Privacy News DentaQuest breach notices sent to 15 million after health data theft

Brownie2019

Level 23
Thread author
Verified
Well-known
Forum Veteran
Mar 9, 2019
1,105
5,828
2,168
Germany
Hackers accessed insurance, treatment, and personal data months before victims were finally notified.
Key takeaways:
  • DentaQuest is notifying nearly 15 million people after hackers accessed sensitive personal and health information.
  • The stolen data may include insurance and billing information, medical diagnoses, and governemnt IDs.
  • One researcher found 1.7 million unique Social Security numbers, most of them appearing to belong to children.
  • The May breach adds to a growing wave of healthcare attacks exposing millions of patients at once.
DentaQuest has begun notifying 15 million people – including an undisclosed number of children – that their sensitive personal and health data was exposed during a breach claimed by the ShinyHunters hacker gang in May.

Considered to be one of the largest healthcare breaches in 2026, DentaQuest began sending the breach notification letters to affected patients on a rolling basis starting on July 17th.
Read more:
 
Important caution

The reported figures are serious, but the article’s claims should be checked against DentaQuest’s official breach notice and any relevant regulatory filings. In particular, the estimate of 1.7 million Social Security numbers and the number of affected children may be based on preliminary or third-party analysis rather than a finalized company determination.

People who receive a notice should:

  • Verify it independently using DentaQuest’s official website or a trusted phone number, rather than links or phone numbers in an unexpected message.
  • Read the notice carefully to determine which data categories were involved and whether complimentary credit-monitoring or identity-restoration services are offered.
  • Place a fraud alert or security freeze with the major credit bureaus if Social Security numbers or other identity data were exposed. A freeze is generally stronger because it restricts new-credit inquiries until removed.
  • Monitor medical statements, insurance activity, credit reports, bank accounts, and tax-related correspondence for unfamiliar activity.
  • Be especially cautious of follow-up phishing messages requesting passwords, payment, verification codes, or personal information.

A breach notification confirms that an organization believes information was involved; it does not by itself prove that every listed data type was misused. Anyone who receives a notice should preserve it and follow the official instructions, while treating unexpected “support” calls or emails as potentially fraudulent.