HealthStream
Disclosed Jul 29, 20268 weeks agoConfirmed
Cybersecurity incident disclosed to the SEC (8-K Item 8.01)
(the "Company") recently detected that the Company had experienced a cybersecurity incident in which an unauthorized third party gained access to a limited portion of files on the Company's corporate file server as described below. Following such detection, the Company initiated response protocols, launched an investigation, which remains ongoing, engaged the services of cybersecurity and forensics specialists and advisors, and notified certain law enforcement authorities. Based on the Company's investigation to date, we do not believe that any customer-facing systems were accessed or compromi
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | Jul 29, 2026 |
| Attack | Vendor breach |
| Data exposed | Names, Social Security numbers, Government IDs |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| Vermont Attorney General breach report: HealthStreamago.vermont.gov · Official notice | Official notice |
| Healthstream Inc Form 8-K, Item 8.01 (2026-07-29)sec.gov · SEC filing | SEC filing |
Notices filed
| Where | Filed | People |
|---|---|---|
| SEC 8-K 8.01total | Jul 29 | |
| Vermont AGresidents of VT | Sep 14 | 4 |
History of this record
- 2026-09-25 · attack: unknown to third-party · backfill source
- 2026-09-25 · disclosed: 2026-09-14 to 2026-07-29 · backfill source
- 2026-09-25 · summary: empty to (the "Company") recently detected that the Company had experienced a cybersecurity incident in which an unauthorized third party gained access to a limited portion of files on the Company's corporate file server as described below. Followin · backfill source
- 2026-09-25 · title: empty to Cybersecurity incident disclosed to the SEC (8-K Item 8.01) · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (Vermont AG), confirmed by Vermont AG. Record counts are as reported. Not legal advice.