Skip to main content
Jump to a category page

HealthStream, Inc., a publicly traded healthcare workforce-compliance software company, disclosed a data breach to the SEC in July 2026. It took another 47 days before affected individuals actually received notice.

HealthStream, Inc., a Nashville-based provider of workforce training and compliance software used by hospitals and healthcare systems, disclosed a data security incident to the Securities and Exchange Commission on July 29, 2026. According to the company, an unauthorized third party gained access to files on HealthStream’s corporate file server. HealthStream states that employee information, billing-related information for certain customers and vendors, and corporate and legal information was accessed and potentially exfiltrated. For approximately 75 credentialing customers, the company had also copied customer data to those same corporate file servers for data conversion, analytics, and troubleshooting purposes — and it separately notified those customers about the incident.

Source: HealthStream, Inc. SEC Form 8-K, filed 07/29/2026.

Individual Notice Came More Than a Month Later

HealthStream’s SEC filing told investors about the breach in late July. But individual consumer notice — the notice that actually reaches the people whose data was involved — didn’t happen until September 14, 2026, when the company reported the breach to both the Vermont Attorney General’s Office (4 Vermont residents) and the Massachusetts Office of Consumer Affairs and Business Regulation (18 Massachusetts residents). That’s 47 days between telling investors and confirming notice to the actual affected individuals.

Source: Vermont Attorney General’s Office security breach notice and Massachusetts Office of Consumer Affairs and Business Regulation filing 2026-1539, both reported 09/14/2026.

What Information Was Exposed?

According to HealthStream’s regulatory filings, the exposed information includes:

  • Social Security number
  • Driver’s license number
  • Government-issued ID number

A Vendor to Hospitals Nationwide

HealthStream provides workforce training, credentialing, and compliance software used by hospitals and health systems across the country. That makes HealthStream a likely business associate under HIPAA for many of its healthcare clients — meaning the practical reach of this breach could extend well beyond HealthStream’s own employees and vendors to the credentialing customers whose data was copied onto the affected servers.

How Many People Are Affected?

HealthStream has not disclosed a national total. The only confirmed population figures come from Vermont (4 residents) and Massachusetts (18 residents) — both small state-level subsets that don’t reflect the company’s national customer and employee base.

Do You Have Legal Options?

Companies that collect and store sensitive personal and identification information have a legal duty to secure it and to notify affected individuals without unreasonable delay.

If you received a notice letter from HealthStream, Inc., contact Emery | Reddy today for a Free Case Review.

Your Personally Identifiable Information (PII) includes information that can be used to identify you, such as your name and other personal details. Organizations that manage healthcare data are legally required to safeguard this information. When PII is exposed in a data breach, it can potentially be used by cybercriminals to commit identity theft, financial fraud, or other misuse.

FAQ

Who is affected by the HealthStream data breach?

HealthStream’s own employees, certain customers and vendors with billing relationships, and approximately 75 credentialing customers whose data was stored on the affected corporate file servers. Confirmed state filings show only 4 Vermont and 18 Massachusetts residents so far; the total is likely larger.

What information was exposed?

According to HealthStream’s regulatory filings, the exposed data includes Social Security numbers, driver’s license numbers, and other government-issued ID numbers.

Why did it take so long to notify people?

HealthStream disclosed the breach to the SEC on July 29, 2026, but individual notice to affected people wasn’t confirmed until September 14, 2026 — 47 days later. An SEC filing informs investors; it isn’t the same as notifying the people whose data was actually exposed.

I’m a patient at a hospital that uses HealthStream. Am I affected?

Possibly, if your hospital is one of the approximately 75 credentialing customers whose data was copied to HealthStream’s affected servers. Check with your hospital or healthcare provider, or contact us if you’re unsure.

Do I have a legal claim?

Companies that collect and store sensitive personal and identification information have a legal duty to secure it and to notify affected individuals without unreasonable delay. If you received a notice letter from HealthStream, Inc., contact the Data Breach Attorneys at Emery | Reddy at 916.995.5968 or www.emeryreddy.com for a Free Case Review. No Fee Unless We Recover.

"Very friendly interview and intake process. I was informed thoroughly about the processes in obtaining a lawyer and was given ample time to make a decision on representation. I’m thankful for everyone’s help and looking forward to working with this Firm on my worker’s compensation claim."

- Darren A.

Receive a
FREE Case Review

Call Now