TENNESSEE — Xsolis, a healthcare technology company based in Tennessee, detected unauthorized activity on its network on January 22, 2026. The company stated: "On January 22, 2026, Xsolis became aware of unauthorized activity impacting a limited portion of the Xsolis environment resulting from a targeted phishing attack on January 20, 2026." The incident compromised the personal and medical data of 1,396,519 individuals, according to data submitted to the U.S. Department of Health and Human Services.

Following the detection, Xsolis stated: "We immediately contained the activity and launched an investigation with the assistance of external cybersecurity experts." The investigation found that attackers accessed files containing customer information. The accessed files contained names, addresses, dates of birth, health insurance information, Social Security numbers, and medical treatment information.

In response to the incident, Xsolis reported the matter to law enforcement. The company reset passwords for all users and key accounts and increased its system monitoring. Xsolis also completed the rollout of updated security measures, strengthened mechanisms for managing credentials, and accelerated its employee security training program.

Xsolis is notifying potentially affected individuals through postal mail and will send notifications to the parents or legal guardians of affected customers who are children. These notifications include instructions on how to enroll in a 12-month identity monitoring and identity theft restoration service provided by Kroll. Xsolis stated it is not aware of any actual or attempted misuse of information because of this incident. No known ransomware group has taken credit for the attack.

Xsolis develops AI-powered software used by more than 600 hospitals and health insurers. Its flagship platform is named Dragonfly.