Threat reportData BreachTL-2026-0922

Xsolis, Inc. Healthcare Technology Data Breach via Targeted Phishing (CVE-less; 1,396,519 individuals)

highRESOLVED

Xsolis, Inc. Healthcare Technology Data Breach via Targeted (TL-2026-0922), also tracked as Xsolis Data Breach, is a high-severity data breach, first published 2026-06-23. It has no confirmed attribution, affects Xsolis, Inc. Xsolis AI-powered utilization / case management platform, maps to 11 MITRE ATT&CK techniques (T1056, T1078, T1083), and is covered by 9 detection rules and 19 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
11MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
19Indicators of compromise

Key facts for TL-2026-0922

Threat ID
TL-2026-0922
Also known as
Xsolis Data Breach, Xsolis, Inc. Data Breach (2026)
Severity
HIGH
Status
RESOLVED
Category
DATA_BREACH
First published
Last reviewed
Attribution confidence
NONE
Motivation
UNKNOWN
Target sectors
healthcare, health insurance, hospitals, healthcare technology
Target regions
North America, United States
Detection rules
9
Indicators of compromise
19

How Xsolis, Inc. Healthcare Technology Data Breach via Targeted works

Xsolis, a healthcare technology business associate providing AI-powered utilization and case management software to 600+ hospitals and health plans, disclosed a data breach affecting 1,396,519 individuals after a targeted phishing attack against an employee on January 20, 2026 yielded unauthorized access to a limited portion of its environment. Exposed protected health information (PHI) and PII included names, addresses, dates of birth, Social Security numbers, health insurance information, and medical treatment details.

Xsolis, Inc. is a Nashville-based healthcare technology firm and HIPAA business associate whose AI-powered platform supports case management, utilization management, and reimbursement/medical-necessity decisioning for more than 600 hospitals and health insurers. On January 20, 2026, a targeted phishing attack against an Xsolis employee compromised credentials and gave attackers unauthorized access to a 'limited portion' of the Xsolis environment. Xsolis identified the unauthorized activity on January 22, 2026, immediately contained the activity, terminated the unauthorized access, and launched an investigation with external cybersecurity experts and law enforcement.

The forensic investigation determined that protected health information and personally identifiable information was accessible during the intrusion window. Exposed data elements included full names, postal addresses, dates of birth, Social Security numbers, health insurance information, and medical treatment information. Because Xsolis operates as a business associate, the exposed records belong to patients of its covered-entity clients; confirmed downstream-affected organizations include VHC Health (Northern Virginia / Washington D.C. metro area) and Rochester Regional Health (New York). Xsolis reported the incident to the U.S. Department of Health and Human Services Office for Civil Rights (HHS OCR), whose breach portal lists 1,396,519 individuals affected.

Xsolis stated it found no evidence of unauthorized access after January 22, 2026 and no evidence that exposed data has been misused. As remediation, Xsolis reset passwords for all users and key accounts, increased system monitoring, rolled out updated security measures, accelerated employee security-awareness training, and strengthened credential-management mechanisms. Affected individuals are being offered 12 months of complimentary identity monitoring, credit monitoring, fraud consultation, and identity-theft restoration services through Kroll. Multiple plaintiff law firms (including Edelson Lechtzin LLP and Emery Reddy) announced investigations into potential class-action claims.

This incident is a credential-phishing-led supply-chain compromise of a healthcare vendor. No CVE, exploit/PoC, malware family, or named threat actor was disclosed. The defensive value is in phishing and identity/credential-abuse detection, business-associate/third-party risk monitoring, and HIPAA breach-response readiness rather than in patch-level vulnerability management.

MITRE ATT&CK techniques used in TL-2026-0922

Credential Access

T1056 Input Capture

Initial Access

T1078 Valid Accounts; T1566 Phishing

Persistence

T1078 Valid Accounts

Defense Evasion

T1078 Valid Accounts

Discovery

T1083 File and Directory Discovery; T1087 Account Discovery

Execution

T1204 User Execution

Collection

T1213 Data from Information Repositories; T1530 Data from Cloud Storage

Exfiltration

T1567 Exfiltration Over Web Service

Resource Development

T1583 Acquire Infrastructure

Reconnaissance

T1598 Phishing for Information

Affected products and versions in Xsolis, Inc. Healthcare Technology Data Breach via Targeted

  • Xsolis, Inc. — Xsolis AI-powered utilization / case management platform
    Vulnerable versions: N/A - data breach, not a software vulnerability
  • VHC Health — Downstream covered entity (patients affected)
    Vulnerable versions: N/A
  • Rochester Regional Health — Downstream covered entity (patients affected)
    Vulnerable versions: N/A

Remediation for Xsolis, Inc. Healthcare Technology Data Breach via Targeted

Immediate actions

  • Reset passwords for all users and key accounts
  • Terminate and contain unauthorized access; preserve forensic evidence
  • Notify affected individuals and offer Kroll identity/credit monitoring (12 months)
  • Report the breach to HHS OCR and law enforcement

Workarounds

  • Apply conditional-access and impossible-travel policies to flag anomalous logins from compromised credentials
  • Restrict and monitor access to PHI repositories on a least-privilege basis

Longer-term hardening

  • Enforce phishing-resistant MFA (FIDO2/WebAuthn) on all employee and remote-access accounts
  • Increase system monitoring and centralized logging across identity and email systems
  • Accelerate and sustain employee security-awareness and phishing-simulation training
  • Strengthen credential-management mechanisms (password hygiene, secrets vaulting, conditional access)
  • Implement third-party / business-associate risk monitoring for downstream covered entities

Weaknesses (CWE) in Xsolis, Inc. Healthcare Technology Data Breach via Targeted

CWE-1216, CWE-522, CWE-307, CWE-200

Timeline of Xsolis, Inc. Healthcare Technology Data Breach via Targeted

  • Targeted phishing attack against an Xsolis employee compromises credentials, granting attackers unauthorized access to a limited portion of the Xsolis environment.
  • Xsolis launches an investigation with external cybersecurity experts and notifies law enforcement.
  • Unauthorized access is terminated; no evidence of unauthorized access has been found since this date.
  • Xsolis identifies the unauthorized activity in its environment and immediately contains it.
  • Xsolis resets passwords for all users and key accounts, increases monitoring, accelerates employee security training, and strengthens credential-management mechanisms (period approximate, post-containment).
  • Plaintiff law firms including Edelson Lechtzin LLP and Emery Reddy announce investigations into potential class-action claims.
  • Xsolis begins notifying affected individuals and offers 12 months of Kroll identity/credit monitoring and identity-theft restoration.
  • Xsolis publicly discloses the breach and reports 1,396,519 individuals affected to HHS OCR; media coverage (BleepingComputer, HIPAA Journal, TechRadar, SecurityAffairs) begins.

Sources cited for Xsolis, Inc. Healthcare Technology Data Breach via Targeted

Detection coverage for TL-2026-0922

As of 2026-06-23, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0922 across Splunk SPL, Microsoft KQL and Sigma, covering 19 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
19 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats