A phishing email sent to a single employee of Xsolis, a Tennessee-based company that builds AI-powered utilization-management software for hospitals and health insurers, gave attackers roughly a two-day window inside its network starting January 20, 2026. The intruders exfiltrated files containing names, Social Security numbers, dates of birth, health insurance details, and medical treatment records for 1,396,519 individuals across seven major hospital systems, including clients of Humana and Mayo Clinic Health System. Xsolis disclosed the breach in early June 2026 and said it found no evidence of actual misuse of the stolen data.