Disclosure: Marshall Gramm is a good friend. He has been a guest on my shows many times and is a regular contributor to In The Money Media. Ten Strike Racing was the first commercial sponsor our company ever had. I am not a neutral party and I won’t pretend to be. I was not among the small group Gramm shared those past performances with before they became public; like a lot of people, I saw them once they were circulating on X. I have tried to report this story the way I would report it about a stranger, including the parts that make him look bad.
Over roughly four weeks this spring, Marshall Gramm used his HISA Portal login, issued to him as an owner, to pull veterinary records for thousands of horses he had no connection to. He built past performances from what he found, including treatment-level detail like intra-articular injections. Those past performances, which he initially shared with a small group of friends, ended up on social media in June, and the industry spent weeks trying to figure out where they had come from.
During that same window, he claimed horses and he bet as usual, even winning an important handicapping contest, the Belmont Betting Challenge.
To me, the claimed horses are the real offense. Veterinary treatment records are supposed to travel with the horses: it’s when the claim goes through that the new designated owner and responsible person get access to that horse’s records. Knowing what you are getting before you drop the slip is a real edge over everyone else playing the claiming game. It doesn’t matter what happened with these specific horses or what his intentions were. That was unfair.
Gramm’s own assessment:
“Where I exercised poor judgment was in not bringing the vulnerability to HISA’s attention sooner after it became a public story. I should have done so, and I regret that I did not. I want to apologize for the difficulties this situation has caused.”
HISA has characterized what he did as fraud on the market, arguing that he had access to information that others didn’t, and was using it to compete in markets, both in the pari-mutuel pools and in claiming horses. From a fellow horseplayer’s perspective, it’s a tough pill to swallow. Marshall is considered a well-respected leader in the game, not someone who needs an unfair edge to succeed. And not coming forward when news of the leak first broke was another error in judgment.
He did stupid things, the optics are terrible, and the anger many throughout the industry are feeling is legitimate.
Having said all that, I think the HISA response has been disproportionate.
The punishment
HISA’s outside counsel John Roach said on Monday’s press call that enforcement will seek sanctions up to and including a lifetime ban. HISA is seeking restitution of Gramm’s proceeds. It has referred the matter to the FBI, to state racing commissions, and to wagering platforms. Lazarus said she personally called all nine owners whose horses were claimed (there is a dispute in the number of claims during the timeframe in question — HISA says nine over six weeks, my research suggests four over four weeks).
The purse money at stake, by HISA’s own accounting: roughly $80,000 to $90,000.
A lifetime ban is the nuclear option, and HISA has reached for it before. Dr. Allen Bonnell, a Penn National veterinarian, accepted one in 2025 to resolve HISA charges that he had conspired with 13 trainers over 18 months to inject horses’ joints inside the mandatory stand-down periods and not report it — precisely so those horses could run when they should not have. More than 100 horses were disqualified. Three died of injuries in races they ran after being injected, and Lazarus said four more died within months.
This is the company they are proposing to put Marshall Gramm in, over unauthorized access to a data set.
He did look at vet records of claims and potential claims. He did incorporate it into custom past performances. He did not use it in the computer modeling that comprises most of his pari-mutuel handle, and it was not a factor in the wager he constructed to win the Belmont Betting Challenge. That doesn’t let him off the hook, of course, but as a horseplayer it is meaningful to me, and it supports the idea that his main interest here was collecting and testing the data, as he indicated in his public statement.
He wrote:
“I am a college professor and data analyst, and gathering and analyzing large datasets is something I have done throughout my career, including extensive work with horse racing data. The information at issue was available through my authorized HISA account. It was a large dataset, and at the time I accessed it, I had not fully reviewed its contents or understood the scope of the information it contained.”
It’s important to note that before the case went public, HISA and Gramm were negotiating a settlement, and the terms were nearly agreed upon: a four-year penalty, restitution, and a substantial charitable contribution. That is a serious sanction and Gramm was prepared to accept it.
The talks collapsed. Lazarus told the press it was because Gramm wanted HISA to conceal information in exchange for settlement, and that transparency was the one thing off the table. Gramm’s account is different and specific: the sticking point was two sentences he refused to strike from his public statement — that he used his own account and credentials and never attempted to conceal his identity or circumvent HISA’s security, and that once logged in he bypassed no security protocols.
Those two accounts cannot both be right. If Gramm is telling the truth — and my research suggests he is — then HISA walked away from a four-year ban and full restitution rather than let him say publicly that he did not hack them. And now they are seeking a lifetime ban instead. The hacking characterization is not a small matter. It is the difference between a rules violation and something a federal prosecutor might be inclined to look at.
The system
Before we get to HISA’s account of what happened, it’s worth understanding the context in which they gave it. Two months earlier, they had told the industry something quite different.
On June 15, in TDN‘s Ask HISA column, Lisa Lazarus was asked about the PPs with the vet records circulating online. Her answer: “Most importantly, the screenshots of PPs circulating online could not have come from the HISA portal because some of the information is different from what is in the HISA portal.”
No hedge. She said definitively that it didn’t come from HISA. And she suggested other entities might have been the source and that they should go and review their systems.
I asked HISA this week what that conclusion had been based on. A HISA spokesperson said the preliminary investigation had established that the leaked PPs “did not come from anyone with unauthorized access to the HISA Portal,” and that Gramm was an authorized user as the Responsible Person for multiple horses. The spokesperson added: “We now know that Mr. Gramm had altered the data that appeared in the PPs he created before sharing it with an associate.”
That is their explanation for why the information in those PPs didn’t match what was in the Portal. It does not explain the second statement, ten days later, that a review of six months of API calls had turned up no unusual Portal activity.
The Jockey Club, whose InCompass Track Manager platform was the other potential source, addressed the question five days later and with more caution:
“While it appears that some veterinarian’s list information was presented in a pair of past performances distributed by an unknown party, a portion of the included veterinarian’s information is not available via the Track Manager system, and it is unclear if Track Manager was used to access the information in this case.”
Unclear. That is what an institution says when it does not know. A week later the Jockey Club did make a definitive statement — that there had been no unauthorized access to or breach of Track Manager, following an IT review of its security controls, monitoring systems and user authentication. That claim has held up. HISA’s has not.
Ten days after the first column, in the same space, Lazarus said HISA’s technology team, led by CTO Steve Keech, had reviewed the results of HISA’s continuous automated monitoring and vulnerability scanning, conducted a comprehensive internal review of all portal systems, and gone through every API call over the previous six months. The conclusion? No unauthorized users had gained access, and there was no unusual Portal activity.
That review covered precisely the window in which HISA now says Gramm was downloading what Lazarus has described as millions of individual treatment records.
To their credit, they did keep looking, and Lazarus said on June 25 that the harder question — whether someone with authorized access had exceeded it — would take more time. That is the investigation that eventually landed on Gramm, with Arete, a cyber risk management company, brought in to confirm what HISA says it had already found.
But let’s pull back a second and review the full arc of HISA’s narrative.
In June, HISA scanned its own systems, reviewed its own monitoring, went through six months of API calls, and then told the industry in print that the information did not come from them. It suggested others must be the source. This proved wrong.
Two months later, the same organization is telling us — again with total confidence — that it knows exactly what Marshall Gramm did, how he did it, and what he was thinking while he did it. And we are asked to take that on faith, because they will not show anyone the report with the supposedly incriminating information.
As a horseplayer, I am a student of past performances. Based on HISA’s past performance in this matter, I need to see the proof before I accept their account.
Marshall Gramm collected available data and used it unfairly, that is not in dispute. But HISA’s assertion that he concealed his identity and bypassed their security has no basis other than HISA’s word. That distinction is what separates a data-handling violation from a more serious one that might deserve a lifetime ban. It is possible Arete found something that supports this hacking claim. Nobody outside HISA can know, because nobody outside HISA has seen the report.
Then there is what the portal actually allows, even now, after all of this controversy became public.
Amanda Simmons Luby is an attorney and bloodstock adviser who founded Welbourne Stud in Ocala. She chaired the largest equine law practice group in Florida, and has spent years publicly pressing racing on integrity — the New York Times quoted her on the Medina Spirit case in 2021. She has never met Marshall Gramm. “I have no dog in this fight,” she told me, “other than being a longtime advocate for transparency for the bettors.”
On Monday, in response to the Paulick Report‘s coverage, she logged into her own HISA portal account and posted what she found. She is the designated owner and responsible person for one horse, and that horse is not at Keeneland.
“You can either search by horse, specifically by the horse’s name, or you can search by location,” she said. “I did location, and it showed me a screenshot of Keeneland horses that were on either a vets list or the HISA list.”
None of them were hers. She could click through to a summary showing the ID number, the horse, the designated owner, the responsible person, the attending veterinarian, the regulatory veterinarian, the reason for listing, and how long the horse had been on the list — with HISA’s reason and the state’s reason in separate columns.
No hacking. She was using the interface as presented.
She was careful to state the limits of what she had accessed. “It does not provide the same detailed veterinarian records that I have available to me as the designated owner representative or the responsible person.” On her own horse’s page she can see Lasix, and the lidocaine used to localize a hind-limb issue. On other people’s horses she could not do that on August 17.
Here I need to correct something I got wrong in the original version of this piece.
I wrote that Luby had been able to see more than she should have. That isn’t right. HISA makes the epistaxis and unsoundness lists available to every registered Portal user, deliberately, and says so in the same June 15 Ask HISA column I quote elsewhere in this article. I missed it, and I should not have.
The reasoning is sound, and it is worth spelling out. Both lists carry compounding stand-down times. A horse placed on the epistaxis list is ineligible to race for 14 days the first time, 30 days on a second placement within 365 days, 180 days on a third, and is permanently barred on a fourth. Unsoundness works similarly: ineligible until released by a regulatory veterinarian, with a minimum of 14 days the first time, 45 on a second within a year, 75 on a third, and a lifetime bar on a fourth. If you are about to claim or buy a horse, you need to know whether it can run.
Which is to say HISA already accepts the principle that some veterinary information has to be visible to people with no connection to the horse, precisely because they are about to put money on the line. That is the argument for wider disclosure, made by HISA.
My confusion came from Monday’s call, where Lisa Lazarus, asked who could see what, described regulatory veterinarians as having essentially unlimited access and owners and trainers as having access to their own horses, and twice said you cannot see a horse’s records unless you are associated with it as a connection. She was talking about full treatment histories, which is what this case is about — though nothing in that Monday call indicated the open tier existed.
What remains is the line itself. Some veterinary information about horses you have no connection to is available to any registered user, because buyers need it. Treatment records are not, and horseplayers are on the wrong side of that line either way.
Luby is not the only one asking how this was possible. J. Kent Sweezey, the graded stakes-winning trainer who divides his string between Kentucky and Florida, put it this way on X:
“The entire point of HISA is to protect the integrity of racing and create a level playing field! If confidential vet records were accessible to someone who could wager, claim, and own horses, that mission has failed. This deserves a serious investigation and some serious answers.”
Note that his complaint runs in both directions, and that is exactly right. Somebody reached data nobody should have been able to reach. And the system that was supposed to prevent it didn’t.
Mike Repole went further. In a post that drew more than 450,000 views in its first day on X, the firebrand owner wrote: “If Marshall did something wrong, punish him. But don’t make the mistake of pretending this is just about Marshall. THIS IS ABOUT THE SYSTEM.” He wants HISA to disclose exactly what happened, how long it went on, who had access and whether anyone else reached the same information — the owner’s version of the questions horseplayers are asking.
Pat Cummings, executive director of Mike Repole’s National Thoroughbred Alliance, made the same point from the cost side: “Given the incredible costs of HISA to our industry, now more than $250 million dollars in four years, it is almost beyond comprehension that anyone could access this information as easily as Marshall may have done. Significant changes are needed.”
Brian Malloy, a horseplayer and owner, posted this week that when HISA launched, his vet showed him how he could look up the records of any horse in the portal, including horses not assigned to him. Malloy later got his own account. “It never occurred to me to use it to my advantage,” he wrote, “and I’m a player always looking for an edge.”
The report
HISA’s technical case rests on a forensic analysis by Arete, a firm supplied by HISA’s cyber insurance carrier. I asked Lazarus on Monday whether that report would be made available for review.
“We have not considered that at this point in time.”
HISA’s public case against Gramm rests on a document it has not shared. Lazarus opened Monday’s call by saying there is nothing more important to HISA, or to her personally, than trust. Trust goes hand in hand with transparency.
Presumably, the report will eventually come to light in the proceedings against Gramm. But there is no reason it cannot be released now, redacted. Proprietary material can be removed while leaving enough to demonstrate what HISA says it demonstrates. If the evidence of intent to covertly steal data is as clear as HISA says it is, showing it costs them nothing.
So how did Gramm access the data in the first place?
It appears that he realized he could look up other owners’ horses’ records by changing reference numbers and that he used a simple script he created to do so.
Lazarus rejected that account before anyone even asked about it. In her opening remarks Monday she called the idea that Gramm could change a number in a URL and reach another horse “patently false” and “not at all what happened,” describing it instead as an automated invisible browser downloading records at scale while employing methods to avoid detection.
Michael Novak, a software developer who has built stable management platforms for the racing industry, reviewed the script Gramm used. Novak has publicly criticized HISA’s handling of this matter and is an associate of mine, and readers should weigh his account accordingly — but his central observation is checkable by HISA, by Arete, and by the hearing panel, all of whom have the same code. Gramm’s username, Novak says, is hard-coded in plain text into the script he used.
That is not what concealment looks like. This matters immensely, because concealment is a major part of HISA’s claim against Gramm.
HISA says Gramm instructed his automated browser to download in batches of 500 to stay below the threshold that would trigger a security alert. Asked how Gramm would have known where that threshold sat, Lazarus said 500 is “fairly standard for websites” and that she would “have to ask our IT guy to be certain.” She also conceded, unprompted, that Gramm “has not conceded” this intent and that HISA “made that assumption based on the evidence that we collected.”
An assumption is not a finding. And there is an obvious alternate explanation. Anyone downloading a large data set batches the data, because that is how you fit records into memory and process them without your computer crashing. You pull a chunk, process it, clear the memory, pull the next one. It is what every person who has ever downloaded a large data set does.
HISA says it is confident Gramm acted alone, and that its investigation found no evidence anyone else ever did the same thing. But this is an organization whose monitoring did not catch the access while it was happening, and which told the industry in June that nothing unusual had occurred. Confidence about what else may have happened in that system rests on the same logs that missed this.
These doubts are also why the report should be published. HISA has already been publicly and confidently wrong once about where this data came from, creating doubts about their knowledge of their own system. Doubts that become questions about the integrity of the system. There is a meaningful difference between “someone defeated our defenses” and “our defenses weren’t there to begin with.” Likewise, Gramm should volunteer to turn over his technology for inspection. There are answers here — let’s see them.
The larger picture for horseplayers
A thought keeps gnawing at me, one that has nothing to do with Marshall Gramm as an individual.
If this veterinary information is so sensitive, so advantage-giving, that obtaining it warrants a lifetime ban and an FBI referral — why can’t the betting public see it in the first place?
Horseplayers fund this sport. Every purse, every salary, every regulator’s budget comes out of the money bettors put through the windows. Yet there is this tier of information about the horses we bet on that owners, trainers, and veterinarians can see and we cannot. That gap is what made this data worth studying.
Luby puts it more plainly. “When it comes to medical records, there’s no reason why the bettors, upon whom our entire industry depends, should not have access to the same veterinarian records that the owners are able to benefit from.”
She also names the obstacle, speaking as an equine attorney rather than a horseplayer with a grievance: at state level, veterinary records are by law the private property of the horse owner. HISA cannot simply publish them. That is a real legal hurdle.
But it is an argument for changing the rule, not for pretending the question doesn’t exist. Luby’s proposal is that the Jockey Club and HISA modify their rules collectively, so that agreeing to race at a HISA-sanctioned racetrack means waiving confidentiality over those records. You want to race for our money, we get to see the medical record.
Hong Kong, she says, “is a shining example of how racing jurisdictions and regulatory oversight can work hand in hand with transparency.” Its handle is the envy of the world, and that is not a coincidence. Transparency gives people confidence to bet more, not less. In America the same information is guarded closely enough to end a career over.
Lazarus was asked about transparency on Monday and said she is “certainly not averse to sharing more information” if that is where the industry lands. That’s a great impulse. Now let’s have a proposal and a timeline.
There is one more thing in the record that makes my teeth itch. That June 15 column — the same answer in which Lazarus said the information did not come from HISA — contains two other sentences worth putting side by side.
The first: through collaboration with technology companies like Palantir, HISA now has the opportunity to analyze its data and “glean learnings that we can then translate into public knowledge.”
The second: “As it pertains to gamblers, individual horse health data is not available for public consumption.”
The data is too sensitive to show the people who pay for the sport, and yet potentially valuable enough to sell.
What happens now
Two enforcement actions run in parallel: the fraud provision before a three-person arbitration panel, and Rule 2251, which governs veterinary records, before the Racetrack Safety Committee. Hearings are set for September 14 and 17.
Marshall Gramm did something stupid and wrong, and he has said so. He should face a real penalty for it. He was prepared to accept a four-year ban and financial restitution.
What he should not face is a lifetime ban, a federal referral, and the label of hacker, imposed by an organization that hasn’t been transparent about the integrity of its own system or its own monitoring of it. This should also be the start of a much larger conversation about access to health information about horses, and the larger unfairness of that knowledge not being available to the people whose money keeps the sport afloat.
Correction: An earlier version of this piece stated that the epistaxis and unsoundness list Amanda Simmons Luby accessed showed her more than she should have been able to see. That was wrong. HISA makes those lists available to all registered Portal users, a fact stated in the June 15 Ask HISA column referenced elsewhere in this article. That passage has been revised.
Update: The disclosure at the top of this piece has been expanded to note that I was not among the group Gramm shared those past performances with before they became public.
Note: Since this piece published, HISA has provided a fuller account of how it says Gramm obtained the records, reported by Chelsea Hackbarth at the Paulick Report. I will address it separately.






