Navvis & Company, LLC
ent_019e0d25a23c1b0f9628fb7712f11847
Disclosures
14
State AG · HHS OCR · 8 jurisdictions
Multi-filing incidents
4
incidents joining 2+ filings here
Max affected reported
2,824,726
nationwide · HHS OCR MO
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Navvis & Company, LLC
- Normalized
- navvis— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300G37CPH6OEET108
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (14)newest first
- ⛰️New Hampshire State AGas victim2024-06-06
Navvis & Company, LLC, a provider of health management services, disclosed a cyber-attack where an unauthorized actor accessed systems between July 12-25, 2023. Suspicious activity was detected on July 25, 2023. The incident involved PII and PHI. Navvis notified law enforcement, HHS, and state regulators, and offered credit monitoring to affected individuals.
- 🐻California State AGas victim2024-06-06
Navvis & Company, LLC reported a cyber-attack occurring between July 12 and July 25, 2023, where a threat actor accessed systems containing personal and protected health information (PHI), including names, dates of birth, and medical records. The incident was discovered on July 25, 2023. This supplemental notice informs affected individuals that their data may have been accessed. Navvis secured its network, launched an investigation, and is offering credit monitoring services.
- 💎Delaware State AGas victim2024-06-06
State AG breach notice from Delaware regarding Navvis & Company, LLC. The attached PDF contains only PostScript page description language (drawing commands, font metrics, and vector paths) with no readable text content describing a breach, incident, or affected data.
- 🍁Vermont State AGas victim2024-06-06
Navvis & Company, LLC, a health management services provider, disclosed a cyber-attack occurring between July 12 and July 25, 2023. Suspicious activity was identified on July 25, 2023. The incident potentially exposed PHI and PII, including names, DOBs, health plan info, and medical record numbers. Navvis secured its network, engaged in investigation, notified regulators, and offered credit monitoring. No specific victim count was provided in the Vermont filing.
- 🐻California State AGas victim2024-02-09
Navvis & Company, LLC, a health management services provider, experienced unauthorized access to its network between July 12 and July 25, 2023. The incident involved potential exposure of protected health information (PHI), including names, dates of birth, health plan info, and medical records. Navvis secured its network, launched an investigation, and is offering credit monitoring. This is a supplemental notice filed with the California Attorney General.
- ⛰️New Hampshire State AGas victim2024-02-09
Navvis & Company, LLC, a provider of health management services, disclosed a data breach affecting 255 New Hampshire residents. Unauthorized access occurred between July 12 and July 25, 2023. Navvis detected suspicious activity on July 25, 2023, and notified law enforcement, HHS, and state regulators. Affected individuals received credit monitoring services.
- 🐻California State AGas victim2024-01-09
Navvis & Company, LLC, a health management services provider, reported a cyber-attack where an unauthorized actor accessed systems containing personal and protected health information between July 12 and July 25, 2023. The incident was discovered on July 25, 2023. This supplemental notice updates prior disclosures. Affected data includes names, dates of birth, health plan info, and medical records. Credit monitoring is offered.
- 🐻California State AGas victim2023-12-29
Navvis & Company, LLC, a health management services provider, reported unauthorized access to its network between July 12 and July 25, 2023. The company identified suspicious activity on July 25, 2023. Affected data may include names and health-related information. Navvis is a business associate of SSM Health. The company secured its network, launched an investigation, and offered credit monitoring to affected individuals.
- 🦫Oregon State AGas victim2023-12-29
Navvis & Company, LLC reported a data breach to the Oregon Attorney General. The breach was reported on 2023-12-29. The breach occurred during 7/12/2023 - 7/25/2023. The breach was discovered on 12/7/2023. 874,506 individuals were affected. Notice was sent on 12/29/2023.
- 🌲Washington State AGas victim2023-12-29
Navvis & Company, LLC, a health sector entity reported a ransomware incident to the Washington Attorney General. The organization became aware of the incident on 2023-07-25 and filed notice on 2023-12-29. 6,783 Washington residents were affected. 157 days elapsed between awareness and notification. 13 days to identify the breach. 0 days to contain the breach.
- 🍁Vermont State AGas victim2023-10-06
Navvis & Company, LLC, a healthcare management services provider, disclosed a cybersecurity incident where an unauthorized actor accessed systems between July 12 and July 25, 2023. Suspicious activity was identified on July 25, 2023. The incident may have exposed names and other PII. Navvis secured its network, launched an investigation, enhanced privacy policies, notified regulators, and offered credit monitoring services to affected individuals.
- ⛰️New Hampshire State AGas victim2023-10-06
Navvis & Company, LLC, a healthcare management services provider, disclosed a cybersecurity incident to New Hampshire residents on October 6, 2023. Unauthorized access occurred between July 12 and July 25, 2023, when an actor accessed systems containing personal information. Navvis notified law enforcement, implemented safeguards, and offered credit monitoring. The specific data elements are redacted in the template but likely include identity and government identifiers.
- MOHHS OCRas victim2023-09-22
Navvis & Company, LLC reported to HHS on 2023-09-22 a Hacking/IT Incident affecting 2,824,726 individuals. Breached information located on Network Server. The business associate experienced a phishing and ransomware attack compromising PHI including names, addresses, DOB, SSN, claims, and diagnoses. The BA offered credit monitoring and implemented safeguards.
- 🧀Wisconsin State AGas victim2023-09-22
Navvis & Company reported a data breach to the Wisconsin DATCP. The public was notified on 2023-09-22. The incident occurred on Between July 12 and July 25, 2023. Data accessed: Names, account numbers, birthdates, diagnoses/clinical information, health insurance policy numbers, medical date of service, medical provider names, medical treatment/procedure information, and patient account numbers. 316,043 Wisconsin residents were affected.