Saber Healthcare Ramps Up Cybersecurity Measures After Late-July Attack As Private Data May Have Been Compromised
AIThis post was created with the assistance of artificial intelligence (AI).

TL;DR

Saber Healthcare says it learned of a cyber incident on July 27 and restored its internal systems within hours. The company reset credentials and added security tools and monitoring; residents’ personal information may have been exposed, but the number of people affected and whether data was misused have not been disclosed in the supplied report.

Saber Healthcare Group says it restored its internal systems within hours after discovering a cybersecurity incident on July 27, and has since added security controls and monitoring. The Ohio-based long-term care provider said residents’ private information may have been compromised, though the report does not specify how many people were affected or whether the information was accessed or misused.

Chief of government affairs Zach Shamberg told Skilled Nursing News that Saber brought in outside cybersecurity experts to investigate and took steps to strengthen its systems. He said the incident was resolved and that internal systems were back online and operating without issue within hours of the company learning of it. Shamberg also said residents continued to receive care during the brief interruption.

A notice posted on the company’s website says potentially affected information varies by person. It may include a person’s name and one or more of the following: date of birth, driver’s license or state identification number, health insurance information, medical information, financial account information, passport number, or Social Security number. The notice says an individual’s information may include all, or only one, of those categories.

As part of the response, Saber reset account credentials across the organization and strengthened password requirements. Shamberg said the company also reviewed and monitored its email system with outside experts, deployed extended detection and response software across network devices, and engaged a security operations center for round-the-clock network monitoring.

At a glance
updateWhen: Incident reported July 27; response mea…
The developmentSaber Healthcare has described security steps taken after a July 27 cyber incident in which residents’ personal information may have been compromised.

Potential Exposure of Resident Records

The incident matters because the categories listed in Saber’s notice include health, identity, and financial information. If accessed or misused, those records could expose residents to privacy harms or identity-related fraud. The company’s description establishes that such information may have been involved, but does not confirm that every listed category was exposed for any individual.

Saber operates more than 160 affiliated facilities across Ohio, Pennsylvania, Delaware, Virginia, and North Carolina, according to the source report. That scale makes the incident relevant to residents, families, and care providers across several states. The report does not say how many facilities or residents were affected, so the size of the incident cannot be determined from the available information.

The added controls may reduce the risk of a similar intrusion, but they do not establish how the attack occurred or whether any data was taken. For residents and families, the distinction between information that may have been exposed and information confirmed as compromised remains important.

Amazon

password manager for healthcare professionals

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

How Saber Responded to the Incident

Saber said it learned of the incident on July 27. The company’s account, as reported by Skilled Nursing News, is that internal systems returned to normal within hours. It also said care continued during the interruption. The supplied report does not describe the length or operational scope of that disruption beyond Shamberg’s account.

The response combines immediate account changes with continuing monitoring and review. Saber reset credentials, tightened password requirements, reviewed email activity with external specialists, installed detection software on network devices, and arranged 24/7 security operations monitoring. Shamberg said the company is also working on data hygiene, reviewing security policies and controls, and adding monitoring and detection capabilities where needed.

Shamberg framed the incident against broader cybersecurity risks in health care, saying organizations should remain alert to suspicious activity. He also cautioned that security safeguards are not complete or limitless. That is the company’s general assessment, not evidence in the report about the specific method used in this attack.

“Within just hours of learning of the incident, our internal systems were back online and operating without issue.”

— Zach Shamberg, chief of government affairs at Saber Healthcare Group, speaking to Skilled Nursing News

Amazon

extended detection and response software

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Key Details Still Undisclosed

The supplied report does not state how many residents may have been affected, which facilities were involved, or whether the incident reached all or only part of Saber’s organization. It also does not identify the attacker, explain how access was gained, or say whether investigators found evidence that information was copied, published, or used.

Saber’s notice describes data that may have been exposed, but the wording does not establish that every listed type was accessed for each person. The report also does not provide details about individual notifications, any offered assistance, or whether regulators or law enforcement were contacted. Those points remain unconfirmed in the available material.

Amazon

round-the-clock network monitoring tools

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Security Reviews and Monitoring Continue

Shamberg said Saber’s work continues on data hygiene, security policies, procedures, and controls, with further monitoring and detection added as needed. The company has also engaged a security operations center for ongoing network monitoring. The report gives no timetable for completing the review or a date for a further public update.

Residents and families seeking details about their own records would need to refer to communications from Saber or contact the provider directly; the source report does not give individual case information. Any further notice from the company or findings from its outside experts could clarify the scope of the incident and whether personal information was actually accessed or misused.

Amazon

cybersecurity kits for small businesses

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Key Questions

When did Saber Healthcare discover the cyber incident?

Saber said it learned of the cybersecurity incident on July 27. The source report does not specify the year in the incident description, but reports the response in October 2026.

What resident information may have been involved?

Saber’s website notice says information may vary by person and could include a name alongside details such as date of birth, identification numbers, health or medical information, financial account information, passport number, or Social Security number. The notice does not say that every category applied to every person.

How many people were affected?

The available report does not give a count of affected residents or identify how many facilities were involved. The scope remains unclear.

What security steps has Saber taken?

Saber says it reset organization-wide account credentials, strengthened password requirements, reviewed and monitored its email system with outside experts, deployed extended detection and response software, and engaged a security operations center for 24/7 network monitoring.

Has Saber confirmed that residents’ data was stolen or misused?

No such confirmation appears in the supplied report. Saber said private information may have been compromised; the report does not establish whether data was taken or misused.

Source: rss

This article is for informational purposes only and is not medical advice. Always consult a qualified healthcare professional about your specific situation.
You May Also Like

Without Blood Donations, Magen David Adom Could Not Have Saved Tel Aviv Mother’s Life – The Media Line

A Tel Aviv mother’s life was saved due to blood donations, highlighting the critical need for ongoing donor support. Details confirmed by Magen David Adom.

VA’s New Antidepressant Rules; App Aids Schizophrenia; Diet And Depression

A VA policy adds consent requirements for younger veterans. A schizophrenia app trial and a small diet study report early findings.

Why SCAN Health Plan Skips The Hospital Stop Between Home And SNF

SCAN Health Plan allows eligible members to move from home to a skilled nursing facility without a prior two-day hospital stay, an executive said.

Parents Say Meta Settlement Is Big, But Not Enough

Parents express disappointment with Meta’s recent settlement over privacy concerns, claiming it is insufficient to address ongoing issues.