← All news

phishing

Xsolis phishing breach exposes 1.4 million patient records

2026-06-25

Xsolis, a Tennessee healthcare AI company whose software sits inside more than 600 hospitals and insurers, has confirmed that a phishing attack exposed personal data belonging to nearly 1.4 million people. The timeline is the part that should make anyone in healthcare IT uneasy.

Attackers got in on 20 January 2026. By 22 January, Xsolis knew something was wrong. Somewhere in that 48-hour window, files left the building.

What was taken

The stolen data is exactly the sort that causes long-tail damage:

  • Names, addresses and dates of birth
  • Social Security numbers
  • Health insurance details
  • Medical treatment information

Xsolis has described the breach as affecting a limited portion of its environment. That is technically accurate and largely beside the point for the 1,396,519 individuals now receiving credit-monitoring offers in the post. Once Social Security numbers and medical histories are in someone else's hands, the scope of the affected subnet is not a comfort.

How they got in

This is the bit worth lingering on. No unpatched server. No zero-day in an obscure appliance. No clever lateral movement through a misconfigured cloud bucket. A targeted phishing email landed in the inbox of someone with enough access to matter, and that person clicked.

The attackers did not need to be sophisticated once they were inside. They needed the door opened, and someone opened it. The rest, two days of quiet rummaging followed by an exit with a copy of the goods, is depressingly routine.

A bad month for healthcare tech

Xsolis is the third healthcare technology firm to disclose an incident in under a month, after iRhythm and Novo Nordisk. The sector is clearly being worked through methodically by people who understand what the data is worth, and who have noticed that healthcare vendors often sit between under-resourced IT teams and enormous troves of regulated data.

No group has claimed responsibility for the Xsolis intrusion. Outside investigators have been brought in and law enforcement notified, which is the standard playbook and provides exactly the reassurance you would expect: not much.

The uncomfortable bit

It is tempting, when reading about breaches at AI companies serving hundreds of hospitals, to assume the failure must have been exotic. Some unknown vulnerability, some bleeding-edge attack technique. The reality is duller and harder to fix. The entry point in a vast number of these incidents is still a person, an email, and a moment of inattention.

You can spend a fortune on detection and response, and Xsolis presumably did, given they spotted the intrusion within 48 hours. That speed is genuinely good by industry standards. It still was not fast enough to stop 1.4 million records from leaving. Detection is the consolation prize. The prize is not letting the email work in the first place.

Xsolis phishing breach exposes 1.4 million patient records | RiskSense