Conduent Business Solutions, a business associate for healthcare entities and government agencies, experienced a data breach affecting its systems. The breach came to light between 2025 and 2026, with the HIPAA Journal providing a summary based on regulator notifications and other reports. The incident involved the exposure of sensitive personal and health information.
The reported data types varied for individuals and clients but may have included names, dates of birth, Social Security numbers, treatment information, and claims information. Initial reports indicated at least 10,515,849 individuals were affected, with later reports by February 4, 2026, suggesting the number had risen to over 25 million. Affected individuals resided in states such as Texas, Montana, California, and New Jersey.
This incident is considered a third-party or vendor breach, impacting customers of various clients, including Blue Cross and Blue Shield plans. At least nine class action lawsuits have been filed in New Jersey federal court in response to the breach. Details about the exact date the breach occurred, when Conduent discovered it, and when consumers were notified are not explicitly stated in the provided research.