TL;DR
Conduent's data breach — first disclosed earlier in 2026 — has reportedly grown to affect more than 62.2 million individuals, according to later breach-tracking reports. Cited data types include Social Security numbers, medical information, health insurance details, and other personal data. The catch: Conduent is a business-process outsourcing vendor that handles payroll, benefits administration, and healthcare-claims processing behind the scenes for employers, health plans, and government agencies — so a lot of affected people have never heard of Conduent and won't know they're in scope until (or unless) a notification letter arrives. Don't wait for the letter. Open your benefits portal, your EOB (explanation of benefits) pages, your employer's HR/payroll dashboard, and your account-security settings right now, and save a dated PDF snapshot of each with Convert: Web to PDF — a free Chrome extension that runs 100% locally, with nothing uploaded, no account required, and full support for pages behind a login. If your plan or employer issues an official downloadable PDF statement or breach notice, get that too — it's the authoritative record. This extension is for everything else: the live dashboards and account screens that have no "export" button at all.
What is Conduent, and why don't more people recognize the name?
Conduent is a business-process outsourcing company. In plain terms, that means Conduent doesn't sell you anything directly — it's hired by other organizations to run parts of their back office. Employers, health insurers, and government benefit programs commonly outsource functions like payroll processing, benefits administration, and healthcare-claims processing to vendors like Conduent.
That arrangement is exactly why this breach is confusing for so many people. If your employer's HR department or your health plan uses Conduent to process your paycheck, your benefits enrollment, or your medical claims, your data can pass through Conduent's systems without you ever seeing the Conduent name on a login screen, an email, or a bill. You know your employer. You know your insurance company. You almost certainly do not know — or think about — the vendor working quietly underneath both.
That's the structural problem with vendor breaches in general, and it's worth naming directly: the entity that got breached is not the entity you have a relationship with. You can't just "check your account with Conduent," because you may never have had one to check.
Why this one is bigger than it first looked
According to later healthcare-breach reporting, the population affected by the Conduent breach has grown sharply since it was first disclosed earlier in 2026 — reports now place the number at more than 62.2 million individuals. Reports cite Social Security numbers, medical information, health insurance data, and other personal details among the types of data exposed. We're intentionally not speculating beyond that: no exact disclosure date, no specific client list, no dollar figures are established well enough to repeat here — just the hedged, reported facts above. If you want the fuller pattern of how vendor breaches like this tend to unfold and get revised over time, our Medtronic vendor-advisory piece covers that in more depth.
Why "wait for the letter" is not a great plan
Breach notification letters get sent to the mailing address on file — which may be years out of date, may go to a former employer's HR system, or may simply take weeks to arrive after the affected population figure has already grown once (as this one reportedly has). Some people affected through a health plan or a government benefits agency may get a notice from that health plan or agency rather than from Conduent directly, worded in a way that doesn't even mention Conduent by name. The practical result: a meaningful number of affected people will find out only when something goes wrong with their benefits account, or not at all.
That's the case for being proactive now, rather than waiting to be told you're affected.
What to save right now, and why each one matters
Think of this as a "before things change" checklist. Below are the four categories most worth a snapshot today, given that Conduent-related fallout (password resets, portal migrations, access changes) can affect what's viewable and how it's presented tomorrow.
1. Your benefits enrollment portal
This is the page that shows your current elections: medical, dental, vision, life insurance, retirement contributions, dependents on file. If your employer or plan administrator ever migrates systems in response to a vendor incident — which does happen after breaches at back-office vendors — the old portal can disappear, get redesigned, or simply time out your access during the transition. A dated snapshot of what your enrollment looked like today is a reference point you can compare against later if anything looks different afterward.
2. EOB (explanation of benefits) pages
EOBs document what was billed, what your plan paid, and what you owed for specific claims. If your health plan uses Conduent (or a similar vendor) for claims processing, your EOB history is exactly the kind of record affected by a claims-processing vendor incident. Many EOB portals only keep a rolling window of history online — 12, 18, or 24 months is common — after which older EOBs quietly disappear from the portal even without a breach. Save the ones that matter for taxes, reimbursement disputes, or your own medical record before that happens.
3. Your employer's HR/payroll dashboard
Pay stubs, W-2/tax document access, direct deposit settings, and personal information on file (address, SSN on file, dependents) typically live in an HR or payroll dashboard. If your employer's payroll is processed through a vendor caught up in this kind of breach, this is one of the first places you'd want a "here's exactly what was on file as of today" snapshot — partly for your own records, partly in case you need to demonstrate what information was (or wasn't) accurate at a point in time.
4. Account security settings, wherever you have them
This one is less about the breach itself and more about damage control. On your benefits portal, your HR/payroll dashboard, and anywhere else tied to your identity in this ecosystem, check and save your security settings screen: what email is on file for account recovery, what phone number is linked, whether multi-factor authentication is on, and what the password-last-changed date shows. If you need to reset credentials in response to a breach notification, having a "before" snapshot makes it easy to confirm afterward that nothing else changed in the process.
How to actually do this with Convert: Web to PDF
The extension is built for exactly this kind of page — a live, often login-gated dashboard with no official "download as PDF" button. Here's the workflow:
- Install Convert: Web to PDF from the Chrome Web Store. Free, no account, no sign-up.
- Log in and navigate to the page you want to save — your benefits portal home, a specific EOB, your payroll dashboard, your security settings. Because the extension runs locally via Chrome's own DevTools Protocol, it works on pages behind your login exactly the way an online URL-to-PDF tool cannot — those tools only ever see the public internet, never your authenticated session.
- Trigger the capture — click the extension icon or press Ctrl+Shift+P.
- Clean it up before you save it. If the dashboard has a slow-loading chart or a lazy-loaded image, turn on Load All Images first so nothing renders blank in the PDF. If the page is dense with navigation chrome you don't need, Article Mode strips it down to the main content — useful for a long EOB or claims-summary page. If you want to blank out an account number before you send the PDF to a support rep or a family member helping you sort this out, use Remove Elements to click and hide that specific field (with undo, so nothing is destroyed — just excluded from this particular export). For a benefits dashboard with a lot of side-by-side data, Capture Element lets you grab just the relevant panel instead of the whole page, and Single Page Mode keeps a long scrolling dashboard as one continuous PDF page instead of splitting across print-style page breaks.
- Set your paper size if you need something specific — A4 through A3/Ledger are supported, useful if a wide payroll table gets cut off at Letter size.
- Preview before you download. You'll see exactly what the PDF will look like before committing, so you can catch a cut-off column or a missing section while it's still easy to fix.
- Download. The output is a real PDF — selectable text, working hyperlinks, not a flattened screenshot — generated by Chrome's own print engine, entirely on your device. Nothing is uploaded anywhere in this process, and nothing about it requires an account.
Do this once for each of the four page types above. It takes a few minutes total, and you now have a dated, text-searchable snapshot regardless of what happens to the live portal next.
What NOT to rely on this tool for
Be clear-eyed about the tool's job here. If your health plan, employer, or Conduent itself makes an official downloadable PDF available — a formal breach notification letter, an official annual benefits statement, a plan document — get that official PDF instead. It's the authoritative legal and administrative record, and it should be the one you keep for anything involving a claim, a dispute, or a legal proceeding. Convert: Web to PDF is for the gap: the live dashboard screen, the claims summary, the settings page that has no "export" button and no official downloadable form at all. It's a snapshot of what you saw, not a substitute for an official record where one exists. It also does not bypass logins, paywalls, or access restrictions — it only captures what you, already logged in, can already see.
Why a local extension instead of an online PDF converter here
This is not a hypothetical concern for benefits data specifically — it's the whole reason a browser extension exists as a separate category of tool from an online converter. An online URL-to-PDF service works by fetching a URL on its own servers and rendering what it finds there. Two problems follow directly from that: it cannot see your authenticated session, so anything behind a login is invisible to it (it would just render a login page), and — more importantly for a breach story — you'd be feeding a sensitive benefits or claims page through a third-party server you don't control, which is precisely the kind of extra exposure you're trying to avoid this week. Our earlier piece on why a PDF converter shouldn't upload your files goes into this in more detail, and the Vercel breach post is a concrete example of what can go wrong on the server side of a "free online converter."
Convert: Web to PDF works differently: conversion happens locally, using Chrome's own rendering and print engine, on the page already open in your already-authenticated tab. Nothing is sent anywhere for the conversion itself.
A broader retention habit worth building
If this is the first time you've thought about archiving your own benefits and account pages, it's worth turning into a standing habit rather than a one-time reaction to this breach. Our records retention guide covers a broader playbook for which webpages to save as PDF and roughly how long to keep them — benefits and payroll pages are one category among several worth a recurring capture, not just a breach-response capture.
Frequently asked questions
How do I know if I'm actually affected by the Conduent breach?
The only fully reliable way is an official notification — a letter or email from Conduent, your employer, your health plan, or a state benefits agency that specifically references Conduent. Because Conduent works behind the scenes for many employers and government programs, you may not receive a notice that uses the Conduent name directly; it may instead come from your employer's HR department or your insurer, referencing a "third-party vendor incident." If you're unsure, ask your HR or benefits department directly whether they use Conduent for payroll, benefits, or claims processing.
Should I archive my accounts even if I haven't received a breach notice?
Yes, and that's really the point of this piece — because Conduent operates as a behind-the-scenes vendor, plenty of affected people won't get a clearly-labeled notice for a while, if ever. Saving a dated snapshot of your benefits, payroll, and security-settings pages now costs a few minutes and gives you a "before" reference regardless of whether a notice eventually arrives.
Does saving a PDF of my benefits portal protect my data from the breach?
No — archiving is about preserving your own record of what your accounts showed at a point in time, not about preventing or undoing the breach itself. It doesn't stop data that's already been exposed from being exposed. Think of it as building your own paper trail, not a security fix.
Is it safe to use a Chrome extension on a page with my Social Security number or health data visible?
Convert: Web to PDF is built to make that safe by design: conversion runs entirely on your device via Chrome's own DevTools Protocol, there's no upload step, no account, and no server that sees the page content. That's a meaningfully different privacy posture than an online "paste a URL, get a PDF" converter, which by definition sends the page through someone else's server.
What if my benefits portal only shows a "print" option, not a "save as PDF" option?
That's exactly the gap this extension fills. A portal's built-in print button often hands off to Chrome's generic print dialog, which can mishandle sticky headers, lazy-loaded charts, or multi-column layouts. Convert: Web to PDF pre-loads lazy content (via Load All Images), gives you Article Mode or Capture Element to isolate what matters, and shows you a preview before you commit — generally a cleaner result than the portal's own print function.
Should I change my passwords before or after taking these snapshots?
Take the snapshots first if you can do so in the next day or two — you want a "before" record of your account settings (recovery email, phone number, MFA status) in case you need to compare against what a password reset or portal migration changes. Then proceed with any password changes your employer, health plan, or Conduent recommends. Don't delay a recommended password reset for more than a day or two just to get a snapshot first — the security action takes priority.
Can I use this same approach for other vendor breaches, not just Conduent?
Yes — the underlying advice generalizes to any back-office vendor breach: identify which of your accounts might route through the affected vendor, save the pages that don't have an official export option, and prioritize the official document (a formal breach letter, a plan statement) wherever one exists over a self-captured snapshot. Our records retention guide is built around that general pattern.
Does this extension send any of my benefits data anywhere, even anonymized?
No page content, URLs, or personal data are ever transmitted. The only network activity is a single anonymous ping after a successful conversion, containing nothing but a random install token — used purely to count total conversions across all users, with no connection back to you or to what you converted.
Bottom line
The Conduent breach is a reminder that the vendor with your data is often invisible to you until something goes wrong — you may never log into "Conduent," but your paycheck, your benefits elections, or your medical claims may run through its systems anyway. Reports now put the affected population at more than 62.2 million people, with Social Security numbers, medical information, and health insurance data among the exposed types. Don't wait for a notification letter that may be delayed, misaddressed, or worded so generically you miss the connection. Open your benefits portal, your EOB history, your HR/payroll dashboard, and your account security settings today, and save each one as a real, local PDF with Convert: Web to PDF — free, no account, nothing uploaded, and it works on exactly the login-protected pages this situation involves. Where an official downloadable statement or breach notice exists, get that too; it's your authoritative record. This is for everything else.