Almeida Law Group is investigating a data breach at L.A. Care Health Plan. The breach occurred on October 31st, 2025. If you were affected, contact Almeida Law Group.
About L.A. Care Health Plan
L.A. Care Health Plan is the nation’s largest publicly operated health plan, serving more than 2.5 million members in Los Angeles County. It is a public entity created by the State of California in 1997 to provide Medi-Cal managed care, and it also offers ACA marketplace coverage, a Medicare plan, and a homecare workers’ health plan. L.A. Care is headquartered at 1200 W. 7th Street in Los Angeles, California. Because L.A. Care administers health coverage for low-income and vulnerable communities, the member records it maintains include sensitive health and claims information.
What Happened?
L.A. Care Health Plan was listed in a California Attorney General sample breach notice. The incident originated at Conduent Business Services LLC, a former L.A. Care vendor that provided printing, mailing, document processing, and other back-office services. According to the breach notification letter, Conduent discovered a cyberattack on January 13th, 2025. Its investigation determined that an unauthorized third party accessed its network between October 21st, 2024 and January 13th, 2025, and obtained files containing L.A. Care member information. The compromised data included members’ names, dates of birth, claim numbers, dates of service, treatment costs, dates of admission and discharge, and health insurance member information. The notice explicitly states that Social Security numbers were not involved for L.A. Care members. The total number of persons affected by this specific notice was not reported in the filing.
The Conduent incident is one of the largest healthcare-related data breaches in recent U.S. history. TechCrunch described it as a ransomware attack, and the Safepay ransomware group claimed responsibility according to HIPAA Journal, though that listing was later removed from Safepay’s data leak site — suggesting a ransom may have been paid. Conduent’s broader breach affected at least 62.2 million individuals across dozens of clients nationwide, per updated HHS Office for Civil Rights filings. A significant litigation concern is Conduent’s notification delay: despite discovering the attack on January 13th, 2025, Conduent did not begin notifying affected individuals until approximately October 2025 — roughly ten months later. As of early 2026, more than 35 federal class action lawsuits have been consolidated against Conduent in the U.S. District Court for the District of New Jersey. Those suits name Conduent, not L.A. Care, as the defendant, and no settlement has been reached.
L.A. Care also has a documented history of prior data incidents. In September 2023, it reached a $1.3 million HIPAA settlement with the HHS Office for Civil Rights stemming from a 2014 member portal breach and a 2019 mailing error. Separately, in March 2026, L.A. Care disclosed an unrelated manual error that mistakenly linked member identification numbers to the wrong names, affecting fewer than 3,000 members.
Key Facts at a Glance
- Company or Organization: L.A. Care Health Plan
- Industry: Healthcare / Health Insurance (publicly operated Medi-Cal managed care health plan)
- Location: Los Angeles, California
- Incident type: Cyberattack / ransomware (at third-party vendor Conduent Business Services LLC)
- Date of breach: October 31st, 2025 (per California Attorney General filing; unauthorized access at Conduent ran from October 21st, 2024 to January 13th, 2025 per the notice letter)
- Date breach discovered: January 13th, 2025 (Conduent’s discovery date per the notice letter)
- Prior breach: Yes — $1.3 million HIPAA settlement with HHS OCR in September 2023 for 2014 and 2019 incidents; separate manual-error breach disclosed March 19th, 2026
- Litigation status: 35+ federal class action lawsuits consolidated against Conduent in the U.S. District Court for the District of New Jersey; no settlement reached as of March 2026
- Source: California Attorney General sample breach notice (https://oag.ca.gov/ecrime/databreach/reports/sb24-625951); HIPAA Journal (https://www.hipaajournal.com/conduent-business-solutions-data-breach/); TechCrunch (https://techcrunch.com/2026/02/05/data-breach-at-govtech-giant-conduent-balloons-affecting-millions-more-americans/)
What Should You Do?
If you received a notice from L.A. Care Health Plan about this incident, start by reviewing your Explanation of Benefits statements and requesting a copy of your medical records from your physicians or from L.A. Care directly, since health and claims information was involved. Consider placing a fraud alert or credit freeze with the three major credit bureaus — Equifax, Experian, and TransUnion — to help prevent new accounts from being opened in your name. Monitor your credit reports regularly; you can request free reports at AnnualCreditReport.com. Watch your financial accounts and health insurance accounts for any suspicious activity. If you discover signs of fraud or identity theft, visit IdentityTheft.gov for step-by-step guidance on reporting and recovery.
Your Legal Rights
If your personal or health information was involved in this breach, you may have legal rights depending on the facts of the incident and the law in your state. Almeida Law Group represents consumers in data breach and privacy litigation and can help you evaluate whether you may have a claim. Contact us at (708) 529-5418 or through our contact page for a free case evaluation.