An Anne Arundel Medical Center patient alleges the hospital’s parent company was negligent in safeguarding their medical information after it was exposed in a Sept. 4 data breach, according to a lawsuit filed in the U.S. District Court of Maryland.

The lawsuit against Luminis Health says the breach happened “in part” because Luminis stored patient data in “an unencrypted, Internet-accessible environment.”

Jokisha White, who filed the complaint Sept. 11, says in it that she and others like her are at a “certainly impending” risk of fraud, “intrusion of their health privacy” and other risks that “may last for the rest of their lives.” Two other plaintiffs who live in Anne Arundel County, Rachel Rogers and Angela Ritchie, joined the lawsuit Wednesday, seeking to make it a class action.

White declined to speak to a reporter before speaking with her attorney, who did not respond Wednesday to a request for comment.

Advertise with us

Luminis operates the Anne Arundel Medical Center in Annapolis and Doctors Community Medical Center in Lanham. The company says it provides care for more than 1.8 million patients in Anne Arundel and Prince George’s counties and on the Eastern Shore.

Luminis fell victim to a cyberattack at the beginning of the month. Since then, the company has been tight-lipped about details, leaving patients in the dark about their medical care.

For example, Luminis’ phone lines and its MyChart online patient portal remain offline.

A spokesperson for the Maryland Department of Emergency Management said the cyberattack remains under investigation and that the department and other state agencies were meeting with Luminis leadership to “assess any critical needs and available support.”

The lawsuit says there are likely “tens of thousands” of people eligible for the class action. It asks Luminis to pay for at least 10 years of credit monitoring as well as monetary damages.

Advertise with us

Markus Rauschecker, executive director of the University of Maryland’s Center for Cyber, Health, and Hazard Strategies, said it’s not uncommon for patients to file these types of suits after cyber incidents.

However, he said, plaintiffs can have a difficult time proving “actual” harm, rather than theoretical future harm.

“If we can’t point to an actual harm as plaintiffs, then we have a hard time establishing standing, and these cases end up being dismissed,” said Rauschecker, who teaches at the University of Maryland Francis King Carey School of Law.

The health system has continued to provide some care services during the system outage but said online that some may be unavailable. Luminis also warned that some appointments may take longer than usual.

Jeff Wichman, senior director of breach preparedness and response for cybersecurity provider Semperis, said hospitals and healthcare systems are “prime targets” for cybercriminals.

Advertise with us

“It’s a critical system, lives are on the line,” Wichman said. “If the attackers can identify an organization that truly isn’t resilient and able to recover quickly, it’s just extra pressure on them to extract a payment.”

Semperis published a report last year that found 77% of the healthcare providers it surveyed had been victimized by a ransomware attack.

“You’re going to get hit,” Wichman said. “Any organization should be operating at a mindset of, ‘There is an attacker in the environment.’”

According to the Semperis report, 52% of healthcare providers returned to normal operations between one day and one week following the attack. That Luminis is more than two weeks into a response, Wichman said, tells him this incident is “a bigger deal.”

“Sometimes it’s a telling sign of how bad it is,” he said.

Advertise with us

Luminis has not said publicly which of its systems were affected by the attack or whether patient medical or financial data has been compromised. Luminis officials have said only that they’re working with third-party experts and legal counsel to resolve the incident and restore “affected systems.” The company has not indicated whether it is working with law enforcement.

Luminis did not respond to multiple requests for comment. Its latest update, shared Tuesday, was a written message from CEO Tori Bayless that said the company is “making progress in our restoration efforts.”

In addition to patient lawsuits, Rauschecker said, health systems can become targets of regulatory enforcement from the federal Department of Health and Human Services, which enforces the Health Insurance Portability and Accountability Act, or HIPAA.

Providers are “legally required to implement certain privacy and security measures to protect health information,” Rauschecker said.

If they don’t, regulators can “start asking questions,” he said, adding that there can be “severe penalties” for providers not in compliance.