DentaQuest Breach Impacts 15 Million in Largest US Well being Information Breach Reported in 2026


Greater than 15 million individuals might now have a really private downside: their dental, authorities ID, and well being info may very well be within the palms of hackers.

DentaQuest, a significant U.S. dental and imaginative and prescient advantages administrator, has begun notifying people affected by a Might 2026 cyberattack that compromised delicate private and well being info.

The corporate reported 15 million affected people to federal regulators, making the incident the most important healthcare knowledge breach reported to the Division of Well being and Human Providers up to now this yr, based on Healthcare Dive. The full may rise, with an impartial researcher cited by the HIPAA Journal estimating that the uncovered knowledge might contain greater than 23.4 million individuals.

DentaQuest found the incident on Might 20 and decided that unauthorized entry to elements of its community occurred from Might 17 by Might 20. The corporate employed Kroll to assist establish the compromised info and decide who was affected.

What the hack uncovered

The compromised info diverse by particular person and will have included names, addresses, Social Safety numbers, member identification numbers, Medicaid and Medicare numbers, and dental or imaginative and prescient well being info. That well being knowledge may embrace supplier names, diagnoses, therapy particulars and billing info, based on DentaQuest’s breach notification.

The stolen info might prolong past these classes. Have I Been Pwned beforehand recognized 2.6 million distinctive e mail addresses in leaked knowledge, together with names, addresses, telephone numbers, dates of beginning and genders. One folder reportedly contained greater than 1.7 million distinctive Social Safety numbers.

DentaQuest has not publicly recognized the attackers. Nonetheless, the extortion group ShinyHunters claimed accountability and reportedly leaked about 234 GB of knowledge stolen from the corporate, based on the HIPAA Journal.

A much bigger downside than the numbers

DentaQuest serves about 32 million individuals by its dental and imaginative and prescient plans, so the breach has a big potential attain. Extra importantly, the uncovered info combines extraordinary id knowledge with healthcare and authorities identifiers.

That mixture could make stolen information extra helpful for id theft and fraud than a easy email-and-password leak. The danger can also be tough to include as soon as info has been printed on-line. DentaQuest started mailing notification letters on July 17 and is providing affected people 24 months of credit score monitoring, fraud session and id theft restoration companies.

What customers ought to do

Individuals who obtain a DentaQuest breach notification ought to reap the benefits of the supplied monitoring companies and watch their credit score stories and monetary accounts for suspicious exercise.

The incident additionally reveals the bounds of breach response: monitoring might help detect misuse, however it can not make leaked Social Safety numbers, medical information or authorities identifiers disappear. DentaQuest’s investigation stays ongoing, that means the ultimate variety of affected individuals and the entire scope of the uncovered knowledge haven’t but been established.

Editor’s be aware: This text initially appeared on our sister publication, eSecurityPlanet.

Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest Articles