A skilled nursing operator in Ohio and a law firm that advises a Southern California hospital have each started sending notices about summer intrusions that touched patient data.
Saber Healthcare, based in Beachwood, Ohio, focuses on skilled nursing, long-term care, and senior rehabilitation. Staff spotted an intruder on one of its servers on July 27, 2026, and locked the system down. By August 19, the company had finished reviewing what the server held. Names, dates of birth, driver’s license or state ID numbers, health insurance and medical records, financial account details, passport numbers, and Social Security numbers all sit among the categories that may have been exposed. Filings with state attorneys general suggest more than 3,000 people are affected; Saber has not given a final figure, and it reports no sign of misuse.
The other notice involves Buchalter, LLP, a California law firm that provides legal services to Arrowhead Regional Medical Center in Colton. Limited data held by the firm was accessed without authorization and discovered on August 28, 2026. Buchalter confirmed on September 4 that some hospital patients were caught up in the incident, then gathered mailing details and sent notices around September 21. A headcount has not been released.
The pair highlights a durable problem for hospitals: sensitive records frequently rest with outside counsel and business associates whose defenses a covered entity cannot directly supervise.