The class action lawsuits over the Conduent data breach have been consolidated into a single case in the U.S. District Court for the District of New Jersey, In Re: Conduent Business Services Data Breach Litigation, and the proceedings are currently stayed for mediation scheduled on August 13, 2026. No settlement has been reached or proposed. If mediation fails, the parties must file a joint status report and a proposed briefing schedule for Conduent’s motion to dismiss by September 10, 2026.1PacerMonitor. In Re: Conduent Business Services Data Breach Litigation
Where the Case Stands Now
At least ten class action complaints were filed in New Jersey federal court beginning in late October 2025, shortly after Conduent’s notification letters started arriving. Early-filed cases include Marshall v. Conduent Business Services, LLC (Case No. 2:25-cv-16994), filed October 28, 2025, along with Kennedy, Larson, Bianco, Fray, and Berkenfeld, among others.2ISMG. Marshall v. Conduent Business Services, LLC – Complaint1PacerMonitor. In Re: Conduent Business Services Data Breach Litigation
On November 24, 2025, the court consolidated the cases into In Re: Conduent Business Services Data Breach Litigation (Case No. 2:25-cv-16953), assigned to Judge Michael E. Farbiarz. Plaintiffs filed an Amended Consolidated Class Action Complaint on June 12, 2026. Three days later, Magistrate Judge Michael A. Hammer stayed all proceedings through September 7, 2026, to permit mediation before Judge Welsh on August 13, 2026.1PacerMonitor. In Re: Conduent Business Services Data Breach Litigation
Firms working on behalf of plaintiffs include Lite DePalma Greenberg & Afanador, Milberg, Morgan & Morgan, Edelson Lechtzin, and Wolf Haldenstein Adler Freeman & Herz, among others. A separate action was filed in federal court in Montana against Health Care Services Corporation, which licenses the Blue Cross Blue Shield brand in that state.
What the Lawsuits Claim
The consolidated complaint pulls together the theories from the individual cases: negligence, breach of implied contract, unjust enrichment, and requests for declaratory judgment. Plaintiffs allege Conduent stored sensitive data in an unencrypted, internet-accessible environment and failed to implement reasonable security measures consistent with industry standards, FTC guidelines, and HIPAA requirements.2ISMG. Marshall v. Conduent Business Services, LLC – Complaint
The relief sought includes financial damages, a court order requiring Conduent to overhaul its data security practices, and lifetime identity theft protection for affected individuals. Plaintiffs argue that the one year of credit monitoring Conduent has offered is not enough given that Social Security numbers and medical records were exposed.2ISMG. Marshall v. Conduent Business Services, LLC – Complaint Conduent denies the allegations.3TechTarget HealthTech Security. Missouri Regulators Say Conduent Is Not Cooperating in Breach Investigation
Why the Notification Delay Matters
Timing is central to the litigation. An unauthorized party accessed Conduent’s network on October 21, 2024, and stayed inside for nearly three months, until Conduent detected the intrusion on January 13, 2025.4Security Magazine. Conduent Data Breach Timeline and What to Know Notification letters did not begin going out until on or around October 24, 2025, roughly nine months after discovery.2ISMG. Marshall v. Conduent Business Services, LLC – Complaint Under HIPAA, covered entities and business associates are generally required to notify individuals within 60 days of discovery.5LlamaLab.ai. Conduent Breach: 25 Million Records Healthcare
Some downstream clients were slow as well. Blue Cross Blue Shield of Montana learned in January 2025 that it was an affected client but did not inform its members until October 2025.4Security Magazine. Conduent Data Breach Timeline and What to Know
Who the Class Covers
The potential class is very large. By June 2026, the HHS breach portal listed at least 62,224,658 affected individuals, placing the incident among the largest healthcare-related breaches in U.S. history. Early estimates had put the number above 25 million.6HIPAA Journal. Conduent Business Solutions Data Breach7Inc.com. Conduent Breach: How to Know if You’re Affected
Because Conduent processes data for other organizations, most affected people were customers or members of a Conduent client rather than of Conduent itself. Confirmed affected clients include Humana, Premera Blue Cross, Blue Cross Blue Shield of Texas, Blue Cross Blue Shield of Montana, Blue Cross Blue Shield of Illinois, Gold Coast Health Plan, and Volvo Group North America, along with the Wisconsin Department of Children and Families and Oklahoma Human Services.6HIPAA Journal. Conduent Business Solutions Data Breach8Cybersecurity Dive. Government Payments Conduent Cyberattack Texas reported roughly 15.5 million affected residents; Oregon estimated 10.5 million; Blue Cross Blue Shield of Montana said it was mailing letters to 462,000 individuals.7Inc.com. Conduent Breach: How to Know if You’re Affected
The exposed data included names, addresses, dates of birth, Social Security numbers, medical records, treatment information, health insurance details, and claims information. Not every data type was exposed for every individual.6HIPAA Journal. Conduent Business Solutions Data Breach7Inc.com. Conduent Breach: How to Know if You’re Affected
What Conduent Is Offering Now
Outside the lawsuit, Conduent has offered affected individuals one year of free credit monitoring and identity restoration services provided through Epiq under the name Privacy Solutions ID. Enrollment deadlines fall at the end of April or May 2026 depending on the specific notification received.9KY3. Conduent Data Breach: What to Do if You Got a Letter You can enroll online at privacysolutionsid.com using the activation code in your notification letter, or by calling the dedicated phone line listed in the letter.10California State Retirees. Conduent Data Incident: What CSR Members Should Know
Enrolling in the offered monitoring does not, on its own, prevent you from being included as a class member if the litigation produces a settlement or judgment. Any release of claims tied to a future settlement would come with its own notice and opt-out process handled through the court.
Regulators Working Alongside the Lawsuits
Several government investigations are running in parallel with the class action. The U.S. Department of Health and Human Services Office for Civil Rights is investigating because of the volume of protected health information involved and Conduent’s role as a HIPAA business associate. As of June 2026, the federal breach portal still listed only 42,616 affected individuals, a figure not updated even as state-level counts confirm tens of millions.11Paubox. Regulators Say Conduent Is Withholding Info as Breach Investigation Stalls
In February 2026, Texas Attorney General Ken Paxton opened a formal investigation and issued civil investigative demands to Conduent and Blue Cross Blue Shield of Texas.12Texas Attorney General. Attorney General Ken Paxton Demands Information From Blue Cross Blue Shield of Texas and Conduent Missouri’s Department of Commerce and Insurance has issued bulletins 26-05 (March 2026) and 26-08 (May 2026) directing insurers to report directly to the state, effectively bypassing Conduent. DCI Director Angela Nelson said Conduent “has not provided sufficient information for regulators to fully assess the potential impact of this breach.”13Missouri Department of Commerce and Insurance. Conduent Data Security Incident – Bulletin 26-08 Conduent has responded that it is not a DCI-licensed entity and lacks authority to share client-specific information with the department.3TechTarget HealthTech Security. Missouri Regulators Say Conduent Is Not Cooperating in Breach Investigation
If You Received a Notification Letter
Enroll in the offered credit monitoring before your deadline; the activation code and phone number are on the letter. Place a fraud alert or credit freeze with the three credit bureaus if you have not already. Keep the notification letter itself: it is the document that ties you to the affected population and will matter if a settlement produces a claims process.
Watch the docket for In Re: Conduent Business Services Data Breach Litigation, Case No. 2:25-cv-16953. The next dates that will move the case are the August 13, 2026 mediation and, if that does not resolve the matter, the September 10, 2026 joint status filing that will set the schedule for Conduent’s motion to dismiss.1PacerMonitor. In Re: Conduent Business Services Data Breach Litigation