Healthcare
UFP Technologies, Inc. (UFPT)
Data as of July 17, 2026
Environment story
UFP Technologies demonstrates significant environmental governance gaps. The company has not disclosed Scope 1, Scope 2, or Scope 3 emissions, nor has it established a quantified net-zero target year. While the 10-K acknowledges ESG regulatory evolution and climate change as material risk factors, operational disclosures remain absent. The company notes exposure to tariffs and energy cost pressures but does not articulate decarbonization infrastructure investments or renewable energy commitments. Manufacturing facilities in the Dominican Republic and Puerto Rico present climate-change physical-risk exposure (hurricane/flooding) but mitigation strategies are not detailed. Greenwashing detection: company publicizes ESG awareness in Risk Factors but provides zero verifiable emissions data or reduction targets, suggesting compliance posture rather than substantive climate action.
Criticisms on file
-
No disclosed emissions inventory (Scope 1, 2, 3); absence of net-zero target; no verifiable decarbonization capex or renewable energy percentage disclosed.Source: UFPT 10-K 2025, Item 1A Risk Factors; MD&A sections lack environmental KPIs
-
Cyber Incident (February 2026) involving IT systems disruption; potential supply-chain and operational impact not yet quantified.Source: UFPT 10-K 2025, Item 1A Risk Factors section 'Security breaches'; MD&A Impact of Cyber Incident
Disclosed initiatives
-
ESG regulatory awarenessCompany acknowledges increased focus on climate change and ESG in Risk Factors (Item 1A), noting potential for expanded regulatory requirements and customer demand for lower-carbon products.
-
Climate-change physical-risk management10-K identifies potential disruptions from climate impacts (material availability, insurance costs) and geographic concentration in Caribbean/Puerto Rico facilities subject to hurricane/flood risk.
Social story
UFP Technologies exhibits moderate social governance with significant labor-management challenges. The company executed a post-acquisition E-Verify compliance review at AJR subsidiary in 2025, resulting in substantial workforce turnover (estimated $6.3M incremental labor cost) and acknowledged productivity decline. This indicates either supply-chain labor compliance issues or inadequate pre-acquisition due diligence. No disclosed CEO-to-worker pay ratio, diversity metrics (executive/board/workforce gender/ethnicity), or union-standing information. The MD&A references 'AJR Labor Issue' and increased headcount for 'back-office resources,' but no evidence of formal labor-relations policies, diversity programs, or supply-chain ethics audits. International operations in Dominican Republic and Puerto Rico raise potential human-rights due-diligence gaps, particularly in manufacturing. No disclosed turnover rate, safety metrics, or DEI initiatives.
Criticisms on file
-
AJR Labor Issue: significant workforce turnover during 2025 post-acquisition E-Verify review; productivity decline due to training burden; estimated $6.3M incremental labor cost.Source: UFPT 10-K 2025, MD&A section 'Overview' and '2025 Compared to 2024'
-
No disclosed CEO-to-worker pay ratio, diversity (gender/ethnicity) in leadership or workforce, turnover rate, union relations, or supply-chain labor audits.Source: UFPT 10-K 2025, comprehensive absence from 10-K and proxy materials examined
Disclosed initiatives
-
Post-acquisition labor compliance (AJR E-Verify review)2025 execution of E-Verify eligibility review at acquired AJR subsidiary resulted in significant workforce turnover and training burden; company recruited legally eligible replacements.Identified and remediated employment-eligibility compliance gap; however, process caused operational disruptions and $6.3M incremental cost.
Governance story
UFP Technologies demonstrates mixed governance with structural protections but limited transparency on ESG oversight. Board composition and independence percentage are not disclosed in the 10-K excerpt provided; no indication of dual-class voting structure. Corporate charter includes standard anti-takeover provisions (preferred stock authorization, Section 203 DEL GCL, advance notice bylaws), which are not penalized in scoring unless paired with evidence of entrenchment abuse. Cybersecurity governance shows reactive rather than proactive posture: February 2026 Cyber Incident disclosed in Risk Factors and MD&A; investigation ongoing; company claims no material financial impact but acknowledges potential for regulatory fines and reputational harm. Lobbying expenditures and PAC contributions not disclosed. No evidence of antitrust, consumer-safety, or financial-fraud regulatory proceedings. Debt covenant structure (minimum fixed-charge coverage, max funded debt-to-EBITDA) indicates creditor-imposed discipline. Substantial intangible assets ($338.3M goodwill/IP, 51.6% of total assets) create earnings-volatility risk if impairment occurs.
Criticisms on file
-
February 2026 Cyber Incident: suspicious IT activity detected February 14, 2026; systems isolated; external cybersecurity advisors engaged; company investigating extent of data exfiltration (files confirmed stolen/destroyed); billing and label-making functions impacted; regulatory notifications pending; potential for government investigations, private litigation, fines, and reputational harm.Source: UFPT 10-K 2025, Item 1A Risk Factors section 'Security breaches' and 'We experienced a material information technology incident'; MD&A 'Cyber Incident' subsection
-
No disclosed board independence percentage, lobbying expenditures, or PAC contributions in 10-K.Source: UFPT 10-K 2025, comprehensive governance sections
-
Significant intangible assets ($338.3M goodwill/IP, 51.6% of total assets) create risk of large impairment charges; amortization of definite-lived intangibles ($140.8M) will continue to reduce future earnings.Source: UFPT 10-K 2025, Item 1A Risk Factors section 'We may never realize the full value of our intangible assets'
Disclosed initiatives
-
Debt governance via financial covenantsThird Amended and Restated Credit Agreement (June 2024, $275M) imposes minimum fixed-charge coverage ratio and maximum total funded debt-to-EBITDA covenant discipline.Creditor-imposed financial discipline; company in compliance as of December 31, 2025.
-
Cybersecurity governance frameworkCompany implemented policy controlling AI use in enterprise operations; restricts upload of personal/confidential data to AI tools absent commercial assurances; external cybersecurity advisors engaged for incident response.Reactive governance framework; February 2026 Cyber Incident indicates gaps in preventive security measures.
These are Missionomics' own editorial scores — directional signals built from disclosed facts under a published method, not certifications or definitive ratings of UFP Technologies, Inc.. Coverage and confidence vary by data point, and figures can lag real-world changes. Read the full Methodology for sourcing, scoring, and correction details — or open UFP Technologies, Inc. in the app for interactive charts and portfolio building.
Browse Companies · Methodology · Terms of Service · Privacy Policy · Back to Missionomics