Luminis Health, which operates the Anne Arundel Medical Center in Annapolis and Doctors Community Medical Center in Lanham, has been dealing with a cyberattack for more than two weeks — and patients have been left in the dark.
The hospital operator said it’s remained open and been caring for patients, but “certain systems” have been offline. Luminis officials have not specified which systems are offline or what, if any, medical services have been affected. The company has not replied to requests for comment.
In a statement shared Monday night, Luminis’ top executive said the company is working with cybersecurity experts to understand the “scope” of the attack and safely restore affected systems.
“Our hospitals remain open, our teams continue to provide care, and we are making progress in our restoration efforts,” CEO Tori Bayless said in the statement.
Here’s what else we know.
Was patient care affected?
Ambulances with noncritical patients bound for emergency departments were rerouted to other hospitals for a few days.
Read More
Luminis has not publicly provided specifics about the availability of patient care during this outage. On its website, it says there are “procedures in place to support the continued delivery of patient care during downtime.”
Some patients have complained online that they’ve been unable to schedule follow-up appointments and missed some critical care.
The company did say that some appointments may take longer than usual — for example, patients may be asked to fill out paper forms instead of electronic ones.
I’m a Luminis patient. What should I be concerned about?
So far, Luminis has not said what information or systems were accessed in the cyberattack. Luminis’ phone lines and its online platform, MyChart, are “unavailable.”
Michael Daniel, CEO of the nonprofit Cyber Threat Alliance, said healthcare systems are increasingly being targeted by cybercriminals.
The networks are complex and have many connected devices, and healthcare systems traditionally have not invested as much in cybersecurity, Daniel said. Plus, the information, including personal medical information, has value.
That combination makes healthcare systems “big targets, unfortunately,” Daniel said.
Daniel said Luminis patients should be “extra vigilant” about any emails, texts or other communications they receive that purport to be from their medical providers, in case they’re from a bad actor.
He also said patients should be on the lookout for potential phishing attempts or other schemes that could exploit their data if it falls into the hands of other criminals.
“Those are the kinds of things we would tell people to be concerned about,” he said. “That’s generally how the criminal marketplace works.”
And generally, Daniel said, he would suggest people use multifactor authentication and other systems, including a password manager, to protect themselves online.
What happened, and who is responsible?
Luminis Health officials have provided little information about the incident. They have not said how the “unauthorized criminal actor” got access to their computer systems, who they are or what demands they might have.
Luminis said it is working with unspecified cybersecurity experts and legal counsel to investigate the incident. It has not said whether it’s working with law enforcement.
Luminis first said it was the victim of a cyberattack the evening of Sept. 1.
Daniel, the cybersecurity expert, said it’s not unusual for an incident like this to take two or three weeks to resolve.
Have medical records been affected?
MyChart, an online platform that lets patients view test results, message providers and pay bills, is down, Luminis confirmed. The company also said that access to some “systems and information remains limited while restoration efforts continue.”
Luminis did not say whether medical records had been accessed by the perpetrator of the attack, and said that patients with questions about their care or medical information should contact their care team. With phones and MyChart down, Luminis did not explain how patients could contact their providers directly.
What do I do if I have a scheduled appointment?
Luminis has a hotline set up from 8 a.m. to 5 p.m., Monday through Friday, that patients can call with questions about upcoming appointments or medical services. The number is 443-222-0193.
If you’re calling outside of those hours, you can leave a message that Luminis says will be returned.
Is this the same incident that affected some Johns Hopkins facilities recently?
No. Howard County Medical Center in Columbia, Suburban Hospital in Bethesda and Sibley Memorial Hospital in Washington, D.C., all had to temporarily reroute patients last week due to an “IT issue.”
Kim Hoppe, a spokesperson for the Hopkins hospital system, said in a statement that the issue was “not a cyber-attack.” The three hospitals are back to full functionality.
Banner reporter Meredith Cohn contributed to this story.



Comments
Welcome to The Banner's subscriber-only commenting community. Please review our community guidelines.