← Blog

OpenLoop Health Breach: 716K PHI in OCR Listing

Share on X

HHS’s Office for Civil Rights eventually put a number on the OpenLoop Health data breach that telehealth patients had been waiting weeks to see: up to 716,000 people had protected health information compromised after an unauthorized party copied files from OpenLoop’s network in early January 2026.

That OCR figure matters more than the forum chatter that briefly claimed a larger haul. OpenLoop Health Inc.—a telehealth platform provider that sits between virtual-care clinics and the patients they serve—told California regulators it discovered the intrusion on January 7, 2026. Forensics later said the window of network access ran from January 7 into January 8. Names, addresses, email addresses, dates of birth, and medical information left the building. Social Security numbers, OpenLoop said, did not.

If you booked care through an OpenLoop-powered provider, this is the incident you search when you type OpenLoop Health data breach or OpenLoop Health breach 2026. Here is what is confirmed, what is still just an actor claim, and what to do next.

What happened: a two-day window in January

According to the breach notice OpenLoop filed with the California Attorney General (listed as reported March 17, 2026), the company learned on January 7 that an unauthorized third party had gained access to some of its systems and copied files containing sensitive data. Outside cybersecurity specialists were brought in to map the scope, shut down access, and harden the environment.

The investigation’s core finding was narrow in time and broad in data type. Access lasted roughly January 7–8, 2026. The copied material included the kinds of fields telehealth platforms accumulate every day: identity markers plus clinical context. OpenLoop said it notified affected individuals by mail and offered complimentary credit monitoring and identity-theft protection.

That CA filing is why many catalogs first showed a stub row with zero records. State AG portals often publish the fact of a notice before HHS OCR posts the national headcount. The HIPAA Journal’s May 11, 2026 update closed that gap: the OCR breach portal listing for the incident shows PHI of up to 716,000 individuals compromised. BreachHistory now uses that regulator-attested count for the canonical OpenLoop Health breach record.

What data was exposed — and what OpenLoop says was not

Confirmed categories from the company notice and trade-press summaries include:

  • Full names
  • Physical addresses
  • Email addresses
  • Dates of birth
  • Medical information (PHI)

OpenLoop stated that Social Security numbers were not accessed or stolen. That distinction is useful for triage, not a free pass. Medical information plus name, DOB, and contact details still fuels targeted phishing, insurance fraud, and social-engineering attacks that pretend to be a clinic, pharmacy, or benefits desk. Attackers do not need an SSN to convince someone to “confirm” one on a fake portal.

Texas’s Attorney General office separately published an OpenLoop Health notice affecting 68,160 Texas residents (posted around March 18, 2026). State counts are slices of the national population, not a competing total—treat the OCR figure as the best overall size estimate unless OpenLoop publishes a different company-wide number.

The Stuckin2019 forum claim: 1.6 million is not the catalog number

Before OCR’s count surfaced, a threat actor using the moniker Stuckin2019 claimed responsibility on a hacking forum and advertised roughly 1.6 million patient records, including sample dumps. Databreaches.net and HIPAA Journal coverage treated that claim with the usual caveats: actor counts can be inflated, non-unique, or fabricated. In this case samples appeared briefly; the listing reportedly lasted only a couple of days before vanishing. Reporting also said the actor claimed to have been paid and to have deleted the data—none of which OpenLoop has publicly validated as a completed ransom negotiation.

BreachHistory does not treat the 1.6 million figure as confirmed. The catalog’s 716,000 records-affected value is the OCR listing. If you see headlines that still lead with 1.6 million without labeling the source as an unverified actor claim, they are mixing marketing with regulation.

How the attack worked (what we know)

Public notices describe unauthorized access and file copying—classic data theft—without publishing a detailed kill chain. There is no public company confirmation that this was ransomware encryption, a named ransomware brand, or a supply-chain compromise of a downstream EHR. The operational takeaway from OpenLoop’s own words is simpler: an outsider reached systems holding patient files and exfiltrated them over about two days before containment.

That pattern matches a large share of 2026 healthcare platform breaches: short dwell, bulk file theft, delayed notification while forensics and counsel decide who is “affected,” then dual-track reporting to state AGs and OCR. Platform vendors are especially painful for patients because the brand on the appointment reminder may not be the brand on the breach letter.

Who is at risk

Patients of OpenLoop-powered clinics

Anyone whose PHI sat in the copied files—patients who received telehealth or related services through OpenLoop’s platform—should assume their name, contact details, DOB, and medical information could be in criminal hands. Watch for:

  • Unexpected “OpenLoop,” clinic, or pharmacy emails or texts asking you to “verify” insurance, refill a prescription, or download records from a new portal
  • Calls from people who already know your DOB and recent appointment history
  • Mail that looks like a benefits update but points to a non-official domain

Clinics and partner practices

Covered entities that used OpenLoop as a business associate should expect BA-side incident paperwork, patient FAQ scripts, and questions from compliance officers about whether local systems also need review. A platform breach does not automatically mean every clinic EHR was hit—but patients will not parse that distinction when the phishing starts.

Employees and contractors

Public writeups emphasize patient PHI. If you worked at OpenLoop and later receive a separate workforce notice, treat that as additive, not a contradiction of the patient-focused OCR listing.

Industry context: telehealth platforms are high-value targets

Virtual-care infrastructure concentrates identity and clinical data across many practices. 2026 already produced large healthcare and benefits incidents elsewhere in the BreachHistory catalog—from EHR vendors such as CareCloud’s AWS EHR intrusion (≥350,000 notified) to mega-notifications at dental and device companies. OpenLoop sits in that same risk class: a single platform compromise can touch hundreds of thousands of patients who never typed “OpenLoop” into a Google search when they booked care.

Actors who specialize in telehealth have also appeared in reporting around this incident. Stuckin2019 was described as an individual with prior claims against other telehealth brands (including an alleged Zealthy incident that company had not publicly confirmed at the time of OpenLoop coverage). Whether or not every claim is real, the pattern is clear: telehealth databases are being shopped and extorted because medical context sells.

What OpenLoop and regulators said

OpenLoop’s California notice is the primary company disclosure path most researchers saw first: discovery on January 7, forensic confirmation of January 7–8 access, data categories listed above, hardening steps, mail notification, and credit monitoring. OCR’s later portal entry supplies the scale—up to 716,000 individuals with PHI compromised—after the March 17 reporting date to OCR noted in HIPAA Journal coverage.

There is no public, detailed OpenLoop statement validating the Stuckin2019 1.6 million claim or confirming a ransom payment. Silence on an actor’s sales pitch is not the same as a denial of the underlying intrusion; the company already acknowledged unauthorized access and file theft.

Regulators will keep this file alive the usual way: OCR breach portal visibility, possible complaints, and—years later—possible settlements if investigators allege HIPAA Security Rule failures. None of that changes what patients should do this week.

Was I affected by the OpenLoop Health breach?

You may be in scope if you received services through an OpenLoop-supported telehealth workflow and your information was among the copied files. Practical checks:

  1. Watch for a mailed notice from OpenLoop Health or a partner clinic naming this incident.
  2. Compare any notice’s breach window (January 7–8, 2026) and data types to what you shared.
  3. Texas residents can also cross-check state AG breach listings that cited tens of thousands of in-state residents.
  4. Do not rely on dark-web “am I in the dump?” search sites that recycle actor marketing.

If you never used an OpenLoop-connected provider, a random email claiming you must “unlock OpenLoop credit monitoring” is almost certainly phishing.

What you should do after the OpenLoop Health data breach

  1. Read the official notice carefully. Note enrollment deadlines for free credit monitoring and which bureau is offering it.
  2. Enroll in the offered monitoring if you are named. It will not stop every scam, but it flags new credit activity tied to your identity.
  3. Consider a credit freeze at Equifax, Experian, and TransUnion—especially if you see fraud attempts even though OpenLoop said SSNs were not taken. Freezes are free and block most new-account fraud.
  4. Treat medical phishing as hostile. Clinics rarely need you to click a fresh link to “re-verify” DOB and insurance after a breach. Call the number on your after-visit summary, not the number in a panic text.
  5. Monitor Explanation of Benefits (EOBs). Watch for claims for visits you did not attend or prescriptions you did not fill—classic medical-identity misuse.
  6. Update passwords on any patient portal that reused credentials you used elsewhere. Prefer a password manager and MFA where available.
  7. Document everything. Keep copies of notices, enrollment confirmations, and any fraud reports. Useful if you later dispute charges or file complaints.
  8. Employees of partner clinics: refresh phishing training with screenshots of fake OpenLoop/OCR-themed lures; help desks will get volume.

How this compares to other 2026 healthcare breaches

At 716,000, OpenLoop is smaller than the multi-million patient notifications tied to some payer and dental-platform incidents this year, but it is still a major telehealth-platform event—and larger than many hospital ransomware notices that never clear six figures of confirmed individuals. Unlike unverified leak-site marketing, this row is anchored in company notification plus an OCR headcount.

Related catalog context includes Medtronic’s multi-million patient notification wave and TriZetto Provider Solutions’ millions-scale portal compromise—different attack paths, same lesson: healthcare adjacency is enough to put ordinary patients in an OCR spreadsheet.

Canonical record and sources

BreachHistory’s indexed record is 2026 OpenLoop Health — OCR: up to 716,000 PHI. Primary references include the HIPAA Journal’s OCR update and March disclosure summary, the California AG breach list entry for OpenLoop Health, Inc., and the HHS OCR breach portal. Actor claims about 1.6 million records remain labeled unverified and are not used as the attested impact size.

If OpenLoop later publishes a different company-wide count or confirms additional data types, the catalog row should be updated—and patients should still keep the January 2026 window and PHI exposure in mind when deciding whether a cold outreach is legitimate.

For readers comparing platform risk more broadly, the CareCloud AWS EHR incident earlier in 2026 is another reminder that cloud-hosted clinical systems remain prime theft targets even when the brand patients remember is the clinic, not the software vendor.

Notification lag: why patients heard late

January intrusion, March California and Texas filings, May OCR portal visibility—that lag is frustrating and normal. HIPAA’s breach-notification clock generally runs from when the organization knows (or should know) of a breach, with mail notices following investigation of who is “affected.” Patients experience that as radio silence while forensics firms hash file lists and counsel debates whether a particular appointment row was in the stolen set.

For the OpenLoop Health breach 2026 timeline, the practical implication is that some people received letters weeks after forum actors already advertised samples. Do not treat dark-web chatter as your official status. Treat the mailed notice—and, secondarily, the OCR listing size—as the authoritative signal that your PHI may be involved.

Business associates and covered entities also use that window to align scripts: what to tell front-desk staff, how to answer “was my SSN stolen?” (OpenLoop’s answer: no), and how to avoid creating a second incident by emailing unencrypted spreadsheets of “possibly affected” patients to the wrong distribution list.

Credit monitoring vs. a freeze after a PHI breach

Complimentary monitoring is useful when you want alerts. A credit freeze is useful when you want to block new accounts. After an OpenLoop Health data breach notice, many people should do both: enroll in whatever product the letter offers, then freeze at the three nationwide bureaus. Freezes do not stop medical-claim fraud or phishing; they do make it harder to open a credit card in your name if an attacker later stitches your DOB and address to other leaked identifiers.

Because OpenLoop said Social Security numbers were not taken, some readers will skip freezes. That is a personal risk call. Name, address, DOB, and medical details still support synthetic-identity attempts and highly convincing pretexting. If you have children or elderly dependents whose data may have been in a family telehealth record, ask whether the notice covers them separately.

Phishing playbook attackers will use

Expect lures that reference:

  • “Your OpenLoop Health records are ready to download”
  • “OCR complaint response required—verify identity”
  • “Enroll in breach credit monitoring before the deadline expires”
  • “Update insurance for your January telehealth visit”

Legitimate enrollment usually starts from instructions printed in a physical letter or a domain you can verify by calling the clinic’s published number. Attackers know people search OpenLoop Health data breach after reading a headline; they buy lookalike domains and run ads. Bookmark the BreachHistory canonical page and the company’s official site rather than trusting the first sponsored result.

What employers and clinic IT teams should review

If your organization contracted OpenLoop as a telehealth layer, pull the business associate agreement, document when you received the incident notice, and confirm whether your local EHR or scheduling tools shared additional copies of the same PHI. Ask whether multi-factor authentication, session logging, and egress controls were in place on the vendor side for the January window—and what changed afterward. Vendor questionnaires that only ask “do you encrypt data at rest?” are not enough after a live exfiltration event.

Security teams should also hunt for secondary compromise: password reuse from patient-portal accounts, help-desk calls that reveal too much over the phone, and staff clicking “breach enrollment” attachments. The OpenLoop incident is a patient-data story first, but every large healthcare disclosure becomes an internal social-engineering story within days.

Looking ahead

OCR listings can be updated if counts change. Class-action filings often follow six-figure healthcare breaches whether or not SSNs were involved. None of that replaces the immediate work: read the notice, enroll or freeze as appropriate, and harden how you respond to medical-themed outreach. The OpenLoop Health breach is already large enough to attract opportunistic fraud; the only controllable part for most patients is how quickly they treat that risk as real.

Key takeaways

The OpenLoop Health data breach is a confirmed January 2026 intrusion with a regulator-posted ceiling of about 716,000 people. PHI left the network; SSNs, per the company, did not. Forum claims of 1.6 million are a separate, unverified storyline. If a notice arrives with your name on it, enroll in monitoring, consider freezes, and assume medical-themed phishing is coming. If no notice arrives and you have no OpenLoop-connected care history, ignore random “OpenLoop breach” links—they are usually the second wave of the attack, aimed at people who only read the headline.