The Tennessee-based utilization management company says a targeted phishing attack exposed Social Security numbers and medical records, with no evidence so far that the data has been misused.

Xsolis, a Tennessee-based company that provides artificial intelligence-powered case and utilization management solutions and operates as a business associate to HIPAA-covered entities, has disclosed a data breach affecting 1,396,519 individuals. The breach stemmed from a targeted phishing attack that gave an unauthorized third party access to a limited portion of the company’s environment from January 20 to January 22, 2026, according to a notice posted on the Kroll website.
According to a data breach notification filed with the California Attorney General, Xsolis identified unauthorized activity within its environment on January 22, 2026. The company has stated that the incident has been contained, that unauthorized access has been terminated, and that no evidence of unauthorized access has been found since that date. Xsolis has also stated that it has found no evidence to suggest the exposed data has been misused, and the company’s disclosure indicates it is not aware of any actual or attempted misuse of information resulting from the incident.
An investigation into the nature and scope of the unauthorized activity confirmed that patient data had been exposed and may have been copied. Xsolis engaged digital specialists to review the affected data, a process the company says has now been completed. The exposed information included names, dates of birth, addresses, Social Security numbers, health insurance information, and medical treatment information.
Xsolis is notifying affected individuals and has arranged 12 months of complimentary credit monitoring and identity theft protection services through Kroll.
The breach has been reported to the Department of Health and Human Services’ Office for Civil Rights, which added the incident to its data breach tracker this week, listing the number of affected individuals at 1,396,519. A complete list of affected Xsolis clients has not been made public, though VHC Health, a healthcare provider serving Northern Virginia and the Washington, D.C., metropolitan area, and Rochester Regional Health, based in New York, have each confirmed they were affected.
No ransomware group has claimed responsibility for the attack. Xsolis has implemented additional security measures since the breach, including increased system monitoring, password resets for key users, deployment of new protective technologies, accelerated security awareness training for employees, and strengthened credential management processes.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543