DentaQuest Data Breach
DentaQuest Wisconsin: 868 Patients Affected by Paper Records Breach
What happened in the DentaQuest data breach?
The DentaQuest data breach was reported on January 6, 2025 and affected 868 individuals. The breach type was Unauthorized Access/Disclosure involving Paper/Films. This breach occurred in Wisconsin. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
DentaQuest Breach Details
DentaQuest Unauthorized Access Breach Report
Overview
DentaQuest, a dental benefits and services organization, reported an unauthorized access incident affecting 868 individuals in Wisconsin. The breach was submitted to the Department of Health and Human Services on January 6, 2025, and involved the unauthorized access and potential disclosure of protected health information (PHI) stored in paper records and dental films. This incident represents a significant breach of patient privacy and triggers mandatory HIPAA notification requirements under the Breach Notification Rule.
Discovery and Response Timeline
DentaQuest discovered the unauthorized access to paper-based records and dental films through its internal security and compliance monitoring processes. Upon discovery, the organization initiated a comprehensive investigation to determine the scope of the breach, identify affected individuals, and assess what specific information may have been accessed or disclosed. The organization notified affected individuals in accordance with HIPAA's Breach Notification Rule, which requires notification without unreasonable delay and no later than 60 calendar days after discovery of a breach affecting unsecured PHI. The submission date of January 6, 2025, indicates the organization met its obligation to report the breach to HHS within the required timeframe.
Breach Mechanics and Vulnerability
This breach involved unauthorized access to physical paper records and dental films rather than digital systems or network servers. Paper-based breaches typically occur through physical theft, misplacement, unauthorized employee access, or inadequate physical security controls in medical record storage areas. The location designation of "Paper/Films" indicates that the compromised information was stored in traditional physical formats rather than electronic health record (EHR) systems. This breach type suggests potential vulnerabilities in physical access controls, record management procedures, or employee training regarding confidentiality obligations. Dental films (radiographic images) are particularly sensitive as they contain both identifiable patient information and clinical diagnostic data that could be misused for identity theft or fraudulent purposes.
Organizational Context
DentaQuest is a major dental benefits and services provider operating across multiple states, including Wisconsin. The organization manages dental insurance plans, processes claims, and maintains extensive patient records including clinical information, treatment histories, and personal identifiers. As a dental services organization handling PHI, DentaQuest is subject to HIPAA Privacy, Security, and Breach Notification Rules. The Wisconsin location of this breach indicates the organization maintains physical facilities or records storage in the state. The scope of operations suggests DentaQuest likely serves thousands of dental patients through affiliated providers and insurance plans, making the security of patient records a critical operational and compliance responsibility.
Patient Impact and Affected Population
Approximately 868 individuals in Wisconsin were affected by this unauthorized access incident. These patients had their protected health information potentially exposed, including information contained in their dental records and radiographic films. The affected population likely includes current and former dental patients whose records were stored in the compromised location. Notification letters were sent to all affected individuals informing them of the breach, the types of information potentially accessed, and recommended protective measures. The notification process is a critical component of HIPAA compliance and provides patients with the information necessary to monitor for potential misuse of their personal health information.
Exposed Information Categories
Based on the breach location (paper records and dental films) and typical dental practice documentation, the exposed PHI likely includes: patient names, dates of birth, addresses, telephone numbers, insurance information including member ID numbers, dental treatment histories and clinical notes, diagnoses and treatment plans, dental radiographic images (X-rays), provider information, and potentially Social Security numbers if used for patient identification or insurance purposes. Dental records are particularly sensitive as they contain both identifiable information and clinical data that could be used for identity theft, fraudulent insurance claims, or unauthorized medical treatment. The combination of demographic data with clinical information increases the risk profile of this breach.
HIPAA Compliance and Industry Context
Under the HIPAA Breach Notification Rule, any unauthorized access or disclosure of unsecured PHI affecting more than 500 residents of a state or jurisdiction requires notification to prominent media outlets in addition to individual notification. While this breach affects fewer than 500 individuals, it still triggers mandatory individual notification requirements. The breach demonstrates the ongoing vulnerability of paper-based records in healthcare settings, despite the industry's shift toward electronic health records. Physical security breaches remain a significant source of healthcare data incidents, accounting for a substantial percentage of reported HIPAA violations. Organizations are required to implement administrative, physical, and technical safeguards to protect PHI, including access controls, employee training, and secure storage of paper records. This incident underscores the importance of comprehensive records management policies and physical security measures in healthcare organizations.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the DentaQuest Breach
Monitor credit reports and consider placing a fraud alert or credit freeze with the three major credit bureaus (Equifax, Experian, TransUnion) to prevent unauthorized accounts from being opened in your name
Review dental insurance statements and claims for unauthorized activity; contact your insurance provider immediately if you identify suspicious charges or claims you did not authorize
Monitor your medical and dental records for unauthorized access or treatment; request copies of your records from DentaQuest and your dental providers to verify accuracy
Consider enrolling in identity theft protection services or credit monitoring if offered by DentaQuest; watch for suspicious communications requesting personal or financial information related to dental services
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Wisconsin Breaches
Search all breaches reported in Wisconsin