Navia Benefit Solutions, a benefits administrator, experienced a data breach that was publicly reported around March 2026. The incident is described as a supply-chain-style breach affecting downstream customers.
The breach exposed data for approximately 2.7 million individuals, including names, dates of birth, Social Security numbers, phone numbers, email addresses, addresses, HRA/FSA/COBRA enrollment and participation information, and dependent information. While some health-related benefits data was exposed, financial account, claims, and payment card data were reportedly not compromised. Customers in Washington, Massachusetts, Texas, Indiana, Iowa, New Hampshire, and Maine were among those affected.
Navia began mailing notices to affected individuals around March 17-18, 2026, and reported the breach to the Maine Attorney General on March 23, 2026. Further details may emerge as investigations continue.