Almeida Law Group is investigating a data breach at DentaQuest. If you were affected, contact Almeida Law Group.
About DentaQuest
DentaQuest is a dental and vision benefits administrator headquartered in Wellesley Hills, Massachusetts. It is the second-largest dental benefits administrator in the United States, serving approximately 32 million beneficiaries, and is the largest Medicaid and CHIP dental benefits administrator in the country. DentaQuest also covers Medicare Advantage, employer groups, health plans, and individual customers, and operates more than 70 oral health centers that provide direct patient care. The company is a subsidiary of Sun Life U.S., which acquired it for approximately $2.5 billion in 2022. Because DentaQuest administers government-sponsored dental and vision benefits, it holds detailed health and personal information for tens of millions of people, making the scope of a breach particularly significant.
What Happened?
DentaQuest was listed in a Vermont Attorney General breach report summary dated September 28th, 2026, identifying the incident type as unauthorized access and the compromised data category as health records.
According to DentaQuest’s own investigation, attackers gained unauthorized access to its network between May 17th, 2026 and May 20th, 2026, when the intrusion was discovered. DentaQuest secured its systems, engaged cybersecurity firm Kroll for forensic analysis and data mining, and publicly confirmed the incident on June 2nd, 2026. The company reported the breach to the U.S. Department of Health and Human Services on July 16th, 2026. Notification letters began going out on July 17th, 2026, with 24 months of complimentary credit monitoring offered to affected individuals. More than 15 million individuals are listed as affected in federal filings, making this the largest healthcare data breach reported to the U.S. government so far in 2026. The data confirmed compromised by DentaQuest includes names, addresses, Social Security numbers, member identification numbers, Medicaid numbers, Medicare numbers, and dental or vision health information such as provider names, diagnoses, treatments, and billing information. Have I Been Pwned’s independent analysis of the leaked dataset also identified email addresses, phone numbers, dates of birth, genders, and government-issued IDs in healthcare enrollment files.
The threat group ShinyHunters claimed responsibility for the attack, alleging it exfiltrated 234 gigabytes of data and attempted ransom negotiations before leaking the stolen data on a dark web site after those negotiations failed. These are attacker-side claims; DentaQuest’s own breach notice confirmed unauthorized access and specific data types but did not name ShinyHunters. Multiple class action lawsuits have been filed, including Whitlow v. DentaQuest Group Inc. et al., Case No. 1:26-cv-13868, alleging negligence, breach of implied contract, breach of fiduciary duty, unjust enrichment, and violations of the Illinois Personal Information Protection Act; King v. DentaQuest Group Inc., filed June 4th, 2026; and Hufnus v. DentaQuest Group Inc., No. 1:26-cv-12851, filed June 23rd, 2026. As of July 31st, 2026, thirteen federal cases had been consolidated. Sun Life’s Q2 2026 SEC filing acknowledged putative class actions seeking unspecified damages are at an early stage. No prior DentaQuest-specific data breaches were identified in research.
Key Facts at a Glance
- Company or Organization: DentaQuest
- Industry: Insurance / Dental and Vision Benefits Administration / Healthcare
- Location: Wellesley Hills, Massachusetts
- Incident type: Unauthorized access to network
- Date of breach: May 17th, 2026
- Date breach discovered: May 20th, 2026
- Date of consumer notification: July 17th, 2026
- Total persons affected: More than 15 million
- Identity theft protection offered: 24 months of complimentary credit monitoring
- Prior breach: None identified specific to DentaQuest
- Litigation status: Multiple class action lawsuits filed; thirteen federal cases consolidated as of July 31st, 2026
- Source: Vermont Attorney General breach report summary; HIPAA Journal; Have I Been Pwned; HLTH; Top Class Actions – ShinyHunters cyberattack; Sun Life SEC Form 6-K (Q2 2026)
What Should You Do?
If you received a notification letter from DentaQuest, enroll in the 24 months of complimentary credit monitoring offered before the enrollment deadline stated in your letter. Whether or not you received a letter, consider placing a fraud alert or credit freeze with all three major credit bureaus — Equifax, Experian, and TransUnion — to make it harder for someone to open new accounts in your name. Review your credit reports for unfamiliar accounts or inquiries at AnnualCreditReport.com. Because dental and vision health information was confirmed compromised, review your Explanation of Benefits statements and any medical or dental records for services you did not receive, which could indicate medical identity theft. If you find anything suspicious, report it at IdentityTheft.gov.
Your Legal Rights
If your personal or health information was involved in this breach, you may have legal rights depending on the facts of the incident and the law in your state. Almeida Law Group represents consumers in data breach and privacy litigation and can help you evaluate whether you may have a claim. Contact us at (708) 529-5418 or through our contact page for a free case evaluation.