Iowa company sued for large health-data cyberattack
A Des Moines-based company is currently facing legal action due to an alleged cyberattack that may have compromised the personal health information of 1.6 million individuals. OpenLoop Health, a digital-health infrastructure firm that collaborates with healthcare organizations to offer telehealth services, is the target of a potential class action lawsuit filed in the U.S. District Court for the Southern District of Iowa.
The lawsuit, spearheaded by plaintiff Kathy Morehart from Texas, asserts that Morehart and other potential class members entrusted OpenLoop to maintain the confidentiality of their private health data. According to the legal filing, on January 7, 2026, a cohort of cybercriminals referred to as “stuckin2019” declared that they had breached OpenLoop’s computer system, gaining access to a trove of highly sensitive and private information linked to over 1.6 million patients across the United States.
Furthermore, the lawsuit alleges that OpenLoop neglected to inform affected patients about the security breach, despite being aware of the susceptibility of healthcare companies to such attacks. Citing previous cyber incidents within the industry and FBI alerts dating back to 2014, the legal complaint states that OpenLoop’s data breach was a result of failures to adhere to the security protocols mandated by the Health Information Portability and Accountability Act (HIPAA) and industry standards.
In addition to seeking financial compensation for individuals impacted by the breach, the lawsuit aims to secure a court injunction that would protect against future breaches. The legal action also requests that OpenLoop cover the costs of lifetime credit monitoring and identity theft insurance for all class members, citing a study that found health data breaches can result in an average individual financial loss of $20,000 due to out-of-pocket expenses associated with healthcare coverage.
While credit card information may fetch a minimal price on the black market, protected health data can command a significantly higher sum, with records showing sales for as much as $363. The lawsuit emphasizes the heightened risk of fraud and identity theft, including medical identity theft, faced by the plaintiffs for years to come, necessitating vigilant monitoring of their accounts.
OpenLoop has yet to formally address the lawsuit, but Larry Trittschuh, the company’s chief information security officer, indicated that they had swiftly responded to the security incident and are working on notifying affected individuals. Trittschuh assured that no financial information or Social Security numbers were compromised during the breach, and emphasized OpenLoop’s commitment to safeguarding patient data and maintaining the security of their platforms and services.
Represented by attorneys J. Barton Goplerud and Brian O. Marty from Shindler, Anderson, Goplerud & Weese in West Des Moines, the plaintiffs are seeking accountability from OpenLoop for the data breach and are pursuing legal recourse to address the breach and protect individuals from future cyber threats.