Navia Benefit Solutions API data incident

Unauthorized read-only access to benefits-participant data through an application programming interface. Potential acquisition of benefits-participant identity and account information held by Navia for clients.

Last modified

Summary

  • Environment: Benefits administrator and business associate whose environment and participant data were accessed.
  • Operational impact: No outage or recovery duration quantified
  • Financial impact: No public cost estimate
  • Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.

What happened

Navia Benefit Solutions disclosed unauthorized read-only access to benefits-participant data through an application programming interface. [1][2]

Impact

Potential acquisition of benefits-participant identity and account information held by Navia for clients. [2][3][4]

Documented data types include:

  • Social Security numbers — Category varied by individual and population; HCA lists Social Security numbers for affected PEBB and SEBB members. [2]
  • Benefits account identifiers — Washington HCA lists Navia ID numbers for its affected member population. [2]
  • Dates of birth [2]
  • Names [2]
  • Contact information — Washington HCA lists physical addresses for its affected member population; Texas also lists addresses. [2]

A cited record reports 62,821 individuals (Texas residents according to report BR-0004920; not a national total; as of 2026-03-20). [2][3][4]

A cited record reports 32,000 individuals (Approximately 32,000 current and former Washington PEBB and SEBB members whom HCA said Navia planned to notify; rounded, overlapping program scope and not additive to regulator totals; as of 2026-03-03). [2][3][4]

A cited record reports 37,498 individuals (Massachusetts residents according to incident 2026-417; not a national total; as of 2026-03-18). [2][3][4]

A cited record reports 2,151,330 individuals (Individuals in the HHS OCR incident report; regulator-reported and not independently verified. This is not treated as the all-population total; as of 2026-08-08). [2][3][4]

A cited record reports 2,697,540 individuals (Total individuals affected according to Texas Attorney General report BR-0004920; regulator-reported and not independently verified. This differs from the HHS OCR population and is retained separately; as of 2026-03-20). [2][3][4]

Navia’s California notice says no claims or financial data were disclosed; Washington HCA separately reported no evidence of access to claims data or members’ bank-account information. [1]

Timeline

  1. Activity began

    Start of the unauthorized-access interval identified by Navia and Washington HCA.

    [1]
  2. Documented activity ended

    End of the unauthorized-access interval identified by Navia and Washington HCA.

    [1]
  3. Discovery

    Date Navia says it discovered suspicious activity in its environment.

    [1]
  4. Public disclosure

    Date Washington HCA publicly issued its Navia incident bulletin; individual letters were planned for mid-March and the sampled letter date is redacted.

    [2]
  5. Briefing updated

    This briefing was last reviewed and updated on August 9, 2026.

Threat Group & Attack Vector

Washington HCA described unauthorized read-only access through an application programming interface and a system vulnerability used to gain access; the sources reviewed do not identify the actor or assign a CVE. [2]

Actors

  • No threat actor group has been identified in the reviewed public evidence.

TTPs

  • No specific MITRE ATT&CK technique is currently mapped for this case.

Response

At the time of the California notice, Navia said it was unaware of attempted or actual misuse of the recipient’s information. Navia said it investigated, reviewed system security and relevant data, notified potentially impacted individuals, and notified federal law enforcement and applicable regulators. Washington HCA said Navia fixed the system vulnerability, engaged external forensic specialists and incident counsel, disabled participant registration temporarily, and strengthened registration and authentication controls including multifactor authentication. Navia offered complimentary Kroll identity monitoring, including credit monitoring, fraud consultation, and identity-theft restoration; the duration is redacted in the California sample. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1][2]