Open Arms Care Discloses 2015 Data Breach After 11-Year Investigation
Open Arms Care Corp. recently revealed a data security incident involving unauthorized access to its email accounts, which occurred between June and August 2015. The company detected unusual activity in its email systems in August 2015 and launched an investigation with independent cybersecurity experts to assess the breach’s scope.
The investigation concluded that sensitive personal data including names, Social Security numbers, medical diagnoses, treatment details, and health insurance information may have been accessed or acquired without authorization. In some cases, financial account information was also exposed. The breach was confined to email accounts and did not affect other company systems.
After an extensive review, Open Arms Care completed its assessment of affected individuals on April 30, 2026, nearly 11 years after the initial detection. The company then gathered updated contact information to notify those impacted. A data privacy notice was posted on its website on June 6, 2026, followed by the mailing of notification letters on June 9, 2026.
In its response, Open Arms Care apologized for the incident and outlined steps for affected individuals to protect their personal information, including placing fraud alerts, requesting credit reports, and reporting suspicious activity. The company also established a toll-free call center (1-833-718-9788) for inquiries, available Monday through Friday, 8 a.m. to 8 p.m. Central Time.
Open Arms Care stated it is implementing measures to prevent future breaches and reminded affected individuals of their rights under the Fair Credit Reporting Act, including the ability to dispute inaccurate credit file information.
Source: https://www.claimdepot.com/data-breach/open-arms-care-2026
Open Arms Care cybersecurity rating report: https://www.rankiteo.com/company/open-arms-care
"id": "OPE1781223902",
"linkid": "open-arms-care",
"type": "Breach",
"date": "6/2015",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Healthcare',
'name': 'Open Arms Care Corp.',
'type': 'Healthcare Provider'}],
'attack_vector': 'Unauthorized email account access',
'customer_advisories': 'Steps to protect personal information, including '
'placing fraud alerts, requesting credit reports, and '
'reporting suspicious activity. Toll-free call center '
'established for inquiries.',
'data_breach': {'personally_identifiable_information': 'Yes',
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Names',
'Social Security numbers',
'Medical diagnoses',
'Treatment details',
'Health insurance information',
'Financial account information']},
'date_detected': '2015-08-01',
'date_publicly_disclosed': '2026-06-06',
'date_resolved': '2026-06-09',
'description': 'Open Arms Care Corp. disclosed a data security incident '
'involving unauthorized access to its email accounts between '
'June and August 2015. Sensitive personal data, including '
'names, Social Security numbers, medical diagnoses, treatment '
'details, health insurance information, and in some cases '
'financial account information, may have been accessed or '
'acquired without authorization.',
'impact': {'data_compromised': 'Sensitive personal data, including names, '
'Social Security numbers, medical diagnoses, '
'treatment details, health insurance '
'information, and financial account '
'information',
'identity_theft_risk': 'High',
'payment_information_risk': 'High',
'systems_affected': 'Email accounts'},
'investigation_status': 'Completed',
'post_incident_analysis': {'corrective_actions': 'Measures to prevent future '
'breaches'},
'recommendations': 'Affected individuals advised to place fraud alerts, '
'request credit reports, and report suspicious activity',
'references': [{'date_accessed': '2026-06-06',
'source': 'Open Arms Care Data Privacy Notice'}],
'regulatory_compliance': {'regulations_violated': ['Fair Credit Reporting '
'Act']},
'response': {'communication_strategy': 'Data privacy notice posted on '
'website, notification letters mailed '
'to affected individuals, toll-free '
'call center established',
'incident_response_plan_activated': 'Yes',
'remediation_measures': 'Implementation of measures to prevent '
'future breaches',
'third_party_assistance': 'Independent cybersecurity experts'},
'title': 'Open Arms Care 2015 Data Breach',
'type': 'Data Breach'}