Sep 18, 2026

News

62 Million Records, One Vendor: What the Conduent Breach Means for Your Practice's Business Associates

Sixty-two point two million people. Names, addresses, Social Security numbers, medical records, treatment and claims information. One of the largest healthcare-adjacent data breaches in U.S. history — and the organization that got breached wasn't a hospital, an insurer, or a medical practice at all.

It was Conduent: a back-office vendor that handles printing, mailing, document processing, and payment services for healthcare providers, insurers, and government agencies, including major names like Humana, Premera Blue Cross, and several Blue Cross/Blue Shield plans.

What actually happened

Attackers first gained access to Conduent's network in October 2024 and weren't detected until mid-January 2025. During those roughly three months, a threat group calling itself SafePay maintained access and ultimately claimed to have stolen 8.5 terabytes of data. Public notifications continued rolling out through 2025 as the full scope of the breach became clear, eventually reaching an estimated 62.2 million affected individuals — making it, by some counts, the third-largest healthcare data breach ever recorded.

Conduent itself never touched a patient in an exam room. It processed mail, statements, and claims paperwork on behalf of the insurers and health systems that did. That's exactly what makes this breach worth understanding.

Why a "back-office vendor" breach is a healthcare breach

Under HIPAA, an organization like Conduent is a business associate — a vendor that handles protected health information (PHI) on behalf of covered entities, bound by a Business Associate Agreement (BAA). When a business associate gets breached, the exposure flows straight back to every covered entity, and every patient, whose data passed through that vendor's systems.

This is the pattern behind almost every large healthcare breach in the last few years: the front door wasn't the hospital or the practice. It was a billing company, a scheduling platform, a document processor, or a cloud EHR vendor sitting one or two layers removed from the patient relationship.

What this means if you're a South Florida practice

Your practice almost certainly works with vendors who touch PHI without you thinking of them as "IT" at all: your billing service, your answering service, your patient reminder/texting platform, your document shredding company, your fax-to-email provider. Each one is a potential Conduent.

A few questions worth asking this quarter:

Do you have a signed, current BAA with every vendor that touches patient data — not just your EHR, but the smaller ones too? Has anyone actually reviewed what security practices those vendors follow, or did the relationship start (and stay) on trust? And if one of them were breached tomorrow, would you even find out in time to notify your patients within HIPAA's required window?

Practical takeaways

Inventory every vendor that handles PHI on your behalf, including the ones that don't feel like "tech" vendors — billing, mailing, texting, and document services all count. Confirm you have a signed BAA in place for each one, and that it's been reviewed in the last two years. Ask vendors directly what security controls they have in place and whether they've had any incidents to disclose. Build vendor breach notification into your incident response plan — know who to contact and what your notification obligations are if a vendor tells you they've been breached.

The Conduent breach is a reminder that "we didn't get hacked" isn't the same as "our patients' data is safe." For most practices, the weakest link isn't the practice itself — it's whichever vendor down the chain hasn't been asked the hard questions yet.

Get expert clarity

Asked questions:

What services do you offer?

We provide IT consulting, cloud setup, security, and automation solutions.

Do you provide ongoing support?

Yes, we offer continuous monitoring, updates, and technical support.

What is your typical project timeline?

Most projects are completed within 2–3 weeks based on scope.

Can you customize solutions for our business?

Yes, all solutions are tailored to your goals and system requirements.

How do you ensure data security?

We use advanced security protocols, monitoring, and compliance practices.

Get expert clarity

Asked questions:

What services do you offer?

We provide IT consulting, cloud setup, security, and automation solutions.

Do you provide ongoing support?

Yes, we offer continuous monitoring, updates, and technical support.

What is your typical project timeline?

Most projects are completed within 2–3 weeks based on scope.

Can you customize solutions for our business?

Yes, all solutions are tailored to your goals and system requirements.

How do you ensure data security?

We use advanced security protocols, monitoring, and compliance practices.

Start your journey

Build smarter systems and grow with confidence

Start your journey

Build smarter systems and grow with confidence