A data breach involving healthcare AI company Xsolis has ensnared at least eight health systems and 1.4 million patients.
Xsolis, which provides utilization management and care coordination technology for health systems, reported the targeted phishing attack June 5, noting that on Jan. 20 an unauthorized person accessed portions of the company’s IT environment and acquired a “limited number” of files. The company told HHS on June 5 that 1.4 million individuals were affected by the breach, a number the agency posted June 22.
Xsolis said it is not aware of any misuse of data and is notifying affected patients. A spokesperson told Becker’s the company isn’t commenting beyond its June 5 statement on the matter. Legal action over the breach has been filed in at least one case.
Here are the health systems reportedly affected by the data breach:
— Mayo Clinic (Rochester, Minn.)
— UW Medicine (Seattle)
— Legacy Health (Portland, Ore.)
— VHC Health (Arlington, Va.)
— Rochester (N.Y.) Regional Health
— Carle Health (Urbana, Ill.)
— Augusta Health (Fishersville, Va.)
— Hendrick Health (Abilene, Texas)
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.