HISA Charges Marshall Gramm with Multiple Rule Violations, Including Fraud, Over Unauthorized Access to Confidential Horse Health Information

August 17, 2026Press Releases
Horseracing Integrity and Safety authority

August 17, 2026 (Lexington, KY) – Following a comprehensive review that involved internal and third-party expert investigators, the Horseracing Integrity and Safety Authority (HISA) has levied charges against Covered Person Marshall Gramm for multiple violations of HISA rules arising from unauthorized access of confidential horse health information.

In June of this year, past performance data reports (PPs) for the horses Deterministic and Griffin’s Wharf, which included confidential horse health data that should only be accessible to the horses’ connections and Regulatory Veterinarians, were posted on social media by someone unconnected to those horses. Consequently, HISA launched a comprehensive internal investigation into the matter.

HISA’s preliminary investigation concluded that there had not been any system breach by a person or entity who did not have prior authorization to access the HISA Portal. Nonetheless, HISA extended its initial investigation to search for any vulnerabilities in its technology systems that may have allowed someone with authorized access to the HISA Portal to view and share confidential horse health information. HISA committed to reporting the findings of its extended investigation at its conclusion.

That investigation included robust information sourcing and interviews conducted by HISA employees and contractors, as well as an independent third-party forensic cyber security analysis conducted by Arete, a leading expert in the field. The results unanimously pointed to Marshall Gramm being solely responsible for accessing confidential horse health information and creating PPs for horses to which he had no legitimate connection.

The investigations concluded that Mr. Gramm deliberately and methodically misappropriated confidential horse health information from the HISA Portal during a 6-week window beginning in early May and concluding in mid-June. Based on information gathered through the investigations, Mr. Gramm developed an automated method of obtaining the confidential horse health information at scale in a manner designed to mimic authorized activity to avoid detection by HISA’s security systems. Mr. Gramm used the resulting information to create the PPs that were shared on social media. Additionally, during this 6-week window, Mr. Gramm participated in handicapping contests, engaged in pari-mutuel wagering and claimed several Covered Horses across multiple jurisdictions and racetracks. HISA will be seeking restitution of any and all proceeds derived from such activities conducted during the relevant time period for the affected entities and individuals.

When confronted with the findings of these investigations, Mr. Gramm admitted that he is the source of the PPs for Deterministic and Griffin’s Wharf. The harm that Mr. Gramm has caused to the Thoroughbred racing community is significant. HISA has initiated enforcement actions against Mr. Gramm for HISA rule violations relating to fraud and unauthorized access of horse health records. In addition to these internal actions, HISA will evaluate and pursue, as necessary, all available remedies and claims arising from the harm caused to horse owners, trainers and veterinarians who rely on the confidentiality of the HISA Portal, Mr. Gramm’s fellow contest participants and the wagering public. HISA will also be sharing the information it has collected from its investigations with federal and local law enforcement, state racing commissions and all other relevant authorities so they may consider any appropriate actions that are outside HISA’s remit.

“There must be significant consequences for individuals who violate the integrity of our rules and obtain and abuse confidential horse health information,” said HISA CEO Lisa Lazarus. “HISA will take every necessary step to fiercely protect the integrity of Thoroughbred racing and ensure that violators of our rules are punished appropriately.”

HISA has made changes to its technology systems to prevent any similar unauthorized access going forward. HISA is also devoting additional time and resources to ensuring that its systems are well-prepared to stop any attempts to use new tools and technologies to obtain confidential information.