Xsolis·Healthcare·
Patient data was exposed.
The report cites HHS confirmation of 1,396,519 affected people after a phishing attack exposed identity and medical records. The exact technical root cause is not established in the attached record.
Report freshness and timeline
- Incident occurred
- First disclosed
- Latest attached source
- Radar data checked
Coverage window — Dataset generated Aug 30, 2026, 12:03 UTC
Executive incident brief
- Incident confirmation
- Regulator confirmed
- Mechanism
- Entry path: Phishing Social Engineering
- Consequence
- Reported: Patient data was exposed.
- Scope
- The complete extent is not established by this record.
1)Incident fact sheet
- Organization
- Xsolis
- Industry
- Healthcare
- Disclosed
- Event date
- Entry path
- Phishing Social Engineering
- Affected asset
- Xsolis environment
- Country
- US
- Data involved
- Personal data · Health Data · Financial Data
- Reported impact
- Data exposure
- Attached evidence
- 6 independent domains · 6 sources
2)Evidence-backed incident path
- 01
Entry path
Initial access involved phishing social engineering.
ConfidenceSecondaryExact excerpt
E1“as a result of a targeted phishing attack”
hipaajournal.com · Jun 23 - 02
Reached
Xsolis environment
ConfidenceSecondaryExact excerpt
E2“a limited portion of the Xsolis environment”
hipaajournal.com · Jun 23 - 03
Observed
Patient data was exposed.
ConfidenceProbableExact excerpt
E3“patient data had been exposed”
hipaajournal.com · Jun 23
3)Impact and scope ledger
Established
Supported at the stated evidence level.
Reported
Present in public reporting; not independently established by Radar.
Not publicly established
No qualifying public evidence in the attached record.
- The exact technical root cause
- The supplied sources do not include a primary HHS excerpt
- That a Defence review would have prevented this incident
4)Relevance to your product
One durable credential can carry yesterday's access into today's product.
This pattern applies when…
- Products that allow employees to access patient records.
- Teams that test phishing resistance and account containment.
Diagnostic questions
- Can a credential retain access beyond its intended lifetime or role?
- Are sessions isolated across users, tenants and recovery paths?
- Can tokens be rotated or revoked without leaving a parallel route open?
This incident does not establish your product's risk.
5)Sector context — Healthcare
- 1 incident threads
- 1 incident threads
- 0 incident threads
- 1 incident threads
- 24 incident threads
- 18 incident threads
- 32 incident threads
- 26 incident threads
- 27 incident threads
- 74 incident threads
- 61 incident threads
- 28 incident threads
- Same incident family
- 78 Data breach / intrusion
- Confirmed share
- 60% 177 confirmed · 116 reported
- Display family
- Data breach Used for Radar's public chart taxonomy
Publicly disclosed incidents and reports from to . Historical discovery is partial and does not measure breach probability.
Explore Healthcare in Radar →6)Defence control mapping
What Defence can test
Identity and session testing
- Can a credential retain access beyond its intended lifetime or role?
- Are sessions isolated across users, tenants and recovery paths?
- Can tokens be rotated or revoked without leaving a parallel route open?
What cannot be concluded
- This incident does not predict an individual product's risk.
- A mapped control does not establish that a Defence review would have prevented the event.
7)Public evidence ledger
6 attached sources across 6 independent domains. No attached source is marked as an organization or regulator primary source.
- E1, E2, E3hipaajournal.comXsolis Data Breach Affects 1.4M IndividualsSpecialist reporting · Jun 23 · CitedSpecialist reportingCited
Exact excerpt
“health insurance information”
- S3securityweek.comXsolis Data Breach Affects 1.4 Million Individuals - SecurityWeekEstablished press · Jun 23 · AttachedEstablished pressAttached
Exact excerpt
“Tennessee-based Xsolis”
Does this access boundary exist in your product?
A bounded review can test the authorized web/API path without assuming this incident predicts your risk.