Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Xsolis

Xsolis Vendor Cyber Rating & Cyber Score

xsolis.com

Xsolis is an AI-driven technology company with a human-centered approach, fostering collaboration between healthcare providers and payers through real-time transparency, objective data for increased accuracy and alignment of medical necessity decisions, and more efficient outcomes. Dragonfly®, its AI-driven proprietary platform, is the first and only solution to use real-time predictive analytics to continuously assign an objective medical necessity score and assess the anticipated level of care for every patient, enabling more efficiency across the healthcare system. Xsolis is headquartered in Franklin, Tennessee. Our Values: - Team First - Client Passionate - Always Curious - Deliver Excellence   Xsolis has been ranked on the


Xsolis A.I CyberSecurity Scoring

Xsolis
Company Information
Website:https://www.xsolis.com
Employees number:243
Number of followers:7,739
NAICS:62
Industry Type:Hospitals and Health Care
Homepage:xsolis.com
Xsolis Risk Score (AI oriented)
Between 0 and 549
logo
XsolisHospitals and Health Care
Updated:
18/06/2026
541/1000
Critical
C
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Xsolis Global Score (TPRM)
xxxx
logo
XsolisHospitals and Health Care
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Xsolis
XsolisCritical
Current Score
541C (CRITICAL)
01000
4 incidents
-64 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
540Before Incident
MAY 2026
539Before Incident
APRIL 2026
534Before Incident
MARCH 2026
530Before Incident
FEBRUARY 2026
526Before Incident
JANUARY 2026
578Before Incident
Breach
22 Jan 2026Xsolis
Xsolis, Inc. and Hendrick Health: Potts Law Firm Takes Legal Action Following Hendrick Health Data Breach and Delayed Patient Notification

Hendrick Health Data Breach and Delayed Notification Lawsuit

520After Incident
CRITICAL-58
HENXSO1781814405
Hendrick Health Faces Class Action Lawsuit Over Delayed Data Breach Notification On June 18, 2026, Potts Law Firm filed a class action lawsuit in Taylor County, Texas, against Hendrick Health and its healthcare technology vendor, Xsolis, Inc., on behalf of patient Ada Louise McHenry and others affected by a January 2026 data breach. The lawsuit alleges that a phishing attack on Xsolis a third-party case management provider for Hendrick Health exposed sensitive patient data, including Social Security numbers, medical records, treatment details, and financial information. The breach, discovered on January 22, 2026, went unreported to affected patients until June 2026, exceeding the 60-day notification window required under federal health data protection laws. The lawsuit claims Hendrick Health and Xsolis failed to implement adequate cybersecurity measures and delayed notifying victims, increasing their risk of identity theft, fraud, and medical privacy violations. Plaintiff McHenry, a longtime Hendrick Health patient, alleges her personal and medical data was compromised. The proposed class includes all individuals whose information was exposed in the breach. The lawsuit seeks damages and injunctive relief for alleged negligence in safeguarding patient data and failing to provide timely breach notifications. The case, Ada Louise McHenry v. Hendrick Medical Center and Xsolis, Inc. (Cause No. 52545-A), is pending in Taylor County District Court.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Data Compromised: Social Security numbers, medical records, treatment details, financial informationBrand Reputation Impact: YesLegal Liabilities: Class action lawsuit filedIdentity Theft Risk: YesPayment Information Risk: Yes
DATA BREACH
Social Security numbersMedical recordsTreatment detailsFinancial informationSensitivity Of Data: HighPersonally Identifiable Information: Yes
JANUARY 2026
636Before Incident
Breach
20 Jan 2026Xsolis
Xsolis, Mayo Clinic, Honor Health and Advent Health: XsolisData Breach

Xsolis Healthcare AI Platform Hit by Phishing Attack, Exposing Sensitive Patient Data

578After Incident
CRITICAL-58
XSOHONADVMAY1780958028
Xsolis Healthcare AI Platform Hit by Phishing Attack, Exposing Sensitive Patient Data On January 22, 2026, Xsolis a provider of AI-driven case management services for healthcare organizations detected unauthorized activity on its network stemming from a phishing attack that occurred two days prior. The breach compromised files containing highly sensitive patient information, including names, addresses, dates of birth, health insurance details, Social Security numbers, and medical treatment records. The exposed data varied by individual. Xsolis’s Dragonfly platform is widely used by over 600 hospitals and healthcare systems, including major institutions like Advent Health, Mayo Clinic, and Honor Health. The company has begun notifying affected individuals via mail. The incident highlights the growing risk of phishing attacks targeting healthcare infrastructure, where AI-driven platforms manage vast amounts of protected health information. Legal investigations are underway to assess potential class action lawsuits on behalf of impacted individuals, focusing on privacy violations, financial losses, and other damages. No further details on the scope of affected patients or the attacker’s identity have been disclosed.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Data Compromised: Sensitive patient information, including names, addresses, dates of birth, health insurance details, Social Security numbers, and medical treatment recordsSystems Affected: Xsolis Dragonfly AI platformLegal Liabilities: Potential class action lawsuits focusing on privacy violations and financial lossesIdentity Theft Risk: High
DATA BREACH
NamesAddressesDates of birthHealth insurance detailsSocial Security numbersMedical treatment recordsSensitivity Of Data: HighPersonally Identifiable Information: Yes
JANUARY 2026
710Before Incident
Breach
01 Jan 2026Xsolis
Xsolis, Inc. and Rochester Regional Health: Rochester Regional Health data breach: Letters sent to 18,600 patients after third-party vendor Xsolis hack

Rochester Regional Health Patients Notified of Data Breach After Phishing Attack

634After Incident
CRITICAL-76
ROCXSO1781563504
Rochester Regional Health Patients Notified of Data Breach After Phishing Attack Rochester Regional Health has confirmed a data breach affecting approximately 18,600 patients following unauthorized access to a third-party vendor’s system. The incident stemmed from a phishing attack in January, potentially exposing personal and protected health information. Patients received notification letters from Xsolis, Inc., a former vendor whose services ended in 2021. However, the letters contained errors including an incorrect name, "Rochester Regional Medical Center" leading many recipients to dismiss them as scams. Social media reactions reflected widespread skepticism, with some patients discarding the notices before verifying their legitimacy. This is not the first breach for Rochester Regional Health, which experienced similar incidents in 2020 and 2023. In December, the health system secured $15 million in state funding to bolster its cybersecurity defenses. Cybersecurity experts, including Rochester Institute of Technology professor Jonathan Weissman, warned that stolen healthcare data can be exploited for medical fraud, identity theft, and targeted scams. Children’s information is particularly vulnerable, as misuse may go undetected for years. Xsolis stated the unauthorized activity has been contained, with no evidence of data misuse to date. Affected patients were offered free 12-month identity monitoring. Rochester Regional Health emphasized its commitment to patient data security, noting it holds partners to strict privacy standards. The health system has requested corrections to the erroneous notifications.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Data Compromised: Personal and protected health informationSystems Affected: Third-party vendor (Xsolis, Inc.) systemCustomer Complaints: Widespread skepticism and dismissal of noticesBrand Reputation Impact: Negative social media reactions and skepticismIdentity Theft Risk: High (medical fraud, identity theft, targeted scams)
DATA BREACH
Type Of Data Compromised: Personal and protected health informationNumber Of Records Exposed: 18,600Sensitivity Of Data: High (health records, personally identifiable information)Personally Identifiable Information: Yes
DECEMBER 2025
710Before Incident
NOVEMBER 2025
709Before Incident
OCTOBER 2025
708Before Incident
SEPTEMBER 2025
707Before Incident
AUGUST 2025
706Before Incident
JULY 2025
705Before Incident
JANUARY 2025
762Before Incident
Breach
01 Jan 2025Xsolis
Xsolis and Rochester Regional Health: Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Rochester Regional Health Patients Receive Confusing Breach Notifications After Vendor Incident

698After Incident
CRITICAL-64
ROCXSO1781634267
Rochester Regional Health Patients Receive Confusing Breach Notifications After Vendor Incident Patients of Rochester Regional Health recently received mailed notifications regarding a data breach linked to a third-party vendor, Xsolis a case and utilization management services provider previously used by the healthcare system. The breach, discovered by the vendor, exposed sensitive patient information, though the hospital itself was not directly compromised. The notifications sparked confusion and skepticism among recipients due to several errors. The letters incorrectly identified the facility as "Rochester Regional Medical Center" instead of its proper name, Rochester Regional Health. Many recipients initially dismissed the notices as scams, particularly given the hospital’s history of prior breaches in 2020 and 2023. Rochester Regional Health later confirmed the legitimacy of the breach notifications, attributing the miscommunication to the vendor’s handling of the incident. The incident highlights ongoing challenges in third-party risk management and the importance of clear, accurate breach disclosures in maintaining patient trust.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Data Compromised: Sensitive patient informationCustomer Complaints: Confusion and skepticism among recipientsBrand Reputation Impact: Negative impact due to errors in notifications and prior breach historyIdentity Theft Risk: Potential risk due to exposure of sensitive patient information
DATA BREACH
Type Of Data Compromised: Sensitive patient informationSensitivity Of Data: HighPersonally Identifiable Information: Likely included

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Xsolis ?
?
What was Xsolis's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Xsolis's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Xsolis's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Xsolis's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Xsolis's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Xsolis's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Xsolis's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Xsolis's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Xsolis's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Xsolis's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Xsolis's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Xsolis's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Xsolis ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Xsolis's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?