Navia Benefit Solutions, Inc., a third-party administrator for employee benefits, experienced a data breach that began on December 22, 2025, and continued until January 15, 2026. The company discovered the breach on January 23, 2026. Official notification letters to affected individuals began on March 18, 2026, with a substitute notice posted on Navia's website on March 13, 2026. This incident was confirmed by filings with various state Attorneys General.
Approximately 2.7 million individuals across Navia's client base were affected. The exposed data includes names, dates of birth, Social Security numbers, phone numbers, email addresses, and health plan enrollment information such as COBRA participation, Health Reimbursement Arrangements (HRAs), and Flexible Spending Accounts (FSAs), including election and termination dates. There is no indication that claims data or financial account information, such as bank or credit card numbers, was compromised.
Navia acted as a vendor for various clients, and this breach impacted their downstream customers. Affected parties were advised to monitor their finances and set up fraud alerts. Additional details may emerge as investigations continue, and affected individuals may receive delayed notifications.