Conifer Value-Based Care Data Breach: What the Notification Letter Tells You

Conifer Value-Based Care, LLC, which provides administrative services to healthcare providers and health plans, has notified individuals that an unauthorized third party gained access to an employee’s Microsoft Office 365-hosted business email account. This is a case of hacking or system intrusion into a single employee’s email, and Conifer says the incident did not reach its internal network or broader systems. The company learned of the access on August 28, 2025, and determined the unauthorized party was in the account on both August 28 and August 29, 2025, before containing the threat and starting an investigation.

The letter is addressed to people who received services from, or paid for services through, one of Conifer’s client healthcare providers or health plans, and some letters went to parents or legal guardians of affected children. Conifer says it completed a review to identify affected individuals and their associated provider or plan by November 10, 2025, notified those organizations on November 14, 2025, and finished locating and verifying mailing addresses by December 5, 2025. No aggregate number of affected individuals was included in the portion of the notice provided.

What information was exposed?
  • The letter references a list of possible data elements but leaves the specific types blank in this version of the template, noting that not every element applied to every individual
  • Some information may relate to guarantors — people who agreed to pay for someone else’s healthcare services rather than the patients themselves
  • Conifer specifically states that Social Security numbers, driver’s license or state ID numbers, credit and debit card information, financial account information, and account passwords were not involved in this incident

Because the specific data elements are not spelled out for your record, it is worth reading your own letter carefully if you have not already, since the version sent to you should list which items applied to your information.

What should you do now?
  • Carefully review statements from your healthcare providers, insurance company, and financial institutions, and report any charges or claims you don’t recognize right away
  • Bring a photo ID to medical appointments and confirm your address, phone number, and other details with your provider’s office so any discrepancies are caught early
  • Order your free annual credit report at www.annualcreditreport.com, by calling 1-877-322-8228, or by mailing the request form from www.ftc.gov to Annual Credit Report Request Service, P.O. Box 105281, Atlanta, GA 30348-5281, and look for accounts or inquiries you don’t recognize
  • Consider placing a fraud alert with one of the three credit bureaus (Equifax, Experian, or TransUnion), which will flag your file at all three
  • You have the right to place a free security freeze on your credit file at each bureau to block new accounts from being opened in your name without your PIN
  • For ongoing peace of mind, consider signing up for a service like Aura or LifeLock, which can alert you if your personal information turns up somewhere it shouldn’t
  • Report any suspected identity theft to your local police, your state Attorney General, and the FTC at 1-877-438-4338 or www.ftc.gov/idtheft

If you have questions, Conifer can be reached at https://response.idx.us/VBCevent2025 or toll-free 1-833-781-8318 (6am-6pm Pacific, Monday through Friday, excluding holidays).

Leave a Comment