HISA rejects Churchill Downs claims in FTC response
Lisa Lazarus has defended HISA’s handling of the Fair Hill betting case and a horse-health data vulnerability while promising an accelerated independent IT audit.
The spat continues to intensify between the Horseracing Integrity and Safety Authority and Churchill Downs Incorporated over HISA’s handling of wagering concerns, medication disclosures and unauthorised access to confidential information concerning horses’ health.
HISA chief executive Lisa Lazarus wrote to Federal Trade Commission chairman Andrew N. Ferguson and commissioner Mark R. Meador this week in response to an August 28 letter from CDI chief executive Bill Carstanjen.
Churchill had asked the FTC to initiate an independent examination of how HISA is governed, its information-security and disclosure practices, and its integrity controls.
Lazarus disputed any suggestion that HISA was responsible for answering questions about betting linked to the Fair Hill Five incident, in which five connected horses attracted substantial wagers before racing on August 9.
“HISA’s congressional mandate does not include the regulation of betting markets and HISA, therefore, has zero authority over wagering activity,” Lazarus said in her letter to the FTC.
She said HISA would disclose further findings that fell under its Racetrack Safety or Anti-Doping and Medication Control programs.
On the timing of an alleged banned-substance violation involving trainer Angel Quiroz, Lazarus said the Horseracing Integrity & Welfare Unit followed its established procedure. Public disclosure occurs after a B sample confirms the A sample or is waived, she said.
Churchill’s letter also questioned HISA’s technology controls after Marshall Gramm allegedly used authorised portal access to obtain confidential records for horses that had no legitimate connection to him. HISA has charged Gramm over the alleged access, while Gramm has said he did not bypass security protocols.
Lazarus said HISA had accepted responsibility for the vulnerability. It engaged an independent cybersecurity expert, notified law enforcement, began enforcement proceedings and updated its systems.
HISA has also accelerated an independent IT audit required under the FTC’s Oversight Rule. Lazarus said the audit would examine the vulnerability and its findings would be supplied to the commission.
“HISA welcomes and stands ready to answer any and all questions the Commission may have regarding the issues raised in Mr. Carstanjen’s letter,” she said.