DEFENCE / RADAR

Public snapshot

Xsolis·Healthcare·

Patient data was exposed.

The report cites HHS confirmation of 1,396,519 affected people after a phishing attack exposed identity and medical records. The exact technical root cause is not established in the attached record.

Report freshness and timeline

Incident occurred
First disclosed
Latest attached source
Radar data checked

Coverage windowDataset generated Aug 30, 2026, 12:03 UTC

Executive incident brief

Incident confirmation
Regulator confirmed
Mechanism
Entry path: Phishing Social Engineering
Consequence
Reported: Patient data was exposed.
Scope
The complete extent is not established by this record.

1)Incident fact sheet

Organization
Xsolis
Industry
Healthcare
Disclosed
Event date
Entry path
Phishing Social Engineering
Affected asset
Xsolis environment
Country
US
Data involved
Personal data · Health Data · Financial Data
Reported impact
Data exposure
Attached evidence
6 independent domains · 6 sources

2)Evidence-backed incident path

  1. 01

    Entry path

    Initial access involved phishing social engineering.

    ConfidenceSecondary
    Exact excerpt

    as a result of a targeted phishing attack

    hipaajournal.com · Jun 23
    E1
  2. 02

    Reached

    Xsolis environment

    ConfidenceSecondary
    Exact excerpt

    a limited portion of the Xsolis environment

    hipaajournal.com · Jun 23
    E2
  3. 03

    Observed

    Patient data was exposed.

    ConfidenceProbable
    Exact excerpt

    patient data had been exposed

    hipaajournal.com · Jun 23
    E3

3)Impact and scope ledger

Not publicly established

No qualifying public evidence in the attached record.

  • The exact technical root cause
  • The supplied sources do not include a primary HHS excerpt
  • That a Defence review would have prevented this incident

4)Relevance to your product

One durable credential can carry yesterday's access into today's product.

This pattern applies when…

  • Products that allow employees to access patient records.
  • Teams that test phishing resistance and account containment.

Diagnostic questions

  1. Can a credential retain access beyond its intended lifetime or role?
  2. Are sessions isolated across users, tenants and recovery paths?
  3. Can tokens be rotated or revoked without leaving a parallel route open?

This incident does not establish your product's risk.

5)Sector context — Healthcare

293 incident threads in the 365-day public record
  1. 1 incident threads
  2. 1 incident threads
  3. 0 incident threads
  4. 1 incident threads
  5. 24 incident threads
  6. 18 incident threads
  7. 32 incident threads
  8. 26 incident threads
  9. 27 incident threads
  10. 74 incident threads
  11. 61 incident threads
  12. 28 incident threads
Same incident family
78
Data breach / intrusion
Confirmed share
60%
177 confirmed · 116 reported
Display family
Data breach
Used for Radar's public chart taxonomy

Publicly disclosed incidents and reports from to . Historical discovery is partial and does not measure breach probability.

Explore Healthcare in Radar →

6)Defence control mapping

What Defence can test

Identity and session testing

  • Can a credential retain access beyond its intended lifetime or role?
  • Are sessions isolated across users, tenants and recovery paths?
  • Can tokens be rotated or revoked without leaving a parallel route open?

What cannot be concluded

  • This incident does not predict an individual product's risk.
  • A mapped control does not establish that a Defence review would have prevented the event.

7)Public evidence ledger

6 attached sources across 6 independent domains. No attached source is marked as an organization or regulator primary source.

  1. E1, E2, E3
    hipaajournal.comXsolis Data Breach Affects 1.4M IndividualsSpecialist reporting · Jun 23 · Cited
    Specialist reportingCited
    Exact excerpt
    health insurance information
  2. S2
    healthexec.comHealthcare AI vendor suffers data breach, exposing patient records to hackersOther public report · Jun 15 · Attached
    Other public reportAttached
  3. S3
    securityweek.comXsolis Data Breach Affects 1.4 Million Individuals - SecurityWeekEstablished press · Jun 23 · Attached
    Established pressAttached
    Exact excerpt
    Tennessee-based Xsolis
  4. S4
    medrisk.ioPhishing Attack at Xsolis Exposes Data of Nearly 1.4 Million Healthcare Patients – MedRiskOther public report · Jun 23 · Attached
    Other public reportAttached
  5. S5
    techtimes.comHealthcare Breach at AI Vendor Xsolis Exposes 1.4 Million Records Across Seven Major HospitalsOther public report · Jun 24 · Attached
    Other public reportAttached
  6. S6
    breached.companyXsolis Healthcare AI Vendor Breach Exposes 1.4 Million Patients After January Phishing Attack | Breached.CompanyOther public report · Jun 24 · Attached
    Other public reportAttached

Does this access boundary exist in your product?

A bounded review can test the authorized web/API path without assuming this incident predicts your risk.

Each report separates what public reporting establishes from what remains unknown. It does not turn another company's incident into a prediction of your risk. Dataset coverage: . View methodology →