{"filing":{"accession_number":"0001437749-26-024890","cik":"0001095565","ticker":"HSTM","company_name":"HEALTHSTREAM INC","form":"8-K","filing_date":"2026-07-29","report_date":"2026-07-29","primary_document":"hstm20260729_8k.htm","primary_document_url":"https://www.sec.gov/Archives/edgar/data/1095565/000143774926024890/hstm20260729_8k.htm"},"events":[{"id":21707,"run_id":19581,"accession_number":"0001437749-26-024890","anchor_item_number":"8.01","event_type":"cybersecurity_incident","event_domain":"legal","is_material":true,"confidence":0.95,"summary":"HealthStream disclosed a material cybersecurity incident in which an unauthorized third party gained access to corporate file servers, resulting in exfiltration of employee information, customer billing data, and corporate/legal information affecting approximately 75 credentialing customers. The company incurred investigation and remediation expenses and notified affected customers, meeting the disclosure requirements for material cybersecurity incidents under Item 1.05 (required since 2023) and Item 8.01 (Other Events).","company_name":"HEALTHSTREAM INC","ticker":"HSTM","filing_date":"2026-07-29","form":"8-K","submitted_at":null,"items":[{"id":21407,"accession_number":"0001437749-26-024890","item_number":"8.01","item_title":"Other Events.","event_type":"cybersecurity_incident","event_domain":"legal","is_material":true,"confidence":0.95,"reasoning":"HealthStream disclosed a material cybersecurity incident in which an unauthorized third party gained access to corporate file servers, resulting in exfiltration of employee information, customer billing data, and corporate/legal information affecting approximately 75 credentialing customers. The company incurred investigation and remediation expenses and notified affected customers, meeting the disclosure requirements for material cybersecurity incidents under Item 1.05 (required since 2023) and Item 8.01 (Other Events).","classifier_version":"claude-haiku-4-5-20251001+prompt-a85dd512","taxonomy_version":"v1.3","classified_at":"2026-07-30T00:04:50.002017+00:00","company_name":"","ticker":null,"filing_date":""}]}],"classifications":[{"id":21407,"accession_number":"0001437749-26-024890","item_number":"8.01","item_title":"Other Events.","event_type":"cybersecurity_incident","event_domain":"legal","is_material":true,"confidence":0.95,"reasoning":"HealthStream disclosed a material cybersecurity incident in which an unauthorized third party gained access to corporate file servers, resulting in exfiltration of employee information, customer billing data, and corporate/legal information affecting approximately 75 credentialing customers. The company incurred investigation and remediation expenses and notified affected customers, meeting the disclosure requirements for material cybersecurity incidents under Item 1.05 (required since 2023) and Item 8.01 (Other Events).","classifier_version":"claude-haiku-4-5-20251001+prompt-a85dd512","taxonomy_version":"v1.3","classified_at":"2026-07-30T00:04:50.002017+00:00","company_name":"HEALTHSTREAM INC","ticker":"HSTM","filing_date":"2026-07-29"}]}
