Xsolis Data Breach: 1.4 Million Patients, a Letter From a Company You Never Used
Questions about this case?
Free · answers in seconds · general information, not legal advice
You almost certainly never signed up with Xsolis. It is a Franklin, Tennessee company whose AI software helps hospitals and insurers make medical-necessity decisions — so your records reached it through your hospital. A phishing attack on January 20, 2026 let an outsider take files covering 1,396,519 people. The letters mailed through Kroll since June 5, 2026 are genuine. The twelve suits filed in Nashville federal court are now one case. There is no settlement and no claim form.
Editorially Reviewed — Content reviewed for accuracy using published legal research, government data, and verified court records. See our methodology
Reviewed by Leonard Goldberg, Editor · Last updated
What Happened, and What the Lawsuits Say
Xsolis sells case and utilization management services to healthcare organizations. To do that, hospitals share parts of patient records with it — dates of care, diagnoses, insurance details. According to Xsolis, a targeted phishing attack on January 20, 2026 gave an outsider access to a limited part of its systems. Xsolis spotted the activity on January 22, 2026, cut it off, and its investigation found that the intruder had acquired files. The company says it is not aware of any misuse. Mayo Clinic received Xsolis's analysis of affected patients on April 23, 2026 — the same date VHC Health gives for when it was told — and letters went out from June 5, 2026.
The consolidated complaint pleads gross negligence/negligence per se, breach of third-party beneficiary contract, invasion of privacy and unjust enrichment. It accuses Xsolis of leaving the data unencrypted, of weak phishing defenses, and of learning of the breach around January 22 but notifying only on June 5 — pointing to Tennessee's 45-day notice rule. These are allegations; no court has ruled on them.
Case Details
On July 15, 2026, U.S. District Judge Eli J. Richardson of the Middle District of Tennessee consolidated the federal Xsolis suits under the first-filed case, Martinez v. XSolis, Inc., No. 3:26-cv-00791 (filed June 10, 2026), with the new caption In re Xsolis, Inc. Data Breach Litigation, and granted the request to appoint interim co-lead counsel. CourtListener lists twelve Xsolis suits filed in that court between June 10 and June 30, 2026. Two also named a hospital: Mayo Clinic in Mitchell v. Xsolis, Inc., No. 3:26-cv-00830, and Legacy Health in Shorey v. Xsolis, Inc., No. 3:26-cv-00834. The consolidated complaint, against Xsolis alone, was filed on September 14, 2026. Magistrate Judge Jeffery S. Frensley has set the initial case-management conference for December 14, 2026.
Two related suits are outside Nashville. McHenry v. Hendrick Medical Center was filed June 17, 2026 in Taylor County, Texas, against Hendrick and Xsolis; Xsolis moved it to federal court (N.D. Tex., No. 1:26-cv-00361) and asked to transfer it, the plaintiff asked to send it back to state court, and deadlines are on hold until that is decided. Perkins v. CommonSpirit Health, No. 1:26-cv-09254 (N.D. Ill., filed August 4, 2026), sues only the hospital system.
Status: One Consolidated Case, No Settlement
Follow this case
There's no claim deadline yet. We'll email you if a settlement opens a claim period.
Who Is in the Proposed Class
The consolidated complaint proposes one class: all individuals in the United States whose information was compromised in the Xsolis data breach, including everyone who received a notice letter — 1,396,519 people by Xsolis's report to HHS. You do not sign up anywhere; if a class is certified or a settlement is reached, notice goes to class members directly.
Your letter is the test. In its filing with Washington's Attorney General, Xsolis listed patients of Alexian Brothers Health System, Banner Health, Hendrick Health, Infirmary Health, Legacy Health, Mayo Clinic, Rochester Regional Health, UW Medicine and Virginia Hospital Center (VHC Health). The lawsuits also describe patients of CommonSpirit Health, HonorHealth and Penn Medicine. Being treated at one of them is not proof either way. Old records count: Rochester Regional Health says about 18,600 of its patients were affected even though its relationship with Xsolis ended in 2021. Keep the letter and the envelope.
What Is Available Now — and What Isn't
Xsolis Breach Timeline
- 1
January 20, 2026 — The Phishing Attack
A targeted phishing attack gives an outsider access to a limited part of the Xsolis environment, according to the company.
- 2
January 22, 2026 — Xsolis Cuts Off Access
Xsolis detects the activity, contains it and ends the access. Its investigation later finds that the intruder acquired files.
- 3
April 23, 2026 — Hospitals Are Told
Xsolis hands its analysis of affected patients to Mayo Clinic; VHC Health says it was notified the same day.
- 4
June 5, 2026 — Letters and Federal Report
Letters go out through Kroll, Xsolis issues a press release, and it reports 1,396,519 affected people to HHS.
- 5
July 15, 2026 — Twelve Suits Become One Case
After twelve suits were filed in Nashville between June 10 and June 30, Judge Eli J. Richardson consolidates them as In re Xsolis, Inc. Data Breach Litigation.
- 6
September 14, 2026 — Consolidated Complaint
The plaintiffs file one complaint against Xsolis. As of September 30, 2026 there is no settlement; a case-management conference is set for December 14, 2026.
Three Things to Watch For
The breach itself began with a phishing email, and a letter from a company nobody has heard of is easy to imitate:
“Claim your Xsolis settlement” pages
There is no Xsolis settlement and no claims site. A page, text or email asking for your Social Security number or bank details to “file your Xsolis claim” is collecting data, not filing anything.
Calls and emails posing as your hospital or Kroll
Anyone who knows your hospital used Xsolis can sound informed. Enroll in the free monitoring only by typing Enroll.krollmonitoring.com/redeem yourself and entering the code from your letter. For questions, use the number Xsolis published: (844) 403-4585. Treat unexpected calls or links about the breach as suspect.
“Pay to join the Xsolis class action”
You do not buy your way into a class action. Under Rule 23 a certified class includes you unless you opt out. Hiring a particular law firm is a separate, real decision — read any retainer before you sign it, rather than treating it as registration.
Xsolis Data Breach — Questions People Actually Ask
Who is Xsolis, and why does it have my medical information?
Xsolis, Inc. is a Franklin, Tennessee company that provides AI-based case and utilization management services — software that helps hospitals, health systems and insurers make medical-necessity decisions about hospital care. You would not have dealt with it directly: your hospital shared parts of your records with it. That is why the letter comes from a name you do not recognize.
Is the Xsolis data breach letter real or a scam?
The letters are real. Xsolis reported the breach to HHS and issued a press release on June 5, 2026, and filed notices with state attorneys general, including California and Washington, on June 19. Genuine letters come from Kroll (“Return to Kroll, P.O. Box 980108, West Sacramento, CA”), list (844) 403-4585 and point to Enroll.krollmonitoring.com/redeem. Some Rochester Regional Health patients threw theirs away because it named a nonexistent “Rochester Regional Medical Center” — the hospital confirmed the letters are legitimate. More on checking Kroll mail: Return to Kroll letters explained.
Which hospitals are affected?
Xsolis's Washington filing lists Alexian Brothers Health System, Banner Health, Hendrick Health, Infirmary Health, Legacy Health, Mayo Clinic, Rochester Regional Health, UW Medicine and Virginia Hospital Center. Lawsuits add patients of CommonSpirit Health, HonorHealth and Penn Medicine. Some letters name the hospital; others say only “your healthcare provider uses a vendor, Xsolis.”
What data was exposed in the Xsolis data breach?
Across all letters: names, addresses, dates of birth, health insurance information, Social Security numbers and medical treatment information. Not everyone lost all of it. The Mayo Clinic letters list date of birth, diagnosis information, medical record number, treatment dates, treatment location and patient ID — no Social Security number — while VHC Health letters include Social Security numbers. Your own letter lists your fields.
Is there an Xsolis class action settlement?
There is an Xsolis lawsuit, but no settlement. The twelve suits filed in Nashville were consolidated on July 15, 2026 as In re Xsolis, Inc. Data Breach Litigation, No. 3:26-cv-00791, in the Middle District of Tennessee. As of September 30, 2026 there is no settlement, fund, administrator or claim form.
Do I need to join the Xsolis data breach lawsuit?
No. The consolidated complaint proposes a class of everyone whose information was compromised, including everyone who got a notice letter. Under Rule 23 you are included in a certified class unless you opt out. There is nothing to register for now.
How do I get the free Kroll monitoring, and is there a deadline?
Go to Enroll.krollmonitoring.com/redeem and enter the activation code and verification ID from your letter; the service runs 12 months. Each letter carries its own enroll-by date, which is not in the public sample letters — check yours now. If it has passed or the letter is lost, call (844) 403-4585, weekdays 8:00 a.m. to 5:30 p.m. Central. Letters about children are addressed to a parent or guardian.
What is worth doing right now?
Enroll in the Kroll monitoring before your deadline. Freeze your credit at Equifax, Experian and TransUnion — free under federal law and reversible. Read your insurer's explanation-of-benefits statements for care you never received. Keep the letter and envelope: they show you are part of the proposed class.
Separate from this case: were you injured in the last 2 years?
Class-action payouts are fixed amounts through an administrator. A personal injury claim is a different case — and often worth far more. Free estimate, no obligation.
Related Consumer Brand Lawsuits
Return to Kroll Letters
Why Kroll mails breach notices, and how to verify one
TriZetto / Cognizant Data Breach
Another vendor breach that reached patients through their doctors
Aesto Health Data Breach
A vendor breach across dozens of providers — is yours listed?
Data Breach Settlement Calculator
What comparable data breach settlements have actually paid