DentaQuest, a Massachusetts-based dental and vision benefits administrator, has disclosed a data breach affecting more than 15 million individuals after hackers accessed its computer systems this spring. According to a breach notice filed with federal regulators, the incident is the largest healthcare data breach reported to the U.S. government so far this year.
DentaQuest is the second-largest dental benefits administrator in the U.S. and serves approximately 32 million beneficiaries through its dental and vision plans. The company determined that unauthorized actors accessed its computer systems between May 17 and May 20.
Following the discovery, DentaQuest engaged financial and risk advisory firm Kroll to analyze the information potentially affected by the incident. The review found that a range of personal, sensitive and medical information may have been exposed. Potentially compromised data includes Social Security numbers, Medicaid and Medicare identification numbers, as well as diagnosis, treatment and billing information.
Multiple reports have attributed the attack to cyber threat group ShinyHunters. The Health Information Sharing and Analysis Center issued a threat bulletin about the group in July, highlighting its use of social engineering techniques. These tactics can include telephone calls designed to persuade individuals to disclose information or provide access that enables account compromise.
DentaQuest said in July that it had begun notifying individuals affected by the incident. The company also reported providing additional security training to employees and implementing more stringent security controls following the breach.
The incident comes amid continued cybersecurity pressure across the healthcare sector. Hacking has been the leading cause of healthcare data breaches reported to federal regulators since 2017, reflecting the persistent risks facing organizations that store personal and medical information.
Other recently reported incidents have included a breach involving revenue cycle vendor Unlimited Technology Systems and a cyberattack affecting a laboratory testing facility in New Jersey.
The scale of the DentaQuest incident is particularly significant given the volume and sensitivity of the information potentially involved. With more than 15 million individuals affected, the breach represents a major addition to the healthcare sector’s cyber incident totals for 2026 and reinforces the ongoing focus on security controls, employee training and protection against social engineering.
Click here for the original news story.
