Xsolis
ent_bfa5447a9eb85b6c8b87b4b7
Disclosures
12
State AG · HHS OCR · 8 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
2,523,302
nationwide · State AG TX
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Xsolis
- Normalized
- xsolis— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- xsolis.com
Disclosure history (12)newest first
- New Hampshire State AGas victim2026-07-28
Xsolis, Inc. filed a supplemental notice with the New Hampshire Attorney General on July 28, 2026, updating a prior June 19, 2026, breach notification. The company reported that approximately 220 New Hampshire residents were affected. Final notification letters were mailed on June 30, 2026. The specific nature of the unauthorized access was not detailed in this submission.
- Texas State AGas victim2026-07-23
Xsolis, Inc. based in Franklin, Tennessee, a business – retail or merchant entity reported a data breach to the Texas Attorney General. The breach was discovered on 2026-01-22 and reported on 2026-07-23. 139,424 Texas residents were affected. 2,523,302 individuals affected in total. Types of information involved: Name of individual;Address;Social Security Number Information;Medical Information;Health Insurance Information;Date of Birth. Consumers were notified via Notice by publication in print media;Posted at company website or special website;U.S. Mail.
- California State AGas victim2026-07-21
Xsolis, Inc. experienced a targeted phishing attack on January 22, 2026, resulting in unauthorized access to a limited portion of its environment. The incident potentially exposed protected health information (PHI) and personal data of patients, including minors, served by healthcare provider clients. Xsolis contained the incident, engaged forensic experts, notified law enforcement, and implemented security enhancements including password resets and increased monitoring. Identity monitoring services were offered to affected individuals.
- Massachusetts State AGas victim2026-06-30
Xsolis, Inc. notified Massachusetts residents of a targeted phishing attack discovered on January 22, 2026. The incident impacted a limited portion of the environment, potentially exposing protected health information and basic identity data of healthcare patients. Xsolis contained the breach, engaged forensic experts, notified law enforcement, and offered 18 months of identity monitoring via Kroll.
- New Hampshire State AGas victim2026-06-25
Xsolis, Inc. notified the New Hampshire Attorney General of a data security incident affecting approximately 47 NH residents. The breach involved a social engineering attack (impersonating IT support) leading to credential compromise and data exfiltration between January 20-22, 2026. Affected data included Social Security numbers. Xsolis contained the incident, engaged forensic experts, notified the FBI, and offered credit monitoring services.
- Texas State AGas victim2026-06-22
Xsolis, Inc. based in Franklin, Tennessee, a business – retail or merchant entity reported a data breach to the Texas Attorney General. The breach was discovered on 2026-01-22 and reported on 2026-06-22. 26,700 Texas residents were affected. 1,396,519 individuals affected in total. Types of information involved: Name of individual;Address;Social Security Number Information;Medical Information;Health Insurance Information;Date of Birth. Consumers were notified via Notice by publication in print media;Posted at company website or special website;U.S. Mail.
- California State AGas victim2026-06-19
Xsolis, Inc. experienced a targeted phishing attack on January 22, 2026, resulting in unauthorized access to a limited portion of its environment. The incident potentially exposed protected health information (PHI) and personal data of patients, including minors, served by Xsolis's healthcare provider clients. Xsolis contained the incident, engaged forensic experts, notified law enforcement, and implemented remediation measures including password resets and enhanced monitoring. Identity monitoring services were offered to affected individuals.
- Washington State AGas victim2026-06-19
Xsolis, Inc. reported a targeted phishing attack on January 22, 2026, affecting healthcare provider data. The incident exposed PHI and PII of 24,711 Washington residents. Xsolis contained the breach, engaged forensic experts, notified law enforcement, and offered 12 months of identity monitoring via Kroll.
- TENNESSEEHHS OCRas victim2026-06-05
Xsolis, Inc. reported to HHS on 2026-06-05 a Hacking/IT Incident affecting 1396519 individuals. Breached information located on Network Server. Business Associate present: Yes.
- Nebraska State AGas victim2026-06-05
Xsolis, Inc. disclosed a targeted phishing attack discovered on January 22, 2026, impacting a limited portion of its case and utilization management environment. The incident exposed protected health information (PHI) and personal data of patients, including minors. Xsolis contained the breach, engaged forensic experts, notified law enforcement, and offered 12 months of identity monitoring via Kroll to affected individuals.
- Nebraska State AGas victim2026-06-05
Xsolis, Inc. disclosed a targeted phishing attack discovered on January 22, 2026, affecting a limited portion of its case and utilization management environment. The incident exposed protected health information (PHI) and personal identifiers of patients, including minors and estate representatives. Xsolis contained the breach, engaged forensic experts, notified law enforcement, and offered 12 months of identity monitoring via Kroll. No evidence of data misuse was found.
- Indiana State AGas victim2026-06-05
Xsolis Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2026-01-20 and was reported on 2026-06-05. 154 Indiana residents were affected. 1,396,519 individuals affected in total.