 |
Patient Protect |
|
HIPAA Pulse |
|
HIPAA PULSE
August 5, 2026 · Bi-Weekly Briefing
|
|
The Number We Reported in June Just Grew Sixfold
|
In June we covered a dental benefits administrator breach initially estimated at 2.6 million people. State filings now show millions more affected, and DentaQuest has reportedly acknowledged at least 15 million.
This is what happens when an extortion claim gets replaced by regulatory filings: the number rarely goes down. DentaQuest's is the story this issue, including a notification-timing question worth watching as the affected count keeps expanding.
Also this window: an EHR vendor used by 45,000 providers disclosed a March breach in late July, a billing company got hit by the same extortion group as a practice we covered two weeks ago, and OCR settled a case over an attack from 2021 — five years later.
|
|
15M+
reportedly acknowledged affected by the DentaQuest breach, with state attorney general filings already showing at least 4.5 million notices across Texas, Massachusetts, and South Carolina — up from the 2.6 million reported when the extortion group first published the data in June. Independent analysis of the leaked dataset puts the plausible total above 23 million.
|
|
Since the last issue, July 22
|
4
named stories verified this window, one an OCR settlement
|
2
business associates — CareCloud and MCBS — each had patient/state breach notice follow the intrusion by 4+ months
|
21st
ransomware enforcement action of OCR's ongoing initiative — OSF is the latest
|
Two historical mega-breaches (Excellus, 2015; Premera, 2014) surfaced again this week with fresh dates through the same Wisconsin filing channel flagged in prior issues. Excluded here for the same reason as always.
|
|
Breach of Note: DentaQuest's number keeps growing
4.5M+ in state filings, 15M+ reportedly acknowledged · Extortion / Hacking · Nationwide
DentaQuest, a Sun Life subsidiary and one of the largest dental benefits administrators in the country, detected unauthorized access to its network on May 20, 2026. The intrusion itself ran May 17–20. ShinyHunters claimed responsibility, demanded ransom, and, after negotiations failed, published the stolen files on its leak site. DentaQuest confirmed the breach June 2. At that point, working estimates put the scope at roughly 2.6 million people — the number we reported at the time.
Notification letters began going out July 16 and 17, filed on a rolling basis with state attorneys general. Public state filings already show at least 4.5 million notices across Texas (3,973,000), Massachusetts (522,000), and South Carolina. Separately, DentaQuest has reportedly acknowledged at least 15 million affected. Independent researchers who deduplicated the leaked dataset by name and date of birth estimate the true number could exceed 23 million. That estimate is not official.
There's a compliance wrinkle worth naming directly. HIPAA's 60-day notification clock starts at discovery, not at the point an organization finishes counting. DentaQuest discovered the intrusion May 20; sixty days from that date is July 19. Notifications began rolling out July 16 and 17. That does not automatically mean late notice — HHS guidance allows an entity to notify with an estimate and submit updates as an investigation continues — but it creates the question OCR would care about: when could DentaQuest, exercising reasonable diligence, have identified each affected person, and did notice follow without unreasonable delay?
Worth asking: Do any of your patients carry DentaQuest dental or vision coverage through Medicaid or Medicare Advantage? Does your own breach-response plan have a documented process for what happens when the affected count grows after your first notification round? If a number moved this much between June and August, what tells you it's finished moving? Run the free assessment.
|
|
An EHR vendor's March incident became patient/state breach notice in late July
CareCloud, a New Jersey health-tech company that provides EHR, practice management, and billing software to more than 45,000 U.S. healthcare providers, had an AWS-hosted environment accessed without authorization between March 10 and 16. The company disclosed the intrusion to investors around that time, and TechCrunch reported on it in late March. What came later, on June 24, was confirmation that personal, financial, and medical information had actually been compromised — and patient/state breach notices didn't follow until late July, four months after the intrusion. At least 345,000 people are affected, including 270,197 in Texas, with the total still climbing as more states file. No group has publicly claimed the attack. If your practice uses CareCloud, or any vendor that stores records in a shared cloud environment on your behalf, this is the exposure your BAA is supposed to cover.
The same extortion group, a second target
MCBS, a medical billing company in Augusta, Georgia, disclosed that attackers accessed its network between September 22 and 26, 2025. MCBS learned of it September 25 — almost immediately — but didn't conclude its investigation until May 28, 2026, roughly eight months later, and didn't report to California until June 26. HHS OCR's portal lists 1,261,464 affected, higher than the rounded 1.2 million figure that circulated when the story first broke. PEAR, the same extortion group behind Western Orthopaedics' breach in our July 22 issue, claims responsibility and says it took roughly 3 terabytes; MCBS has not confirmed the attribution. Two PEAR claims in three issues is enough to call it a pattern worth watching, not yet enough to call it a trend.
A 2021 attack, a 2026 settlement
HHS OCR settled its investigation into a 2021 ransomware attack on OSF Healthcare System, a Peoria, Illinois system with providers in Illinois and Michigan. The attacker, a group called Xing Team, encrypted files and exfiltrated the health information of 53,907 patients; OSF didn't file its breach report until October 2021, months after discovering the intrusion in April. The settlement, announced this week, carries a $552,250 penalty and a two-year corrective action plan requiring a real risk analysis and a risk management plan to act on it. It's OCR's 21st ransomware-related enforcement action. The lesson isn't new, but the five-year gap is a useful reminder: an OCR investigation opening today can still be running, and still cost you, years from now.
|
|
30-minute system check
Five items, each tied to something above.
| 1. |
Check your patient roster against DentaQuest coverage. Medicaid and Medicare Advantage dental and vision plans are the most exposed. If you have patients on those plans, you may field questions before DentaQuest's own notifications finish going out. |
|
| 2. |
Write a scope-growth clause into your own breach-response plan. DentaQuest's number moved from 2.6 million to 15 million-plus over two months. If your practice ever has a breach, decide now how you'll handle a count that keeps changing after the first notification. |
|
| 3. |
Ask your EHR and billing vendors how fast they'd tell you. CareCloud and MCBS both took four or more months from intrusion to patient/state breach notice. Your BAA should specify a deadline shorter than that, in writing. |
|
| 4. |
Pull your risk analysis and check the date. OSF's settlement, five years after the attack, still centers on the same finding OCR cites most often: no accurate, thorough risk analysis. This is the control OCR keeps returning to in ransomware and Security Rule enforcement. |
|
| 5. |
Know your own 60-day clock, not just the calendar date. It starts at discovery. If a breach at your practice grows in scope over time, each newly identified person still needs to be handled under the same "without unreasonable delay" standard, measured against when reasonable diligence should have identified them — not from when you started telling anyone. |
|
|
The free HIPAA Risk Assessment inventories your vendors, BAAs, and data flows in about 30 minutes. No account needed.
|
|
| |
|
A word from Patient Protect, who pays for this newsletter to exist
Your vendors are your attack surface. Track them like it.
Vendor inventory with offboarding and data-disposition tracking. BAA lifecycle alerts, including notification-deadline terms. Continuous risk analysis. $39/month, no contracts, 14-day free trial.
|
|
|
Worth reading elsewhere
|
|
Six issues in, the through-line holds: impact concentrates at whichever vendor or administrator is holding the most data, and the gap between when a vendor knows and when your patients find out is where the real risk sits. DentaQuest is that pattern at its largest scale yet.
Next Pulse drops August 19.
Editorial coverage at hipaapulse.com. Operational response at patient-protect.com/hipaa-pulse. This briefing comes from Patient Protect.
|
 |
Patient Protect |
Chicago, IL · patient-protect.com · HIPAA Pulse
|
Instagram
LinkedIn
X
|
|
DentaQuest's 4.5M+ figure reflects state attorney general filings in Texas, Massachusetts, and South Carolina; the 15M+ figure reflects DentaQuest's reported acknowledgment, distinct from the state-filing total; the 23M+ figure is an independent, unofficial estimate from analysis of leaked data. CareCloud and MCBS figures reflect state filings and the HHS OCR breach portal respectively. OSF Healthcare figures reflect the official HHS.gov settlement announcement, verified directly. Excellus and Premera figures reflect their original historical disclosures, re-verified independently; neither is a fresh 2026 incident despite current filing dates.
You're receiving HIPAA Pulse because you subscribed at patient-protect.com. Unsubscribe · Privacy Policy
© 2026 Patient Protect LLC. All rights reserved.
|
|
|