DentaQuest, LLC
ent_019e57ad257eaad4f6ec03a2c2c6c73e
Disclosures
14
State AG · Leak Site · HHS OCR · 11 jurisdictions
Incidents
2
filings grouped by incident
Max affected reported
15,000,000
as filed · State AG OR
Leak-site claims
2
unverified actor claims
Identity resolution
- Canonical name
- DentaQuest, LLC
- Normalized
- dentaquest— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300ZCNU2PLEFURZ45
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (14)newest first
- ⭐Texas State AGas victim2026-07-17
DentaQuest, LLC based in Wellesley Hills, Massachusetts, a healthcare – medical provider entity reported a data breach to the Texas Attorney General. The breach was discovered on 2026-05-20 and reported on 2026-07-17. 3,973,000 Texas residents were affected. 15,000,000 individuals affected in total. Types of information involved: Name of individual;Address;Social Security Number Information;Medical Information;Health Insurance Information;Date of Birth.
- 💎Delaware State AGas victim2026-07-17
DentaQuest LLC notified affected individuals in Delaware of a data breach occurring May 17-20, 2026. Unauthorized individuals accessed personal identification and dental/vision health information, which was posted on the internet. DentaQuest engaged cybersecurity experts, reported to law enforcement, and offered 24 months of Kroll identity monitoring. Data types included names, SSNs, and health records.
- 🌲Washington State AGas victim2026-07-16
DentaQuest, LLC, a health sector entity reported a phishing incident to the Washington Attorney General. The organization became aware of the incident on 2026-05-20 and filed notice on 2026-07-16. 91,700 Washington residents were affected. 57 days elapsed between awareness and notification. 3 days to identify the breach. 0 days to contain the breach.
- 🐻California State AGas victim2026-07-16
DentaQuest LLC disclosed that unauthorized individuals accessed its computer network between May 17 and May 20, 2026. The incident involved the exfiltration and public posting of personal identification and dental/vision health information (PHI) for adults, minors, and deceased individuals. DentaQuest engaged forensic experts, secured the network, and is offering 24 months of identity monitoring via Kroll.
- 🌴South Carolina State AGas victim2026-07-16
DentaQuest LLC reported a data breach discovered on May 20, 2026, involving unauthorized access to its computer network between May 17 and May 20, 2026. The incident exposed personal identification, dental/vision health information, and for minors, Social Security numbers. DentaQuest engaged independent cybersecurity experts, reported the incident to law enforcement, and offered 24 months of identity monitoring via Kroll to affected individuals.
- 🌽Iowa State AGas victim2026-07-16
DentaQuest LLC, a health care sector entity reported a data breach to the Iowa Attorney General. The breach was reported on 2026-07-16.
- 🦫Oregon State AGas victim2026-07-16
DentaQuest LLC reported a data breach to the Oregon Attorney General. The breach was reported on 2026-07-16. The breach occurred during 5/17/2026 - 5/19/2026. The breach was discovered on 5/20/2026. 15,000,000 individuals were affected. Notice was sent on 7/16/2026.
- 🏛️Massachusetts State AGas victim2026-07-01
DentaQuest LLC notified Massachusetts residents of a data breach occurring May 17-20, 2026. Unauthorized individuals accessed personal identification and dental/vision health information, which was subsequently posted on the internet. DentaQuest engaged cybersecurity experts, reported the incident to law enforcement, and offered 24 months of identity monitoring via Kroll.
- GLOBALLeak Siteas victim2026-05-30
The company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don't care. | Size: 234GB+ (compressed) | Updated: 30 May 2026 | SHA256: db3088225c36be26ce2b458fa7a190176d071441e2e0830c0d82143e6323a3e1
- GLOBALLeak Siteas victim2026-05-28
You wouldn't want us to describe what data and how much data was compromised. It is in your best interests to reply to us or we are leaking it all by the deadline. This is a final warning to reach out by 29 May 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. Pay or Leak. | Updated: 28 May 2026 | Warning: FINAL WARNING PAY OR LEAK
- MASSACHUSETTSHHS OCRas victim2026-05-22
DentaQuest reported to HHS on 2026-05-22 a Unauthorized Access/Disclosure affecting 3086 individuals. Breached information located on Network Server. Business Associate present: Yes.
- ⛰️New Hampshire State AGas victim2026-05-22
DentaQuest, a dental benefits provider, notified the New Hampshire Attorney General of a data security incident involving 3,086 NH residents. On March 27, 2026, a CMS Prior Authorization Interoperability Report was posted to DentaQuest.com containing a second tab with member-level PII, including names and Medicaid/Medicare ID numbers. DentaQuest discovered the error on March 30, 2026, removed the report, and notified HHS. Notices were mailed to affected individuals on May 22, 2026. No evidence of misuse was found.
- WISCONSINHHS OCRas victim2025-01-06
DentaQuest (Health Plan, WI) reported to HHS OCR on 2025-01-06 an Unauthorized Access/Disclosure breach affecting 868 individuals. Breached information was located on Paper/Films. No business associate was involved. No additional detail was provided in the web description.
- MASSACHUSETTSHHS OCRas victim2010-06-09
DentaQuest reported to HHS on 2010-06-09 a Theft affecting 10515 individuals. Breached information located on Laptop. A car containing an unencrypted laptop computer was stolen from West Monroe Partners, a contractor for the covered entity's (CE) business associate (BA), DentaQuest. The laptop stored a database containing the electronic protected health information (ePHI) of approximately 76,000 individuals, including data on 10,515 of the CE's members. The types of PHI involved in the breach included names, social security numbers, dates, and certain provider identification numbers. The CE and BA worked together to provide breach notification to affected individuals and the media, and offered free credit monitoring and enhanced credit services to affected individuals for one year. The CE reported the breach to HHS and provided substitute notification on its website. The BA implemented procedures to ensure that any third party laptops connecting to its network employ disk encryption. Further, the BA established a policy to prohibit contractors from storing PHI on laptops. The breach incident involved a BA and occurred prior to the September 23, 2013, compliance date. OCR verified that the CE had a proper BA agreement in place that restricted the BA's use and disclosure of PHI and required the BA to safeguard all PHI.