Threat reportData BreachTL-2026-1023
Xsolis Data Breach: Targeted Phishing Attack Exposes PHI/PII of 1,396,519 Individuals
Xsolis Data Breach (TL-2026-1023), also tracked as Xsolis Phishing Breach 2026, is a high-severity data breach, first published 2026-07-01. It has no confirmed attribution, affects Xsolis Xsolis Utilization Management / Clinical Decision Support, maps to 18 MITRE ATT&CK techniques (T1005, T1020, T1071), and is covered by 9 detection rules and 18 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 18MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 18Indicators of compromise
Key facts for TL-2026-1023
- Threat ID
- TL-2026-1023
- Also known as
- Xsolis Phishing Breach 2026, Xsolis PHI Exposure
- Severity
- HIGH
- Status
- ACTIVE
- Category
- DATA_BREACH
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- FINANCIAL
- Target sectors
- health, health insurance, healthcare technology business associates
- Target regions
- united states of america, North America
- Detection rules
- 9
- Indicators of compromise
- 18
Malware and tooling in Xsolis Data Breach
Malware and tooling: Xsolis Dragonfly platform
How Xsolis Data Breach works
Tennessee-based healthcare AI vendor Xsolis, which provides utilization-management and revenue-cycle software to 600+ hospitals and health insurers, suffered unauthorized network access from a targeted phishing attack on January 20, 2026, discovered January 22, 2026. The breach exposed names, addresses, dates of birth, Social Security numbers, health insurance information, and medical treatment data for 1,396,519 individuals, with public/HHS disclosure delayed until June 2026.
Xsolis, a Tennessee-based healthcare technology company that develops AI-powered utilization management and clinical decision-support software used by more than 600 hospitals, health systems, and health insurers (including client relationships with organizations such as VHC Health in the Northern Virginia/Washington D.C. metro area and Rochester Regional Health in New York), suffered a targeted phishing attack on January 20, 2026. An unauthorized third party gained access to a limited portion of the Xsolis environment and remained present until the intrusion was detected on January 22, 2026. Xsolis engaged external cybersecurity specialists and law enforcement, contained the incident, and reviewed the affected files to determine that attackers acquired data including patient names, addresses, dates of birth, Social Security numbers, health insurance information, and medical treatment information belonging to 1,396,519 individuals — data that was received from Xsolis's healthcare-provider and payer clients in its capacity as a HIPAA business associate.
Notably, Xsolis did not report the breach to HHS Office for Civil Rights until June 5, 2026 — approximately 135 days after discovery, exceeding HIPAA's Breach Notification Rule requirement that business associates notify covered entities without unreasonable delay (generally within 60 days). Public disclosure followed via a company data security notice in early June and press coverage on June 23-24, 2026, with the incident subsequently added to the HHS OCR public breach-report tracker.
Xsolis's remediation included immediate containment and termination of unauthorized access, password resets across all user and key accounts, expanded system/network monitoring, deployment of new protective technologies, acceleration of employee security-awareness training, and strengthening of credential-management processes. Affected individuals are being offered 12 months of complimentary credit monitoring and identity-theft protection services through Kroll. As of disclosure, Xsolis reported no evidence of attempted or actual misuse of the exposed data, no ransomware group publicly claimed responsibility, and the company did not confirm whether an extortion demand was made or paid. This incident is the third healthcare-sector data breach disclosed within roughly a month (following breaches at iRhythm Technologies and Novo Nordisk), reflecting a continuing trend of attackers targeting healthcare technology vendors and business associates — who aggregate PHI/PII across many downstream provider and payer clients — as a high-leverage single point of compromise via social-engineering/phishing rather than technical exploitation.
MITRE ATT&CK techniques used in TL-2026-1023
Collection
T1005 Data from Local System; T1119 Automated Collection; T1213 Data from Information Repositories
Exfiltration
T1020 Automated Exfiltration; T1567 Exfiltration Over Web Service
Command and Control
T1071 Application Layer Protocol
Initial Access
T1078 Valid Accounts; T1566 Phishing
Persistence
Privilege Escalation
Defense Evasion
Discovery
T1083 File and Directory Discovery; T1087 Account Discovery
Execution
Impact
Credential Access
T1539 Steal Web Session Cookie; T1552 Unsecured Credentials
Resource Development
T1583 Acquire Infrastructure; T1586 Compromise Accounts
Reconnaissance
T1589 Gather Victim Identity Information; T1598 Phishing for Information
Affected products and versions in Xsolis Data Breach
- Xsolis — Xsolis Utilization Management / Clinical Decision Support Platform (corporate network / email environment)
Vulnerable versions: Production environment as of January 2026
Remediation for Xsolis Data Breach
Immediate actions
- Reset credentials for all users and privileged/key accounts across the affected environment
- Terminate unauthorized access and isolate compromised accounts/endpoints
- Engage external incident response and forensics specialists
- Report incident to federal law enforcement
- Notify affected individuals and offer credit monitoring / identity theft protection (Kroll, 12 months)
Workarounds
- Enforce conditional access / geofencing on webmail and VPN portals pending MFA rollout
- Increase email gateway sensitivity for credential-phishing indicators targeting healthcare-sector staff
Longer-term hardening
- Deploy phishing-resistant MFA (FIDO2/hardware tokens) for all remote and email access
- Expand continuous system and network monitoring / EDR coverage
- Accelerate and recur security-awareness and phishing-simulation training for all employees
- Strengthen credential management and privileged access governance
- Implement DLP and egress monitoring for bulk PHI file access/exfiltration
- Review and tighten business-associate data minimization and retention practices for downstream client PHI
Weaknesses (CWE) in Xsolis Data Breach
Timeline of Xsolis Data Breach
- Targeted phishing attack executed against Xsolis, granting an unauthorized third party access to a limited portion of the Xsolis network environment.
- Xsolis establishes a toll-free support center for affected individuals and confirms no evidence of unauthorized access to the environment after this date.
- Forensic investigation launched to determine scope of accessed files and affected individuals; no evidence of unauthorized access found after this date.
- Xsolis detects unauthorized network activity, terminates unauthorized access, and begins containment; engages external cybersecurity specialists and law enforcement.
- Xsolis submits breach report to U.S. Department of Health and Human Services Office for Civil Rights, roughly 135 days after discovery — exceeding HIPAA's Breach Notification Rule 60-day expectation for business associates.
- Xsolis files a sample data breach notification letter with the California Attorney General's Office, disclosing the incident to state regulators in addition to HHS OCR.
- Xsolis publishes a data security notice disclosing the breach and begins notifying affected individuals with an offer of 12 months of Kroll credit monitoring and identity-theft protection.
- Plaintiffs' law firms (e.g., ClassAction.org) announce investigations into potential class-action litigation on behalf of affected individuals.
- Breach widely reported by security and healthcare trade media (Help Net Security, HIPAA Journal, SecurityWeek, BleepingComputer, SecurityAffairs, TechTarget, Cybernews) citing the HHS OCR breach tracker figure of 1,396,519 affected individuals.
Sources cited for Xsolis Data Breach
- Xsolis data breach caused by phishing attack impacts 1.4 million people
- Xsolis Data Breach Affects 1.4M Individuals
- Xsolis Data Breach Affects 1.4 Million Individuals
- Healthtech firm Xolis suffers data breach impacting 1.4 million people
- Healthcare AI provider for Humana exposes data of 1.4M patients after phishing attack
- Healthcare Vendor Xsolis Reports Breach Affecting 1.4M People
- Healthcare AI platform Xsolis suffers data breach impacting 1.4M individuals
- Xsolis Data Breach Confirmed; Attorneys Investigating
- Xsolis Data Breach Impacts 1.4 Million People
- Healthcare Breach at AI Vendor Xsolis Exposes 1.4 Million Records Across Seven Major Hospitals
- Xsolis breach affected 1,396,519 of its clients' patients
- Xsolis Data Breach Affects 1.4 Million Individuals
- U.S. Department of Health & Human Services - Office for Civil Rights Breach Portal
- Xsolis Data Breach Impacts Over 1.3 Million Individuals Across the Nation
- Xsolis, Inc. Data Breach Investigation
Detection coverage for TL-2026-1023
As of 2026-07-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1023 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.