What Happened in the Xsolis Data Breach?
Xsolis, Inc. is a company that provides case and utilization management services to healthcare providers. Because of this role, the company handles sensitive patient information on behalf of the hospitals and clinics it works with. A recent security incident at Xsolis has raised concerns for patients whose data passed through its systems.
According to breach notification letters, Xsolis became aware of unauthorized activity on January 22, 2026. The activity resulted from a targeted phishing attack against the company. As soon as Xsolis discovered the intrusion, it moved to interrupt and contain the issue and cut off the unauthorized access.
In response, Xsolis brought in outside cybersecurity experts to investigate the scope of the incident. The company also notified law enforcement of the attack. Xsolis has stated that it found no evidence of unauthorized activity in its environment since January 22, 2026, and no evidence that the exposed information has been misused so far.
Xsolis worked with forensic consultants to determine exactly which categories of protected health information may have been affected. This step was necessary because the company needed to identify which specific patients and data elements were involved before sending notifications. As a result, notification letters went out identifying that certain personal information may have been accessed during the phishing incident.
Who was affected?
The individuals affected by this breach are patients of healthcare providers that rely on Xsolis for case and utilization management services. Because Xsolis works as a vendor across multiple healthcare organizations, the breach could reach patients connected to several different providers rather than just one facility.
Xsolis has not publicly disclosed the total number of individuals affected by this incident. However, since Xsolis serves as a utilization management vendor for hospital systems, the affected population likely includes patients whose medical cases were reviewed or managed through the company’s platform. The geographic scope also has not been specified, though healthcare vendors of this type often serve providers across many states.
What Information Was Potentially Exposed?
The exact data elements exposed vary by individual, since notification letters reference specific data fields unique to each recipient. However, based on the nature of the incident and the fact that Xsolis provides case management services, the exposed information is tied to protected health information.
- Full names
- Protected health information related to case or utilization management
- Other personal identifiers used in healthcare record-keeping
When protected health information becomes exposed, the risk goes beyond typical identity theft concerns. For example, stolen medical details can be used to commit medical identity theft, where a criminal uses someone else’s information to obtain treatment or prescriptions. This type of fraud can be difficult to detect because it may not show up on a standard credit report.
In addition, exposed health information can be combined with other stolen data to build a more complete profile for scammers. Because of this, affected individuals may face an increased risk of targeted phishing attempts that reference their actual medical history. This can make future scam attempts appear more credible and harder to recognize.
What is the company doing?
Once Xsolis discovered the unauthorized access, the company acted quickly to contain the threat and shut down the attacker’s access. Xsolis also engaged external cybersecurity experts to investigate the full scope of the incident and confirm what happened.
Since then, Xsolis has taken several additional steps to strengthen its security. These include resetting passwords across all user and key accounts, increasing monitoring of its systems, and deploying new protective technology. The company has also accelerated employee security training and improved how it manages credentials to reduce the risk of similar incidents in the future.
To help affected individuals, Xsolis is offering twelve months of complimentary identity monitoring through Kroll. This service includes credit monitoring, fraud consultation, and identity theft restoration support. Affected individuals must enroll by the deadline listed in their personal notification letter to receive these services at no charge.
What Should Affected Individuals Do?
Monitor Your Credit Reports Regularly
Anyone who received a notification letter from Xsolis should start checking their credit reports on a regular basis. Reviewing your reports helps you catch new accounts or inquiries that you did not authorize.
You can request a free copy of your credit report from each of the three major credit bureaus. Because fraud does not always appear immediately, it helps to space out these requests throughout the year so you have ongoing visibility into your credit file.
Take Advantage of Free Identity Monitoring
Since Xsolis is offering twelve months of complimentary identity monitoring through Kroll, affected individuals should strongly consider enrolling. This service can alert you quickly if your information is being misused elsewhere.
To enroll, follow the instructions and enrollment deadline included in your personalized notification letter. Signing up early ensures you don’t miss the coverage window, and it gives you an added layer of protection while the investigation continues.
Watch for Healthcare-Related Fraud
Because protected health information may have been involved, it’s important to review any medical bills, insurance statements, or explanation-of-benefits notices you receive. Unfamiliar charges or services could indicate that someone used your information fraudulently.
If you notice anything suspicious, contact your healthcare provider and insurance company right away. Reporting issues quickly can help limit the damage and correct your medical records before problems compound.
Stay Alert for Phishing Attempts
Since this breach began with a phishing attack, affected individuals should be extra cautious about unexpected emails, texts, or phone calls. Scammers sometimes use information from a breach to make their messages appear more legitimate.
Avoid clicking links or providing personal details in response to unsolicited messages. Instead, contact the organization directly using a verified phone number or website to confirm whether the request is genuine.
Consider a Fraud Alert or Credit Freeze
If you’re concerned about potential misuse of your personal information, placing a fraud alert or credit freeze on your credit file can add extra protection. A fraud alert requires creditors to verify your identity before opening new accounts in your name.
A credit freeze goes a step further by restricting access to your credit file entirely until you lift it. Both options are free to set up through the three major credit bureaus, and they can meaningfully reduce your risk of becoming a victim of identity theft.
More Information
Official data breach notification from Washington State Attorney General
Official data breach notification from California Attorney General
