▼
Allegations Only · No Settlement Yet
This article describes class action complaints and a threat actor's public claims. The statements
below are unproven allegations. DentaQuest has not been found liable, there is no certified class, and
nothing to claim at this time. This page is informational and is not legal advice.
DentaQuest, one of the largest dental-benefits administrators in the United States and part of Sun Life, has now put a number on its May 2026 data breach. On July 16, 2026, the company reported the incident to the U.S. Department of Health and Human Services as affecting 15,000,000 people, the largest health data breach reported to HHS so far this year, and on July 17 it began mailing notification letters.
The lawsuits have grown with it. The first federal complaints were filed within weeks of the attack, and on July 31, 2026, the U.S. District Court for the District of Massachusetts consolidated 13 of them into a single proceeding, In re: DentaQuest Group, Inc. Data Incident Litigation, No. 1:26-cv-12458. More suits have followed. The case is still at its earliest stage: the claims are unproven allegations, no class has been certified, and there is no settlement and nothing to claim.
When we first covered this case in July, DentaQuest had not published a count, and the only public figure was the roughly 2.6 million email addresses verified in a leaked dataset. That figure has been superseded by the company's own 15 million report.
Status
Cases Consolidated · Pleading Stage
In re: DentaQuest Group, Inc. Data Incident Litigation · D. Mass. · consolidated July 31, 2026
People Affected
15 million, as reported to HHS
Reported July 16, 2026 · DentaQuest says its review is continuing
Data Involved
Names, addresses, SSNs, member IDs, Medicaid & Medicare numbers, dental or vision health info
Per DentaQuest's notice letter · varies by person
Can I Claim?
No — nothing to claim yet
No settlement, no fund, no claim form · 24 months of free credit monitoring offered in the notice letter
According to DentaQuest's notice letter, filed with the Massachusetts Attorney General's office, the company discovered on May 20, 2026 that unauthorized people had accessed data on its computer network. Its investigation found the intruders had access from May 17 through May 20. DentaQuest says it secured its systems, began a forensic investigation, and brought in outside specialists to work out what data was taken and whose.
The letter says the information involved may include names, addresses, Social Security numbers, member identification numbers, Medicaid and Medicare numbers, and dental or vision health information such as provider name, diagnosis, treatment and billing information. What was involved varies from person to person, and each letter spells out what applied to its recipient. DentaQuest is offering 24 months of complimentary credit monitoring and identity-protection services, with enrollment instructions in each letter.
The 15,000,000 figure is the number DentaQuest gave HHS. It is a round number, and DentaQuest has said its review is not finished, so the count may change. Some security outlets have reported a potential population above 23 million, drawn from analysis of the leaked data rather than from a DentaQuest filing. That is not a company-confirmed count.
Free settlement alerts
Get notified when new class actions open to claims
Join thousands of readers who get the latest class action settlements you may qualify for — delivered straight to your inbox.
DentaQuest's notice does not name the attacker. The ShinyHunters extortion group publicly claimed responsibility, listing DentaQuest on its dark-web leak site around May 22–23, 2026 with a ransom demand and a May 27 deadline. After negotiations reportedly broke down, the group published what it said was about 234 GB of DentaQuest data around May 30. The volume figure is the attacker's own claim.
DentaQuest publicly confirmed a cybersecurity incident on June 2, 2026. The next day, the breach-notification service Have I Been Pwned added the leaked dataset after verifying about 2.6 million unique email addresses in it. That was the figure most early coverage used, including ours. It counts email addresses in one leaked file, not affected people, and it has been overtaken by the company's own report.
Plaintiffs began filing proposed class actions against DentaQuest in the District of Massachusetts within weeks of the attack. One of the earliest we tracked was Hufnus v. DentaQuest Group Inc, No. 1:26-cv-12851, filed June 23, 2026. On July 31, 2026, Judge Angel Kelley granted a motion to consolidate 13 of the cases, including Hufnus, under the lowest-numbered case, No. 1:26-cv-12458. The consolidated case is now captioned In re: DentaQuest Group, Inc. Data Incident Litigation, and filings in the member cases go on that master docket.
Complaints have continued to arrive since then. Whitlow v. DentaQuest Group Inc. et al, No. 1:26-cv-13868, filed in the same court, drew news coverage in early September because it cited the 15 million figure. Whether and when each later suit is formally folded into the consolidated case is up to the court.
Under the consolidation order, applications to serve as interim class counsel were due within seven days, and plaintiffs have 45 days after interim class counsel is appointed to file a single consolidated complaint. DentaQuest then has 45 days to respond, most likely with a motion to dismiss. Competing applications for interim class counsel were filed in August. As of the latest docket activity we could confirm, no consolidated complaint had been filed.
The complaints are proposed data-breach class actions. They allege that DentaQuest failed to adequately protect the personal and health information it held for plan members. According to reporting on the complaints, the allegations include not meeting regulatory and industry security standards, such as training staff to spot phishing and using multi-factor authentication. Plaintiffs seek damages and court-ordered security improvements. These are allegations only. DentaQuest has not responded on the merits, and no court has tested any of the claims.
DentaQuest administers dental benefits heavily through government programs such as Medicaid, CHIP and Medicare Advantage. That is why so many of the affected records carry Medicaid and Medicare numbers, and why the breach falls under HIPAA's notification rules.
No. The plaintiffs have not yet filed their consolidated complaint, so the case has not reached a motion to dismiss, class certification or settlement talks on the public record. There is no settlement fund, no claim form, no payout and no deadline. If the litigation settles, a court-appointed administrator would send notices and open a claims process. We will update this page and our data breach settlements hub if that happens. Be cautious of any website claiming you can "file a DentaQuest claim" today.
If you received a DentaQuest letter, keep it. It is the most reliable record that you are in the affected group, and settlement notices are typically sent to the same people. Consider enrolling in the free credit monitoring before the deadline printed in your letter. Because Social Security and Medicaid or Medicare numbers were involved for some people, review your explanation-of-benefits statements for care you did not receive, and consider a fraud alert or credit freeze with the major credit bureaus. Treat unexpected emails, texts or calls about your dental coverage with suspicion.
For similar health-data cases, see the Change Healthcare data breach and the Health Payment Systems data breach lawsuit. Our earlier DentaQuest breach investigation coverage covers the first weeks of the incident.
This page is informational and is not legal advice.
Has a class action lawsuit been filed over the DentaQuest data breach?
Yes — many. On July 31, 2026, Judge Angel Kelley of the U.S. District Court for the District of Massachusetts consolidated 13 federal cases into one proceeding, In re: DentaQuest Group, Inc. Data Incident Litigation, No. 1:26-cv-12458. More complaints have been filed in the same court since then. All of them contain unproven allegations; no class has been certified and DentaQuest has not been found liable.
Is there a DentaQuest data breach settlement?
No. The litigation is at the pleading stage and the plaintiffs have not yet filed their consolidated complaint. There is no settlement fund, no claim form, no payout and no deadline. Be cautious of any site claiming you can file a DentaQuest claim today.
How many people were affected by the DentaQuest data breach?
DentaQuest reported the breach to the U.S. Department of Health and Human Services on July 16, 2026 as affecting 15,000,000 people, the largest health data breach reported to HHS so far in 2026. Some security outlets have reported a larger potential population, above 23 million, but that figure is not a count DentaQuest has reported, and the company has said its review is continuing.
Were Social Security numbers exposed in the DentaQuest breach?
For some people, yes. DentaQuest's notice letter lists names, addresses, Social Security numbers, member ID numbers, Medicaid and Medicare numbers, and dental or vision health information such as provider name, diagnosis, treatment and billing information. The specific data involved varies from person to person, and each letter says what applied to that recipient.
What is DentaQuest offering people who got a breach letter?
DentaQuest is offering 24 months of complimentary credit monitoring and identity-protection services to people it notified. Enrollment instructions and the enrollment deadline are printed in each individual letter. That offer is separate from the lawsuits and does not waive anyone's rights in the class action.
• CourtListener — In re: DentaQuest Group, Inc. Data Incident Litigation, 1:26-cv-12458 (D. Mass.)
• PacerMonitor — consolidated DentaQuest docket
• Justia Dockets — Hufnus v. DentaQuest Group Inc, 1:26-cv-12851 (D. Mass.)
• Justia Dockets — Whitlow v. DentaQuest Group Inc. et al, 1:26-cv-13868 (D. Mass.)
• Massachusetts Attorney General — DentaQuest notice of data breach (filing 2026-1155)
• Healthcare Dive — "DentaQuest breach exposes data of 15M people, a record this year"
• HIPAA Journal — DentaQuest starts notifying 15 million+ individuals
• Medical Daily — DentaQuest says its review is not finished
• SecurityWeek — "DentaQuest Data Breach Potentially Impacts Over 23 Million People"
• Have I Been Pwned — DentaQuest breach entry (~2.6M email addresses)
• BankInfoSecurity — "ShinyHunters Leaks 234GB DentaQuest Data Trove"
For more class actions keep scrolling below.
Status
Consolidated — no consolidated complaint yet, no class certified, no settlement
Case Title
In re: DentaQuest Group, Inc. Data Incident Litigation
Case Number
1:26-cv-12458 (lead case)
Court
U.S. District Court, District of Massachusetts
Judge
Angel Kelley
Consolidated
July 31, 2026 (13 cases)
People Affected
15 million (reported to HHS July 16, 2026)