
"BCBSMT, the largest health insurance provider in Montana, said in October that up to 462,000 of its members' data may have been exposed by a "cyber incident" affecting Conduent, a third-party vendor. The company reported the incident to Montana State Auditor James Brown's office, which launched an investigation. Now, BCBSMT is arguing the auditor's actions have been unlawful. The company filed a lawsuit in state district court in Helena, claiming Brown's office doesn't have the authority to pursue an investigation."
"The legal issue seems fairly straightforward: Montana passed a law that went into effect on October 1, 2025 that would require entities to report breaches to the state auditor. Previously, entities like BCBS that are covered by HIPAA were exempt under state notification law if they complied with HIPAA's breach notification rule and requirements. The insurer learned about the breach on July 1, 2025 from Conduent."
"DataBreaches notes that when we first reported on this incident on October 22, 2025, we had found no entry on HHS's public breach tool from BCBSMT or Conduent, although there was a much smaller report from Conduent Business Services on October 8, 2025. As of publication today, we still do not see any entry on HHS's public breach tool from BCBSMT or Conduent."
Blue Cross Blue Shield of Montana reported that up to 462,000 members' records may have been exposed in a cyber incident involving third-party vendor Conduent. Montana enacted a law effective October 1, 2025 requiring entities to report breaches to the state auditor; previously HIPAA-covered entities complying with the Breach Notification Rule were exempt under state law. BCBSMT learned of the breach on July 1, 2025, completed its investigation on September 23, and notified the state auditor after October 1, calling that notification a courtesy. BCBSMT filed suit claiming the auditor lacks authority to investigate. No entry appears on HHS's public breach tool from BCBSMT or Conduent, though Conduent Business Services reported a smaller incident on October 8, 2025.
Read at DataBreaches.Net
Unable to calculate read time
Collection
[
|
...
]