|
We want to make you aware of a recent notice the Health Care Authority received from Navia Benefit Solutions (Navia) regarding a confirmed data breach. (Navia is the administrator for the Flexible Spending Arrangement [FSA] and Dependent Care Assistance Program [DCAP] benefits for the PEBB and SEBB Programs.)
What happened
Navia experienced a breach involving unauthorized read-only access to participants’ data through an application programming interface (API) between December 22, 2025, and January 15, 2026.
In late January, Navia took action to fix the system vulnerability that had been used to gain access and immediately hired external forensics specialists and breach counsel. Navia also temporarily disabled participant registration to its portal and strengthened registration and authentication controls, including enhanced multi-factor authentication requirements.
Who is affected
This breach included Navia records going back seven years (to 2018) affecting almost 27,000 current and former PEBB members and about 5,600 current and former SEBB members.
Potential data exposed includes members’ Navia ID numbers, names, Social Security numbers, dates of birth, and addresses. Navia confirmed that there was no evidence of system intrusion, data modification, fund movement, or access to claims data or members’ bank account information.
Immediate actions
Navia will mail a letter to about 32,000 affected current and former PEBB and SEBB members by mid-March to notify them of the breach, and how they can protect their data through a credit monitoring service. We will notify you of when the letters are mailed to members and include a copy of the letter.
Navia also recently notified all employers that currently or previously contracted with them, including school districts that contracted with them before implementation of the SEBB Program in 2020. Because of this, some individuals who enrolled with Navia before and after SEBB Program implementation may receive more than one letter from Navia.
HCA has posted an announcement on its website and will provide updates as needed. Navia will post an announcement to its PEBB and SEBB public webpages shortly.
|