HIPAA Journal reported on 1 October three US healthcare-sector breach disclosures. Saber Healthcare, a Beachwood, Ohio-based skilled nursing, long-term and senior rehabilitation provider, began notifying individuals about unauthorised access to one of its computer servers identified on 27 July 2026; a review completed 19 August found data may have been accessed or acquired, including names combined with dates of birth, driver's licence numbers, health insurance and medical information, financial account information, passport numbers and Social Security numbers. No count is published, but state attorney general disclosures indicate more than 3,000 individuals were affected; no misuse has been found. Separately, patients of Arrowhead Regional Medical Center in Colton, California were affected by an incident at law firm Buchalter, LLP, which provides legal services to the hospital; Buchalter discovered limited patient data was accessed by an unauthorised third party on 28 August and confirmed on 4 September that certain ARMC patients were compromised, with no number yet disclosed. Bright Smile Dental Care in Fishers, Indiana reported a ransomware attack on a server holding practice management, dental imaging and EHR software, identified 3 August; data was encrypted and decryption keys are not believed to have been taken, so unauthorised access is considered unlikely — but the server held names, insurance details, dependants' information and, in some cases, Social Security numbers.
| Attribute | Detail |
|---|---|
| Sector | Healthcare |
| Date | 2026-10-02 |
| Source | HIPAA Journal |
| Reliability | Tier 2 |