HealthStream disclosed a cybersecurity incident in which an unauthorized party accessed a limited portion of files on its corporate file server; investigation and remediation are ongoing.

Key Highlights:

  • Unauthorized access to a limited portion of corporate file servers detected; cybersecurity and forensics specialists engaged and law enforcement notified.
  • No evidence to date that customer-facing systems, PHI under HIPAA, or file encryption were impacted; product and service delivery uninterrupted.
  • Accessed data may include employee information, billing info of certain customers/vendors, and corporate and legal files; ~75 credentialing customers had copied data on servers and were notified.
  • Company has incurred and expects further remediation and investigation expenses but currently does not expect a material adverse impact on business or financial results.

Original SEC Filing:

This is an AI-powered summary. It may contain inaccuracies. Consider verifying important information with the source. Please note this summary is solely based on documents filed with the SEC.