The health data of more than 15 million individuals was compromised after a hacker breached Massachusetts-based dental and vision benefits administrator DentaQuest this spring, according to a breach notice filed with federal regulators. It’s the largest health data breach reported to the government this year.
DentaQuest, the second-largest dental benefits administrator in the U.S., has approximately 32 million beneficiaries across its dental and vision plans. The company discovered that hackers had accessed its computer systems from May 17 to May 20, according to the notice.
DentaQuest engaged financial and risk advisory firm Kroll to conduct an analysis of the impacted data. According to the review, beneficiaries’ personal, sensitive and medical information could have been exposed, including Social Security numbers, Medicaid and Medicare IDs, diagnosis, treatment and billing information.
Multiple reports have said the cyber threat group ShinyHunters was responsible for the hack.
The Health Information Sharing and Analysis Center — a global organization that facilitates information sharing among healthcare organizations — released a threat bulletin about ShinyHunters in July, warning that the group uses social engineering, such as phone calls, to trick people into sharing information and compromising accounts.
DentaQuest did not respond to a request for comment. However, the company said in July that it had begun notifying affected individuals of the breach and provided additional security training to its employees, as well as implementing more stringent security controls.
Hacking has been the leading cause of healthcare data breaches reported to federal regulators since 2017. Recently reported hacks include a breach at revenue cycle vendor Unlimited Technology Systems and a cyberattack against a laboratory testing facility in New Jersey.