DentaQuest network data incident

Unauthorized access to data on DentaQuest's computer network between May 17 and May 20, 2026. Personal-identification, benefits, dental, and vision information accessed during the DentaQuest incident.

Last modified

Summary

  • Environment: Date DentaQuest discovered unauthorized individuals had accessed network data.
  • Operational impact: No outage or recovery duration quantified
  • Financial impact: No public cost estimate
  • Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.

What happened

Unauthorized access to data on DentaQuest’s computer network between May 17 and May 20, 2026. [2][3]

Impact

Personal-identification, benefits, dental, and vision information accessed during the DentaQuest incident. [1][2]

Documented data types include:

  • Patient account numbers — Member identification numbers; affected fields varied by individual and the review remained ongoing. [1][2]
  • Dates of birth — Dates of birth reported in Texas Attorney General report BR-0005182; affected fields varied by individual. [1][2]
  • Clinical information — Dental or vision information including provider name, diagnosis, treatment, and billing information; affected fields varied by individual. [1][2]
  • Social Security numbers — Social Security numbers; affected fields varied by individual and the review remained ongoing. [1][2]
  • Contact information — Addresses; affected fields varied by individual and the review remained ongoing. [1][2]
  • Names — Names; affected fields varied by individual and the review remained ongoing. [1][2]
  • Health insurance information — Medicaid numbers, Medicare numbers, and other health-plan information; affected fields varied by individual. [1][2]

A cited record reports 3,973,000 individuals (Texas residents in report BR-0005182; a subset of the overall reported count and not additive; as of 2026-07-17). [1][2]

A cited record reports 15,000,000 individuals (Overall individuals affected as reported in Texas Attorney General report BR-0005182; regulator-reported and not independently verified; as of 2026-07-17). [1][2]

The incident affected certain personal information for some DentaQuest members, providers, and other connected individuals. [2]

Timeline

  1. Activity began

    Beginning of the unauthorized-access window determined by DentaQuest’s investigation.

    [2]
  2. Documented activity ended

    DentaQuest said the incident ended by May 20, 2026.

    [2]
  3. Discovery

    Date DentaQuest discovered unauthorized individuals had accessed network data.

    [2]
  4. Public disclosure

    Date of DentaQuest’s public substitute notice.

    [2]
  5. Public disclosure

    Date DentaQuest said individual incident notifications would begin to issue.

    [2]
  6. Briefing updated

    This briefing was last reviewed and updated on August 9, 2026.

Threat Group & Attack Vector

The cited public record does not establish a specific initial-access vector, malware family, exploited vulnerability, or ATT&CK technique.

Actors

  • No threat actor group has been identified in the reviewed public evidence.

TTPs

  • No specific MITRE ATT&CK technique is currently mapped for this case.

Response

DentaQuest said it enhanced security and monitoring controls and provided additional employee training after the incident. DentaQuest said it immediately secured the network, notified law enforcement, and engaged independent cybersecurity experts to investigate. DentaQuest offered affected individuals 24 months of Kroll identity monitoring at no charge, including credit monitoring, fraud consultation, and identity-theft restoration. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [2]