Summary

Telehealth platform OpenLoop Health has disclosed that a January 2026 intrusion resulted in the theft of personal information belonging to 716,000 individuals. Details of the breach emerged publicly on May 13, 2026, months after the initial compromise.

The compromised data includes names, addresses, email addresses, birth dates, and medical data. OpenLoop confirmed that electronic health records, Social Security numbers, and financial account information were not accessed. However, the combination of medical data with personal identifiers still presents significant risks for identity theft and insurance fraud targeting affected patients.

The breach is the latest in a string of healthcare data incidents that have plagued the telehealth sector as rapid pandemic-era expansion created sprawling attack surfaces that many providers are still struggling to secure.

Sources

Commentary

The four-month gap between the January intrusion and public disclosure is concerning but not unusual in healthcare. HIPAA breach notification rules allow up to 60 days, and investigations routinely stretch timelines further. Still, 716,000 patients went months without knowing their medical data was in criminal hands.

Telehealth platforms expanded rapidly during and after COVID, and security often took a back seat to growth. OpenLoop isn’t the first and won’t be the last — healthcare data remains one of the most valuable targets on the dark web, and the sector continues to be an easy mark.

By Allan