OpenLoop Health
Incident posture
Linked entities
- Victim
- OpenLoop Health
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
OpenLoop Health experienced a breach in which hackers accessed its systems and stole personal information including names, addresses, email addresses, birth dates, and medical data from approximately 716,000 individuals. The intrusion was discovered and promptly terminated, after which the company launched an investigation with external cybersecurity experts, enhanced its security controls, and worked with law enforcement. The company stated that no electronic health records, Social Security numbers, or financial account information were compromised, and that it had not observed any misuse of the stolen data while offering affected individuals one year of free identity and credit monitoring. A threat actor later claimed to have taken data from 1.6 million people, and the firm, based in Des Moines, Iowa, provides white‑label digital health infrastructure for virtual care services.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On January 7, 2026, OpenLoop Health discovered an intrusion into its systems that allowed unauthorized access between January 7 and January 8 of the same year. During this window, attackers exfiltrated personal information belonging to 716,000 individuals, including names, addresses, email addresses, birth dates, and medical data. The company confirmed that the breach did not involve electronic health records, Social Security numbers, or financial account information. OpenLoop Health initially reported the incident to the appropriate authorities in March 2026, but the specific count of affected individuals was only added to the U.S. Department of Health and Human Services’ breach portal in early January 2026, coinciding with the article’s publication date. Notification letters were subsequently filed with the Attorney General’s Offices in California and Texas to inform the impacted individuals.
Upon discovery, OpenLoop Health immediately terminated the unauthorized access and engaged external cybersecurity specialists to conduct a thorough investigation of the incident. As part of its response, the company implemented enhanced security controls to prevent future intrusions and coordinated closely with law enforcement agencies. OpenLoop Health stated that it had no evidence of misuse of the stolen personal information at the time of notification. The company advised affected individuals to remain vigilant for signs of fraud or identity theft and offered them one year of free identity and credit monitoring services. These actions were communicated directly in the notification letters sent to the residents of California and Texas.
A threat actor later claimed responsibility for the attack, asserting that they had obtained data from approximately 1.6 million individuals, a figure that exceeds the number confirmed by OpenLoop Health. The company is headquartered in Des Moines, Iowa, and operates as a provider of white‑label digital health infrastructure for healthcare and consumer organizations seeking to deliver virtual care services. The breach impacted 716,000 people, and the updated figure was reflected in the HHS breach portal after the initial disclosure to authorities. No further details about the attacker’s identity or methods were provided in the available sources.
Sources
Sources available to members: 1 source.