HEALTHSTREAM INC disclosed a cybersecurity incident
What the company disclosed
HealthStream, Inc. (the "Company") recently detected that the Company had experienced a cybersecurity incident in which an unauthorized third party gained access to a limited portion of files on the Company's corporate file server as described below. Following such detection, the Company initiated response protocols, launched an investigation, which remains ongoing, engaged the services of cybersecurity and forensics specialists and advisors, and notified certain law enforcement authorities.
Based on the Company's investigation to date, we do not believe that any customer-facing systems were accessed or compromised. In addition, the Company has not identified evidence to date that protected health information, as defined by the Health Insurance Portability and Accountability Act ("HIPAA") was accessed or exfiltrated. Moreover, the Company has not identified any evidence indicating that any files were encrypted by the unauthorized third party. We have not experienced any interruption in our product or service delivery to customers or to our business operations.
Based on the Company's investigation to date, the Company believes that certain information of the Company's employees, as well as billing related information of certain customers and vendors, and corporate and legal information of the Company, was accessed and/or exfiltrated from the Company's corporate file servers as the result of the incident. In addition, for approximately 75 of our credentialing customers, the Company had copied certain customer data to the Company's corporate file servers for purposes of data conversion, analytics, and troubleshooting for these customers. The Company has notified such customers regarding this incident.
We have incurred, and expect to continue to incur, certain expenses related to this incident, including, among others, expenses to respond to, remediate and investigate this incident. To the extent required by contract or law, the Company will ensure that any additional notification is provided to individuals or other entities affected by this incident.
While the Company's investigation is ongoing, based on information currently known, the Company does not expect that this incident will have a material adverse impact on the Company's business, operations or financial results.
Cautionary Note regarding Forward-Looking Statements
This Current Report on Form 8-K contains forward-looking statements within the meaning of the Private Securities Litigation Reform Act of 1995 and federal securities laws that may relate to, among other things, statements regarding our current beliefs, understanding and expectations regarding this cybersecurity incident and its anticipated impact on our business, operations and financial results. Forward-looking statements are based on management's current expectations and beliefs concerning future developments and their potential effects on the Company. Forward-looking statements are not a guarantee of future events, results or performance and are subject to a variety of risks and uncertainties, many of which are beyond our control. Future events and actual results and performance could differ materially from those set forth in, contemplated by or underlying the forward-looking statements. Factors that could cause actual events, results or performance to differ from forward-looking statements include legal, reputational, and financial risks resulting from this cybersecurity incident, our ongoing investigation of this cybersecurity incident, including the Company's potential discovery of additional information related to the incident in connection with this investigation or otherwise, the potential impact of this incident on customer and vendor relationships and our business, the extent of available insurance coverage, the extent of expenses that are incurred by the Company in connection with this incident, and the risks set forth in Item 1A - "Risk Factors" in the Company's Annual Report on Form 10-K for the year ended December 31, 2025, filed with the Securities and Exchange Commission (the "SEC"), and in the Company's other filings with the SEC from time to time. These forward-looking statements speak only as of the date on which they are made. Readers should not place undue reliance on forward-looking statements, which reflect management's views only as of the date hereof. The Company undertakes no obligation to update or revise any such forward-looking statements.
Quoted from the company’s own Form 8-K, Item 1.05, as filed with the US Securities and Exchange Commission. SEC filings are works of the US federal government and are in the public domain.
The record
- Organisation
- HEALTHSTREAM INC (HSTM) →
- Identity
- HEALTHSTREAM INCidentified by its SEC Central Index Key (0001095565)
- Records affected
- Records not disclosed
- Sector
- Services-Computer Programming, Data Processing, Etc.SIC 7370, from the company’s own filing
- Occurred
- Not disclosed
- Disclosed
- 2026-07-29
- First recorded here
- 2026-09-16
Sources (1)
One source so far.
- SEC EDGAR ↗First reported
2026-07-29