---
schema_version: "secwatch.filing_event.v1"
accession: "0001437749-26-024890"
form_type: "8-K"
ticker: "HSTM"
cik: "0001095565"
company_name: "HEALTHSTREAM INC"
filed_at: "2026-07-29T20:30:29+00:00"
generated_at: "2026-07-29T20:31:06.850847+00:00"
event_type: "cyber"
sentiment: "negative"
materiality_score: 0.55
calibrated_materiality_score: 0.55
confidence: "high"
source: SEC EDGAR
---

# HealthStream reports cybersecurity incident; employee and billing data accessed

## Summary
- Unauthorized third party accessed limited files on corporate file server; no customer-facing systems compromised.
- Employee information, billing data of certain customers/vendors, and corporate/legal info accessed/exfiltrated.
- About 75 credentialing customers had data copied to corporate file servers; those customers notified.
- No evidence of PHI access, no file encryption, no service interruption; investigation ongoing.
- Company does not expect material adverse impact on business, operations, or financial results.

## SEC filing metadata
- accession: 0001437749-26-024890
- form_type: 8-K
- ticker: HSTM
- cik: 0001095565
- company_name: HEALTHSTREAM INC
- filed_at: 2026-07-29T20:30:29+00:00
- event_type: cyber
- sentiment: negative
- materiality_score: 0.55
- calibrated_materiality_score: 0.55
- confidence: high
- sec_items: 8.01
- EDGAR index: https://www.sec.gov/Archives/edgar/data/1095565/000143774926024890/0001437749-26-024890-index.htm
- EDGAR primary document: https://www.sec.gov/Archives/edgar/data/1095565/000143774926024890/hstm20260729_8k.htm

## Machine-readable alternates
- HTML: https://secwatch.observer/filing/0001437749-26-024890
- JSON: https://secwatch.observer/filing/0001437749-26-024890.json
- Plain text: https://secwatch.observer/filing/0001437749-26-024890.txt

This AI-assisted summary is a reading aid. Review the linked SEC EDGAR filing before relying on any specific claim.
