HealthStream, a software solutions provider for healthcare organizations, disclosed a cybersecurity incident in an SEC Form 8-K filing on July 29, 2026. This filing indicated unauthorized access to a corporate file server.
The breach involved employee information, billing information for certain customers and vendors, corporate and legal files, and data related to approximately 75 credentialing customers. No evidence of access to Protected Health Information (PHI) was found, and customer-facing systems were not affected. The total number of affected individuals has not been publicly specified.
Details regarding the full scope of the breach and exact notification timelines may emerge as investigations continue.