2026 Carle Health — XSolis vendor phishing breach; 1,444 patients (Jan)
Data compromised
Per Carle Health and XSolis notices: patient names, dates of birth, doctor names, health insurance information, diagnoses, medical record numbers, treatment dates/locations, and in some cases Social Security numbers
Technical writeup
Verified healthcare vendor breach affecting Carle patients — disclosed April–June 2026. XSolis, Inc., a case and utilization management vendor used by Carle Health in Urbana, Illinois, notified Carle April 23, 2026 that unauthorized network activity occurred January 22, 2026 following a targeted phishing attack. XSolis contained the access and engaged forensic specialists; Carle stated its own medical records and electronic environment were not impacted. For affected patients, exposed data may include names, diagnoses, medical record numbers, insurance information, treatment details, and in some cases SSNs. The U.S. HHS OCR breach portal lists Carle Health with 1,444 individuals affected, submitted June 19, 2026, as a hacking/IT incident involving email with a business associate present.
Root cause
Vendor XSolis, Inc. experienced unauthorized network activity January 22, 2026 from a targeted phishing attack; notified Carle Health April 23, 2026