HackingData ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICLowContained
OpenLoop Health Inc.
bd_1854e89c1f8039ce · schema v1 · pii pii-v1
Full breach record for OpenLoop Health Inc. →OpenLoop Health, Inc. disclosed that an unauthorized third party gained access to its systems from January 7-8, 2026, and removed certain personal information. The incident did not involve electronic health records, Social Security numbers, or financial account information. OpenLoop terminated the access, coordinated with federal law enforcement, and is offering one year of identity monitoring to affected individuals.
California clockDiscovered Jan 7, 2026 → Notified Mar 17, 202669d ✗ CA 30-day late10 weeks discovery → filing
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_f690d1be3282f569HHS OCRfiled 2026-03-17Verified
- bd_7782d804f57f84a0Texas State AGfiled 2026-03-18(1d gap)Verified
- bd_7b5ec9ff3e604672Washington State AGfiled 2026-03-27(10d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-620380
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 17, 2026
- Raw hash
- e03d05116d16266b97c4de5b6e9f7e8bb576a6d37ab73fd5f5361cb7d95e4e6c
Reporting entity
- Name
- OpenLoop Health Inc.norm: openloop health
Victim entity
- Name
- OpenLoop Health Inc.norm: openloop health
Incident
- Discovered
- Jan 7, 2026
- Materiality determined
- —
- Notification sent
- Mar 17, 2026
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Coordinated with federal law enforcement regarding the incident
Compliance
- Time to disclose
- 10 weeks(69 days from discovery to filing)
- Compliance flags
- CA 30-day late · 69dCA AG copy ≤15d · 0d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jan 7, 2026→ Notified: Mar 17, 202669d 30 calendar days CA 30-day late California Consumers notified: Mar 17, 2026→ AG copy submitted: Mar 17, 20260d 15 calendar days CA AG copy ≤15d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.