Cybercriminals who attacked Luminis Health might not have targeted patients’ credit cards, Social Security numbers or other valuable information in its system.
Instead, they likely wanted a more direct payday.
Ransom.
“What they’re looking for is leverage over an entity that can then potentially give them a big payout,” said Nate Apathy, who studies hospital cyberattacks as an assistant professor at the University of Maryland School of Public Health. “‘We’ve crippled your system. Pay us however much Bitcoin,’ or whatever, ‘and we’ll allow you to have your system back, and we won’t do anything nefarious.’”
It’s been more than three weeks since Luminis, which operates Anne Arundel Medical Center in Annapolis, Doctors Community Hospital in Lanham and several outpatient centers, revealed it was the target of an “incident.”
The not-for-profit hospital group’s public statements have focused on efforts to restore its healthcare systems for its 1.8 million patients. By last week, emergency rooms were open, surgeries were going as scheduled, phones were working again and patient records were back, but only in “read-only” mode.
Read More
Luminis hasn’t detailed what happened or its response, so trying to figure out what happened involves looking at national patterns. If it was a ransomware attack, the disruption is a strong sign the company didn’t pay.
But it may never explain exactly what happened.
Hospitals increasingly rely on outside software vendors to protect them from cybercriminals.
“The vendors know that that’s their whole business, right?” Apathy said. “If they can’t be credibly secure, then what business do they have selling a system to anyone?”
The attack appears to be different from a summer phishing campaign aimed at the electronic health record-keeping system Luminis uses, MyChart.
After that attack, the app, sold by Epic Systems, locked out patients and providers at Luminis’ hospitals, outpatient centers and affiliated medical practices across eight counties.
MyChart warned customers about an increase in bogus emails asking users to log in using their passwords.
“Some might try to steal your login information or promise free gifts if you enter payment details,” wrote Trevor Berceau, Luminis’ research and development director, on the company website in July. “The increase in attempts is due to scammers taking advantage of the popularity of the MyChart brand rather than any security concern, so you can continue to use MyChart as normal.”
A week before the Aug. 31 attack on Luminis, Epic Systems updated its warning with examples that seem aimed at patients rather than providers.
One phishing email was titled “Your recent results are ready.” Users were asked to enter a command to identify themselves, but the key combination secretly opened a coding window on the computer.
Epic spokesperson Coral Graszer declined to comment but pointed to public statements by the hospital and the software company.
But companies such as Epic have their own vulnerabilities, including reliance on other companies to develop parts of an app, store code or provide cloud data services that the various systems use to operate.
“Every transaction point is a potential point of failure,” Apathy said.
The result, he said, is a daisy chain of potential openings.
In 2022, Oracle Health bought one of the pioneers of electronic health records, Cerner. Three years later, Oracle was still updating Cerner’s software when hackers discovered compromised passwords and used them to break into the system.
The data breach exposed patient records at hospital systems nationwide, including LifeBridge Health in Baltimore.
“You go further up the chain and it gets even more centralized,” Apathy said. “Amazon Web Services is supplying the backend database architecture for hundreds, maybe thousands of health systems to run their cloud-based applications.”
Just as IT system integration created vulnerabilities, Luminis’ years of expansion spread the attack’s impact beyond its two hospitals.
Anne Arundel Medical Center adopted the name Luminis Health in 2019, reflecting its acquisition of Doctors Community Hospital. Long before that, though, the system was buying up specialty medical practices, adding vertical healthcare services such as heart surgery and building outpatient centers and medical office buildings.
The result is a system deeply connected to medical practices, lab services and other healthcare providers — all of which were affected by the attack.
If the attack compromised individual records, Maryland law requires healthcare companies to notify patients whose data was exposed. Far harder to detect will be the impact on the healthcare itself.
Hannah Neprash, a professor at the University of Minnesota, led one of the first attempts to quantify harm to patients from hospital cyberattacks. She and her colleagues created a national database stretching back to 2016.
“We’ve recently updated our data through 2025 and each year saw an increase in ransomware attacks on health care providers,” she wrote in an email.
Published in the American Economic Journal, Neprash’s research used Medicare data to track hospital deaths after an attack. Delayed surgeries, rerouted ambulances and care interruptions for chronic conditions all contributed to an increase.
“Ransomware attacks increase in-hospital mortality for patients already admitted to ransomware-attacked hospitals when the attack begins, compared to patients whose admissions concluded in the five weeks prior,” Neprash wrote.
Luminis has not said whether surgeries were affected, but ambulances carrying “noncritical” patients were rerouted to other hospitals.
The company has said it is working with outside cybersecurity firms on its recovery, but it undoubtedly had plans in place to cope with the loss of IT systems.
“Every health system has these plans, and they can activate them whenever they need to,” Apathy said.
No national policy exists to improve hospital cybersecurity. An agency within the U.S. Department of Health and Human Services regulates data-sharing rules but not safeguards.
Apathy and other researchers last year called on the agency to set minimum safety standards. The called-for rules build on existing cyber tools to improve protections that electronic health record companies such as Epic and Oracle must provide.
And while the FBI and other agencies will investigate the attack, the criminals have likely moved on in search of another target.
“It’s fairly sophisticated organizations that are clearly intentionally targeting health systems for the value and quantity of data that health systems have,” Apathy said.


Comments
Welcome to The Banner's subscriber-only commenting community. Please review our community guidelines.