Cyber & AI intelligence
Wasteland.
Briefs indexed2910
Issues30
Published Mondays07:30 CT
▣ Breach LUMINIS-HEALTH-CYB 2026-09-28

Luminis Health: Cyberattack by Unnamed Criminal Actor Disrupts Maryland Hospital System

"Luminis Health, the Annapolis-based nonprofit that runs Anne Arundel Medical Center and Doctors Community Medical Center, has confirmed that an "unauthorized criminal actor" was behind a cybersecurity incident. The…"

Luminis Health, the Annapolis-based nonprofit that runs Anne Arundel Medical Center and Doctors Community Medical Center, has confirmed that an "unauthorized criminal actor" was behind a cybersecurity incident. The attack took its phone system, MyChart patient portal and CareConnectNow offline for weeks. The system says it serves more than 1.8 million patients, and its hospitals stayed open throughout. Nearly four weeks after disclosure, it still has not said how the attackers got in, what they took, or whether it was ransomware. No ransomware or extortion group has publicly claimed the attack. A class-action lawsuit filed in federal court alleges that patient data was kept in an unencrypted environment reachable from the internet. None of the sources available for this brief is a primary document such as a Luminis statement, a regulator filing or a CERT advisory. Luminis' own statements are known only through press reports, and the details below should be read with that in mind.

What Happened

Luminis posted an alert on its website on Sept. 1 saying it was "responding to a cybersecurity incident affecting certain systems across our organization" (Becker's Hospital Review, CBS Baltimore). Other outlets give a later date. HIPAA Journal says Luminis announced the attack on Sept. 4, and The Banner calls it a "Sept. 4 data breach." HealthExec calls it an "August cyberattack," which would mean the intrusion started before the public notice. Luminis has not said when the incident began (Becker's), so the start date is still unknown. Accounts also differ on size: Becker's says Luminis operates three hospitals and about 100 ambulatory sites, while most other coverage names only its two main hospitals.

Timeline as reported:

The Maryland Department of Emergency Management said the attack is still under investigation and that state agencies have been meeting with Luminis (The Banner).

What Was Taken

This has not been confirmed. Luminis says it is too early to know whether patient data was involved or to what extent. It says it will notify patients if data was exposed or stolen and if applicable law requires notice (HIPAA Journal, Becker's). HealthExec reports that no breach notifications have gone out yet.

The only figures and specifics come from the lawsuit and from unverified reports:

National Cyber Security suggests the attackers may not have been after financial data or Social Security numbers at all, and that the aim was leverage for a ransom. This is expert commentary, not a finding from the investigation.

Why It Matters

The Attack Technique

This has not been disclosed. Luminis has not named the initial access vector, the malware or the threat actor.

What is known or alleged:

What Organizations Should Do

  1. Find and encrypt internet-reachable stores of patient data. Inventory every database, file share and cloud bucket that holds PHI and can be reached from outside. Require encryption at rest and put access behind a VPN or zero-trust gateway. The central allegation in this case is exactly that kind of exposure.
  2. Plan for weeks of downtime, not days. Luminis ran on paper charts, diverted patients and had no phones for more than two weeks. Test downtime procedures, keep a backup phone system that does not depend on the main network, and prepare read-only EHR access for recovery.
  3. Protect patient portals from credential attacks. After this summer's MyChart phishing campaign, require MFA for portal users and staff, watch for credential stuffing, and reset credentials exposed in phishing before treating an incident as closed.
  4. Keep offline, immutable backups and test restores. A long outage without a ransom payment only works if backups survive the attack. Keep EHR and identity-system backups offline or immutable and rehearse full restores.
  5. Write the disclosure plan before an incident. Decide in advance what gets said, and when, about attack type, scope and data involved. When the organization says little, lawsuits and unverified dark-web claims set the story.
  6. Watch leak sites and dark-web markets. Given the unverified sale claim here, run continuous monitoring for your organization's data so you can confirm or rule out exfiltration before patients or plaintiffs do.

Sources: Here’s what Luminis Health won’t say about its cyberattack #ransom... | Luminis Health MyChart, phones remain offline amid cyberattack | Luminis Health Working to Restore Systems After Cyberattack | Luminis Health cybersecurity incident takes MyChart offline | Luminis class-action lawsuit claims unencrypted patient data expose... | Luminis patients seek class action lawsuit after cyberattack - The... | Patients of Luminis Health file class action lawsuit following Augu... | Luminis Health sued over alleged failure to protect patient data af...