OpenLoop Health Breach Exposes 716,000 Patient Records Across 120 Healthcare Organizations
A recently confirmed breach at OpenLoop Health compromised the personal and medical data of over 716,000 patients across 120 healthcare providers. The incident, stemming from a single unauthorized session lasting less than 24 hours, exposed names, addresses, dates of birth, and medical information tied to multiple telehealth and healthcare brands relying on OpenLoop’s infrastructure.
The breach underscores a growing vulnerability in healthcare security: patient data no longer resides solely within provider-owned systems but flows through third-party platforms, telehealth services, scheduling tools, and analytics systems. When shared infrastructure is compromised, a single breach can impact dozens of downstream organizations even those without direct system intrusions.
Most affected patients likely never interacted with OpenLoop directly, highlighting the risks of "invisible" healthcare infrastructure. Modern digital care relies on backend platforms that aggregate sensitive data from multiple providers, creating concentrated risk. While healthcare organizations invest in securing their own systems, compliance programs often overlook how patient data is stored, segmented, and accessed once it enters a vendor’s multi-tenant environment.
Multi-tenant platforms, where data from different organizations is aggregated into shared storage and analytics systems, frequently lack consistent classification and access controls. This can leave large volumes of protected health information (PHI) broadly accessible, increasing exposure during a breach. The challenge extends beyond whether vendors have security controls organizations must understand how those controls apply to their specific data.
To mitigate such risks, healthcare providers should prioritize continuous discovery and classification of PHI in shared environments, ensuring proper segmentation. Identity and access analysis is critical, as service accounts, APIs, and integrations can expand over time, leaving outdated permissions in place. Data lineage tracking where PHI originates, moves, and is stored also helps organizations quickly scope breaches and meet notification obligations.
The OpenLoop breach reveals gaps in third-party data governance. Healthcare organizations must now map where regulated data resides across vendors, verify how it is isolated in shared environments, and review internal aggregation points like data lakes and warehouses. Incident response plans must also account for third-party exposures, as legal and reputational consequences can extend beyond direct system compromises.
As healthcare data increasingly flows across interconnected platforms, security programs must evolve beyond internal systems. Continuous visibility into data location, access patterns, and vendor governance is essential to managing risk in an ecosystem where a single breach can have far-reaching consequences.
OpenLoop Health TPRM report: https://www.rankiteo.com/company/openloophealth
"id": "ope1785068638",
"linkid": "openloophealth",
"type": "Breach",
"date": "7/2026",
"severity": "100",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '120 healthcare organizations',
'industry': 'Healthcare/Telehealth',
'name': 'OpenLoop Health',
'type': 'Third-party healthcare platform'}],
'attack_vector': 'Unauthorized session',
'data_breach': {'number_of_records_exposed': '716,000',
'personally_identifiable_information': ['Names',
'Addresses',
'Dates of Birth'],
'sensitivity_of_data': 'High (PHI and PII)',
'type_of_data_compromised': ['Personal Identifiable '
'Information (PII)',
'Medical Information']},
'description': 'A recently confirmed breach at OpenLoop Health compromised '
'the personal and medical data of over 716,000 patients across '
'120 healthcare providers. The incident, stemming from a '
'single unauthorized session lasting less than 24 hours, '
'exposed names, addresses, dates of birth, and medical '
'information tied to multiple telehealth and healthcare brands '
'relying on OpenLoop’s infrastructure.',
'impact': {'brand_reputation_impact': 'High (affected multiple healthcare '
'brands)',
'data_compromised': '716,000 patient records',
'identity_theft_risk': 'High (PII and medical data exposed)',
'legal_liabilities': 'Potential (regulatory violations)',
'operational_impact': 'Exposure of sensitive patient data across '
'120 healthcare organizations',
'systems_affected': 'Third-party healthcare platform (OpenLoop '
'Health)'},
'lessons_learned': 'The breach highlights gaps in third-party data '
'governance, particularly in multi-tenant environments '
'where patient data is aggregated. Healthcare '
'organizations must map where regulated data resides '
'across vendors, verify isolation in shared environments, '
'and review internal aggregation points like data lakes '
'and warehouses. Incident response plans must account for '
'third-party exposures.',
'post_incident_analysis': {'corrective_actions': ['Implement stricter access '
'controls and segmentation '
'for PHI in shared '
'environments',
'Conduct regular audits of '
'service accounts, APIs, '
'and integrations',
'Improve data lineage '
'tracking and breach '
'scoping capabilities'],
'root_causes': 'Insufficient access controls and '
'segmentation in OpenLoop’s '
'multi-tenant environment, allowing '
'unauthorized access to aggregated '
'patient data.'},
'recommendations': ['Prioritize continuous discovery and classification of '
'PHI in shared environments',
'Ensure proper segmentation of sensitive data',
'Conduct identity and access analysis to remove outdated '
'permissions',
'Track data lineage to scope breaches and meet '
'notification obligations',
'Enhance visibility into data location, access patterns, '
'and vendor governance'],
'regulatory_compliance': {'regulations_violated': ['Potential HIPAA '
'violations']},
'response': {'enhanced_monitoring': 'Recommended (continuous visibility into '
'data location and access patterns)',
'network_segmentation': 'Recommended (prioritize PHI '
'segmentation in shared environments)'},
'title': 'OpenLoop Health Breach Exposes 716,000 Patient Records Across 120 '
'Healthcare Organizations',
'type': 'Data Breach',
'vulnerability_exploited': 'Insufficient access controls in multi-tenant '
'environment'}