Sep 012026
 

Bloodhorse – Eric Mitchell – Churchill Downs Inc. Lobbies for FTC Review of HISA

TDN – Sue Finley – Churchill Asks FTC for Independent Review of HISA

HISA Has Questions to Answer: Who Was Watching the Watchdog?
By Eric J. Hamelback, Chief Executive Officer

National Horsemen’s Benevolent & Protective Association

Let me be clear about something from the beginning: if Marshall Gramm knowingly accessed confidential veterinary information concerning horses with which he had no legitimate connection and used that information for handicapping, wagering or claiming purposes, then those allegations should be investigated and, if proven, appropriately adjudicated.

This op ed is not about defending Marshall Gramm.

It is about asking who is responsible for protecting the information of thousands of horse owners, trainers, veterinarians and horses when that information is placed into a centralized national database operated by the Horseracing Integrity and Safety Authority.

That is a question that the horse-racing industry needs answered.

In June, confidential veterinary information from the HISA Portal appeared on social media. HISA initially denied that the information could have come from its system. After an investigation involving digital forensics, contractor interviews and a third-party cybersecurity investigation, HISA ultimately charged Gramm on August 17 with improper access to veterinary records and fraud on the betting market.

Again, if those allegations are true, they should be taken seriously.

But there is another side to this story that cannot simply be ignored.

How was an individual using his own HISA login credentials allegedly able to repeatedly obtain a large volume of confidential veterinary information that was outside the scope of his legitimate access?

How could that activity allegedly continue for approximately six weeks? But we now know that breach was accessible by veterinarians and others, seemingly since the beginning.

And perhaps most importantly, why didn’t HISA’s security systems detect and stop it?

Those are not questions about whether one individual followed the rules. They are questions about whether the organization responsible for safeguarding the industry’s information had adequate safeguards in the first place.

According to the information that has become public, Gramm did not attempt to hide his identity from the HISA Portal. If that is accurate, then this was not necessarily a sophisticated attack involving a stolen password or an anonymous hacker breaking through a firewall.

It raises a much more basic question:

What good is an authorized login if the system cannot determine what that authorized user is actually authorized to see?

HISA has made centralized technology and centralized data collection fundamental components of its national regulatory system. Its own 2023 Annual Metrics Report stated that the HISA Portal contained a broad range of equine treatment and health records and that nearly two million veterinary treatment records had been uploaded to the system, with thousands of treatment reports being received every day.

That is an extraordinary amount of sensitive information.

And it is not information that HISA collected casually. Horsemen and veterinarians have been required to provide it as part of the regulatory system.

That creates a corresponding responsibility.

When an organization spends millions of dollars on technology and builds a national regulatory system around the collection of sensitive information, the industry has every right to expect sophisticated access controls, monitoring, intrusion detection and auditing.

Instead, we now have a situation in which an authorized user allegedly obtained information he was not entitled to access, apparently over an extended period, before the issue came to light publicly.

That should concern every participant in this industry.

And it should concern the Federal Trade Commission.

The FTC should not simply ask whether Marshall Gramm broke a rule. It should ask whether HISA fulfilled its responsibility to protect the information it compelled the industry to provide.

Those are two separate questions.

One does not excuse the other.

Horse racing has learned, sometimes painfully, that when something goes wrong, the first question cannot simply be, “Who made the mistake?” We examine the circumstances surrounding an incident. We review the records. We look at the equipment, the environment, the procedures and the decisions that were made. We try to determine whether there was a systemic failure that could cause the same problem to happen again.

The same standard should apply to HISA.

If a trainer violates a medication rule, HISA expects the trainer to be accountable. If a veterinarian violates a rule, HISA expects the veterinarian to be accountable. If an owner violates a rule, HISA expects the owner to be accountable.

But when the system itself fails to protect confidential information, the organization operating that system must be accountable as well.

The industry deserves answers to some very straightforward questions.

  • What technical controls were supposed to prevent an authorized user from accessing information outside the scope of his legitimate permissions?
  • What monitoring systems were in place to identify unusual or excessive activity?
  • Why did repeated requests for confidential information allegedly continue for weeks without triggering an alert?
  • How much information was accessed?
  • Whose information was accessed?
  • Were other horses, owners, trainers or veterinarians affected?
  • What did HISA’s internal security personnel discover?
  • What did the independent forensic investigation determine?
  • And what has HISA changed since this incident occurred?

These are not unreasonable questions. They are the minimum questions that should be asked when an organization entrusted with millions of confidential records experiences a security failure.

There is another important question: Who is independently verifying HISA’s answers?

The National HBPA believes the FTC should require an independent investigation into this incident and HISA’s data-security practices. The objective should not be to prejudge Gramm, HISA or anyone else. We want the objective should be to determine what happened, why it happened, how much information was exposed, whether other information remains vulnerable and what must be done to ensure it cannot happen again.

The investigation should also examine whether HISA’s cybersecurity expenditures have produced the level of protection that horsemen and the public have been led to expect.

The FTC should consider requiring an independent cybersecurity audit of HISA’s systems, along with an independent review of its financial controls and technology expenditures. Any organization exercising this level of regulatory authority and collecting this volume of sensitive information should be able to demonstrate, not simply proclaim that its systems are secure.

Horsemen have been told that HISA exists to protect the integrity and safety of the sport, and we believe that responsibility runs in both directions.

If Marshall Gramm broke the rules, he should answer for that conduct. But if HISA’s systems allowed an authorized user to access information he was not authorized to see for weeks without detection, HISA has questions to answer, too.

The National HBPA is not asking for special treatment for anyone. We are asking for the same standard of accountability from the regulator that the regulator demands from the industry it regulates.

The racing industry deserves nothing less.

Read National HBPA, NAARV, US Trotting’s letter to FTC Chairman Ferguson

Paulick Report – Chelsea Hackbarth – Churchill To FTC: HISA Controversies Show ‘Troubling Gaps And Warning Signs’

Horse Race Insider – John Pricci – ONE MAN’S TAKE ON SCANDALOUS ACTIVITIES; GOLDEN TEMPO EARLY FAVORITE FOR TRAVERS

Paulick Report – Andrew Cohen – Keeping Pace: Grammgate Is A New-Age Scandal Over Age-Old Tricks

TDN – Bill Finley – Gramm Accepts Provisional Suspension from HISA

Bloodhorse – Frank Angst – Gramm Immediately Suspended as Owner, Contest Player

Phil has a question:

Why wasn’t Lisa Lazarus immediately suspended for brutal incompetence.

Since Lisa Lazarus seems to be very good at closing the barn door after the horse has bolted can she also not let the barn door hit her on the way out.

Paulick Report – Chelsea Hackbarth – How He Did It: Marshall Gramm’s Actions Went Beyond Finding A Security Flaw

Phil has a question:

If a horseplayer at a tournament hadn’t spied an enhanced PP with his little eyes would HISA have ever noticed the data breach.

Men now monopolize the upper levels… depriving women of their rightful share of opportunities for incompetence.

Laurence J. Peter

Chain Of Fools

DRF – David Grening – HISA could seek lifetime ban for owner Gramm over unauthorized access to portal

I think the funniest part is this was all uncovered not by HISA, but by gamblers that were mad they were getting cheated.

TDN – Bill Finley – How Owner Michael Imperio Broke The Story of PP-Gate

Horse Racing Nation – Ed deRosa – Gramm gives up tourney wins, but his horses are still running

Phil has a question:

Since when do you call a hole big enough to drive a semi through a vulnerability.

Was the HISA portal system code written on an Atari 400.

Was the HISA portal system code written by Mickey Mouse.

How the in God’s Green Earth (Phil would normally use an expletive, but a milquetoast asked Phil to tone down) did HISA not notice myriad logins required to download the amount of data that HISA claims was downloaded.

How did over 4,000,000 records being downloaded in a very compressed time frame not trigger some type of alarm at HISA.

How did HISA not catch Gramm until someone noticed the allegedly tainted PPs on line.

Does HISA stand for Hugest Incompetent Society in America or Hugely Incompetent Stupid Assholes.

How can Lisa Lazarus stand up with a straight face and blame Gramm for her and her organizations’ brutal (Phil would normally use an expletive, but a milquetoast asked Phil to tone down) incompetence.

Why is Lisa Lazarus so smart in hindsight.

Would you trust HISA or Liza Lazarus to babysit your cockroaches.

When is Lisa’s head gonna roll.

Head’s Will Roll

TSN – CP – Soccer fans launch global petition urging Infantino to resign over World Cup ‘betrayal’

Phil has a question:

Where do you sign the petition to get rid of Lisa Lazarus.

Paulick Report – Ray Paulick – View From The Eighth Pole: Looking For An Edge

The Edge… There is no honest way to explain it because the only people who really know where it is are the ones who have gone over. The others-the living-are those who pushed their control as far as they felt they could handle it, and then pulled back, or slowed down, or did whatever they had to when it came time to choose between Now and Later. But the edge is still Out there.”

Hunter S. Thompson

Phil has a question:

Who is more wrong – Marshall Gramm for taking and using data that was openly accessible on HISA’s portal or the loud mouth attack when you’re wrong Lisa Lazarus and HISA for failing to secure the alleged confidential data.

Why hasn’t Lisa Lazarus been summarily fired for failing to ensure that thoroughbred owners confidential data was not properly secured.

Why hasn’t Lisa Lazarus and HISA admitted that there was a massive failure on their part to ensure that thoroughbred owners confidential data was properly secured.

Is Liza Lazarus favourite thoroughbred Buckpasser or Spend a Buck. 

In a closed society where everybody’s guilty, the only crime is getting caught. In a world of thieves, the only final sin is stupidity.

Hunter S. Thompson


Phil M. Stockmen

 Leave a Reply

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <s> <strike> <strong>

(required)

(required)