Desk live·
ForensicPost
Ransomware/Verification/File 24-0620

Change Healthcare Affected-Person Count Took Eleven Months to Settle

The affected-person count took eleven months to settle. It did not grow because the intrusion grew; it grew because working out whose records were in four terabytes takes that long.

Constructed geometry · not a chart of case data
JurisdictionUSANashville, Tennesseethe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetChange Healthcare
ActorALPHV
D. Kennedy13 min readConfidence: high3 sources reviewed

Notifications began in June 2024 and ran into January 2025. Over that period the reported figure moved from "tens of millions" to roughly 100 million and finally to 192.7 million — the largest healthcare breach on the United States record by a wide margin.

A Moving Count Is Not A Growing Incident

Nothing further was taken after 21 February. Every revision reflects a review getting further through the material, matching records to people and people to clients.

This corpus recorded the same shape at 26-0731, where a processor’s count moved four times over more than a year, and at 25-0403, where a company needed six months to establish what a supplier had lost. The delay is structural and treating it as concealment obscures where the failure actually sat.

Why A Processor Produces The Biggest Number

Change Healthcare is not an insurer or a hospital. It moves claims and payments between them, which means the records of a large share of the country pass through one estate.

The corpus files that concentration argument repeatedly: the breach happens somewhere the affected person has never heard of, under a contract they never saw. 192.7 million is what that argument looks like at full scale.

The Figure Is A Count Of Notifications

It counts people the company determined it had to notify. That is a legal threshold rather than a measure of harm, and it says nothing about how many records were actually read, sold or used.

The corpus keeps reachable, taken and published as three populations. A notification count is a fourth, and it is the only one anybody publishes.

How we reported this

Compiled from contemporaneous reporting of the notification process and the final filed figure, listed below. Graded high: the 192.7 million figure originates with the company’s regulatory notification rather than with an attacker or a researcher. It is a count of individuals notified, which is not a measure of harm, and this file does not treat it as one. Corrections: corrections@forensicpost.com.

Sources
  1. Change Healthcare data breach: 192.7 million affectedThe HIPAA Guide
  2. Change Healthcare responding to cyberattackHIPAA Journal
  3. Change Healthcare cybersecurity breach: impact on providersNixon Peabody
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary