Skip to content
The Cyber Security Place

716,000 people, 120 brands, and a company none of them chose

Event dated 7 January 2026 · Published 2 September 2026 · 4 sources

A telehealth platform was accessed on 7 and 8 January 2026 and files containing patient data were copied. The confirmed total is 716,000 individuals, filed to the federal breach portal. The person claiming the intrusion said on 8 January that they held 1.6 million records including phone numbers, IP addresses and prescription data — a figure never verified and never reconciled with the official one. What makes the case worth reading is the shape rather than the size: the platform sits behind roughly 120 consumer brands, so the people exposed had a relationship with a company whose name they knew, and none with the company that held their records.

Supply chain risk is normally described from the buyer's chair. You choose a supplier, you assess them, you accept what you cannot verify, and you carry the consequences of that choice. The vocabulary — due diligence, vendor assessment, fourth-party risk — assumes somebody did the choosing.

This case is the same structure seen from the other end, where nobody chose anything. A patient signs up with a telehealth brand they have heard of. That brand runs on a platform they have not. Their prescription history sits in the platform's systems, under the platform's controls, subject to the platform's retention. The relationship they consented to and the relationship that holds their data are different relationships, and only one of them was visible at sign-up.

Why aggregation concentrates the consequence

A hundred and twenty brands each holding their own records would mean a hundred and twenty separate intrusions to reach the same number of people, each needing its own access, each offering its own chance of being noticed. One platform serving all of them collapses that into a single target where two days of access reached the lot.

That is not an argument against shared platforms, which exist because a small brand running its own clinical infrastructure would do it worse. It is an argument about where the security spending should sit relative to where the records sit — and the two have quietly separated. The brands carry the customer relationship and the reputational damage; the platform carries the data.

Two numbers, and no way to choose

The official figure is 716,000, established by the organisation and filed with a regulator. The claim from the other side is 1.6 million, with a longer list of fields. Both were published, neither has been reconciled, and a reader has no way to prefer one.

They are not necessarily contradictory, which is the part worth sitting with. An organisation counts the individuals it can establish were affected, from the records it can reconstruct. Somebody who copied files counts rows in what they copied, which may include duplicates, test data, or people the organisation no longer considers current. The two methods can produce different answers about the same event without either being a lie.

Which leaves the same discipline that applies to every widely quoted figure in this field: before repeating a number, establish what question produced it. Where that cannot be established, the number is decoration, and the honest thing is to publish both and say they do not agree.

What a person can actually do

Very little about the platform, and that is the uncomfortable conclusion. There was no decision to make differently: the platform was not disclosed at sign-up in any form a consumer would notice, and no realistic amount of care would have surfaced it.

What remains is narrow and still worth doing. Medical and prescription information cannot be reissued, so the useful response is watching rather than replacing — for approaches that cite real details about your care, which is what this category of data is worth to somebody buying it. The letter, when it arrives, will name the brand you recognise. The company that lost the file may not be mentioned at all.