DentaQuest Data Breach: What to Do If Your Health Data Was Exposed

DentaQuest says at least 15 million people were hit by a breach claimed by ShinyHunters. How to guard against medical identity theft and fraud right now.
DentaQuest, the largest Medicaid and CHIP dental benefits administrator in the US, which also serves Medicare Advantage members, operating in all 50 states, began mailing notification letters on a rolling basis on July 17, 2026, in a breach it says affected at least 15 million people. The company says intruders had unauthorized access to its network between May 17 and May 20, 2026, and that the information taken included names, addresses, Social Security numbers, member ID numbers, Medicaid and Medicare numbers, and dental or vision health details such as provider names, diagnoses, treatment records and billing information. The extortion group ShinyHunters claimed responsibility and posted stolen files to a dark web leak site after, according to the group, ransom talks with DentaQuest failed.
What we could confirm: the 15 million figure comes from DentaQuest's own notification process, reported by the HIPAA Journal and cited in TechCrunch's tally of 2026's biggest breaches as "the largest known breach of 2026." One independent researcher who analyzed the leaked data told HIPAA Journal the total could exceed 23.4 million. We could not independently confirm DentaQuest's exact entry on the HHS Office for Civil Rights breach portal at the time of writing, so treat 15 million as DentaQuest's disclosed figure rather than a final count. The guidance below applies either way.
Why health and insurance data matters
A stolen credit card number gets cancelled and reissued in days. Health and insurance data is harder to change and lasts longer in criminal hands. Your Social Security number, Medicaid or Medicare number and member ID can be used to open new credit lines, file fraudulent tax returns, or commit medical identity theft, where someone uses your identity to receive medical care or equipment billed to your insurance. That can leave false information in your medical records, generate bills for care you never received, and in some cases affect your coverage or benefits eligibility until it is corrected. Because this breach also includes diagnosis, treatment and billing detail, the exposed data is also useful to scammers building a convincing story to call or text you as if they already know your medical history.
What to do right now
- Confirm whether you were notified. If you received a letter from DentaQuest, keep it. DentaQuest is offering 24 months of free credit monitoring and identity restoration through Kroll to those it has notified; see the official notice for enrollment details. If you had DentaQuest dental or vision coverage through a Medicaid or Medicare Advantage plan but have not received a letter yet, that does not mean you are unaffected. Notifications are going out on a rolling basis.
- Place a security freeze at all three credit bureaus. A freeze is free and stops most companies from opening new credit in your name. Do it at all three separately, since a freeze at one does not cover the others: Equifax, Experian and TransUnion. Keep the PIN or password each site gives you, since you will need it to lift the freeze later if you apply for credit yourself.
- Or place a fraud alert if a freeze feels like too much friction. A one-year alert, placed through any one bureau, tells lenders to verify your identity before opening new accounts. It is weaker than a freeze but easier to manage.
- Watch your Explanation of Benefits (EOB) statements. Your plan typically sends an Explanation of Benefits (EOB) after it processes a claim; if you don't receive them, ask your plan or check its member portal. Read it. If you see a provider you never visited, a service you never received, or dates that do not match your care, that is a sign of medical identity theft. Contact your insurer's fraud department immediately and ask them to open an investigation.
- Request an accounting of disclosures from your health plan. Under HIPAA (45 CFR 164.528), you can request an accounting of certain disclosures of your health information over the past six years. This excludes routine treatment, payment and operations disclosures, so pair the request with your claims and billing records from your plan. If something looks wrong on an EOB, this record helps establish what happened and when.
- File a recovery plan at identitytheft.gov. This is the free federal government tool for identity theft recovery. It generates a personalized step-by-step plan, and if needed, an FTC Identity Theft Report that helps you dispute fraudulent accounts and remove them from your credit file.
- If you lost money because of this breach, report it to the FBI's Internet Crime Complaint Center at ic3.gov. This applies if a scammer used the leaked information to trick you into a payment, not simply because your data was exposed.
- Check your credit reports. You can get free weekly reports from each bureau at AnnualCreditReport.com. Look for accounts you do not recognize.
Watch for these follow-on scams
Every large breach is followed by a second wave of scams that use the news of the breach itself as bait. Be alert to the following.
- Fake "breach support" calls or texts. Scammers impersonate DentaQuest, your insurer, or a credit bureau, claiming they need to "verify your identity" or "activate your free monitoring" and asking for your Social Security number, card number, or a one-time passcode. No legitimate breach response line asks for full account numbers or codes over the phone.
- Phishing emails and texts with links to "check if you were affected." These often lead to fake login pages designed to steal your real credentials. If you already clicked a suspicious link, see our guide on what to do after clicking a phishing link, and for background on how these messages are built to look convincing, read how phishing works and how to spot it.
- Fake credit monitoring or "protection" offers. If someone contacts you asking you to pay for credit monitoring related to this breach, it is not legitimate. DentaQuest's own offer, if you qualify, comes through its official notification letter, not an unsolicited call or email asking for payment.
- Unauthorized charges after a scam. If a scammer used stolen information to make a card charge in your name, you may be able to dispute it directly with your card issuer. Our chargeback guide explains how that process works.
FAQ
How do I know if I was one of the people affected?
DentaQuest is mailing notification letters on a rolling basis to those it has identified. If you or a family member had DentaQuest dental or vision coverage through Medicaid or a Medicare Advantage plan, watch your mail, and consider placing a credit freeze regardless while notifications continue.
Is a credit freeze enough to protect me, since health data was also exposed?
A freeze protects against new credit and loan accounts being opened in your name, but it does not stop medical identity theft on its own. Pair it with reviewing your Explanation of Benefits statements and, if anything looks off, requesting an accounting of disclosures from your insurer (it covers the past six years but excludes routine treatment and payment disclosures, so also ask for your claims and billing records).
Do I need to pay for identity theft protection after a breach like this?
No. The tools that matter most, credit freezes at the three bureaus, a recovery plan at identitytheft.gov, and reporting losses to ic3.gov, are all free. DentaQuest's own offer of 24 months of free credit monitoring and identity restoration through Kroll is worth using if you qualify, but do not pay a third party for "breach protection" solicited by phone or email.
Sources: TechCrunch, "The worst hacks and breaches of 2026 so far" · HIPAA Journal, DentaQuest breach notification coverage · FTC, identitytheft.gov · FBI Internet Crime Complaint Center
If you have been targeted, you are not alone. See our country-by-country cybercrime help hub for step-by-step reporting and recovery guides.