Healthcare Vendor Xsolis Reports Breach Affecting 1.4M People

Healthcare Vendor Xsolis Reports Breach Affecting 1.4M People

Generated with Google’s Nano Banana 2.

Xsolis confirmed a healthcare data breach affecting nearly 1.4 million people after a phishing attack exposed health and identity data.

Written By
Liz Ticong
Liz Ticong
Jun 24, 2026

Nearly 1.4 million people are affected by a healthcare data breach involving Xsolis, a technology vendor that helps hospitals and health insurers review patient care.

Xsolis has confirmed that an unauthorized actor acquired files containing personal and protected health information, and the incident is now listed on the US Department of Health and Human Services’ public breach portal. HHS lists the breach as affecting 1,396,519 people.

You may never deal with Xsolis directly, but your health data might.

January intrusion began with targeted phishing

Xsolis traced the incident to a targeted phishing attack on Jan. 20, 2026, and said it discovered suspicious activity two days later that affected a limited portion of its systems.

After detecting the intrusion, the company said it cut off unauthorized access, isolated affected hosts and user accounts, engaged external cybersecurity experts, and notified law enforcement.

Investigators later found that the attacker acquired a limited number of files during the access period. The company said it has not detected further unauthorized activity since Jan. 22.

Stolen files contained health and identity data

The files taken from the company’s systems contained information that varied by person, according to Xsolis.

Names, addresses, dates of birth, health insurance information, Social Security numbers, and medical treatment information were among the data categories involved.

More than 600 hospitals and organizations use the vendor’s Dragonfly platform, though the attack has not been linked to all of them. Mayo Clinic, Legacy Health, Rochester Regional Health, and UW Medicine have confirmed patient impact from the breach.

Xsolis said it is not aware of any actual or attempted misuse related to the incident. Even so, identity details can be used in fraud attempts. Insurance and treatment information can also reveal details connected to care, billing, and benefits.

Advertisement

Must-read security coverage

Xsolis strengthens security and offers monitoring

Following the incident, Xsolis said it took several steps to strengthen security, including:

  • resetting passwords for all users and key accounts
  • increasing system monitoring
  • deploying new protective technology
  • completing the rollout of updated security measures
  • accelerating annual security training
  • strengthening processes for managing credentials and responding to future incidents

The company is offering eligible people who receive notification letters 12 months of identity-monitoring services through Kroll at no cost. For adults, the offer includes credit monitoring, fraud consultation, and identity theft restoration. Separate notices for minors include minor identity monitoring.

Password resets and stronger credential processes can reduce the chance that compromised access remains usable. Heavier monitoring gives security teams a better shot at catching unusual activity before an intrusion deepens.

Related reading: Novo Nordisk has confirmed a security incident after hackers claimed to have stolen 1.3 TB of sensitive company data. 

Liz Ticong

Liz Ticong is a technology writer specializing in artificial intelligence, cybersecurity, software reviews, and emerging business technologies. With more than a decade of professional writing experience and over five years contributing technology content for TechnologyAdvice, she helps readers understand complex technologies and evaluate the tools that best fit their needs. Liz has extensive experience researching, testing, and analyzing software platforms, AI tools, and technology solutions. Her work includes in-depth software reviews, buyer’s guides, product comparisons, and technology news coverage designed to help businesses make informed purchasing and implementation decisions. She regularly evaluates AI applications, automation tools, cybersecurity solutions, and business software, providing practical insights based on hands-on testing and research. In addition to her work with TechnologyAdvice, Liz has contributed technology content to leading industry publications, including eWeek and TechRepublic. Her background in technical writing and software analysis enables her to translate complex technical concepts into clear, actionable guidance for both business and technology audiences. Liz holds a bachelor's degree in Broadcast Communication from the Polytechnic University of the Philippines and continues to expand her expertise through ongoing education in artificial intelligence and emerging technologies. Through her writing, she helps readers navigate a rapidly evolving technology landscape with practical, research-driven insights and real-world product analysis.