Churchill Downs, Horsemen Urge FTC to Audit HISA Data Security
After a bettor accessed confidential horse health data, Churchill Downs and horsemen's groups want federal auditors to review HISA's IT systems.
This article was produced with AI assistance and edited by the ON360 newsroom.
Churchill Downs Inc. and a coalition of horsemen’s organizations have asked the U.S. Federal Trade Commission to order an independent security review of the Horseracing Integrity and Safety Authority, following revelations that a bettor improperly accessed confidential veterinary data through the authority’s online portal.
The requests, sent in separate letters last week, come days after handicapper Marshall Gramm accepted a provisional suspension from HISA over charges that he pulled health records on horses he did not own and used the information to inform purchases at claiming races. Gramm has agreed to return any purse money, horses claimed and contest winnings tied to the period in question, and to divest his remaining racehorses.
Churchill Downs cites “troubling gaps”
Churchill Downs CEO Bill Carstanjen wrote to FTC Chairman Andrew Ferguson and Commissioner Mark Meador, saying the Gramm case exposed weaknesses in HISA’s governance. “Recent events have highlighted troubling gaps and warning signs in HISA’s governance,” Carstanjen wrote, according to Gambling Insider.
Carstanjen’s letter also referenced the so-called “Fair Hill Five,” a group of horses trained by Angel Quiroz that raced last month at Monmouth Park and Saratoga after workouts at Maryland’s Fair Hill Training Center, each making its first start in months.
Horsemen question portal spending
Three days before Churchill Downs sent its letter, the National Horsemen’s Benevolent and Protective Association joined the North America Association of Racetrack Veterinarians and the U.S. Trotting Association in a separate appeal to Ferguson. The groups want HISA’s cybersecurity and financial records independently audited before its next budget is approved.
According to the NHBPA’s letter, HISA spent $10.7 million on IT systems in 2025, up 75 percent from the $6.1 million it budgeted in 2023. The NHBPA represents more than 30,000 owners and trainers, many of whom have horses registered in the HISA portal.
The letter asked how Gramm, using only his own login credentials, could repeatedly pull a large dataset of confidential veterinary information over roughly six weeks “without the HISA system detecting and stopping the activity.”
HISA has said Gramm used an automated process to retrieve records in batches, extracting a volume of data comparable to what an approved veterinarian would access. HISA CEO Lisa Lazarus initially denied that leaked past-performance charts circulating on social media in mid-June had come from the authority’s database.
A rocky relationship with regulators
The NHBPA has opposed HISA since its creation under the Horseracing Integrity and Safety Act, passed by Congress nearly six years ago to nationalize the sport’s rules under FTC oversight. Horsemen sued in federal court arguing the authority was unconstitutional, winning at the Fifth Circuit Court of Appeals in 2022 before the Sixth Circuit upheld the law. The U.S. Supreme Court sent the cases back for reconsideration, and the Fifth Circuit again sided with the NHBPA in June.
Churchill Downs, by contrast, has publicly backed HISA’s legislation. That did not prevent a dispute earlier this year, when HISA claimed the company owed more than $6 million in unpaid 2025 fees for tracks in Kentucky, Louisiana, Pennsylvania and Virginia. Churchill argued its bill should total less than $2.5 million.
HISA had threatened to block simulcasting of Churchill’s tracks, a step that risked cutting off wagering on the Kentucky Derby. The two sides settled the fee dispute in March, after Churchill took the matter to federal court.
Both letters now sit with the FTC. No timeline for a decision on an independent audit has been announced.