15M patients impacted by largest healthcare data breach of 2026
The second-largest dental insurance company revealed that it suffered a cyberattack in May, impacting 15 million patients. The incident sets a record for 2026 as the largest data breach of a healthcare entity.
Although the Massachusetts-based company put out a notice in July alerting the public to the “cybersecurity event” in July, adding that it will be sending out notices to victims, it did not include any details on how many there were.
Those details came out when the U.S. Department of Health and Human Services’ Office for Civil Rights updated its healthcare data breach tracker sometime later, where the number of victims is said to be exactly 15 million.
Stolen information, according to DentaQuest, may include names, addresses, Social Security numbers, member identification numbers, Medicaid and Medicare IDs, provider names, details on diagnoses and treatments, and additional billing information.
The company did not provide a lot of details as to the nature of the breach. It’s unknown how the unauthorized third party gained access to its network. However, a posting on the dark web may provide some clues.
Data on the dark web
A notorious cybercrime cell—known for its deployment of ransomware—posted a notice on a dark web leak site in June, threatening to release a 234-gigabyte data trove it said was stolen from DentaQuest.
According to the hackers, it had data on more than 2.1 million patients in its possession, including sensitive medical records and information that could be used to identify individuals. The group posted screenshots as evidence their bounty is real.
DentaQuest did not confirm whether or not ransomware was deployed. The company has also not responded to claims made by ShinyHunters.
HealthExec reached out to the dental insurance administrator for comment.
It is unclear what happened to the data trove.
The hack was confirmed to have occurred between May 17 and May 20, meaning the unauthorized third party was inside the DentaQuest network for three days. The company said it worked with an outside cybersecurity firm to investigate the scope of the breach and to re-secure its systems.
“We have taken steps to further safeguard our systems, including enhancing our security and monitoring controls and providing additional employee training,” DentaQuest wrote.
Breach notices were sent to individuals beginning on July 17, the dental payer stated. Victims will be given complimentary access to identity theft protection and credit monitoring services, should they wish to sign up.
DentaQuest serves roughly 32 million dental and vision beneficiaries nationwide.
