DentaQuest Data Breach Exposes Social Security Numbers and Health Records

Healthcare data breach illustration
Breach Discovery: May 2026Breach Notification: July 2026

What Happened in the DentaQuest Data Breach?

DentaQuest, a major dental and vision benefits administrator, has confirmed a data breach that exposed sensitive personal and health information belonging to millions of people. The company discovered the intrusion in May 2026, after noticing suspicious activity on its network. As a result, DentaQuest launched an internal investigation to determine what happened and how far the exposure reached.

That investigation found that hackers had access to DentaQuest’s network for a short window in May 2026. During this time, the attackers were able to view and potentially copy files containing detailed personal and health-related records. Although DentaQuest has not publicly named the responsible party, the extortion group ShinyHunters claimed credit for the attack. The group also leaked roughly 234 GB of data it said came from DentaQuest’s systems.

Following the discovery, DentaQuest brought in forensic specialists to assess the scope of the compromise. The company has since worked to determine exactly which records were accessed and which individuals need to be notified. Because the leaked data reportedly surfaced publicly, outside researchers were also able to review samples of the stolen files. This gave additional confirmation that real personal information was taken, not just accessed without exfiltration.

DentaQuest began sending written notification letters to impacted individuals and filed notices with several state Attorneys General offices, including in Texas, Massachusetts, and South Carolina. These filings show the scale of the breach growing as the investigation continued. This pattern is common in large-scale breaches, where initial estimates rise as more records are reviewed.

Who was affected?

The DentaQuest data breach affects a broad population of people connected to dental and vision benefit plans. This includes current and former plan members, as well as individuals whose information was stored through Medicaid or Medicare benefit administration. Because DentaQuest serves millions of people nationwide, the breach touches a wide geographic footprint across the United States.

Public estimates of the total number affected vary. Regulatory filings point to more than 23 million individuals potentially impacted, while DentaQuest has reportedly confirmed that at least 15 million people were affected. In addition, the company has stated it is mailing written notices to at least 4.5 million people directly. Since DentaQuest is a Sun Life subsidiary serving tens of millions of people across all 50 states, the pool of at-risk individuals is unusually large compared to many other healthcare-related breaches.

Given that Medicaid numbers were involved, it’s likely that lower-income individuals and other vulnerable populations are represented among those affected. Because Medicare numbers were also exposed, older adults may make up a significant share of the impacted group as well. Anyone who held dental or vision coverage administered by DentaQuest should consider themselves potentially at risk until they confirm otherwise.

What Information Was Potentially Exposed?

The data accessed during this breach spans both identity information and detailed health records. This combination makes the incident particularly serious, since it goes well beyond a simple email or password leak. According to DentaQuest’s own disclosures and outside reporting, the following categories of information were involved:

  • Full names
  • Home addresses
  • Social Security numbers
  • Member identification numbers
  • Medicaid and Medicare numbers
  • Benefits provider names
  • Diagnosis and treatment details
  • Billing information
  • Email addresses
  • Phone numbers
  • Dates of birth
  • Government-issued IDs

Because Social Security numbers and government IDs were exposed, affected individuals face a heightened risk of identity theft. Criminals can use this kind of data to open new credit accounts, file fraudulent tax returns, or apply for loans in someone else’s name. When this information is combined with a full name, address, and date of birth, it becomes even easier for a fraudster to impersonate the victim convincingly.

In addition, the exposure of diagnosis and treatment details raises the risk of medical identity theft. This happens when someone uses stolen health information to receive medical care, obtain prescriptions, or submit fraudulent insurance claims under another person’s name. Because Medicaid and Medicare numbers were also included, affected individuals could see fraudulent claims filed against these government programs. This type of fraud can be especially difficult to detect and unwind, since it may not show up on a typical credit report.

What is the company doing?

In response to the breach, DentaQuest says it worked to secure its network and investigate the full scope of the incident. The company has been coordinating with regulators, filing breach notifications with multiple state Attorneys General offices as it confirmed additional details. This phased notification approach reflects the scale and complexity of reviewing tens of millions of records.

DentaQuest is also offering affected individuals 24 months of free credit monitoring. This includes fraud consultation services and identity theft restoration support. Individuals who receive a notification letter can enroll in these services to help detect and respond to any misuse of their information. Meanwhile, DentaQuest continues to notify newly confirmed individuals as its review of the stolen data progresses.

What Should Affected Individuals Do?

Monitor Your Credit Reports Closely

Affected individuals should check their credit reports regularly for any accounts or inquiries they don’t recognize. You can request free reports from each of the three major credit bureaus and review them for suspicious activity. Because Social Security numbers were exposed, this step is especially important for catching new-account fraud early.

In addition, consider spacing out your free credit report requests throughout the year so you have ongoing visibility. If you spot an unfamiliar account, report it to the credit bureau immediately. Acting quickly can limit the financial damage and make it easier to dispute fraudulent charges.

Place a Fraud Alert or Credit Freeze

Given that Social Security numbers and government IDs were compromised, placing a fraud alert or credit freeze is a strong protective step. A fraud alert requires lenders to verify your identity before opening new credit in your name. A credit freeze goes further by blocking most access to your credit file entirely.

To set up either option, contact one of the three major credit bureaus, since a fraud alert placed with one will notify the others. While a freeze offers stronger protection, it does require you to lift it temporarily whenever you apply for new credit yourself. Either option significantly reduces the odds that someone can open accounts using your stolen information.

Watch for Medical Identity Theft and Insurance Fraud

Because diagnosis, treatment, and billing details were exposed, affected individuals should review any Explanation of Benefits statements carefully. Look for services or providers you don’t recognize, since this can indicate someone else is using your identity for medical care. If you spot anything unusual, contact your benefits provider and DentaQuest right away.

It’s also wise to request a copy of your medical records periodically to confirm accuracy. This is especially important if you rely on Medicaid or Medicare, since fraudulent claims filed under your name could affect your future coverage or benefits. Catching errors early can prevent bigger complications down the road.

Stay Alert for Phishing and Scam Attempts

Because names, phone numbers, and email addresses were leaked, affected individuals may become targets of phishing attempts. Scammers often use breached personal details to make fraudulent emails or calls seem legitimate. Be cautious of any message asking you to confirm personal information or click a suspicious link.

Instead, verify any unexpected contact by reaching out to the organization directly through a known phone number or website. Never provide sensitive information in response to an unsolicited message. If something feels off, trust that instinct and don’t engage further.

Enroll in the Free Identity Protection Services Offered

DentaQuest is providing 24 months of free credit monitoring, fraud consultation, and identity restoration services to affected individuals. If you received a notification letter, take advantage of this offer as soon as possible. These services can help detect misuse of your information faster than checking on your own.

Furthermore, keep your enrollment confirmation and any reference numbers in a safe place. If you ever need to dispute fraudulent activity, having proof of enrollment can streamline the resolution process. Because identity theft can surface months or even years after a breach, staying enrolled for the full covered period is worthwhile.



More Information

Official data breach notification from California Attorney General

Related Data Breaches