Saber Healthcare Data Breach Class Action Lawsuit Investigation
Data breach law firm Abington Cole + Ellery is investigating potential legal claims related to the Saber Healthcare data breach, which reportedly affected about 427,084 individuals and may have exposed names, addresses, dates of birth, Social Security numbers, driver’s license or state identification numbers, passport numbers, financial account information—including bank account numbers used for billing—medical records, treatment information, and health insurance information.
JOIN THIS INVESTIGATION: If you are interested in potentially volunteering to serve as a class representative in a class action lawsuit against Saber Healthcare, please submit your information to be considered:
You may also open the form here: Saber Healthcare Data Breach Lawsuit Form. An attorney-client relationship is not formed by submitting information through this website.
Saber Healthcare Data Breach: Key Facts
| Company: | Saber Healthcare |
|---|---|
| Location: | Beachwood, Ohio |
| Incident Type: | Data Breach and Encryption |
| Number Affected: | APPROXIMATELY 427,084 |
| Data Involved: | names, addresses, dates of birth, Social Security numbers, driver’s license or state identification numbers, passport numbers, financial account information—including bank account numbers used for billing—medical records, treatment information, and health insurance information |
| Date Began: | May 29, 2026 |
| Date Discovered: | July 27, 2026 |
| Date Ended: | July 27, 2026 |
| Notice Date: | September 25, 2026 |
| Credit Monitoring: | YES |
| Status: | Class Action Lawsuit Investigation |
What happened in the Saber Healthcare data breach?
Saber Healthcare Group announced the data breach on September 25, 2026, following a cybersecurity incident that disrupted some of its internal and external computer systems. Saber, an Ohio-based organization affiliated with senior care, skilled nursing, and rehabilitation communities, detected the outage on July 27, 2026. Its investigation determined that an unauthorized outside party had entered the corporate network and encrypted some files. This describes a ransomware-type attack, although Saber’s public disclosures do not identify the attacker, describe a ransom demand, or explain the initial method of entry. Saber Healthcare Notice Of Data Incident
The Texas AG’s underlying record lists the breach period as May 29 through July 27, 2026. Saber’s announcement identifies July 27 as the day it detected the disruption and file encryption. After discovering the incident, the organization isolated affected systems and brought in outside cybersecurity specialists. Saber reports that it restored the inaccessible files from unaffected backups within 24 to 48 hours, without losing data. Restoration, however, does not establish whether information had been accessed before the files were encrypted. Texas Attorney General Data Security Breach Reports
The potentially affected information varied by individual. Saber’s notice identifies names, dates of birth, Social Security numbers, driver’s license or state identification numbers, passport numbers, financial account information, medical information, and health insurance information. The Texas filing also includes addresses. A sample notification submitted to South Carolina provides more detail about certain records, identifying bank account numbers used for billing, medical records, and treatment information. These disclosures do not mean that every affected person had every listed category exposed.
Saber states that its review of potentially affected information was completed on August 19, 2026, after which it worked to locate addresses for notification. Its public notice and a sample consumer letter are dated September 25. The sample letter is addressed to the next of kin of an affected individual, indicating that at least some notices concern deceased individuals. That letter also describes the review as ongoing, which differs from the completion language in Saber’s public announcement.
In response, Saber reports that it reset passwords, reviewed security policies and procedures, and introduced additional safeguards. It is offering free credit monitoring and identity protection services, although the notices reviewed do not specify the duration. Saber says it has no evidence of attempted or actual misuse of the information. Affected individuals can contact its incident assistance line at 1-833-918-1128 and consult their notification letters for the information involved and available services.
How did the Saber Healthcare data breach occur?
The Saber Healthcare data breach occurred when an unauthorized outside party gained access to Saber’s corporate computer network. On July 27, 2026, the intruder encrypted a portion of its files, causing an outage affecting some internal and external systems. That encryption is consistent with a ransomware attack. Saber has not publicly disclosed how the attacker initially entered the network, such as through stolen credentials, phishing, or a software vulnerability.
When did the Saber Healthcare data breach occur?
The Saber Healthcare data breach occurred between May 29 and July 27, 2026, according to the breach start and end dates in the Texas Attorney General’s underlying reporting data. Saber says it detected unauthorized activity and a system outage on July 27, 2026, when the attacker encrypted some corporate files.
How many people were affected by the Saber Healthcare data breach?
The Saber Healthcare data breach affected 427,084 people overall, including 269 Texas residents, according to the Texas Attorney General’s underlying reporting data for Saber Healthcare Inc., report BR-0005370.
What information was exposed in the Saber Healthcare data breach?
- The Saber Healthcare data breach may have exposed the following information, depending on the individual:
- Names and addresses
- Dates of birth
- Social Security number
- Driver’s license or state identification numbers
- Passport numbers
- Financial account information, including bank account numbers used for billing
- Medical records and treatment information
- Health insurance information
Has Saber Healthcare offered free credit monitoring and/or identity theft protection services?
Yes. As a result of the data breach, Saber Healthcare is offering free credit monitoring and/or identity theft protection services to at least some affected individuals.
Saber Healthcare Data Breach Timeline
| Date | Event |
|---|---|
| May 29, 2026 | Breach period began, according to the Texas Attorney General’s underlying reporting data. |
| July 27, 2026 | Breach period ended in the Texas record. Saber detected unauthorized activity and a system outage after an outside party encrypted some corporate network files. |
| August 19, 2026 | Saber says it completed its review of potentially affected information and began locating addresses for notification. |
| September 25, 2026 | Saber publicly announced the incident. The sample consumer notification letter bears this date, and South Carolina recorded the breach report. |
Who is Saber Healthcare?
Saber Healthcare Group, commonly known as Saber Healthcare, is a healthcare organization based in Beachwood, Ohio, with more than 160 affiliated care communities across Delaware, North Carolina, Ohio, Pennsylvania, and Virginia. Its affiliated facilities provide skilled nursing, rehabilitation, long-term care, assisted living, memory care, and personal care services. The network serves individuals recovering from illness or injury, as well as residents who need ongoing nursing care or assistance with daily activities. Depending on the location, services also include dialysis, ventilator management, and care for pulmonary and cardiac conditions.
What should you do if you received a Saber Healthcare data breach letter?
If you received a Saber Healthcare data breach letter, take these steps:
-
- Read and save the letter. Identify which information was potentially exposed and keep the notice, enrollment instructions, and any deadlines.
- Enroll in the free protection services offered. Saber says it is providing credit monitoring and identity protection at no cost. Follow your letter’s instructions or call 1-833-918-1128 for enrollment details.
- Consider freezing your credit , especially if your Social Security number was involved. Contact Equifax, Experian, and TransUnion separately. Freezes are free and do not affect your credit score. You can also place a free, one-year fraud alert by contacting one bureau, which must notify the other two.
- Review financial and medical statements. Watch bank accounts, credit reports, medical bills, and insurance explanations of benefits for unfamiliar accounts, charges, or treatment. Report discrepancies promptly to the bank, healthcare provider, or insurer.
- Act promptly if you discover identity theft. Visit IdentityTheft.gov for reporting and recovery assistance. Keep records of suspicious activity, related expenses, and communications.
If the letter concerns a deceased loved one, the executor or surviving spouse can contact the credit bureaus to request a deceased notation and obtain guidance on reviewing the person’s credit file. Saber’s sample notice specifically addresses next-of-kin recipients.
Saber Healthcare Data Breach Notice
The notice describes the Saber Healthcare data breach, including the type of information that may have been involved and the steps offered to affected individuals.
Open the Saber Healthcare Data Breach Notice in a New Tab
Sources & Additional Information About the Saber Healthcare Data Breach
-
- Saber Healthcare Website
- Saber Healthcare Notice Of Data Incident
- Texas Attorney General Data Security Breach Reports
- South Carolina Security Breach Notices
- my Social Security
- Medicare.gov: Reporting Medicare fraud & abuse
- FTC: Checking Your Credit Report
- FTC: Credit Freezes and Fraud Alerts
- AnnualCreditReport.com
- FTC Consumer Advice: Identity Theft
- IdentityTheft.gov
- IRS Identity Theft Guide for Individuals
- IRS Identity Theft Guide Central
- IRS: Get an identity protection PIN (IP PIN)
- U.S. Department of Health and Human Services Office of Inspector General: Medical Identity Theft
- IdentityTheft.gov: What To Do if Your Information Was Lost or Stolen, or Part of a Data Breach
Class Action FAQ
About This Data Breach Resource
This page was created to give affected individuals and researchers a clear, comprehensive explanation of the Saber Healthcare data breach. It summarizes what is currently known about the incident, including the timeline, how the breach was discovered, the types of information involved, the number of people affected when available, important notice dates, and steps individuals may want to take after receiving a data breach notification.
This resource is independently written and organized to help readers understand the breach without having to review multiple notices, state attorney general filings, company statements, and related materials. When available, this page relies on primary sources and identifies key facts, unanswered questions, and updates as new information becomes public.
This page is especially relevant for readers searching for information about the Saber Healthcare data breach, Saber Healthcare data breach notice, Saber Healthcare class action investigation, what information was exposed, how many people were affected, and what affected individuals should do next.
Abington Cole + Ellery reviews data breach incidents involving sensitive personal information, financial information, and protected health information. This page is intended to help affected individuals understand the publicly reported facts, the types of information that may have been involved, and practical steps that may reduce the risk of identity theft or medical identity theft.
The information on this webpage is provided for general informational purposes only and does not constitute legal advice. Nothing on this page should be relied upon as legal advice for any particular situation. Submitting information through this page does not create an attorney-client relationship.
For more information about steps you can take to possibly reduce the risk harm arising from a data breach, please review the following article: What are some steps you can take if you've been the victim of a data breach?
This website is not associated with nor authorized by Saber Healthcare or any affiliated companies. If you have received any other data breach notifications, you may want to review Abington Cole + Ellery's current list of data breach investigations.