I have always felt that since pptp is based on usernames & passwords it is exactly as secure as your usernames and passwords. A remote user checking webmail on a terminal with a key logger installed can easily reveal a username and password, for example.
OpenVPN, by contrast, is server and certificate based - an attacker has to crack into one end or the other to get certificate information, and possibly may need to spoof IP information, too.
I don't know of any other reason that PPTP would be considered 'insecure'.
The basic implication is that you need to carefully train any users who have access to your PPTP server to make sure they understand the importance of password security, etc, etc.