CSIDB logo
Incident

OpenLoop Health

Incident posture

Attack window
Jan 2026
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-08-17 13:25

Linked entities

Victim
OpenLoop Health
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jan 2026
Discovered
Jan 2026
Disclosed
Mar 2026
Resolved
Pending

Summary

OpenLoop Health experienced a breach in which hackers accessed its systems and stole personal information including names, addresses, email addresses, birth dates, and medical data from approximately 716,000 individuals. The intrusion was discovered and promptly terminated, after which the company launched an investigation with external cybersecurity experts, enhanced its security controls, and worked with law enforcement. The company stated that no electronic health records, Social Security numbers, or financial account information were compromised, and that it had not observed any misuse of the stolen data while offering affected individuals one year of free identity and credit monitoring. A threat actor later claimed to have taken data from 1.6 million people, and the firm, based in Des Moines, Iowa, provides white‑label digital health infrastructure for virtual care services.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

0 techniques

Description

On January 7, 2026, OpenLoop Health discovered an intrusion into its systems that allowed unauthorized access between January 7 and January 8 of the same year. During this window, attackers exfiltrated personal information belonging to 716,000 individuals, including names, addresses, email addresses, birth dates, and medical data. The company confirmed that the breach did not involve electronic health records, Social Security numbers, or financial account information. OpenLoop Health initially reported the incident to the appropriate authorities in March 2026, but the specific count of affected individuals was only added to the U.S. Department of Health and Human Services’ breach portal in early January 2026, coinciding with the article’s publication date. Notification letters were subsequently filed with the Attorney General’s Offices in California and Texas to inform the impacted individuals.

Upon discovery, OpenLoop Health immediately terminated the unauthorized access and engaged external cybersecurity specialists to conduct a thorough investigation of the incident. As part of its response, the company implemented enhanced security controls to prevent future intrusions and coordinated closely with law enforcement agencies. OpenLoop Health stated that it had no evidence of misuse of the stolen personal information at the time of notification. The company advised affected individuals to remain vigilant for signs of fraud or identity theft and offered them one year of free identity and credit monitoring services. These actions were communicated directly in the notification letters sent to the residents of California and Texas.

A threat actor later claimed responsibility for the attack, asserting that they had obtained data from approximately 1.6 million individuals, a figure that exceeds the number confirmed by OpenLoop Health. The company is headquartered in Des Moines, Iowa, and operates as a provider of white‑label digital health infrastructure for healthcare and consumer organizations seeking to deliver virtual care services. The breach impacted 716,000 people, and the updated figure was reflected in the HHS breach portal after the initial disclosure to authorities. No further details about the attacker’s identity or methods were provided in the available sources.

Sources

Sources available to members: 1 source.

CSIDB