Business Context and Reporting Period
Company: HealthStream, Inc. (HSTM)
Filing Type: Form 8-K (Current Report)
Date of Report: July 29, 2026
Event: Notification of a cybersecurity incident involving unauthorized access to a limited portion of the company's corporate file server.
Key Financial Metrics
The filing does not provide specific financial data such as revenue, profit, cash flow, margins, debt, or liquidity figures. The report focuses exclusively on the cybersecurity incident and its potential implications.
Material Changes and Incident Details
- Incident Scope: An unauthorized third party accessed a limited portion of files on the corporate file server.
- Systems Affected: No customer-facing systems were accessed or compromised. No evidence of file encryption (ransomware) was found.
- Data Compromised:
- Employee information.
- Billing-related information of certain customers and vendors.
- Corporate and legal information.
- Data for approximately 75 credentialing customers (copied to servers for conversion, analytics, and troubleshooting).
- Protected Health Information (PHI): No evidence to date that PHI as defined by HIPAA was accessed or exfiltrated.
- Operational Impact: No interruption to product or service delivery or business operations.
Outlook, Risks, and Management Commentary
- Financial Impact: The Company expects to incur expenses related to response, remediation, and investigation. However, management does not currently expect a material adverse impact on business, operations, or financial results.
- Response Actions: The Company has engaged cybersecurity and forensics specialists, notified law enforcement, and initiated an ongoing investigation.
- Notifications: Affected credentialing customers have been notified. Additional notifications will be made as required by contract or law.
- Risks: Potential legal, reputational, and financial risks remain. Actual results could differ from current expectations due to the ongoing nature of the investigation and potential discovery of additional information.
Investor Verification Checklist
- Verify the extent of data exfiltration as the investigation continues.
- Monitor for updates regarding potential regulatory fines or legal actions related to the incident.
- Track the actual costs incurred for remediation and investigation against the "no material impact" assertion.
- Review future filings for any changes in the assessment of Protected Health Information (PHI) exposure.
- Assess the impact on customer retention, particularly among the 75 affected credentialing customers.