|

DentaQuest Data Breach Lawsuit, Were You Affected? May v. DentaQuest Group, No. 1:26-cv-12458

DentaQuest Group Inc. is facing a federal class action, May v. DentaQuest Group, No. 1:26-cv-12458, over a data breach that exposed the Social Security numbers and health records of at least 15 million patients. If you or your child had DentaQuest dental or vision coverage, you weren’t imagining that letter in the mail. Here’s what the lawsuit means for you.

DentaQuest Data Breach — Key Facts

Lawsuit FiledJune 1, 2026 (first of at least a dozen related suits)
DefendantDentaQuest Group Inc. (DentaQuest LLC), a Sun Life subsidiary
Alleged HarmData breach exposing personal and health information of 15 million+ patients
Law AllegedNegligence, breach of contract, unjust enrichment, invasion of privacy
Who Is AffectedAt least 15 million people nationwide; DentaQuest’s review is ongoing
Court & Case NumberU.S. District Court, District of Massachusetts — No. 1:26-cv-12458
Current StageComplaint filed; no class certified; consolidation of related suits likely
Lead Plaintiff DeadlineUNVERIFIED — not publicly set as of this writing
Settlement StatusNo settlement, no claims process exists
Last UpdatedSeptember 8, 2026

Who Is DentaQuest and Why Are They Being Sued for the Data Breach?

DentaQuest is a Sun Life subsidiary and the largest dental and vision benefits administrator for state Medicaid and CHIP programs in the country, handling coverage for roughly 32 million people — most of whom never chose the company themselves. Their state assigned it to them. That setup means DentaQuest sat on a single database holding Social Security numbers, Medicaid ID numbers, and dental records for a population that had no say in who was protecting their data. When hackers broke in, they hit one company and reached patients in every state at once.

DentaQuest Data Breach Lawsuit, Were You Affected? May v. DentaQuest Group, No. 1:26-cv-12458

What Did DentaQuest Do to Patients Between May and July 2026?

Hackers first got into DentaQuest’s network on May 17, 2026. They had access for three days before DentaQuest caught it on May 20. A group calling itself ShinyHunters claimed responsibility, said it had stolen roughly 234 gigabytes of data, and demanded a ransom. DentaQuest didn’t pay. Around May 30, the group posted the stolen files online.

That’s where HIPAA comes in — the federal law that requires companies handling health data to protect it and notify people when it’s stolen. HIPAA doesn’t let patients sue directly, though. So the lawsuit against DentaQuest rests on older legal ground: negligence, breach of contract, unjust enrichment, and invasion of privacy. Put plainly, the complaint says DentaQuest promised to keep this information safe, didn’t, and should pay for what that failure cost patients.

By the time DentaQuest finished sorting out who was affected, the confirmed number landed at 15 million — with an independent researcher telling the HIPAA Journal the real total, once the leaked files are fully analyzed, could top 23.4 million. That gap matters. It means DentaQuest’s own count may still be catching up to the size of what actually happened.

Are You Part of the DentaQuest Data Breach Lawsuit?

Here’s exactly how to know if this breach touches your family.

You may be covered if you fall into one of these groups:

  • Anyone who had DentaQuest dental or vision coverage — including through a state Medicaid or CHIP program — any time before May 2026
  • Parents of children enrolled in DentaQuest’s Medicaid dental benefits, since minors make up an unknown share of the 15 million affected
  • People who received a notification letter from DentaQuest in July or August 2026 confirming their data was involved
  • Family members handling a deceased relative’s affairs, since DentaQuest sent a separate notice for deceased members

If you’ve never had dental or vision coverage through DentaQuest or a program it administers, this breach doesn’t involve you — even if you’ve seen the headlines.

The information at risk includes names, addresses, dates of birth, Social Security numbers, member ID numbers, Medicaid and Medicare numbers, and dental or vision treatment and billing details, according to DentaQuest’s own filing with the California Attorney General.

If your child has ever had Medicaid dental coverage, assume their Social Security number was part of this — and act like it.

DentaQuest Members Outside California — Are You Still Covered?

This is a nationwide breach, not a California-only event. DentaQuest filed its breach notice with California regulators because state law requires it, but the company also notified attorneys general in Texas, Massachusetts, and South Carolina — and it administers Medicaid dental benefits in all 50 states. If you had DentaQuest coverage anywhere in the country, the breach can include you.

Not sure if you qualify for the DentaQuest data breach lawsuit? A free consultation with a data privacy attorney can help you understand your options while the case moves forward.

What Are DentaQuest Patients Asking the Court to Award?

The plaintiffs in May v. DentaQuest Group are asking the court for damages to cover the cost of the breach — money for credit monitoring beyond what DentaQuest already offers, compensation for time spent dealing with the fallout, and, in some of the related complaints, punitive damages meant to punish the company rather than just repay a loss. No dollar figure has been set. No claim form exists. No settlement fund exists.

What Could DentaQuest Patients Receive If This Settles?

Nobody can put a number on this yet. Would a few years of free credit monitoring even cover what a stolen Social Security number can cost a family over the next decade? That’s the gap plaintiffs say DentaQuest needs to close. Healthcare data breach settlements have ranged from a few million dollars to well over a hundred million, depending on class size, the evidence, and how negotiations go. With more than a dozen suits already filed and consolidation likely, that process is still months away at best. Talk to a data privacy attorney before deciding whether to wait for a settlement or explore an individual claim.

What Should DentaQuest Patients Do Right Now?

  1. Most affected members don’t need to do anything to join the lawsuit yet. No sign-up. No claim form exists right now.
  2. Save your DentaQuest notification letter, any Medicaid or CHIP enrollment records, and — if you’ve noticed anything suspicious — bank or credit alerts.
  3. Write down what this has already cost you: hours on the phone, credit freezes, monitoring fees you’re paying out of pocket. That record matters if the case moves toward a settlement.
  4. Lead plaintiff deadline — UNVERIFIED. Courts haven’t set one publicly yet. If you want to be considered as a named plaintiff rather than a class member, talk to an attorney before that deadline is set.
  5. Monitor the docket. May v. DentaQuest Group, No. 1:26-cv-12458, sits in the U.S. District Court for the District of Massachusetts — check PACER or Justia periodically for updates.
  6. Consider the free Kroll monitoring. DentaQuest is offering 24 months of credit monitoring and identity restoration through Kroll. Your letter lists your enrollment deadline and activation code.

DentaQuest Data Breach Lawsuit — Full Timeline

MilestoneDate
Unauthorized network access beginsMay 17, 2026
DentaQuest discovers the breachMay 20, 2026
ShinyHunters claims responsibility, demands ransomAround May 22, 2026
ShinyHunters publishes stolen data after failed negotiationsAround May 30, 2026
First class action filed (May v. DentaQuest Group)June 1, 2026
Additional suits filed (King, Hufnus, and others)June–July 2026
DentaQuest files breach notice with California AGJuly 16, 2026
Notification letters begin mailingJuly 17, 2026
Next scheduled hearingUNVERIFIED — not publicly scheduled as of this writing
Expected resolutionUNVERIFIED — consolidation and litigation timeline not yet set

DentaQuest Data Breach — Frequently Asked Questions, No. 1:26-cv-12458

Is there a class action lawsuit against DentaQuest for the data breach right now?

 Yes. At least a dozen federal class actions are pending in the U.S. District Court for the District of Massachusetts, with May v. DentaQuest Group, No. 1:26-cv-12458, filed first on June 1, 2026. Courts often consolidate related cases like these before a single judge.

Do I need to do anything right now to be part of the DentaQuest lawsuit? 

No. If your data was involved, you’re likely already part of the proposed class described in the complaints. You don’t need to sign up or hire a lawyer for the case to include you — that changes only if you want to pursue an individual claim.

When will the DentaQuest data breach case settle? 

Nobody knows yet. The suits were filed in June and July 2026, no class has been certified, and cases of this size often take a year or more to reach a settlement.

Can I file my own lawsuit against DentaQuest instead of joining the class? 

Yes, in some cases. If your damages are significant, an attorney may recommend an individual claim rather than waiting on the class. That depends on your specific losses.

How will I find out if the DentaQuest lawsuit settles? 

Courts require formal notice to class members before any settlement is finalized, typically by mail or email using the same information DentaQuest already has on file for you.

What does “lead plaintiff” mean for the DentaQuest case, and why does the deadline matter?

 A lead plaintiff represents the class in court. No public deadline for that role has been confirmed for this case as of this writing — check with an attorney if you want to be considered.

What specific claims does DentaQuest allegedly face?

 The complaints allege negligence, breach of contract, unjust enrichment, and invasion of privacy for failing to secure patient data — not a HIPAA violation directly, since HIPAA doesn’t allow private lawsuits.

How much could DentaQuest patients get if this case settles? 

There’s no way to predict that yet. No settlement fund exists, and any amount would depend on the size of the certified class and the strength of the evidence against DentaQuest.

Sources Used in This DentaQuest Data Breach Article

  • California Attorney General — DentaQuest LLC Breach Notification Filing, July 16, 2026: https://oag.ca.gov/ecrime/databreach/reports/sb24-626583
  • HIPAA Journal — “DentaQuest Starts Notifying 15 Million+ Individuals About May 2026 Cyber Incident,” July 23, 2026: https://www.hipaajournal.com/dentaquest-data-breach/
  • Cybernews — “DentaQuest breach notices sent to 15 million after health data theft,” July 25, 2026: https://cybernews.com/news/dentaquest-breach-notices-sent-to-15-million-after-health-data-theft/
  • SecurityWeek — “DentaQuest Data Breach Potentially Impacts Over 23 Million People,” July 27, 2026: https://www.securityweek.com/dentaquest-data-breach-potentially-impacts-over-23-million-people/
  • Justia Dockets — DentaQuest data breach litigation, District of Massachusetts: https://dockets.justia.com/docket/massachusetts/madce/1:2026cv13868/305288

Researched and written by Israr Ahmad, legal content researcher and founder of AllAboutLawyer.com. All facts verified against the California Attorney General’s breach filing and named primary sources on September 8, 2026. Last Updated: September 8, 2026.

This article is for informational purposes only and does not constitute legal advice. Laws vary by state and individual circumstances differ. For advice about your specific situation, consult a qualified attorney.

About the Author

Israr Ahmad is a legal content researcher with 4+ years of experience covering class action settlements and consumer rights cases. He has researched and published coverage of 2,500+ settlements using verified court records, settlement administrator filings, and government sources. Learn more about Israr.

Leave a Reply

Your email address will not be published. Required fields are marked *