ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Xsolis data breach exposes patient and health plan member information following phishing attack

Xsolis Inc., a Nashville-based company that provides artificial intelligence-based case and utilization management services to hospitals and health plans, has disclosed a data breach stemming from a phishing attack that compromised a portion of its technology environment in January 2026.


The company detected unauthorized activity on its network on Jan. 22, 2026, two days after a targeted phishing attack occurred on Jan. 20. An investigation determined that an unauthorized actor gained access to a segment of the Xsolis environment and obtained files containing personal and medical information that healthcare organization clients had shared with the company.


The types of information exposed included names, addresses, dates of birth, health insurance information, Social Security numbers, and medical treatment information. The specific data involved varies from person to person.


Because Xsolis operates as a technology vendor to hospitals and health plans rather than as a direct provider of patient care, many individuals whose information was exposed may have no prior knowledge of the company. Their data was shared with Xsolis by the healthcare organizations it serves, meaning patients and health plan members could be among those affected without having any direct relationship with the company.


Xsolis’s Dragonfly platform is used by more than 600 hospitals and organizations, including Advent Health, Beacon Health System, Carle Health, Honor Health, Mayo Clinic, and MLK Community Healthcare.


The total number of individuals affected has not been publicly disclosed. Xsolis posted a notice about the incident on a dedicated website and said it will mail notification letters to potentially affected individuals.


The company is offering free credit monitoring and identity protection services to eligible affected individuals. Those seeking to enroll or with questions about the incident may contact a dedicated toll-free call center at 844-405-4638, available Monday through Friday from 8 a.m. to 5:30 p.m. Central Time, excluding major U.S. holidays.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543