Overview
- Xsolis says a targeted phishing attack on January 20 led to unauthorized access that was detected on January 22 and that attackers acquired files from a limited portion of its environment.
- Files taken include names, addresses, dates of birth, Social Security numbers, health insurance details and medical treatment information for about 1,396,519 people.
- The company contained the incident, hired external cybersecurity investigators, reset credentials, reported the matter to law enforcement and set up a toll‑free call center for questions.
- Xsolis is notifying affected people by mail and offering free credit monitoring and identity‑protection services while client systems such as Mayo Clinic, UW Medicine (about 23,600 patients) and VHC Health have posted or linked to notices.
- HHS has added the incident to its breach tracker and, although there are no public signs of ransom demands or misuse so far, experts warn the exposed data raises the risk of follow‑on phishing and identity theft so people should monitor accounts and consider fraud alerts or credit freezes.