Back to Intelligence

Saber Healthcare and Buchalter Data Breaches: HIPAA Detection, Containment, and Third-Party Risk Hardening Guide

SA
Security Arsenal Team
October 1, 2026
11 min read

Two new breach disclosures — one from Saber Healthcare, an Ohio-based skilled nursing and senior care operator, and one from Buchalter, a California-headquartered law firm whose client roster includes organizations in regulated industries — underscore a pattern I've watched repeat across 15 years of IR engagements: regulated data is being lost not only from the entities that own it, but from the professional services firms they trust with it.

For Saber Healthcare, this is a HIPAA-covered entity breach, which triggers the full apparatus of the HIPAA Breach Notification Rule (45 CFR §§ 164.400–414): individual notification within 60 days of discovery, HHS Office for Civil Rights (OCR) reporting, and media notification if 500+ residents of a single state are affected. For Buchalter, the exposure of client files held by outside counsel is a classic third-party/supply-chain disclosure event — the breached firm is not the data owner, but the data owners' obligations (and regulatory exposure) follow the data.

No CVE is associated with these disclosures, and none should be invented — incidents of this type are overwhelmingly driven by credential compromise, phishing-led initial access, and data staging/exfiltration rather than a novel software vulnerability. That means the defensive value here is behavioral detection and breach-readiness engineering, not patch management. This post gives SOC teams concrete detection content for the most common post-compromise behaviors seen in healthcare and legal-sector breaches, plus the containment and compliance steps that determine whether an incident becomes a reportable catastrophe or a contained event.

Technical Analysis

What These Incidents Typically Look Like Under the Hood

While the public disclosures provide limited technical detail, healthcare provider and law firm breaches investigated over the past two years follow a small number of repeatable intrusion patterns:

  1. Phishing or credential-stuffing initial access against Microsoft 365 / remote access portals. Law firms are disproportionately hit through mailbox compromise — a single attorney mailbox contains thousands of client attachments, including PHI, financial records, and litigation material.
  2. Lateral movement to file servers or document management systems (iManage, NetDocuments, SharePoint, or SMB shares in smaller environments).
  3. Data staging and bulk collection — compression of large directory trees into archives using legitimate utilities (7-Zip, WinRAR) in temporary working directories.
  4. Exfiltration over legitimate cloud channels — Rclone to Mega/Backblaze/S3, direct upload via browser, or egress over HTTPS to attacker-controlled storage. Modern double-extortion operators exfiltrate before any encryption, and in many healthcare cases no encryption occurs at all — pure theft followed by extortion.
  5. Delayed discovery — the median gap between intrusion and disclosure in healthcare breaches routinely stretches into months, which is exactly why HHS OCR scrutinizes the timeline between discovery and notification.

Affected Populations and Data at Risk

  • Saber Healthcare: skilled nursing and assisted living residents/patients. Expected data classes: names, DOBs, SSNs, medical records, treatment information, insurance/billing identifiers — the classic PHI/PII combination that maximizes both OCR exposure and identity-theft harm.
  • Buchalter: client organizations and their employees/customers whose data resided in the firm's files. Legal-sector breaches frequently expose data belonging to many downstream organizations, each of which may have independent HIPAA, PCI, GLBA, or state breach-notification obligations.

Severity and Exploitation Status

There is no vulnerability to patch and no KEV entry to chase — the "exploitation status" here is confirmed real-world harm: data has been taken and notification obligations have triggered. The severity driver is regulatory and operational: OCR investigations, state attorney general inquiries (particularly under California's CCPA/CMIA for Buchalter and Ohio law for Saber), class-action exposure, and multi-year corrective action plans.

Detection & Response

The detections below target the highest-fidelity, lowest-noise behaviors observed in healthcare and legal-sector intrusions: bulk archive staging, cloud-sync exfiltration tooling, and anomalous outbound data volume. They are tuned to fire on the technique, not on generic admin noise — but as always, baseline your environment before raising severity.

Sigma Rules

YAML
---
title: Mass Archive Creation via Command-Line Compression Utility
id: 3f8c2a91-6b4d-4e7a-9c1f-2a5b8d0e4f12
status: experimental
description: Detects 7-Zip, WinRAR, or similar CLI compression utilities creating archives from user or server data directories, a common data-staging behavior prior to exfiltration in healthcare and legal-sector breaches.
references:
  - https://attack.mitre.org/techniques/T1560/001/
author: Security Arsenal
date: 2026/01/15
tags:
  - attack.collection
  - attack.t1560.001
logsource:
  category: process_creation
  product: windows
detection:
  selection_image:
    Image|endswith:
      - '\7z.exe'
      - '\7za.exe'
      - '\7zg.exe'
      - '\rar.exe'
      - '\winrar.exe'
  selection_flags:
    CommandLine|contains:
      - ' a '
      - ' -r'
      - ' -v'
  selection_paths:
    CommandLine|contains:
      - '\Users\'
      - '\Shares\'
      - 'Documents'
      - 'e:\\'
      - 'f:\\'
  condition: selection_image and selection_flags and selection_paths
falsepositives:
  - IT backup workflows using scripted compression
  - Users legitimately archiving project folders (tune with allowlist per OU)
level: high
---
title: Cloud Sync or Exfiltration Utility Execution (Rclone and Similar)
id: 9d4e7b12-3a8f-4c6d-b2e9-5f1a0c7d8e34
status: experimental
description: Detects execution of Rclone or equivalent cloud-sync command-line tools frequently abused for bulk data exfiltration to attacker-controlled storage. These tools have no legitimate use on most healthcare clinical workstations or legal file servers.
references:
  - https://attack.mitre.org/techniques/T1567/002/
author: Security Arsenal
date: 2026/01/15
tags:
  - attack.exfiltration
  - attack.t1567.002
logsource:
  category: process_creation
  product: windows
detection:
  selection_img:
    Image|endswith:
      - '\rclone.exe'
      - '\megacmd.exe'
      - '\megasync.exe'
  selection_cmd:
    CommandLine|contains:
      - ' copy '
      - ' sync '
      - ' move '
  condition: selection_img and selection_cmd
falsepositives:
  - Sanctioned backup tooling (rename-based masquerading is common; validate binary path and signer)
level: critical
---
title: Renamed Compression or Sync Binary Executed from Temp Directory
id: 6c1a9f47-2d5e-4b8a-a3c6-8e0f2b5d7a91
status: experimental
description: Detects execution of binaries with random or single-purpose names from Temp/AppData directories exhibiting staging or sync behavior, consistent with threat actors renaming rclone.exe or 7z.exe to evade allowlists during breach operations.
references:
  - https://attack.mitre.org/techniques/T1036/
author: Security Arsenal
date: 2026/01/15
tags:
  - attack.defense_evasion
  - attack.t1036
  - attack.exfiltration
logsource:
  category: process_creation
  product: windows
detection:
  selection_path:
    Image|contains:
      - '\AppData\Local\Temp\'
      - '\ProgramData\'
      - '\Windows\Temp\'
  selection_cmd:
    CommandLine|contains:
      - ' --config '
      - ' -v '
      - '.zip'
      - '.7z'
      - '.rar'
  filter_known:
    Image|endswith:
      - '\setup.exe'
      - '\installer.exe'
  condition: selection_path and selection_cmd and not filter_known
falsepositives:
  - Software deployment tools staging payloads in ProgramData (validate publisher/signer)
level: high

KQL (Microsoft Sentinel / Defender)

The following hunt aggregates outbound bytes per device to spot abnormal exfiltration volume from servers and clinical/legal workstations — the single most reliable breach indicator when endpoint tooling missed the intrusion itself. The second query hunts Defender process telemetry for staging behavior matching the Sigma logic above.

KQL — Microsoft Sentinel / Defender
// Hunt 1: Devices with anomalous outbound transfer volume (potential exfiltration)
// Baseline over 14 days, flag devices whose last-24h egress exceeds 3x their daily average
let Lookback = 14d;
let Recent = 24h;
let Baseline = DeviceNetworkEvents
| where TimeGenerated between (ago(Lookback) .. ago(Recent))
| where RemoteIPType == "Public"
| summarize AvgDailyBytes = avg(tolong(todynamic(AdditionalFields).bytes_sent)) by DeviceId, bin(TimeGenerated, 1d)
| summarize BaselineAvg = avg(AvgDailyBytes) by DeviceId;
DeviceNetworkEvents
| where TimeGenerated > ago(Recent)
| where RemoteIPType == "Public"
| summarize RecentBytes = sum(tolong(todynamic(AdditionalFields).bytes_sent)), RemoteIPs = dcount(RemoteIP) by DeviceId, DeviceName
| join kind=inner Baseline on DeviceId
| where RecentBytes > (BaselineAvg * 3) and RecentBytes > 500000000
| project DeviceName, RecentBytes, BaselineAvg, Ratio = round(RecentBytes / todouble(BaselineAvg), 1), RemoteIPs
| order by RecentBytes desc;

// Hunt 2: Compression or cloud-sync staging behavior on servers and workstations
DeviceProcessEvents
| where TimeGenerated > ago(7d)
| where FileName in~ ("7z.exe","7za.exe","rar.exe","rclone.exe","megacmd.exe")
   or ProcessCommandLine has_any ("rclone copy", "rclone sync", "7z a", "rar a")
| project TimeGenerated, DeviceName, FileName, ProcessCommandLine, FolderPath, AccountName, InitiatingProcessFileName
| order by TimeGenerated desc;

// Hunt 3: M365 mailbox audit — bulk export or suspicious inbox rules (law firm / BEC angle)
// Requires OfficeActivity table from Microsoft 365 audit log ingestion
OfficeActivity
| where TimeGenerated > ago(14d)
| where Operation in~ ("New-InboxRule", "Set-InboxRule", "MailboxExportRequest", "SearchExportCreated")
| extend RuleAction = tostring(parse_json(Parameters)[0].Value)
| project TimeGenerated, UserId, ClientIP, Operation, RuleAction
| order by TimeGenerated desc;

Velociraptor VQL

This artifact hunts endpoints for staging directories and compression/sync tool artifacts — useful when triaging a suspected exfiltration host during breach response.

VQL — Velociraptor
-- Hunt for data staging artifacts: recent archives and sync tool presence
LET archive_hunt = SELECT FullPath, Size, Mtime
FROM glob(globs=['C:/Users/*/AppData/Local/Temp/*.7z',
                 'C:/Users/*/AppData/Local/Temp/*.zip',
                 'C:/Users/*/AppData/Local/Temp/*.rar',
                 'C:/ProgramData/**/*.7z',
                 'C:/ProgramData/**/*.zip'],
          accessor='ntfs')
WHERE Size > 10000000
   AND Mtime > now() - 1209600

LET tool_hunt = SELECT Pid, Name, Exe, CommandLine, Username
FROM pslist()
WHERE Exe =~ '(?i)(rclone|megacmd|7za?|winrar|rar)\.exe$'
   OR CommandLine =~ '(?i)(rclone (copy|sync|move)|7z a |rar a )'

SELECT * FROM archive_hunt
UNION ALL
SELECT Exe AS FullPath, 0 AS Size, NULL AS Mtime FROM tool_hunt

Remediation and Hardening Script

The following PowerShell performs the three highest-value hardening actions for a Windows file-server environment handling PHI or client data: enables object-access auditing on sensitive shares (so bulk reads are logged before the next breach), deploys an AppLocker deny rule for common exfiltration utilities, and validates that audit logging is actually flowing.

PowerShell
#Requires -RunAsAdministrator
# 1) Enable File System object access auditing (Success + Failure)
auditpol /set /subcategory:"File System" /success:enable /failure:enable

# 2) Apply SACLs to sensitive data roots (adjust paths to your shares)
$sensitivePaths = @('D:\Shares\PatientData', 'D:\Shares\ClientFiles')
foreach ($path in $sensitivePaths) {
    if (Test-Path $path) {
        $acl = Get-Acl -Path $path -Audit
        $rule = New-Object System.Security.AccessControl.FileSystemAuditRule(
            'Everyone','ReadData,WriteData,Delete','ContainerInherit,ObjectInherit','None','Success')
        $acl.AddAuditRule($rule)
        Set-Acl -Path $path -AclObject $acl
        Write-Output "[+] Audit SACL applied: $path"
    } else {
        Write-Output "[!] Path not found, skipped: $path"
    }
}

# 3) AppLocker deny rules for exfiltration utilities (enforce mode)
$denyTools = @('rclone.exe','megacmd.exe','megasync.exe')
foreach ($tool in $denyTools) {
    New-AppLockerPolicy -FileInformation (Get-ChildItem "C:\*\" -Filter $tool -Recurse -ErrorAction SilentlyContinue | Select-Object -First 1) -ErrorAction SilentlyContinue | Out-Null
    $rule = New-Object Microsoft.Security.ApplicationId.PolicyManagement.PolicyModel.FilePublisherRule
    # Simpler and reliable: path-based deny under user-writable dirs
}
$xml = @"
<AppLockerPolicy Version="1">
  <RuleCollection Type="Exe" EnforcementMode="Enabled">
    <FilePathRule Id="a1b2c3d4-1111-4a1a-9a1a-aa11bb22cc33" Name="Deny rclone" Description="Block rclone exfiltration utility" UserOrGroupSid="S-1-1-0" Action="Deny">
      <Conditions><FilePathCondition Path="*\rclone.exe"/></Conditions>
    </FilePathRule>
    <FilePathRule Id="a1b2c3d4-2222-4a2a-9a2a-aa11bb22cc33" Name="Deny MEGAcmd" Description="Block MEGAcmd exfiltration utility" UserOrGroupSid="S-1-1-0" Action="Deny">
      <Conditions><FilePathCondition Path="*\megacmd.exe"/></Conditions>
    </FilePathRule>
  </RuleCollection>
</AppLockerPolicy>
"@
$xml | Set-Content "$env:TEMP\applocker-deny.xml"
Set-AppLockerPolicy -XmlPolicy "$env:TEMP\applocker-deny.xml" -Merge
Set-Service AppIDSvc -StartupType Automatic; Start-Service AppIDSvc

# 4) Verify auditing is active and recent object-access events exist
$events = Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4663} -MaxEvents 5 -ErrorAction SilentlyContinue
if ($events) { Write-Output "[+] Object access auditing verified — $($events.Count) recent 4663 events." } else { Write-Output "[!] No 4663 events yet — generate file access on an audited path to confirm pipeline." }

Note: path-based AppLocker denies are a speed bump, not a wall — actors rename binaries. Pair this with the renamed-binary Sigma rule above and, where licensing permits, WDAC or AppLocker publisher rules. For the M365/mailbox side (the dominant law-firm vector), enforce phishing-resistant MFA (FIDO2/passkeys) on all mailboxes, block legacy authentication, and alert on inbox-rule creation and mailbox export operations (KQL Hunt 3).

Remediation

Because no software vulnerability is implicated, "remediation" here means breach response, regulatory execution, and architectural hardening. In priority order:

If you are Saber Healthcare, Buchalter, or a similarly situated entity responding now:

  1. Forensically establish the window of compromise. Pull EDR telemetry, M365 unified audit logs, VPN/RMM logs, and firewall egress records. The breach notification clock and your notification scope depend entirely on this timeline. OCR will ask for it.
  2. Scope the data, not just the systems. Determine exactly which files/mailboxes were accessed — HIPAA notification thresholds turn on whether PHI was actually acquired, not merely exposed. Preserve forensic images before remediation wipes evidence.
  3. Execute notification obligations on schedule. HIPAA: individuals within 60 days of discovery; HHS OCR within 60 days for 500+ affected (or annual submission for smaller incidents); prominent media notice for 500+ in a single state. State statutes may be stricter — California's breach law and CMIA apply to Buchalter; Ohio's Data Protection Act framework applies to Saber.
  4. Reset credentials comprehensively. All accounts that touched compromised systems, plus enforced phishing-resistant MFA. Assume session-token theft, not just password theft — revoke active sessions in Entra ID/M365.
  5. Engage counsel under privilege and retain a DFIR firm if internal forensics capacity is thin. Notification letters drafted without forensic certainty get retracted and re-sent — that is worse than a slightly slower, accurate notice.

If you are a healthcare organization whose data sits with outside counsel, billing vendors, or IT providers (the Buchalter lesson):

  1. Inventory where your PHI/PII actually lives downstream. Every law firm, collection agency, and consultant holding your data is a breach-notification dependency.
  2. Enforce BAAs with teeth — require security attestations (HITRUST/SOC 2), minimum MFA standards, breach notification to you within a defined window (24–72 hours), and evidence of EDR coverage.
  3. Contract for log access. You cannot meet your 60-day notification clock if your vendor takes 45 days to tell you what happened.

Standing defenses for every covered entity:

  • Deploy the detection content above; validate in audit mode first, then enforce.
  • Establish egress baselines and alert on volume anomalies — exfiltration-before-encryption is the norm.
  • Test your IR plan against a pure-data-theft scenario, not just ransomware. Most healthcare tabletop exercises still assume encryption as the trigger.

There is no vendor patch link to provide for these incidents; the authoritative references are the HHS OCR breach portal (https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf) for affected-individual verification and the HIPAA Breach Notification Rule text at 45 CFR § 164.400.

Related Resources

Security Arsenal Healthcare Cybersecurity AlertMonitor Platform Book a SOC Assessment healthcare Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.