Benefits Administrator Reports 2.7 Million-record Data Breach

Another massive data breach has been reported involving unauthorized access to the sensitive data of millions of individuals. The data breach was announced by Navia Benefit Solutions, a Renton, Washington-based administrator of benefits programs, including Health Reimbursement Arrangements (HRAs), Flexible Spending Accounts (FSAs), Dependent Care Assistance Program (DCAP), and COBRA benefits. Navia Benefits Solutions works with companies nationwide and has around 10,000 clients serving more than 1 million subscribers. According to the breach report submitted to the Maine Attorney General, 2,697,540 people were affected. Some clients affected by the incident said data was compromised going back 7 years.

A suspected network intrusion was identified on January 23, 2026, prompting immediate action to secure its network. An investigation was launched to determine the nature and scope of the unauthorized activity, and Navia Benefit Solutions determined that its network was accessed by an unauthorized third party between December 22, 2025, and January 15, 2026.

Individuals affected by the incident were told that sensitive data may have been obtained. Whenever there has been a data breach, victims of the breach should assume the worst and take steps to protect themselves against identity theft and fraud, especially when financial information and Social Security numbers have been exposed. The hackers had a considerable window of opportunity to exfiltrate sensitive data from the network, so data theft is likely in this case.

While financial information was not compromised in the incident, Social Security numbers were exposed, as well as names, dates of birth, phone numbers, and email addresses, enrolment start and end dates, Navia ID numbers, and employee IDs. Navia Benefit Solutions had not identified any misuse of the affected data at the time of issuing notification letters. Out of an abundance of caution, the affected individuals have been offered complimentary credit monitoring and identity theft protection services.

Navia Benefit Solutions said it has taken steps to prevent similar incidents in the future, including reinforcing its API authorization and enabling multifactor authentication, and enforcing strict data access controls. While the full list of affected clients has not been made public at this stage, the Washington Health Care Authority issued a substitute breach notice confirming that it has been affected, and confirmed that Navia Benefits Solutions will start deleting data for accounts that have been inactive for 8 years, or if a subscriber did not select a DCAP or FSA in the previous 12 months. The HHS’ Office for Civil Rights has been notified, but the incident is not currently listed on the OCR data breach portal. It is therefore unclear how many individuals had protected health information compromised in the incident.

About Liam Johnson

Liam Johnson has produced articles about HIPAA for several years. He has extensive experience in healthcare privacy and security. With a deep understanding of the complex legal and regulatory landscape surrounding patient data protection, Liam has dedicated his career to helping organizations navigate the intricacies of HIPAA compliance. Liam focusses on the challenges faced by healthcare providers, insurance companies, and business associates in complying with HIPAA regulations. Liam has been published in leading healthcare publications, including The HIPAA Journal. Liam was appointed Editor-in-Chief of The HIPAA Guide in 2023. Contact Liam via LinkedIn: https://www.linkedin.com/in/liamhipaa/