Skip to content
NetarxImpact Database
Spear Phishing (Email)No AI reportedConfirmed

Phishing attack on healthcare AI firm Xsolis exposes 1.4 million patients

Xsolis · Healthcare · United States · January 20, 2026

People or records affected
1,396,519
1.4M as reported

What happened

Nashville-based healthcare AI company Xsolis, whose utilisation-management platform is used by payers and health systems, suffered a targeted phishing attack on 20 January 2026 and detected the unauthorised activity two days later. Files containing names, addresses, dates of birth, Social Security numbers, health insurance details and treatment information were taken. 1,396,519 individuals were reported affected to HHS. No group claimed responsibility.

How the deception worked

Xsolis described the entry point as a targeted phishing attack against its own staff rather than an exploited vulnerability. The attacker reached an employee mailbox or account and, over roughly a two-day window before detection on 22 January, accessed and copied files holding protected health information belonging to patients of Xsolis's health system and payer customers. The company has not published the pretext used, the sender identity spoofed, or whether MFA was bypassed.

The control that would have caught it· our reading, not a claim from the sources

Phishing-resistant MFA on email and any admin console, plus data-loss monitoring on bulk file access to PHI repositories, is what converts a successful lure into a contained account compromise.

Sources (2)

  1. Phishing attack on healthcare firm Xsolis impacts 1.4 million people
    Help Net Security·helpnetsecurity.comOpen ↗
  2. Xsolis Data Breach Affects 1.4M Individuals
    HIPAA Journal·hipaajournal.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.