DentaQuest, LLC
ent_019e57ad257eaad4f6ec03a2c2c6c73e
Disclosures
24
State AG · HHS OCR · Leak Site · 15 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
27,400,000
nationwide · State AG ID
Leak-site claims
2
unverified actor claims
Identity resolution
- Canonical name
- DentaQuest, LLC
- Normalized
- dentaquest— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300ZCNU2PLEFURZ45
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (24)newest first
- Idaho State AGas victim2026-08-12
DentaQuest, a dental and vision benefits provider for Humana Medicaid and D-SNP plans, experienced a data breach affecting 26 Idaho residents. A threat actor used social engineering to compromise an employee account, gaining unauthorized access to DentaQuest's IT environment from May 17-20, 2026. The accessed data included names, addresses, member IDs, Medicaid/Medicare numbers, dental/vision health information, and in some cases, Social Security Numbers. DentaQuest contained the incident, engaged CrowdStrike for investigation, and is offering 24 months of identity monitoring via Kroll. Humana notified the Idaho Attorney General as part of its Business Associate agreement.
- Idaho State AGas victim2026-08-03
DentaQuest, LLC filed a supplemental notice with the Idaho Attorney General on August 3, 2026, updating the scope of a prior cybersecurity incident. The breach affected at least 3,200 Idaho residents and over 27.4 million individuals nationwide, involving access to Protected Health Information (PHI) and Personal Information (PII). The investigation remains ongoing, and affected individuals are being offered two years of complimentary credit monitoring.
- Massachusetts State AGas victim2026-07-30
DentaQuest, a dental and vision benefits provider, notified Massachusetts residents of a data breach occurring between May 17 and May 20, 2026. Unauthorized individuals accessed and posted member data, including names, SSNs, Medicaid/Medicare numbers, and health information, on the internet. DentaQuest engaged forensic experts, reported to law enforcement, and offered 24 months of Kroll identity monitoring. The incident was discovered on May 20, 2026.
- Idaho State AGas victim2026-07-30
DentaQuest, LLC, a dental and vision benefits provider for Humana Medicaid/D-SNP plans, experienced a security incident impacting 26 Idaho residents. A threat actor gained unauthorized access to DentaQuest's IT environment on May 17, 2026, using compromised credentials obtained via a social engineering attack targeting a single employee. The actor accessed personal and health information (including SSNs) before being contained on May 19, 2026. Humana notified the Idaho AG on July 30, 2026. Affected individuals received notification letters and offers for credit monitoring via Kroll.
- New Hampshire State AGas victim2026-07-29
DentaQuest, LLC, a dental and vision benefits provider for Humana Medicaid and D-SNP plans, reported a cybersecurity incident to the New Hampshire Attorney General on July 29, 2026. This is a supplemental notice to a prior filing from July 17, 2026. The breach involved unauthorized access via a social engineering attack targeting a single employee's SSO credentials. The incident occurred between May 17 and May 20, 2026. Data exposed includes names, addresses, SSNs, Medicaid/Medicare numbers, and dental/vision health information. 189,492 individuals were affected nationwide, including 5 in New Hampshire. The threat actor posted data on the internet. DentaQuest engaged CrowdStrike, revoked access, and offered 24 months of Kroll identity monitoring.
- Texas State AGas victim2026-07-17
DentaQuest, LLC based in Wellesley Hills, Massachusetts, a healthcare – medical provider entity reported a data breach to the Texas Attorney General. The breach was discovered on 2026-05-20 and reported on 2026-07-17. 3,973,000 Texas residents were affected. 15,000,000 individuals affected in total. Types of information involved: Name of individual;Address;Social Security Number Information;Medical Information;Health Insurance Information;Date of Birth.
- Nebraska State AGas victim2026-07-17
DentaQuest LLC notified Nebraska residents of a data breach discovered on May 20, 2026, involving unauthorized access to dental and vision health plan data. The incident occurred between May 17 and May 20, 2026. Affected data included names and health information. DentaQuest reported the incident to law enforcement, engaged cybersecurity experts, and offered 24 months of identity monitoring via Kroll.
- Delaware State AGas victim2026-07-17
DentaQuest LLC notified affected individuals in Delaware of a data breach occurring May 17-20, 2026. Unauthorized individuals accessed personal identification and dental/vision health information, which was posted on the internet. DentaQuest engaged cybersecurity experts, reported to law enforcement, and offered 24 months of Kroll identity monitoring. Data types included names, SSNs, and health records.
- Rhode Island State AGas victim2026-07-16
DentaQuest LLC, a dental and vision benefits provider, disclosed a data breach affecting over 15 million individuals nationwide, including at least 1,000 Rhode Island residents. The incident involved a social engineering attack (phishing) on May 17-19, 2026, where an employee provided credentials and MFA codes to a threat actor. The actor exfiltrated and published PHI, including SSNs, Medicare/Medicaid IDs, and health records, on the dark web. DentaQuest engaged CrowdStrike and Kroll, notified the FBI and HHS OCR, and is offering 24 months of identity monitoring.
- Washington State AGas victim2026-07-16
DentaQuest, LLC reported a phishing incident affecting at least 91,700 Washington residents and up to 15 million nationwide. Unauthorized access occurred May 17-19, 2026, via stolen credentials obtained through social engineering. Exfiltrated data included names, SSNs, DOBs, Medicare/Medicaid IDs, and PHI. DentaQuest engaged CrowdStrike and Kroll, notified the FBI and HHS OCR, and offered 24 months of identity monitoring. Data was posted on the dark web.
- California State AGas victim2026-07-16
DentaQuest LLC disclosed that unauthorized individuals accessed its computer network between May 17 and May 20, 2026. The incident involved the exfiltration and public posting of personal identification and dental/vision health information (PHI) for adults, minors, and deceased individuals. DentaQuest engaged forensic experts, secured the network, and is offering 24 months of identity monitoring via Kroll.
- South Carolina State AGas victim2026-07-16
DentaQuest LLC reported a data breach discovered on May 20, 2026, involving unauthorized access to its computer network between May 17 and May 20, 2026. The incident exposed personal identification, dental/vision health information, and for minors, Social Security numbers. DentaQuest engaged independent cybersecurity experts, reported the incident to law enforcement, and offered 24 months of identity monitoring via Kroll to affected individuals.
- Iowa State AGas victim2026-07-16
DentaQuest LLC reported a data security incident where a social engineering attack tricked an employee into providing credentials and MFA codes. The threat actor accessed and exfiltrated data from a network file share between May 17-19, 2026. Data included names, SSNs, DOBs, Medicare/Medicaid IDs, and PHI. Over 15 million individuals nationwide were affected, including 3,200 Iowa residents. The actor posted data on the dark web. DentaQuest engaged CrowdStrike and Kroll, notified the FBI and HHS OCR, and offered 24 months of credit monitoring.
- Massachusetts State AGas victim2026-07-16
DentaQuest LLC notified Massachusetts residents of a data breach occurring May 17-20, 2026. Unauthorized individuals accessed personal identification and dental/vision health information, which was subsequently posted on the internet. DentaQuest engaged cybersecurity experts, reported the incident to law enforcement, and offered 24 months of identity monitoring via Kroll.
- MASSACHUSETTSHHS OCRas victim2026-07-16
DentaQuest, LLC reported to HHS on 2026-07-16 a Hacking/IT Incident affecting 15000000 individuals. Breached information located on Network Server.
- Oregon State AGas victim2026-07-16
DentaQuest LLC reported a data breach to the Oregon Attorney General. The breach was reported on 2026-07-16. The breach occurred during 5/17/2026 - 5/19/2026. The breach was discovered on 5/20/2026. 15,000,000 individuals were affected. Notice was sent on 7/16/2026.
- Illinois State AGas victim2026-07-01
DENTAQUEST, LLC filed a data-breach notice with the Illinois Attorney General in July 2026 (case 26-07-1320). The register records the breach as discovered on May 20, 2026. Personal information types reported: medical information, ssn. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- GLOBALLeak Siteas victim2026-05-30
The company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don't care. | Size: 234GB+ (compressed) | Updated: 30 May 2026 | SHA256: db3088225c36be26ce2b458fa7a190176d071441e2e0830c0d82143e6323a3e1
- GLOBALLeak Siteas victim2026-05-28
You wouldn't want us to describe what data and how much data was compromised. It is in your best interests to reply to us or we are leaking it all by the deadline. This is a final warning to reach out by 29 May 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. Pay or Leak. | Updated: 28 May 2026 | Warning: FINAL WARNING PAY OR LEAK
- MASSACHUSETTSHHS OCRas victim2026-05-22
DentaQuest reported to HHS on 2026-05-22 a Unauthorized Access/Disclosure affecting 3086 individuals. Breached information located on Network Server. Business Associate present: Yes.
- New Hampshire State AGas victim2026-05-22
DentaQuest, a dental benefits provider, notified the New Hampshire Attorney General of a data security incident involving 3,086 NH residents. On March 27, 2026, a CMS Prior Authorization Interoperability Report was posted to DentaQuest.com containing a second tab with member-level PII, including names and Medicaid/Medicare ID numbers. DentaQuest discovered the error on March 30, 2026, removed the report, and notified HHS. Notices were mailed to affected individuals on May 22, 2026. No evidence of misuse was found.
- WISCONSINHHS OCRas victim2025-01-06
DentaQuest (Health Plan, WI) reported to HHS OCR on 2025-01-06 an Unauthorized Access/Disclosure breach affecting 868 individuals. Breached information was located on Paper/Films. No business associate was involved. No additional detail was provided in the web description.
- Massachusetts State AGas victim2021-05-19
DentaQuest LLC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2021-05-19. 4 Massachusetts residents were affected. The report records the breach type as paper.
- MASSACHUSETTSHHS OCRas victim2010-06-09
DentaQuest reported to HHS on 2010-06-09 a Theft affecting 10515 individuals. Breached information located on Laptop. A car containing an unencrypted laptop computer was stolen from West Monroe Partners, a contractor for the covered entity's (CE) business associate (BA), DentaQuest. The laptop stored a database containing the electronic protected health information (ePHI) of approximately 76,000 individuals, including data on 10,515 of the CE's members. The types of PHI involved in the breach included names, social security numbers, dates, and certain provider identification numbers. The CE and BA worked together to provide breach notification to affected individuals and the media, and offered free credit monitoring and enhanced credit services to affected individuals for one year. The CE reported the breach to HHS and provided substitute notification on its website. The BA implemented procedures to ensure that any third party laptops connecting to its network employ disk encryption. Further, the BA established a policy to prohibit contractors from storing PHI on laptops. The breach incident involved a BA and occurred prior to the September 23, 2013, compliance date. OCR verified that the CE had a proper BA agreement in place that restricted the BA's use and disclosure of PHI and required the BA to safeguard all PHI.