---
title: "Navia Benefit Solutions API data incident"
description: "Evidence-backed account of Navia Benefit Solutions API data incident, covering what happened, impact, timeline, attack vector, technical details, and primary sources."
incident_type: "Data incident"
status: "active"
last_modified: "2026-08-09"
canonical_url: "https://www.ally.security/incidents/navia-benefit-solutions-api-data-incident-2025"
markdown_url: "https://www.ally.security/incidents/navia-benefit-solutions-api-data-incident-2025.md"
stix_url: "https://www.ally.security/incidents/navia-benefit-solutions-api-data-incident-2025/stix.json"
---

# Navia Benefit Solutions API data incident

Unauthorized read-only access to benefits-participant data through an application programming interface. Potential acquisition of benefits-participant identity and account information held by Navia for clients.

Last modified Aug 9, 2026 · 5 sources

## Summary

- **Environment:** Benefits administrator and business associate whose environment and participant data were accessed.
- **Operational impact:** No outage or recovery duration quantified
- **Financial impact:** No public cost estimate

## What happened

[Navia Benefit Solutions](https://www.naviabenefits.com/) disclosed unauthorized read-only access to benefits-participant data through an application programming interface. [1](#source-1) [2](#source-2)

## Impact

Potential acquisition of benefits-participant identity and account information held by Navia for clients. [2](#source-2) [3](#source-3) [4](#source-4)

Documented data types include:

- Social Security numbers — Category varied by individual and population; HCA lists Social Security numbers for affected PEBB and SEBB members. [2](#source-2)
- Benefits account identifiers — Washington HCA lists Navia ID numbers for its affected member population. [2](#source-2)
- Dates of birth [2](#source-2)
- Names [2](#source-2)
- Contact information — Washington HCA lists physical addresses for its affected member population; Texas also lists addresses. [2](#source-2)

A cited record reports 62,821 individuals (Texas residents according to report BR-0004920; not a national total; as of 2026-03-20). [2](#source-2) [3](#source-3) [4](#source-4)

A cited record reports 32,000 individuals (Approximately 32,000 current and former Washington PEBB and SEBB members whom HCA said Navia planned to notify; rounded, overlapping program scope and not additive to regulator totals; as of 2026-03-03). [2](#source-2) [3](#source-3) [4](#source-4)

A cited record reports 37,498 individuals (Massachusetts residents according to incident 2026-417; not a national total; as of 2026-03-18). [2](#source-2) [3](#source-3) [4](#source-4)

A cited record reports 2,151,330 individuals (Individuals in the HHS OCR incident report; regulator-reported and not independently verified. This is not treated as the all-population total; as of 2026-08-08). [2](#source-2) [3](#source-3) [4](#source-4)

A cited record reports 2,697,540 individuals (Total individuals affected according to Texas Attorney General report BR-0004920; regulator-reported and not independently verified. This differs from the HHS OCR population and is retained separately; as of 2026-03-20). [2](#source-2) [3](#source-3) [4](#source-4)

Navia's California notice says no claims or financial data were disclosed; Washington HCA separately reported no evidence of access to claims data or members' bank-account information. [1](#source-1)

## Timeline

### December 22, 2025 — Activity began

Start of the unauthorized-access interval identified by Navia and Washington HCA. [1](#source-1)

### January 15, 2026 — Documented activity ended

End of the unauthorized-access interval identified by Navia and Washington HCA. [1](#source-1)

### January 23, 2026 — Discovery

Date Navia says it discovered suspicious activity in its environment. [1](#source-1)

### March 3, 2026 — Public disclosure

Date Washington HCA publicly issued its Navia incident bulletin; individual letters were planned for mid-March and the sampled letter date is redacted. [2](#source-2)

### August 9, 2026 — Briefing updated

This briefing was last reviewed and updated on August 9, 2026.

## Threat Group & Attack Vector

Washington HCA described unauthorized read-only access through an application programming interface and a system vulnerability used to gain access; the sources reviewed do not identify the actor or assign a CVE. [2](#source-2)

### Actors

- No threat actor group has been identified in the reviewed public evidence.

### TTPs

- No specific MITRE ATT\&CK technique is currently mapped for this case.

## Response

At the time of the California notice, Navia said it was unaware of attempted or actual misuse of the recipient's information. Navia said it investigated, reviewed system security and relevant data, notified potentially impacted individuals, and notified federal law enforcement and applicable regulators. Washington HCA said Navia fixed the system vulnerability, engaged external forensic specialists and incident counsel, disabled participant registration temporarily, and strengthened registration and authentication controls including multifactor authentication. Navia offered complimentary Kroll identity monitoring, including credit monitoring, fraud consultation, and identity-theft restoration; the duration is redacted in the California sample. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1](#source-1) [2](#source-2)

## Assets

[Download the case-scoped STIX 2.1 bundle](<https://www.ally.security/incidents/navia-benefit-solutions-api-data-incident-2025/stix.json>)

## Sources

Primary source records used to research this incident.

<a id="source-1"></a>

### Navia Benefit Solutions notice of data event — California sample

official · Navia Benefit Solutions, Inc.

<https://oag.ca.gov/system/files/Navia%20Benefit%20Solutions%20-%20Notice%20of%20Data%20Event%20-%20CA_0.pdf>

<a id="source-2"></a>

### Notification of Navia data breach

official · Washington State Health Care Authority

<https://content.govdelivery.com/accounts/WAHCA/bulletins/40c7b47>

<a id="source-3"></a>

### Data Security Breach Reports — 2026 public records

regulatory · Office of the Attorney General of Texas

<https://www.texasattorneygeneral.gov/consumer-protection/data-breach-reporting>

<a id="source-4"></a>

### 2026 Data Breach Notification Report

regulatory · Massachusetts Office of Consumer Affairs and Business Regulation

<https://www.mass.gov/doc/data-breach-report-2026/download>

<a id="source-5"></a>

### Breach Portal current investigation table

regulatory · U.S. Department of Health and Human Services Office for Civil Rights

<https://ocrportal.hhs.gov/ocr/breach/breach_report_hip.jsf>

<details>
<summary>Evidence ledger</summary>

Review the supporting structured claims.

1. **Affected Individual Count · 100% confidence · current**  
   Navia benefits-participant data exposure: 62,821 individual
2. **Affected Individual Count · 100% confidence · current**  
   Navia benefits-participant data exposure: 32,000 individual
3. **Resulted In · 100% confidence · current**  
   December 2025–January 2026 Navia API incident: Navia benefits-participant data exposure
4. **Resulted In · 100% confidence · current**  
   Navia client, public, and affected-individual notifications: At the time of the California notice, Navia said it was unaware of attempted or actual misuse of the recipient's information.
5. **Affected Organization · 100% confidence · current**  
   December 2025–January 2026 Navia API incident: Washington State Health Care Authority
6. **Exposed Data Category · 100% confidence · current**  
   Navia benefits-participant data exposure: Social Security numbers
7. **Exposed Data Category · 100% confidence · current**  
   Navia benefits-participant data exposure: Benefits account identifiers
8. **Resulted In · 100% confidence · current**  
   December 2025–January 2026 Navia API incident: Navia said it investigated, reviewed system security and relevant data, notified potentially impacted individuals, and notified federal law enforcement and applicable regulators.
9. **Affected Organization · 100% confidence · current**  
   December 2025–January 2026 Navia API incident: Navia Benefit Solutions, Inc.
10. **Resulted In · 100% confidence · current**  
   December 2025–January 2026 Navia API incident: Washington HCA said Navia fixed the system vulnerability, engaged external forensic specialists and breach counsel, disabled participant registration temporarily, and strengthened registration and authentication controls including multifactor authentication.
11. **Exposed Data Category · 100% confidence · current**  
   Navia benefits-participant data exposure: Dates of birth
12. **Affected Individual Count · 100% confidence · current**  
   Navia benefits-participant data exposure: 37,498 individual
13. **Affected Individual Count · 100% confidence · current**  
   Navia benefits-participant data exposure: 2,151,330 individual
14. **Resulted In · 100% confidence · current**  
   December 2025–January 2026 Navia API incident: Washington HCA described unauthorized read-only access through an application programming interface and a system vulnerability used to gain access; the sources reviewed do not identify the actor or assign a CVE.
15. **Resulted In · 100% confidence · current**  
   Navia client, public, and affected-individual notifications: Navia offered complimentary Kroll identity monitoring, including credit monitoring, fraud consultation, and identity-theft restoration; the duration is redacted in the California sample.
16. **Disclosed At · 100% confidence · current**  
   December 2025–January 2026 Navia API incident: 2026-03-03
17. **Exposed Data Category · 100% confidence · current**  
   Navia benefits-participant data exposure: Names
18. **Ended At · 100% confidence · current**  
   December 2025–January 2026 Navia API incident: 2026-01-15
19. **Resulted In · 100% confidence · current**  
   Navia benefits-participant data exposure: Navia's California notice says no claims or financial data were disclosed; Washington HCA separately reported no evidence of access to claims data or members' bank-account information.
20. **Affected Individual Count · 100% confidence · current**  
   Navia benefits-participant data exposure: 2,697,540 individual
21. **Began At · 100% confidence · current**  
   December 2025–January 2026 Navia API incident: 2025-12-22
22. **Exposed Data Category · 100% confidence · current**  
   Navia benefits-participant data exposure: Contact information
23. **Resulted In · 100% confidence · current**  
   December 2025–January 2026 Navia API incident: Navia client, public, and affected-individual notifications
24. **Discovered At · 100% confidence · current**  
   December 2025–January 2026 Navia API incident: 2026-01-23

</details>
