FULLTEXT DEL 2 AV 2
10-Q – 2026-07-29 – cort-20260630.htm
We are subject to regulations and other legal obligations relating to drug development and commercialization, the conduct of business as an issuer of publicly traded securities and individual privacy and data protection. Compliance with these obligations is complex and costly. Failure to comply could materially harm our business. New laws and regulations, as well as changes to existing laws and regulations, including statutes and regulations concerning taxes and the development, approval, marketing and pricing of medications, the provisions of the ACA requiring the reporting of aggregate spending related to health care professionals, the provisions of the Sarbanes-Oxley Act of 2002, the Dodd-Frank Act of 2010 and rules adopted by the SEC and by The Nasdaq Stock Market LLC have increased and will likely continue to increase our cost of doing business and divert management’s attention from revenue-generating activities. We and our partners are subject to federal, state and foreign laws and regulations concerning data privacy and security, including HIPAA and the EU General Data Protection Regulation (“GDPR”). These and other regulatory frameworks are evolving rapidly as new rules are enacted and existing ones updated and made more stringent. In the United States, numerous federal and state laws and regulations, including state data breach notification laws, state health information privacy laws, and federal and state consumer protection laws and regulations (e.g., Section 5 of the Federal Trade Commission Act), that govern the collection, use, disclosure, and protection of health-related and other personal information could apply to our operations or the operations of our partners. In addition, we may obtain health information from third parties (including research institutions from which we obtain clinical trial data) that are subject to privacy and security requirements under HIPAA. Depending on the facts and circumstances, we could be subject to criminal penalties if we knowingly obtain, use, or disclose individually identifiable health information maintained by a HIPAA-covered entity in a manner that is not authorized or permitted by HIPAA. Requirements for compliance under HIPAA are also subject to change, as the U.S. Department of Health and Human Services Office for Civil Rights issued a proposed rule that would amend certain security compliance requirements for covered entities and business associates. Even when HIPAA does not apply, according to the Federal Trade Commission (the “FTC”), violating consumers’ privacy or failing to take appropriate steps to keep consumers’ personal information secure may constitute unfair acts or practices in or affecting commerce in violation of Section 5(a) of the Federal Trade Commission Act. The FTC expects a company’s data security measures to be reasonable and appropriate in light of the sensitivity and volume of consumer information it holds, the size and complexity of its business, and the cost of available tools to improve security and reduce vulnerabilities. Individually identifiable health information is considered sensitive data that merits stronger safeguards. In 2024, the FTC also finalized its rulemaking on additional data privacy rules and requirements, which may add additional complexity to compliance obligations going forward. The DOJ issued a rule in 2025 entitled “Access to U.S. Sensitive Personal Data and Government-Related Data by Countries of Concern or Covered Persons,” and known less formally as the “Bulk Transfer Rule.” The Bulk Transfer Rule is codified at 28 CFR part 202 and prohibits and restricts bulk transfers of sensitive personal data (including genetic and health data) to countries of concern, such as China, Russia, and Iran to prevent access by foreign adversaries. It restricts our ability to engage in certain cross-border transactions involving genomic or biological samples and related data, which may increase compliance costs, lead to increased regulatory scrutiny or liability, and may require additional contractual negotiations, which may adversely impact our business, financial condition, and operating results. In addition, certain state laws govern the privacy and security of health-related and other personal information in certain circumstances, some of which may be more stringent, broader in scope or offer greater individual rights with respect to protected health information than HIPAA and many of which may differ from each other in significant ways and may not have the same effect, thus complicating compliance efforts. Failure to comply with these laws, where applicable, can result in the imposition of significant civil and/or criminal penalties and private litigation. For example, the California Confidentiality of Medical Information Act imposes restrictive requirements regulating the use and disclosure of health information and other personally identifiable information. Further, the California Consumer Privacy Act (the “CCPA”), revised and amended by the California Privacy Rights Act (the “CPRA” and collectively, the “CCPA”), created individual privacy rights for California consumers and increased the privacy and security obligations of entities handling certain personal information as well as limitations on data uses, audit requirements for higher risk data, and opt outs for certain uses of sensitive data. The CCPA provides for civil penalties for violations, as well as a private right of action for data breaches that is expected to increase data breach litigation. The CCPA is enforced by the California Privacy Protection Agency, which is authorized to issue substantive regulations resulting in increased privacy and information security enforcement. The CCPA may increase our compliance costs and potential liability. Several other states have implemented similar comprehensive privacy laws that took effect in the past year or will take effect in the near future, and states have implemented or are considering laws that specifically focus on the processing of personal data related to individuals’ health, including Washington’s My Health My Data Act and California’s Confidentiality of Medical Information Act. As a result, additional compliance investment and potential business process changes may be required. In the event that we are subject to or affected by HIPAA, the CCPA or other domestic privacy and 43 data protection laws, any liability from failure to comply with the requirements of these laws could adversely affect our financial condition. Additional legislation proposed at the federal level and in other states, along with increased regulatory action, reflects a trend toward more stringent privacy legislation in the United States. Outside the United States, many jurisdictions have or are in the process of enacting extensive data privacy regulations. In Europe, the GDPR took effect in 2018, and is imposing stringent data protection requirements for controllers and processors of personal data of individuals within the EEA, particularly with respect to clinical trials. The GDPR provides that EEA member states may make further laws and regulations limiting the processing of health data, which could limit our ability to use and share personal data or could cause our costs to increase and harm our business and financial condition. In addition, the GDPR increases the scrutiny that clinical trial sites located in the EEA should apply to transfers of personal data from such sites to countries that are considered to lack an adequate level of data protection, such as the United States. Legal developments have added complexity and compliance uncertainty regarding certain transfers of information from the EEA to the United States. Following EU court decisions, updated standard contractual clauses (“SCCs”) were adopted to account for these judicial decisions, imposing new requirements on data transfers. The revised SCCs must be used for relevant new data transfers from September 27, 2021, and existing SCC arrangements were required to be retired by December 27, 2022. As supervisory authorities issue further guidance on personal data export mechanisms, and/or start taking enforcement action, we could suffer additional costs, complaints and/or regulatory investigations or fines, and/or if we are otherwise unable to transfer personal data between and among countries and regions in which we operate, it could affect the manner in which we provide our services, the geographical location or segregation of our relevant systems and operations, and could adversely affect our financial results. Further, on July 10, 2023, the European Commission adopted its adequacy decision on the E.U.-U.S. Data Privacy Framework (“DPF”). The decision, which took effect on the day of its adoption, concludes that the United States ensures an adequate level of protection for personal data transferred from the EEA to companies certified to the DPF. It is currently unclear how the future of the DPF will evolve and what impact it will have on our international activities. The GDPR imposes substantial fines for breaches of data protection requirements, which can be up to four percent of global revenue for the preceding financial year or €20 million, whichever is greater, and it also confers a private right of action on data subjects for breaches of data protection requirements. Compliance with European data protection laws is a rigorous and time-intensive process that may increase our cost of doing business, and despite those efforts, there is a risk that we may be subject to fines and penalties, litigation and reputational harm in connection with our European activities. From January 1, 2021, we have had to comply with the GDPR and separately the UK GDPR, which, together with the amended UK Data Protection Act 2018, retains the GDPR in UK national law, each regime having the ability to fine up to the greater of €20 million/£17.5 million or 4 percent of global turnover. It is unclear how UK data protection laws and regulations will develop in the medium to long term and these changes may lead to additional costs and increase our overall risk exposure. In addition, on June 19, 2025, the UK’s Data (Use and Access) Act 2025 (the “DUAA”) was granted Royal Assent, implementing various measures concerning data usage in the UK and reforming data protection laws. The provisions within the DUAA will come into force through 2026, and it is currently unclear how the DUAA will be implemented and what impact it will have on our international activities. Preparing for and complying with U.S. and foreign privacy and security laws and regulations is complex and costly as it is rigorous and time-intensive and requires significant resources and a review of our technologies, systems and practices, as well as those of any third-party collaborators, service providers, CROs, contractors or consultants that process or transfer personal data collected in the EU. The GDPR and other changes in laws or regulations associated with the enhanced protection of certain types of sensitive data, such as healthcare data or other personal data from our clinical trials, and access to certain data such as the European Health Data Space Regulation, could require us to change our business practices and put in place additional compliance mechanisms, may interrupt or delay our development, regulatory and commercialization activities and increase our cost of doing business, and could lead to government enforcement actions, private litigation and significant fines and penalties against us and could have a material adverse effect on our business, financial condition or results of operations. Similarly, failure to comply with federal and state laws regarding privacy and security of personal data could expose us to fines and penalties under such laws. Even if we are not determined to have violated these laws, government investigations into these issues typically require the expenditure of significant resources and generate negative publicity, which could harm our reputation and our business. We rely on information technology to conduct our business. A breakdown or breach of our information technology systems or our failure to protect confidential information concerning our business, patients or employees could interrupt the operation of our business and subject us to liability. We store valuable confidential information relating to our business, patients and employees on our computer networks and on the networks of our vendors. In addition, we rely heavily on internet technology, including video conferencing, teleconferencing and file-sharing services, to conduct business. Despite our security measures, our networks and the networks of our vendors are at risk of break-ins, installation of malware or ransomware, denial-of-service attacks, data theft and other forms of malfeasance by persons seeking to commit fraud or theft, which could result in unauthorized access to, and/or misuse of, our clinical data or other confidential information, including confidential information relating to our patients or employees. 44 We may continue to increase our cybersecurity risks, due to our reliance on internet technology and the number of our employees that are working remotely, which may create additional opportunities for cybercriminals to exploit vulnerabilities. We and our vendors have experienced data breaches, theft, “phishing” attacks and other unauthorized access to confidential data and information. There can be no assurance that our cybersecurity systems and processes will prevent unauthorized access in the future that causes serious harm to us, our patients or employees. We may also experience security breaches that remain undetected for an extended period. Disruptions or security breaches that result in the disclosure of confidential or proprietary information could cause us to incur liability and delay or otherwise harm our research, development and commercialization efforts. We may be liable for losses suffered by patients or employees or other individuals whose confidential information is stolen as a result of a breach of the security of the systems that we or third parties and our vendors store this information on, and any such liability could be material. Even if we are not liable for such losses, any breach of these systems could expose us to material costs in notifying affected individuals, as well as regulatory fines or penalties. In addition, any breach of these systems could disrupt our normal business operations and expose us to reputational damage and harm our business, operating results and financial condition. Any insurance we maintain against the risk of this type of loss may not be sufficient to cover actual losses or may not apply to the circumstances relating to any particular loss. Changes in federal, state and local tax laws may reduce our net earnings. Our earnings are subject to federal, state and local taxes. We offset a portion of our earnings using net operating losses and our taxes using research and development tax credits, which reduces the amount of tax we pay. Some jurisdictions require that we pay taxes or fees calculated as a percentage of sales, payroll expense, or other indicia of our activities. Please see “ Part I, Item 1, Notes to Condensed Consolidated Financial Statements – Income Taxes .” Changes to existing tax laws could materially increase the amounts we pay, which would reduce our after-tax net income. Research analysts may not continue to provide or initiate coverage of our common stock or may issue negative reports. The market for our common stock may be affected by the reports financial analysts publish about us. If any of the analysts covering us downgrades or discontinues coverage of our stock, the price of our common stock could decline rapidly and significantly. Paucity of research coverage may also adversely affect our stock price. Any acquisition of Corcept shares through our Stock Repurchase Program or, in certain cases, pursuant to the exercise of stock options, will reduce our cash reserves. In January 2024, our Board of Directors authorized the repurchase of up to $200 million of our common stock pursuant to the Stock Repurchase Program. In addition, we sometimes accept, in our sole discretion, shares equal in value to any tax and exercise price liability due from option holders at the time of exercise and remit the applicable tax amounts to the tax authorities. Neither our Stock Repurchase Program nor the acceptance of shares at the time of options exercise requires us to acquire shares. Furthermore, the Stock Repurchase Program may be modified, suspended or discontinued at any time without notice. It is possible that other uses of our capital would have been more advantageous or that our future capital requirements would increase unexpectedly. By reducing our cash balance, our repurchases of common stock could hamper our ability to execute our plans, meet financial obligations or access financing. Anti-takeover provisions in our charter and bylaws and under Delaware law may make an acquisition of us or a change in our management more expensive or difficult, even if an acquisition or a management change would be beneficial to our stockholders. Provisions in our charter and bylaws may delay or prevent an acquisition of us or a change in our management. Some of these provisions allow us to issue preferred stock without any vote or further action by the stockholders, require advance notification of stockholder proposals and nominations of candidates for election as directors and prohibit stockholders from acting by written consent. In addition, a supermajority vote of stockholders is required to amend our bylaws. Our bylaws provide that special meetings of the stockholders may be called only by our Chairman, President or the Board of Directors and that the authorized number of directors may be changed only by resolution of the Board of Directors. These provisions may prevent or delay a change in our Board of Directors or our management, which our Board of Directors appoints. In addition, because we are incorporated in Delaware, we are governed by the provisions of Section 203 of the Delaware General Corporation Law. Section 203 may prohibit large stockholders, in particular those owning 15 percent or more of our outstanding voting stock, from merging or combining with us. These provisions in our charter and bylaws and under Delaware law could reduce the price that investors would be willing to pay for shares of our common stock. 45 Our officers, directors and principal stockholders, acting as a group, could significantly influence corporate actions. As of July 22, 2026, our officers and directors beneficially owned approximately 20 percent of our common stock. Acting together, these stockholders could significantly influence any matter requiring approval by our stockholders, including the election of directors and the approval of mergers or other business combinations. The interests of this group may not always coincide with our interests or the interests of other stockholders and may prevent or delay a change in control. This significant concentration of share ownership may adversely affect the trading price of our common stock because many investors perceive disadvantages to owning stock in companies with controlling stockholders. ITEM 2. UNREGISTERED SALES OF EQUITY SECURITIES AND USE OF PROCEEDS There were no unregistered sales of equity securities during the period covered by this report. Issuer Purchases of Equity Securities In January 2024, our Board of Directors approved a program authorizing the repurchase of up to $200 million of our common stock. Purchases under this program may be made in the open market, in privately negotiated transactions or otherwise. The timing and amount of any repurchases will be determined based on market conditions, our stock price and other factors. The program does not require us to repurchase any specific number of shares and may be modified, suspended or discontinued at any time without notice. As of June 30, 2026, $11.4 million of the current authorization remained available for the repurchase of shares of our common stock. The following table contains information relating to the purchase of shares of our common stock in the three months ended June 30, 2026 as part of the cashless net exercises of stock options and vesting of restricted stock (in thousands, except average price per share): Fiscal Period Total Number of Shares Purchased (1) Average Price Per Share Total Purchase Price of Shares (2) April 1, 2026 to April 30, 2026 11 $ 41.02 $ 458 May 1, 2026 to May 31, 2026 121 55.79 6,718 June 1, 2026 to June 30, 2026 189 74.85 14,150 Total 321 $ 66.51 $ 21,326 (1) In April 2026, we issued 62 shares of common stock as part of a net-share settlement of a cashless option exercise, of which 54 shares were surrendered to us in satisfaction of related exercise cost and tax obligations. In May 2026, we issued 119,501 shares of common stock as part of a net-share settlement of a cashless option exercise, of which 71,513 shares were surrendered to us. In June 2026, we issued 345,303 shares of common stock as part of a net-share settlement of a cashless option exercise, of which 162,832 shares were surrendered to us. In April 2026, we issued 28,711 shares of common stock as part of restricted stock vesting, of which 11,098 shares were surrendered to us in satisfaction of related tax obligations. In May 2026, we issued 132,878 shares of common stock as part of restricted stock vesting, of which 48,906 shares were surrendered to us. In June 2026, we issued 72,122 shares of common stock as part of restricted stock vesting, of which 26,218 shares were surrendered to us. (2) We paid $11.5 million to satisfy the tax withholding obligations associated with the net-share settlement of these cashless option exercises and vesting of restricted stock. ITEM 3. DEFAULTS UPON SENIOR SECURITIES Not applicable. ITEM 4. MINE SAFETY DISCLOSURES Not applicable. 46 ITEM 5. OTHER INFORMATION Insider Trading Arrangements During the three months ended June 30, 2026, none of our directors and officers (as defined in Rule 16a-1(f) under the Exchange Act) adopted or terminated any contract, instruction or written plan for the purchase or sale of our securities that is intended to satisfy the affirmative defense conditions of Rule 10b5-1(c) of the Securities Exchange Act of 1934, as amended, or any “non-Rule 10b5-1 trading arrangement,” as defined in Item 408(a) of Regulation S-K, other than as set forth in the table below. Name Position Action Adoption Date Total Shares of Common Stock to be Sold Expiration Date (1) David L. Mahoney Director Adoption 5/19/2026 Up to 103,606 11/11/2027 Joseph D. Lyon Chief Accounting & Technology Officer Adoption 6/10/2026 Up to 120,000 8/31/2027 Joseph K. Belanoff, M.D. Chief Executive Officer and Director Adoption 6/11/2026 Up to 400,000 8/31/2027 (1) Each trading arrangement permits transactions through and including the earlier to occur of (a) the completion of all sales or (b) the date listed in the table. 47 ITEM 6. EXHIBITS Exhibit Number Description of Document 3.1 Restated Certificate of Incorporation (incorporated by reference to Exhibit 3.1 to the registrant’s Current Report on Form 8-K filed on May 24, 2023). 3.2 Amended and Restated Bylaws (incorporated by reference to Exhibit 3.1 to the registrant’s Current Report on Form 8-K filed on December 11, 2023). 10.1# Corcept Therapeutics Incorporated 2024 Incentive Award Plan (as Amended) (incorporated by reference to Appendix A to the registrant's Definitive Proxy Statement on Schedule 14A filed on April 17, 2026). 31.1 Rule 13a-14(a)/15d-14(a) Certifications of Joseph K. Belanoff, M.D., Chief Executive Officer of the registrant. 31.2 Rule 13a-14(a)/15d-14(a) Certifications of Atabak Mokari, Chief Financial Officer of the registrant. 32.1 18 U.S.C. Section 1350 Certifications of Joseph K. Belanoff, M.D., Chief Executive Officer of the registrant. 32.2 18 U.S.C. Section 1350 Certifications of Atabak Mokari, Chief Financial Officer of the registrant. 101 The following materials from the registrant’s Quarterly Report on Form 10-Q for the quarter ended June 30, 2026, formatted in Extensible Business Reporting Language (XBRL): (i) Unaudited Condensed Consolidated Balance Sheets at June 30, 2026 and December 31, 2025, (ii) Unaudited Condensed Consolidated Statements of Income for the three and six month periods ended June 30, 2026 and 2025, (iii) Unaudited Condensed Consolidated Statements of Comprehensive Income for the three and six month periods ended June 30, 2026 and 2025, (iv) Unaudited Condensed Consolidated Statements of Cash Flows for the six month periods ended June 30, 2026 and 2025, (v) Unaudited Condensed Consolidated Statements of Stockholders’ Equity and (vi) Notes to Unaudited Condensed Consolidated Financial Statements. 104 Cover Page Interactive Data File - the cover page XBRL tags are embedded within the Inline XBRL document. # Indicates a management contract or compensatory plan or arrangement. 48 SIGNATURES Pursuant to the requirements of the Securities Exchange Act of 1934, the registrant has duly caused this report to be signed on its behalf by the undersigned thereunto duly authorized. CORCEPT THERAPEUTICS INCORPORATED Date: July 29, 2026 /s/ Joseph K. Belanoff Joseph K. Belanoff, M.D. Chief Executive Officer Date: July 29, 2026 /s/Atabak Mokari Atabak Mokari Chief Financial Officer Date: July 29, 2026 /s/Joseph D. Lyon Joseph D. Lyon Chief Accounting & Technology Officer 49