LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › OpenLoop Health Breach Impacts 716K Telehealth Users

CRITICAL severityReportedHow we verify

OpenLoop Health Breach Impacts 716K Telehealth Users: What Was Reportedly Exposed & What To Do

RBRecent Breaches Breach Intelligence·May 13, 2026
OpenLoop Health Breach Impacts 716K Telehealth Users

Reported May 13, 2026. Approximately 716K people affected.

CRITICAL
Severity
716K
People affected
5
Data types exposed
May 13, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

OpenLoop Health disclosed on May 13, 2026 that personal information of 716,000 telehealth users may have been exposed, including names, addresses, email addresses, birth dates, and medical data. Individuals should check whether their information was affected and take steps to protect their accounts.

Severity & verification
CRITICAL severityReported
Exposes government-ID/medical data.
Based on public reporting. Not independently confirmed by the named organization.
Check your exposure
716K accounts were exposed here. We can’t confirm any single incident against the sources we search — but we can show you every leak and listing tied to your email. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Approximately 716,000 people who used the OpenLoop Health telehealth platform have been notified that their personal and medical information was accessed during an intrusion in January 2026. The incident was added to the HHS breach portal on May 13, 2026, and affected individuals were offered credit monitoring.

Breaking down the breach

OpenLoop Health disclosed that unauthorized actors gained access to its systems for roughly two days in January 2026 and removed personal and medical information. The company reported that no Social Security numbers, financial data, or complete electronic health records were taken. The breach notification was posted to the HHS portal this week and covers 716,000 individuals.

How a breach like this happens

Incidents involving unauthorized access to systems for a limited period often begin with an attacker obtaining valid credentials or exploiting a remote access vulnerability. Once inside, the actor may move laterally to locate and copy files containing user records before the activity is detected and contained. In the health sector, such events frequently involve the exfiltration of contact details and clinical information rather than payment card data.

About OpenLoop Health

OpenLoop Health operates a telehealth platform that connects patients with medical providers. Organizations in this sector routinely process names, contact information, dates of birth, and clinical details to facilitate remote consultations and prescriptions. A compromise at such a service can affect individuals who have shared sensitive health information under the expectation of privacy protections required by regulation.

What was likely exposed

The company has stated that the following categories of information were accessed and removed:

What's at stake

Individuals whose records were taken may face increased risk of targeted phishing or unwanted contact using their verified health-related details. For the organization, the event triggers regulatory reporting obligations and may result in costs associated with notification and offered monitoring services. No further details on the method of access or the duration of undetected presence have been released.

What to do if you're exposed

People who received a notification from OpenLoop Health or believe their information may be involved should review the credit monitoring offered and remain alert for unusual account activity. They can also run a free exposure scan of their email address against known breach data to check for additional appearances of their information.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

CompanyOpenLoop Health security record
68/100
DoxxScan™ · Moderate doxx risk
C- 63Below-average record

1 reported incident on record.

See OpenLoop Health’s full breach history →

More recent breaches

Aflac Japan Discloses Breach Impacting 4.38M CustomersJune 30, 2026DentaQuest Data Breach (2026)May 23, 2026Medtronic Notifies 3.8M+ on ShinyHunters BreachApril 24, 2026Praxis EMR Listed by Insomnia Ransomware GroupOctober 5, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the OpenLoop Health Breach Impacts 716K Telehealth Users →

Source: SecurityWeek

Based on public reporting

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram