# Xsolis, Inc. Healthcare Technology Data Breach via Targeted Phishing (CVE-less; 1,396,519 individuals)

> Xsolis, a healthcare technology business associate providing AI-powered utilization and case management software to 600+ hospitals and health plans, disclosed a data breach affecting 1,396,519 individuals after a targeted phishing attack against an employee on January 20, 2026 yielded unauthorized access to a limited portion of its environment. Exposed protected health information (PHI) and PII included names, addresses, dates of birth, Social Security numbers, health insurance information, and medical treatment details.

- **Published:** 2026-06-23T00:00:00Z
- **Last reviewed:** 2026-06-23T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0922
- **ID:** TL-2026-0922
- **Severity:** HIGH
- **Category:** DATA_BREACH
- **Status:** RESOLVED
- **Detections:** 9 · **IOCs:** 19 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Xsolis, Inc. is a Nashville-based healthcare technology firm and HIPAA business associate whose AI-powered platform supports case management, utilization management, and reimbursement/medical-necessity decisioning for more than 600 hospitals and health insurers. On January 20, 2026, a targeted phishing attack against an Xsolis employee compromised credentials and gave attackers unauthorized access to a 'limited portion' of the Xsolis environment. Xsolis identified the unauthorized activity on January 22, 2026, immediately contained the activity, terminated the unauthorized access, and launched an investigation with external cybersecurity experts and law enforcement.

The forensic investigation determined that protected health information and personally identifiable information was accessible during the intrusion window. Exposed data elements included full names, postal addresses, dates of birth, Social Security numbers, health insurance information, and medical treatment information. Because Xsolis operates as a business associate, the exposed records belong to patients of its covered-entity clients; confirmed downstream-affected organizations include VHC Health (Northern Virginia / Washington D.C. metro area) and Rochester Regional Health (New York). Xsolis reported the incident to the U.S. Department of Health and Human Services Office for Civil Rights (HHS OCR), whose breach portal lists 1,396,519 individuals affected.

Xsolis stated it found no evidence of unauthorized access after January 22, 2026 and no evidence that exposed data has been misused. As remediation, Xsolis reset passwords for all users and key accounts, increased system monitoring, rolled out updated security measures, accelerated employee security-awareness training, and strengthened credential-management mechanisms. Affected individuals are being offered 12 months of complimentary identity monitoring, credit monitoring, fraud consultation, and identity-theft restoration services through Kroll. Multiple plaintiff law firms (including Edelson Lechtzin LLP and Emery Reddy) announced investigations into potential class-action claims.

This incident is a credential-phishing-led supply-chain compromise of a healthcare vendor. No CVE, exploit/PoC, malware family, or named threat actor was disclosed. The defensive value is in phishing and identity/credential-abuse detection, business-associate/third-party risk monitoring, and HIPAA breach-response readiness rather than in patch-level vulnerability management.

## MITRE ATT&CK

- T1598 Phishing for Information
- T1583 Acquire Infrastructure
- T1566 Phishing
- T1078 Valid Accounts
- T1204 User Execution
- T1078 Valid Accounts
- T1078 Valid Accounts
- T1056 Input Capture
- T1087 Account Discovery
- T1083 File and Directory Discovery
- T1213 Data from Information Repositories
- T1530 Data from Cloud Storage
- T1567 Exfiltration Over Web Service

## Sources

- [Healthtech firm Xolis suffers data breach impacting 1.4 million people](https://www.bleepingcomputer.com/news/security/healthtech-firm-xolis-suffers-data-breach-impacting-14-million-people/)
- [Xsolis Data Breach Affects 1.4M Individuals](https://www.hipaajournal.com/xsolis-data-breach/)
- [US healthcare AI platform Xsolis confirms data breach that affects 1.4 million individuals](https://www.techradar.com/pro/security/us-healthcare-ai-platform-xsolis-confirms-data-breach-that-affects-1-4-million-individuals)
- [Xsolis Data Breach Impacts 1.4 Million People](https://securityaffairs.com/194067/cyber-crime/xsolis-data-breach-impacts-1-4-million-people.html)
- [Xsolis breach exposes personal and health data of 1.4 million people](https://www.scworld.com/brief/xsolis-breach-exposes-personal-and-health-data-of-1-4-million-people)
- [Xsolis Data Breach Hits 1.4 Million People As Healthcare Vendor Reports Patient Data Exposure](https://nchstats.com/xsolis-data-breach/)
- [Xsolis, Inc. Data Breach: Edelson Lechtzin LLP Launches Investigation Into Exposure of Personal Information](https://www.prnewswire.com/news-releases/xsolis-inc-data-breach-edelson-lechtzin-llp-launches-investigation-into-exposure-of-personal-information-302807098.html)
- [Xsolis, Inc. Data Breach (Emery Reddy)](https://www.emeryreddy.com/blog/data-breach/xsolis-inc-data-breach)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0922
