In June we published an analysis of the DentaQuest breach based on the figures available at the time: the ShinyHunters extortion group had leaked roughly 234 GB of data tied to the Sun Life–owned dental benefits administrator, and the working estimate was approximately 2.6 million affected individuals. That analysis is here.

The number has moved. Substantially.

Notification letters began rolling out on 17 July 2026. State attorney general filings and the notification programme confirm at least 15 million individuals. Independent analysis of the leaked data set — deduplicating on unique first name, last name, and date of birth combinations — puts the plausible total at more than 23.4 million.

The confirmed timeline is now:

  • 17–20 May 2026: unauthorised access to DentaQuest’s network.
  • 20 May 2026: DentaQuest discovers the intrusion and secures systems.
  • 5 June 2026: ShinyHunters claims responsibility and publishes the data after ransom negotiations fail.
  • 17 July 2026: notification letters begin, on a rolling basis, including filings with the California Attorney General.

The exposed fields are extensive: names, addresses, Social Security numbers, member identification numbers, Medicaid and Medicare numbers, and dental and vision health information including provider names, diagnoses, treatment details, and billing information. Affected individuals are being offered 24 months of credit monitoring and identity theft protection.

If the higher figure holds, this ranks among the largest health-data breaches ever reported in the United States — in the same tier as the Conduent breach that reached 62.2 million earlier this year.

The compliance problem nobody drills for: the number moves

Breach response training almost universally assumes a fixed population. You discover the incident, you scope it, you notify, you file. In practice, the population is an estimate that gets revised — sometimes by an order of magnitude, as here — and the revisions arrive after obligations have already been discharged on the smaller figure.

HIPAA’s Breach Notification Rule (45 CFR §§ 164.400–414) does not contain a “revised scope” procedure. What it contains are obligations that attach to each individual whose PHI was breached, which means the answer is derived rather than stated. Working through it:

The 60-day clock runs from discovery, not from scoping

45 CFR § 164.404(b) requires notification to each affected individual without unreasonable delay and in no case later than 60 calendar days after discovery of the breach.

Discovery is defined in § 164.404(a)(2): a breach is treated as discovered on the first day it is known, or by exercising reasonable diligence would have been known, to the covered entity or business associate.

DentaQuest discovered the intrusion on 20 May 2026. Sixty calendar days from 20 May is 19 July 2026. Notifications beginning 17 July fall inside that window — narrowly, and only for the individuals notified by 19 July.

This is the crux of the rolling-notification problem. The 60-day maximum is not a deadline for starting notification. It is a deadline for notifying each individual. An individual identified as affected on 1 August, in a breach discovered on 20 May, is notified outside the statutory window regardless of when the programme started, unless the covered entity can establish that reasonable diligence would not have identified them earlier.

OCR has been consistent on this point. The regulatory preamble to the Breach Notification Rule makes clear that the 60-day period is an outer limit, not a safe harbour, and that “without unreasonable delay” is an independent obligation. An entity that takes 55 days to complete an analysis it could have completed in 20 has violated the delay standard even while meeting the 60-day cap.

The OCR report and the substitute-notice thresholds change with the number

§ 164.408 governs notification to the Secretary of HHS:

  • For breaches affecting 500 or more individuals, notice to the Secretary must be provided contemporaneously with the individual notices and within 60 days of discovery.
  • The OCR breach portal submission requires the number of individuals affected — and OCR’s process permits and expects updates to a submitted report as the figure is refined. Filing an initial report with an estimate and updating it is the correct procedure. Filing once with a low estimate and never revising it is not.

§ 164.406 requires media notice to prominent outlets serving a state or jurisdiction where more than 500 residents of that state are affected, within the same 60-day window. When the national figure moves from 2.6 million to 23 million, the set of states crossing the 500-resident threshold expands — and media notice obligations attach in jurisdictions that were previously below the line.

§ 164.404(d)(2) requires substitute notice where contact information is insufficient or out of date for 10 or more individuals: a conspicuous posting on the entity’s home page for 90 days, or major print or broadcast media notice, plus a toll-free number active for at least 90 days. At 23 million records assembled over years of benefits administration, the population with stale addresses is very large, and the substitute-notice obligation scales accordingly.

Supplemental notice to already-notified individuals

Here is the subtler obligation. § 164.404(c) specifies the required content of the individual notice, including a description of the types of unsecured PHI involved.

If the initial notification to a tranche of individuals described a narrower set of data elements than subsequent forensic work established — for example, if the early letters did not mention Medicaid or Medicare numbers and later analysis confirmed their presence — then those individuals received a notice that no longer satisfies the content requirement. A supplemental notice is the appropriate remedy.

This matters practically because Medicaid and Medicare identifiers carry a distinct harm profile: they enable medical identity theft and fraudulent billing in ways a credit-monitoring product does not address. An individual told they lost “name and address” makes different decisions than one told they lost their Medicare number.

The business associate question, again

DentaQuest administers dental and vision benefits on behalf of health plans, including a substantial Medicaid managed-care book. In HIPAA terms it operates principally as a business associate to covered-entity health plans, and in some arrangements as part of an organised health care arrangement.

Under § 164.410, a business associate must notify the covered entity of a breach without unreasonable delay and no later than 60 days after discovery. The covered entity then owes the individual notice under § 164.404 — and the covered entity’s own 60-day clock is generally treated as running from the business associate’s discovery where the business associate is acting as the covered entity’s agent under federal common law of agency.

That agency determination is the fault line. A plan that assumed its clock started when DentaQuest told it, only to find OCR treating the clock as having started on 20 May, is retroactively late.

The scope expansion multiplies this. Every health plan with members in the affected set needs a current, specific answer to: how many of our members are in the confirmed population, and has that number changed since we were last told? Plans that received a figure in June and have not re-asked have a stale number driving their own notification and reporting.

Business-associate agreements should — and frequently do not — require:

  • Notification of the incident within a defined period in hours, not the statutory 60 days.
  • A standing duty to update the affected-population count and data-element list, at defined intervals, until the count is final.
  • Delivery of the covered-entity-specific member list in a usable format, with a committed date.
  • Preservation of the forensic record and reasonable cooperation in the covered entity’s own analysis.
  • Explicit allocation of notification cost and, separately, of regulatory liability.

We examined the same structural dynamic from the banking side in the Pinnacle Financial and Mercadien breach, where nine months elapsed between intrusion and client identification.

State law does not wait for HIPAA

The California AG filing is a reminder that HIPAA is a floor. State breach-notification statutes apply in parallel and several are stricter:

  • California (Civ. Code § 1798.82) requires notification in the most expedient time possible and without unreasonable delay, with AG notification where more than 500 California residents are affected. California’s medical-information statute, the CMIA (Civ. Code § 56 et seq.), carries its own penalties, including statutory damages available in private actions — a materially different exposure from HIPAA, which has no private right of action.
  • Texas (Bus. & Com. Code § 521.053) requires notification within 60 days, and AG notification within 30 days where 250 or more Texas residents are affected.
  • Florida (Fla. Stat. § 501.171) requires individual notice within 30 days, with limited extension.
  • Massachusetts, New York, and others impose their own regulator-notification duties and content requirements.

A rolling notification programme that satisfies HIPAA’s 60 days can miss Florida’s 30 days for the same individuals. The scope expansion widens the set of states in play.

What this means for the affected population

Roughly 23 million people, holding a data combination — name, date of birth, Social Security number, Medicaid or Medicare number, diagnosis and treatment detail — that supports both financial and medical identity fraud, published in full on a leak site after a failed negotiation.

Credit monitoring addresses the financial half. It does not detect fraudulent medical claims filed against a Medicare or Medicaid number. The practical protective steps for individuals in this set:

  • Request and review the Medicare Summary Notice or Medicaid claims history for services not received.
  • Place a security freeze with all three credit bureaus, which is free and materially more effective than monitoring.
  • Obtain an IRS Identity Protection PIN, given SSN exposure ahead of the next filing season.
  • Treat unsolicited contact referencing dental benefits or the breach itself as likely fraudulent — published breach data reliably produces targeted follow-on social engineering, as we saw in the Abbott and Exact Sciences vishing campaign.

Actions for covered entities and business associates

  1. Re-ask your vendors for current numbers. Any affected-population figure you received more than 30 days ago in an active incident is probably wrong. Make the re-ask a scheduled step in the incident process, not an ad-hoc one.
  2. File the OCR report early and update it. An initial report with a labelled estimate, revised as scope firms up, is the compliant path. Waiting for certainty is how entities blow the 60-day contemporaneous-reporting requirement.
  3. Audit your notification content against the final data-element list. Where early letters understated the categories, issue supplemental notices. Document the decision either way.
  4. Recalculate state thresholds after every scope revision. Media notice and AG notification obligations turn on per-state counts that move with the total.
  5. Fix the BAA clock. Sixty days from the business associate is the statutory maximum and an indefensible contractual term. Negotiate hours, plus a standing update obligation.
  6. Document your reasonable-diligence position. If individuals will be notified beyond day 60, the defence is a contemporaneous record showing why they could not have been identified sooner. That record has to be written during the incident, not reconstructed for OCR afterwards.

Conclusion

The interesting fact about DentaQuest is not that the number grew — breach counts nearly always grow. It is the ratio. A ninefold revision, from 2.6 million to more than 23 million, arriving after the notification programme had already begun, means that every downstream obligation calculated on the earlier figure was calculated wrong: which states cross the media-notice threshold, how many people need substitute notice, how large the toll-free capacity must be, and which health plans have members in scope.

HIPAA’s Breach Notification Rule assumes you know who was affected. The rule that actually governs a large modern breach is the one nobody wrote down: your obligations are recalculated every time forensics revises the population, the 60-day clock does not restart when they do, and the only defensible position is a contemporaneous record showing you moved as fast as the evidence allowed.

This article is provided for informational purposes only and does not constitute legal advice.