Blue Fish Pediatrics, Xsolis Announce Breaches

At McShane & Brady, we want to make everyone aware of some the most recent data breaches. If you or someone you know who may have been affected by these or any other breaches, please call our office at 816-888-8010 or use our contact form on our website. We want to hold those entrusted with protecting our private information responsible.
Blue Fish Pediatrics
Blue Fish Pediatrics, a network of pediatric medical practices based in Houston,, has filed a data breach notice with the Texas Attorney General.
This breach has affected 41,000 individuals.
An investigation was conducted and confirmed that a threat actor had access to a limited number of files between July 11, 2025, and July 17, 2025. Some of those files contained personally identifiable information and protected health information and may have been acquired in the incident.
Information disclosed included names, dates of birth, driver’s license numbers/state ID numbers, Social Security numbers, medical record numbers, diagnosis/condition information, lab results, medications, claims information, and clinical/treatment information.
Xsolis
Xsolis, Inc., a third party vendor that provides case and utilization management services to healthcare organizations, has recently announced a data breach that may have involved certain personal and protected health information. This breach affected 1.3 million of its clients’ patients.
On January 22, 2026, Xsolis became aware of unauthorized activity from a targeted phishing attack on January 20, 2026.
An investigation was conducted and determined that an unauthorized actor acquired certain files containing information that, depending on the individual, may include names, addresses, date of birth, health insurance information, Social Security numbers, and medical treatment information.
Cherry Health
Cherry Health, Michigan’s largest non-profit Federally Qualified Health Center, announced a breach of patients’ protected health information last week.
Suspicious network activity was identified on or around April 19, 2026 and an investigation was conducted. The investigation concluded that unauthorized access to its network and the copying of files containing patient information.
It is unclear how many have been affected by this breach.

If you receive notification of these breaches or any other data breaches, we ask that you call our office at 816-888-8010 or email us at firm@mcshanebradylaw.com.
From hospitals, healthcare providers, government services, service providers to insurance companies, proper precautions and training have not been made to secure these records. Once public, your information is out there for everyone to see. McShane & Brady is leading firm representing those who have affected by a data breach.
