Luminis Health, the Annapolis-based nonprofit that runs Anne Arundel Medical Center and Doctors Community Medical Center, has confirmed that an "unauthorized criminal actor" was behind a cybersecurity incident. The attack took its phone system, MyChart patient portal and CareConnectNow offline for weeks. The system says it serves more than 1.8 million patients, and its hospitals stayed open throughout. Nearly four weeks after disclosure, it still has not said how the attackers got in, what they took, or whether it was ransomware. No ransomware or extortion group has publicly claimed the attack. A class-action lawsuit filed in federal court alleges that patient data was kept in an unencrypted environment reachable from the internet. None of the sources available for this brief is a primary document such as a Luminis statement, a regulator filing or a CERT advisory. Luminis' own statements are known only through press reports, and the details below should be read with that in mind.
What Happened
Luminis posted an alert on its website on Sept. 1 saying it was "responding to a cybersecurity incident affecting certain systems across our organization" (Becker's Hospital Review, CBS Baltimore). Other outlets give a later date. HIPAA Journal says Luminis announced the attack on Sept. 4, and The Banner calls it a "Sept. 4 data breach." HealthExec calls it an "August cyberattack," which would mean the intrusion started before the public notice. Luminis has not said when the incident began (Becker's), so the start date is still unknown. Accounts also differ on size: Becker's says Luminis operates three hospitals and about 100 ambulatory sites, while most other coverage names only its two main hospitals.
Timeline as reported:
- Sept. 1: First website alert. MyChart and CareConnectNow are down. Luminis says it has brought in legal counsel and third-party cybersecurity experts (Becker's).
- Early September: Some patients are sent to other facilities and physicians switch to paper charts (Becker's). Some appointments are rescheduled (HIPAA Journal). WBAL reported delays to patient care on Sept. 9.
- Sept. 10: Luminis update says phones and MyChart are still down, gives no restoration timeline, and says an "unauthorized criminal actor" was responsible (Becker's).
- Sept. 11: Patient Jokisha White files a complaint in the U.S. District Court for Maryland. Rachel Rogers and Angela Ritchie join on Sept. 16 and seek class-action status (The Banner, CBS Baltimore).
- Sept. 18: Latest status update. Clinics and hospitals are open, and recovery is still under way (HealthExec).
- Around Sept. 27: ERs are open, surgeries are running on schedule and phones work again. Patient records are back, but only in read-only mode (National Cyber Security, republishing local reporting).
The Maryland Department of Emergency Management said the attack is still under investigation and that state agencies have been meeting with Luminis (The Banner).
What Was Taken
This has not been confirmed. Luminis says it is too early to know whether patient data was involved or to what extent. It says it will notify patients if data was exposed or stolen and if applicable law requires notice (HIPAA Journal, Becker's). HealthExec reports that no breach notifications have gone out yet.
The only figures and specifics come from the lawsuit and from unverified reports:
- Scale: The complaint says "tens of thousands" of people could be eligible to join the class (CBS Baltimore, citing The Banner). This is a plaintiff's allegation, not a confirmed count of affected records. The 1.8 million figure is Luminis' total patient population, not a breach total.
- Data types: The plaintiffs claim medical and personal information was "fully exposed." The complaint stresses how much medical records sell for on the dark web and warns of prescription fraud, false insurance claims and medical identity theft (WBAL).
- Dark web sale: HealthExec reports an allegation that data from the incident was posted for sale on the dark web, and says the claim "has yet to be substantiated." wasteland.me has not been able to verify it.
National Cyber Security suggests the attackers may not have been after financial data or Social Security numbers at all, and that the aim was leverage for a ransom. This is expert commentary, not a finding from the investigation.
Why It Matters
- Silence is now a risk in its own right. Four weeks in, Luminis has not described the attack type, the entry point or the data involved. Patients are left guessing, and the lawsuit's claims are filling the gap. Nate Apathy of the University of Maryland says Luminis "may never explain exactly what happened" (National Cyber Security).
- The pattern looks like ransomware, but that is not confirmed. Hospital-wide outages, a switch to paper charts and records restored only in read-only mode fit a ransomware attack. HealthExec says it "appears" to be one. Apathy notes that if it was ransomware, the length of the disruption strongly suggests Luminis did not pay. No group has claimed it (HIPAA Journal). That could mean negotiations are ongoing, a leak is being held back, or the attacker is not a typical extortion crew.
- Legal exposure started almost at once. A federal suit was filed ten days after the first disclosure, before any notification letters went out. It asks for at least 10 years of credit monitoring plus damages (CBS Baltimore). Markus Rauschecker of UMB's Center for Cyber, Health and Hazard Strategies notes that plaintiffs often struggle to show actual harm and establish standing (WBAL). Even so, the speed of filing is now normal for healthcare breaches.
- Care was disrupted. Patients were diverted and appointments rescheduled across a regional system. That makes this a patient-safety event, not only a data breach.
The Attack Technique
This has not been disclosed. Luminis has not named the initial access vector, the malware or the threat actor.
What is known or alleged:
- Unencrypted, internet-facing data (alleged). The complaint says the breach happened "in part" because Luminis stored patient data in "an unencrypted, Internet-accessible environment" (The Banner, CBS Baltimore). HealthExec describes this as an unencrypted server connected to the internet, and says the plaintiffs claim Luminis knew about the weakness. Luminis has not responded publicly to these claims, and they have not been tested in court.
- Not linked to the earlier MyChart phishing campaign. National Cyber Security reports that this attack appears separate from a phishing campaign this summer that targeted Epic's MyChart and locked out patients and providers at Luminis facilities. Having two incidents in one year means defenders should not rule out credential exposure from that campaign until investigators do.
- Possible vendor exposure. Commentary in National Cyber Security points to hospitals' growing dependence on outside software vendors for security. Nothing yet connects this incident to a specific vendor.
What Organizations Should Do
- Find and encrypt internet-reachable stores of patient data. Inventory every database, file share and cloud bucket that holds PHI and can be reached from outside. Require encryption at rest and put access behind a VPN or zero-trust gateway. The central allegation in this case is exactly that kind of exposure.
- Plan for weeks of downtime, not days. Luminis ran on paper charts, diverted patients and had no phones for more than two weeks. Test downtime procedures, keep a backup phone system that does not depend on the main network, and prepare read-only EHR access for recovery.
- Protect patient portals from credential attacks. After this summer's MyChart phishing campaign, require MFA for portal users and staff, watch for credential stuffing, and reset credentials exposed in phishing before treating an incident as closed.
- Keep offline, immutable backups and test restores. A long outage without a ransom payment only works if backups survive the attack. Keep EHR and identity-system backups offline or immutable and rehearse full restores.
- Write the disclosure plan before an incident. Decide in advance what gets said, and when, about attack type, scope and data involved. When the organization says little, lawsuits and unverified dark-web claims set the story.
- Watch leak sites and dark-web markets. Given the unverified sale claim here, run continuous monitoring for your organization's data so you can confirm or rule out exfiltration before patients or plaintiffs do.
Sources: Here’s what Luminis Health won’t say about its cyberattack #ransom... | Luminis Health MyChart, phones remain offline amid cyberattack | Luminis Health Working to Restore Systems After Cyberattack | Luminis Health cybersecurity incident takes MyChart offline | Luminis class-action lawsuit claims unencrypted patient data expose... | Luminis patients seek class action lawsuit after cyberattack - The... | Patients of Luminis Health file class action lawsuit following Augu... | Luminis Health sued over alleged failure to protect patient data af...