# Xsolis Data Breach: Targeted Phishing Attack Exposes PHI/PII of 1,396,519 Individuals

> Tennessee-based healthcare AI vendor Xsolis, which provides utilization-management and revenue-cycle software to 600+ hospitals and health insurers, suffered unauthorized network access from a targeted phishing attack on January 20, 2026, discovered January 22, 2026. The breach exposed names, addresses, dates of birth, Social Security numbers, health insurance information, and medical treatment data for 1,396,519 individuals, with public/HHS disclosure delayed until June 2026.

- **Published:** 2026-07-01T00:00:00Z
- **Last reviewed:** 2026-07-01T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1023
- **ID:** TL-2026-1023
- **Severity:** HIGH
- **Category:** DATA_BREACH
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 18 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Xsolis, a Tennessee-based healthcare technology company that develops AI-powered utilization management and clinical decision-support software used by more than 600 hospitals, health systems, and health insurers (including client relationships with organizations such as VHC Health in the Northern Virginia/Washington D.C. metro area and Rochester Regional Health in New York), suffered a targeted phishing attack on January 20, 2026. An unauthorized third party gained access to a limited portion of the Xsolis environment and remained present until the intrusion was detected on January 22, 2026. Xsolis engaged external cybersecurity specialists and law enforcement, contained the incident, and reviewed the affected files to determine that attackers acquired data including patient names, addresses, dates of birth, Social Security numbers, health insurance information, and medical treatment information belonging to 1,396,519 individuals — data that was received from Xsolis's healthcare-provider and payer clients in its capacity as a HIPAA business associate.

Notably, Xsolis did not report the breach to HHS Office for Civil Rights until June 5, 2026 — approximately 135 days after discovery, exceeding HIPAA's Breach Notification Rule requirement that business associates notify covered entities without unreasonable delay (generally within 60 days). Public disclosure followed via a company data security notice in early June and press coverage on June 23-24, 2026, with the incident subsequently added to the HHS OCR public breach-report tracker.

Xsolis's remediation included immediate containment and termination of unauthorized access, password resets across all user and key accounts, expanded system/network monitoring, deployment of new protective technologies, acceleration of employee security-awareness training, and strengthening of credential-management processes. Affected individuals are being offered 12 months of complimentary credit monitoring and identity-theft protection services through Kroll. As of disclosure, Xsolis reported no evidence of attempted or actual misuse of the exposed data, no ransomware group publicly claimed responsibility, and the company did not confirm whether an extortion demand was made or paid. This incident is the third healthcare-sector data breach disclosed within roughly a month (following breaches at iRhythm Technologies and Novo Nordisk), reflecting a continuing trend of attackers targeting healthcare technology vendors and business associates — who aggregate PHI/PII across many downstream provider and payer clients — as a high-leverage single point of compromise via social-engineering/phishing rather than technical exploitation.

## MITRE ATT&CK

- T1589 Gather Victim Identity Information
- T1598 Phishing for Information
- T1583 Acquire Infrastructure
- T1586 Compromise Accounts
- T1566 Phishing
- T1078 Valid Accounts
- T1204 User Execution
- T1078 Valid Accounts
- T1078 Valid Accounts
- T1078 Valid Accounts
- T1552 Unsecured Credentials
- T1539 Steal Web Session Cookie
- T1087 Account Discovery
- T1083 File and Directory Discovery
- T1213 Data from Information Repositories
- T1005 Data from Local System
- T1119 Automated Collection
- T1071 Application Layer Protocol
- T1567 Exfiltration Over Web Service
- T1020 Automated Exfiltration
- T1531 Account Access Removal

## Sources

- [Xsolis data breach caused by phishing attack impacts 1.4 million people](https://www.helpnetsecurity.com/2026/06/24/xsolis-data-breach-phishing-attack/)
- [Xsolis Data Breach Affects 1.4M Individuals](https://www.hipaajournal.com/xsolis-data-breach/)
- [Xsolis Data Breach Affects 1.4 Million Individuals](https://www.securityweek.com/xsolis-data-breach-affects-1-4-million-individuals/)
- [Healthtech firm Xolis suffers data breach impacting 1.4 million people](https://www.bleepingcomputer.com/news/security/healthtech-firm-xolis-suffers-data-breach-impacting-14-million-people/)
- [Healthcare AI provider for Humana exposes data of 1.4M patients after phishing attack](https://cybernews.com/news/xsolis-humana-healthcare-data-breach-1-4-million-patients/)
- [Healthcare Vendor Xsolis Reports Breach Affecting 1.4M People](https://www.techrepublic.com/article/news-xsolis-healthcare-data-breach/)
- [Healthcare AI platform Xsolis suffers data breach impacting 1.4M individuals](https://www.techtarget.com/healthtechsecurity/news/366645116/Healthcare-AI-platform-Xsolis-suffers-data-breach-impacting-14M-individuals)
- [Xsolis Data Breach Confirmed; Attorneys Investigating](https://www.classaction.org/data-breach-lawsuits/xsolis-june-2026)
- [Xsolis Data Breach Impacts 1.4 Million People](https://securityaffairs.com/194067/cyber-crime/xsolis-data-breach-impacts-1-4-million-people.html)
- [Healthcare Breach at AI Vendor Xsolis Exposes 1.4 Million Records Across Seven Major Hospitals](https://www.techtimes.com/articles/319011/20260624/healthcare-breach-ai-vendor-xsolis-exposes-14-million-records-across-seven-major-hospitals.htm)
- [Xsolis breach affected 1,396,519 of its clients' patients](https://hipaapulse.com/xsolis-breach-affected-1-396-519-of-its-clients-patients-9cc9b7c6)
- [Xsolis Data Breach Affects 1.4 Million Individuals](https://hipaapulse.com/xsolis-data-breach-affects-1-4-million-individuals-84d9dcb0)
- [U.S. Department of Health & Human Services - Office for Civil Rights Breach Portal](https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf)
- [Xsolis Data Breach Impacts Over 1.3 Million Individuals Across the Nation](https://www.claimdepot.com/data-breach/xsolis-2026)
- [Xsolis, Inc. Data Breach Investigation](https://www.almeidalawgroup.com/data-breach-news/xsolis-inc-data-breach-investigation/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1023
