Horseracing's integrity regulator is now defending its own playbook, as the Horseracing Integrity and Safety Authority answers federal questions about how owner and handicapper Marshall Gramm accessed a massive trove of confidential veterinary data and what that means for bettors who depend on a level playing field.
HISA formally charged Gramm on Aug. 17 with violating its rule on access to veterinary treatment records and a separate provision that bans fraud and misrepresentation in connection with covered horses, after concluding he had obtained information on horses well beyond the 76 he owns. Investigative accounts describe Gramm discovering that he could change a horse identification number in a portal URL while logged in to his authorized account, then using automation tools, including artificial intelligence, to pull roughly four million records from a database that houses health information for about 100,000 horses. HISA's enforcement notice carried a provisional suspension and put a potential lifetime ban on the table, alleging that Gramm sought or attempted to seek a competitive edge in racing activities through access to the data.
The Gramm episode landed in Washington because Churchill Downs Inc. and several horsemen's groups argue it exposes deeper weaknesses in HISA's systems and oversight. Churchill Downs CEO Bill Carstanjen wrote to the Federal Trade Commission on Aug. 28, urging an independent review of HISA centered on unexpected betting outcomes linked to horses training at Fair Hill and on the handling of Gramm's access to confidential records through the portal. Days earlier, the U.S. Trotting Association, National Horsemen's Benevolent and Protective Association and North American Association of Racetrack Veterinarians jointly asked the FTC how an authorized user could repeatedly extract large quantities of protected veterinary data over roughly six weeks without triggering alarms, and pressed for a full audit of HISA's access controls and monitoring.
HISA's Sept. 9 response letter, signed by CEO Lisa Lazarus, attempts to turn that narrative around by stressing that the authority has “taken responsibility” for the vulnerability and moved quickly to contain it. In that letter, HISA outlines a sequence of steps: triggering its cyber insurance policy, hiring an independent cybersecurity firm to conduct a forensic review, identifying Gramm as the user who exploited the flaw, publicly disclosing the incident, notifying law enforcement, initiating formal enforcement proceedings against Gramm, and updating portal systems to close off the method he used. The authority also emphasizes that its investigation did not find evidence of an external hack by a non-authorized party, framing the incident as an abuse of legitimate credentials rather than a classic breach, even as it acknowledges the damage to stakeholder confidence. HISA has accelerated the timing of an independent IT audit mandated under FTC oversight and pledged to provide those results to the Commission, positioning the review as an opportunity to strengthen its technology and reassure participants.
While regulators circle, Gramm's reputation as a sharp player is also on the line. A Rhodes College professor of economics, prominent Thoroughbred owner and respected bettor, he has told reporters that he used only his authorized login and “bypassed no security protocols or other safeguards” to access the information, arguing that HISA's characterization overstates the sophistication of his methods. Gramm has acknowledged that he should have alerted HISA to the vulnerability sooner, a concession that has done little to blunt the authority's case or the optics of a well-known handicapper quietly building a private database with sensitive medical information. The Jockey Club, citing HISA's investigation, has moved to strip Gramm of his membership, underscoring how seriously traditional governance bodies view the incident even though their own systems were not compromised. Separate reporting notes that HISA's disciplinary process could still result in a lifetime ban, leaving Gramm's ownership and betting career in limbo while the FTC and racing regulators weigh next steps.
For everyday horseplayers, the controversy cuts to the heart of what constitutes a fair edge versus forbidden “inside information.” Confidential veterinary records can reveal surgeries, injections, lameness issues and chronic conditions that go far beyond the public clues found in past performances, layoff lines and workout reports, and access to that depth of data could meaningfully shape wagering and claiming strategies. Churchill's letter explicitly ties its concerns to potential impacts on betting markets, pointing to unusual winning streaks and asking whether privileged health information could have influenced decisions in ways the wider public could not match. At the same time, published accounts have not documented specific races where Gramm demonstrably used the data to move odds or claims, leaving regulators to argue on principle that unauthorized use of confidential records for potential wagering advantage crosses a bright line even absent proven market manipulation. For a sport that has long tolerated private workout intel and barn whispers, the scale and automation of this data grab mark new territory.
The Gramm case now doubles as a stress test of HISA itself, which was created to centralize safety and integrity rules and operates under FTC oversight. Horsemen's groups want the Commission to require independent cybersecurity and even financial audits before approving future HISA budgets, a sign that they see broader governance issues wrapped up in the portal incident. HISA, in its letter, counters that it has embraced “unprecedented” transparency by fielding press conferences, podcast interviews and detailed public statements about the investigation, and insists that the vulnerability exploited by Gramm has already been fixed. The FTC has not yet signaled what level of review it will demand, but whatever emerges—tighter access controls, more granular logging, rate limits on data queries, or explicit rules on using confidential information in handicapping—will shape how digital data fits into the handicapping toolbox going forward. For now, bettors can still rely on traditional past performances and official vet reporting, but the Gramm saga is a clear warning that in the era of big data and AI, racing's regulators and its sharpest players are going to keep testing the edges of what constitutes a fair bet.
