DentaQuest, LLC Data Breach Notice (Washington Attorney General)
If you were named in this filing, here’s what the filing says was exposed, and what to do about it.
DentaQuest, LLC notified Washington residents of a data breach in a filing reported to the Washington State Attorney General on July 16, 2026, and the notice lists name, social security number, full date of birth, health insurance policy or id number, medical information and protected health information owned or licensed by a hipaa covered entity among the information exposed. The filing puts the incident itself on May 17, 2026.
The breach notice from DentaQuest, LLC means that your name, Social Security number, full date of birth, health insurance policy number, and detailed medical records were exposed in an incident that occurred on May 17, 2026. The company filed the notification with the Washington Attorney General on July 16, 2026 — exactly 60 days later. This two-month gap between the incident and the filing is the most immediate fact in the record.
That interval matters because it is long enough for the exposed information to have been used, copied, or sold before anyone outside the company knew it was at risk. The filing does not disclose how the breach happened, whether the data was taken by an outsider or someone with legitimate access, or whether it has already appeared elsewhere. What it does establish clearly is that the records of 148,300 people were involved.
The combination that creates lasting risk
A Social Security number paired with a full date of birth is one of the most valuable combinations for identity thieves. With those two pieces, someone can apply for credit, file fraudulent tax returns, open accounts, or impersonate you in medical settings. Unlike a credit card, neither of these identifiers can be replaced. They remain attached to you for life.
The addition of your health insurance policy number and medical information raises a separate set of concerns. Protected Health Information owned or licensed by a HIPAA covered entity can be used to file false claims, obtain prescription drugs in your name, or create fake identities for ongoing medical fraud. Medical identity theft is often discovered years later, when an Explanation of Benefits statement arrives for care you never received or when your insurance limits are suddenly exhausted.
No passwords were exposed in this incident. That is genuine good news. You do not need to change any DentaQuest password, and there is no evidence that your account login itself was compromised. The risk here is not account takeover. It is the permanent biographical and medical data that cannot be reset.
What the exposed medical records actually enable
Health insurance ID numbers combined with names, dates of birth, and clinical information give fraudsters enough to submit phony medical claims. Insurers sometimes pay these claims before catching the pattern, which can damage your coverage history and leave you responsible for unexpected deductibles or denials later.
More quietly, this data can be used to build synthetic identities or to support larger fraud schemes that rely on real patient histories. Once sold, the package of 148,300 records becomes a long-term resource for criminals. The filing does not state whether the data was exfiltrated, but the categories listed are exactly those that retain value on the black market for years.
The record lists these categories for the incident as a whole. Your individual notification letter will specify which pieces of information applied to you. The letter is the only reliable way to confirm your personal exposure.
How to determine whether this notice concerns you
DentaQuest is required to notify affected individuals directly, usually by mail. If you have not received a letter, it is likely that your records were not part of the 148,300 affected in this filing. However, if you have moved since May 17, 2026, or if your address on file with the company is outdated, the letter may never have reached you. In that case, contact DentaQuest directly to ask whether your information was included.
The permanent nature of the exposure
Because your Social Security number and date of birth cannot be changed, the core risk from this breach will not expire. Credit monitoring for a year or two is useful, but it does not solve the long-term problem. The same is true for your medical history. Once it is loose, it stays loose.
This is why the most practical response is to reduce what thieves can do with the data rather than hoping the data itself disappears. The filing gives you no information about the root cause or the attacker’s identity, so any speculation about how preventable it was remains unsupported. What matters now is translating the exposed categories into concrete protections you can still control.
Placing controls around the data that cannot be replaced
The presence of Social Security numbers in the exposed set means you should treat this as a trigger to lock down new credit. A freeze prevents anyone from opening accounts in your name without your explicit permission. It is free, reversible, and far more effective than monitoring alone.
Your medical information requires its own vigilance. Regularly review Explanation of Benefits statements from your insurer. Look for services you did not receive, unfamiliar providers, or claims that do not match your own care. Discrepancies can be the first sign that someone is using your insurance identity.
Because health insurance policy numbers were also exposed, consider asking your insurer whether they can issue a new member ID. Some carriers will do this when a breach is confirmed. A new number breaks the direct link between the stolen data and your current coverage.
Place fraud alerts with the three major credit bureaus. While a freeze is stronger, an alert forces creditors to verify your identity before issuing new credit. It also gives you an additional layer if you need to unfreeze your reports temporarily.
Finally, keep your own records. Save the breach notification letter, note the dates, and document every call you make to DentaQuest, your insurer, or the credit bureaus. If identity theft does occur months or years from now, this paper trail will help you dispute fraudulent activity more quickly.
The 60-day interval between the May 17 incident and the July 16 filing is the clearest fact the record provides. It does not tell us what happened inside DentaQuest during those weeks, but it does tell you that the information has had time to travel. The categories exposed — especially the SSN, date of birth, and medical details — create risks that last far longer than the news cycle around this filing. Your job is not to prevent what has already occurred. It is to limit what can still be built on top of it.
What to do now
Steps that match what this notice says was exposed
Every step below is free and you do it yourself, and none of it depends on DentaQuest, LLC.
- Freeze your credit — this is the one that matters. A freeze is free, it takes minutes, and it has to be done separately at all three bureaus: Equifax, Experian and TransUnion. It stops a new account being opened in your name, which is what a Social Security number in the wrong hands is for. You can lift it temporarily whenever you need credit.
- Read your next explanation of benefits. Medical identity theft shows up as treatment you did not receive, billed to your policy and written into your medical record. Your insurer can flag the policy, and you can request an accounting of disclosures from the provider named here.
- Expect the phone calls to get better. A date of birth is not secret, but it is what call centres use to confirm you are you. Treat any unexpected call that already knows your details as unverified until you call the company back yourself.
One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.
Report details & sourcing
Related breaches
Trezor Shipping Data Breach — 13,689 Hardware Wallet Buyers, Home Addresses Included
ShipMonk, a logistics provider used by Trezor, was breached through a vulnerability in the third-par…
Match Group (Tinder, Hinge, OkCupid) Data Breach — January 2026
ShinyHunters claimed responsibility for stealing over 10 million Match Group user records in early 2…
Crunchbase Massive Personal Records Leak — January 2026
ShinyHunters exfiltrated approximately 2 million records from the business-intelligence platform Cru…