Xsolis, a Tennessee-based healthcare technology company and business associate for HIPAA-covered entities, disclosed a data breach affecting 1,396,519 individuals after attackers gained access to a limited portion of its environment through a targeted phishing attack. The company said unauthorized activity began on January 20, 2026, was detected on January 22, and was then contained by terminating the intruder’s access. The incident has been reported to the US Department of Health and Human Services Office for Civil Rights and added to the HHS breach tracker, confirming the scale of the exposure.
The compromised files contained personal and protected health information received from Xsolis clients, including names, dates of birth, addresses, Social Security numbers, health insurance details, and medical treatment information. Xsolis said the data may have been copied, but it has found no evidence of actual or attempted misuse so far and no ransomware group has claimed responsibility. Confirmed affected healthcare clients include VHC Health and Rochester Regional Health, and Xsolis is offering 12 months of credit monitoring and identity theft protection through Kroll.

See attribution, scope, and your downstream exposure.
8 events from the most recent confirmed update back to the earliest known activity.
Several healthcare organizations, including Mayo Clinic, Legacy Health, Rochester Regional Health, and UW Medicine, confirmed that their patients were affected by the Xsolis data breach. This added named downstream victims to the incident beyond Xsolis’s previously reported aggregate total.
Xsolis said exposed information included names, dates of birth, addresses, Social Security numbers, health insurance details, and medical treatment information, and stated it found no evidence of misuse. The company also said it is offering 12 months of credit monitoring and identity theft protection through Kroll.
Xsolis reported the breach to the HHS Office for Civil Rights as affecting 1,396,519 patients of its healthcare provider clients. The incident was also added to the HHS data breach tracker, confirming the reported scale.
Reporting on the Xsolis incident identified VHC Health as one of the healthcare provider clients whose patient data was affected. This adds a newly named downstream victim beyond those already publicly linked to the breach.
Xsolis said it began mailing notification letters to people affected by the breach after reporting the incident to regulators and law enforcement. The notices informed impacted individuals about the compromise and available identity protection services.
The California Attorney General’s Office posted a copy of Xsolis’s breach notification, publicly surfacing details of the incident. This posting was noted as occurring on June 19, 2026.
On January 22, 2026, Xsolis detected the unauthorized activity, contained the incident, and terminated the attacker’s access. The company later said the unauthorized access lasted from January 20 to January 22, 2026.
Xsolis said an unauthorized third party accessed a limited portion of its environment beginning on January 20, 2026, after a targeted phishing attack. Files containing personal and protected health information were exposed during the intrusion.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
9 references tracked. Mallory keeps watching after this page renders.
techrepublic.com
Open sourcescworld.com
Open sourcesecurityaffairs.com
Open sourcehipaajournal.com
Open sourcesecurityweek.com
Open sourceteiss.co.uk
Open sourcebleepingcomputer.com
Open sourcemalware.news
Open sourcexsolisdataincident.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.