← Blog

Xsolis Breach: 1.4M Patients Across Hospital Clients

Share on X

June 2026: Tennessee healthcare utilization vendor Xsolis, Inc. told federal regulators that 1,396,519 patients across its hospital and health-system clients were affected by a targeted phishing attack discovered January 22, 2026. The count makes Xsolis one of the largest healthcare vendor breaches disclosed in the first half of 2026—and it landed in patients' mailboxes through downstream clients like Rochester Regional Health and coverage naming Mayo Clinic among affected organizations.

What Xsolis does

Xsolis sells case and utilization management software—Dragonfly and related services—to more than 600 U.S. hospitals. Its files sit between clinicians and payers: authorization workflows, clinical documentation, and insurance metadata. That makes a vendor breach a multi-hospital event even when Xsolis itself is not a household name.

What the company confirmed

Xsolis detected unauthorized activity on its network on January 22, 2026, interrupted access, and launched forensics. It reported no known misuse at disclosure time and stood up xsolisdataincident.com with 12 months of Kroll identity monitoring.

On June 5, 2026 the company issued a press release and filed with HHS Office for Civil Rights at 1,396,519 individuals. California's attorney general posted an exemplar notification letter June 19, 2026. BleepingComputer summarized the regulatory filing and vendor context.

What data was exposed

Notification materials cite a mix that can include:

  • Names, addresses, and dates of birth
  • Health insurance information
  • Social Security numbers (for many individuals)
  • Medical treatment information

Exact fields vary by patient and client hospital. Rochester Regional Health told local press roughly 18,600 of its patients were affected; other clients are still notifying.

Who should act

If you received care at a hospital that uses Xsolis for utilization review—or got a Kroll/Xsolis letter—assume PHI and identity data may be in the wild even if Xsolis saw no fraud yet.

  1. Enroll in offered monitoring or freeze credit if SSNs were cited.
  2. Watch Explanation of Benefits for services you never received.
  3. Reject "hospital billing" calls that cite real procedure dates; call your provider on a published number.

Canonical record

Xsolis 2026 breach on BreachHistory.

Sources: Xsolis press release, BleepingComputer, California AG exemplar.