If you got a DentaQuest breach letter, do these five things now: freeze your credit at all three bureaus, enroll in the 24 months of free credit and identity monitoring DentaQuest is offering, place a fraud alert, watch every Explanation of Benefits statement for medical identity theft, and remove your personal data from broker sites so criminals cannot combine it with the leaked information. Below is exactly how to do each step, plus the current class-action status.
What Happened in the DentaQuest Breach
DentaQuest, one of the largest dental benefits administrators in the United States, discovered a network intrusion on May 20, 2026. Attackers had access to internal systems between May 17 and May 20, 2026 and exfiltrated roughly 234 GB of member data. The ShinyHunters extortion group — the same threat actor behind the 2026 breaches at McKesson, McGraw Hill, Charter Communications, and Instructure — claimed responsibility around May 22, 2026. When DentaQuest refused to pay the ransom, ShinyHunters published the data on its dark web leak site on June 2, 2026.
DentaQuest began mailing breach notification letters on a rolling basis starting July 17, 2026. The company confirmed at least 15 million individuals were affected, and one independent researcher's analysis of unique name-plus-date-of-birth combinations in the leaked archive puts the potential impact at over 23.4 million people — making this one of the largest healthcare breaches ever disclosed in the United States.
What Information Was Exposed?
The leaked data includes both personally identifiable information (PII) and protected health information (PHI) covered by HIPAA:
- Full names
- Home addresses
- Dates of birth
- Email addresses and phone numbers
- Social Security numbers (confirmed in updated disclosures)
- Government-issued IDs, including driver's license numbers
- Member identification numbers
- Medicaid and Medicare numbers
- Benefits provider names, diagnoses, treatment details, and billing information
This Is a Full-Identity Breach — Not Just a Contact Leak
The combination of Social Security numbers, dates of birth, and health information is the exact recipe fraudsters need for medical identity theft, synthetic identity fraud, and tax refund fraud. Treat any DentaQuest notification the same way you would a direct Social Security number leak — assume attackers have everything they need to open credit lines or file fraudulent claims in your name.
How to Check if You Were Affected
- Watch your mail and email. DentaQuest began mailing letters July 17, 2026. Notifications are going out in waves — you may not receive yours until several weeks later. The company filed two separate notices with the California Attorney General: one for adult members, and a separate letter addressed to the parents of affected minors.
- Contact DentaQuest directly. If you have ever had dental benefits administered by DentaQuest, Sun Life dental, or a Medicaid dental plan and have not received a notice, call member services to ask if your records were included.
- Check Have I Been Pwned. The DentaQuest dataset was added to haveibeenpwned.com. Enter the email addresses you have used for insurance accounts to check for a match.
- Review your insurance portal. Log into your dental plan and look for unfamiliar claims, providers, or account changes.
Step 1: Enroll in the Free Monitoring DentaQuest Is Offering
DentaQuest is providing affected individuals with 24 months of free credit monitoring, fraud consultation, and identity theft restoration services. Follow the enrollment instructions in your notification letter — the enrollment code has a deadline and is worth using even if you already have identity protection elsewhere. Free monitoring is a supplement, not a substitute, for the steps below.
Step 2: Freeze Your Credit at All Three Bureaus
Because Social Security numbers and driver's license numbers were exposed, a credit freeze is the single most effective step you can take. It is free, takes about 15 minutes, and blocks anyone — including you — from opening new credit in your name without lifting the freeze first.
- Equifax: equifax.com/personal/credit-report-services/credit-freeze/
- Experian: experian.com/freeze/center.html
- TransUnion: transunion.com/credit-freeze
Do not skip a bureau. Fraudsters will try the one you missed. Also place a fraud alert at any one of the three — it automatically applies to the other two — which requires lenders to take extra steps to verify identity before opening credit.
Step 3: Watch for Medical Identity Theft
Medical identity theft is harder to catch than credit fraud, and DentaQuest's data includes exactly the fields criminals need to commit it.
- Review every Explanation of Benefits (EOB) statement — flag any procedure, provider, or date you do not recognize
- Request an accounting of disclosures from your health plan under HIPAA to see who has accessed your records
- Order your free annual medical record from providers you have visited
- If you spot a fraudulent claim, contact the insurer's fraud line immediately and file a report at IdentityTheft.gov
Step 4: Freeze Your Children's Credit Too
DentaQuest administers dental benefits for millions of children covered by Medicaid and CHIP (Children's Health Insurance Program). Child identity theft is especially damaging because it can go undetected for years — often until a teen applies for their first credit card or student loan.
You can request a credit freeze for a minor by mailing documentation directly to each bureau. All three bureaus offer this free of charge for children under 16.
Protect Your Children
If your child is covered under a DentaQuest-administered plan, request a child credit freeze from each bureau. It is the only reliable way to prevent someone from opening accounts in a minor's name until they turn 16.
Is your data already out there?
Leaked data ends up on broker sites and in scammers' hands. Run a free 60-second scan to see your exposure — then let us remove it.
Run a free scan★★★★★ 4.8/5 · Trusted by thousands of families
Step 5: Change Passwords and Turn On 2FA
Update passwords on your DentaQuest account, dental plan portal, primary email, and any account where you have reused a password. Use a password manager to generate unique passwords for each site. Then enable two-factor authentication on your email, financial accounts, and insurance portals — this stops account takeovers even if your password leaks.
Step 6: Watch for Targeted Phishing
Attackers who have your full medical profile can craft phishing that looks disturbingly authentic. Expect a wave of:
- Fake DentaQuest "breach response" emails asking you to "verify identity"
- Calls from people who know your Medicaid ID and try to "confirm" account details
- Text messages about dental claims you supposedly filed
- Emails offering free credit monitoring from a company DentaQuest did not name
Never click a link in a breach-related email. Go to DentaQuest's official site directly, and only enroll in monitoring through the code printed in your mailed letter.
Step 7: File Complaints if You See Misuse
- Report identity theft at IdentityTheft.gov to get an FTC recovery plan and affidavit
- File a HIPAA complaint with the HHS Office for Civil Rights at hhs.gov/hipaa/filing-a-complaint
- File a police report if fraudulent accounts or claims are opened in your name — you will need the report number to dispute fraud with creditors
Step 8: Remove Your Data From People-Search Sites
Data brokers like Spokeo, BeenVerified, WhitePages, and Radaris publish your name, address, phone, relatives, and employer for free. When combined with the DentaQuest leak, this gives attackers everything they need to impersonate you, target your family, or trick medical providers.
PrivacyOn removes your personal information from 100+ data broker sites, monitors the dark web for exposures like the DentaQuest leak, and keeps re-submitting removal requests when brokers relist your data — which they routinely do. Reducing your public footprint is the one long-term step that actually stays effective after a breach.
Class-Action Lawsuit Status
A federal class action, Hufnus v. DentaQuest Group Inc., was filed in the U.S. District Court for the District of Massachusetts on June 23, 2026, and multiple additional complaints have been filed since. As of September 2026 there is no approved settlement — healthcare breach class actions of this size typically take 1–3 years to resolve. If you received a notification letter, keep it and any related mail; it will be needed to join any eventual class. You do not need to file an individual claim while class actions are still forming.
The Rise of Healthcare Breaches in 2026
DentaQuest is the largest but not the only healthcare breach of 2026. ShinyHunters returned in late August with a claimed 284 million-record theft from pharmaceutical distributor McKesson, and Blue Shield of California, Change Healthcare, and Navia Benefit Solutions have all disclosed multi-million-record incidents this year. Complete medical records sell for 10 to 40 times more than credit card numbers on dark web marketplaces — which is why healthcare organizations are now the top ransomware target in the country.
How PrivacyOn Helps After the DentaQuest Breach
- Dark web monitoring alerts you when your DentaQuest data appears for sale or in new dumps
- Data broker removal pulls your personal information from 100+ people-search sites — reducing the ammunition for identity thieves
- 24/7 continuous monitoring catches new exposures as they happen, not months later
- Family plans cover up to 5 people, so children on your DentaQuest policy are protected too
- Starts at $8.33/month — a fraction of the cost of restoring a stolen identity
Take Action Today
PrivacyOn's dark web monitoring and data broker removal are the long-term protection layer breaches like DentaQuest require. Start protecting your family today — plans from $8.33/month.
Frequently Asked Questions
How many people were affected by the DentaQuest data breach?
DentaQuest has confirmed at least 15 million people were affected. An independent analysis of the leaked dataset by security researchers puts the potential total at over 23.4 million individuals based on unique name-plus-date-of-birth combinations. Notifications began July 17, 2026 and are being sent in waves, so the confirmed number may continue to rise.
Was my Social Security number exposed in the DentaQuest breach?
Yes. Updated disclosures confirm Social Security numbers were among the data stolen, along with dates of birth, addresses, driver's license numbers, Medicaid and Medicare numbers, and dental treatment details. This combination is enough for full identity theft — treat it accordingly.
Is the free credit monitoring from DentaQuest enough?
The 24 months of free credit monitoring and identity restoration DentaQuest is offering is worth enrolling in, but it is not enough on its own. Credit monitoring alerts you after suspicious activity occurs. A credit freeze prevents new accounts from being opened in the first place, and data broker removal shrinks the personal information attackers can use to impersonate you. Use all three together.
How do I know if my child's data was exposed?
DentaQuest filed a separate notification letter with the California Attorney General specifically addressed to parents of affected minors. If your child is enrolled in a DentaQuest-administered Medicaid or CHIP plan, assume their data was exposed and place a child credit freeze at all three bureaus — it is free and prevents adult identity theft down the road.
Is there a DentaQuest class-action settlement yet?
Not as of September 2026. A federal class action (Hufnus v. DentaQuest Group Inc.) was filed in the District of Massachusetts on June 23, 2026, and other complaints have followed, but the case is still in early litigation. Keep your notification letter — you will need it to join any eventual class.
What is the best long-term protection after a healthcare breach?
Because the DentaQuest data will circulate on the dark web indefinitely, the highest-value long-term steps are (1) keeping credit frozen except when you actively apply for credit, (2) enabling two-factor authentication everywhere, and (3) subscribing to a data broker removal service like PrivacyOn that continuously removes your personal information from people-search sites so attackers cannot easily combine it with the leaked medical data.