Healthcare cyberattacks rise as hospitals face ransomware risks (The Case of Luminis Health) | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


Cyberattacks against healthcare organizations are becoming more frequent, increasing pressure on state governments to improve coordination and response planning, according to a University of Maryland cybersecurity policy expert.

The warning followed a cyber incident at Luminis Health in Anne Arundel County, Maryland, that disrupted some medical appointments and services.

Benjamin Yelin, public policy and external affairs program director at the University of Maryland, Baltimore’s Center for Cyber, Health and Hazard Strategies, said state policymakers should prepare for further incidents. He said governments need stronger coordination and readiness before major healthcare systems are affected.

Luminis Health disclosed last week that an unauthorized criminal actor had caused a cyber incident affecting parts of its technology environment. Its hospitals remained open, but certain systems were unavailable and some appointments or services were affected.

The health system said its teams were working to restore affected systems safely. As of Tuesday, its website continued to warn patients about possible service disruptions.

Luminis hadn’t provided an additional public update on the investigation by that point. The organization said patient care remained its main operational priority while technical teams worked on recovery.

The incident follows a broader pattern of ransomware attacks against healthcare organizations. FBI data for 2025 shows that healthcare and public health was the most frequently targeted critical infrastructure sector for reported ransomware incidents.

Healthcare organizations accounted for 460 of 2,118 reported ransomware attacks against critical infrastructure during the year. That represented more attacks than any other sector listed in the FBI data.

Yelin said the Luminis incident adds to a series of significant healthcare cyberattacks stretching back at least a decade. He pointed to the 2016 ransomware incident affecting MedStar Health as an earlier example.

Maryland’s healthcare infrastructure has experienced several other major incidents since then. A 2021 ransomware attack against the Maryland Department of Health and local health departments disrupted operations for weeks.

Ascension hospitals were also affected by ransomware in 2024, including facilities in Baltimore. These incidents have demonstrated how attacks against healthcare systems can interrupt access to digital tools used in daily patient care.

Hospitals remain attractive targets partly because they hold large volumes of sensitive personal and medical information. Attackers can use ransomware to block access to systems while demanding payment for restoration or control of stolen data.

“Hospitals have this enhanced risk. Not only are they interconnected, but just the quality of the data they have makes them more attractive to cyber criminals,” Yelin said.

Cyberattacks also create operational risks beyond data theft. Disruption to technical infrastructure can affect electronic health records, laboratory systems and other services used by medical staff.

Even short periods of downtime can affect patient care. Delays may interfere with treatment, access to test results or the ability to review medication interactions.

That dependence on digital systems gives healthcare cyber incidents a different operational profile from attacks against many other industries. The effects can extend from IT departments directly into clinical services.

Yelin said state officials should therefore treat healthcare cyber readiness as a continuing policy issue. His recommendation centres on improving coordination and ensuring institutions are better prepared before the next major incident occurs.

——————————————————–


Click Here For The Original Source.

.........................