15 Million Individuals Affected by DentaQuest Data Breach

DentaQuest has started sending notification letters to individuals affected by a cybersecurity incident that involved unauthorized access to portions of its computer network between May 17 and May 20, 2026, and the company has confirmed that at least 15 million individuals have been affected while its review of the incident continues.

The notification letter sent to the California Attorney General stated that DentaQuest became aware of unauthorized access to its computer network on May 20, 2026. The company immediately secured its systems and launched a forensic investigation to determine the nature and extent of the breach.

The investigation determined that the unauthorized access occurred from May 17 to May 20, 2026. DentaQuest also engaged Kroll to conduct a data mining process to identify the types of information affected and determine which individuals were potentially affected by the incident.

Data Review Continues

DentaQuest stated that its review of the affected data remains in progress. The company has confirmed that at least 15 million individuals were affected by the incident. The total number of affected individuals has not been finalized.

An independent researcher conducted an analysis of unique first name, last name, and date of birth combinations and indicated that the total number of affected individuals could exceed 23.4 million if the review identifies all corresponding records. DentaQuest has not confirmed that higher figure and has stated that the data review is still underway.

The incident affected multiple categories of personal and health-related information including the following: names, addresses, member ID numbers, Medicare numbers, Medicaid numbers, dental or vision health data, and Social Security numbers. The health information identified includes provider names, diagnoses, treatment information, and billing information.

Notification Process

DentaQuest began issuing notification letters to affected individuals on July 17, 2026 on a rolling basis while the review of breached records continues. The notification letter submitted to the California Attorney General describes the actions taken after the company detected unauthorized access, including securing its systems, conducting a forensic investigation, and performing data analysis with assistance from Kroll.

Credit Monitoring and Identity Protection

DentaQuest is offering affected individuals 24 months of free credit monitoring and identity theft protection services. The affected individuals are encouraged to enroll in the available services because the compromised information has been leaked online.

Attribution of the Incident

The breach notification issued by DentaQuest did not mention the group responsible for the cyberattack. However, the group ShinyHunters claimed responsibility for the attack as per a report published on June 5, 2026.

The total number of affected individuals remains subject to DentaQuest’s ongoing review of the compromised data. The company has confirmed that at least 15 million individuals were affected and continues to analyze records to determine the full scope of the incident and identify all individuals whose information was involved. In case the security incident is linked to potential HIPAA violations, the HHS Office for Civil Rights will conduct its own investigations.

Tags

Daniel Lopez

Daniel Lopez

Daniel Lopez stands out as an exceptional HIPAA trainer, dedicated to elevating standards in healthcare data protection and privacy. Daniel, recognized as a leading authority on HIPAA compliance, serves as the HIPAA specialist for Healthcare IT Journal. He consistently offers insightful and in-depth perspectives on a wide range of HIPAA-related topics, addressing both typical and complex compliance issues. With his extensive experience, Daniel has made significant contributions to multiple publications such as hipaacoach.com, ComplianceJunction, and The HIPAA Guide, enriching the field with his deep knowledge and practical advice in HIPAA regulations. Daniel offers a comprehensive training program that covers all facets of HIPAA compliance, including privacy, security, and breach notification rules. Daniel's educational background includes a degree in Health Information Management and certifications in data privacy and security. You can contact Daniel via HIPAAcoach.com.

Get The FREE HIPAA Checklist

Discover everything you need to become HIPAA compliant
Scroll to Top

Get the free newsletter

Discover everything you need to become HIPAA compliant
Name

Get The FREE HIPAA Checklist

Discover everything you need to become HIPAA compliant
Name