Navia Benefit Solutions, Inc., an employee benefits administrator, disclosed a data breach that occurred between December 22, 2025, and January 15, 2026. The company discovered the unauthorized access on January 23, 2026. Substitute notice was uploaded to their website on March 13, 2026, and individual notification letters were mailed starting March 18, 2026.
The breach affected approximately 2,697,540 individuals across the United States. Exposed data types include names, Social Security Numbers (SSNs), dates of birth, phone numbers, email addresses, physical addresses, government IDs, and protected health information (PHI), such as health plan enrollment details. Financial and claims data were not disclosed. The incident is reportable under HIPAA due to the exposure of PHI, and the HHS Office for Civil Rights has been notified. The full scope of the breach is still emerging, and additional details may become available.
Data breach details can change as new information emerges, and it is common for notification processes to be delayed.