62.2 Million Records: The Conduent Breach and Why "We're Just a Vendor" Isn't a Defence
Conduent's breach became the third-largest in US healthcare history after its confirmed victim count nearly tripled — a reminder that vendors carry the same breach obligations as the businesses they serve.
What happened
Conduent Business Services, which provides back-office processing, billing, and document handling for health plans, government agencies, and large employers, discovered on 13 January 2025 that attackers had been inside its network since the previous October. The SafePay ransomware group claimed responsibility for stealing multiple terabytes of data.
The scale kept growing. As of February 2026, state regulators had confirmed around 25 million affected individuals. By mid-2026, the US Department of Health and Human Services' Office for Civil Rights confirmed the real number: 62,224,658 people — making it the third-largest healthcare data breach ever recorded, behind only the 2024 Change Healthcare breach (192.7 million records) and the 2015 Anthem breach (78.8 million).
Conduent's direct breach-response costs hit $25 million in Q1 2025 alone, with a further $16 million anticipated through Q1 2026.
Why this matters even if you're not a healthcare giant
Conduent isn't a healthcare provider itself — it's a business associate, a vendor that processes data on behalf of the organisations that actually hold the customer relationship. Under both US HIPAA rules and UK/EU GDPR's equivalent "data processor" obligations, that distinction doesn't reduce liability. If your business handles data on behalf of another company — payment processing, booking systems, appointment scheduling, printing and mailing — you carry real breach-notification and security obligations even though you're not the brand the end customer thinks they're dealing with.
What smaller processors and subcontractors should check
- Do you actually know what data-processing obligations are in your contracts with the businesses you work for?
- Do you have cyber insurance, and does it cover incident response costs at a scale that matters to your business?
- Would you detect an intrusion in under three months? Conduent's attackers had roughly that long before discovery.
Sources: Paubox, HIPAA Journal
$ ./get-your-score
Get a free Security Score for your site
Automated TLS, headers, DNS, and exposure checks — results in under a minute.
Request a free scan