VYPR
breachPublished Jun 23, 2026· Updated Jun 24, 2026· 3 sources

Healthcare AI Firm Xsolis Breach Exposes Data of 1.4 Million Patients

Healthcare AI company Xsolis disclosed a data breach affecting nearly 1.4 million individuals after a targeted phishing attack in January exposed personal and medical information.

Healthcare technology company Xsolis, Inc. has disclosed a data breach affecting nearly 1.4 million individuals, according to a filing with the US Department of Health and Human Services (HHS). The Tennessee-based firm, which provides utilization management and revenue cycle solutions for hospitals, health systems, and payers, revealed that unauthorized activity was detected on its systems on January 22, stemming from a targeted phishing attack two days earlier.

The breach exposed files containing personal and protected health information (PHI) that Xsolis received from its clients. The compromised data includes names, dates of birth, addresses, Social Security numbers, health insurance information, and medical treatment details. The HHS data breach tracker now lists the incident as affecting 1,396,519 individuals.

Xsolis published a data security notice in early June, but the full scale of the incident became clearer only after the HHS disclosure. The company stated it is not aware of any actual or attempted misuse of the stolen information. No known ransomware group has claimed responsibility for the attack, and SecurityWeek has reached out to Xsolis for comment on whether an extortion attempt occurred.

The breach underscores the persistent vulnerability of healthcare data aggregators, which hold vast troves of sensitive patient information. Xsolis processes data from numerous healthcare providers, making it an attractive target for attackers seeking to monetize medical records. The incident follows a pattern of large-scale healthcare breaches, such as the DentaQuest incident affecting 2.6 million accounts.

Xsolis is in the process of notifying affected individuals and regulators. The company has not disclosed specific remediation steps beyond the initial detection and response. Healthcare organizations that rely on Xsolis's services may need to reassess third-party risk management practices in light of this incident.

The breach highlights the growing threat of phishing attacks targeting healthcare technology vendors. As AI-driven healthcare analytics become more prevalent, the concentration of sensitive data in third-party platforms creates new attack surfaces. Regulators and industry groups are likely to scrutinize Xsolis's security posture and response timeline in the coming months.

The BleepingComputer report adds that Xsolis reset all user passwords, increased system monitoring, and accelerated employee security training in response to the breach. Affected individuals are being offered 12 months of identity monitoring and restoration services through Kroll. The company also noted that if the affected customer is a child, notifications will be sent to their parents or legal guardians.

The Help Net Security report adds that Xsolis serves more than 600 hospitals and health insurers, and that the exposed data may include Social Security numbers and medical treatment information. The company has established a toll-free call center and is offering free credit monitoring and identity protection services to affected individuals. No threat actor has publicly claimed responsibility for the incident, which is the third healthcare technology breach disclosed in less than a month, following incidents at iRhythm Technologies and Novo Nordisk.

Synthesized by Vypr AI