Quick Answer: Conduent Data Breach Lawsuit 2026
The Conduent data breach exposed the personal and protected health information of 62.2 million Americans — the third-largest healthcare data breach in US history. The intrusion ran from October 21, 2024 to January 13, 2025 at Conduent Business Services, which processes back-office data for major US health insurers. As of September 2026, no settlement exists, no claim form is available, and more than 35 class actions have been consolidated in the US District Court for the District of New Jersey before Judge Michael A. Hammer. There is nothing to file today — but you should still protect yourself now.
What Happened in the Conduent Breach
Between October 21, 2024 and January 13, 2025, hackers had access to systems at Conduent Business Services LLC, a New Jersey-based company that provides back-office processing, eligibility verification, and claims handling for some of the largest health insurers in the United States. Most affected consumers never heard of Conduent — they interacted with it through insurers like Blue Cross Blue Shield plans in Texas, Illinois, Montana, New Mexico, and Oklahoma (operated by Health Care Service Corporation) and other large carriers that outsource back-office work to Conduent.
The exposed data included names, addresses, dates of birth, Social Security numbers, email addresses, phone numbers, and clinical or health-insurance information. Conduent first disclosed the incident to its insurer clients in early 2025, but it took nearly ten months for breach notification letters to reach most affected consumers — letters were postmarked October 24, 2025 and did not arrive at many homes until late January 2026.
How the Case Stands in 2026
| Detail | Information |
|---|---|
| Total affected | 62,224,658 (revised upward multiple times) |
| Breach period | October 21, 2024 – January 13, 2025 |
| Notification letters | Postmarked October 24, 2025 |
| Class actions filed | 35+ (consolidated) |
| Court | U.S. District Court, District of New Jersey |
| Judge | Hon. Michael A. Hammer |
| Defendants | Conduent Business Services, Health Care Service Corporation (BCBS), AIG Procurement Services |
| Plaintiffs' Steering Committee | Appointed December 22, 2025 |
| Consolidated complaint | Filed March 18, 2026 |
| Status | Early-stage litigation, no settlement yet |
| Free credit monitoring | Enrollment closed March 31, 2026 |
Why the Number Keeps Climbing
Conduent's first public count of affected individuals was 10.5 million. By mid-2026, after additional forensic review, the figure had been revised to more than 62.2 million — a sixfold increase. Forensic investigations in healthcare breaches routinely reveal more affected records than initial estimates, because the compromised systems often process data across multiple client relationships and historical timeframes. Plaintiffs in the lawsuits argue that Conduent deliberately lowballed the initial disclosure to limit reputational damage and that the true scope was apparent internally far earlier.
What to Do Right Now
Even though there is no settlement to claim, you should take protective action today. If your data was exposed, your Social Security number and clinical history are now in criminal hands — and that exposure does not expire when the lawsuit ends.
- Place a free fraud alert. Contact any one of the three credit bureaus (Equifax, Experian, TransUnion) to place a one-year fraud alert. The bureau you contact is required to notify the other two.
- Consider a credit freeze. A credit freeze is stronger than a fraud alert — it prevents new credit from being opened in your name entirely. Freezes do not affect your existing credit and can be lifted temporarily when you apply for new credit.
- Get an IRS Identity Protection PIN. Tax-related identity fraud is one of the most common consequences of a healthcare breach. An IRS IP PIN prevents anyone from filing a tax return in your name without a six-digit code you control.
- Review your EOBs. Your Explanation of Benefits statements from your health insurer may show services you did not receive — a sign someone is using your medical identity. Report anything suspicious to your insurer.
- Monitor your credit reports. You can request free weekly reports from all three bureaus at AnnualCreditReport.com. Look for inquiries or accounts you do not recognize.
Watch Out for Scam Claim Sites
Scammers regularly set up fake claim websites targeting people affected by major data breaches. As the Conduent case progresses, expect websites that look official but ask for an upfront fee or your bank details to process a non-existent payment. No legitimate claim form exists for Conduent today. The only official updates will come through the US District Court for the District of New Jersey docket and through official breach notification letters from your health insurer.
Estimated Timeline to Resolution
Healthcare class actions of this size typically take two to four years to resolve. The realistic timeline:
- Late 2026: Motions to dismiss ruled on; case moves toward discovery or settlement talks.
- 2027: Possible preliminary settlement approval and a claims process opens.
- 2028: Final approval hearing and payments begin.
Conduent has already spent more than $9 million on breach notification and expects another $16 million in costs by the first quarter of 2026. That spending is a leading indicator that defendants are treating the case as a material exposure — which usually correlates with a willingness to negotiate a meaningful settlement.
For broader guidance on responding to a data breach and whether to consider data breach insurance, see our complete guide to data breach insurance and consumer response.






