Two unrelated breaches have exposed sensitive patient information. Saber Healthcare Group runs nursing homes and senior care from Beachwood, Ohio. Its notice says an outside party got into its corporate network on July 27, 2026, and encrypted part of its files. Buchalter, LLP is a law firm headquartered in California that does legal work for Arrowhead Regional Medical Center (ARMC). On August 28, 2026, it found that "a limited set" of its data had been taken without authorization, and that data included ARMC patient information. Neither organization has published a total count of affected people. For Saber, state filings cited by plaintiff law firms show at least 3,319 people across South Carolina, Texas, and Vermont. HIPAA Journal says the total is "more than 3,000," and further people are affected nationwide. No threat actor has claimed either incident in the available sources.
What Happened
Saber Healthcare. Saber published its notice on PR Newswire on September 25, 2026. It says the company "detected a service outage affecting some of its internal and external computer systems" on July 27. Investigators then found that an outside party had accessed the corporate network and "encrypted a small portion of files, which is what caused the outage." Saber says it restored the affected files from unaffected backups within 24 to 48 hours and lost no data. The company's electronic medical record (EMR) system is hosted and maintained by a separate outside provider. Saber says that system was not affected and that there is no evidence the medical record database was accessed, modified, or copied.
The account in HIPAA Journal is narrower. It describes "unauthorized access to one of its computer servers," says the data on that server "may have been accessed or acquired," and does not mention encryption. The two accounts fit together, but the company's own notice gives the fuller picture. Saber finished its file review on August 19, 2026, and then started looking up current addresses so it could mail notification letters. Edelson Lechtzin LLP reports that Saber notified the South Carolina, Texas, and Vermont attorneys general. Saber is offering free credit monitoring and identity protection, and says it has seen no further unauthorized activity since adding new security measures.
How big Saber is depends on the source. Edelson Lechtzin describes communities in five states. Federman & Sherwood says Saber operates or supports more than 160 facilities across several states.
Buchalter / ARMC. ARMC is a public hospital in Colton, California, run by San Bernardino County. The following timeline comes from the notification letter as summarized by Emery Reddy and Class Action U:
- August 28, 2026: Buchalter learns that a limited amount of its data was subject to unauthorized acquisition.
- Buchalter brings in third-party forensic specialists, and later "data mining experts," to review the affected data.
- September 4, 2026: The review finds ARMC patient information in the affected data, and Buchalter tells ARMC.
- September 28, 2026: San Bernardino County reports the breach to the California Attorney General and mails letters dated the same day.
Buchalter calls the incident "isolated." It says it has no evidence the attacker reached or affected its wider network or systems, and no evidence the data has been viewed or misused. The firm has reported the incident to law enforcement.
What Was Taken
Saber Healthcare: The company's notice and HIPAA Journal both list names combined with one or more of the following:
- Date of birth
- Driver's license or state ID number
- Passport number
- Social Security number
- Financial account information
- Health insurance information
- Medical information
Federman & Sherwood, citing the Vermont Attorney General filing, also lists biometric information and credit or debit account information. No other source in this set mentions biometric data, so treat it as unconfirmed until the filing itself can be checked.
Counts: Saber has not disclosed a total. Edelson Lechtzin reports at least 3,025 residents in South Carolina, 269 in Texas, and 25 in Vermont. Federman & Sherwood independently confirms the Vermont figure of 25. HIPAA Journal puts the total at "more than 3,000," based on disclosures to state attorneys general. The 3,319 total across those three states is a minimum, because every source says more people are affected nationwide. The Massachusetts September 2026 breach-notification index was also among the sources, but the excerpt available does not show an entry or count for either organization.
Buchalter / ARMC: The sources do not give a complete list of data types. Class Action U describes the exposed data as names combined with other elements that differ by person, and says the full list has not been published. None of the sources gives the number of ARMC patients affected.
Why It Matters
- Ransomware-style impact presented as an "outage." Saber's notice describes encryption by an outside party, which is consistent with ransomware. Its fast recovery from backups is a good result. Even so, files were exposed, which suggests data was copied before encryption. Fast restoration does not mean no data was stolen.
- Separating the EMR limited the damage. Saber's EMR was hosted by a third party and reached over the web, so the clinical records database appears to have escaped the corporate network compromise. The administrative and HR-type files on corporate servers still held SSNs, passports, and medical details.
- Law firms are a weak point in the healthcare supply chain. ARMC's own systems were not breached. Patients' data was exposed because it was held by outside counsel who are several steps removed from the patients, most of whom had no idea the firm held their information. Legal, billing, and claims vendors often keep large, unstructured file sets containing PHI.
- Disclosure gaps. Both organizations have released partial figures, and the full scope still has to be pieced together from state AG filings and plaintiff firms' notices. Class-action investigations had already started within days of each notice.
The Attack Technique
Neither organization has disclosed how the attacker got in, and no group has publicly claimed either attack in these sources.
- Saber: Someone accessed the corporate network, files were encrypted, and the encryption caused a service outage. That pattern matches ransomware, which commonly involves stealing data before encrypting it. The sources do not say how the attacker first got in, how long they were inside, or whether there was a ransom demand.
- Buchalter: The firm describes "unauthorized acquisition" of a limited data set and says there is no evidence of wider network access. That would fit a compromised cloud or file-sharing account, a third-party platform, or a single exfiltration point rather than a network-wide intrusion. This is an inference, and Buchalter has not confirmed any of it.
What Organizations Should Do
- Keep clinical systems apart from corporate IT. Saber's separately hosted EMR stayed untouched. Make sure EMR access does not depend on, or trust, the identity and network layers of the corporate domain.
- Assume data was stolen whenever files were encrypted. Restoring from backup is the start of the investigation, not the end. Review egress logs, cloud sync activity, and archive or compression activity from before the encryption to determine what left the network.
- Reduce sensitive files on file servers. Scans of IDs, SSNs, and insurance details stored in shared folders made Saber's exposure worse. Run data discovery, set retention limits, and tokenize or encrypt identifiers at rest.
- Treat outside counsel as a PHI vendor. Business associate agreements (BAAs) should cover law firms, with security requirements, breach notification deadlines, and data minimization terms. Send only the records a legal matter needs, and require them to be returned or destroyed when the matter closes.
- Monitor file-sharing and document platforms at vendors. Ask legal and billing partners how they log access and exfiltration on DMS, eDiscovery, and cloud file-transfer tools, and how quickly they would tell you.
- Test backups for both restore speed and isolation. Saber recovered within 48 hours because its backups were not reachable by the attacker. Use immutable, offline, or logically isolated copies, and run timed restore drills.
Sources: Data Breaches Announced by Saber Healthcare & Buchalter | Notice of Data Incident | Buchalter & ARMC Data Breach Lawsuit Emery Reddy | Saber Healthcare Data Breach Investigation: Edelson Lechtzin LLP Pr... | Arrowhead Regional Medical Center Data Breach Lawsuit - Class Action U | Saber Healthcare Discloses Data Breach Involving Sensitive Personal... | Saber Healthcare Inc. Data Breach – Investigated by Federman & Sher... | Data Breach Notification Letters September 2026 - Mass.gov