A breach reported at 10 million victims in February is now confirmed at 62.2 million in July

Conduent didn't get hacked five more times. It just took that long to find out how big the first one was.

Conduent Business Services, a back-office vendor serving hundreds of healthcare covered entities, now ranks third-largest healthcare data breach in US history — behind only Change Healthcare (192.7M) and Anthem (78.8M).

WHAT ACTUALLY HAPPENED

Hackers were inside Conduent's servers from October 21, 2024 to January 13, 2025 — nearly three months before discovery. Conduent filed an initial breach report with HHS OCR in October 2025 using a placeholder figure. From there, the number climbed in waves as state Attorney General filings landed: 10.5 million in Oregon, 15.5 million in Texas alone, each representing a separate round of client-by-client review. The final confirmed total — names, addresses, dates of birth, Social Security numbers, health insurance details, and medical information for 62.2 million people — took nearly a year to fully establish after the intrusion ended.

WHY ONE VENDOR BREACH BECOMES HUNDREDS OF NOTIFICATIONS

Conduent doesn't hold one organization's data — it processes back-office functions for hundreds of separate healthcare covered entities simultaneously. Determining breach scope isn't counting rows in one database; it's reconciling which records belonged to which client, under which contract, subject to which state's notification law. That reconciliation work is combinatorial, not linear, which is exactly why the number kept climbing for the better part of a year instead of being final on day one.

WHAT TO DO NOW

IF A VENDOR TOUCHES YOUR CUSTOMERS' PHI, DEMAND A SCOPE-DETERMINATION TIMELINE IN THE BAA — "we'll let you know" is not an acceptable answer to "how long until we know the real number."

TREAT AN EARLY VICTIM COUNT AS A FLOOR, NOT A FINAL FIGURE — build your own incident response around the assumption that vendor breach numbers grow.

CHECK WHETHER THIS VENDOR TOUCHED YOUR DATA EVEN IF YOU WEREN'T IN THE FIRST NOTIFICATION WAVE — client-by-client review means later waves catch relationships the vendor initially missed.

BUILD YOUR OWN VENDOR BREACH ESCALATION PATH NOW — waiting for a vendor's placeholder number to become real is not a monitoring strategy.

A breach notification isn't finished when it's filed. This one took nine months after filing to reach its real size — and the people affected had no way to know that while they waited.

Do you know which of your vendors' past breach disclosures are still placeholder numbers waiting to grow?
Turn the analysis into a plan

The gap between knowing the risk and closing it is a purchase order and a weekend.

We specify, source and deploy the equipment that closes it — firewalls, segmentation, secure remote access — and we support it afterwards.