Xsolis, Inc. Healthcare Technology Data Breach via Targeted Phishing (CVE-less; 1,396,519 individuals) — Threadlinqs Intelligence
As of 2026-06-23, Xsolis, Inc. Healthcare Technology Data Breach via Targeted Phishing (CVE-less; 1,396,519 individuals) is a high-severity data breach threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 19 indicators of compromise.
Threat ID: TL-2026-0922 · Severity: HIGH · Status: RESOLVED · Category: DATA_BREACH
Xsolis, a healthcare technology business associate providing AI-powered utilization and case management software to 600+ hospitals and health plans, disclosed a data breach affecting 1,396,519
Xsolis, Inc. is a Nashville-based healthcare technology firm and HIPAA business associate whose AI-powered platform supports case management, utilization management, and reimbursement/medical-necessity decisioning for more than 600 hospitals and health insurers. On January 20, 2026, a targeted phishing attack against an Xsolis employee compromised credentials and gave attackers unauthorized access to a 'limited portion' of the Xsolis environment. Xsolis identified the unauthorized activity on January 22, 2026, immediately contained the activity, terminated the unauthorized access, and launched an investigation with external cybersecurity experts and law enforcement.
The forensic investigation determined that protected health information and personally identifiable information was accessible during the intrusion window. Exposed data elements included full names, postal addresses, dates of birth, Social Security numbers, health insurance information, and medical treatment information. Because Xsolis operates as a business associate, the exposed records belong to patients of its covered-entity clients; confirmed downstream-affected organizations include VHC Health (Northern Virginia / Washington D.C. metro area) and Rochester Regional Health (New York). Xsolis reported the incident to the U.S. Department of Health and Human Services Office for Civil Rights (HHS OCR), whose breach portal lists 1,396,519 individuals affected.
Xsolis stated it found no evidence of unauthorized access after January 22, 2026 and no evidence that exposed data has been misused. As remediation, Xsolis reset passwords for all users and key accounts, increased system monitoring, rolled out updated security measures, accelerated employee security-awareness training, and strengthened credential-management mechanisms. Affected individuals are being offered 12 months of complimentary identity monitoring, credit monitoring, fraud consultation, and identity-theft restoration services through Kroll. Multiple plaintiff law firms (including Edelson Lechtzin LLP and Emery Reddy) announced investigations into potential class-action claims.
This incident is a credential-phishing-led supply-chain compromise of a healthcare vendor. No CVE, exploit/PoC, malware family, or named threat actor was disclosed. The defensive value is in phishing and identity/credential-abuse detection, business-associate/third-party risk monitoring, and HIPAA breach-response readiness rather than in patch-level vulnerability management.
Weaknesses (CWE)
CWE-1216, CWE-522, CWE-307, CWE-200
Target sectors: healthcare, health insurance, hospitals, healthcare technology
Target regions: North America, United States
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 19 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
DATA_BREACH, HIGH, threat intelligence, cybersecurity, T1598, T1583, T1566, T1566, T1566, T1078, T1078, T1204, T1204, T1078