started · updated
HealthStream data breach exposes employee and billing data
HealthStream, a provider of software solutions for healthcare organizations, announced on July 29, 2026 that an unauthorized party accessed its corporate file servers. The breach potentially resulted in the exfiltration of employee information and billing data belonging to its customers and vendors. The company stated that protected health information (PHI) and patient‑facing systems were not compromised. Approximately 75 credentialing customers have been notified, and the disclosure was made through a Form 8‑K filing with the U.S. Securities and Exchange Commission. The incident has triggered concerns in the cybersecurity and healthcare sectors and may lead to class‑action lawsuits against the firm.