
Three days of access, 15 million patients, 24 months of cover
A class action was filed against the dental benefits provider DentaQuest in the US District Court for the District of Massachusetts. The Daily Hodl reported the case. Three numbers in it belong next to each other, and the company put them in separate paragraphs.
Intruders had access for three days, from 17 to 20 May. More than 15 million people had protected health information reached. Those affected are being offered 24 months of identity monitoring.
“DentaQuest failed to comply with regulatory, legal, ethical and industry standards for cybersecurity and confidentiality of patient records, failed to take reasonable security measures, such as training employees to identify phishing emails, employing biometric or multi-factor authentication requirements for authorized users, and monitoring for unusual activity.”
— Complaint filed by Amanda Whitlow, US District Court for the District of Massachusetts, via The Daily Hodl
Quote source: the complaint filed by plaintiff Amanda Whitlow, via The Daily Hodl
Three days, and the law allowed until July
Across a three-day window that averages five million people a day, which tells you the records were not read one by one. Bulk access to a benefits database is a single query repeated, and the size of the haul is limited by bandwidth rather than by effort.
The company says it discovered the activity on 20 May, the same day it stopped, and began notifying people in July.
American law allows that. The federal breach notification rule gives a covered organisation up to 60 days from discovery, which in this case ran to 19 July. Notifying in July is therefore compliant, and it also means people learned their medical records had been taken roughly six to eight weeks after it happened.
What cannot be reissued
What was reached is the part that outlasts the lawsuit.
- Names, addresses and Social Security numbers.
- Member identification numbers, plus Medicaid and Medicare numbers.
- Dental and vision records: diagnoses, treatments and billing details.
A Social Security number is issued once and never rotated. A Medicaid number identifies a person to a payer for years. A diagnosis is permanent by definition. None of these can be changed after a breach the way a password or a card number can.
Against that, the remedy on offer is two years of monitoring through Kroll. Monitoring does not remove the data from wherever it now sits; it tells you afterwards when someone uses it. The exposure has no expiry date and the cover does.
Why the DentaQuest data breach sits on a crypto site
There is no cryptocurrency in this case, and we are writing about it because this is where the other kind of theft begins. A full identity file with a Social Security number and medical history is the raw material for account takeovers and phone-number hijacking, and those land on exchanges months later.
We covered the Trezor customer data leak for the same reason: what leaks from a supplier turns up as a targeted approach to a wallet owner. We also wrote today about medical records handled by AI transcription, which is the same data in a different building.
The suit alleges negligence, breach of implied contract, breach of fiduciary duty, unjust enrichment and violation of the Illinois Personal Information Protection Act. DentaQuest says it reported the incident to law enforcement and engaged cybersecurity specialists. The allegations have not been tested in court.
Nothing here should be taken as financial advice; treat it as information to consider.

Comments (0)
No comments yet — be the first!
The market talks all day. We write when it says something
Short, and it tells you why it came
Related news
Most readTop 7
Silicon Valley Workers Are Wearing Noise-Cancelling Masks to Dictate AI Prompts
286AI





