Notifications began in June 2024 and ran into January 2025. Over that period the reported figure moved from "tens of millions" to roughly 100 million and finally to 192.7 million — the largest healthcare breach on the United States record by a wide margin.
A Moving Count Is Not A Growing Incident
Nothing further was taken after 21 February. Every revision reflects a review getting further through the material, matching records to people and people to clients.
This corpus recorded the same shape at 26-0731, where a processor’s count moved four times over more than a year, and at 25-0403, where a company needed six months to establish what a supplier had lost. The delay is structural and treating it as concealment obscures where the failure actually sat.
Why A Processor Produces The Biggest Number
Change Healthcare is not an insurer or a hospital. It moves claims and payments between them, which means the records of a large share of the country pass through one estate.
The corpus files that concentration argument repeatedly: the breach happens somewhere the affected person has never heard of, under a contract they never saw. 192.7 million is what that argument looks like at full scale.
The Figure Is A Count Of Notifications
It counts people the company determined it had to notify. That is a legal threshold rather than a measure of harm, and it says nothing about how many records were actually read, sold or used.
The corpus keeps reachable, taken and published as three populations. A notification count is a fourth, and it is the only one anybody publishes.
Compiled from contemporaneous reporting of the notification process and the final filed figure, listed below. Graded high: the 192.7 million figure originates with the company’s regulatory notification rather than with an attacker or a researcher. It is a count of individuals notified, which is not a measure of harm, and this file does not treat it as one. Corrections: corrections@forensicpost.com.
- Change Healthcare data breach: 192.7 million affectedThe HIPAA Guide
- Change Healthcare responding to cyberattackHIPAA Journal
- Change Healthcare cybersecurity breach: impact on providersNixon Peabody