June 2026: The victim count for Conduent Business Services did not inch upward—it ballooned to 62,224,658 people. That figure, filed with the U.S. Department of Health and Human Services Office for Civil Rights, makes the incident the third-largest healthcare data breach in American history, behind only Change Healthcare (~192.7 million, 2024) and Anthem (~78.8 million, 2015), per HIPAA Journal reporting.
Conduent is not a hospital you visited once. It is the back-office machine behind your insurer's mailroom—printing ID cards, processing claims paperwork, running payment-integrity checks for health plans and government agencies. When that vendor loses control of files for three months, the blast radius is every plan member whose data passed through its systems.
What happened
Conduent Business Services, a New Jersey-based unit of Conduent Inc., first spotted unauthorized activity on January 13, 2025. Forensics walked the timeline backward: initial access on October 21, 2024, with the intruder inside for roughly three months before Conduent locked them out.
The SafePay ransomware group claimed the attack in February 2025, advertising 8.5 terabytes of stolen data on its leak site. Conduent later disappeared from that blog—often a sign of negotiation, though groups also fabricate victim lists. What is not in dispute: Conduent told the SEC in an 8-K filing that a threat actor exfiltrated files holding customer data and data belonging to those customers' members—exactly the nested PHI problem HIPAA business associates create.
Notification letters did not start mailing until October 2025, nearly a year after the first compromise. That lag is now fuel for class actions and state investigations, not just angry tweets.
How 10.5 million became 62.2 million
The count kept climbing as Conduent finished file reviews state by state:
- October 2025: Oregon attorney general filings cited 10.5 million nationwide—already one of the largest healthcare breaches announced that year, per BleepingComputer.
- February 2026: Texas alone reported 15.49 million affected residents; Oregon/Texas combined implied 25 million+ Americans.
- June 2026: HHS OCR received 62,224,658—the number that puts Conduent on the all-time podium.
Why the gap? Conduent processes documents for dozens of covered entities. Each client's file layout differs; deduplicating individuals across overlapping plan populations takes months. HIPAA Journal also notes the true total could rise further if every affected insurer delegated notification duties differently.
What was exposed
There is no single uniform dump. State breach notices describe a mix that can include:
- Full names, dates of birth, and mailing addresses
- Social Security numbers
- Treatment and diagnosis information
- Claims and billing details
- Health insurance policy and member identifiers
That is enough to commit medical identity theft—not just open a credit card. Fraudulent clinic visits billed to your policy show up as dull Explanation of Benefits paperwork, not dramatic dark-web screenshots.
Who got hit downstream
Conduent's healthcare client roster reads like a who's who of U.S. coverage:
- Humana — top-five national insurer
- Premera Blue Cross — largest insurer in the Pacific Northwest
- Blue Cross Blue Shield of Texas — Texas AG Ken Paxton says 15.49 million+ Texans affected; his office opened a formal investigation in February 2026
- Blue Cross Blue Shield of Montana — ~462,000 notification letters
- Employer and government programs that relied on Conduent mailroom and document services
You may never have heard of Conduent until a letter arrived naming your health plan as the covered entity. That is normal for business-associate breaches—and exactly why vendor risk is patient risk.
Regulators are done waiting
Federal OCR scrutiny is expected on an incident this size—Change Healthcare set the precedent for high-impact HIPAA enforcement. But in 2026 the louder frustration is coming from states.
Missouri's Department of Commerce and Insurance issued bulletins accusing Conduent of stonewalling requests about Missouri policyholders, escalating to insurers directly when the vendor would not answer. Texas AG Paxton demanded records from BCBS Texas and Conduent about security practices. Montana officials opened a parallel probe tied to the BCBS Montana vendor relationship.
Conduent told HIPAA Journal it cooperates "to the full extent possible" without breaking client contracts—and that it lacks visibility into which clients hold state insurance licenses. Victims hear that as corporate opacity; regulators hear it as noncompliance.
What Conduent says about misuse
A Conduent spokesperson told reporters the company engaged third-party forensics, notified clients and authorities, mailed victim letters on clients' behalf, and—critically—had seen no evidence stolen data was misused, posted, or made publicly available as of early 2026. Absence of proof is not proof of absence, especially ten months after exfiltration. SafePay's 8.5 TB claim has not been fully validated in public filings.
Conduent booked roughly $25 million in breach-response costs and offered many victims 12 months of complimentary credit monitoring. Missouri's bulletin noted enrollment deadlines for that monitoring had already passed for some residents—leaving freeze-and-monitor as the practical fallback.
What you should do
If a letter names Conduent, your health plan, or a BCBS/Humana/Premera program:
- Freeze credit at Equifax, Experian, and TransUnion if SSNs were involved—free and stronger than a fraud alert alone.
- Scrutinize Explanation of Benefits statements for doctor visits, labs, or devices you never received.
- Enable MFA on your insurer's member portal and the email account tied to plan communications.
- Reject "urgent verification" calls citing your real plan name or breach date—look up insurer numbers yourself.
- Document everything if you dispute fraudulent medical bills; medical identity theft is harder to unwind than a bad credit-card charge.
No letter yet but you are a Humana, Premera, or BCBS member in a disclosed state? You are allowed to act now. Waiting for postage is how people learn about exposure from a collections call instead of a notice.
Why this breach still matters in July 2026
Conduent sits in the shadow of Change Healthcare, but 62 million people is not a footnote—it is roughly one in five Americans with some connection to the affected files. The lesson for the industry is the same as UnitedHealth's catastrophe: a single BPO with broad PHI access is a concentration risk. For individuals, the lesson is simpler: your data left a vendor you never chose, and the count may still not be final.
Canonical record
BreachHistory entry: Conduent Business Services 2025 breach (62.2M+ OCR update, 2026).
Sources: HIPAA Journal, BleepingComputer, BleepingComputer (SEC 8-K), HIPAA E-Tool, Texas Attorney General.