Texas Attorney General Ken Paxton issued Civil Investigative Demands to Blue Cross Blue Shield of Texas and Conduent Business Services LLC as part of an investigation into a data breach that exposed the protected health information of approximately four million Texans. The breach, which occurred between October 21, 2024 and January 13, 2025, is believed to be the largest in U.S. history. The investigation focuses on Conduent's security measures and BCBS's compliance with state data protection laws.
In-house legal teams should immediately review all vendor, customer, and data processing agreements where Conduent Business Services LLC or similar service providers handle protected health information or sensitive personal data. Focus on clauses governing data security obligations, breach notification timelines and procedures, compliance with state-specific data protection laws (particularly Texas), data processing addendums, and indemnification/liability provisions. Given the investigation into potential negligence and the scale of the breach, contracts may require amendments to mandate stricter security safeguards (e.g., encryption, access controls), explicit adherence to Texas data protection statutes, clearer breach response protocols, and enhanced audit rights to ensure ongoing compliance and allocate risk appropriately.
Entity
Conduent Business Services LLC
Also known as: Conduent
Industry
TechnologyConduent Business Services LLC (Business Associate, NJ) reported a HIPAA breach affecting 42,616 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
$7.5M
Texas Attorney General Ken Paxton announced a $7.5 million settlement with Tris Pharmaceuticals over alleged misrepresentations about the efficacy of Dyanavel XR, an ADHD drug marketed for children. The release says the company overstated the drug’s efficacy and directed sales representatives to make misleading claims to doctors, including Medicaid providers.
Texas Attorney General Ken Paxton announced an agreement with Plum Organics requiring stronger testing and limits for heavy metals in covered baby food products, along with publicly accessible testing results. The release does not state a monetary penalty; the agreement follows an ongoing investigation into baby food manufacturers.
Texas Attorney General Ken Paxton opened an investigation into Blue Cross and Blue Shield of Texas, its parent Health Care Service Corporation, and related entities over alleged denials or delays of urgent and medically necessary care and potentially burdensome prior authorization requirements. The investigation is ongoing; the Attorney General issued a Civil Investigative Demand to obtain information and assess potential violations of Texas law.
Texas Attorney General Ken Paxton issued a consumer alert warning Texas businesses and nonprofits about a surge of demand letters alleging California Invasion of Privacy Act (CIPA) violations based on common website technologies such as cookies, pixels, and analytics tools. The AG cautions that some letters may exaggerate or misrepresent violations and may be fraudulent, noting serial CIPA plaintiff Vivek Shah has been declared a vexatious litigant. Recipients are advised not to pay or respond directly, to consult privacy counsel, and to report suspected fraud to the Consumer Protection Division.
A Texas state district court (Judge Cory Liu) has found TikTok liable for lying to parents about the safety of its platform and for exposing children to inappropriate and explicit content, making Texas the first state in the nation to hold TikTok liable on these claims. The court found that although TikTok claimed it would remove graphic videos depicting drugs, nudity, alcohol, injuries, and profanity, such videos remained accessible to minors, even under 'Restricted Mode.' No penalty has been imposed yet; Attorney General Paxton will proceed to trial, expected next month, where relief and penalties will be determined.