Conduent, a back-office contractor that processes documents, claims and benefits paperwork for health insurers and government agencies, is now confirmed to have exposed the personal records of more than 62 million people in one of the largest data breaches ever recorded. The stolen files included Social Security numbers and medical information, the two categories that do the most lasting damage once they leak. For retirees who rely on Medicare, Medicaid and private health plans, the exposure creates a durable risk of identity theft and medical-billing fraud that can surface months or years after the fact.
How the Conduent Total Reached 62 Million
The scale climbed steadily as investigators reviewed which clients’ records were caught in the incident. The federal government’s breach portal, run by the Department of Health and Human Services Office for Civil Rights, now lists the exposure at 62,224,658 individuals, according to an analysis by the HIPAA Journal, making it the third-largest healthcare-linked breach on record. Because Conduent handles paperwork for many separate insurers and agencies, the count grew as each client’s affected population was tallied and folded into a single filing, rather than from a new attack.
The underlying intrusion itself was not recent. Conduent has said attackers accessed parts of its network between October 2024 and January 2025, when the activity was detected, and notifications went out to affected people in waves through 2025 and into 2026 as the review widened. What changed this year is the confirmed total, which consolidated regional disclosures — including more than 15 million people in Texas alone — into the 62 million-plus figure now on the federal record.
Free retirement updates: Scam calls targeting retirees change every week. Our free Retirement Shield newsletter flags the ones going around and the one tell that stops each. Sign up free.
Why Medical Records and Social Security Numbers Cost Real Money
A Social Security number is the master key to a person’s financial identity, and unlike a password it effectively cannot be changed. Criminals use stolen numbers to open credit lines, file fraudulent tax returns and claim benefits under another name. The Social Security Administration warns on its scam-reporting page that number misuse often shows up first as an unexpected benefit change, a denied claim or a tax notice for income the victim never earned. When a number is paired with a date of birth and address, as in the Conduent files, the barrier to impersonation nearly disappears.
Medical records add a second, less familiar danger: medical identity theft. A thief who holds someone’s health-insurance and Medicare details can obtain care, prescriptions or equipment billed to the victim’s account, corrupting the medical file and draining benefit limits. Older adults are especially exposed because Medicare fraud is a heavily targeted scheme, and a fraudulent claim can go unnoticed until a legitimate one is denied or a surprise bill arrives. Untangling a contaminated medical record is slow and can require disputing charges with multiple providers and insurers at once, sometimes over many months.
The combination of both data types in a single breach is what makes the Conduent exposure so damaging. A Social Security number opens financial accounts, while medical and insurance details support health-care fraud and lend credibility to targeted scams, and the two together give criminals far more room to operate than either would alone. Security researchers note that stolen medical records also tend to sell for more than payment-card data on illicit markets, precisely because they cannot be quickly canceled and can be exploited long after a breach fades from the headlines.
State Regulators Are Pressing Conduent for Answers
The breach has drawn formal government scrutiny. The Texas attorney general’s office announced that it issued Civil Investigative Demands to Conduent and Blue Cross Blue Shield of Texas, describing the incident as potentially the largest data breach in U.S. history and demanding documents on how the exposed data of roughly four million Texans was protected. Multiple class-action lawsuits have also been consolidated in federal court, alleging that Conduent failed to safeguard the data and was too slow to notify the public. Those cases remain in progress, and no findings of liability have been entered.
What Consumer Officials Recommend for Affected People
The remedies for this kind of exposure are well established. The Federal Trade Commission’s identity-theft recovery service at IdentityTheft.gov walks victims through placing a free credit freeze, filing an official identity-theft report and disputing fraudulent accounts. For the medical side, officials advise reviewing the explanation-of-benefits statements from Medicare and private insurers for care never received, and reporting anything unfamiliar promptly, because catching a false claim early limits the cleanup.
Breach victims are also frequent targets of follow-on fraud. Scammers posing as Conduent, an insurer, Medicare or a government agency often call using details from the leak to sound legitimate, then push for a Social Security number, a payment or account access. Government agencies do not call to demand immediate payment or threaten arrest, and a genuine breach notice never requires a recipient to verify sensitive information over the phone. With a breach this large, the safer assumption is that the data is already circulating, which makes a proactive credit freeze the single most protective step available.
This article was researched and drafted with AI assistance and reviewed against the linked primary sources.
More Financial Reading
- What really happens to your joint savings account when you die?
- Bank statements: how long to keep them and when to toss them



