Sep 18, 2026
News
Conduent Breach: A Business Associate Risk


Sixty-two point two million people. Names, addresses, Social Security numbers, medical records, treatment and claims information. One of the largest healthcare-adjacent data breaches in U.S. history — and the organization that got breached wasn't a hospital, an insurer, or a medical practice at all.
It was Conduent: a back-office vendor that handles printing, mailing, document processing, and payment services for healthcare providers, insurers, and government agencies, including major names like Humana, Premera Blue Cross, and several Blue Cross/Blue Shield plans.
What actually happened
Attackers first gained access to Conduent's network in October 2024 and weren't detected until mid-January 2025. During those roughly three months, a threat group calling itself SafePay maintained access and ultimately claimed to have stolen 8.5 terabytes of data. Public notifications continued rolling out through 2025 as the full scope of the breach became clear, eventually reaching an estimated 62.2 million affected individuals — making it, by some counts, the third-largest healthcare data breach ever recorded.
Conduent itself never touched a patient in an exam room. It processed mail, statements, and claims paperwork on behalf of the insurers and health systems that did. That's exactly what makes this breach worth understanding.
Why a "back-office vendor" breach is a healthcare breach
Under HIPAA, an organization like Conduent is a business associate — a vendor that handles protected health information (PHI) on behalf of covered entities, bound by a Business Associate Agreement (BAA). When a business associate gets breached, the exposure flows straight back to every covered entity, and every patient, whose data passed through that vendor's systems.
This is the pattern behind almost every large healthcare breach in the last few years: the front door wasn't the hospital or the practice. It was a billing company, a scheduling platform, a document processor, or a cloud EHR vendor sitting one or two layers removed from the patient relationship.
What this means if you're a South Florida practice
Your practice almost certainly works with vendors who touch PHI without you thinking of them as "IT" at all: your billing service, your answering service, your patient reminder/texting platform, your document shredding company, your fax-to-email provider. Each one is a potential Conduent.
A few questions worth asking this quarter:
Do you have a signed, current BAA with every vendor that touches patient data — not just your EHR, but the smaller ones too? Has anyone actually reviewed what security practices those vendors follow, or did the relationship start (and stay) on trust? And if one of them were breached tomorrow, would you even find out in time to notify your patients within HIPAA's required window?
Practical takeaways
Inventory every vendor that handles PHI on your behalf, including the ones that don't feel like "tech" vendors — billing, mailing, texting, and document services all count. Confirm you have a signed BAA in place for each one, and that it's been reviewed in the last two years. Ask vendors directly what security controls they have in place and whether they've had any incidents to disclose. Build vendor breach notification into your incident response plan — know who to contact and what your notification obligations are if a vendor tells you they've been breached.
The Conduent breach is a reminder that "we didn't get hacked" isn't the same as "our patients' data is safe." For most practices, the weakest link isn't the practice itself — it's whichever vendor down the chain hasn't been asked the hard questions yet.
Get expert clarity
Frequently asked questions
Can my staff use the free version of ChatGPT or Claude at work?
Yes, for tasks with no patient information at all, like drafting a generic handout or a job posting. Never for anything touching a patient’s chart or PHI, per both companies’ own consumer terms.
What is a BAA and why does it matter for AI tools?
A Business Associate Agreement is a signed contract required under HIPAA before any vendor can touch PHI on your behalf. Anthropic and OpenAI only offer BAAs on business-tier or API plans, and it must be separately executed, not assumed from a paid subscription.
Does paying for ChatGPT Plus or Claude Pro make it HIPAA-compliant?
No. Both companies state that even paid individual consumer accounts (Plus, Pro, Max) are not covered by a BAA and PHI should not be entered into them.
What should our practice do before letting staff use AI with patient information?
Confirm a business-tier account is provisioned with an executed BAA, set a written policy distinguishing PHI from non-PHI use cases, and fold AI access into your existing audit-logging and access-review process.
How does UpsiteGroup help with this?
We confirm which AI tools your staff can access, verify a BAA is actually on file (not just technically available), and manage AI access controls alongside your EHR’s existing security configuration.

