Conduent Said 4 Million. It Was 62.2 Million. That Gap Is the Story.
On April 9, 2025, Conduent told the SEC that a breach discovered months earlier had affected roughly 4 million people. Fourteen months later, on June 4, 2026, the number Conduent's own regulatory filings settled on was 62,224,658. Not a revision. A fifteen-fold expansion, delivered across three separate disclosures, each one bigger than the last.
Track the sequence: April 2025, ~4 million. February 2026, 25.9 million — Texas residents (15.4 million) and Oregon residents (10.5 million) accounting for most of the jump. June 2026, 62.2 million, final. Third-largest healthcare data breach in U.S. history, behind only Change Healthcare and Anthem.
The reason the number kept climbing isn't that Conduent kept lying. It's that Conduent is a business associate — a vendor that processes claims and eligibility data for state Medicaid and human-services programs on behalf of the actual covered entities. A breach at a business associate doesn't announce its own size. It waits for every state customer to finish auditing its own residents' exposure and report back. Texas reports. Oregon reports. The number moves. That's not transparency working as designed — that's a structural blind spot in how business-associate breaches get measured, and Conduent is the latest example of it playing out in public.
Attackers were inside Conduent's environment from October 21, 2024, to January 13, 2025 — eighty-four days — and took more than 8 terabytes: Social Security numbers, medical information, insurance data. HIPAA's Security Rule requires covered entities and their business associates to monitor for and detect exactly this kind of intrusion. Eighty-four days of undetected access to that volume of data is not bad luck. It's a monitoring failure, full stop, and the statute puts the liability for that failure on the business associate directly, not just the state agencies that hired it.
Conduent has booked more than $41 million in breach-response costs. Divided across 62.2 million people, that's about sixty-six cents each — the price of cleanup for data that doesn't have an expiration date.
HHS's Office for Civil Rights has the authority to bring an enforcement action against a business associate for a Security Rule failure of this scale. Sixty-two million people and eighty-four undetected days is the test case. Whether OCR treats a fifteen-times undercount and a three-month dwell time as the violation it plainly is — that's the next number to watch, and it's the only one that will tell you whether "business associate liability" means anything or is just a phrase in a statute nobody enforces at this scale.