DentaQuest, a major U.S. dental and vision benefits administrator, is notifying millions of members that their personal and health information may have been exposed in a data breach discovered on May 20. The company’s investigation found that attackers had access to its network between May 17 and May 20.

According to DentaQuest’s incident notice, the exposed data includes names, addresses, Social Security numbers, member identification numbers, Medicaid and Medicare numbers, benefits provider names, diagnosis and treatment details, and billing information. The company is offering affected individuals 24 months of free credit monitoring, fraud consultation, and identity theft restoration services.

Scale of the Breach

The full scope of the incident has emerged gradually through regulatory filings. Notifications submitted to Attorney General offices in Texas, Massachusetts, and South Carolina indicate DentaQuest is sending written notices to at least 4.5 million people. However, the HIPAA Journal reports that more than 23.4 million individuals were potentially affected overall, with DentaQuest reportedly confirming at least 15 million impacted members.

DentaQuest is a subsidiary of Sun Life and serves roughly 35 million people across 50 states, making it one of the largest dental benefits administrators in the country.

ShinyHunters Claims Responsibility

While DentaQuest has not publicly attributed the attack to a specific threat actor, the extortion group ShinyHunters claimed responsibility and leaked approximately 234 GB of data allegedly stolen from the company. Data breach notification site HaveIBeenPwned reported in early June that the leaked material also included email addresses, phone numbers, dates of birth, and government-issued ID numbers, expanding on what DentaQuest itself disclosed.

Why It Matters

The combination of Social Security numbers, Medicaid and Medicare identifiers, and detailed clinical and billing records makes this data especially attractive for identity theft and healthcare fraud schemes. Security teams at organizations that partner with DentaQuest or process its member data should watch for phishing and social engineering attempts referencing exposed personal details, and individuals affected should enroll in the offered monitoring services and remain alert to unusual account or insurance activity.