HealthStream probes cyber incident after unauthorized access to corporate file server
HSTM•Impact and information accessed
No evidence so far of access to customer-facing systems. No signs of HIPAA-protected health information exfiltration.
Investigation indicates employee information, certain customer and vendor billing data, and corporate legal information were accessed or exfiltrated.
About 75 credentialing customers were notified. Management does not expect a material adverse impact on results.
Investigation into unauthorized access
HealthStream launched an investigation into a cybersecurity incident involving unauthorized access to a limited portion of files on its corporate file server.
Response protocols were activated. Cybersecurity and forensics specialists were engaged. Law enforcement authorities were notified.




