secwatch.observer — SEC 8-K summary ====================================== Issuer: HEALTHSTREAM INC (HSTM) CIK: 0001095565 Form: 8-K Filed at: 2026-07-29T20:30:29+00:00 Accession: 0001437749-26-024890 Event type: cyber Sentiment: negative Materiality: 0.55 Item codes: 8.01 LLM model: deepseek-v4-flash:cloud@v2 HealthStream reports cybersecurity incident; employee and billing data accessed ------------------------------------------------------------------------------- - Unauthorized third party accessed limited files on corporate file server; no customer-facing systems compromised. - Employee information, billing data of certain customers/vendors, and corporate/legal info accessed/exfiltrated. - About 75 credentialing customers had data copied to corporate file servers; those customers notified. - No evidence of PHI access, no file encryption, no service interruption; investigation ongoing. - Company does not expect material adverse impact on business, operations, or financial results. Source: EDGAR index: https://www.sec.gov/Archives/edgar/data/1095565/000143774926024890/0001437749-26-024890-index.htm Primary doc: https://www.sec.gov/Archives/edgar/data/1095565/000143774926024890/hstm20260729_8k.htm HTML page: https://secwatch.observer/filing/0001437749-26-024890 License: Source filings: public domain (SEC EDGAR). Summaries (headline + bullets): CC-BY-4.0; attribute https://secwatch.observer