▼
Allegations Only · No Settlement Yet
This page describes a data breach, a threat actor's public claims, and class action complaints
whose claims are unproven allegations. DentaQuest has not been found liable, no class has been
certified, and there is nothing to claim. This page is informational and is not legal advice.
Status
Class Actions Filed · Consolidated
13 cases consolidated July 31, 2026 (D. Mass.) — no class certified, no settlement
Scale
15 million, as reported to HHS
Reported July 16, 2026 · supersedes the ~2.6M email addresses first seen in the leaked dataset
Reportedly Involved
Names, addresses, SSNs, member IDs, Medicaid & Medicare numbers, dental or vision health info
Per DentaQuest's notice letter · varies by person
Can I Claim?
No — nothing to claim yet
No settlement, no fund, no claim form
DentaQuest, one of the largest dental-benefits administrators in the United States and a subsidiary of Sun Life, has reported that its May 2026 data breach affected 15 million people. The company reported that figure to the U.S. Department of Health and Human Services on July 16, 2026, making it the largest health data breach reported to HHS so far this year, and began mailing notification letters on July 17.
We first covered this incident in June, when the attorney investigations began and the scope was still unknown. At that point DentaQuest had confirmed only that an incident happened, and the only public figure was the roughly 2.6 million email addresses found in a dataset the attackers leaked. This page keeps that early record, corrected for what DentaQuest has since disclosed. For where the litigation stands now, see our DentaQuest data breach class action lawsuit page.
DentaQuest's first public statement, in early June 2026, said it was "actively managing a cybersecurity incident involving unauthorized access to a limited part of its network," that its systems remained operational, and that it had not yet determined the scope or what data was affected.
Its notice letter, filed with the Massachusetts Attorney General's office in July, filled in the details. DentaQuest says it discovered the intrusion on May 20, 2026, and that the intruders had access from May 17 through May 20. The information involved may include names, addresses, Social Security numbers, member identification numbers, Medicaid and Medicare numbers, and dental or vision health information such as provider name, diagnosis, treatment and billing information. What was involved varies by person. DentaQuest is offering 24 months of complimentary credit monitoring and identity-protection services, with enrollment instructions in each letter.
Free settlement alerts
Get notified when new class actions open to claims
Join thousands of readers who get the latest class action settlements you may qualify for — delivered straight to your inbox.
Before DentaQuest reported a number, the public figures came from the attacker:
• Threat-actor claims: the extortion group ShinyHunters claimed responsibility, said it took more than 234 GB of data and, after negotiations reportedly broke down, leaked it. DentaQuest's notice does not name the attacker, and the data-volume figure is the group's own claim.
• The ~2.6 million figure: security researchers found about 2.6 million unique email addresses in the leaked dataset. That counted email addresses in one file, not affected people. Early reporting on the dataset also noted no Social Security numbers among its verified fields, but DentaQuest's own notice now lists SSNs among the information involved for some people.
• Company-reported: 15,000,000 people, as reported to HHS on July 16, 2026. DentaQuest has said its review is continuing, and some security outlets have reported a potential population above 23 million based on analysis of the leaked data. That higher number is not a company-confirmed count.
Yes. Proposed class actions began arriving in the U.S. District Court for the District of Massachusetts within weeks of the attack, including Hufnus v. DentaQuest Group Inc, No. 1:26-cv-12851, filed June 23, 2026. On July 31, 2026, the court consolidated 13 of the cases into In re: DentaQuest Group, Inc. Data Incident Litigation, No. 1:26-cv-12458, and more suits have been filed since. The complaints' claims are unproven allegations — no class has been certified and DentaQuest has not been found liable. Our DentaQuest lawsuit page tracks the docket.
No. The consolidated case is at the pleading stage, and the plaintiffs have not yet filed their consolidated complaint.
There is no settlement fund, no claim form, no payout, and no deadline. No class has been certified. The free credit monitoring in DentaQuest's notice letter is a company offer, separate from the lawsuits. Be cautious of any website that claims you can "file a claim" for this matter today.
Keep any DentaQuest notification letter you receive and consider enrolling in the credit monitoring before the deadline printed in it. Treat any email or call about the breach with caution, since phishing often follows breaches. Monitor your insurance statements and financial accounts for unfamiliar activity, and consider placing a fraud alert or a credit freeze with the major credit bureaus. There is nothing to file right now. For related health-data incidents, see our coverage of the NYC Health + Hospitals data breach and the Change Healthcare data breach.
This page is informational and is not legal advice.
Is there a DentaQuest data breach settlement or class action?
Class actions have been filed, but there is no settlement. On July 31, 2026, the federal court in Massachusetts consolidated 13 cases as In re: DentaQuest Group, Inc. Data Incident Litigation, No. 1:26-cv-12458. The claims are unproven allegations, no class has been certified, and there is no settlement fund, no claim form, and nothing to claim.
How many people were affected by the DentaQuest breach?
DentaQuest reported the breach to the U.S. Department of Health and Human Services on July 16, 2026 as affecting 15,000,000 people and began mailing notification letters on July 17. The earlier figure of about 2.6 million counted unique email addresses in the leaked dataset, not affected people, and has been superseded by the company's report.
What information may have been involved?
DentaQuest's notice letter says the information involved may include names, addresses, Social Security numbers, member identification numbers, Medicaid and Medicare numbers, and dental or vision health information such as provider name, diagnosis, treatment and billing information. What was involved varies by person.
Who is DentaQuest?
DentaQuest is one of the largest dental-benefits administrators in the United States and a subsidiary of Sun Life. It administers dental (and some vision) benefits for tens of millions of Americans, heavily through government programs such as Medicaid, CHIP, and Medicare Advantage — which is why the incident involves protected health information.
What should I do if I'm a DentaQuest member?
Keep any DentaQuest notification letter you receive, consider enrolling in the 24 months of free credit monitoring it offers, monitor your insurance statements and accounts for unfamiliar activity, be alert to phishing, and consider a fraud alert or credit freeze. Because there is no settlement, there is nothing to claim right now.
• Massachusetts Attorney General — DentaQuest notice of data breach (filing 2026-1155)
• Healthcare Dive — "DentaQuest breach exposes data of 15M people, a record this year"
• CourtListener — In re: DentaQuest Group, Inc. Data Incident Litigation, 1:26-cv-12458 (D. Mass.)
• BleepingComputer — "DentaQuest data breach exposed info of 2.6 million accounts"
• HIPAA Journal — DentaQuest data breach coverage
• SecurityWeek — "Hackers Leak DentaQuest Information"
For more class actions keep scrolling below.
Status
Class actions consolidated July 31, 2026 — no class certified, no settlement
Company
DentaQuest (a Sun Life company)
People Affected
15 million (reported to HHS July 16, 2026)
Lead Case
In re: DentaQuest Group, Inc. Data Incident Litigation, No. 1:26-cv-12458 (D. Mass.)
Settlement
None — litigation at complaint stage