Conduent data breach (2025): what was exposed and what to do
We publish these pages from public notices and reporting so you can understand what was exposed. Everything here is already public. Always confirm with the organization named in your notice.
Conduent data breach (2025): what was exposed and what to doBy Delist Editorial Team · Updated September 28, 2026 · Corrections
September 28, 2026
What happened
Conduent Business Services LLC, a New Jersey–based business-process / back-office vendor that provides printing, mailing, document processing, payment integrity, and related services to health plans, providers, and government agencies, disclosed a cybersecurity incident after discovering unauthorized network access.
Date labels matter. Conduent’s own Notice of Data Incident and client notices (including Premera Blue Cross and Massachusetts AG sample letters) say the company discovered the incident on January 13, 2025, and that an unauthorized third party accessed its environment from October 21, 2024, through January 13, 2025. Consumer and AG notifications scaled through late 2025 into 2026 as file review continued. On June 4, 2026, HIPAA Journal reported that Conduent’s updated total to HHS OCR put compromised protected health information at 62,224,658 individuals—making it one of the largest healthcare-sector breaches on the OCR track (third-largest in common tallies behind Change Healthcare and Anthem, per HIPAA Journal / Paubox). The HHS OCR breach portal is the federal listing surface for large PHI incidents; portal row fields can lag or show interim counts while investigations continue—prefer the June 2026 updated total as reported by HIPAA Journal / HIPAA Guide / Paubox when citing the 62.2M lock.
Earlier AG/state snapshots were lower and grew over time (for example, multi-million Oregon/Texas figures and interim ~10.5M / ~25M waves in late 2025–early 2026 press before the HHS update). Use the HHS-linked 62,224,658 figure as the current regulatory scale lock cited in June 2026 coverage, and treat earlier interim totals as superseded snapshots. SafePay ransomware claims of multi-terabyte theft circulated in early 2025 press—label those as actor claims unless mirrored in an official notice.
Clients named in public reporting have included health plans such as Humana, Premera Blue Cross, and various Blue Cross Blue Shield plans (including Texas and Montana in press summaries), plus some employer/BA clients. Exact membership impact varies by plan; your letter from Conduent or your health plan is authoritative for you. Premera’s October 21, 2025 member notice states the incident did not involve Premera’s IT systems.
Sources
- Notice of Data Incident – Conduent Business Services
- Notice of Conduent Data Security Incident – Premera Blue Cross (Oct 21, 2025)
- Massachusetts AG sample consumer notice – Conduent Business Services LLC
- Conduent Business Services Data Breach Affected More Than 62.2 Million Individuals – HIPAA Journal (Jun 4, 2026)
- Conduent Business Services Confirms 2024 Data Breach Affected 62.2 Million Individuals – The HIPAA Guide
- Conduent breach hits 62M, ranking third largest in US healthcare history – Paubox
- HHS OCR Breach Portal (Cases Currently Under Investigation)
What data was exposed
Across Conduent’s company notice, Premera’s client notice, AG sample letters, and HIPAA Journal / HIPAA Guide summaries, impacted data has varied by individual and client and has included combinations of:
- Names
- Social Security numbers
- Medical / treatment / claims information (PHI)
- Health-insurance / member identifiers
- Dates of birth (named in Premera’s field list)
- Treatment cost, admission/discharge dates, claim numbers (as listed by Premera for some members)
Exact fields vary. Rely on the notice you were mailed by Conduent or your covered-entity health plan. Conduent’s web notice lists a dedicated line at (855) 403-1589.
Breach details
| Detail | Value |
|---|---|
| Breach name | Conduent Business Services LLC (HIPAA business associate) |
| Date | Intrusion window Oct 21, 2024 – Jan 13, 2025 (discovery Jan 13, 2025) |
| Disclosed | Company / client notices from ~2025; large-scale consumer mail from ~Oct 2025; HHS OCR total update reported Jun 4, 2026 |
| Accounts affected | 62,224,658 (HHS OCR update as reported by HIPAA Journal / HIPAA Guide / Paubox, Jun 2026). Earlier AG interim totals were lower. |
| Domain | conduent.com |
This summary is compiled from public notices and reporting available when this page was last updated. Figures reflect what those sources report and may change as investigations continue. If something here looks wrong or you think your information is involved, contact our support team.
We report breaches as a factual record to help people check their exposure. Inclusion here is not an allegation of wrongdoing or negligence by Conduent; it reflects a publicly reported security incident.
For whether your information was involved and for official remediation offers, rely on notices from the organization named above (or from anyone they say will contact you) — not this page alone.
What to do now
This page is coverage-first, like other large BA / health-plan vendor incidents on this site—not a Demand-first HIPAA scare:
- Freeze credit at Equifax, Experian, and TransUnion if your notice names a Social Security number. See how to freeze your credit.
- Enroll in any credit monitoring offered in your letter only through printed channels (Massachusetts sample letters name Epiq / Privacy Solutions ID for 12 or 24 months depending on the wave; Premera’s member notice described two years from Conduent). Deadlines and codes vary—use yours.
- Review Explanation of Benefits, health-plan portals, and claims history for unfamiliar providers or services.
- Treat cold “Conduent breach settlement” or “HIPAA payout” outreach as suspect unless it matches a court-approved administrator you can verify independently.
- Keep your letter; it documents which fields and which plan applied to you.
See first 48 hours after a data breach and a company emailed me about a breach.
How this shows up on the open web
Names, dates of birth, and addresses are the same fields people-search sites and data brokers already publish. When those sit next to health-plan context from a breach notice, scam calls can sound more tailored. Run a free open-web scan to see what is already findable about you. Delist does not claim to have scanned Conduent’s systems or this incident’s files, and it does not remove dump copies.
Related health-sector coverage: DentaQuest (2026), AdaptHealth (2026), and Three Oaks Hospice (2026).
I got a Conduent or health-plan letter about this breach—what first?
Freeze credit if your notice names an SSN. Review claims/EOBs for unfamiliar activity. Enroll in monitoring only through printed channels. This page is coverage + soft open-web CTA, not a Demand scare.
Frequently asked questions
How many people did HHS say were affected?
HIPAA Journal reported on June 4, 2026, that Conduent’s updated total to HHS OCR was 62,224,658 individuals with PHI compromised (also summarized by HIPAA Guide and Paubox). Earlier state/AG interim totals were lower as file review continued.
When did the hacking actually happen?
Conduent’s company notice, Premera’s client notice, and Massachusetts AG sample letters describe unauthorized access from October 21, 2024, through January 13, 2025 (discovery January 13, 2025). Consumer notices and the large HHS total came later in 2025–2026—label intrusion vs notice dates separately.
Was my health insurer breached, or only a vendor?
Conduent is a business associate / back-office vendor to health plans and agencies. Your notice may come from Conduent and/or your plan. Premera’s notice states Premera’s IT systems were not involved. Public reporting also named clients such as Humana and various BCBS plans—your letter is authoritative for you.
Can Delist remove my PHI from the Conduent files?
No. Delist does not scrub BA systems or breach dumps. A free scan checks open-web people-search and broker listings only.
What to do after a breach
- A company emailed me about a breach: what should I do?
- Dark web data versus data brokers
- What to do after a data breach
- DentaQuest breach (2026)
- AdaptHealth breach (2026)
- Three Oaks Hospice breach (2026)
- First 48 hours after a data breach
- Got a breach email?
- How to freeze your credit
A free Delist scan checks open-web exposure we support: people-search sites, public records, data brokers, and breach-source signals. Signals are not live listings, and this is not removing you from a dump, a DMV database, or a vendor's private ID store.
More breaches
Free personal data exposure scan
We search the open web for your personal data and show what’s exposed. The scan is free. Removal and monitoring require a paid plan.