Xsolis Breach Hits 1.4M Patients Across 7 Health Systems
Healthcare AI company Xsolis, which sells utilization management and care coordination technology to health systems, has disclosed a data breach affecting roughly 1.4 million patients across seven health systems, according to Becker's Hospital Review.
Xsolis reported a targeted phishing attack on June 5. The company said an unauthorized person accessed portions of its IT environment on Jan. 20 and acquired a "limited number" of files. The gap between the January intrusion and the June disclosure points to the time it often takes vendors to scope what was taken and identify which downstream clients were affected.
The incident fits a broader pattern: hospitals increasingly rely on outside AI and software vendors that hold large volumes of patient data, turning each vendor into a single point of failure. When one is compromised, the blast radius spans every health system it serves. For provider organizations, the takeaway is sharper vendor risk management, tighter contractual breach-notification terms, and scrutiny of how partners secure access to protected health information.
Sources