Healthtech Firm Xsolis Suffers Data Breach Affecting 1.4 Million People
Healthtech firm Xsolis disclosed a targeted phishing breach that exposed the personal data of about 1.4 million people, including names, addresses, dates of birth, Social Security numbers, health-insurance details and medical information. Unauthorized activity was detected January 22, 2026, stemming from a phishing attack on January 20, 2026; the company has reset passwords, increased monitoring, and is offering 12 months of identity monitoring via Kroll, with no confirmed misuse to date.

Xsolis Breach: Data Exposure Affects 1.4 Million Health Data Records
OverviewA United States–based healthtech company, Xsolis, disclosed that sensitive information belonging to nearly 1.4 million individuals was compromised in a phishing intrusion that gained unauthorized access to its network. The firm emphasizes that there is no confirmed evidence of misuse of the exposed data at this time, but it is alerting potentially affected individuals to remain vigilant against targeted attacks. Xsolis develops AI-powered software used by hundreds of hospitals and health insurers to support utilization management, medical necessity reviews, patient status determinations, discharge planning, and reimbursement decisions. Its flagship platform, Dragonfly, analyzes clinical data in real time to help providers and payers make more informed decisions regarding patient care and insurance coverage.
Breach Details and Timeline
- Incident origin: A targeted phishing attack occurred on January 20, 2026, which led to unauthorized activity detected on January 22, 2026.
- Containment and investigation: Xsolis states that it immediately contained the activity and initiated a formal investigation with the help of external cybersecurity experts.
- Scope of access: The investigation determined that attackers accessed certain files within the Xsolis environment containing customer information.
Impacted DataThe data involved in the breach included:
- Names
- Addresses
- Dates of birth
- Health insurance information
- Social Security numbers
- Medical treatment information
According to the U.S. Department of Health and Human Services breach portal, 1,396,519 individuals are affected by this incident.
Company Response and Security Enhancements
- Notification and containment: Xsolis reported the incident to law enforcement, implemented additional security measures, and began notifying potentially affected individuals by mail.
- Access and credential controls: The company reset passwords for all users and key accounts, enhanced system monitoring, and completed the rollout of updated security measures.
- Training and credential management: The security training program for employees was accelerated, and credential-management processes were strengthened.
- Identity monitoring: Notifications sent to affected individuals include enrollment instructions for a 12-month identity monitoring and identity theft restoration service through Kroll.
- Special consideration for minors: If the affected individual is a child, the data notification is sent to the child’s parent or legal guardian.
About Xsolis and Dragonfly
- Role in care decisions: Xsolis’s Dragonfly platform analyzes real-time clinical data to help healthcare providers and payers make more informed and consistent decisions regarding patient care and insurance coverage.
- Business scope: The company’s software supports utilization management, medical necessity reviews, patient status determinations, discharge planning, and reimbursement decisions across more than 600 hospitals.
Notifications and Support Provided
- Contact and remediation: Affected individuals are being contacted by mail with details of the breach and the steps taken by Xsolis.
- Monitoring services: Enclosed in the notifications are instructions to enroll in a 12-month identity monitoring and identity theft restoration service through Kroll.
- Access safeguards: The company indicates that password resets and enhanced protections are in place to reduce future risk.
Industry Context and Related Considerations
- Security posture and preparedness: The incident underscores the ongoing importance of phishing defenses, rapid detection, and the swift deployment of security enhancements in healthcare IT environments.
- Continuous improvement: Beyond immediate containment, organizations typically review access controls, monitoring capabilities, and employee security training to mitigate similar threats.
SummaryThe breach at Xsolis highlights the vulnerability of healthtech platforms to phishing attacks that can expose a wide range of personal and health information. While there is currently no confirmed misuse of the compromised data, the company has taken steps to contain the breach, notify affected individuals, strengthen security measures, and provide ongoing identity protection services through a third-party provider. The incident also reinforces the critical role of real-time analytics in clinical decision support and the importance of robust security practices in protecting patient information across healthcare networks.


