INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Buchalter Discloses Data Breaches with Saber Healthcare

| 2026-10-01 13:46 CRITICAL LOW DATA BREACH
Executive Summary
AI-generated
On October 1, 2026, data breaches were announced by Saber Healthcare in Ohio and Buchalter, a California-headquartered law firm providing services to Arrowhead Regional Medical Center. The incident at Saber Healthcare was identified on July 27, 2026, with immediate action taken to secure its systems; third-party cybersecurity experts assisted the investigation, indicating that data stored on one of its computer servers may have been accessed or acquired. Data compromised in the incident varies from individual to individual and may include names combined with date of birth, driver’s license/state issued identification number, health insurance information, medical information, financial account information, passport number, and/or Social Security number; no evidence has been found to indicate any misuse of exposed data, but affected individuals have been advised to remain vigilant against identity theft and fraud. The incident is believed to affect more than 3,000 individuals, with notification letters being mailed after obtaining up-to-date address information on September 21, 2026.
Technical Mitigations AI-generated
• Patch the Bright Smile Dental Care server to prevent future ransomware attacks. • Review and update data security policies and procedures for Saber Healthcare, Buchalter, LLP, and other affected organizations. • Implement additional network security measures at Buchalter, LLP to improve overall cybersecurity posture.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
Global Scope healthhealth legallegal
Incident Timeline
‎July 27, 2026
Threat actors announced data breaches at Saber Healthcare and Buchalter on July 27, 2026.
‎August 3, 2026
Threat actors used ransomware to target the servers of Saber Healthcare & Buchalter, potentially exposing sensitive patient data.
‎August 19, 2026
Threat actors used Buchalter, LLP's server to target patients of Arrowhead Regional Medical Center.
organisation Social Security
organisation Buchalter, LLP (Arrowhead Regional Medical Center
organisation Patients of Arrowhead Regional Medical Center
‎August 28, 2026
Buchalter discovered that limited data was accessed by an unauthorized third party on August 28, 2026.
‎September 4, 2026
Threat actors used phishing to target ARMC patients, resulting in certain patient data being compromised.
‎September 21, 2026
Threat actors used ransomware to target Bright Smile Dental Care's server containing its practice management, dental imaging, and electronic health record software.
organisation Bright Smile Dental Care
‎Oct 1, 2026
Saber Healthcare has started notifying individuals about unauthorized access to one of its computer servers.
industry Healthcare
organisation Saber Healthcare
organisation Arrowhead Regional Medical Center
‎2026/10/01
Threat actors announced data breaches at Saber Healthcare & Buchalter on October 1, 2026.
organisation Saber Healthcare & Buchalter
Intelligence Sources
HIPAA Journal 2026-10-01