All Breaches
June 1, 2025 Verified Sensitive Record Healthcare

Open Arms Care 2025 Data Breach

The Open Arms Care 2025 data breach involved an unauthorized party potentially accessing or acquiring messages in the organization's email environment between June and August 2025. Open Arms Care detected unusual activity involving an email account in August and opened an investigation with independent specialists.

The HHS Office for Civil Rights public record classifies the event as a Hacking/IT Incident involving Email and reports 893 affected people. Possible scope included names, SSNs, medical diagnosis or treatment information, health insurance information, and financial account information for a small number of people. No person-level raw records were imported into LeakData.

How Was the Open Arms Care Breach Confirmed?

The primary source is Open Arms Care Corporation's Data Privacy Notice dated June 9, 2026 on its own domain. It confirms the month-level email-access window, detection in August, the person-and-data review completed April 30, 2026, the data fields, the system boundary, and the organization's assistance line at 1-833-788-9712.

The second official source is the HHS Office for Civil Rights breach portal. Its row identifies the organization as a Tennessee Healthcare Provider, classifies the event as a Hacking/IT Incident involving Email, reports 893 people, and gives a June 11, 2026 submission date. ClaimDepot is a third source-linked cross-check; the organization notice controls where contact details differ.

What Happened Between June and August 2025?

The organization said it experienced unusual activity involving an email account in August 2025 and immediately opened an investigation. Work supported by independent specialists found that some messages in the email environment may have been accessed or acquired without authorization between June and August. No exact beginning or ending days were published.

The stored June 1 date therefore represents the earliest disclosed month; it does not claim that the event began on that exact day. Public sources do not disclose the initial-access method, account used, actor identity, malware, or a ransom demand. The organization specifically states that the event did not affect its other information systems.

What Information Was Involved?

Potential fields were names, Social security numbers, medical diagnosis or treatment information, and health insurance information. Financial account information may also have been present in the relevant email for a small number of people. Fields varied by person, and it should not be inferred that all 893 people had every data type involved.

The official notice does not list birth dates, addresses, driver's licenses, or other government identification in its incident-specific data list. General category labels on the ClaimDepot page do not replace the organization's direct statement. LeakData stores only the confirmed list and does not generalize the small financial-account subset to the entire population.

What Risks Follow From Email Access?

A name, SSN, diagnosis or treatment information, and insurance details in the same correspondence can create targeted phishing, impersonation, and medical-identity risks. A message should not be trusted merely because it knows a real health condition, insurance plan, or relationship with the organization; independently verify the request through an official channel.

The small number of people whose private notices include financial account information should closely monitor transactions, new payees, and contact-detail changes. People whose SSNs were involved can consider a credit freeze or fraud alert. The public notice does not publish a definitive finding about confirmed misuse, so each person's risk assessment should follow their own letter.

How Many People Were Affected and How Did the Organization Respond?

The verified affected-person count in the HHS record is 893. That figure is written to pwnCount and totalRecords; it does not represent 893 person records uploaded into LeakData, and importedRecordCount is zero. Open Arms Care finished determining the affected people and data on April 30, 2026 and sent notices June 9.

The organization said independent experts supported the investigation, it gathered current contact information, and it took steps intended to prevent a similar event. The incident was described as limited to information transmitted through email. A dedicated call center was established for questions, available weekdays from 8:00 a.m. to 8:00 p.m. Central.

What Should Affected People Do?

A notice recipient should first identify the data types listed in their own letter. If an SSN was involved, review credit reports, new accounts, and unexpected tax correspondence; if health or insurance data was involved, monitor explanation-of-benefits statements, medical bills, providers, and unfamiliar claims.

Do not provide a full SSN, account number, password, payment, or one-time code to a caller using the Open Arms Care name. The number confirmed in the organization's official notice is 1-833-788-9712; independently open the notice before calling. A different number included in an incoming message should not be assumed trustworthy.

893
Affected Accounts
5
Data Types
Low
Severity
Yes
Verification

Exposed Data Types

5
First and last names
Social security numbers
Medical diagnosis or treatment information
Health insurance information
Financial account information for a small number of people

Additional Information

Added DateJuly 27, 2026
Breach DateJune 1, 2025
Domainopenarmscare.org
SourceOfficial provider notice and HHS record confirming unauthorized email access or acquisition and 893 affected people
Last Content UpdateJuly 27, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information