Xsolis, a third-party business associate for multiple hospital systems, experienced a data breach that was contained between January 20 and 22, 2026. This breach resulted from a targeted phishing email that compromised Xsolis's network. The incident was publicly reported around June 23, 2026.
The confirmed data types exposed in this breach include full names, dates of birth, Social Security numbers (SSN), health insurance information, and medical treatment information. Approximately 1.4 million individuals were affected, including patients from VHC Health in Virginia and Rochester Regional Health in New York, with other states potentially involved. It remains unclear if any financial data beyond health insurance information was compromised. Xsolis is offering 12 months of complimentary identity monitoring to affected individuals.
More details about the full scope and impact of this breach may emerge over time, and notifications to affected individuals may still be in progress.