Skip to content

DentaQuest data breach exposes health and personal data of 15 mn people

DentaQuest data breach affects at least 15 mn people

DentaQuest, part of Sun Life Insurance, is notifying millions of people after a cybersecurity incident exposed personal, insurance and health-related information. The company has confirmed at least 15 mn people were affected, while the final number remains under review.

DentaQuest discovered unauthorized access to its network on May 20. Its investigation determined attackers had access to parts of the network between May 17 and May 20, according to the company’s breach notice.

Information involved in the incident includes names, addresses, Social Security numbers, member identification numbers, Medicaid and Medicare numbers, benefits provider names, diagnoses, treatment details and billing information. DentaQuest said its data review is continuing as it works to identify affected individuals.

Filings with attorneys general in Texas, Massachusetts and South Carolina indicate notification letters are being sent to at least 4.5 mn people. HIPAA Journal reported that DentaQuest has confirmed at least 15 mn affected individuals, while an independent analysis estimated the number potentially involved at more than 23.4 mn.

DentaQuest began sending notification letters on a rolling basis in July. Affected individuals are being offered 24 months of complimentary credit monitoring, fraud consultation and identity theft restoration services.

ShinyHunters claims responsibility for DentaQuest breach

DentaQuest has not publicly identified the group behind the intrusion. ShinyHunters, a data theft and extortion group, claimed responsibility and said it stole around 234 GB of information from the company’s systems.

The group later published data after attempts to obtain a payment from DentaQuest failed, according to material posted on its leak site. Have I Been Pwned analyzed part of the exposed dataset and identified approximately 2.6 million unique email addresses.

The leaked records also contained names, physical addresses, phone numbers, dates of birth, gender information and government-issued identifiers. Some files included Medicaid IDs, other insurance information and healthcare enrollment records.

A later review of the leaked material found a folder containing more than 1.7 million unique Social Security numbers, according to HIPAA Journal. The publication reported that those records appeared to be associated with an organization in Texas and could relate to children.

DentaQuest said it moved to secure its systems after discovering the unauthorized access and launched a forensic investigation. The company also brought in Kroll to assist with reviewing the affected data and determining which individuals were involved.

The scale of the review remains substantial. Hundreds of thousands of files were reportedly taken, and some of the information dates back to at least 2009, according to a security researcher cited by HIPAA Journal.

DentaQuest is part of Sun Life U.S. Dental and operates across all 50 states. The company administers dental benefits for Medicaid programs, Medicare Advantage plans, employers, health plans and individual customers, serving tens of millions of people nationwide.

The breach affects a large volume of insurance and health-related data rather than account credentials alone. DentaQuest continues to notify affected individuals as its review identifies additional records and people involved in the incident.