HISA Faced the Questions on Marshall Gramm. They Answered Them.

August 17, 2026

Lisa Lazarus sat front and center and answered every question asked

I have criticized HISA when I thought they deserved it. I have questioned their rules, their decisions, their priorities, their budgets and at times their judgment. I will undoubtedly do it again. That is part of what we do here. Fair, however, has to be fair, and on Monday afternoon Lisa Lazarus and HISA went front and center over the Marshall Gramm charges and did something officials in this industry don’t exactly have a long and distinguished history of doing.

They stood there and answered the questions. All of them.

The Zoom press conference was scheduled for approximately 30 minutes. It went about 36. Not because there was a filibuster or a long-winded opening statement designed to eat the clock. Lisa Lazarus opened with a succinct but informative explanation of what HISA says happened, how they got there and where the case goes from here. Then she took questions. When 30 minutes came and there were still questions, she stayed. When she knew the answer, she answered it. When she didn’t know something, she said she didn’t know. When something got beyond her technical expertise in cybersecurity, she said that too.

Nobody had to pull teeth. That shouldn’t be noteworthy. In horse racing, unfortunately, it is. There was also considerably more information provided than what appeared in HISA’s original announcement. HISA did not investigate this entirely in-house and then grade its own paper. Lazarus explained that the Authority brought in Arete, a third-party cybersecurity forensic firm, in addition to using HISA’s own personnel and investigators. HISA’s release says those investigations independently pointed to Marshall Gramm as solely responsible for accessing the confidential horse-health information and creating the past performances for horses with which he had no legitimate connection.

That is important considering some of the narrative that developed before HISA’s announcement. The story circulating earlier Monday was essentially that Gramm had discovered a simplistic vulnerability in HISA’s system, changed something in a URL and suddenly found himself looking at information he wasn’t supposed to see.

According to Lazarus, it wasn’t that simple. HISA isn’t running from that, nor should it. Its system allowed someone with legitimate credentials to get somewhere those credentials weren’t supposed to take him. Owners, trainers and veterinarians trusted HISA with confidential information, and protecting that information was HISA’s responsibility. That part belongs to HISA. What allegedly happened after the vulnerability was discovered belongs somewhere else.

HISA’s investigation concluded Gramm developed an automated method to obtain confidential horse-health information at scale and did it in a manner designed to mimic authorized activity and avoid detection. During the press conference, Lazarus discussed a threshold of approximately 500 that, as she understands it, was significant to the system’s security monitoring. She also described steps HISA believes were taken to conceal the activity, including information relating to the user and browser, while appropriately acknowledging that she is not a cybersecurity expert and leaving some of the technical specifics to those who are.

There is a considerable difference between finding a door unlocked and developing a system for repeatedly going through it without anyone noticing you are there. That is also why I don’t buy any attempt to make this entirely about HISA’s technology.

HISA absolutely has to own the vulnerability. They have to fix it, explain it and determine whether anyone else ever exploited it. According to Lazarus, changes have already been made and nobody else has exploited it. But a vulnerability doesn’t eliminate personal responsibility for deliberately exploiting it. Two things can be true at the same time. HISA can have had an unacceptable weakness in its system, and someone can deliberately exploit that weakness. One doesn’t absolve the other.

The investigation also went considerably beyond the two past performances that originally surfaced on social media. HISA says Gramm’s activity occurred during an approximately six-week period from early May through mid-June. During that same period, Gramm participated in handicapping contests, wagered into pari-mutuel pools and claimed horses.

Lazarus said horses Gramm claimed during the relevant period subsequently earned approximately $90,000 in purse money, and HISA intends to seek recovery of that money from Gramm but after HISA pays the affected owners. That does not mean HISA said Gramm used confidential veterinary information to make every one of those claims. It does mean those transactions fall within the period HISA is examining, and when someone is alleged to have possessed information unavailable to everyone else while making financial decisions involving horses, you follow the money and you follow the horses. That is Investigating 101.

One of the more remarkable things Lazarus disclosed involved Gramm himself. Many on social media are coming to his defense. According to Lazarus, when HISA finally confronted Gramm with what investigators had found, he admitted what he had done immediately, apologized and expressed remorse. Had it ended there, perhaps the story would have taken a different course. It didn’t. Lazarus said Gramm as I understood it subsequently sought a resolution that would have protected his anonymity and concealed or limited disclosure of the scope of what had occurred. HISA would agree to neither. Those were non-negotiable according to Lazarus.

That goes directly to something I wrote earlier. There is a difference between being sorry something happened and being sorry everyone found out it happened. People can decide for themselves where they think that line falls here. Gramm is entitled to his own explanation and his due process, and we should hear it.

There was another detail I found particularly difficult to get past. During the period all this was unfolding, Gramm participated in an approximately hour-long industry call with Lazarus, Pat Cummings and others concerning data protection and safeguarding racing information. Think about that. According to HISA’s timeline, Gramm was involved in an industry conversation about protecting racing’s data while possessing knowledge of the very vulnerability HISA says he had been exploiting. He said nothing. Lazarus made an important point about that. Had Gramm come forward when he discovered the vulnerability, or even raised his hand during that conversation and told HISA what he knew, they would have viewed his conduct very differently. He didn’t. That doesn’t decide the case. It does tell you something about why HISA apparently views the conduct as considerably more serious than an owner accidentally wandering into information he wasn’t supposed to see.

The sanctions could reflect that. HISA’s attorney explained that Gramm is entitled to due process and a hearing, which has been scheduled as expeditiously as possible. The attorney also indicated HISA will probably seek a lifetime ban, along with other penalties. That is a long way from some of the chatter circulating earlier Monday suggesting a relatively finite suspension and negotiated resolution were essentially done. They weren’t. Negotiations did not result in a settlement. HISA filed charges. Gramm gets his hearing. HISA gets to present its evidence. Gramm gets to challenge it. That is how it should work.

I also asked about referrals outside HISA’s jurisdiction. Lazarus confirmed that the information gathered in the investigation is being shared with appropriate regulatory and law-enforcement authorities, although she appropriately declined to get into specifics concerning law enforcement. Again, that’s how it should work.

If HISA believes its investigation uncovered conduct potentially falling outside the boundaries of its own rules and authority, HISA shouldn’t play prosecutor for jurisdictions it doesn’t control. Give those agencies the evidence and let them decide what, if anything, belongs to them.

There were plenty of other questions. HISA’s cyber insurance covered the forensic investigation subject to a deductible. Lazarus didn’t remember the amount of the deductible and said so. There was a question about whether the Arete forensic report itself would be made public. HISA apparently hasn’t even gotten to the point of deciding that yet. Nobody dodged anything I heard.

I actually wound up asking the first question and the last question. Most of what I intended to ask in between had already been answered either in Lazarus’ opening statement or during the press conference. That may be the best compliment I can give them.

I didn’t have to manufacture a gotcha because they weren’t hiding from the questions. There are still questions, plenty of them. How many horses’ records were actually accessed? Which horses? What was done with the information? Did any of it influence wagers, handicapping contests or claims? Was it shared beyond the past performances we saw? Can HISA establish that Gramm was the only person ever to exploit this vulnerability, as opposed to the only person its investigation identified? How long did the vulnerability itself exist before Gramm allegedly found it? And there is still the biggest institutional question of all. How did confidential information entrusted to HISA become accessible this way in the first place? Today’s press conference doesn’t make that question disappear. It shouldn’t. But accountability works both ways. I have watched racing organizations issue statements designed to say as little as humanly possible. I have watched executives hide behind public-relations departments. I have watched legitimate questions answered with corporate word salad until everybody forgot what the original question was. That isn’t what I watched Monday.

Lisa Lazarus went in front of the racing media knowing exactly what kind of day this had become. She explained what HISA believes happened, acknowledged the vulnerability in HISA’s own system, explained how they investigated it, discussed what they believe Gramm did to avoid detection, addressed restitution, discussed his response when confronted, confirmed outside referrals, explained where due process takes the case next and stayed until everyone who wanted to ask a question had the opportunity.

High marks.

That isn’t an endorsement of everything HISA has ever done. It isn’t absolution for the vulnerability. And it certainly isn’t a prediction about what happens when Marshall Gramm has his opportunity to answer the charges. It is simply calling this one the way I saw it. You don’t establish credibility by demanding applause when things go right. You establish it by standing in front of people when something went very wrong and answering for it. Today, HISA did that.

There will be more questions, and there should be. There will be due process for Marshall Gramm, and there should be. There should also be a complete accounting of how this happened, what information was accessed, what was done with it and whether anyone else ever found the same door. But for approximately 36 minutes Monday afternoon, nobody hid behind a press release.

In horse racing, that shouldn’t be unusual. Unfortunately, it is.

Contributing Authors

"Jon Stettin at the Breeders' Cup draw at Del Mar"

Jonathan "Jon" Stettin

Jonathan “Jon” Stettin is the founder and publisher of Past the Wire and one of horse racing’s most respected professional handicappers, known industry-wide as the...

View Jonathan "Jon" Stettin

easy like button and so much good info here glad have a few days now to prepare.

@innopva9973 View testimonials

Facebook

Comments

Leave a Comment