Threat reportData BreachTL-2026-0922
Xsolis, Inc. Healthcare Technology Data Breach via Targeted Phishing (CVE-less; 1,396,519 individuals)
Xsolis, Inc. Healthcare Technology Data Breach via Targeted (TL-2026-0922), also tracked as Xsolis Data Breach, is a high-severity data breach, first published 2026-06-23. It has no confirmed attribution, affects Xsolis, Inc. Xsolis AI-powered utilization / case management platform, maps to 11 MITRE ATT&CK techniques (T1056, T1078, T1083), and is covered by 9 detection rules and 19 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 11MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 19Indicators of compromise
Key facts for TL-2026-0922
- Threat ID
- TL-2026-0922
- Also known as
- Xsolis Data Breach, Xsolis, Inc. Data Breach (2026)
- Severity
- HIGH
- Status
- RESOLVED
- Category
- DATA_BREACH
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- UNKNOWN
- Target sectors
- healthcare, health insurance, hospitals, healthcare technology
- Target regions
- North America, United States
- Detection rules
- 9
- Indicators of compromise
- 19
How Xsolis, Inc. Healthcare Technology Data Breach via Targeted works
Xsolis, a healthcare technology business associate providing AI-powered utilization and case management software to 600+ hospitals and health plans, disclosed a data breach affecting 1,396,519 individuals after a targeted phishing attack against an employee on January 20, 2026 yielded unauthorized access to a limited portion of its environment. Exposed protected health information (PHI) and PII included names, addresses, dates of birth, Social Security numbers, health insurance information, and medical treatment details.
Xsolis, Inc. is a Nashville-based healthcare technology firm and HIPAA business associate whose AI-powered platform supports case management, utilization management, and reimbursement/medical-necessity decisioning for more than 600 hospitals and health insurers. On January 20, 2026, a targeted phishing attack against an Xsolis employee compromised credentials and gave attackers unauthorized access to a 'limited portion' of the Xsolis environment. Xsolis identified the unauthorized activity on January 22, 2026, immediately contained the activity, terminated the unauthorized access, and launched an investigation with external cybersecurity experts and law enforcement.
The forensic investigation determined that protected health information and personally identifiable information was accessible during the intrusion window. Exposed data elements included full names, postal addresses, dates of birth, Social Security numbers, health insurance information, and medical treatment information. Because Xsolis operates as a business associate, the exposed records belong to patients of its covered-entity clients; confirmed downstream-affected organizations include VHC Health (Northern Virginia / Washington D.C. metro area) and Rochester Regional Health (New York). Xsolis reported the incident to the U.S. Department of Health and Human Services Office for Civil Rights (HHS OCR), whose breach portal lists 1,396,519 individuals affected.
Xsolis stated it found no evidence of unauthorized access after January 22, 2026 and no evidence that exposed data has been misused. As remediation, Xsolis reset passwords for all users and key accounts, increased system monitoring, rolled out updated security measures, accelerated employee security-awareness training, and strengthened credential-management mechanisms. Affected individuals are being offered 12 months of complimentary identity monitoring, credit monitoring, fraud consultation, and identity-theft restoration services through Kroll. Multiple plaintiff law firms (including Edelson Lechtzin LLP and Emery Reddy) announced investigations into potential class-action claims.
This incident is a credential-phishing-led supply-chain compromise of a healthcare vendor. No CVE, exploit/PoC, malware family, or named threat actor was disclosed. The defensive value is in phishing and identity/credential-abuse detection, business-associate/third-party risk monitoring, and HIPAA breach-response readiness rather than in patch-level vulnerability management.
MITRE ATT&CK techniques used in TL-2026-0922
Credential Access
Initial Access
T1078 Valid Accounts; T1566 Phishing
Persistence
Defense Evasion
Discovery
T1083 File and Directory Discovery; T1087 Account Discovery
Execution
Collection
T1213 Data from Information Repositories; T1530 Data from Cloud Storage
Exfiltration
T1567 Exfiltration Over Web Service
Resource Development
Reconnaissance
Affected products and versions in Xsolis, Inc. Healthcare Technology Data Breach via Targeted
- Xsolis, Inc. — Xsolis AI-powered utilization / case management platform
Vulnerable versions: N/A - data breach, not a software vulnerability - VHC Health — Downstream covered entity (patients affected)
Vulnerable versions: N/A - Rochester Regional Health — Downstream covered entity (patients affected)
Vulnerable versions: N/A
Remediation for Xsolis, Inc. Healthcare Technology Data Breach via Targeted
Immediate actions
- Reset passwords for all users and key accounts
- Terminate and contain unauthorized access; preserve forensic evidence
- Notify affected individuals and offer Kroll identity/credit monitoring (12 months)
- Report the breach to HHS OCR and law enforcement
Workarounds
- Apply conditional-access and impossible-travel policies to flag anomalous logins from compromised credentials
- Restrict and monitor access to PHI repositories on a least-privilege basis
Longer-term hardening
- Enforce phishing-resistant MFA (FIDO2/WebAuthn) on all employee and remote-access accounts
- Increase system monitoring and centralized logging across identity and email systems
- Accelerate and sustain employee security-awareness and phishing-simulation training
- Strengthen credential-management mechanisms (password hygiene, secrets vaulting, conditional access)
- Implement third-party / business-associate risk monitoring for downstream covered entities
Weaknesses (CWE) in Xsolis, Inc. Healthcare Technology Data Breach via Targeted
Timeline of Xsolis, Inc. Healthcare Technology Data Breach via Targeted
- Targeted phishing attack against an Xsolis employee compromises credentials, granting attackers unauthorized access to a limited portion of the Xsolis environment.
- Xsolis launches an investigation with external cybersecurity experts and notifies law enforcement.
- Unauthorized access is terminated; no evidence of unauthorized access has been found since this date.
- Xsolis identifies the unauthorized activity in its environment and immediately contains it.
- Xsolis resets passwords for all users and key accounts, increases monitoring, accelerates employee security training, and strengthens credential-management mechanisms (period approximate, post-containment).
- Plaintiff law firms including Edelson Lechtzin LLP and Emery Reddy announce investigations into potential class-action claims.
- Xsolis begins notifying affected individuals and offers 12 months of Kroll identity/credit monitoring and identity-theft restoration.
- Xsolis publicly discloses the breach and reports 1,396,519 individuals affected to HHS OCR; media coverage (BleepingComputer, HIPAA Journal, TechRadar, SecurityAffairs) begins.
Sources cited for Xsolis, Inc. Healthcare Technology Data Breach via Targeted
- Healthtech firm Xolis suffers data breach impacting 1.4 million people
- Xsolis Data Breach Affects 1.4M Individuals
- US healthcare AI platform Xsolis confirms data breach that affects 1.4 million individuals
- Xsolis Data Breach Impacts 1.4 Million People
- Xsolis breach exposes personal and health data of 1.4 million people
- Xsolis Data Breach Hits 1.4 Million People As Healthcare Vendor Reports Patient Data Exposure
- Xsolis, Inc. Data Breach: Edelson Lechtzin LLP Launches Investigation Into Exposure of Personal Information
- Xsolis, Inc. Data Breach (Emery Reddy)
Detection coverage for TL-2026-0922
As of 2026-06-23, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0922 across Splunk SPL, Microsoft KQL and Sigma, covering 19 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.