US healthcare technology firm Xsolis confirms it suffered a data breach that affects about 1.4 million individuals, according to multiple outlets. The company says it discovers unauthorized activity on January 22, 2026, linked to a targeted phishing attack that occurred on January 20, 2026. Xsolis states the phishing incident led to unauthorized access to its network and to information it received from client organizations.

Reporting across the sources says the impacted data includes sensitive personal and protected health information. TechRadar and other outlets specifically mention Social Security numbers and health insurance information among the types of data involved. SecurityWeek and Bleeping Computer describe the access as involving personal and protected health information provided to Xsolis by its customers.

Xsolis informs affected customers to take precautions, and it says it acts promptly to contain the incident. The company’s offerings include AI-powered software used by hospitals, health systems, and health plans, and it serves more than 600 hospitals and health insurers, as reflected in the reporting.