Xsolis Data Breach Exposes PHI for 1.4 Million via Phishing: What Was Reportedly Exposed & What To Do
Xsolis disclosed a data breach on June 5, 2026, exposing personal information, protected health information, Social Security numbers, and medical records for 1.4 million individuals after a phishing incident. Anyone potentially affected should check the organization’s notice and take steps to protect their data.
Healthcare technology firm Xsolis reported a data breach on June 5, 2026, that exposed personal and protected health information of 1,396,519 individuals. The incident followed a targeted phishing attack in January 2026 that granted unauthorized access to files the company had received from hospital and payer clients. No ransomware was involved and there is no reported evidence of data misuse to date.
Incidents involving healthcare data continue to draw attention because they combine sensitive personal details with information that retains value over time. The scale of this exposure places it among larger breaches disclosed in recent years, underscoring how phishing remains an effective entry point even against organizations that handle regulated information.
What happened
Xsolis disclosed that a phishing campaign in January 2026 succeeded in obtaining access to internal files. Those files contained personal information and protected health information supplied by the firm’s hospital and payer clients. The company stated that 1,396,519 individuals were affected. No claim of ransomware deployment was made, and the organization has not reported any confirmed misuse of the exposed data.
How a breach like this happens
Targeted phishing typically begins with messages crafted to appear as legitimate communications from known contacts or internal systems. When an employee interacts with the message, attackers obtain credentials or install tools that allow further movement inside the network. Once inside, they locate and copy files containing client-supplied data before detection occurs. Organizations that store aggregated records from multiple sources can inadvertently increase the volume of information accessible through a single successful entry point.
Xsolis and its sector
Xsolis operates as a healthcare technology company that works with hospitals and payers. In this role it receives and processes personal and medical information on behalf of those clients. Healthcare technology firms routinely hold records that include identifiers, clinical details, and insurance data because their services depend on integrating information across providers and insurers. A breach at such a firm can therefore affect individuals whose records were never stored directly by the company itself.
The information in question
The disclosure identifies the exposed data as personal information, protected health information, Social Security numbers, and medical records. These categories align with the types of client data the company is known to receive. The exact fields contained in each record have not been itemized beyond these descriptions, so the precise combination of elements for any individual remains unconfirmed.
What's at stake
Individuals whose information appears in the affected files face the possibility of identity theft or fraud that relies on medical or financial identifiers. Healthcare data can also be used for targeted scams or to file false claims. For the organization, the incident adds to regulatory reporting obligations and may prompt reviews of access controls and employee training. Because the data originated from multiple client sources, downstream effects could extend to the hospitals and payers that supplied the records.
If your data was in this claimed breach
People who believe their information may have been involved should review statements or notices issued by Xsolis or their healthcare providers for specific instructions. Standard steps include monitoring financial and insurance accounts for unusual activity, placing fraud alerts with credit bureaus if Social Security numbers may have been exposed, and requesting free credit reports. Individuals can also run a free exposure scan of their email address against known breach datasets to check for appearances in public listings of compromised information.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
AdaptHealth Patient Data Stolen via Contractor PhishingBaylor Genetics Notifies on Cybersecurity IncidentGolden State Orthopedics & Spine Breached by BrainCipherEagle Crest Communities Hit by SafePay RansomwareLatest breaches
Based on public reporting
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.