Skip to main content
Waystar10-Q: Cybersecurity incident

Waystar suffered a data breach in June 2026, exposing source code and client PHI/PII.

What happened

Unauthorized actors acquired source code and inactive data files containing Protected Health Information (PHI) and Personally Identifiable Information (PII) for under 1% of clients.

Source

SEC EDGARJul 29, 2026

Quarterly report (Form 10-Q)

Waystar 10-Q

Filing excerpt

For example, in early June 2026, we identified the unauthorized acquisition of point-in-time copies of source code, primarily used for testing purposes, from a cloud-based repository hosted by a third-party provider and the unauthorized acquisition of four files of inactive data from a single application, which had been written to cloud-based storage pending its scheduled destruction.

sec.gov/Archives/edgar/data/1990354/000199035426000035/way-20260630.htmRead the full source

Other signals in this filing (6)

Extracted by Autobound

From the Signal API record
Signal
10-Q: Cybersecurity incident

What this signalsFilings often name leadership changes, deals and spending plans.

Fiscal year end
06/30
Filed
Jul 29, 2026

More 10-Q signals at other companies

The full record

From the Signal API record

Numbers

Percent
1% (Maximum percentage of clients whose PHI/PII was included in the breached data.)

Details

CIK
1990354
Accession number
0001990354-26-000035
Timeframe
Current quarter
Filing year
2026
Fiscal year
0
Why it matters
Urgent security needs
Signal category
Technology

Topics and mentions

Technologies

  • cloud

Extraction

Confidence
High
Relevance
100%
Sentiment
Negative
Detected
Aug 4, 2026
signal_type
sec-10q
signal_subtype
cybersecurityIncident

Use this data

Get every 10-Q signal for Waystar and the companies you sell to, in the tools you already use.

  1. Ask Claude about it

    Connect Autobound to Claude, Claude Code or Cursor with MCP. Then ask: “What changed at Waystar this week?”

  2. Send it to your own tools

    The Signal API returns 10-Q signals for any list of companies as JSON, for your CRM, warehouse or app.

  3. Try it free

    Sign up and spend your free credits on the companies you sell to.

    Start Free1,000 free credits

The API returns more than this page shows

This page shows a preview. The full sec-10q record in the Signal API and MCP can also have these 8 fields. Some fields are empty for some signals.

Company

  • linkedin_urlValue in the API
  • industriesValue in the API
  • employee_count_lowValue in the API
  • employee_count_highValue in the API
  • revenueValue in the API
  • descriptionValue in the API

Signal

  • signal_nameValue in the API
  • associationValue in the API
Show the full JSONThe record on this page and the API request

GET /v1/signals/f70d0823-8d19-42fd-9eb4-87e040c54b70 returns this record as JSON. POST /v1/companies/enrich returns every signal for waystar.com.

{
  "signal_id": "f70d0823-8d19-42fd-9eb4-87e040c54b70",
  "signal_type": "sec-10q",
  "signal_subtype": "cybersecurityIncident",
  "detected_at": "2026-08-04T07:03:41.072+00:00",
  "company": {
    "name": "Waystar",
    "domain": "waystar.com"
  },
  "data": {
    "detail": "Unauthorized actors acquired source code and inactive data files containing Protected Health Information (PHI) and Personally Identifiable Information (PII) for under 1% of clients. This incident creates urgent needs for remediation, client communication, and security posture review, despite the company's belief it will not have a material financial impact.",
    "metrics": {
      "pct": 0.01,
      "timeframe": "current_quarter",
      "pct_context": "Maximum percentage of clients whose PHI/PII was included in the breached data."
    },
    "summary": "Waystar suffered a data breach in June 2026, exposing source code and client PHI/PII.",
    "excerpts": "For example, in early June 2026, we identified the unauthorized acquisition of point-in-time copies of source code, primarily used for testing purposes, from a cloud-based repository hosted by a third-party provider and the unauthorized acquisition of four files of inactive data from a single application, which had been written to cloud-based storage pending its scheduled destruction.",
    "relevance": 1,
    "sentiment": "negative",
    "confidence": "high",
    "source_url": "https://www.sec.gov/Archives/edgar/data/1990354/000199035426000035/way-20260630.htm",
    "filing_date": "2026-07-29",
    "filing_year": 2026,
    "fiscal_year": 0,
    "fiscal_year_end": "06/30",
    "sales_relevance": "Urgent security needs",
    "signal_category": "technology",
    "technologies_mentioned": [
      "cloud"
    ]
  }
}

Long text fields are shortened on this page.

Looking up one signal by its id is free. Enrich costs 2 credits per signal returned; a call with no results is free.