Saber Healthcare Inc. filed a data breach notification with the Vermont Attorney General in September 2026 after unauthorized access exposed Social Security numbers, government ID numbers, financial account data, health records and biometric information. The exact number of affected individuals has not been publicly disclosed. Affected individuals should immediately check credit reports, consider a credit freeze, and watch for phishing attempts.
| Company | Saber Healthcare Inc. |
|---|---|
| Industry | Healthcare |
| Data Types Exposed | Social Security Numbers, Government ID Numbers, Financial Account Codes, Credit and Debit Account Information, Health Records, Biometric Information |
| People Affected | Not Publicly Disclosed |
| Attack Method | Unspecified/Unauthorized Access |
| Regulators Notified | Vermont Attorney General |
Were you affected by this breach?
You may be owed compensation.
Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.
Check if you qualify — free reviewWhat Happened in the Saber Healthcare Data Breach?
Saber Healthcare Inc. recently disclosed a data breach that exposed a wide range of sensitive personal information. The company filed a formal notification describing the incident with the Vermont Attorney General in September 2026. This filing confirms that unauthorized parties accessed or acquired protected personal data tied to affected individuals.
The exact method used by the attacker has not been publicly disclosed. Similarly, the specific timeline of the intrusion, including when it began and how long it went undetected, remains unclear based on available information. What is confirmed is that the breach involved highly sensitive categories of data, including Social Security numbers and health records.
Because Saber Healthcare operates in the healthcare sector, this breach likely involved systems that store both administrative and clinical information. As a result, the exposure could touch nearly every part of a patient’s or employee’s personal profile. The company’s notification to Vermont regulators indicates it completed some level of internal review before notifying affected individuals and government authorities.
At this time, no further public details have emerged about the forensic investigation process. However, the fact that a formal notification was filed suggests Saber Healthcare identified enough evidence of unauthorized access to trigger legal disclosure requirements. This step is typically taken only after a company confirms that personal data was actually compromised.
Who was affected?
The population affected by this breach has not been publicly disclosed in terms of an exact number. Because Saber Healthcare operates within the healthcare industry, those affected likely include patients, residents, or clients whose personal and medical information was stored in company systems. Employees may also be included, since payroll and HR-related data often overlaps with financial account information.
The geographic scope of the breach is not fully known. However, the filing with Vermont’s Attorney General indicates that at least some affected individuals reside in Vermont. In addition, healthcare organizations of this type often serve broader regional or multi-state populations, meaning individuals outside Vermont could also be affected.
Given the presence of health records and biometric information among the exposed data types, it is reasonable to assume that vulnerable populations, including elderly patients or those receiving long-term care, may be part of the affected group. This is significant because these individuals often face greater difficulty monitoring their accounts or responding quickly to fraud alerts.
What Information Was Potentially Exposed?
According to the breach notification filed with Vermont regulators, several categories of sensitive personal data were involved. This combination of data types creates a notably high risk profile for affected individuals.
- Social Security Numbers
- Government ID Numbers
- Financial Account Codes
- Credit and Debit Account Information
- Health Records
- Biometric Information
This type of exposure carries serious risk because it includes both identity-verifying data and financial account details. For example, a criminal armed with a Social Security number and a government ID number could open new credit accounts or file fraudulent tax returns. Because financial account codes and card information were also involved, affected individuals may face a higher chance of direct financial fraud, including unauthorized charges or account takeovers.
In addition to financial risk, the inclusion of health records and biometric information raises concerns about medical identity theft. Criminals could use stolen health data to obtain medical services fraudulently or to submit false insurance claims. Biometric data is especially concerning because, unlike a password, it cannot be changed if compromised. As a result, individuals may face long-term risks that extend beyond typical financial fraud protections.
What is the company doing?
Saber Healthcare Inc. filed a formal notification describing the breach with the Vermont Attorney General. This filing represents the company’s official acknowledgment of the incident and its scope, at least as currently understood. The notification to Vermont regulators is a required legal step meant to inform both government authorities and affected residents.
Saber Healthcare Inc. also filed formal notification with the Vermont Attorney General. This filing confirms the categories of data involved and represents part of the company’s broader compliance response. Beyond this filing, further specific remediation steps, such as system hardening or credit monitoring offers, have not been publicly detailed in available records.
Because breach notification laws generally require timely disclosure once a compromise is confirmed, the filing itself suggests Saber Healthcare has already taken initial investigative steps internally. However, without additional public statements, it is not possible to confirm whether the company has implemented long-term security upgrades or additional support services for affected individuals.
What Should Affected Individuals Do?
Monitor Your Credit Reports Regularly
Affected individuals should begin checking their credit reports as soon as possible. This is especially important given that Social Security numbers and financial account data were involved in this breach. Regular monitoring can help catch new account openings or unusual credit inquiries early.
You can request free credit reports from all three major credit bureaus. Because fraud can take time to appear, continued monitoring over the coming months is advisable. If you notice any unfamiliar accounts or inquiries, report them immediately to the credit bureau involved.
Consider a Fraud Alert or Credit Freeze
Because this breach exposed Social Security numbers and government ID numbers, placing a fraud alert or credit freeze is a strong protective step. A fraud alert requires lenders to verify your identity before opening new credit in your name. A credit freeze goes further by restricting access to your credit file entirely.
Setting up a freeze is free and can be done directly through each credit bureau. Although it requires a small amount of effort to lift temporarily when applying for credit, this extra step can meaningfully reduce your risk of identity theft after a breach involving sensitive identification numbers.
Protect Against Medical Identity Theft
Since health records were part of the exposed data, affected individuals should closely review any insurance statements or medical bills. Look for services or prescriptions that you do not recognize. This could be a sign that someone is using your identity for fraudulent medical care.
In addition, request a copy of your medical records periodically to check for inaccuracies. If you find suspicious entries, contact your healthcare provider and insurer right away. Correcting a compromised medical file can be a lengthy process, so early action is important.
Stay Alert for Phishing Attempts
Following a healthcare data breach, criminals often use stolen information to craft convincing phishing emails or phone calls. These messages may reference real details, such as your provider’s name, to appear legitimate. Because of this, affected individuals should be cautious with any unexpected communication asking for personal information.
Never click on links or provide sensitive details in response to unsolicited messages. Instead, verify requests directly through official phone numbers or websites. This simple habit can prevent attackers from gaining further access to your accounts.
Consult a Data Breach Attorney
Given the sensitive nature of the data involved, affected individuals may want to speak with a data breach attorney. An attorney can help evaluate whether you qualify for compensation or participation in a class action related to this incident.
Many attorneys offer free consultations to review your specific situation. Because deadlines for legal claims can vary, seeking guidance sooner rather than later is generally recommended. This step can also help clarify your rights if identity theft or fraud occurs later.
Get a Free Case Review
Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.
More Information
View the public data breach notification listing from Vermont Attorney General
