The DentaQuest data breach is the largest health data breach reported to the federal government so far in 2026, and it was not a ransomware attack in the sense most people picture. Nothing was encrypted and no systems went down. The extortion group ShinyHunters copied the data, demanded payment to keep it private, and published it when DentaQuest did not pay. If you have had dental or vision coverage through a Medicaid plan, a Medicare Advantage plan or an employer plan that used DentaQuest, this page covers what was taken, why three different victim counts are in circulation, what DentaQuest is offering, and what to do about it as of September 2026.
What happened in the DentaQuest data breach, and when
DentaQuest is a Boston-based dental and vision benefits administrator, part of Sun Life U.S., and the second-largest dental benefits administrator in the country according to Healthcare Dive. It works behind health plans rather than selling to consumers, which is why most of the people affected never dealt with it directly.
Per DentaQuest's web notice, the company discovered on May 20, 2026 that unauthorized individuals had accessed data on its network, and the investigation later placed the intrusion between May 17 and May 20. ShinyHunters listed DentaQuest on its leak site within days, with a deadline of May 27 according to the class action complaint filed later, and released the data, more than 234 GB of it, before the end of the month. On June 3, Have I Been Pwned loaded the leaked files and found 2.6 million unique email addresses.
DentaQuest reported the breach to the Department of Health and Human Services on July 16, 2026 at 15 million individuals, posted its notice the same day, and began mailing letters on July 17 on a rolling basis. It hired Kroll to analyze the stolen files and says that review is still ongoing.
Three numbers, three different things
Coverage of this breach uses at least three figures, and they measure different things.
- 15 million is what DentaQuest reported to HHS on July 16. It is the company's count of people whose data was in the accessed systems, and it is the number the notification letters are based on.
- 23.4 million is an independent researcher's estimate of the true total, cited by HIPAA Journal, based on analysis of the leaked data itself.
- 2.6 million is Have I Been Pwned's count of unique email addresses in the leak. It is smaller because most dental-benefit records have no email address attached; a Medicaid enrollment file is keyed on member IDs, not inboxes. Absence from HIBP tells you nothing about whether your record is in the dump.
State filings fill in some of the geography: classaction.org's tracking page records preliminary counts of about 522,000 Massachusetts residents, 3,973,000 Texas residents and 17,100 South Carolina residents. If you have not received a letter, that alone does not clear you. DentaQuest said in its notice that the letters are going out on a rolling basis and that its data review is not finished, and a share of affected people will have moved since the address on file was recorded.
What was actually stolen
DentaQuest's notice lists the data as name, address, Social Security number, member identification number, Medicaid number and Medicare number, plus dental or vision health information including provider name, diagnosis, treatment and billing information. HIBP's analysis of the leak adds dates of birth, phone numbers and gender.
The Medicaid and Medicare numbers deserve more attention than they have had. DentaQuest administers dental benefits for state Medicaid programs, so a large share of the people in this breach are Medicaid enrollees: lower-income households, children, and people with less slack to absorb identity theft or fight a fraudulent claim. A Medicaid ID is a credential for billing a government health program in someone else's name, and it is monitored far less closely than a credit card. Put it next to an SSN and a treatment history and you have what is needed to open credit, file fake claims and receive care under a stolen identity. A password gets reset. None of these numbers do.
What DentaQuest is offering
The notice offers 24 months of identity monitoring through Kroll at no charge, covering credit monitoring, fraud consultation and identity theft restoration. Unlike many breach offers, the web notice sets no enrollment deadline, and you do not need a letter to use it: DentaQuest's line for confirming whether your data was involved and enrolling is (844) 959-7163, Monday to Friday, 8:00 a.m. to 5:30 p.m. Central. If you believe you were covered through DentaQuest and no letter has arrived, calling is the fastest way to find out.
DentaQuest data breach: what to do right now
- Call the number above and enroll in the Kroll monitoring. It is free, it runs two years, and the restoration service is the part that matters if fraud does occur.
- Freeze your credit at all three bureaus. Equifax, Experian and TransUnion each take a few minutes, and a credit freeze is free to place, lift and replace. Monitoring tells you after an account is opened; a freeze stops it being opened.
- Freeze a child's credit too. Children's records are in this breach because Medicaid dental coverage skews young. A minor with no credit file is a favorite target precisely because nobody checks. All three bureaus let a parent or guardian create and freeze a file for a minor.
- Watch for medical identity theft as well as financial. The FTC's medical identity theft page lists the signs: an Explanation of Benefits for care you never received, a bill from a provider you have never seen, a collector chasing a medical debt, a notice that you have hit a benefit limit. Report errors to the provider and plan in writing.
- If you are on Medicaid or Medicare, know where to report misuse. HHS-OIG takes reports at 1-800-HHS-TIPS or through its fraud reporting page, and your state Medicaid office can flag an account. This step is skipped constantly because breach checklists are written for credit card leaks.
- If anything goes wrong, file at IdentityTheft.gov. It produces the affidavit and recovery plan that bureaus, banks and providers accept.
The lawsuit, and what "adequate safeguards" means now
On June 4, 2026, plaintiff Melissa King filed a class action against DentaQuest in the U.S. District Court for the District of Massachusetts (No. 1:26-cv-12529). The complaint brings claims for negligence, breach of third-party contract, unjust enrichment and invasion of privacy, and alleges DentaQuest failed to implement industry-standard measures including multi-factor authentication, staff training and encryption.
The complaint's sharpest point is one that applies to most people in this breach. King says she had no relationship with DentaQuest at all; her data reached it through her dental provider, Advantage Dental, and she never consented to DentaQuest holding it. DentaQuest exists to process Social Security numbers, Medicaid numbers and treatment records, including children's, for people who never chose it. Whatever discovery turns up about its security posture in May 2026 will say more than the notice does. As of September 2026 the case is at an early stage and no settlement has been announced.
Where this data goes next
A leak this size does not end when the news cycle does. The 234 GB is copied and repackaged, and pieces get merged with whatever else is already circulating about you. Our identity theft statistics page covers how many separate exposure records now exist for the average breached person; it is a lot more than one.
The people-search layer is where that merging becomes visible, and it is also where the SSN is not the problem. Those sites publish the parts that make a scam call land: addresses, relatives, age, phone numbers. In our removal work, PeopleSearchNow shows current and past addresses and relatives on its free preview before asking for a cent. And the records those sites hold are often wrong in ways that matter here: PeopleConnect's suppression tool, which covers TruthFinder, Intelius and Instant Checkmate, offers to text a verification code to a phone number from its own file, and that number is frequently stale. A caller armed with your DentaQuest record and a people-search preview knows your address, your relatives and your insurer, which is all the script needs.
The National Public Data case shows the other half: the broker that lost an estimated 270 million SSNs in 2024 is back online as a free people-search engine under new ownership, and opting out of the relaunched site does nothing about the data the hackers took, and the same split applies here. The freeze and the monitoring handle the SSN and the Medicaid number. Getting your address history and relatives off the people-search sites is a separate, recurring task, and our data broker opt-out guide covers it one site at a time.
Delist My Data is being built for that task: finding your listings across the people-search sites and re-filing when they come back. We're in pre-launch; join the waitlist for founding-member access.
Sources
- DentaQuest: Notice of Data Breach (web notice, July 16, 2026; PDF hosted by classaction.org)
- HIPAA Journal: DentaQuest starts notifying 15 million+ individuals about May 2026 cyber incident
- Healthcare Dive: DentaQuest breach exposes data of 15M people, a record this year (August 11, 2026)
- Have I Been Pwned: DentaQuest breach (added June 3, 2026)
- Paubox: DentaQuest notifies 15 million after ShinyHunters leaks stolen data
- Top Class Actions: DentaQuest data breach class action filed over ShinyHunters cyberattack (King v. DentaQuest, June 4, 2026)
- ClassAction.org: DentaQuest data breach lawsuit investigation and state filing counts
- Equifax: Credit freeze
- Experian: Freeze center
- TransUnion: Credit freeze
- FTC: IdentityTheft.gov
- FTC: What to know about medical identity theft
- HHS Office of Inspector General: Report fraud