Saber Healthcare and law firm Buchalter both announced data breaches in October 2026, exposing protected health information and personal data. The incidents highlight rising third-party risk, notification obligations, and enforcement exposure under HIPAA and state laws. Affected individuals should monitor accounts and review breach notices carefully.
Two significant data breaches were announced on October 1, 2026, involving Saber Healthcare, a major skilled nursing and rehabilitation provider, and Buchalter, a full-service law firm with healthcare clients. The HIPAA Journal reported both incidents, which underscore the growing vulnerability of healthcare data across provider and business associate environments.
Saber Healthcare disclosed a network security incident involving unauthorized access to systems containing resident and employee protected health information (PHI). The breach affected multiple facilities and potentially exposed names, dates of birth, Social Security numbers, medical record numbers, diagnoses, treatment information, and health insurance details. The organization stated it engaged third-party forensic investigators and has begun notifying affected individuals.
Buchalter, a law firm that handles healthcare transactions and litigation, reported a separate incident affecting personal data in its possession. While specific details about the data types remain under investigation, law firms serving healthcare entities often hold PHI as business associates, which directly triggers HIPAA obligations.
The Saber Healthcare breach potentially impacts thousands of current and former residents, patients, and employees across its network of skilled nursing facilities, assisted living centers, and rehabilitation locations. Individuals who received care at Saber-affiliated facilities should treat any notification seriously and review their medical and financial statements for unusual activity.
The Buchalter incident may affect clients of the firm, including healthcare organizations that shared sensitive case information, as well as employees and counterparties whose personal information was processed during legal matters. The firm has indicated that its investigation is ongoing and that additional individuals may receive notifications as details emerge.
Both incidents carry substantial HIPAA compliance implications, though the legal obligations differ based on each entity's role.
As a covered entity, Saber Healthcare must comply with the HIPAA Breach Notification Rule, which requires:
If Buchalter acted as a business associate for healthcare clients, it has direct liability under HIPAA for safeguarding PHI and complying with breach notification duties. The incident reinforces that law firms are not exempt from HIPAA simply because they are not healthcare providers. Business associate agreements (BAAs) likely govern the firm's use and disclosure of client PHI, and breach notification responsibilities may flow both to the covered entity and directly to affected individuals.
Both incidents serve as a wake-up call for healthcare organizations and their vendors. Recommended actions include:
1. Reassess third-party risk management. Review all BAAs and confirm that business associates have implemented appropriate safeguards, incident response plans, and cyber liability insurance. 2. Test incident response capabilities. Run tabletop exercises that simulate a breach involving PHI to identify gaps in detection, containment, notification, and regulatory reporting. 3. Implement or strengthen multifactor authentication (MFA). Many breaches begin with compromised credentials; MFA remains a critical control under HIPAA's security rule. 4. Practice data minimization. Limit the storage and retention of Social Security numbers and highly sensitive identifiers where not operationally necessary. 5. Review breach notification workflows. Ensure contact information for affected individuals is current and that notification letters comply with HIPAA content requirements. 6. Provide ongoing workforce training. Reinforce phishing awareness and secure handling of PHI across clinical and administrative staff.
OCR continues to prioritize breach investigations, and October 2026 marks another month of increased enforcement activity. Organizations should expect that both Saber Healthcare and Buchalter will face regulatory scrutiny, potential litigation, and reputational consequences. For compliance professionals, the key takeaway is clear: proactive security, timely breach response, and rigorous vendor oversight are no longer optional—they are the baseline expectation under HIPAA.
Saber Healthcare disclosed unauthorized access to systems containing resident and employee protected health information, including names, dates of birth, Social Security numbers, and medical details. Forensic investigators were engaged and affected individuals are being notified.
Yes, if Buchalter handled protected health information as a business associate for healthcare clients, it had direct HIPAA obligations, including safeguarding PHI and complying with breach notification requirements under a business associate agreement.
Covered entities must notify affected individuals within 60 days of discovering a breach. Breaches affecting 500 or more people must be reported to HHS OCR and prominent media outlets in the relevant state or jurisdiction.
Review the notification for what data was exposed, place a fraud alert or credit freeze if Social Security numbers were involved, monitor medical and financial accounts, and consider enrolling in any free credit monitoring offered.
OCR can impose civil monetary penalties based on the level of culpability, ranging from around $137 to over $68,000 per violation, with annual caps exceeding $2 million for identical violations. Failure to report timely increases enforcement risk and penalty exposure.
PoliWriter creates all the policies and documentation you need for compliance, customized to your organization. AI-powered, audit-ready, hours not months.
Get Started Free