Healthcare
Doximity, Inc. (DOCS)
Data as of July 16, 2026
Environment story
Doximity discloses no formal environmental strategy, climate targets, or emissions data in its 10-K filing. The company operates as a SaaS healthcare platform with minimal direct physical infrastructure (relying heavily on AWS and Google Cloud). No Scope 1, 2, or 3 emissions are reported. No net-zero commitment, renewable energy targets, or decarbonization initiatives are documented. The absence of ESG disclosures and climate commitments results in significant penalty deductions. Without verified emissions baselines or mitigation strategies, environmental score reflects minimal positive attribution.
Criticisms on file
No material criticisms on file for this pillar.
Disclosed initiatives
-
Cloud Infrastructure RelianceCompany relies on Amazon Web Services and Google Cloud for computing and storage, outsourcing physical infrastructure carbon footprint to third-party providers.Indirect emissions management; no direct control or transparency over provider sustainability practices.
Social story
Doximity reports headcount growth from 830 to 880 FTE (March 2025–2026), indicating modest workforce expansion. No CEO-to-median-worker pay ratio, diversity metrics, turnover rates, or union relations data are disclosed in the 10-K. The company emphasizes 'physicians first' philosophy and investments in talent acquisition and retention (stock-based compensation increased 68% YoY for equity awards). However, absence of formal diversity targets, pay-equity audits, supply-chain labor standards, and union-neutrality agreements prevents verification of social governance depth. The company acknowledges competition for talent and relies on remote work arrangements.
Criticisms on file
-
Workforce Cybersecurity Risk from Remote WorkSource: DOCS_10k.txt, Risk Factors: 'A substantial portion of our workforce is currently working remotely on a part- or full-time basis. This could increase our cyber security risk, create data accessibility concerns, and make us more susceptible to communication disruptions.'
Disclosed initiatives
-
Physicians-First PhilosophyCompany states it prioritizes member (physician) interests over revenue expansion when conflicts arise; foregoes certain revenue opportunities perceived as misaligned with member welfare.Intended to build trust and engagement; no quantified outcome metrics disclosed.
-
Talent Acquisition & Retention ProgramsCompetitive equity compensation packages, stock-based incentive programs for executives and employees. Stock-based compensation expense increased from $72.4M (FY2025) to $121.6M (FY2026), reflecting expanded awards for new hires and existing staff.Attracts talent; no disclosure of effectiveness, retention rates, or diversity outcomes.
-
Remote Work InfrastructureMajority of workforce operates remotely part- or full-time.Flexible work arrangements; cited as creating cybersecurity risks and data accessibility concerns.
Governance story
Doximity operates under a dual-class share structure concentrating voting control with executive officers and directors. The 10-K explicitly warns: 'The dual class structure of our common stock has the effect of concentrating voting control with our executive officers (including our Chief Executive Officer) and directors and their affiliates; this will limit or preclude your ability to influence corporate matters.' No disclosure of board independence percentage, board size, or committee composition. No lobbying expenditures, PAC contributions, or political stance data are provided. No active antitrust, consumer-safety, or financial-fraud proceedings are noted. The company discloses significant legal/regulatory exposure (HIPAA, FTC, TCPA, state privacy laws, AI regulation) but no ongoing enforcement actions. Recent CFO departure (April 2026) and interim appointments noted without material operational impact.
Criticisms on file
-
Dual-Class Share StructureSource: DOCS_10k.txt, Risk Factors Summary: 'The dual class structure of our common stock has the effect of concentrating voting control with our executive officers (including our Chief Executive Officer) and directors and their affiliates; this will limit or preclude your ability to influence corporate matters.'
-
Regulatory Exposure: HIPAA, Privacy & Data ProtectionSource: DOCS_10k.txt, Risk Factors: 'As a Business Associate under HIPAA, we face significant penalties for compliance failures, including civil monetary penalties, criminal penalties, and imprisonment. The OCR and DOJ may enforce HIPAA requirements, and state attorneys general can prosecute violations affecting their residents.'
-
Regulatory Exposure: TCPA LiabilitySource: DOCS_10k.txt, Risk Factors: 'For violations of the TCPA, the law provides for a private right of action under which a plaintiff may recover statutory damages of $500 for each call, text message, or facsimile made in violation of the statute's prohibitions. A court also may treble the amount of damages upon a finding of a willful or knowing violation of the statute. There is no statutory cap on maximum aggregate exposure.'
-
Regulatory Exposure: AI Governance & Evolving Legal FrameworkSource: DOCS_10k.txt, Risk Factors: 'Several jurisdictions globally have proposed or enacted laws governing AI development and use, which may increase compliance costs, trigger regulatory actions, or require business practice changes. AI models may contain inaccuracies or biases that could adversely impact individuals' rights or access to services.'
-
Regulatory Exposure: Section 230 CDA Amendments RiskSource: DOCS_10k.txt, Risk Factors: 'In the United States, government authorities, elected officials, and political candidates have called for amendments to Section 230 of the CDA that would purport to limit or remove protections afforded to interactive computer service providers and our current protections from liability for third-party content in the United States could decrease or change.'
Disclosed initiatives
-
Privacy & Data Protection Compliance FrameworkCompany implements systems and procedures to comply with HIPAA, CCPA/CPRA, FTC consent decrees, state medical privacy laws, and evolving AI/consumer-protection regulations. Invests in security measures, vendor oversight, and internal controls.Compliance costs increasing; no quantified investment or breach history disclosed.
-
Cybersecurity & Data Protection MeasuresRecovery systems, security protocols, network protection mechanisms, and physical facility safeguards designed to prevent and detect security breaches. Third-party vendor management and subprocessor audits.Mitigation of data breach risk; no independent third-party audit or certification disclosed.
-
AI Governance & Risk ManagementCompany developing policies, procedures, safeguards, and oversight mechanisms for responsible AI deployment in products and internal operations. Acknowledges risks of model inaccuracy, bias, intellectual property infringement, and regulatory non-compliance.Intended to reduce AI-related harms; governance framework details not disclosed.
These are Missionomics' own editorial scores — directional signals built from disclosed facts under a published method, not certifications or definitive ratings of Doximity, Inc.. Coverage and confidence vary by data point, and figures can lag real-world changes. Read the full Methodology for sourcing, scoring, and correction details — or open Doximity, Inc. in the app for interactive charts and portfolio building.
Browse Companies · Methodology · Terms of Service · Privacy Policy · Back to Missionomics