key":"0001000228","primary_entity_name":"HENRY SCHEIN INC"},"word_count":11121,"has_tables":false,"body_markdown":"ITEM 1A. Risk Factors\n\nOur business operations could be affected by factors that are not presently known\n\nto us or that we currently\n\nconsider not to be material to our operations, so you should not consider\n\nthe risks disclosed in this section to\n\nnecessarily represent a complete statement of all risks and uncertainties.\n\nThe Company believes that the following\n\nrisks could have a material adverse impact on our business, reputation, operating\n\nresults, financial condition and/or\n\nthe trading price of our common stock.\n\nThe order in which these factors appear does not necessarily reflect\n\ntheir\n\nrelative importance or priority.\n\nCOMPANY RISKS\n\nWe are dependent upon third parties for the manufacture/supply of a significant volume of our products and\n\nwhere we manufacture products, we are dependent upon third parties\n\nfor raw materials/purchased components.\n\nWe obtain a significant volume of the products we distribute from third parties, with whom we generally do not\n\nhave long-term contracts.\n\nWhile there is typically more than one source of supply, some key suppliers, in the\n\naggregate, supply a significant portion of the products we sell.\n\nIn 2025, our top 10 Global Distribution and Value-\n\nAdded Services suppliers and our single largest supplier accounted for approximately\n\n24% and 4%, respectively, of\n\nour aggregate purchases.\n\nAdditionally, where we are the manufacturer of products for our speciality business (\n\ne.g.\n\n,\n\ndental implants, endodontics, and orthopedics), we are dependent upon third parties\n\nfor raw materials and\n\npurchased components.\n\nAlthough no single supplier is material, because of our dependence\n\nupon such suppliers,\n\nour operations are subject to the suppliers’ ability and willingness to supply\n\nproducts in the quantities that we\n\nrequire, and the risks include delays caused by interruption in production\n\nbased on conditions outside of our\n\ncontrol, including a supplier’s failure to comply with applicable government\n\nrequirements (which may result in\n\nproduct recalls, product detentions, and/or cessation of sales) or an interruption\n\nin the suppliers’ manufacturing\n\ncapabilities.\n\nIn the event of any such interruption in supply, we would need to timely identify and obtain acceptable\n\nreplacement sources.\n\nThere is no guarantee that we would be able to obtain such alternative\n\nsources of supply on a\n\ntimely basis, if at all, and an extended interruption in supply, particularly of a high-sales volume and/or high-\n\nmargin product, could result in a significant disruption in our sales and operations,\n\nas well as damage to our\n\nrelationships with customers and our reputation.\n\nWe may be unsuccessful in achieving our strategic growth objectives.\n\nOur 2025 – 2027 BOLD+1 Strategic Plan is defined under “Business, Business\n\nStrategy” above.\n\nIn particular, we\n\nare focused on continuing to grow our Henry Schein specialty brands\n\nand technology and value-added services\n\nsolutions both organically and inorganically, and to drive greater efficiencies.\n\nIf we are unable to effectively\n\nimplement our strategic plan, we may not achieve our desired return on our\n\ninvestments through our growth\n\nstrategies.\n\nOur business could be affected by the Strategic Partnership Agreement with KKR.\n\nOn January 29, 2025, we announced a strategic investment by\n\nfunds affiliated with KKR & Co. Inc. (“KKR”), a\n\nleading global investment firm, and a Strategic Partnership Agreement (the “Partnership\n\nAgreement”) with KKR.\n\nUnder the Partnership Agreement, two independent directors, Max Lin and\n\nWilliam K. “Dan” Daniel, joined our\n\nBoard of Directors.\n\nOn May16, 2025, we issued 3,285,151 shares of common stock\n\nto funds affiliated with KKR\n\nfor an investment of $250 million, at approximately $76.10 per share.\n\nPursuant to the Partnership Agreement, KKR\n\nalso has the ability to purchase additional shares via open market purchases\n\nup to a total equity stake of 14.9% of\n\nthe outstanding shares of common stock of the Company.\n\nOn November 4, 2025, the Company and KKR entered\n\ninto an amendment to the Partnership Agreement that increased the beneficial ownership\n\nlimit from 14.9% to19.9%\n\nof the outstanding shares of the Company’s common stock that KKR is permitted to acquire during the\n\nstandstill\n\nperiod.\n\nThe standstill provisions, including the increased ownership limit,\n\ncontinue in effect for a period of six\n\nmonths following the later of the expiration of the term of the Partnership Agreement\n\nand the date on which no\n\nKKR director appointed pursuant to the Partnership Agreement is serving on\n\nthe Company’s Board of Directors.\n\nOn December 7, 2025, pursuant to the Partnership Agreement, KKR notified\n\nthe Company of its election to\n\nexercise the Extension Election (as defined in the Partnership Agreement) whereby\n\nthe Company’s Board of\n\n[Table of Contents](#a296)\n\n[Index to Financial Statements](#a33909)\n\n29\n\nDirectors will renominate KKR’s designees, Max Lin and William K. “Dan” Daniel, to stand for election at the\n\nCompany’s 2026 annual meeting of stockholders for a term expiring at the Company’s 2027 annual meeting of\n\nstockholders. The Partnership Agreement may have unintended consequences,\n\nsuch as uncertainty about our\n\nmanagement, operations, or future strategic direction, which could\n\nresult in the loss of future business opportunities\n\nor negatively impact our ability to attract and retain qualified talent.\n\nKKR also invests in many different types of\n\nbusinesses, and has or may continue to invest in customers, suppliers,\n\njoint venture partners, or other entities that\n\nhave relationships with the Company, or in competitors of such entities, which may create unintended conflicts\n\nresulting in a loss of business.\n\nOur future growth (especially for our Global Technology and Global Specialty Products segments) is dependent\n\nupon our ability to develop or acquire and maintain and protect\n\nnew products and services and utilize new\n\ntechnologies that achieve market acceptance with acceptable margins.\n\nOur future success depends on our ability to timely develop (or obtain the right\n\nto sell) competitive and innovative\n\n(particularly for our Global Technology and Global Specialty Products segments) products and services and utilize\n\nnew technologies, such as artificial intelligence (“AI”) (among other emerging technologies)\n\nand to market them\n\nand/or utilize them quickly and cost-effectively.\n\nOur ability to anticipate customer needs and emerging trends and\n\ndevelop or acquire new products, services and technologies at competitive\n\nprices requires significant resources,\n\nincluding employees with the requisite skills, experience and expertise, particularly\n\nin our Global Technology\n\nsegment, including dental practice management, patient engagement\n\nand demand creation software solutions.\n\nThe\n\nfailure to successfully address these challenges could materially disrupt\n\nour sales and operations.\n\nWe have increased and expect to continue to increase our use of AI technologies in various contexts to improve\n\ncustomer and patient experiences and drive efficiencies in certain areas of our business,\n\nincluding, without\n\nlimitation, making AI features available within our practice management\n\nsystems, which, among other things, helps\n\ndentists and clinical staff detect caries.\n\nWhile these innovations can present benefits to the Company, they also\n\ncreate risks and challenges.\n\nThe use of AI in healthcare offerings poses certain clinical risks resulting\n\nfrom\n\npotential misdiagnosis or misinformation provided from AI applications, diminishing\n\ncritical judgment, or loss of\n\ninterpersonal care from clinicians.\n\nThese deficiencies could undermine the decisions, predictions,\n\nor analysis AI\n\napplications produce, as well as their adoption, subjecting us to competitive\n\nharm, legal liability (including under\n\nnew proposed legislation regulating AI in jurisdictions such as the EU\n\nor new applications of existing data\n\nprotection, privacy, intellectual property, and other laws), regulatory actions, and reputational harm.\n\nIn addition,\n\nsome AI scenarios, such as using AI applications to generate patient data\n\n(including, without limitation, using AI to\n\ncapture and summarize patient interactions, and voice-activated perio charting),\n\npresent ethical, privacy, or other\n\nsocial issues, risking reputational harm and/or reduced market demand\n\nor acceptance of AI solutions.\n\nThe\n\nsafeguards we have designed to promote the ethical implementation\n\nof AI may not be sufficient to protect us\n\nagainst negative outcomes.\n\nAll of these risks are amplified by the critical nature of healthcare decisions\n\nand the\n\nsensitivity of health-related information, and the occurrence of any of\n\nthe above could have a material adverse\n\neffect on our business, financial condition or operating results.\n\nAdditionally, if investments in emerging\n\ntechnologies are less successful at attracting and retaining customers than\n\nsimilar investments by our competitors,\n\nor if we are otherwise unsuccessful at realizing the benefits of these\n\ntechnological investments generally, this could\n\nhave a material adverse effect on our business, financial condition, or operating\n\nresults.\n\nAdditionally, widely\n\naccessible generative AI that rapidly surpasses our organizational ability to understand\n\nassociated risks and\n\nopportunities (including employees’ failure to comply with principles,\n\npolicies and processes governing AI usage)\n\ncould endanger our intellectual property, lead to misuse or loss of data and cause reputational harm and other fines,\n\npenalties or losses.\n\nRisks inherent in acquisitions, dispositions and joint ventures could\n\noffset the anticipated benefits.\n\nOne of our business strategies has been to expand in part through acquisitions\n\nand joint ventures and we expect to\n\ncontinue to make acquisitions and enter into joint ventures in the future.\n\nThere is risk that one or more may not\n\nsucceed.\n\nWe cannot be sure, for example, that we will achieve the benefits of revenue growth that we expect from\n\nthese transactions or that we will avoid unforeseen additional costs, taxes,\n\nor expenses.\n\nOur ability to successfully\n\nimplement our acquisition and joint venture strategy depends upon,\n\namong other things, the following:\n\n•\n\nthe availability of suitable acquisition or joint venture candidates at\n\nacceptable prices;\n\n[Table of Contents](#a296)\n\n[Index to Financial Statements](#a33909)\n\n30\n\n•\n\nour ability to consummate such transactions, which could potentially\n\nbe prohibited due to U.S. or\n\nforeign antitrust regulations;\n\n•\n\nthe liquidity of our investments and the availability of financing on\n\nacceptable terms;\n\n•\n\nour ability to retain customers or product lines of the acquired businesses or\n\njoint ventures;\n\n•\n\nour ability to retain, recruit and incentivize the management of the\n\ncompanies we acquire; and\n\n•\n\nour ability to successfully integrate these companies’ operations, systems,\n\nservices, products and\n\npersonnel with our culture, management policies, legal, regulatory and compliance\n\npolicies,\n\ninformation technology and cybersecurity systems and policies,\n\ninternal procedures, working capital\n\nmanagement, financial, operational and internal controls and strategies.\n\nFurthermore, some of our acquisitions and future acquisitions may give\n\nrise to an obligation to make contingent\n\npayments or to satisfy certain repurchase obligations, which payments\n\ncould have material adverse impacts on our\n\nfinancial results individually or in the aggregate.\n\nAdditionally, when we decide to sell assets or a business, we may\n\nencounter difficulty in finding buyers or timely executing alternative exit strategies\n\non acceptable terms, which\n\ncould delay the accomplishment of our strategic objectives.\n\nDispositions may also involve continued financial\n\ninvolvement in a divested business, such as through transition service agreements,\n\nindemnities or other current or\n\ncontingent financial obligations.\n\nCertain provisions in our governing documents and other documents to\n\nwhich we are a party may discourage\n\nthird parties from seeking to acquire us that might otherwise result\n\nin our stockholders receiving a premium\n\nover the market price of their shares.\n\nThe provisions of our certificate of incorporation and by-laws may\n\nmake it more difficult for a third-party to\n\nacquire us, may discourage acquisition bids and may impact the price\n\nthat certain investors might be willing to pay\n\nin the future for shares of our common stock.\n\nThese provisions, among other things require (i) the affirmative vote\n\nof the holders of at least 60% of the shares of common stock entitled to vote\n\nto approve a merger, consolidation, or\n\na sale, lease, transfer or exchange of all or substantially all of our assets;\n\nand (ii) the affirmative vote of the holders\n\nof at least 66 2/3% of our common stock entitled to vote to (a)\n\nremove a director; and (b) to amend or repeal our\n\nby-laws, with certain limited exceptions.\n\nIn addition, certain of our employee incentive plans provide\n\nfor\n\naccelerated vesting of equity awards upon termination without cause within\n\ntwo years following a change in\n\ncontrol, or grant the plan committee discretion to accelerate awards\n\nupon a change of control.\n\nFurther, certain\n\nagreements between us and our executive officers provide for increased severance\n\npayments and certain benefits if\n\nthose executive officers are terminated without cause by us or if they terminate\n\nfor good reason, in each case within\n\ntwo years following a change in control or within ninety days prior to the\n\neffective date of the change in control or\n\nafter the first public announcement of the pendency of the change\n\nin control.\n\nAdverse changes in supplier rebates or other purchasing incentives\n\ncould negatively affect our business.\n\nThe terms on which we purchase or sell products from many suppliers may\n\nentitle us to receive a rebate or other\n\npurchasing incentive based on the attainment of certain growth goals.\n\nSuppliers may reduce or eliminate rebates or\n\nincentives offered under their programs, or increase the growth goals or other conditions\n\nwe must meet to earn\n\nrebates or incentives to levels that we cannot achieve.\n\nIncreased competition either from generic or equivalent\n\nbranded products could result in us failing to earn rebates or incentives\n\nthat are conditioned upon achievement of\n\ngrowth goals.\n\nAdditionally, factors outside of our control, such as customer preferences, consolidation of suppliers\n\nor supply issues, can have a material impact on our ability to achieve\n\nthe growth goals established by our suppliers,\n\nwhich may reduce the amount of rebates or incentives we receive.\n\nSales of corporate brand products and products that we manufacture\n\nentail additional risks, including the risk\n\nthat such sales could materially adversely affect our relationships with suppliers.\n\nWe offer\n\ncertain corporate brand products that are available exclusively\n\nfrom us.\n\nThe sale of such corporate brand\n\nproducts and the sale of products that we manufacture subject us to\n\npotential product liability risks, mandatory or\n\nvoluntary product recalls, potential supply chain and distribution chain\n\ndisruptions and potential intellectual\n\nproperty infringement risks, among other risks.\n\nIn addition, an increase in the sales of our corporate brand products\n\nand our own manufactured products may negatively affect our sales of products\n\nowned by our suppliers which,\n\n[Table of Contents](#a296)\n\n[Index to Financial Statements](#a33909)\n\n31\n\nconsequently, could adversely impact certain of our supplier relationships.\n\nOur ability to locate qualified,\n\neconomically stable suppliers who satisfy our requirements, and\n\nto acquire sufficient products in a timely and\n\neffective manner, are critical to ensuring, among other things, that customer confidence is not diminished.\n\nIn\n\naddition, we are exposed to the risk that our competitors or our large customers may\n\nintroduce their own private\n\nlabel, generic, or low-cost products that compete with our products at\n\nlower price points.\n\nSuch products could\n\ncapture significant market share or decrease market prices overall, eroding\n\nour sales and margins.\n\nAny failure to\n\ndevelop sourcing relationships with a broad and deep supplier base\n\ncould have a material adverse effect on our\n\nbusiness, financial condition or operating results.\n\nOur business could be affected by activist investors.\n\nWe actively engage in discussions with our stockholders.\n\nIn other cases, stockholders can engage in certain\n\ndivisive activist tactics, which can take many forms (including potential\n\nproxy contests).\n\nSome stockholder\n\nactivism has resulted in, and could in the future result in, substantial\n\ncosts, such as professional fees, and the\n\ndiversion of management’s and our Board of Directors’ attention and resources from our business and strategic\n\nplans.\n\nAdditionally, it could cause uncertainty about our management, operations or future strategic direction,\n\nwhich could result in the loss of future business opportunities or negatively\n\nimpact our ability to attract and retain\n\nqualified talent.\n\nActivists or other stockholders holding a large portion of our outstanding shares\n\ncould also exert\n\ninfluence on actions requiring a stockholder vote, including the election of directors\n\nand the approval of certain\n\nextraordinary business transactions.\n\nThese risks could cause volatility in the trading price of our common\n\nstock\n\nbased on factors other than the fundamentals of our business.\n\nINDUSTRY RISKS\n\nSecurity risks generally associated with our information systems and our\n\ntechnology products and services have\n\nin the recent past adversely affected our business and results of operations, and could\n\nin the future materially\n\nadversely affect our business and our results of operations if such products, services,\n\nor systems (or third-party\n\nsystems we rely on) are interrupted, damaged by unforeseen events, are subject\n\nto cyberattacks or fail for any\n\nextended period of time.\n\nWe rely on information systems (“IS”) in our business to obtain, rapidly process, analyze, manage and store\n\ncustomer, product, supplier and employee data to, among other things:\n\n•\n\nmaintain and manage worldwide systems to facilitate the purchase and\n\ndistribution of thousands of\n\ninventory items from numerous distribution centers;\n\n•\n\nreceive, process and ship orders on a timely basis;\n\n•\n\nmanage the accurate billing and collections for our customers;\n\n•\n\nprocess payments to suppliers;\n\n•\n\nprovide products and services that maintain certain of our customers’ electronic\n\nmedical or dental\n\nrecords (including protected health information of their patients); and\n\n•\n\nmaintain and manage global human resources, compensation and payroll\n\nsystems.\n\nThere could be an adverse impact on our business, financial condition\n\nor operating results if we do not maintain an\n\nadequate information and technology infrastructure (\n\ne.g.\n\n, hardware, networks, software, people and processes) to\n\neffectively protect and support the current and future information requirements of the business.\n\nIn addition to\n\nhealth information in our customers’ electronic medical and dental records, certain\n\nof our IS store other sensitive\n\npersonal and financial information, such as health care and other information\n\nrelated to our employees and\n\nindividuals we service, as well as other sensitive information such as\n\ncredit card information from our third-party\n\nbusiness partners, that is confidential, and in many cases subject to privacy\n\nlaws.\n\nOur IS are susceptible to, among other things, natural disasters, power\n\nlosses, telecommunication failures,\n\ncybersecurity threats and other criminal activity.\n\nInformation security risks have significantly increased\n\nin recent\n\nyears in part because of an overall increase in cyber incidents, their increased\n\nsophistication and the involvement of\n\norganized crime, hackers, terrorists and foreign state agents.\n\nThe health care industry has been targeted by threat\n\nactors seeking to undermine companies’ cybersecurity defensive\n\nmeasures.\n\nMoreover, cyberattacks have become\n\nmore difficult to detect and respond to.\n\nThey increasingly exploit AI and machine learning techniques,\n\nsuch as\n\n[Table of Contents](#a296)\n\n[Index to Financial Statements](#a33909)\n\n32\n\ngenerative AI-phishing, deepfake impersonations, automated vulnerability\n\ndiscovery, adaptive malware and large-\n\nscale credential-stuffing campaigns.\n\nNew subsidiaries that we acquire and non-integrated subsidiaries have\n\nbeen,\n\nand may continue to be, targets to cyberattacks as we update their defensive measures\n\nto meet our standards.\n\nWe\n\nhave processes in place intended to ensure that our security measures\n\nkeep pace with new and emerging risks.\n\nWe\n\nregularly review, monitor and implement multiple layers of security through technology, processes and our people.\n\nWe utilize security technologies designed to protect and maintain the integrity of our IS and data, and our defenses\n\nare monitored and routinely tested internally and by external parties.\n\nDespite these efforts, our facilities and\n\nsystems and those of our third-party service providers have been, and\n\nmay in the future be, vulnerable to privacy\n\nand security incidents, cybersecurity attacks and data breaches, acts of\n\nvandalism or theft, computer viruses and\n\nother malicious code, misplaced or lost data, programming and/or human\n\nerrors, attacks or other acts undermining\n\nIS of third party business partners including our customers, or other similar\n\nevents that could impact the security,\n\nreliability and availability of our systems.\n\nIn addition, hardware, software or applications developed\n\ninternally or\n\nprocured from third parties may contain defects in design or manufacture\n\nor other problems that could unexpectedly\n\ncompromise information security.\n\nAs a practical matter, so long as we depend on IS to operate our business, and\n\nour business partners do the same, there can be no guaranty\n\nthat such measures will successfully stop any one\n\nparticular cybersecurity incident given the constantly evolving nature of\n\nthe threat.\n\nWe have incurred, continue to\n\nincur, and may in the future incur substantial costs as we update our cybersecurity defense systems\n\nand our general\n\ncomputer controls to meet evolving challenges, and legislative or regulatory\n\naction related to cybersecurity which\n\nmay increase our costs to develop or implement new technology products\n\nand services.\n\nA cyberattack that bypasses or compromises our, or our vendors’, IS cybersecurity and/or general\n\ninformation\n\ntechnology (“IT”) controls (including third-party systems we rely on)\n\ncausing an IS security breach may lead, and\n\nhas in the past led, to a disruption of our, or our vendors’, IS business systems (including third-party systems\n\nwe\n\nrely on), interruption of operations (including, without limitation, receiving,\n\nverifying and processing customer\n\norders, customer service, accounts payable, warehouse management and\n\nshipping and systems tied to internal\n\ncontrols over financial reporting), the loss or alteration of business,\n\nfinancial and other protected information, a\n\nnegative impact on our financial performance, and to an adverse\n\nimpact on our financial accounting and reporting\n\ncontrols.\n\nA cyberattack that bypasses or compromises our IS cybersecurity\n\nand/or general computer controls or\n\nthose of third parties with whom we engage may also lead to claims against\n\nus by affected parties and/or\n\ngovernmental agencies, and involve fines and penalties, as well as substantial\n\ndefense and settlement expenses.\n\nAny of these impacts may alone, or collectively, have a material impact on our business.\n\nA successful cyberattack\n\nhas, and may again in the future, disrupt our business operations, adversely\n\nimpact our financial accounting and\n\nreporting of results of operations, divert the attention of management,\n\nand adversely impact our results of\n\noperations.\n\nIn addition, we develop products and provide services to our customers\n\nthat are technology-based, and a\n\ncyberattack that bypasses the IS supporting our products or services causing\n\na security breach and/or perceived\n\nsecurity vulnerabilities in our products or services could also cause significant\n\nloss of business and reputational\n\nharm, and actual or perceived vulnerabilities may lead to claims against\n\nus by our customers and/or governmental\n\nagencies.\n\nIn addition, certain of our practice management products and services\n\npurchased by health care\n\nproviders, such as physicians and dentists, are used to store and manage patient\n\nmedical or dental records, and when\n\ncloud-based approaches are used, we may be responsible for hosting\n\nthose records.\n\nThese customers, and in some\n\ncases, we are subject to laws and regulations which require that\n\nthey protect the privacy and security of those\n\nrecords, and our products may be used as part of these customers’ comprehensive\n\ndata security programs, including\n\nin connection with their efforts to comply with applicable privacy and security laws.\n\nIn addition to immaterial and unrelated incidents at certain of our subsidiaries,\n\nin October 2023 Henry Schein\n\nexperienced a cybersecurity incident that primarily affected the operations of our\n\nNorth American and European\n\ndental and medical distribution businesses.\n\nHenry Schein One, our practice management software, revenue\n\ncycle\n\nmanagement and patient relationship management solutions business was\n\nnot affected, and our manufacturing\n\nbusinesses were mostly unaffected.\n\nNevertheless, the October 2023 cybersecurity incident disrupted\n\nkey business\n\noperations, adversely impacted our financial results for the fourth quarter\n\nand full year 2023, diverted attention of\n\nmanagement, and caused the Company to incur significant remediation\n\ncosts.\n\nThe incident had residual impact on\n\nour financial results in 2024.\n\nWe have spent, and plan to expend in the future, additional resources to continue to\n\n[Table of Contents](#a296)\n\n[Index to Financial Statements](#a33909)\n\n33\n\nprotect against, or to address problems caused by, business interruptions and data security breaches.\n\nWe also may\n\nbe perceived as a more vulnerable target of the cyber hackers as a result of the October\n\n2023 incident.\n\nThe health care products distribution industry is highly competitive\n\n(including, without limitation, competition\n\nfrom third-party online commerce sites) and consolidating, and we may not\n\nbe able to compete successfully.\n\nWe compete with numerous companies, including several major manufacturers and distributors.\n\nSome of our\n\ncompetitors have greater financial and other resources than we do, which\n\ncould allow them to compete more\n\nsuccessfully.\n\nMost of our products are available from several sources and our customers\n\ntend to have relationships\n\nwith several distributors.\n\nCompetitors could obtain exclusive rights to market particular\n\nproducts, which we would\n\nthen be unable to market.\n\nManufacturers also could increase their efforts to sell directly to end-users and\n\nthereby\n\neliminate or reduce our role in distribution.\n\nIndustry consolidation among health care product distributors and\n\nmanufacturers, price competition, product unavailability, whether due to our inability to gain access to products or\n\nto interruptions in manufacturing supply, or the emergence of new competitors, also could increase competition.\n\nConsolidation has also increased among manufacturers of health care\n\nproducts, which could have a material\n\nadverse effect on our margins and product availability.\n\nWe could be subject to charges and financial losses in the\n\nevent we fail to satisfy minimum purchase commitments contained\n\nin some of our contracts.\n\nAdditionally,\n\ntraditional health care supply and distribution relationships are being challenged\n\nby online commerce solutions.\n\nThe continued advancement of online commerce by third parties and online\n\nprice transparency requires us to cost-\n\neffectively adapt to changing technologies, to enhance existing services and to differentiate\n\nour business (including\n\nwith additional value-added services) to address changing demands\n\nof consumers and our customers.\n\nThe\n\nemergence of such competition and our inability to anticipate and effectively respond to changes on\n\na timely basis\n\ncould have a material adverse effect on our business, financial condition or operating\n\nresults.\n\nThe health care industry is experiencing changes due to political, economic\n\nand regulatory influences that could\n\nmaterially adversely affect our business.\n\nThe health care industry is highly regulated and subject to changing\n\npolitical, economic and regulatory influences.\n\nUncertainty surrounding possible changes to the health care environment,\n\nincluding changes to regulatory\n\nenforcement priorities, may directly or indirectly adversely affect us.\n\nIn recent years, the health care industry has\n\nbeen undergoing significant changes driven by various efforts to reduce costs, including, among\n\nother factors:\n\ntrends toward managed care; collective purchasing arrangements and\n\nconsolidation among office-based health care\n\npractitioners; and changes in reimbursements to customers, including increased\n\nattention to value-based payment\n\narrangements, as well as enforcement activities (and related\n\nmonetary recoveries) by governmental officials.\n\nBoth\n\nour profitability and that of our customers may be materially adversely\n\naffected by laws and regulations reducing\n\nreimbursement rates for pharmaceuticals, medical supplies and devices,\n\nand/or medical treatments or services,\n\nchanges to the methodology by which reimbursement levels are determined,\n\nor regulating pricing, contracting and\n\ndiscounting practices with respect to medical products and services.\n\nIt is possible that the adoption of the One Big\n\nBeautiful Bill Act could impact eligibility for participation in Medicare\n\nand Medicaid programs, resulting in a\n\nchange in utilization of the health care system.\n\nIn addition, a number of states are considering and enacting laws\n\nor\n\nregulations to expand their oversight of health care transactions, which\n\nmay impact the financial stability and\n\nstrategic opportunities of certain of our customers.\n\nIf we are unable to react effectively to these and other changes\n\nin the health care industry, our business could be materially adversely affected.\n\nThe ACA greatly expanded health\n\ninsurance coverage in the United States and has been the target of legal and political\n\nchallenges since its adoption.\n\nAny outcome of these challenges that changes the ACA could have\n\na significant impact on the U.S. health care\n\nindustry and the ability or willingness of individuals to engage with it.\n\nExpansion of GPOs, DSOs, MSOs or provider networks and the\n\nmulti-tiered costing structure may place us at a\n\ncompetitive disadvantage.\n\nThe health care products industry is subject to a multi-tiered costing structure, which\n\ncan vary by manufacturer\n\nand/or product.\n\nUnder this structure, certain institutions can obtain more favorable\n\nprices for health care products\n\nthan we are able to obtain.\n\nThe multi-tiered costing structure continues to expand as many large integrated health\n\ncare providers and others with significant purchasing power, such as GPOs, DSOs and MSOs, demand\n\nmore\n\nfavorable pricing terms.\n\nAdditionally, the formation of provider networks, GPOs, DSOs and MSOs may shift\n\n[Table of Contents](#a296)\n\n[Index to Financial Statements](#a33909)\n\n34\n\npurchasing decisions to entities or persons with whom we do not have a historical\n\nrelationship and may threaten our\n\nability to compete effectively, which could in turn negatively impact our financial results.\n\nIn addition, such\n\norganizations may establish direct relationships with manufacturers, thereby\n\neither eliminating or reducing the\n\nservices historically provided by distributors.\n\nAlthough we are seeking to obtain similar terms from manufacturers\n\nto access lower prices demanded by GPO, DSO and MSO contracts or\n\nother contracts, and to develop relationships\n\nwith existing and emerging provider networks, GPOs, DSOs and MSOs, we\n\ncannot guarantee that such terms will\n\nbe obtained or contracts executed.\n\nIncreases in shipping costs or service issues with our third-party shippers\n\ncould harm our business.\n\nOur ability to meet our customers’ expedited delivery expectations is an\n\nintegral component of our business\n\nstrategy for which our customers rely.\n\nShipping is a significant expense in the operation of our business.\n\nWe ship\n\nalmost all of our orders through third-party delivery services, and typically bear\n\nthe cost of shipment.\n\nAccordingly,\n\nany significant increase in shipping rates could have a material adverse\n\neffect on our business, financial condition\n\nor operating results.\n\nWhile we have recently experienced increases in shipping costs,\n\nwe do not expect these\n\nadditional expenses to be material to our results now, however they could become material in a future fiscal period.\n\nSimilarly, strikes or other service interruptions by those shippers, including at transportation centers or shipping\n\nports, could cause our operating expenses to rise and materially adversely\n\naffect our ability to deliver products on a\n\ntimely basis.\n\nMACRO-ECONOMIC AND POLITICAL RISKS\n\nUncertain global and domestic macro-economic and political conditions\n\ncould materially adversely affect our\n\nresults of operations and financial condition.\n\nUncertain global and domestic macro-economic and political conditions\n\nthat affect the economy and the economic\n\noutlook of the United States, Europe, Asia and other parts of the\n\nworld could have a material adverse effect on our\n\nbusiness, financial condition or operating results.\n\nThese uncertainties, include, among other things, those listed\n\nunder “Management’s Discussion and Analysis of Financial Condition and Results of Operations, Cautionary\n\nNote\n\nRegarding Forward-Looking Statements.”\n\nAdditionally, changes in government, government debt and/or budget crises may lead to reductions in government\n\nspending in certain countries, which could reduce overall health care spending\n\nand/or lead to higher income or\n\ncorporate taxes, which could depress spending overall.\n\nRecessionary or inflationary conditions and depressed\n\nlevels of consumer and commercial spending may also cause customers\n\nto reduce, modify, delay,\n\nor cancel plans to\n\npurchase our products and may cause suppliers to reduce their output\n\nor change their terms of sale.\n\nWe have\n\nexperienced inflationary pressures, including higher freight costs and\n\ninterest expense, and pressures resulting from\n\nthe strengthening of the dollar, which have and continue to impact our results of operations.\n\nWe generally sell\n\nproducts to customers with payment terms.\n\nIf customers’ cash flow or operating and financial performance\n\ndeteriorate, or if they are unable to make scheduled payments or obtain\n\ncredit, they may not be able to, or may\n\ndelay, payment to us.\n\nLikewise, for similar reasons suppliers may restrict credit or impose\n\ndifferent payment terms.\n\nREGULATORY\n\nAND LITIGATION RISKS\n\nFailure to comply with existing and future regulatory requirements\n\ncould materially adversely affect our\n\nbusiness.\n\nWe strive to be compliant with the applicable laws, regulations and guidance described below in all material\n\nrespects, and believe we have effective compliance programs and other controls\n\nin place to ensure substantial\n\ncompliance.\n\nHowever, compliance is not guaranteed either now or in the future as certain laws, regulations\n\nand\n\nguidance may be subject to varying and evolving interpretations that could\n\naffect our ability to comply, as well as\n\nfuture changes, additions and enforcement approaches, including in light\n\nof political changes.\n\nChanges with\n\nrespect to the applicable laws, regulations and guidance described below\n\nmay require us to update or revise our\n\noperations, services, marketing practices, and compliance programs\n\nand controls, and may impose additional and\n\nunforeseen costs on us, pose new or previously immaterial risks to us, or\n\nmay otherwise have a material adverse\n\n[Table of Contents](#a296)\n\n[Index to Financial Statements](#a33909)\n\n35\n\neffect on our business.\n\nThere can be no assurance that current and future government\n\nregulations will not adversely\n\naffect our business, and we cannot predict new regulatory priorities, the form, content\n\nor timing of regulatory\n\nactions, and their impact on the health care industry and on our business\n\nand operations.\n\nGlobal efforts to contain health care costs continue to exert pressure on product pricing.\n\nIn the United States, there\n\nhas been increased scrutiny on drug pricing and concurrent efforts to control or\n\nreduce drug costs by Congress, the\n\nPresident, executive branch agencies and various states.\n\nWe may be required to report drug pricing data under\n\nfederal laws and regulations.\n\nSeveral U.S. states have adopted laws, that may apply to some of\n\nour operations, that\n\nrequire drug manufacturers, including re-packagers or re-labelers, to provide\n\nadvance notice of certain price\n\nincreases and to report information relating to price increases, while\n\nothers have established prescription drug\n\naffordability boards or multi-payer purchasing pools to reduce the cost of prescription\n\ndrugs.\n\nAt the federal level,\n\nfor example, the Inflation Reduction Act of 2022, among other things,\n\nrequires drug manufacturers that raise certain\n\nof their drug prices faster than the rate of inflation to pay rebates to Medicare,\n\nand over time will authorize the\n\nfederal government to negotiate directly with drug manufacturers to\n\nlower the prices of certain brand-name drugs\n\ncovered by Medicare.\n\nThese various evolving efforts create uncertainty and may adversely affect our business.\n\nUnder the Sunshine Act, we are required to collect and report detailed\n\ninformation regarding certain financial\n\nrelationships we have with covered recipients (\n\ne.g.\n\n, physicians, dentists, teaching hospitals, other health care\n\npractitioners) as well as physician ownership or investment interest.\n\nWe may be required to report information\n\nunder state transparency laws that address circumstances not covered\n\nby the Sunshine Act.\n\nWe are also subject to\n\nsimilar foreign transparency laws.\n\nWhile we believe we have substantially compliant programs and controls\n\nin\n\nplace satisfying the above laws and requirements, such compliance imposes\n\nadditional costs on us and the\n\nrequirements are sometimes unclear.\n\nOur business is subject to additional requirements under various local, state,\n\nfederal and foreign laws and\n\nregulations applicable to the sale and distribution of, and third-party payment\n\nfor, pharmaceuticals and medical\n\ndevices and HCT/P products.\n\nAmong the federal laws with which we must comply are the Controlled Substances\n\nAct, the Food, Drug & Cosmetic Act, the Federal Drug Quality and Security\n\nAct, including the Drug Supply Chain\n\nSecurity Act, and Section 361 of the Public Health Services Act.\n\nAmong other things, such laws and the\n\nregulations promulgated thereunder:\n\n•\n\nregulate the introduction, manufacture, advertising, marketing, promotion,\n\nsampling, pricing,\n\nreimbursement, labeling, packaging, storage, handling, returning,\n\nrecalling, reporting, distribution of,\n\ndisposal, and recordkeeping for drugs, HCT/P products and medical devices,\n\nincluding unique device\n\nidentifiers;\n\n•\n\nsubject us to inspection by the FDA, OSHA, and DEA and similar state\n\nauthorities;\n\n•\n\nregulate the storage, transportation and disposal of hazardous materials;\n\n•\n\nrequire us to advertise and promote our drugs and devices in accordance\n\nwith FDA regulations;\n\n•\n\nrequire us to report average sales price (ASP) to CMS for drugs or biologicals\n\npayable under Medicare\n\nPart B with or without a Medicaid drug rebate agreement;\n\n•\n\nrequire registration with the FDA and the DEA and various state agencies;\n\n•\n\nrequire us to design and operate a system to identify and report suspicious\n\norders of controlled\n\nsubstances to the DEA and certain states;\n\n•\n\nrequire us to manage returns of products that have been recalled and subject\n\nus to inspection of our\n\nrecall procedures and activities;\n\n•\n\nimpose on us reporting requirements if a pharmaceutical, HCT/P product or\n\nmedical device causes an\n\nadverse event, serious illness, injury or death;\n\n•\n\nrequire manufacturers, wholesalers, re-packagers and dispensers of prescription\n\ndrugs to identify and\n\ntrace certain prescription drugs as they are distributed;\n\n•\n\nrequire the licensing of prescription drug wholesalers and third-party\n\nlogistics providers; and\n\n•\n\nmandate compliance with standards for the recordkeeping, storage,\n\nhandling and documentation of\n\ntransactions involving prescription drugs and devices and associated\n\nreporting requirements.\n\nThe FDA regulates certain computer software and digital health products intended\n\nfor use in health care settings,\n\nincluding, for example, AI and machine learning-enabled medical devices\n\nand the cybersecurity of medical devices.\n\nCertain of our businesses involve the development and sale of\n\nsoftware and related products to support physician\n\n[Table of Contents](#a296)\n\n[Index to Financial Statements](#a33909)\n\n36\n\nand dental practice management, and it is possible that the FDA or\n\nforeign government authorities could determine\n\nthat one or more of our products is subject to regulation as a medical device,\n\nwhich could subject our businesses to\n\nsubstantial additional requirements, costs, potential enforcement actions\n\nor liabilities for noncompliance with\n\nrespect to these products.\n\nFor example, some of our imaging software is regulated\n\nas a medical device which\n\nsubjects our businesses to substantial additional requirements, costs\n\nand potential enforcement actions or liabilities\n\nfor noncompliance with respect to these products.\n\nApplicable federal, state, local and foreign laws and regulations also may\n\nrequire us to meet various standards\n\nrelating to, among other things, licensure, registration, program eligibility, procurement, third-party reimbursement,\n\nsales and marketing practices, product integrity and supply\n\ntracking to product manufacturers, product labeling,\n\npersonnel, privacy and security of health or other personal information,\n\ninstallation, maintenance and repair of\n\nequipment and the importation and exportation of products.\n\nThe FDA, DEA, OCR, and state privacy regulators, as\n\nwell as CMS (including with respect to complex Medicare reimbursement\n\nrequirements applicable to our specialty\n\nhome medical supplies business) and state Medicaid agencies, have\n\nrecently increased their regulatory and\n\nenforcement activities and, in particular, the DEA has heightened enforcement activities due to the\n\nopioid crisis in\n\nthe United States.\n\nThe failure to comply with any of these laws or regulations, or new interpretations\n\nof them, or the imposition of any\n\nadditional laws and regulations, could materially adversely affect our business.\n\nThe costs to us associated with\n\ncomplying with the various applicable statutes and regulations, as they now\n\nexist and as they may be modified,\n\ncould be material.\n\nAllegations by a governmental body that we have not complied\n\nwith these laws could have a\n\nmaterial adverse effect on our businesses.\n\nWhile we believe that we are substantially compliant with\n\napplicable\n\nlaws and regulations, and have adequate compliance programs and controls\n\nin place to ensure substantial\n\ncompliance, if it is determined that we have not complied with these laws,\n\nwe are potentially subject to warning\n\nletters, substantial civil and criminal penalties, mandatory recall of product,\n\nseizure of product and injunction,\n\nconsent decrees and suspension or limitation of payments to us, product\n\nsale and distribution.\n\nIf we enter into\n\nsettlement agreements to resolve allegations of non-compliance, we\n\ncould be required to make settlement payments\n\nor be subject to civil and criminal penalties, including fines and\n\nthe loss of licenses.\n\nNon-compliance with\n\ngovernment requirements could also adversely affect our ability to participate in\n\nimportant federal and state\n\ngovernment health care programs, such as Medicare and Medicaid,\n\nand damage our reputation.\n\nThe EU Medical Device Regulation (“MDR”) may adversely affect our business.\n\nThe EU MDR significantly modified the regulatory compliance requirements\n\nfor the medical device industry as a\n\nwhole.\n\nAmong other things, as mentioned above, the EU\n\nMDR:\n\n•\n\nstrengthens the rules on placing devices on the market and reinforces\n\nsurveillance thereafter;\n\n•\n\nestablishes explicit provisions on manufacturers’ responsibilities\n\nfor the follow-up of the quality,\n\nperformance and safety of devices placed on the market;\n\n•\n\nimproves the traceability of medical devices throughout the supply chain to\n\nthe end-user or patient\n\nthrough a unique identification number;\n\n•\n\nsets up a central database (EUDAMED) to provide patients, health care\n\nprofessionals and the public\n\nwith comprehensive information on devices, importers, and distributors\n\nregistered in the EU;\n\n•\n\nstrengthens rules for the assessment of certain high-risk devices, such\n\nas implants, which may have to\n\nundergo an additional check by experts before they are placed on the market; and\n\n•\n\ncontains specific provisions in the event of interruption or discontinuation\n\nof supply of a device.\n\nThe EU MDR imposes strict requirements for the confirmation that a\n\nproduct meets the regulatory requirements,\n\nincluding regarding a product’s clinical evaluation and a company’s quality systems, and for the distribution,\n\nmarketing and sale of medical devices, including post-market surveillance.\n\nPursuant to Regulation 2023/607 and\n\nsubject to certain conditions, medical devices that (i) obtained\n\na certificate under the EU Medical Device Directive\n\nfrom May 25, 2017, (ii) which was still valid on May 26, 2021, and (iii)\n\nhas not been subsequently withdrawn may\n\ncontinue to be placed on the market or put into service until December\n\n31, 2027 for higher risk devices or\n\nDecember 31, 2028 for medium and lower risk devices.\n\nThe modifications created by the EU MDR may have an\n\nimpact on the way we design and manufacture products and the way we\n\nconduct our business in the EEA.\n\n[Table of Contents](#a296)\n\n[Index to Financial Statements](#a33909)\n\n37\n\nIf we fail to comply with laws and regulations relating to health care\n\nfraud or other laws and regulations, we\n\ncould suffer penalties or be required to make significant changes to our operations,\n\nwhich could materially\n\nadversely affect our business.\n\nCertain of our businesses are subject to federal and state (and similar\n\nforeign) health care fraud and abuse, referral\n\nand reimbursement laws and regulations with respect to their operations.\n\nSome of these laws, referred to as “false\n\nclaims laws,” prohibit the submission or causing the submission of false or\n\nfraudulent claims for reimbursement to\n\nfederal, state and other health care payers and programs.\n\nOther laws, referred to as “anti-kickback laws,” prohibit\n\nsoliciting, offering, receiving or paying remuneration in order to induce or reward\n\nthe referral of a patient or\n\nordering, purchasing, leasing or arranging for, or recommending ordering, purchasing or leasing\n\nof, items or\n\nservices that are paid for by federal, state and other health care payers and programs.\n\nCertain additional state and\n\nfederal laws, such as the federal Physician Self-Referral Law (“Stark Law”),\n\nprohibit physicians and other health\n\ncare professionals from referring a patient to an entity with which\n\nthe physician (or family member) has a financial\n\nrelationship, for the furnishing of certain designated health services\n\n(for example, durable medical equipment and\n\nmedical supplies), unless an exception applies.\n\nThe fraud and abuse laws and regulations have been subject to heightened\n\nenforcement activity over the past few\n\nyears, often as the result of “relators” who serve as whistleblowers by filing\n\ncomplaints in the name of the United\n\nStates (and if applicable, particular states) under applicable false claims\n\nlaws, and who may receive up to 30% of\n\ntotal government recoveries.\n\nPenalties under fraud and abuse laws may be severe, including treble damages\n\nand\n\nsubstantial civil penalties under the federal False Claims Act, as\n\nwell as potential loss of licenses and the ability to\n\nparticipate in federal and state health care programs, criminal penalties,\n\nor imposition of a corporate compliance\n\nmonitor, which could have a material adverse effect on our business.\n\nAlso, these measures may be interpreted or\n\napplied by a prosecutorial, regulatory or judicial authority in a\n\nmanner that could require us to make changes in our\n\noperations or incur substantial defense and settlement expenses.\n\nEven unsuccessful challenges by regulatory\n\nauthorities or relators could result in reputational harm and the incurring of\n\nsubstantial costs.\n\nMost states have\n\nadopted similar state false claims acts, and these state laws have their\n\nown penalties which may be in addition to\n\nfederal False Claims Act penalties, and other fraud and abuse laws.\n\nThe U.S. government and industry trade associations (among others) have expressed\n\nconcerns about financial\n\nrelationships between suppliers or manufacturers on the one hand and\n\nphysicians, dentists and other health care\n\nproviders, on the other.\n\nAs a result, we regularly review and revise our marketing\n\npractices as necessary to\n\nfacilitate compliance.\n\nOur aspirations, goals and disclosures related to environmental, social\n\nand governance matters and the focus on\n\nregulators and private litigants among other things on related claims made\n\nby companies and funds expose us to\n\nnumerous risks, including reputational, financial, legal and other risks,\n\nthat could have an adverse impact on us.\n\nCalifornia has adopted stringent new climate disclosure requirements, as\n\nhas the EU.\n\nWe are subject to Directive (EU) 2022/2464 on corporate sustainability reporting (“CSRD”) which became\n\neffective on January 5, 2023.\n\nCSRD requires in-scope companies to report sustainability-related information\n\nthat is\n\nmaterial from both a financial risk or opportunity and an environmental\n\nor social impact perspective, and the\n\nassessment of materiality is inherently subjective.\n\nFurthermore, Directive No. 2025/794 of 14 April 2025, the\n\n“Omnibus” Directive, amended Directive 2022/2464 by introducing a\n\ntwo-year postponement of the sustainability\n\nreporting requirements for financial years beginning on or after 1\n\nst\n\nJanuary 2025 and on or after 1\n\nst\n\nJanuary 2026.\n\nThis “Omnibus” legislative package amending the CSRD alters the scope,\n\nthresholds, timing and contents of\n\nreporting obligations, which may increase our costs.\n\nCSRD is being transposed into national law across EU\n\nMember States, and further legislative or implementation changes may\n\nalso increase our costs.\n\nWe also are subject to certain United States and foreign laws and regulations concerning the conduct of our foreign\n\noperations, including the U.S. Foreign Corrupt Practices Act, the U.K. Bribery\n\nAct, German anti-corruption laws\n\nand other anti-bribery laws and laws pertaining to the accuracy of our internal\n\nbooks and records.\n\nOur businesses\n\nare generally subject to numerous other laws and regulations that\n\ncould impact our financial results, including,\n\nwithout limitation, securities, antitrust, consumer protection and marketing\n\nlaws and regulations.\n\n[Table of Contents](#a296)\n\n[Index to Financial Statements](#a33909)\n\n38\n\nIn the EU, Directive No. 2019/1937 of October 23, 2019,\n\non the protection of persons who report breaches of\n\nUnion law,\n\norganizes the legal protection of whistleblowers.\n\nThis Directive covers whistleblowers reporting\n\nbreaches of EU laws and regulations and protects a wide range of people,\n\nincluding former employees.\n\nAll private\n\ncompanies with 50 or more employees are required to create effective internal reporting\n\nchannels.\n\nAll EU Member\n\nStates have now implemented the Directive.\n\nIn the EU, both active and passive corruption in the private sector are\n\ncriminalized.\n\nThe EU Council Framework\n\nDecision 2003/568/JHA of 22 July 2003\n\non combating corruption in the private sector\n\nestablishes more detailed\n\nrules on the liability of legal persons and deterrent sanctions.\n\nHowever, the liability of legal persons is regulated at\n\na national level.\n\nFailure to comply with fraud and abuse laws and regulations, and other\n\nlaws and regulations, could result in\n\nsignificant civil and criminal penalties and costs, including the loss of\n\nlicenses and the ability to participate in\n\nfederal and state health care programs, and could have a material adverse\n\neffect on our business.\n\nWe may\n\ndetermine to enter into settlements, make payments, agree to consent decrees\n\nor enter into other arrangements to\n\nresolve such matters.\n\nIntentional or unintentional failure to comply with settlement agreements\n\nor consent decrees\n\ncould materially adversely affect our business.\n\nWhile we believe that we are substantially compliant with applicable\n\nlaws and regulations, and believe we have\n\nadequate compliance programs and controls in place to ensure substantial\n\ncompliance, we cannot predict whether\n\nchanges in applicable law, or interpretation of laws, or changes in our services or marketing practices in response\n\nto\n\nchanges in applicable law or interpretation of laws, could have a material\n\nadverse effect on our business.\n\nIf we fail to comply with laws and regulations relating to the collection,\n\nstorage and processing of sensitive\n\npersonal information or standards in electronic health records or transmissions,\n\nwe could be required to make\n\nsignificant changes to our products, or incur substantial fines, penalties, or\n\nother liabilities.\n\nOur businesses that involve physician and dental practice management\n\nproducts, equipment and our specialty home\n\nmedical supplies businesses, and our self-funded employee benefits programs\n\ninclude information technology (IT)\n\nsystems that store and process personal health, clinical, financial, and\n\nother sensitive information of individuals.\n\nThese IT systems may be vulnerable to breakdown, wrongful intrusions, data\n\nbreaches and malicious attack, which\n\ncould require us to expend significant resources to eliminate these\n\nproblems and address related security concerns,\n\nand could involve claims against us by private parties and/or governmental agencies.\n\nWe are directly or indirectly subject to numerous and evolving federal, state, local and foreign laws and regulations\n\nthat protect the privacy and security of personal information (including\n\nhealth data), such as HIPAA, CAN-SPAM,\n\nTCPA, Section 5 of the FTC Act, the CCPA/CPRA\n\nand various other privacy laws that have or will soon come\n\ninto\n\neffect.\n\nLaws and regulations relating to privacy and data protection\n\nare continually evolving and subject to\n\npotentially differing interpretations, including those relating to AI.\n\nThese requirements may not be harmonized,\n\nmay be interpreted and applied in a manner that is inconsistent from one\n\njurisdiction to another or may conflict with\n\nother rules or our practices.\n\nIn addition to state-specific data breach notification laws (which exist in\n\nall U.S. states\n\nand territories), cybersecurity laws such as the federal Cyber Incident\n\nReporting for Critical Infrastructure Act of\n\n2022, proposed Federal Acquisition Regulations and amendments to SEC\n\nreporting requirements may require us to\n\nprovide notifications about cybersecurity incidents in limited timeframes and\n\nbefore investigations are complete.\n\nOur businesses’ failure to comply with these laws and regulations could expose\n\nus to breach of contract claims,\n\nsubstantial fines, penalties and other liabilities and expenses, costs\n\nfor remediation and harm to our reputation.\n\nEvolving laws and regulations in this area could restrict the ability\n\nof our customers to obtain, use or disseminate\n\npatient information, or could require us to incur significant additional\n\ncosts to re-design our products to reflect these\n\nlegal requirements, which could have a material adverse effect on our operations.\n\nIn addition, the European Parliament and the Council of the EU adopted\n\nthe GDPR that has been effective since\n\nMay 25, 2018, which increased privacy rights for Data Subjects in\n\nthe European Economic Area (EEA), including\n\nindividuals who are our customers, suppliers and employees.\n\nThe GDPR extended the scope of responsibilities for\n\ndata controllers and data processors, and generally imposes increased\n\nrequirements and potential penalties on\n\ncompanies, such as us, that are either established in the EU and process personal\n\ndata of Data Subjects (regardless\n\n[Table of Contents](#a296)\n\n[Index to Financial Statements](#a33909)\n\n39\n\nthe Data Subject location), or that are not established in the EU but\n\nthat offer goods or services to Data Subjects in\n\nthe EU or monitor their behavior in the EU. Noncompliance can result\n\nin penalties of up to the greater of EUR 20\n\nmillion, or 4% of global company revenues (sanction that may be public),\n\nand Data Subjects may seek damages.\n\nMember states may individually impose additional requirements and penalties\n\nregarding certain limited matters (for\n\nwhich the GDPR left some room of flexibility), such as employee personal data.\n\nWith respect to the personal data\n\nit protects, the GDPR requires, among other things, controller accountability, consents from Data Subjects or\n\nanother acceptable legal basis to process the personal data, notification\n\nwithin 72 hours of a personal data breach\n\nwhere required, data integrity and security, and fairness and transparency regarding the storage, use or other\n\nprocessing of the personal data.\n\nThe GDPR also provides rights to Data Subjects relating notably\n\nto information,\n\naccess, rectification, erasure of the personal data and the right to object to\n\nthe processing.\n\nDespite Brexit, the UK\n\nalso has data protection laws equivalent to the GDPR and has implemented\n\nfurther data protection related\n\nlegislation.\n\nSwitzerland enacted FADP.\n\nData protection authorities located in different EU Member States may\n\ninterpret GDPR differently, or requirements of national laws may vary between the EU Member States, UK and\n\nSwitzerland, or guidance on GDPR and related laws and compliance practices\n\nmay be often updated or otherwise\n\nrevised.\n\nAny of these events will increase the complexity and costs of\n\nprocessing personal data in the European\n\nEconomic Area, UK or Switzerland or concerning individuals located\n\nin these jurisdictions.\n\nEffective November 1, 2021, China’s PIPL imposes specific rules for processing personal information and specifies\n\nthat the law shall also apply to personal information activities carried\n\nout outside China but for the purpose of\n\nproviding products or services to PRC citizens.\n\nAny non-compliance with these laws and regulations may\n\nsubject\n\nus to fines, orders to rectify or terminate any actions that are deemed\n\nillegal by regulatory authorities, other\n\npenalties, reputational damage, or legal proceedings against us, which\n\nmay affect our business, financial condition\n\nor results of operations.\n\nThe PIPL carries maximum penalties of CNY50 million or\n\n5% of the annual revenue of\n\nentities that process personal data.\n\nData protection laws in other countries, such as Brazil, are\n\nalso quickly\n\nevolving, with many countries having updated, or are in the process\n\nof updating, their laws to bring them more in\n\nline with the model created by GDPR.\n\nIn the United States, the CCPA, effective January 1, 2020, establishes a privacy framework for covered businesses\n\nsuch as ours by, among other things, creating an expanded definition of personal information, establishing new data\n\nprivacy rights for California residents and creating a new and potentially\n\nsevere statutory damages framework for\n\nviolations of the CCPA, as well as potentially severe statutory damages and a private right of action against\n\nbusinesses that suffer a data security breach due to their violation of a duty to\n\nimplement reasonable security\n\nprocedures and practices.\n\nThis private right of action may increase the likelihood of, and risks associated\n\nwith, data\n\nbreach litigation.\n\nIn addition, California voters adopted the CPRA (effective January 1, 2023)\n\nwhich enhances and\n\nstrengthens regulatory requirements and individual protections that currently\n\nexist under the CCPA.\n\nEffective as of\n\nJanuary 1, 2026, the CCPA/CPRA regulatory framework includes expanded requirements.\n\nOther states have\n\nenacted or are considering enacting similar privacy laws, which may subject\n\nus to additional requirements and\n\nrestrictions that could have an impact on our business.\n\nAs of January 1, 2026, comprehensive privacy laws are now\n\nin effect in 20 states, further complicating our privacy compliance obligations through\n\nthe introduction of\n\nincreasingly disparate requirements across the various U.S. jurisdictions\n\nin which we operate.\n\nAdditionally, certain\n\nstates have enacted specific health data privacy laws and other states\n\nare considering similar legislation.\n\nCongress\n\nis considering legislation that may preempt some or all of such U.S. state\n\nprivacy laws, but which may also provide\n\na more expansive private right of action for privacy claims than exists under\n\ncurrent state laws.\n\nThe evolving complexity of privacy and data security legislation in\n\nthe U.S. and other jurisdictions globally may\n\ncomplicate our compliance efforts and further increase our risk of regulatory enforcement,\n\npenalties and litigation.\n\nWhile we believe we have substantially compliant programs and controls\n\nin place to comply with privacy laws\n\ndomestically and internationally, our compliance with data privacy and cybersecurity laws is likely to impose\n\nadditional costs on us, and we cannot predict whether the interpretations\n\nof the requirements, or changes in our\n\npractices in response to new requirements/interpretations, could have\n\na material adverse effect on our business.\n\nOur products and services utilize new technologies, such as AI.\n\nThe regulatory landscape for AI is changing\n\nrapidly, with both domestic and international activity.\n\nWhile there is currently no comprehensive federal legislation\n\nin the U.S. concerning the use, development or deployment of AI, regulators\n\npursue AI-related enforcement actions\n\nunder existing federal consumer protection laws and have issued related\n\nguidance.\n\nFurther, state privacy, consumer\n\n[Table of Contents](#a296)\n\n[Index to Financial Statements](#a33909)\n\n40\n\nprotection and AI-specific laws are proliferating and may be applicable to our\n\nbusiness.\n\nOther countries are also\n\napplying their data and consumer protection laws to AI, particularly\n\ngenerative AI, and are considering and\n\nimplementing specific legal frameworks with respect to AI.\n\nRegulation (EU) 2024/1689 on harmonized rules on\n\nartificial intelligence (the EU AI Act), for example, establishes a comprehensive\n\nregulatory framework for AI that\n\nbecame law in August 2024 with implementation phased through\n\ninto 2027.\n\nAs with the GDPR, it has extra-\n\nterritorial effect.\n\nAny failure or perceived failure by us to comply with such requirements\n\ncould have an adverse\n\nimpact on our business.\n\nAnticipated further evolution of regulations and legislation\n\non this topic may substantially\n\nincrease the penalties to which we could be subject in the event of any\n\nnon-compliance.\n\nCompliance with these\n\nlaws is challenging, constantly evolving and time consuming and federal\n\nregulators, state attorneys general and\n\nplaintiff’s attorneys have been and will likely continue to be active in this space.\n\nWe may incur substantial expense\n\nin complying with legal obligations to be imposed by new regulations\n\nand we may be required to make significant\n\nchanges to our solutions and expanding business operations, all of which\n\nmay adversely affect our operations.\n\nWe also sell products and services that health care providers, such as physicians and dentists, use to store and\n\nmanage patient medical or dental records.\n\nThese customers and we are subject to laws, regulations and\n\nindustry\n\nstandards, such as HIPAA and the Payment Card Industry (PCI) Data Security Standards, which require the\n\nprotection of the privacy and security of those records.\n\nOur products or services may be used as part of these\n\ncustomers’ comprehensive data security programs, including in connection\n\nwith their efforts to comply with\n\napplicable data privacy and security laws and contractual requirements.\n\nPerceived or actual security vulnerabilities\n\nin our products or services, or the perceived or actual failure by us\n\nor our customers who use our products or\n\nservices to comply with applicable legal or contractual data privacy and\n\nsecurity requirements, may not only cause\n\nus significant reputational harm, but may also lead to claims against us by our\n\ncustomers and/or governmental\n\nagencies and involve substantial fines, penalties and other liabilities and\n\nexpenses and costs for remediation.\n\nAdditionally, under the GDPR (and equivalent laws) and U.S. state privacy laws, health data belong to the category\n\nof “sensitive data” and benefit from specific protection.\n\nProcessing of such data is generally prohibited, except for\n\nspecific exceptions.\n\nCertain of our businesses involve the manufacture and sale of electronic\n\nhealth record (EHR) systems and other\n\nproducts linked to government supported incentive programs, where\n\nthe EHR systems must be certified as having\n\ncertain capabilities designated in evolving standards, such as those adopted\n\nby CMS and ONC.\n\nIn order to maintain\n\ncertification of our EHR products, we must satisfy the changing governmental\n\nstandards.\n\nIf any other EHR systems\n\ndo not meet these standards, yet have been relied upon by health care providers\n\nto receive federal incentive\n\npayments, we may be exposed to risk, such as under federal health care\n\nfraud and abuse laws, including the False\n\nClaims Act.\n\nAdditionally, effective September 1, 2023, the HHS-OIG issued a final rule implementing civil money\n\npenalties for information blocking as established by the Cures Act.\n\nOIG incorporated regulations published by\n\nONC as the basis for enforcing information blocking penalties.\n\nEach information blocking violation carries a $1\n\nmillion penalty.\n\nWhile we believe we are substantially in compliance with such certifications\n\nand with applicable\n\nfraud and abuse laws and regulations and that we have adequate compliance\n\nprograms and controls in place to\n\nensure substantial compliance, we cannot predict whether changes in\n\napplicable law, or interpretation of laws, or\n\nresulting changes in our compliance programs and controls, could have a\n\nmaterial adverse effect on our business.\n\nMoreover, in order to satisfy our customers and comply with evolving legal requirements, our products\n\nmay need to\n\nincorporate increasingly complex functionality, such as reporting and information blocking.\n\nAlthough we believe\n\nwe are positioned to accomplish this, the effort may involve increased costs, and\n\nour failure to implement product\n\nmodifications, or otherwise satisfy applicable standards, could have a\n\nmaterial adverse effect on our business.\n\nAdditionally, as electronic medical devices are increasingly connected to each other and to other technology, the\n\nability of these connected systems to safely and effectively exchange and use exchanged\n\ninformation becomes\n\nincreasingly important.\n\nAs a medical device manufacturer, we must manage risks including those associated with\n\nan electronic interface that is incorporated into a medical device.\n\nTax legislation could materially adversely affect our financial results and tax liabilities.\n\nWe are subject to the tax laws and regulations of the United States federal, state and local governments, as well as\n\nforeign jurisdictions.\n\nFrom time to time, various legislative initiatives may be proposed\n\nthat could materially\n\n[Table of Contents](#a296)\n\n[Index to Financial Statements](#a33909)\n\n41\n\nadversely affect our tax positions.\n\nThere can be no assurance that our effective tax rate will not be\n\nmaterially\n\nadversely affected by legislation resulting from these initiatives.\n\nIn addition, tax laws and regulations are extremely\n\ncomplex and subject to varying interpretations.\n\nAlthough we believe that our historical tax positions are sound and\n\nconsistent with applicable laws, regulations and existing precedent,\n\nthere can be no assurance that our tax positions\n\nwill not be challenged by relevant tax authorities or that we would be\n\nsuccessful in any such challenge.\n\nWe face inherent risk of exposure to product liability, intellectual property infringement and other claims in the\n\nevent that the use of the products we sell results in injury.\n\nOur business involves a risk of product liability, intellectual property infringement and other claims in the ordinary\n\ncourse of business, and from time to time we are named as a defendant\n\nin cases as a result of our distribution of\n\nproducts.\n\nAdditionally, we own and own interests in companies that manufacture certain dental and medical\n\nproducts.\n\nAs a result, we could be subject to the potential risk of product liability, intellectual property\n\ninfringement or other claims relating to the manufacture and distribution\n\nof products by those entities.\n\nIn addition,\n\nas our corporate brand business continues to grow, purchasers of such products may increasingly seek recourse\n\ndirectly from us, rather than the ultimate product manufacturer, for product-related claims.\n\nAnother potential risk\n\nwe face in the distribution of our products is liability resulting from counterfeit\n\nor tainted products infiltrating the\n\nsupply chain.\n\nIn addition, some of the products that we transport and sell are\n\nconsidered hazardous materials.\n\nThe\n\nimproper handling of such materials or accidents involving the transportation\n\nof such materials could subject us to\n\nliability or at least legal action that could harm our reputation.\n\nCustoms policies or legislative import restrictions could hinder the Company’s ability to import goods necessary\n\nto our operations on a timely basis and result in government enforcement\n\nactions and/or sanctions.\n\nGovernment-imposed import policies and legislation regulating the\n\nimport of goods and prohibiting the use of\n\nforced labor or human trafficking could result in delays or the inability to import\n\ngoods in a timely manner that are\n\nnecessary to our operations, and such policies or legislation could also\n\nresult in financial penalties, other sanctions,\n\ngovernment enforcement actions and reputational harm.\n\nCertain of our suppliers have had their ability to service\n\ncertain markets restricted or negatively impacted because of allegations\n\nof forced labor in their supply chain.\n\nWhile\n\nthe Company has policies against and seeks to avoid the import of goods\n\nthat are manufactured in whole or in part\n\nby forced labor or through human trafficking, as a result of legislative and governmental\n\npolicy initiatives, we may\n\nbe subject to increasing potential delays, added costs, supply chain disruption\n\nand other restrictions.\n\nGENERAL RISKS\n\nOur business operations, results of operations, cash flows, financial condition\n\nand liquidity may be negatively\n\nimpacted by the effects of disease outbreaks, epidemics, pandemics, or similar wide-spread public\n\nhealth\n\nconcerns and other natural or man-made disasters, such as terrorism, civil\n\nunrest, fire and extreme weather\n\n.\n\nOur business operations, results of operations, cash flows, financial condition\n\nand liquidity may be negatively\n\nimpacted by the effects of disease outbreaks, epidemics, pandemics, similar wide-spread\n\npublic health concerns and\n\nother natural or man-made disasters, such as terrorism, civil unrest, fire\n\nand extreme weather (“disasters”).\n\nFor\n\nexample, as a global health care solutions company, the COVID-19 pandemic and the governmental responses\n\nto it\n\nhad a material adverse effect on our business, financial condition, operating results\n\nand cash flows.\n\nThe impacts\n\nand potential impacts from the COVID-19 pandemic included, and could include\n\nas a result of other disasters,\n\nadverse impacts such as significant volatility in supply, demand and selling prices, interrupted operations of\n\nindustries that use or manufacture the products we distribute for personal\n\nprotective equipment (PPE), test kits and\n\nrelated products, reduction in peoples’ ability and willingness to be in\n\npublic, impact of adapted business practices,\n\nvolatility in the financial markets, and unavailability or impairment\n\nof our manufacturing, distribution, or other\n\nfacilities, or firmwide systems such as our IS.\n\nOur global operations are subject to inherent risks that could materially\n\nadversely affect our business.\n\nOur global operations are subject to risks that could materially adversely affect our business,\n\nincluding, among\n\nother things:\n\n[Table of Contents](#a296)\n\n[Index to Financial Statements](#a33909)\n\n42\n\n•\n\ndifficulties and costs relating to staffing and managing foreign operations;\n\n•\n\ndifficulties and delays inherent in sourcing products, establishing channels of distribution\n\nand contract\n\nmanufacturing in foreign markets;\n\n•\n\nfluctuations in the value of foreign currencies;\n\n•\n\nuncertainties relating to trade agreements and international trade relationships;\n\n•\n\nlonger payment cycles and difficulty of collecting receivables in foreign jurisdictions;\n\n•\n\nrepatriation of cash from our foreign operations to the United States;\n\n•\n\nregulatory requirements, including, without limitation, anti-bribery, anti-corruption and laws pertaining\n\nto the accuracy of our internal books and records;\n\n•\n\nlitigation risks;\n\n•\n\nunexpected difficulties in importing or exporting our products and import/export\n\ntariffs, quotas,\n\nsanctions or penalties;\n\n•\n\nlimitations on our ability under local laws to protect our intellectual\n\nproperty;\n\n•\n\nunexpected regulatory, legal, economic and political changes in foreign markets;\n\n•\n\nchanges in tax regulations that influence purchases of capital equipment;\n\n•\n\ncivil disturbances, geopolitical turmoil, including terrorism, war or political\n\nor military coups; and\n\n•\n\nrisks associated with climate change, including physical risks such as\n\nimpacts from extreme weather\n\nevents and other potential physical consequences, regulatory and technological\n\nrequirements, market\n\ndevelopments, stakeholder expectations and reputational risk.\n\nOur future success is substantially dependent upon our senior\n\nmanagement, and our revenues and profitability\n\ndepend on our relationships with capable personnel, as well as\n\ncustomers, suppliers and manufacturers of the\n\nproducts that we distribute.\n\nOn July 15, 2025, the Company announced that Mr. Bergman will retire as the Company’s CEO on December 31,\n\n2025 (which date was extended to March 1, 2026), and that Mr. Bergman will continue to serve as Chairman of the\n\nBoard of Directors of the Company following his retirement.\n\nOn January 12, 2026, the Company announced the\n\nappointment of Frederick M. Lowery as its next CEO, effective March 2, 2026, at\n\nwhich time he will join the\n\nCompany’s Board of Directors.\n\nOur future success is substantially dependent upon the efforts and abilities of\n\nmembers of our senior management.\n\nCompetition for senior management is intense, burnout and turn-over rates\n\nare increasing workplace concerns,\n\ntransitions among senior level officers can present challenges as well as opportunities,\n\nand we may not be\n\nsuccessful in attracting and retaining key personnel, or transitioning to\n\nnew personnel following departures.\n\nAdditionally, our future revenues and profitability depend on our ability to maintain satisfactory relationships with\n\nqualified personnel, as well as customers, suppliers and manufacturers.\n\nIf we fail to maintain our existing\n\nrelationships with such persons or fail to acquire relationships with such key\n\npersons in the future, our business may\n\nbe materially adversely affected.\n\nDisruptions in the financial markets may materially adversely\n\naffect the availability and cost of credit to us.\n\nOur ability to make scheduled payments or refinance our obligations with\n\nrespect to indebtedness will depend on\n\nour operating and financial performance, which in turn is subject to prevailing\n\neconomic conditions and financial,\n\nbusiness and other factors beyond our control.\n\nDisruptions in the financial markets may materially adversely affect\n\nthe availability and cost of credit to us."}