DentaQuest breach notices sent to 15 million after health data theft
Hackers accessed insurance, treatment, and personal data months before victims were finally notified.

Image by PiyaZIrconplus | Shutterstock
- DentaQuest is notifying nearly 15 million people after hackers accessed sensitive personal and health information.
- The stolen data may include insurance and billing information, medical diagnoses, and governemnt IDs.
- One researcher found 1.7 million unique Social Security numbers, most of them appearing to belong to children.
- The May breach adds to a growing wave of healthcare attacks exposing millions of patients at once.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
DentaQuest has begun notifying 15 million people – including an undisclosed number of children – that their sensitive personal and health data was exposed during a breach claimed by the ShinyHunters hacker gang in May.
Considered to be one of the largest healthcare breaches in 2026, DentaQuest began sending the breach notification letters to affected patients on a rolling basis starting on July 17th.
The company filed two separate letters with the California State Attorney General’s office – one for adult patients and another addressed specifically to the parents of affected minors.
DentaQuest, a subsidiary of Sun Life, is one of the largest dental and vision benefits administrators in the US, serving nearly 33 million insured patients each year.
The breach was first discovered on May 20th, according to the letter, and a breach notice posted on the company website dated July 16th.
The hackers were said to have obtained unauthorized access to DentaQuest’s computer network three days earlier, on May 17th.
“We are writing to tell you about a data security incident. Your personal information was accessed by unauthorized individuals,” the letter states.
After taking “immediate action to secure the network,” DentaQuest says it alerted law enforcement and brought in outside security experts to investigate.
ShinyHunters leaks data
ShinyHunters, which claimed to have stolen more than 234GB from the dental healthcare company, published the alleged cache on its leak site on May 30th after reporting negotiations with DentaQuest were unsuccessful.
“The company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don't care,” the extortionists wrote at the time.
Although DentaQuest reports the personal and health information of at least 15 million beneficiaries was exposed – an independent researcher examining the published data, told The HIPAA Journal on Thursday the number “could increase to more than 23.4 million."
That conclusion is based on the researcher’s “data analysis of unique firstname+lastname+DOB combinations,” the media outlet said.
That researcher also reported finding more than 1.7 million unique Social Security numbers, most of them appearing to belong to children, and noted that some of the files in the dataset date back to 2009.
What data did hackers access?
Headquartered in Massachusetts, DentaQuest benefits programs are contracted across all 50 states through employer plans, Medicare Advantage, commercial options, and government programs like Medicaid and CHIP, according to its website.
According to a June 3rd report by HaveIBeenPwned (HIBP), the compromised data included 2.6 million unique email addresses along with names, addresses, and phone numbers.
“Much of the data appeared in healthcare enrollment files (ASC X12 transaction sets) with some containing Medicaid IDs, while additional data appeared in member records and related files,” HIBP said.
DentaQuest expanded on that information to include “dental or vision health information, such as provider names, diagnoses, treatments and billing information.”
The full list of information accessed includes:
- Names
- Dates of birth
- Gender
- Email addresses, physical addresses and phone numbers
- Social Security numbers
- Government-issued IDs
-
Dental and Vision insurance information:
- Member identification numbers
- Provider names
- Diagnoses and treatments
- Billing information
- Medicaid and Medicare numbers
DentaQuest offers
DentaQuest says it is providing affected individuals with complimentary credit monitoring and identity theft protection services for the next 24 months.
Paul Bischoff, Consumer Privacy Advocate at Comparitech, calls the DentaQuest attack “a major data breach both in terms of the number of people affected and the types of personal information involved.”
The privacy advocate is also urging anyone impacted by the breach to take advantage of the free services to “monitor credit reports, bank accounts, and medical bills for unrecognized activity.”
“Whether or not DentaQuest paid ShinyHunters' ransom demand, there is no guarantee that the group will delete the stolen data. Breach victims should assume the worst and act accordingly to protect their accounts and identities," Bishoff said.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Another dental company targeted
Meanwhile, earlier this month, US dental referral service 1-800-Dentist was also claimed by the Qilin ransomware gang, along with 11 file samples, and a threat to leak the alleged stolen data unless the company paid an undisclosed ransom.
The hacker group claimed to have siphoned an unknown amount of personally identifiable information (PII) and health-related data from the company.
Notably, at the time of this report, 1-800-Dentist no longer appears on the Qilin leak site, leading Cybernews to believe that the company has either paid an extortion fee or is currently in negotiations.
The dental referral service collects information from roughly two million callers a year and works with thousands of dental practices nationwide.
Check if your data has been leaked