Computer systems have been down for all Luminis Healthcare providers for two weeks and it’s not clear when services will be fixed.
Luminis was hacked on Sept. 1. Luminis runs Anne Arundel Medical Center in Annapolis, Maryland Doctor’s, Community Medical Center in Lanham, Maryland, and several other primary care and specialty offices around the region.
The provider issued a statement Wednesday, saying: “Luminis Health continues to make considerable progress in restoring affected systems. We are pleased to share that telephone service has now been restored across all Luminis Health locations.”
“With telephone service restored, patients can call their physician or surgeon’s office directly for scheduling, test results, prescription questions, and other care needs. MyChart, our patient portal, remains unavailable at this time. Patients should contact their doctor’s office directly for assistance.”
Related stories
The impact was widespread. Patients couldn’t communicate with doctors, pay bills or access health records through the provider’s MyChart app. Providers can’t access those records either.
The sister of a woman recently admitted to Anne Arundel Medical Center described a situation where nurses gave out their own cellphone numbers to patients so they could respond to needs. She also said each wing of the hospital had developed its own system for taking notes and communicating with patients to continue providing care.
Luminis’ phone system is down and multiple emails were not returned when asked for comment. But the situation the healthcare company finds itself in is becoming more and more common across the country.
“Hackers have identified that health systems are vulnerable and have tons and tons of valuable data, and so have targeted those increasingly,” said Nate Apathy, an assistant professor at the University of Maryland School of Public Health who studies health information and electronic health records.
“They don’t seem to be particularly targeting specific types of health systems or hospitals,” he said. “It’s just like everybody’s at risk … rural hospitals are at risk and big metropolitan-based systems are at risk, and ambulatory surgery centers are at risk, and clearinghouses are at risk. The risk is all over.”
In most cases, Luminis officials are reticent to say much about the attack, including whether it was ransomware or something else. That can be frustrating for patients who don’t know what information was taken or when systems will be back up and running.
“They don’t want to give credibility to anyone seeking a ransom,” Apathy said. “This is a challenge that the healthcare industry is actively trying to figure out how to deal with because it is getting so much more common.
“The risks of lower-quality care are real,” he added.
Computer attacks increase in-hospital mortality
A study published in February in the American Economic Journal showed that ransomware attacks decrease hospital volume by 17% to 24%, while in-hospital mortality increases by 34% to 38%. It usually takes hospitals about three weeks to recover.
“It’s a big risk, and that is something that patients should take very seriously, but to a large extent, it’s out of their control,” he said.
Dori Cross, an associate professor at the University of Minnesota School of Public Health said third-party companies that manage data are also targeted, but when hospital systems are hit, they typically focus more on care than messaging.
“I think clinicians, patients, families — I think what they care about most is, what are you doing to try to protect the quality and safety of healthcare?” she asked.
“What are we doing to try to ensure that in this downtime we’re still taking the best care of patients that we can?”
“I’m not sure how much extra they would get by kind of disclosing the sensitive specifics of what’s happening behind the curtain,” she added. I think there’s … positives and negatives to that type of transparency.”
Because every healthcare system is a target, Cross said simply switching providers isn’t going to lead to better outcomes.
“It’s not like I can say, ‘Oh, well, I used to get my care at Luminis, but I’m going to switch to their competitor because they have stronger cybersecurity, and so this isn’t going to happen,’ right,” Cross said.
“All delivery organizations have relatively comparable levels of risk, and so from a patient perspective, it’s not, ‘Oh, I should change where I get my care’ because today it’s Luminis, but next month it could be … whoever the other kind of main health system is in that area.”
“It is affecting patients and their families, but there’s not much that they can do proactively, and that’s what makes it such a kind of insidious problem,” she added.
Get breaking news and daily headlines delivered to your email inbox by signing up here.
© 2026 WTOP. All Rights Reserved. This website is not intended for users located within the European Economic Area.
Click Here For The Original Source.
