Xsolis Data Breach Notice (Washington Attorney General)
If you were named in this filing, here’s what the filing says was exposed, and what to do about it.
Xsolis notified Washington residents of a data breach in a filing reported to the Washington State Attorney General on June 19, 2026, and the notice lists name, social security number, full date of birth, health insurance policy or ID number, medical information and protected health information owned or licensed by a HIPAA covered entity among the information exposed. The filing puts the incident itself on January 20, 2026.
The breach notice from Xsolis has placed your name, Social Security number, full date of birth, health insurance policy number, and detailed medical information in the hands of unknown parties. These records belong to 26,203 people, and the filing makes clear that Protected Health Information owned or licensed by a HIPAA covered entity was also exposed.
Because this combination of identifiers and medical details cannot be replaced or cancelled, the consequences are permanent. A Social Security number paired with a date of birth is the exact information needed to open accounts, file fraudulent tax returns, or obtain medical services in someone else’s name. The medical and insurance information adds another layer: it can be used to file false claims, order prescription drugs, or create convincing deepfake identities for long-term fraud.
The 150-Day Gap Between Incident and Notification
The incident occurred on January 20, 2026. Xsolis filed the breach notice with the Washington Attorney General on June 19, 2026 — an interval of 150 days, or nearly five months. The record does not disclose when the organization discovered the incident, so it is impossible to know how long the exposed data may have been accessible before notification began.
What the Exposed Categories Actually Enable
A name, Social Security number, and date of birth together form the foundation of synthetic identity fraud and traditional identity theft. Once an attacker has those three pieces, they can apply for credit, government benefits, or new health insurance using your identity. The addition of your health insurance policy number and medical information makes the records far more valuable on the dark web. Criminals can use them to submit bogus medical claims, obtain controlled substances, or blackmail individuals by threatening to release sensitive treatment details.
The filing lists these categories for the incident as a whole. Your own notification letter will specify which exact pieces of information about you were involved. No passwords were exposed in this breach.
Why Medical Information Cannot Be Changed Like a Credit Card
Unlike a compromised credit card or password, your date of birth, Social Security number, and medical history stay with you for life. You cannot request a new one. This permanence turns a single breach into a decades-long risk. Fraudsters who obtain Protected Health Information can continue to exploit it years later when public attention has moved on. The record shows that Xsolis held data protected under HIPAA, which means the exposed medical details carry both financial and privacy consequences that standard credit monitoring alone cannot fully address.
How to Determine Whether This Notice Applies to You
Xsolis is required to notify affected individuals directly, usually by mail. If you have not received a letter, it is likely your records were not part of this incident. However, if you have moved since January 20, 2026, or changed addresses at any point after the incident date, contact Xsolis directly to confirm whether you were included. Absence of a letter is usually a positive sign, but only direct confirmation from the organization settles the question with certainty.
The Long-Term Identity Theft Risk Created by This Breach
With your Social Security number and date of birth now outside your control, the primary threat is not an immediate account takeover but the slow, quiet construction of fraud in your name. Tax refunds can be diverted, loans taken out, and medical bills run up that later damage your credit and your medical record. The health insurance policy number makes it easier for thieves to impersonate you at hospitals or clinics, potentially contaminating your actual health history with incorrect information.
Because this is healthcare-related data, the breach also creates risks around insurance fraud. Someone with your details could seek treatment or prescriptions that later appear on your Explanation of Benefits statements, triggering surprise bills or coverage disputes that take months to resolve.
What Remains Under Your Control
While you cannot change your Social Security number or date of birth, you can still limit how these stolen details are used. Placing a freeze on your credit files prevents new accounts from being opened without your explicit permission. Monitoring your Explanation of Benefits statements from every health insurer you use lets you catch fraudulent claims before they become major problems. Regular review of your tax transcripts from the IRS can reveal filings made in your name that you did not authorize.
These steps do not undo the breach, but they shrink the window during which criminals can profit from your information. The 26,203 affected individuals now share the same permanent exposure; the difference lies in who acts quickly to contain the downstream damage.
Practical Steps Specific to This Exposure
- Place a security freeze with Equifax, Experian, and TransUnion immediately. This blocks new credit applications using your stolen Social Security number and is the single most effective step against identity theft enabled by this breach.
- Review every Explanation of Benefits statement from your health insurers starting now. Look for claims you did not make or services you did not receive. Report anything suspicious to both the insurer and Xsolis.
- Obtain your IRS tax transcript every three months for the next two years. This lets you detect fraudulent tax returns filed with your Social Security number and date of birth before the IRS acts on them.
- Set up alerts with the three major credit bureaus for any new inquiries or accounts. Early warnings give you time to respond before fraudulent activity escalates.
- Contact Xsolis directly if you have changed addresses since January 20, 2026. Confirm whether your specific records were included in the 26,203 affected individuals so you know exactly which categories apply to you.
The notice you received from Xsolis is the beginning of a long vigilance period rather than the end of a single event. The data exposed on January 20, 2026 cannot be taken back, but its ability to harm you can still be limited through consistent monitoring and the credit freeze that prevents new accounts. The 150-day interval between the incident and the filing simply underscores that this risk has already existed for months; the useful response is to treat the exposure as permanent and act accordingly from today forward.
What to do now
Steps that match what this notice says was exposed
Every step below is free and you do it yourself, and none of it depends on Xsolis.
- Freeze your credit — this is the one that matters. A freeze is free, it takes minutes, and it has to be done separately at all three bureaus: Equifax, Experian and TransUnion. It stops a new account being opened in your name, which is what a Social Security number in the wrong hands is for. You can lift it temporarily whenever you need credit.
- Read your next explanation of benefits. Medical identity theft shows up as treatment you did not receive, billed to your policy and written into your medical record. Your insurer can flag the policy, and you can request an accounting of disclosures from the provider named here.
- Expect the phone calls to get better. A date of birth is not secret, but it is what call centres use to confirm you are you. Treat any unexpected call that already knows your details as unverified until you call the company back yourself.
One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.
Report details & sourcing
Related breaches
Trezor Shipping Data Breach — 13,689 Hardware Wallet Buyers, Home Addresses Included
ShipMonk, a logistics provider used by Trezor, was breached through a vulnerability in the third-par…
Match Group (Tinder, Hinge, OkCupid) Data Breach — January 2026
ShinyHunters claimed responsibility for stealing over 10 million Match Group user records in early 2…
Crunchbase Massive Personal Records Leak — January 2026
ShinyHunters exfiltrated approximately 2 million records from the business-intelligence platform Cru…