Confirmed breach. Intrusion Dec 22, 2025–Jan 15, 2026, discovered Jan 23, 2026 — the first regulatory filing landed 54 days later (flagged late). 5,240,277 individuals reported across the linked filings.
Regulatory clocksOregon✗ OR AG >45dTexas✗ TX AG >30dVermont⏱ VT AG >14 bdayWashington⏱ WA AG >30dMaine⏱ ME AG >30d · 54dHIPAA✓ HHS notifiedFull clock table in Litigation Timeline
HHS OCRState AGConfirmedLifecycle stage 2 of 3: ConfirmedUnverified claimConfirmedEnforcedmoderate sensitivity
Affected (total reported)
12days
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
5,240,277
Data types
2
Health (basic) · Identity (basic)
Jurisdictions
9
DE IA IN ME NH OR TX VT
Linked filings
14
HHS OCR · State AG
Affected residents by state
per-filing reported counts
OR2,697,540
WA319,208
TX62,821
IN6,088
NH1,351
WA1,100
ME833
NH5
ME1
State AGs report only their own residents; bars show per-filing counts.
Timeline
Earliest sighting first · deep chronology in Litigation Timeline
14 filings across 9 jurisdictions · Mar 18, 2026 – Mar 30, 2026 · 2 milestones
Breach window
Dec 22, 2025 → Jan 15, 2026
When the intrusion reportedly occurred, per the linked filings
32 days
Breach discoveredAG web form
Jan 23, 2026
Reported by VERMONT AG, WASHINGTON AG, DELAWARE AG, OREGON AG, NEW HAMPSHIRE AG, MAINE AG, TEXAS AG filings
Navia Benefit Solutions, Inc. notified consumers of a data breach where an unauthorized actor accessed information between Dec 22, 2025, and Jan 15, 2026. Impacted data included names and health plan participation details (HRAs, FSAs, COBRA). No claims or financial data were disclosed. Navia notified federal law enforcement and offered Kroll identity monitoring services.
VT AG >14 bday
⛰️New Hampshire State AGlinked via same-victim cross-source · 100%
Navia Benefit Solutions, Inc. notified the New Hampshire Attorney General of a data event affecting 1,351 NH residents. Unauthorized access occurred between Dec 22, 2025, and Jan 15, 2026. Navia discovered suspicious activity on Jan 23, 2026. Impacted data included names, DOBs, SSNs, phone numbers, and emails. Navia notified federal law enforcement, offered 12 months of Kroll credit monitoring, and implemented additional safeguards.
Navia Benefit Solutions, Inc. reported to HHS on 2026-03-18 a Hacking/IT Incident affecting 2151330 individuals. Breached information located on Network Server, Other. Business Associate present.
Affected (this filing): 2,151,330
HHS notified
Most recent
11 State AG filingsMar 18, 2026 – Mar 30, 2026ExpandCollapse
MEWADEIAORINTXVT+1 more
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
🦞Maine State AGlinked via same-victim cross-source · 100%
Navia Benefit Solutions (benefit administration) reported an external breach: unauthorized actor accessed and acquired PII/PHI between Dec 22, 2025 and Jan 15, 2026; discovered Jan 23, 2026. Data: name, DOB, SSN, phone, email, health plan participation. 833 ME residents affected (2,697,540 total). Kroll credit monitoring/identity restoration offered for 12 months.
Affected (this filing): 833
ME AG >30d · 54d
🌲Washington State AGlinked via same-victim cross-source · 100%
Navia Benefit Solutions, Inc., a business sector entity reported a other incident to the Washington Attorney General. The organization became aware of the incident on 2026-01-23 and filed notice on 2026-03-18. 319,208 Washington residents were affected. 54 days elapsed between awareness and notification. 32 days to identify the breach. 0 days to contain the breach.
Affected (this filing): 319,208
WA AG >30d
💎Delaware State AGlinked via same-victim cross-source · 100%
Navia Benefit Solutions, Inc. disclosed a security incident discovered on January 23, 2026, involving unauthorized access to systems between December 22, 2025, and January 15, 2026. The breach impacted names and government identifiers (SSN, DOB) of individuals enrolled in HRAs, FSAs, or COBRA. Navia notified federal law enforcement, engaged forensic investigation, and offered identity monitoring via Kroll. The incident status is contained.
🌽Iowa State AGlinked via same-victim cross-source · 100%
Navia Benefit Solutions, a financial services sector entity reported a data breach to the Iowa Attorney General. The breach was reported on 2026-03-18.
🦫Oregon State AGlinked via same-victim cross-source · 100%
Navia Benefit Solutions, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2026-03-18. The breach occurred during 12/22/2025 - 1/15/2026. The breach was discovered on 1/23/2026. 2,697,540 individuals were affected. Notice was sent on 3/18/2026.
Affected (this filing): 2,697,540
OR AG >45d
🏎️Indiana State AGlinked via same-victim cross-source · 100%
Navia Benefit Solutions Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2025-12-22 and was reported on 2026-03-18. 6,088 Indiana residents were affected.
Affected (this filing): 6,088
⭐Texas State AGlinked via same-victim cross-source · 100%
Navia Benefit Solutions, Inc. based in Renton, Washington, a other entity reported a data breach to the Texas Attorney General. The breach was discovered on 2026-01-23 and reported on 2026-03-20. 62,821 Texas residents were affected. 2,697,540 individuals affected in total. Types of information involved: Name of individual;Address;Social Security Number Information;Date of Birth. Consumers were notified via U.S. Mail.
Navia Benefit Solutions, Inc. disclosed an unauthorized access incident occurring between Dec 22, 2025, and Jan 15, 2026, discovered on Jan 23, 2026. The incident impacted names and other data elements. Navia notified federal law enforcement, offered credit monitoring via Kroll, and is reviewing security policies. No specific count of affected individuals was provided in the filing.
VT AG >14 bday
🌲Washington State AGlinked via same-victim cross-source · 100%
Navia Benefits Solutions Inc, a health sector entity reported a unclear/unknown incident to the Washington Attorney General. The organization became aware of the incident on 2026-01-23 and filed notice on 2026-03-23. 1,100 Washington residents were affected. 59 days elapsed between awareness and notification. 32 days to identify the breach. 0 days to contain the breach.
Affected (this filing): 1,100
WA AG >30d
🦞Maine State AGlinked via same-victim cross-source · 100%
HackerOne's benefits administrator Navia Benefit Solutions experienced a breach via a BOLA vulnerability. An unknown actor accessed Navia data Dec 22, 2025–Jan 15, 2026; discovered Jan 23, 2026. Exposed employee data includes SSNs, names, addresses, DOBs, emails, and health plan details. 287 total affected; 1 Maine resident. Kroll credit monitoring (12–24 months) offered.
Affected (this filing): 1
ME AG >30d · 59d
⛰️New Hampshire State AGlinked via same-victim cross-source · 100%
Navia Benefit Solutions, Inc. filed a supplemental data event notice with the New Hampshire Attorney General on March 30, 2026, regarding 5 additional NH residents affected by an unauthorized access incident occurring between December 22, 2025, and January 15, 2026. The breach exposed names, DOB, SSNs, and health plan participation data. Navia notified law enforcement, provided 12 months of Kroll credit monitoring, and implemented additional safeguards.