HomeIntelligenceBrief
BREACH BRIEF🟠 High Breach

DentaQuest Breach Exposes Personal & Dental Health Data of Over 23 Million Individuals

Hackers accessed DentaQuest’s network in May 2026, stealing personal and dental health records of more than 23 million people. The incident underscores the need for continuous SOC 2‑aligned privacy controls and audit‑ready evidence.

LiveThreat™ Intelligence · 📅 July 28, 2026· 📰 securityaffairs.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
4 recommended
📰
Source
securityaffairs.com

DentaQuest Breach Exposes Personal & Dental Health Data of Over 23 Million Individuals

What Happened — In May 2026, unauthorized actors infiltrated DentaQuest’s network and accessed personal and dental health records of more than 23 million people. The breach was discovered on May 20, the network was secured, and law‑enforcement was notified. The ShinyHunters extortion group later claimed responsibility, publishing 234 GB of stolen data after ransom talks failed.

Why It Matters for Compliance & Audit Readiness

  • Demonstrates the need for continuous monitoring of access controls and rapid incident‑response evidence to satisfy SOC 2 CC6 (Security) and CC7 (Privacy) audit requirements.
  • Highlights the importance of a documented privacy‑program framework (consent management, DSAR processes) that can be proved to regulators and auditors after a large‑scale data exposure.
  • Aligns directly with Verisq’s CookiePLUS capability, which provides automated consent capture, DSAR readiness, and audit‑ready privacy evidence.

Who Is Affected — Health‑care and dental‑benefits administrators; insurers; Medicaid and CHIP program participants; downstream providers that rely on DentaQuest data.

Recommended Actions

  • Map the incident to SOC 2 CC7 (Privacy) and CC6 (Security) controls; capture logs, containment steps, and notification timelines as audit evidence.
  • Verify that consent records for all affected data subjects are current; update consent where gaps are found.
  • Initiate a DSAR readiness review to ensure rapid response to any subject‑access requests stemming from the breach.
  • Conduct a post‑incident risk assessment and adjust third‑party monitoring policies for any vendors with network access.

Source: Security Affairs

Technical Notes

  • Attack window: May 17 – May 20 2026; exact entry method not disclosed (likely credential compromise or exploitation of an unpatched service).
  • Exfiltrated data: names, addresses, SSNs, Medicaid/Medicare IDs, dental diagnoses, treatment codes, billing details; ~2.6 M unique email addresses and 1.7 M SSNs identified.
  • No ransomware payload observed; extortion was attempted via public data dump.

Source: same article

📰 Original Source
https://securityaffairs.com/196100/data-breach/dentaquest-disclosed-a-data-breach-that-impacted-23-million-individuals.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · PrivacyOps · CookiePLUS

A privacy incident is a question about your consent record.

CookiePLUS and Verisq AI Trust Operations keep consent, DSAR, and data-handling evidence continuously ready — so a data-exposure event finds you prepared, not scrambling.

See how Verisq AI Trust Operations handles privacy →