HIPAA Pulse by Patient Protect logo

HIPAA Pulse by Patient Protect

Archives
Log in
June 24, 2026

HIPAA PULSE | JUNE 24

HIPAA Pulse — June 24, 2026
An AI vendor most patients never heard of just affected 1.4 million of them — including data from a hospital that stopped using it in 2021. The Security Rule's May window is still empty. ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌
Patient Protect
HIPAA Pulse

HIPAA PULSE

June 24, 2026  ·  Bi-Weekly Briefing

An AI Vendor's 1.4M, the Data That Outlived the Contract & the Rule Still in Limbo

An AI vendor most patients have never heard of affected 1.4 million people. One affected health system stopped using the vendor in 2021 — its patients' data was still in the vendor environment.

Xsolis, a Tennessee company that sells AI-driven utilization-management software to more than 600 hospitals, disclosed a breach affecting 1,396,519 individuals. The attack was a phishing email in January. The disclosure came in June. The window between them is where the story lives.

Last issue promised a Security Rule redline if a final rule landed. It still hasn't. The May target passed, OCR is working through thousands of comments, and there's no new timeline. So this issue does what the data supports: covers the biggest vendor breach of the window, the AI-vendor angle underneath it, and the retention problem that keeps turning one breach into many.

Stat of the Issue

2021

the year Rochester Regional Health ended its relationship with Xsolis. Roughly 18,600 of its patients were still in the Xsolis environment when the 2026 breach happened. Data that survives a vendor relationship without documented disposition is data that can still be stolen years later.

Risk Barometer  ·  What Moved Since June 10

Newly Observed

31

OCR + State AG entries, Patient Protect dashboard

One Vendor's Share

86%

of the window's affected total is Xsolis alone

Top Breach Type

Hacking /
IT Incident

25 of 31 newly observed entries (81%)

Largest After Xsolis

MN Epilepsy
80K

HHS OCR, June 23 — Minnesota

One vendor accounted for 1.4 million of the window's 1.6 million affected individuals. Strip out Xsolis and the other 30 entries affected roughly 218,000 people combined — the concentration is the story.

Open the live dashboard → Free · No account · Updated nightly

Breach of Note

Xsolis, Inc.

HHS OCR June 22  ·  1,396,519 affected  ·  Phishing  ·  Tennessee

Xsolis is an AI healthcare technology company in Franklin, Tennessee. Its Dragonfly platform uses predictive analytics to assess medical necessity and level of care, and it's used by more than 600 hospitals and health systems. Most patients in the breach have never heard the name — their data reached Xsolis through the hospitals and health plans that use it. On January 20, a targeted phishing attack reached the Xsolis environment. The company detected it on January 22, contained it, and began notifying affected individuals in June.

The exposed data is the serious kind: names, dates of birth, Social Security numbers, health insurance information, and medical treatment information. Mayo Clinic, VHC Health, and Rochester Regional Health have confirmed they were affected. The breach is one of the larger healthcare disclosures of 2026 so far — and it originated at a single vendor, not at the hospitals and health systems whose patient data flowed through it.

Two things make this a marker for where healthcare risk is heading. The vendor is an AI company, which means the data aggregation that makes its product work is also what makes its breach this large — predictive analytics need volume, and volume is exposure. And the disclosure carried a five-month gap between the January attack and the June notifications. Q1's concentration pattern, our radiology lead's slow-disclosure pattern, and now an AI vendor holding 1.4 million records: the same thesis at higher resolution each time.

Three questions for your practice: Do you know which AI and analytics vendors your EHR, billing, or utilization-management workflows feed data into? For each one, do you have a current BAA and a record of what data they hold? When a vendor relationship ends, do you have a documented process confirming they purge your patients' data? Run the free assessment →

Three Signals From the Past Two Weeks

Retention Is Becoming the Root-Cause Story

The Xsolis breach reached Rochester Regional Health patient data five years after the two companies stopped working together. That detail is the center of a growing argument in healthcare security: the most consequential breaches are driven less by who attacked and more by how much data the victim was holding, where, and for how long. A practice that keeps every record forever, in every system it ever used, has built a larger target with each passing year. The question any serious post-breach investigation can raise is whether the data needed to be there at all. Retention schedules — the unglamorous discipline of deleting what you no longer need — are quietly becoming a security control.

Extortion Groups Keep Naming Healthcare Targets

The same group tied to the DentaQuest publication we covered last issue, ShinyHunters, has now claimed to have stolen 8.8 terabytes of data from One Medical, the primary-care provider Amazon acquired in 2023. The claim is unverified and no sample data has been released, so treat the scope as alleged. The pattern is what matters: extortion crews are publicly naming healthcare targets and setting negotiation deadlines as a pressure tactic. For any practice connected to a named entity, the operational concern arrives before the facts are confirmed — patients see the headline and call you first.

The Security Rule Is Still in Limbo — and OCR Is Still Enforcing the Old One

No final Security Rule has published. The May target passed, OCR is working through thousands of comments, and a coalition of 100-plus provider groups continues to push for withdrawal. Meanwhile OCR keeps enforcing the rule already in force: this month it settled a ransomware investigation with an employer health plan for $450,000 and a corrective action plan, with the agency's findings centered on the absence of a compliant risk analysis. The proposal's direction — mandatory encryption and MFA, vulnerability scanning, the end of the required/addressable distinction — remains the clearest signal of where the baseline is heading. The slip is runway, not relief.

30-Minute System Check  ·  This Window's Edition

Each item responds to something in this issue's data. Items 1–3 are directly actionable this week.

1

List the AI and analytics vendors in your data flows. Utilization management, clinical decision support, ambient documentation, coding and billing optimization, patient-communication tools. Any vendor running analytics on your patients' data is aggregating it somewhere. For each, confirm a current BAA and a record of what categories of data they receive.

2

Pull the list of vendors you've stopped using. For every vendor relationship that ended in the last several years, do you have written confirmation they purged or returned your patients' data? The Xsolis breach reached a health system that left in 2021. An offboarding checklist with a data-disposition step is the control that prevents a dead vendor from breaching you.

3

Write down your data retention schedule. If you can't say how long you keep records in each system and when they get deleted, you're holding more data than you can defend. A documented retention schedule — and actually following it — shrinks your attack surface and supports the kind of risk analysis OCR expects: where ePHI exists, how it flows, and whether it is reasonably protected.

4

Re-confirm MFA on email. The Xsolis breach started with a phishing attack, the single most common entry point in healthcare. MFA on every email account is the highest-leverage control against it. If any staff inbox still opens with a password alone, close that gap this week.

5

Keep your Security Rule prep moving. No final rule yet, but the NPRM's direction stands: encryption at rest and in transit, MFA, vulnerability scanning at least every six months. Everything you implement now is enforce-ready under the current rule, where a missing risk analysis remains OCR's most-cited finding — the same gap behind this month's $450,000 settlement.

Map Your Vendor Exposure.

The free HIPAA Risk Assessment inventories your vendors, BAAs, and data flows alongside the rest of your compliance baseline. 30 minutes, no account, produces the kind of documented artifact OCR would expect to see.

Run the free assessment → Free · No account · 30 minutes

What This Points To

Four issues running, the same shape at higher resolution. Q1: four upstream incidents drove most of healthcare's affected patients. A radiology practice whose slow response left it exposed across two breaches. A dental administrator whose alleged exposure dwarfed every practice filing around it. And now an AI vendor holding 1.4 million records — 86% of this window's affected total — including data from a hospital that walked away five years ago. The exposure concentrates where data aggregates, and aggregation is accelerating: AI products need more data, held longer, in more places. The independent practice is rarely the breach origin. It's the name attached to the records.

The retention angle is the part worth sitting with. The Xsolis breach didn't just affect current patients — it reached people whose providers stopped using the vendor years ago. Every system your practice has ever touched, every vendor you've ever offboarded, every archive you never purged is still part of your attack surface until the data is actually gone. The Security Rule update was built to force this discipline. Whether it publishes or not, the breaches keep making its case: know where your data is, hold only what you need, and confirm it's gone when you're done with it.

 

Patient Protect

Your vendors are your attack surface. Track them like it.

Vendor inventory with offboarding and data-disposition tracking. BAA lifecycle alerts. Continuous risk analysis. Encryption posture monitoring. Audit-ready documentation across every domain the proposed rule names. $39/month, no contracts, 14-day free trial.

Start free trial → See pricing →

Worth Reading

  Xsolis Breach — Full Coverage →

The complete breakdown: the January phishing timeline, the confirmed affected health systems, and what 1.4 million exposed records mean for the 600-plus organizations that fed Xsolis their data.

  Why Threat-Actor Focus Misses the Real Problem →

An analysis arguing that healthcare fixates on identifying attackers while ignoring the conditions that make breaches catastrophic — excess data collection, centralization, and long retention. The frame behind this issue's retention signal.

  OCR Settles Ransomware Case for $450K →

OCR's settlement with an employer-sponsored health plan over a ransomware incident, with a corrective action plan attached. A live reminder that the current Security Rule is being enforced while the update sits in limbo.

Closing Note

The Security Rule watch continues into July with no new signal from OCR. If a final rule publishes, the redline analysis lands in the next available issue. Until then, the through-line of the last four issues holds: the breaches that matter most start upstream, at the vendors and platforms aggregating data on a scale no single practice ever could — and increasingly, holding it longer than anyone remembered to ask.

Next Pulse drops July 8.

Editorial coverage at hipaapulse.com. Operational response at patient-protect.com/hipaa-pulse. This briefing comes from Patient Protect.

Patient Protect

Chicago, IL  ·  patient-protect.com  ·  HIPAA Pulse

Instagram LinkedIn X

Breach data reflects publicly reported incidents from federal, regulatory, and community sources. Xsolis figures reflect the HHS OCR breach portal and SecurityWeek reporting; affected health systems confirmed via their own public notices. One Medical figure reflects an unverified extortion-group claim and may be revised.

You're receiving HIPAA Pulse because you subscribed at patient-protect.com. Unsubscribe  ·  Privacy Policy

© 2026 Patient Protect LLC. All rights reserved.

Don't miss what's next. Subscribe to HIPAA Pulse by Patient Protect:
← Newer HIPAA Pulse | July 08 | Q2 Recap Older → HIPAA Pulse | June 10
Instagram
Twitter
LinkedIn
YouTube