Boardroom Alpha
Boardroom Alpha
HSTM · Current Report (Form 8-K) · Filed July 29, 2026

Healthstream Inc — Current Report (Form 8-K)

Form
8-K
Filed
July 29, 2026
Period
Jul 29, 2026
Ticker
HSTM
Accession
0001437749-26-024890
Boardroom Alpha · Filing insights

Cybersecurity incident exposed limited internal files; employee and some customer/vendor data accessed; no PHI; investigation ongoing.

Cyber incident
About Healthstream Inc
Market cap
$859M
1Y TSR
+7.8%
3Y TSR
+10.1%
Board grade
B+
Sector
Healthcare
CEO
Robert A Frist Jr
Last annual meeting: May 28, 2026 · View full Healthstream Inc profile →
hstm20260729_8k.htm
 


UNITED STATES
SECURITIES AND EXCHANGE COMMISSION
WASHINGTON, D.C. 20549
 

 
FORM 8-K
 

 
CURRENT REPORT
 
Pursuant to Section 13 or 15(d) of the Securities Exchange Act of 1934
 
Date of Report (Date of earliest event reported):  July 29, 2026
 

HealthStream, Inc.
(Exact name of Registrant as Specified in Its Charter)

 
Tennessee
000-27701
62-1443555
(State or Other Jurisdiction
of Incorporation)
(Commission File Number)
(IRS Employer
Identification No.)
 
 
 
500 11th Avenue North, Suite 850,
Nashville, Tennessee
 
37203
(Address of Principal Executive Offices)
 
(Zip Code)
 
Registrants Telephone Number, Including Area Code: 615-301-3100
 
Not Applicable
(Former Name or Former Address, if Changed Since Last Report)
 

 
Securities registered pursuant to Section 12(b) of the Act:
 
Title of each Class
Trading Symbol(s)
Name of each exchange on which registered
Common Stock (Par Value $0.00)
HSTM
Nasdaq Global Select Market
 
Check the appropriate box below if the Form 8-K filing is intended to simultaneously satisfy the filing obligation of the registrant under any of the following provisions (see General Instructions A.2. below):
 
 
Written communications pursuant to Rule 425 under the Securities Act (17 CFR 230.425)
 
Soliciting material pursuant to Rule 14a-12 under the Exchange Act (17 CFR 240.14a-12)
 
Pre-commencement communications pursuant to Rule 14d-2(b) under the Exchange Act (17 CFR 240.14d-2(b))
 
Pre-commencement communications pursuant to Rule 13e-4(c) under the Exchange Act (17 CFR 240.13e-4(c))
 
Indicate by check mark whether the registrant is an emerging growth company as defined in Rule 405 of the Securities Act of 1933 (§ 230.405 of this chapter) or Rule 12b-2 of the Securities Exchange Act of 1934 (§ 240.12b-2 of this chapter).
 
Emerging growth company ☐
If an emerging growth company, indicate by check mark if the registrant has elected not to use the extended transition period for complying with any new or revised financial accounting standards provided pursuant to Section 13(a) of the Exchange Act. ☐ 

 
Item         8.01          Other Events.
 
HealthStream, Inc. (the “Company”) recently detected that the Company had experienced a cybersecurity incident in which an unauthorized third party gained access to a limited portion of files on the Company’s corporate file server as described below. Following such detection, the Company initiated response protocols, launched an investigation, which remains ongoing, engaged the services of cybersecurity and forensics specialists and advisors, and notified certain law enforcement authorities.
 
Based on the Company’s investigation to date, we do not believe that any customer-facing systems were accessed or compromised. In addition, the Company has not identified evidence to date that protected health information, as defined by the Health Insurance Portability and Accountability Act (“HIPAA”) was accessed or exfiltrated. Moreover, the Company has not identified any evidence indicating that any files were encrypted by the unauthorized third party. We have not experienced any interruption in our product or service delivery to customers or to our business operations.
 
Based on the Company’s investigation to date, the Company believes that certain information of the Company’s employees, as well as billing related information of certain customers and vendors, and corporate and legal information of the Company, was accessed and/or exfiltrated from the Company’s corporate file servers as the result of the incident. In addition, for approximately 75 of our credentialing customers, the Company had copied certain customer data to the Company’s corporate file servers for purposes of data conversion, analytics, and troubleshooting for these customers. The Company has notified such customers regarding this incident.
 
We have incurred, and expect to continue to incur, certain expenses related to this incident, including, among others, expenses to respond to, remediate and investigate this incident. To the extent required by contract or law, the Company will ensure that any additional notification is provided to individuals or other entities affected by this incident.
 
While the Company’s investigation is ongoing, based on information currently known, the Company does not expect that this incident will have a material adverse impact on the Company’s business, operations or financial results.
 
Cautionary Note regarding Forward-Looking Statements
 
This Current Report on Form 8-K contains forward-looking statements within the meaning of the Private Securities Litigation Reform Act of 1995 and federal securities laws that may relate to, among other things, statements regarding our current beliefs, understanding and expectations regarding this cybersecurity incident and its anticipated impact on our business, operations and financial results. Forward-looking statements are based on management’s current expectations and beliefs concerning future developments and their potential effects on the Company. Forward-looking statements are not a guarantee of future events, results or performance and are subject to a variety of risks and uncertainties, many of which are beyond our control. Future events and actual results and performance could differ materially from those set forth in, contemplated by or underlying the forward-looking statements. Factors that could cause actual events, results or performance to differ from forward-looking statements include legal, reputational, and financial risks resulting from this cybersecurity incident, our ongoing investigation of this cybersecurity incident, including the Company’s potential discovery of additional information related to the incident in connection with this investigation or otherwise, the potential impact of this incident on customer and vendor relationships and our business, the extent of available insurance coverage, the extent of expenses that are incurred by the Company in connection with this incident, and the risks set forth in Item 1A – “Risk Factors” in the Company’s Annual Report on Form 10-K for the year ended December 31, 2025, filed with the Securities and Exchange Commission (the “SEC”), and in the Company’s other filings with the SEC from time to time. These forward-looking statements speak only as of the date on which they are made. Readers should not place undue reliance on forward-looking statements, which reflect management’s views only as of the date hereof. The Company undertakes no obligation to update or revise any such forward-looking statements.
 

 
SIGNATURE
 
 
Pursuant to the requirements of the Securities Exchange Act of 1934, the Registrant has duly caused this report to be signed on its behalf by the undersigned hereunto duly authorized.
 
Date: July 29, 2026
HealthStream, Inc.
 
 
 
 
 
 
 
 
By:
/s/ Scott A. Roberts
 
 
 
Scott A. Roberts
Chief Financial Officer
 
 
From this filing to the watchlist

Catch material events the day they file.

Boardroom Alpha's monitors flag CEO/CFO transitions, restatements, going-concern risk, auditor changes, and 8-K events the day they hit EDGAR — across 6,000+ U.S. public companies. Daily digest by watchlist, API-accessible.

Independent — issuer-pays-free, ideology-free, U.S.-owned.

More filings

Other filings from Healthstream Inc (HSTM)

Reference

Frequently asked questions

When did Healthstream Inc file this 8-K?
Healthstream Inc (HSTM) filed this Current Report (Form 8-K) with the SEC on July 29, 2026. The accession number assigned by EDGAR is 0001437749-26-024890.
What does an 8-K disclose?
Form 8-K is the SEC's current-report form, used to disclose material events between periodic reports (10-K / 10-Q). Triggers include CEO/CFO departures, acquisitions, bankruptcies, earnings releases, auditor changes, changes in fiscal year, and amendments to corporate governance. Each 8-K is keyed to one or more Item numbers (1.01 through 9.01).
What is the key takeaway from this filing?
Cybersecurity incident exposed limited internal files; employee and some customer/vendor data accessed; no PHI; investigation ongoing. This is Boardroom Alpha's one-line summary of the current report; see the full filing text above for the formal disclosure.
What events did Boardroom Alpha flag in this filing?
BA's event-extraction layer identified this signal in the filing text: "Cyber incident". It appears above the filing body as a labeled pill.
What Item codes does an 8-K cover?
An 8-K's Item codes (1.01 through 9.01) specify what kind of event is being disclosed — e.g. Item 1.01 for entering a material agreement, Item 5.02 for departure/election of directors and executive officers, Item 8.01 for other events. The Item codes for this 8-K appear in the filing text above.
Where can I find Healthstream Inc's prior current reports on EDGAR?
The SEC EDGAR browser lists every 8-K Healthstream Inc has filed under CIK 1095565, sortable by date. Use the "View on SEC EDGAR" link in the page header, or browse directly via https://www.sec.gov/cgi-bin/browse-edgar.
Disclaimer

The opinions and information contained herein have been obtained or derived from sources believed to be reliable, but Boardroom Alpha cannot guarantee its accuracy and completeness, and that of the opinions based thereon.

This report contains opinions and is provided for informational purposes only – it does not constitute investment, legal or tax advice. You should not rely solely upon the research herein for purposes of transacting securities or other investments, and you are encouraged to conduct your own research and due diligence, and to seek the advice of a qualified securities professional before you make any investment.

None of the information contained in this report constitutes, or is intended to constitute a recommendation by Boardroom Alpha of any particular security or trading strategy or a determination by Boardroom Alpha that any security or trading strategy is suitable for any specific person. To the extent any of the information contained herein may be deemed to be investment advice, such information is impersonal and not tailored to the investment needs of any specific person.

No representation or warranty, expressed or implied, is made on behalf of Boardroom Alpha as to the accuracy or completeness of the information contained herein. Boardroom Alpha does not accept any liability for any direct, indirect or consequential loss or damage suffered by any person as a result of relying on all or any part of this research and any liability is expressly disclaimed.

Full disclaimer