INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Buchalter Discloses Data Breaches with Saber Healthcare
| 2026-10-01 13:46 CRITICAL LOW DATA BREACH
Executive Summary
AI-generated
On October 1, 2026, data breaches were announced by Saber Healthcare in Ohio and Buchalter, a California-headquartered law firm providing services to Arrowhead Regional Medical Center. The incident at Saber Healthcare was identified on July 27, 2026, with immediate action taken to secure its systems; third-party cybersecurity experts assisted the investigation, indicating that data stored on one of its computer servers may have been accessed or acquired. Data compromised in the incident varies from individual to individual and may include names combined with date of birth, driver’s license/state issued identification number, health insurance information, medical information, financial account information, passport number, and/or Social Security number; no evidence has been found to indicate any misuse of exposed data, but affected individuals have been advised to remain vigilant against identity theft and fraud. The incident is believed to affect more than 3,000 individuals, with notification letters being mailed after obtaining up-to-date address information on September 21, 2026.
Technical Mitigations AI-generated
• Patch the Bright Smile Dental Care server to prevent future ransomware attacks.
• Review and update data security policies and procedures for Saber Healthcare, Buchalter, LLP, and other affected organizations.
• Implement additional network security measures at Buchalter, LLP to improve overall cybersecurity posture.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
Global Scope
healthhealth
legallegal
Incident Timeline
July 27, 2026
Threat actors announced data breaches at Saber Healthcare and Buchalter on July 27, 2026.
August 3, 2026
Threat actors used ransomware to target the servers of Saber Healthcare & Buchalter, potentially exposing sensitive patient data.
August 19, 2026
Threat actors used Buchalter, LLP's server to target patients of Arrowhead Regional Medical Center.
Click on any entity below to view its context and source!
organisation
Social Security
Data compromised in the incident varies from individual to individual and may include names in combination with one or more of the following: date of birth, driver’s license/state issued identification number, health insurance information, medical information, financial account information, passport number, and/or Social Security number.
organisation
Buchalter, LLP (Arrowhead Regional Medical Center
Buchalter, LLP (Arrowhead Regional Medical Center)
Patients of Arrowhead Regional Medical Center (ARMC) in Colton, California, have been affected by a cybersecurity incident at the law firm Buchalter, LLP.
organisation
Patients of Arrowhead Regional Medical Center
Buchalter, LLP (Arrowhead Regional Medical Center)
Patients of Arrowhead Regional Medical Center (ARMC) in Colton, California, have been affected by a cybersecurity incident at the law firm Buchalter, LLP.
August 28, 2026
Buchalter discovered that limited data was accessed by an unauthorized third party on August 28, 2026.
September 4, 2026
Threat actors used phishing to target ARMC patients, resulting in certain patient data being compromised.
September 21, 2026
Threat actors used ransomware to target Bright Smile Dental Care's server containing its practice management, dental imaging, and electronic health record software.
Click on any entity below to view its context and source!
organisation
Bright Smile Dental Care
Bright Smile Dental Care
Bright Smile Dental Care, a Fishers, Indiana-based dental practice, has experienced a ransomware attack involving a server containing its practice management, dental imaging, and electronic health record software.
Oct 1, 2026
Saber Healthcare has started notifying individuals about unauthorized access to one of its computer servers.
Click on any entity below to view its context and source!
industry
Healthcare
Data Breaches Announced by Saber Healthcare & Buchalter
Posted By
Steve Alder
on Oct 1, 2026
Data breaches have been announced by Saber Healthcare in Ohio and Buchalter, a California-headquartered law firm that provides services to Arrowhead Regional Medical Center.
organisation
Saber Healthcare
Data Breaches Announced by Saber Healthcare & Buchalter
Posted By
Steve Alder
on Oct 1, 2026
Data breaches have been announced by Saber Healthcare in Ohio and Buchalter, a California-headquartered law firm that provides services to Arrowhead Regional Medical Center.
organisation
Arrowhead Regional Medical Center
Data Breaches Announced by Saber Healthcare & Buchalter
Posted By
Steve Alder
on Oct 1, 2026
Data breaches have been announced by Saber Healthcare in Ohio and Buchalter, a California-headquartered law firm that provides services to Arrowhead Regional Medical Center.
2026/10/01
Threat actors announced data breaches at Saber Healthcare & Buchalter on October 1, 2026.
Click on any entity below to view its context and source!
organisation
Saber Healthcare & Buchalter
Data Breaches Announced by Saber Healthcare & Buchalter.
Intelligence Sources
HIPAA Journal
2026-10-01
Data Breaches Announced by Saber Healthcare & Buchalter
HIPAA Journal
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-05T10:42
Comprehensive Tactical Telemetry
Highly Correlated Entities
7x
organisation
Identified Entity
Saber Healthcare & Buchalter
entity
7x
timeline
Temporal Reference
Oct 1, 2026
date
3x
industry
Targeted Sector
Healthcare
sector
Contextual Telemetry
Context Block
2 METRICS
tactic
Cyber Operation Type
Ransomware
tactic
general metric
Individuals
3,000
individuals
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.