Breach taxonomy
Summary
HealthStream detected that an unauthorized third party had gained access to a limited portion of files on its corporate file server, then launched an investigation, engaged forensic specialists, and notified law enforcement. The company believes employee information, billing information for certain customers and vendors, and corporate and legal information were accessed and/or exfiltrated; data belonging to roughly 75 credentialing customers that had been copied to those servers for conversion, analytics, and troubleshooting was also implicated. No customer-facing systems were accessed, no HIPAA-protected health information was identified as exposed, no files were encrypted, and product and service delivery continued uninterrupted. Filed under Item 8.01; materiality not yet determined as of the filing date.
Tagging rationale
ThreatUnknown
Filing refers only to 'an unauthorized third party' and gives no actor type or attribution → UNKNOWN.
MethodsData Exfil
Filing states information 'was accessed and/or exfiltrated from the Company's corporate file servers' and that it 'has not identified any evidence indicating that any files were encrypted' → DATA-EXFIL with no ransomware; initial access vector not disclosed.
AssetsPersonal DataConfidential Biz
Filing states 'certain information of the Company's employees, as well as billing related information of certain customers and vendors, and corporate and legal information of the Company, was accessed and/or exfiltrated', plus data for approximately 75 credentialing customers → PERSONAL-DATA primary and CONFIDENTIAL-BIZ.
EffectsInfo Privacy Loss
Filing states 'We have not experienced any interruption in our product or service delivery to customers or to our business operations' while confirming employee and customer data was exfiltrated → INFO-PRIVACY-LOSS only.
Business continuityNot Required
Filing states no interruption in product or service delivery or business operations and that no files were encrypted — a data-only incident requiring no continuity procedures → Not Required.
Impact
Employee, billing, and corporate data plus data for approximately 75 credentialing customers was exfiltrated, but the filing reports no HIPAA protected health information exposed, no encryption, no operational interruption, and only unquantified response and remediation expenses → score 2.
InsuranceNot disclosed
Filing makes no mention of insurance → null.
Read the original SEC filing excerpt
Item 8.01 Other Events. HealthStream, Inc. (the “Company”) recently detected that the Company had experienced a cybersecurity incident in which an unauthorized third party gained access to a limited portion of files on the Company’s corporate file server as described below. Following such detection, the Company initiated response protocols, launched an investigation, which remains ongoing, engaged the services of cybersecurity and forensics specialists and advisors, and notified certain law enforcement authorities. Based on the Company’s investigation to date, we do not believe that any customer-facing systems were accessed or compromised. In addition, the Company has not identified evidence to date that protected health information, as defined by the Health Insurance Portability and Accountability Act (“HIPAA”) was accessed or exfiltrated. Moreover, the Company has not identified any evidence indicating that any files were encrypted by the unauthorized third party. We have not experienced any interruption in our product or service delivery to customers or to our business operations. Based on the Company’s investigation to date, the Company believes that certain information of the Company’s employees, as well as billing related information of certain customers and vendors, and corporate and legal information of the Company, was accessed and/or exfiltrated from the Company’s corporate file servers as the result of the incident. In addition, for approximately 75 of our credentialing customers, the Company had copied certain customer data to the Company’s corporate file servers for purposes of data conversion, analytics, and troubleshooting for these customers. The Company has notified such customers regarding this incident. We have incurred, and expect to continue to incur, certain expenses related to this incident, including, among others, expenses to respond to, remediate and investigate this incident. To the extent required by contract or law, the Company will ensure that any additional notification is provided to individuals or other entities affected by this incident. While the Company’s investigation is ongoing, based on information currently known, the Company does not expect that this incident will have a material adverse impact on the Company’s business, operations or financial results.