Summary
- Environment: Benefits administrator and business associate whose environment and participant data were accessed.
- Operational impact: No outage or recovery duration quantified
- Financial impact: No public cost estimate
- Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.
What happened
Navia Benefit Solutions disclosed unauthorized read-only access to benefits-participant data through an application programming interface. [1][2]
Impact
Potential acquisition of benefits-participant identity and account information held by Navia for clients. [2][3][4]
Documented data types include:
- Social Security numbers — Category varied by individual and population; HCA lists Social Security numbers for affected PEBB and SEBB members. [2]
- Benefits account identifiers — Washington HCA lists Navia ID numbers for its affected member population. [2]
- Dates of birth [2]
- Names [2]
- Contact information — Washington HCA lists physical addresses for its affected member population; Texas also lists addresses. [2]
A cited record reports 62,821 individuals (Texas residents according to report BR-0004920; not a national total; as of 2026-03-20). [2][3][4]
A cited record reports 32,000 individuals (Approximately 32,000 current and former Washington PEBB and SEBB members whom HCA said Navia planned to notify; rounded, overlapping program scope and not additive to regulator totals; as of 2026-03-03). [2][3][4]
A cited record reports 37,498 individuals (Massachusetts residents according to incident 2026-417; not a national total; as of 2026-03-18). [2][3][4]
A cited record reports 2,151,330 individuals (Individuals in the HHS OCR incident report; regulator-reported and not independently verified. This is not treated as the all-population total; as of 2026-08-08). [2][3][4]
A cited record reports 2,697,540 individuals (Total individuals affected according to Texas Attorney General report BR-0004920; regulator-reported and not independently verified. This differs from the HHS OCR population and is retained separately; as of 2026-03-20). [2][3][4]
Navia’s California notice says no claims or financial data were disclosed; Washington HCA separately reported no evidence of access to claims data or members’ bank-account information. [1]
Timeline
Activity began
Start of the unauthorized-access interval identified by Navia and Washington HCA.
[1]Documented activity ended
End of the unauthorized-access interval identified by Navia and Washington HCA.
[1]Discovery
Date Navia says it discovered suspicious activity in its environment.
[1]Public disclosure
Date Washington HCA publicly issued its Navia incident bulletin; individual letters were planned for mid-March and the sampled letter date is redacted.
[2]Briefing updated
This briefing was last reviewed and updated on August 9, 2026.
Threat Group & Attack Vector
Washington HCA described unauthorized read-only access through an application programming interface and a system vulnerability used to gain access; the sources reviewed do not identify the actor or assign a CVE. [2]
Actors
- No threat actor group has been identified in the reviewed public evidence.
TTPs
- No specific MITRE ATT&CK technique is currently mapped for this case.
Response
At the time of the California notice, Navia said it was unaware of attempted or actual misuse of the recipient’s information. Navia said it investigated, reviewed system security and relevant data, notified potentially impacted individuals, and notified federal law enforcement and applicable regulators. Washington HCA said Navia fixed the system vulnerability, engaged external forensic specialists and incident counsel, disabled participant registration temporarily, and strengthened registration and authentication controls including multifactor authentication. Navia offered complimentary Kroll identity monitoring, including credit monitoring, fraud consultation, and identity-theft restoration; the duration is redacted in the California sample. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1][2]
