Noting it has taken responsibility for a data breach involving horse owner and handicapper Marshall Gramm, the Horseracing Integrity and Safety Authority outlined in a Sept. 9 letter to the Federal Trade Commission a number of steps it has taken to address the vulnerability.
HISA's letter to the FTC follows an Aug. 31 letter from Churchill Downs Inc. that asked the FTC to conduct an independent review of HISA, citing the alleged Gramm breach—he says the information was available through his HISA account—as well as a recent betting scandal tied to trainers based at Fair Hill Training Center.
The FTC has broad oversight of HISA, a private, self-regulatory organization tasked with developing rules and overseeing anti-doping, medication control, and track safety in racing.
As a covered person, Gramm was supposed to have access to such information on his runners but not on any other horses. The ultimate truth of Gramm's action likely is the key question in this dispute between HISA and the prominent track owner. Should the FTC conduct a review, it will be of interest to find out which side's version of events is true, or closer to the truth. HISA's position is that Gramm made a dedicated, illicit effort to view protected information, while Gramm's position is that he simply accessed information available to covered persons.
In its letter to the FTC Wednesday, HISA characterized Gramm's actions as a breach. The letter penned by HISA CEO Lisa Lazarus noted that data breaches have been all too common in recent years and noted that her organization has acted quickly to address the problem that saw Gramm allegedly gain access to veterinary records of horses in training. In making the case that such breaches are all too common, Lazarus referenced a reported 2012 data breach at CDI-owned advance-deposit wagering outlet TwinSpires.com.
"Several major companies and organizations with budgets far larger than HISA's have reportedly suffered major data thefts and cybersecurity incidents in 2026," Lazarus said in the letter. "In HISA's case, within weeks of discovering the issue, HISA triggered its cyber insurance policy and retained an independent third-party cybersecurity expert to conduct a forensic investigation, identified Dr. Gramm as the individual responsible, publicly disclosed Dr. Gramm and the vulnerability that was exploited, notified law enforcement, initiated an internal enforcement action against Dr. Gramm and updated our systems to address the exploited vulnerability.
"In addition, HISA has accelerated the timeline for the independent IT audit required under the commission's oversight rule and is in the process of engaging a third-party auditor to conduct a comprehensive review of its systems, including the vulnerability at issue. The results of that audit will be provided to the commission, and we look forward to working with the commission to keep our stakeholders informed on these issues and further strengthen our systems."
The incident involving Gramm led to a provisional suspension of the owner by HISA, which is pursuing charges of fraud and unauthorized access and use of confidential information, and has turned over findings to law enforcement. As noted earlier, Gramm contests those charges.
CDI's letter penned by CEO Bill Carstanjen said the data breach involving Gramm exposed multiple vulnerabilities. It said that HISA came out early and vehemently denied that the health data came from its portal. Then when it became clear the data did come from the HISA portal, HISA focused on "fraud" and "misappropriation" rather than addressing the key issues, including: how Gramm was able to access the information, how long this vulnerability existed, what audit tools are in place to detect improper access, and what corrective actions are being taken, and who will verify the changes are sufficient.
"When such information is accessible to persons who should not have access to it, the resulting issue is not only individual misconduct. It is a potential failure of governance, technological controls, procurement oversight, auditing, incident response, and disclosure," stated Carstanjen's letter. "The industry is entitled to understand whether this was an isolated event, a broader systems failure, or a symptom of more significant weaknesses in HISA's technology and oversight processes."
READ: Churchill Downs Inc. Lobbies for FTC Review of HISA

CDI's letter also questioned HISA's efforts regarding an Aug. 9 betting scandal involving unusual betting activity at more than 10 betting shops in Great Britain, as well as North American pari-mutuel pools on horses racing at Saratoga Race Course, Monmouth Park, and Colonial Downs (owned by CDI). Three of the horses involved are trained by Angel Quiroz and other horses were trained at Fair Hill, where Quiroz was based.
Four days after details of the betting coup surfaced, the Horseracing Integrity and Welfare Unit—the testing and enforcement arm of HISA—disclosed that Quiroz had allegedly violated anti-doping rules after a horse in his care tested positive for the banned substance albuterol in a sample taken following a workout July 10.
In its letter Wednesday, HISA noted that its congressional mandate does not include the regulation of betting markets and it has no authority over wagering activity. It then pointed the finger at CDI as having more responsibility than HISA for such matters. State regulators have oversight of betting pools and tracks themselves provide oversight through the Thoroughbred Racing Protective Bureau, a wholly owned subsidiary of the Thoroughbred Racing Associations of North America.
"The apparent criticism of HISA on this topic is particularly interesting given CDI's own position within the industry. In his letter, Mr. Carstanjen describes CDI's ownership of 'an-advance-deposit wagering platform' and the company's 'direct and substantial interest' in wagering. It follows, then, that CDI would be uniquely positioned and should be motivated to identify suspicious betting patterns and take action to protect its customers and the industry at large," Lazarus wrote in the letter. "But, when a horse linked to the 'Fair Hill Five' was scheduled to race at a CDI-owned racetrack the very next day, CDI took no action to prevent the horse from racing despite having been made aware of the issue and presented with an opportunity to act. It was HISA that took the appropriate steps to protect the horse and other racing participants."
The CDI letter also questioned the timing of the Quiroz anti-doping violation, noting that if the July 10 finding had occurred sooner perhaps the scandal could have been prevented.
"One of HISA's central promises was more uniform, timely, and transparent handling of integrity related matters. Delayed disclosure of significant violations was precisely the type of problem HISA was created to address," stated Carstanjen's letter. "This situation raises a number of legitimate questions, including whether delays in HISA's testing or reporting procedures allow violators to continue racing for extended periods after failed doping tests; whether racetracks and the betting public are being properly informed of the doping violations that undermine the integrity of the sport; and whether HISA's disclosure practices are meeting the expectations that justified the creation of a national authority."
Lazarus responded in her Wednesday letter that HISA and HIWU had followed the proper protocol in releasing that finding.
"CDI's criticism also extends to the timing of the disclosure of an alleged Banned Substance violation. Once again, this appears to be an effort to generate misplaced concern rather than to engage with the relevant facts. In this particular case, the timing of the alleged violation followed the very process that has been in place for approximately the last two years. Public notification of an alleged violation is not made until the B sample is waived or the result is returned confirming the A Sample. If the B sample is waived, public disclosure is made when the notice of violation is served to the Covered Person. If it is not waived, the public disclosure is made following the return of the B Sample. The Horseracing Integrity and Welfare Unit followed HISA's public disclosure procedures to the letter and there was no deviation whatsoever from its standard protocol."
The letter from CDI to the FTC was notable as the track owner initially had largely been a supporter of HISA, although it later was involved in litigation over HISA's assessment fees. In 2022 when HISA cleared a hurdle in Congress, Carstanjen said: "CDI believes HISA is a critical vehicle for establishing a comprehensive and consistent regulatory framework to protect the integrity of our sport and the safety and wellbeing of our equine and human athletes. We also believe that HISA's ultimate success will depend on the Authority working collaboratively and in good faith with various industry groups to ensure widely accepted regulatory principles and an effective implementation."
Other industry groups involved in active litigation opposing HISA, or otherwise opposed to HISA such as the National Horsemen's Benevolent and Protective Association also have reportedly sent letters to the FTC requesting a review.
"We are asking for the same standard of accountability from the regulator that the regulator demands from the industry it regulates," said Eric Hamelback, CEO of the NHBPA in a statement released Aug. 31.
Lazarus concluded her letter by saying HISA welcomes any questions from the FTC and stands ready to answer them.
"We remain confident in the commission's ongoing oversight and review of our actions, policies, protocols and systems and welcome further conversations on this matter should they be warranted."







