DentaQuest data breach (2026): what was exposed and what to do
We publish these pages from public notices and reporting so you can understand what was exposed. Everything here is already public. Always confirm with the organization named in your notice.
What happened
DentaQuest LLC, a Wellesley Hills, Massachusetts dental and vision benefits administrator that works with health plans, notified state attorneys general and consumers of a cybersecurity incident involving personal and health information.
Per letters filed with the Rhode Island and Iowa Attorneys General (dated July 16, 2026), DentaQuest became aware on May 20, 2026 of an unauthorized third party claiming to hold company data. Counsel engaged CrowdStrike. The investigation found unauthorized access to a limited portion of the network after a social-engineering attack that tricked a single employee into providing credentials and an MFA code. Threat-actor activity began May 17, 2026 and concluded May 19, 2026 (consumer letters summarize the window as beginning May 17 and ending by May 20). The actor accessed and exfiltrated data from a network file share; DentaQuest said operating systems were not affected, and it informed the FBI on May 21, 2026. On May 29, 2026, the company learned the exfiltrated data had been posted on the dark web.
Kroll’s data-mining review provided initial impacted-individual information on June 29, 2026. In the Rhode Island AG letter, DentaQuest stated it was then aware of more than 15 million individuals nationwide whose PHI was accessed—with review ongoing. That is a company statement in an AG filing, not a Delist estimate. Consumer notifications began mailing July 17, 2026, with 24 months of identity monitoring through Kroll offered to eligible individuals.
Separate press coverage (including the HIPAA Journal) discussed dark-web claims and Have I Been Pwned analysis of leaked samples earlier in June 2026. Those sample and actor figures are not the same as the company’s AG-stated “more than 15 million” count; treat them as press/researcher reporting unless you see them in an official notice.
Sources
- Rhode Island Attorney General notice (July 16, 2026) – DentaQuest LLC
- Iowa Attorney General notice (July 16, 2026) – DentaQuest LLC
- DentaQuest substitute Notice of Data Breach (July 16, 2026) – classaction.org hosted copy
- DentaQuest Starts Notifying 15 Million+ Individuals About May 2026 Cyber Incident – HIPAA Journal
What data was exposed
Per AG letters and DentaQuest’s consumer/web notices, impacted data varies by individual and has included:
- Name
- Address
- Date of birth (named in AG letters / Kroll review summaries)
- Social Security number
- Member / health plan identification numbers
- Medicare and Medicaid identification numbers
- Dental or vision health information (such as provider name, diagnosis, treatment, and billing information)
Exact fields vary by person. Rely on the notice you were mailed.
Breach details
| Detail | Value |
|---|---|
| Breach name | DentaQuest LLC |
| Date | Unauthorized access ~May 17–20, 2026 (actor activity May 17–19 per AG letters); dark-web posting learned May 29, 2026 |
| Disclosed | AG letters July 16, 2026; consumer mail from July 17, 2026 |
| Accounts affected | More than 15 million nationwide with PHI accessed (company statement in RI AG letter; review ongoing). Press/HIBP sample figures are separate and not a substitute for that count. |
| Domain | dentaquest.com |
This summary is compiled from public notices and reporting available when this page was last updated. Figures reflect what those sources report and may change as investigations continue. If something here looks wrong or you think your information is involved, contact our support team.
We report breaches as a factual record to help people check their exposure. Inclusion here is not an allegation of wrongdoing or negligence by DentaQuest; it reflects a publicly reported security incident.
For whether your information was involved and for official remediation offers, rely on notices from the organization named above (or from anyone they say will contact you) — not this page alone.
What to do now
Based on the data that may have been exposed, here are the steps you should take:
- Freeze your credit at Equifax, Experian, and TransUnion if your notice names a Social Security number or government ID—freezes are free and reversible when you need credit.
- Enroll in the Kroll monitoring offered in your letter (24 months for eligible individuals) only through channels printed there. The substitute web notice lists (844) 959-7163 (Monday–Friday, 8:00 a.m.–5:30 p.m. Central, excluding major U.S. holidays) to confirm eligibility and enroll.
- Review Explanation of Benefits, health-plan portals, and dental/vision statements for unfamiliar claims or providers.
- Treat cold outreach that cites your dental plan, Medicaid/Medicare ID, or a “breach help” offer as suspect; verify on DentaQuest’s or your health plan’s own site.
- Keep the letter; it documents which fields applied to you.
See first 48 hours after a data breach and a company emailed me about a breach.
How this shows up on the open web
Names, dates of birth, and addresses are the same fields people-search sites and data brokers already publish. When those sit next to health-plan context from a breach notice, scam calls can sound more tailored. Run a free open-web scan to see what is already findable about you. Delist does not claim to have scanned DentaQuest’s systems or this incident’s files, and it does not remove dump copies.
Related health-sector coverage on this site includes AdaptHealth (2026) and Three Oaks Hospice (2026).
I got a DentaQuest breach letter—what should I do first?
Freeze credit if your notice names an SSN. Enroll in Kroll monitoring only through the official letter or printed call center ((844) 959-7163 on the substitute web notice). Review EOBs for unfamiliar dental or vision claims. A free Delist scan checks open-web listings—not this health dataset.
Frequently asked questions
How many people were affected?
In its Rhode Island Attorney General letter, DentaQuest said it was aware of more than 15 million individuals nationwide whose PHI was accessed, with Kroll’s review ongoing. Press discussion of smaller HIBP samples or actor claims is separate from that company statement.
Was data posted online?
DentaQuest’s AG letters say it learned on May 29, 2026 that the threat actor had posted exfiltrated data on the dark web. Consumer letters also state that accessed personal information was posted on the internet for notified individuals.
What monitoring is DentaQuest offering?
Eligible individuals were offered 24 months of identity monitoring through Kroll. Use the activation details and call center printed on your mailed letter or the official substitute notice—not links in unexpected messages.
Can Delist remove my dental records from this incident?
No. Delist does not access DentaQuest systems or remove dump copies. Open-web people-search removal is a separate pipeline.
What to do after a breach
- A company emailed me about a breach: what should I do?
- Dark web data versus data brokers
- What to do after a data breach
- AdaptHealth breach (2026)
- Three Oaks Hospice breach (2026)
- First 48 hours after a data breach
- Got a breach email?
- How to freeze your credit
- Dark web vs. data brokers
A free Delist scan checks open-web exposure we support: people-search sites, public records, data brokers, and breach-source signals. Signals are not live listings, and this is not removing you from a dump, a DMV database, or a vendor's private ID store.
More breaches
Free personal data exposure scan
We search the open web for your personal data and show what’s exposed. The scan is free. Removal and monitoring require a paid plan.