Navia Benefit Solutions, Inc., a third-party benefits administrator, disclosed a data breach that occurred in late 2025 and was discovered on January 23, 2026. This incident affected nearly 2.7 million individuals nationwide. The company formally notified individuals via mail on March 18, 2026, after a substitute breach notice was posted on its website on March 13, 2026.
The breach involved the exposure of names, dates of birth, Social Security numbers, phone numbers, email addresses, government IDs, employee IDs, health plan information (including FSA, HSA, HRA, and COBRA details), and enrollment dates. The U.S. Department of Health and Human Services (HHS) Office for Civil Rights was notified, confirming that 2,151,330 individuals had protected health information compromised. Navia stated that direct financial account numbers and claims data were not exposed.
More details regarding the full impact of this breach may emerge over time as investigations continue and affected individuals receive notifications.