Navia Benefit Solutions, Inc.
ent_1c269722dd6753e7
Disclosures
18
State AG · HHS OCR · 14 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
2,697,540
nationwide · State AG TX
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Navia Benefit Solutions, Inc.
- Normalized
- navia benefit— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- naviabenefits.com
Disclosure history (18)newest first
- New Hampshire State AGas victim2026-03-30
Navia Benefit Solutions, Inc. filed a supplemental data event notice with the New Hampshire Attorney General on March 30, 2026, regarding 5 additional NH residents affected by an unauthorized access incident occurring between December 22, 2025, and January 15, 2026. The breach exposed names, DOB, SSNs, and health plan participation data. Navia notified law enforcement, provided 12 months of Kroll credit monitoring, and implemented additional safeguards.
- Vermont State AGas victim2026-03-23
Navia Benefit Solutions, Inc. disclosed an unauthorized access incident occurring between Dec 22, 2025, and Jan 15, 2026, discovered on Jan 23, 2026. The incident impacted names and other data elements. Navia notified federal law enforcement, offered credit monitoring via Kroll, and is reviewing security policies. No specific count of affected individuals was provided in the filing.
- Washington State AGas victim2026-03-23
Navia Benefits Solutions Inc reported a cyberattack affecting 1,100 Washington residents. Unauthorized access occurred between Dec 22, 2025, and Jan 15, 2026. Navia discovered suspicious activity on Jan 23, 2026. Impacted data included names and other personal information. Navia notified law enforcement and offered credit monitoring.
- Texas State AGas victim2026-03-20
Navia Benefit Solutions, Inc. based in Renton, Washington, a other entity reported a data breach to the Texas Attorney General. The breach was discovered on 2026-01-23 and reported on 2026-03-20. 62,821 Texas residents were affected. 2,697,540 individuals affected in total. Types of information involved: Name of individual;Address;Social Security Number Information;Date of Birth. Consumers were notified via U.S. Mail.
- Vermont State AGas victim2026-03-18
Navia Benefit Solutions, Inc. notified consumers of a data breach where an unauthorized actor accessed information between Dec 22, 2025, and Jan 15, 2026. Impacted data included names and health plan participation details (HRAs, FSAs, COBRA). No claims or financial data were disclosed. Navia notified federal law enforcement and offered Kroll identity monitoring services.
- New Hampshire State AGas victim2026-03-18
Navia Benefit Solutions, Inc. notified the New Hampshire Attorney General of a data event affecting 1,351 NH residents. Unauthorized access occurred between Dec 22, 2025, and Jan 15, 2026. Navia discovered suspicious activity on Jan 23, 2026. Impacted data included names, DOBs, SSNs, phone numbers, and emails. Navia notified federal law enforcement, offered 12 months of Kroll credit monitoring, and implemented additional safeguards.
- Nebraska State AGas victim2026-03-18
Navia Benefit Solutions, Inc. disclosed a data breach affecting 17,485 Nebraska residents. Unauthorized access occurred between December 22, 2025, and January 15, 2026. Navia discovered the activity on January 23, 2026. Impacted data included names, DOBs, SSNs, phone numbers, emails, and HRA/FSA/COBRA participation details. Navia notified law enforcement, provided 12 months of Kroll credit monitoring, and implemented additional safeguards.
- Massachusetts State AGas victim2026-03-18
Navia Benefit Solutions, Inc. notified Massachusetts residents of a security incident affecting personal information. The company investigated the incident, confirmed system security, and reviewed data for sensitive information. Due to Massachusetts law, specific details of the incident nature are withheld in the notice. Navia notified federal law enforcement and is offering 24 months of identity monitoring via Kroll. No specific dates, counts, or attack vectors were disclosed in the letter.
- WASHINGTONHHS OCRas victim2026-03-18
Navia Benefit Solutions, Inc. reported to HHS on 2026-03-18 a Hacking/IT Incident affecting 2151330 individuals. Breached information located on Network Server, Other. Business Associate present.
- Maine State AGas victim2026-03-18
Navia Benefit Solutions, Inc. disclosed an external system breach (hacking) occurring between Dec 22, 2025, and Jan 15, 2026. Discovered Jan 23, 2026, the incident impacted 2,697,540 individuals, including 833 in Maine. Compromised data included names, DOBs, SSNs, and contact info. Navia notified law enforcement, offered 12 months of Kroll credit monitoring, and implemented additional safeguards.
- Washington State AGas victim2026-03-18
Navia Benefit Solutions, Inc. disclosed a cyberattack affecting 319,208 Washington residents. Unauthorized access occurred Dec 22, 2025 – Jan 15, 2026; discovered Jan 23, 2026. Data exposed: names, DOB, SSNs, contact info, and HRA/FSA/COBRA participation. Navia notified law enforcement, offered 12 months of Kroll credit monitoring, and implemented additional safeguards.
- Delaware State AGas victim2026-03-18
Navia Benefit Solutions, Inc. disclosed a security incident discovered on January 23, 2026, involving unauthorized access to systems between December 22, 2025, and January 15, 2026. The breach impacted names and government identifiers (SSN, DOB) of individuals enrolled in HRAs, FSAs, or COBRA. Navia notified federal law enforcement, engaged forensic investigation, and offered identity monitoring via Kroll. The incident status is contained.
- Iowa State AGas victim2026-03-18
Navia Benefit Solutions, Inc. notified the Iowa AG of a data event affecting 2,718 Iowa residents. Unauthorized access occurred between Dec 22, 2025, and Jan 15, 2026. Navia discovered suspicious activity on Jan 23, 2026. Impacted data included names, DOBs, SSNs, phone numbers, and emails. Navia notified law enforcement, offered 12 months of credit monitoring via Kroll, and implemented additional safeguards.
- Oregon State AGas victim2026-03-18
Navia Benefit Solutions, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2026-03-18. The breach occurred during 12/22/2025 - 1/15/2026. The breach was discovered on 1/23/2026. 2,697,540 individuals were affected. Notice was sent on 3/18/2026.
- Montana State AGas victim2026-03-18
Navia Benefit Solutions, Inc. notified Montana residents of a security incident discovered on January 23, 2026. Unauthorized access occurred between December 22, 2025, and January 15, 2026, impacting names and government identifiers (SSN, DOB). Navia engaged forensic investigators, notified federal law enforcement, and offered Kroll identity monitoring services. The incident status is contained.
- Indiana State AGas victim2026-03-18
Navia Benefit Solutions Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2025-12-22 and was reported on 2026-03-18. 6,088 Indiana residents were affected.
- California State AGas victim2026-03-18
Navia Benefit Solutions, Inc., a benefits administration company, discovered on January 23, 2026 that an unauthorized actor accessed and acquired certain personal information between December 22, 2025 and January 15, 2026. Potentially impacted data includes names, and may include health plan participation details (HRAs, FSAs, COBRA), termination dates, and election dates. No claims or financial data were disclosed. Federal law enforcement was notified and identity monitoring services via Kroll were offered to affected individuals.
- Illinois State AGas victim2026-03-01
NAVIA BENEFIT SOLUTIONS, INC. filed a data-breach notice with the Illinois Attorney General in March 2026 (case 26-03-1076). The register records the breach as discovered on January 23, 2026. Personal information types reported: ssn. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.