Amanda Whitlow filed a class action against DentaQuest Group Inc. and DentaQuest LLC, alleging a data breach exposed personally identifiable information for about 15 million patients. The complaint says stolen data included names, dates of birth, Social Security numbers, health insurance and Medicaid/Medicare numbers, plus dental and vision records such as provider names, diagnoses, treatments and billing details. Whitlow argues DentaQuest failed to meet regulatory, legal and industry cybersecurity standards - failing to train employees to spot phishing, implement biometric or multi-factor authentication, or monitor for unusual activity - and notes the hacker group ShinyHunters claimed responsibility for the incident.
The lawsuit asserts DentaQuest discovered unauthorized activity on its network on May 20 but did not notify patients until August, increasing the risk of identity theft and financial harm; Whitlow claims both present and future concrete injuries. She seeks a jury trial and requests injunctive and declaratory relief, monetary damages and other equitable relief, alleging negligence, breach of implied contract, breach of fiduciary duty, unjust enrichment and violation of the Illinois Personal Information Protection Act. The case, Whitlow v. DentaQuest Group Inc., No. 1:26-cv-13868, was filed in U.S. District Court in Massachusetts and is being handled by Block & Leviton, Zimmerman Law Offices and DannLaw; some affected individuals report receiving notification letters and limited credit-monitoring offers.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.