HISA Has Questions to Answer: Who Was Watching the Watchdog?

By Eric J. Hamelback, Chief Executive Officer
National Horsemen’s Benevolent & Protective Association

Let me be clear about something from the beginning: if Marshall Gramm knowingly accessed confidential veterinary information concerning horses with which he had no legitimate connection and used that information for handicapping, wagering or claiming purposes, then those allegations should be investigated and, if proven, appropriately adjudicated.

This op ed is not about defending Marshall Gramm.

It is about asking who is responsible for protecting the information of thousands of horse owners, trainers, veterinarians and horses when that information is placed into a centralized national database operated by the Horseracing Integrity and Safety Authority.

That is a question that the horse racing industry needs answered.

In June, confidential veterinary information from the HISA Portal appeared on social media. HISA initially denied that the information could have come from its system. After an investigation involving digital forensics, contractor interviews and a third-party cybersecurity investigation, HISA ultimately charged Gramm on August 17 with improper access to veterinary records and fraud on the betting market.

Again, if those allegations are true, they should be taken seriously.

But there is another side to this story that cannot simply be ignored.

How was an individual using his own HISA login credentials allegedly able to repeatedly obtain a large volume of confidential veterinary information that was outside the scope of his legitimate access?

How could that activity allegedly continue for approximately six weeks? But we now know that breach was accessible by veterinarians and others, seemingly since the beginning.

And perhaps most importantly, why didn’t HISA’s security systems detect and stop it?

Those are not questions about whether one individual followed the rules. They are questions about whether the organization responsible for safeguarding the industry’s information had adequate safeguards in the first place.

According to the information that has become public, Gramm did not attempt to hide his identity from the HISA Portal. If that is accurate, then this was not necessarily a sophisticated attack involving a stolen password or an anonymous hacker breaking through a firewall.

It raises a much more basic question:

What good is an authorized login if the system cannot determine what that authorized user is actually authorized to see?

HISA has made centralized technology and centralized data collection fundamental components of its national regulatory system. Its own 2023 Annual Metrics Report stated that the HISA Portal contained a broad range of equine treatment and health records and that nearly two million veterinary treatment records had been uploaded to the system, with thousands of treatment reports being received every day.

That is an extraordinary amount of sensitive information.

And it is not information that HISA collected casually. Horsemen and veterinarians have been required to provide it as part of the regulatory system.

That creates a corresponding responsibility.

When an organization spends millions of dollars on technology and builds a national regulatory system around the collection of sensitive information, the industry has every right to expect sophisticated access controls, monitoring, intrusion detection and auditing.

Instead, we now have a situation in which an authorized user allegedly obtained information he was not entitled to access, apparently over an extended period, before the issue came to light publicly.

That should concern every participant in this industry.

And it should concern the Federal Trade Commission.

The FTC should not simply ask whether Marshall Gramm broke a rule. It should ask whether HISA fulfilled its responsibility to protect the information it compelled the industry to provide.

Those are two separate questions.

One does not excuse the other.

Horse racing has learned, sometimes painfully, that when something goes wrong, the first question cannot simply be, “Who made the mistake?” We examine the circumstances surrounding an incident. We review the records. We look at the equipment, the environment, the procedures and the decisions that were made. We try to determine whether there was a systemic failure that could cause the same problem to happen again.

The same standard should apply to HISA.

If a trainer violates a medication rule, HISA expects the trainer to be accountable. If a veterinarian violates a rule, HISA expects the veterinarian to be accountable. If an owner violates a rule, HISA expects the owner to be accountable.

But when the system itself fails to protect confidential information, the organization operating that system must be accountable as well.

The industry deserves answers to some very straightforward questions.

  • What technical controls were supposed to prevent an authorized user from accessing information outside the scope of his legitimate permissions?
  • What monitoring systems were in place to identify unusual or excessive activity?
  • Why did repeated requests for confidential information allegedly continue for weeks without triggering an alert?
  • How much information was accessed?
  • Whose information was accessed?
  • Were other horses, owners, trainers or veterinarians affected?
  • What did HISA’s internal security personnel discover?
  • What did the independent forensic investigation determine?
  • And what has HISA changed since this incident occurred?

These are not unreasonable questions. They are the minimum questions that should be asked when an organization entrusted with millions of confidential records experiences a security failure.

There is another important question: Who is independently verifying HISA’s answers?

The National HBPA believes the FTC should require an independent investigation into this incident and HISA’s data-security practices. The objective should not be to prejudge Gramm, HISA or anyone else. We want the objective should be to determine what happened, why it happened, how much information was exposed, whether other information remains vulnerable and what must be done to ensure it cannot happen again.

The investigation should also examine whether HISA’s cybersecurity expenditures have produced the level of protection that horsemen and the public have been led to expect.

The FTC should consider requiring an independent cybersecurity audit of HISA’s systems, along with an independent review of its financial controls and technology expenditures. Any organization exercising this level of regulatory authority and collecting this volume of sensitive information should be able to demonstrate, not simply proclaim that its systems are secure.

Horsemen have been told that HISA exists to protect the integrity and safety of the sport, and we believe that responsibility runs in both directions.

If Marshall Gramm broke the rules, he should answer for that conduct. But if HISA’s systems allowed an authorized user to access information he was not authorized to see for weeks without detection, HISA has questions to answer, too.

The National HBPA is not asking for special treatment for anyone. We are asking for the same standard of accountability from the regulator that the regulator demands from the industry it regulates.

The racing industry deserves nothing less.

Read National HBPA, NAARV, US Trotting’s letter to FTC Chairman Ferguson

Share This Story, Choose Your Platform!