Healthcare technology company Xsolis disclosed a data breach affecting 1,396,519 individuals whose information it received from hospitals, health systems, and payers. Xsolis said attackers gained access after a targeted phishing attack on January 20, 2026, with unauthorized activity detected on January 22. Exposed data includes names, dates of birth, addresses, Social Security numbers, health insurance details, and medical treatment information, according to the company and the U.S. Department of Health and Human Services breach tracker.
Why it matters: This is a large-scale exposure of sensitive medical and identity data, creating long-term risks of identity theft, insurance fraud, and targeted scams for affected people. Healthcare organizations and partners using Xsolis should review third-party access and phishing defenses, while affected individuals should watch for breach notices, fraud, and medical-identity misuse.
Bill Toulas
2026.06.23
99% relevant
This article is the same underlying breach event and adds detail on the January 20 phishing attack, January 22 detection, the exposed data elements, password resets, and mitigation steps described in Xsolis' notices.
Eduard Kovacs
2026.06.23
100% relevant
This article appears to be the first concrete report in this set establishing Xsolis as the breached organization, the phishing intrusion timeline, and the confirmed scope of 1.4 million affected individuals.
← Back to all stories