DentaQuest, a dental benefits administrator managing Medicaid and Medicare programs across 35 states, filed an official breach notification revealing up to 23.4 million individuals potentially affected by a network intrusion — nearly ten times the victim count initially claimed when stolen data appeared online weeks earlier.
DentaQuest’s Official Notification Confirms Scope and PHI Categories
The network intrusion occurred between May 17 and 20, 2026, when hackers accessed DentaQuest’s computer systems and exfiltrated patient and administrative records at scale. DentaQuest’s breach notification, filed with state attorneys general and issued as written letters to affected individuals, places the potential impact at 23.4 million people, with at least 15 million confirmed affected. DentaQuest identified 4.5 million individuals who can be directly located in its records and is mailing written notification letters to each of them. The company administers dental benefits for more than 30 million enrollees across state Medicaid programs in 35 states, a coverage footprint that defines the outer boundary of the potential exposure.
Medicaid IDs, Dental Diagnosis Codes, SSNs, and Billing Records Among Stolen Data
The breach exposed a broad set of data categories: names, addresses, Social Security numbers, dates of birth, email addresses, phone numbers, and government-issued identification numbers including Medicaid and Medicare member IDs. Clinical records were also compromised, including dental diagnosis codes, treatment details, and billing information. The combination of government health program identifiers with detailed clinical and billing records creates a comprehensive profile that enables medical identity theft — where criminals use victims’ government program credentials to obtain dental care billed to Medicaid or Medicare — in addition to conventional financial identity fraud.
ShinyHunters’ 234 GB Leak and the Nearly 10x Discrepancy With the Official Notification Count
The extortion group ShinyHunters claimed responsibility for the breach and published approximately 234 GB of stolen data. An earlier report placed the exposure at approximately 2.6 million individuals — the figure ShinyHunters cited at the time of the data release. DentaQuest’s official notification now places that count at up to 23.4 million potentially affected, illustrating the gap between an extortion group’s public claim and an organization’s full internal accounting of compromised records across its entire enrollment database. DentaQuest has not officially confirmed the attack method or named the threat actor responsible in its notification filing.
DentaQuest’s 24-Month Monitoring Offer and Its Limits for Medicaid Beneficiaries
DentaQuest is offering 24 months of free credit monitoring, fraud consultation, and identity theft restoration services through a third-party provider to affected individuals. The population exposed is predominantly composed of low-income Medicaid beneficiaries — people who rely on government health programs for dental coverage and who have limited independent resources for legal identity theft recovery.
Medical identity theft involving Medicaid records operates on a different detection timeline than financial fraud. Fraudulent dental claims are billed to government programs rather than appearing on a personal bank statement, and affected individuals may only discover the theft when their Medicaid dental benefits are suspended, denied, or exhausted by claims they never filed. The 24-month credit monitoring window covers conventional financial identity fraud, but government program fraud may not trigger a credit alert at all, leaving a meaningful gap in the protection DentaQuest’s offer provides. Unlike financial fraud, which typically surfaces through bank statement anomalies and credit bureau alerts, Medicaid dental benefit fraud surfaces through the government program itself — and only when a victim attempts to use benefits already consumed by fraudulent claims. At 23.4 million potentially impacted, the DentaQuest breach ranks among the largest healthcare data compromises of 2026, with the disproportionate exposure of Medicaid enrollees amplifying the harm potential relative to breaches affecting populations with greater resources to respond.