Home » DentaQuest Breach Affects 15 Million in Largest US Health Data Breach Reported in 2026

DentaQuest Breach Affects 15 Million in Largest US Health Data Breach Reported in 2026

by Abigail Avery


More than 15 million people may now have a very personal problem: their dental, government ID, and health information could be in the hands of hackers.

DentaQuest, a major U.S. dental and vision benefits administrator, has begun notifying individuals affected by a May 2026 cyberattack that compromised sensitive personal and health information.

The company reported 15 million affected individuals to federal regulators, making the incident the largest healthcare data breach reported to the Department of Health and Human Services so far this year, according to Healthcare Dive. The total could rise, with an independent researcher cited by the HIPAA Journal estimating that the exposed data may involve more than 23.4 million people.

DentaQuest discovered the incident on May 20 and determined that unauthorized access to parts of its network occurred from May 17 through May 20. The company hired Kroll to help identify the compromised information and determine who was affected.

What the hack exposed

The compromised information varied by individual and may have included names, addresses, Social Security numbers, member identification numbers, Medicaid and Medicare numbers, and dental or vision health information. That health data could include provider names, diagnoses, treatment details and billing information, according to DentaQuest’s breach notification.

The stolen information may extend beyond those categories. Have I Been Pwned previously identified 2.6 million unique email addresses in leaked data, along with names, addresses, phone numbers, dates of birth and genders. One folder reportedly contained more than 1.7 million unique Social Security numbers.

DentaQuest has not publicly identified the attackers. However, the extortion group ShinyHunters claimed responsibility and reportedly leaked about 234 GB of data stolen from the company, according to the HIPAA Journal.

A bigger problem than the numbers

DentaQuest serves about 32 million people through its dental and vision plans, so the breach has a large potential reach. More importantly, the exposed information combines ordinary identity data with healthcare and government identifiers.

That combination can make stolen records more useful for identity theft and fraud than a simple email-and-password leak. The risk is also difficult to contain once information has been published online. DentaQuest began mailing notification letters on July 17 and is offering affected individuals 24 months of credit monitoring, fraud consultation and identity theft restoration services.

What consumers should do

People who receive a DentaQuest breach notification should take advantage of the offered monitoring services and watch their credit reports and financial accounts for suspicious activity.

The incident also shows the limits of breach response: monitoring can help detect misuse, but it cannot make leaked Social Security numbers, medical records or government identifiers disappear. DentaQuest’s investigation remains ongoing, meaning the final number of affected people and the complete scope of the exposed data have not yet been established.

Editor’s note: This article originally appeared on our sister publication, eSecurityPlanet.



Source link

You may also like

Subscribe my Newsletter for new blog posts, tips & new photos. Let's stay updated!

Top Post

Editor Picks

Feature Posts

© 2025 chaintechdaily.online. All rights reserved.