Data Breaches

Xsolis Data Breach Affects 1.4 Million Individuals

Threat actors gained access to personal and protected health information that Xsolis received from its clients.

Healthcare data breach

Healthcare technology company Xsolis, Inc. has disclosed a data breach affecting nearly 1.4 million individuals. 

Tennessee-based Xsolis provides utilization management and revenue cycle solutions for hospitals, health systems, and payers.

The company published a data security notice in early June, revealing that unauthorized activity was detected on its systems on January 22. The intrusion resulted from a targeted phishing attack carried out two days earlier.

According to Xsolis, the hackers gained access to files storing personal and protected health information received by the company from its clients, including names, dates of birth, addresses, SSNs, health insurance information, and medical treatment information. 

While the data breach was disclosed two weeks ago, the US Department of Health and Human Services (HHS) has now disclosed the number of affected individuals. 

The Xsolis cybersecurity incident was added to the HHS data breach tracker on Monday, with the number of affected individuals listed as 1,396,519. 

Advertisement. Scroll to continue reading.

No known ransomware group appears to have taken credit for the attack on the healthcare tech company.

SecurityWeek has asked Xsolis whether it was targeted in an extortion attempt and, if so, whether a ransom has been paid. The company’s disclosure indicates that it’s “not aware of any actual or attempted misuse of information because of this incident”.

It’s not uncommon for healthcare-related data breaches to affect millions of people. One recent example is the incident involving the dental benefits administrator DentaQuest, in which hackers stole information from 2.6 million accounts. 

Related: Millions Impacted Across Several US Healthcare Data Breaches

Related: 266,000 Affected by Data Breach at Radiology Associates of Richmond

Related: Oncology Institute Discloses Data Breach

Related Content

Artificial Intelligence

A threat actor is using three AI harnesses for vulnerability research, exploitation, and attack orchestration.

Data Breaches

Hackers impersonated the company’s personnel and contacted its employees to gain access to Astrana Health’s servers.

Data Breaches

The cybercrime group is unhappy with its description in an FBI report and threatens to leak stolen information. 

Data Breaches

The attackers used a compromised BigCommerce application key held by Ribon to access customer data.

Data Breaches

The cybersecurity firm believes the data breach was the result of the May 2026 TanStack supply chain attack.

Data Breaches

Gyazo maker Helpfeel said the attacker exploited a vulnerability in its image upload server to gain unauthorized access.

Data Breaches

Revolut allegedly fed customer information to hackers impersonating an Italian government agency for five months.

Artificial Intelligence

Spanish regulators say an AI agent chained together a successful login, vulnerability discovery, and access to personal data in a potential milestone for autonomous...

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version