HIPAA Pulse by Patient Protect logo

HIPAA Pulse by Patient Protect

Archives
Log in
August 5, 2026

HIPAA Pulse | August 5th

HIPAA Pulse — August 5, 2026
The dental breach we covered at 2.6 million in June is now reportedly at 15 million or more, and independent analysis says it could be over 23. Here's what changed, and a notification deadline worth watching. ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌
Patient Protect
HIPAA Pulse

HIPAA PULSE

August 5, 2026  ·  Bi-Weekly Briefing

The Number We Reported in June Just Grew Sixfold

In June we covered a dental benefits administrator breach initially estimated at 2.6 million people. State filings now show millions more affected, and DentaQuest has reportedly acknowledged at least 15 million.

This is what happens when an extortion claim gets replaced by regulatory filings: the number rarely goes down. DentaQuest's is the story this issue, including a notification-timing question worth watching as the affected count keeps expanding.

Also this window: an EHR vendor used by 45,000 providers disclosed a March breach in late July, a billing company got hit by the same extortion group as a practice we covered two weeks ago, and OCR settled a case over an attack from 2021 — five years later.

15M+

reportedly acknowledged affected by the DentaQuest breach, with state attorney general filings already showing at least 4.5 million notices across Texas, Massachusetts, and South Carolina — up from the 2.6 million reported when the extortion group first published the data in June. Independent analysis of the leaked dataset puts the plausible total above 23 million.

Since the last issue, July 22

4

named stories verified this window, one an OCR settlement

2

business associates — CareCloud and MCBS — each had patient/state breach notice follow the intrusion by 4+ months

21st

ransomware enforcement action of OCR's ongoing initiative — OSF is the latest

Two historical mega-breaches (Excellus, 2015; Premera, 2014) surfaced again this week with fresh dates through the same Wisconsin filing channel flagged in prior issues. Excluded here for the same reason as always.

Open the live dashboard Free · No account · Updated nightly

Breach of Note: DentaQuest's number keeps growing

4.5M+ in state filings, 15M+ reportedly acknowledged  ·  Extortion / Hacking  ·  Nationwide

DentaQuest, a Sun Life subsidiary and one of the largest dental benefits administrators in the country, detected unauthorized access to its network on May 20, 2026. The intrusion itself ran May 17–20. ShinyHunters claimed responsibility, demanded ransom, and, after negotiations failed, published the stolen files on its leak site. DentaQuest confirmed the breach June 2. At that point, working estimates put the scope at roughly 2.6 million people — the number we reported at the time.

Notification letters began going out July 16 and 17, filed on a rolling basis with state attorneys general. Public state filings already show at least 4.5 million notices across Texas (3,973,000), Massachusetts (522,000), and South Carolina. Separately, DentaQuest has reportedly acknowledged at least 15 million affected. Independent researchers who deduplicated the leaked dataset by name and date of birth estimate the true number could exceed 23 million. That estimate is not official.

There's a compliance wrinkle worth naming directly. HIPAA's 60-day notification clock starts at discovery, not at the point an organization finishes counting. DentaQuest discovered the intrusion May 20; sixty days from that date is July 19. Notifications began rolling out July 16 and 17. That does not automatically mean late notice — HHS guidance allows an entity to notify with an estimate and submit updates as an investigation continues — but it creates the question OCR would care about: when could DentaQuest, exercising reasonable diligence, have identified each affected person, and did notice follow without unreasonable delay?

Worth asking: Do any of your patients carry DentaQuest dental or vision coverage through Medicaid or Medicare Advantage? Does your own breach-response plan have a documented process for what happens when the affected count grows after your first notification round? If a number moved this much between June and August, what tells you it's finished moving? Run the free assessment.

An EHR vendor's March incident became patient/state breach notice in late July

CareCloud, a New Jersey health-tech company that provides EHR, practice management, and billing software to more than 45,000 U.S. healthcare providers, had an AWS-hosted environment accessed without authorization between March 10 and 16. The company disclosed the intrusion to investors around that time, and TechCrunch reported on it in late March. What came later, on June 24, was confirmation that personal, financial, and medical information had actually been compromised — and patient/state breach notices didn't follow until late July, four months after the intrusion. At least 345,000 people are affected, including 270,197 in Texas, with the total still climbing as more states file. No group has publicly claimed the attack. If your practice uses CareCloud, or any vendor that stores records in a shared cloud environment on your behalf, this is the exposure your BAA is supposed to cover.

The same extortion group, a second target

MCBS, a medical billing company in Augusta, Georgia, disclosed that attackers accessed its network between September 22 and 26, 2025. MCBS learned of it September 25 — almost immediately — but didn't conclude its investigation until May 28, 2026, roughly eight months later, and didn't report to California until June 26. HHS OCR's portal lists 1,261,464 affected, higher than the rounded 1.2 million figure that circulated when the story first broke. PEAR, the same extortion group behind Western Orthopaedics' breach in our July 22 issue, claims responsibility and says it took roughly 3 terabytes; MCBS has not confirmed the attribution. Two PEAR claims in three issues is enough to call it a pattern worth watching, not yet enough to call it a trend.

A 2021 attack, a 2026 settlement

HHS OCR settled its investigation into a 2021 ransomware attack on OSF Healthcare System, a Peoria, Illinois system with providers in Illinois and Michigan. The attacker, a group called Xing Team, encrypted files and exfiltrated the health information of 53,907 patients; OSF didn't file its breach report until October 2021, months after discovering the intrusion in April. The settlement, announced this week, carries a $552,250 penalty and a two-year corrective action plan requiring a real risk analysis and a risk management plan to act on it. It's OCR's 21st ransomware-related enforcement action. The lesson isn't new, but the five-year gap is a useful reminder: an OCR investigation opening today can still be running, and still cost you, years from now.

30-minute system check

Five items, each tied to something above.

1.

Check your patient roster against DentaQuest coverage. Medicaid and Medicare Advantage dental and vision plans are the most exposed. If you have patients on those plans, you may field questions before DentaQuest's own notifications finish going out.

2.

Write a scope-growth clause into your own breach-response plan. DentaQuest's number moved from 2.6 million to 15 million-plus over two months. If your practice ever has a breach, decide now how you'll handle a count that keeps changing after the first notification.

3.

Ask your EHR and billing vendors how fast they'd tell you. CareCloud and MCBS both took four or more months from intrusion to patient/state breach notice. Your BAA should specify a deadline shorter than that, in writing.

4.

Pull your risk analysis and check the date. OSF's settlement, five years after the attack, still centers on the same finding OCR cites most often: no accurate, thorough risk analysis. This is the control OCR keeps returning to in ransomware and Security Rule enforcement.

5.

Know your own 60-day clock, not just the calendar date. It starts at discovery. If a breach at your practice grows in scope over time, each newly identified person still needs to be handled under the same "without unreasonable delay" standard, measured against when reasonable diligence should have identified them — not from when you started telling anyone.

The free HIPAA Risk Assessment inventories your vendors, BAAs, and data flows in about 30 minutes. No account needed.

Run the free assessment Free · No account · 30 minutes
 

A word from Patient Protect, who pays for this newsletter to exist

Your vendors are your attack surface. Track them like it.

Vendor inventory with offboarding and data-disposition tracking. BAA lifecycle alerts, including notification-deadline terms. Continuous risk analysis. $39/month, no contracts, 14-day free trial.

Start free trial See pricing

Worth reading elsewhere

  Amgen Says Cloud Data Breach Exposed Patient Health, Proprietary Info

Attackers reportedly stole patient health data and proprietary corporate information from cloud systems run by third-party providers. No confirmed affected count yet. Source: Bleeping Computer.

  Health-ISAC Warns of Rising ShinyHunters Attacks on Healthcare

The same group behind DentaQuest is using social engineering to compromise single sign-on accounts and steal data from cloud services more broadly. Source: Bleeping Computer.

Six issues in, the through-line holds: impact concentrates at whichever vendor or administrator is holding the most data, and the gap between when a vendor knows and when your patients find out is where the real risk sits. DentaQuest is that pattern at its largest scale yet.

Next Pulse drops August 19.

Editorial coverage at hipaapulse.com. Operational response at patient-protect.com/hipaa-pulse. This briefing comes from Patient Protect.

Patient Protect

Chicago, IL  ·  patient-protect.com  ·  HIPAA Pulse

Instagram LinkedIn X

DentaQuest's 4.5M+ figure reflects state attorney general filings in Texas, Massachusetts, and South Carolina; the 15M+ figure reflects DentaQuest's reported acknowledgment, distinct from the state-filing total; the 23M+ figure is an independent, unofficial estimate from analysis of leaked data. CareCloud and MCBS figures reflect state filings and the HHS OCR breach portal respectively. OSF Healthcare figures reflect the official HHS.gov settlement announcement, verified directly. Excellus and Premera figures reflect their original historical disclosures, re-verified independently; neither is a fresh 2026 incident despite current filing dates.

You're receiving HIPAA Pulse because you subscribed at patient-protect.com. Unsubscribe  ·  Privacy Policy

© 2026 Patient Protect LLC. All rights reserved.

Don't miss what's next. Subscribe to HIPAA Pulse by Patient Protect:
← Newer HIPAA Pulse | August 19th Older → HIPAA Pulse | July 22
Instagram
Twitter
LinkedIn
YouTube