The OpenLoop Health 2026 data breach involved an unauthorized third party accessing some systems of the telehealth infrastructure provider on January 7, 2026 and copying files. A forensic review determined that the access continued through January 8. The breach record maintained by the US Department of Health and Human Services Office for Civil Rights shows that 716,000 people were affected.
OpenLoop Health supplies virtual-care technology and support services to healthcare organizations. The affected information therefore concerned patient data processed for customers rather than only the company's own workforce records. Contents varied by person; LeakData imports no personal records and importedRecordCount is zero.
How Was the Data Theft Confirmed?
The organization learned on January 7, 2026 that an unauthorized party had accessed certain systems and began incident response. An investigation conducted with cybersecurity specialists confirmed that the third party was present on January 7 and 8 and copied particular files during that period. That finding makes this organization-confirmed acquisition, not merely a possibility that information was viewed.
HHS OCR lists the event as a Hacking/IT Incident, the information location as Network Server, and OpenLoop as a Business Associate. HIPAA Journal compared the California notice with the federal record and reported the access window, copied files, and scope of 716,000 people. The sources do not confirm an initial-access technique or attribute the attack to a named ransomware group.
What Was the Incident and Notification Timeline?
The breachDate field uses January 7, 2026, the start of the confirmed access period. Unauthorized activity ended on January 8; after learning of the event, the organization secured its systems and reviewed content to identify which files had been copied. The discovery, end-of-access, and notice dates are kept distinct from the start date.
OpenLoop later notified affected individuals, and the event was submitted to the federal HHS portal on March 17, 2026. The news record updated in May corroborated the federal total of 716,000 people. A short access window does not eliminate the risk: confirmation that files were copied means information left the affected systems.
What Personal and Health Information Was Affected?
The disclosed personal fields were names, physical addresses, email addresses, and dates of birth. Medical information was also present in the copied files; the organization's notice did not enumerate narrower fields such as diagnoses, treatments, or prescriptions. LeakData therefore lists only the high-level data classes expressly confirmed by the sources and adds no inferred categories.
Contents were not identical for every person, and the disclosure did not say that every category was present for all victims. Social Security numbers were specifically reported as not accessed or stolen, so that field is excluded from dataClasses. Payment cards, bank accounts, passwords, and biometric information were also not disclosed as confirmed parts of the event and are not added.
Why Does This Record Use 716,000 People?
pwnCount and totalRecords use the 716,000-person regulatory total in the current HHS OCR public record. This is the scope the organization reported to the federal authority under its HIPAA notification obligations. LeakData does not round the figure, recalculate it from a news headline, or create assumed subtotals for different customer groups.
A threat actor using the name Stuckin2019 claimed to have obtained data concerning 1.6 million patients and said samples had been published. OpenLoop did not confirm that larger number, while the reliable official record shows 716,000 people. The actor's allegation is therefore not added to the total, and the two values are not combined.
Why Does the Incident Matter to Telehealth Networks?
A breach at a business associate can reach a broader care network than an incident at one direct provider. Identity fields such as addresses and birth dates combined with medical information can make phishing, false billing, or social-engineering attempts impersonating healthcare organizations more convincing. The sources, however, do not state that misuse has been detected.
OpenLoop's platform role means the record is maintained under the company's identity; unconfirmed separate breach entries are not created for each customer. The Business Associate classification in the HHS row supports this vendor relationship. This entry represents only the 716,000 people confirmed under the same January access window and federal report.
What Should Affected People Do?
OpenLoop offered affected people complimentary credit monitoring and identity-theft protection. Notice recipients should review the scope stated in their letter, monitor credit reports and health-insurance explanations, and report unfamiliar services or claims to the relevant organization. Although Social Security numbers were reported as unaffected, unexpected healthcare-themed communications still deserve caution.
Messages using a person's name, address, email address, and birth date may appear to come from a real healthcare provider. People should use known official channels rather than embedded links and independently verify unexpected payment or password requests. LeakData does not host stolen files; this page documents the verified event scope, sources, and practical follow-up steps.