Court Rules
All enforcement actions
InvestigationCritical Risk

Texas AG Issues CIDs to BCBS and Conduent Over 4M Texans' Health Data Breach

Blue Cross Blue Shield of Texas and Conduent Business Services LLCFebruary 12, 2026Texas Attorney General

Consumers Affected

4,000,000

Summary

Texas Attorney General Ken Paxton issued Civil Investigative Demands to Blue Cross Blue Shield of Texas and Conduent Business Services LLC as part of an investigation into a massive data breach at Conduent that exposed the protected health information of approximately four million Texans. The breach occurred between October 21, 2024 and January 13, 2025, affecting Texas Medicaid recipients and other residents. The AG's office is investigating the security failures and compliance with Texas law.

Contract Impact

In-house legal teams should review all contracts with third-party service providers handling protected health information or other sensitive consumer data, ensuring they include robust data security safeguard requirements, clear breach notification timelines, and liability provisions for security failures. Contracts with vendors processing health data should specifically require compliance with applicable state and federal health privacy laws, regular security audits, and incident response protocols. Additionally, teams should verify that vendor agreements include provisions for prompt notification of any unauthorized access to data, as well as indemnification for breaches caused by vendor negligence.

Contract Search Terms

protected health information (PHI)data security safeguardsthird-party vendor data protectionbreach notification requirementssystem security audithealth data complianceincident response planvendor security assessment

Violation Types

Entity Details

Entity

Blue Cross Blue Shield of Texas and Conduent Business Services LLC

Also known as: Blue Cross Blue Shield and Conduent

Industry

Insurance

Official Sources

Source Evidence

Entity Name
"Blue Cross Blue Shield of Texas (“BCBS”) and Conduent Business Services LLC (“Conduent”)"
Consumers Affected
"exposed the sensitive personal data of approximately four million Texans"
Violation Types
"breach of Conduent’s system security that occurred between October 21, 2024 through January 13, 2025. During the breach, an unauthorized third-party accessed the protected health information of Texas residents, including Texas Medicaid recipients"
Jurisdiction
"Attorney General Ken Paxton"
Event Type
"part of the investigation of the Conduent data breach"
Entity Industry
"any insurance giant cut corners"

Related Enforcement Actions

TX

Tris Pharmaceuticals

$7.5M

Texas Attorney General Ken Paxton announced a $7.5 million settlement with Tris Pharmaceuticals over alleged misrepresentations about the efficacy of Dyanavel XR, an ADHD drug marketed for children. The release says the company overstated the drug’s efficacy and directed sales representatives to make misleading claims to doctors, including Medicaid providers.

TX

Plum Organics

Texas Attorney General Ken Paxton announced an agreement with Plum Organics requiring stronger testing and limits for heavy metals in covered baby food products, along with publicly accessible testing results. The release does not state a monetary penalty; the agreement follows an ongoing investigation into baby food manufacturers.

TX

Health Care Service Corporation (including Blue Cross and Blue Shield of Texas)

Texas Attorney General Ken Paxton opened an investigation into Blue Cross and Blue Shield of Texas, its parent Health Care Service Corporation, and related entities over alleged denials or delays of urgent and medically necessary care and potentially burdensome prior authorization requirements. The investigation is ongoing; the Attorney General issued a Civil Investigative Demand to obtain information and assess potential violations of Texas law.

TX

N/A (consumer alert; no enforcement target)

Texas Attorney General Ken Paxton issued a consumer alert warning Texas businesses and nonprofits about a surge of demand letters alleging California Invasion of Privacy Act (CIPA) violations based on common website technologies such as cookies, pixels, and analytics tools. The AG cautions that some letters may exaggerate or misrepresent violations and may be fraudulent, noting serial CIPA plaintiff Vivek Shah has been declared a vexatious litigant. Recipients are advised not to pay or respond directly, to consult privacy counsel, and to report suspected fraud to the Consumer Protection Division.

TX

TikTok

A Texas state district court (Judge Cory Liu) has found TikTok liable for lying to parents about the safety of its platform and for exposing children to inappropriate and explicit content, making Texas the first state in the nation to hold TikTok liable on these claims. The court found that although TikTok claimed it would remove graphic videos depicting drugs, nudity, alcohol, injuries, and profanity, such videos remained accessible to minors, even under 'Restricted Mode.' No penalty has been imposed yet; Attorney General Paxton will proceed to trial, expected next month, where relief and penalties will be determined.

TX

TriWest Healthcare Alliance Corp.

Texas Attorney General Ken Paxton opened an investigation into TriWest Healthcare Alliance Corp., the U.S. government contractor that administers the VA Community Care Network and the Defense Health Agency's TRICARE West Region, over reports that it wrongfully denied health care claims by falsely treating insureds as having other health insurance (OHI). The OAG has issued Civil Investigative Demands (CIDs) and plans to interview consumers and employees to determine whether TriWest violated the Texas Deceptive Trade Practices Act. No findings or penalties have been imposed yet.