The Luminis Health Cyberattack: What Hospital Downtime Costs

Spare Tire banner: "When the EHR goes dark, care goes to paper" — on the Luminis Health cyberattack and the cost of hospital downtime.

TL;DR

Luminis Health, a major Maryland health system, confirmed a cybersecurity incident on September 1, 2026. Patient portals went offline and staff at Anne Arundel Medical Center and Doctors Community Medical Center reported system outages. Luminis has not said whether patient data was accessed, and no attacker has been named. The lasting damage in incidents like this rarely comes from the breach itself. It comes from the days a hospital has to run without its electronic health record.

What happened at Luminis Health

Luminis Health confirmed a cybersecurity incident on September 1, 2026, and posted a public notice the following day. Outages had already begun hitting facilities across the system earlier that week. According to the health system’s own incident page, “certain systems are currently unavailable,” and patients with upcoming appointments are asked to call 443-222-0193 before arriving to confirm their visit.

 

The affected facilities include Luminis Health Anne Arundel Medical Center in Annapolis and Luminis Health Doctors Community Medical Center in Lanham, along with sites on Maryland’s Eastern Shore (CBS News Baltimore, DataBreaches.net). The patient portal was reported down, and staff at some locations were sent home as networks went offline (Hoodline).

 

Luminis says its “priority remains providing safe, high-quality care to our patients while responding to this incident,” and that it is investigating with legal counsel and third-party cybersecurity experts. The system has not disclosed whether any patient information was accessed or removed, and no group has been publicly identified. As of publication, the cause, the scope, and any data impact are still under investigation. Speculation helps no one who depends on these hospitals.

 

The attack also lands during a rough stretch for the system. About two weeks earlier, an unverified telephoned bomb threat prompted temporary Code Black lockdowns at both hospitals (Hoodline). Officials have not connected the two events, and there is no public evidence that they are related.

What actually stops when the systems go dark

The headline says “cyberattack.” What clinicians experience is a blackout. When the electronic health record and patient portals go down, scheduling, medication records, lab results, imaging, and billing can go with them. Care doesn’t stop, but it slows, and it moves to paper.

 

That shift carries its own risk. Nurses lose fast access to allergy lists and medication histories. Orders that normally take seconds get written by hand and walked down a hallway. The people absorbing that load are the same clinicians already carrying full patient panels.

 

This is the part of a cyberattack that boards and IT teams tend to underweight. The security conversation focuses on how attackers got in. The operational reality is how long the hospital runs blind after they do.

The pattern is consistent, and it's expensive

Luminis is the newest name on a list that has grown steadily.

 

When Ascension was hit by ransomware in May 2024, the attack affected 142 hospitals across 19 states. Clinicians reverted to pen and paper, and it took roughly six weeks to restore EHR access to normal operations. The breach ultimately exposed data belonging to about 5.6 million people (HIPAA Journal).

 

The October 2022 attack on CommonSpirit Health knocked EHRs offline across roughly 100 facilities in 13 states, and some systems were still down about a month later (HIPAA Journal, BankInfoSecurity). In February 2024, the Change Healthcare attack disrupted claims and pharmacy systems nationwide for weeks, stalling payments to providers well beyond the walls of any single hospital.

 

The financial weight is documented. IBM’s 2025 Cost of a Data Breach Report put the average healthcare breach at $7.42 million, the highest of any industry for the fourteenth year running (IBM, via HIPAA Journal). That figure counts remediation and notification. It doesn’t fully capture the revenue a hospital loses while its systems are dark, or the strain on staff working around them.

Chart of hospital EHR downtime after ransomware attacks: Ascension about 6 weeks (May 2024, 142 hospitals), CommonSpirit about 4 weeks (Oct 2022). Healthcare breaches averaged $7.42M in 2025, highest of any industry for 14 years; the 2024 Ascension attack exposed 5.6M people's data.
EHR restoration time and breach-cost context from recent hospital ransomware attacks. Sources: IBM, HIPAA Journal, BankInfoSecurity.

What a real downtime plan has to survive

Most hospitals have a downtime policy. Under a multi-day EHR outage, many of those plans amount to paper forms and a read-only copy of yesterday’s records. That’s a fallback, not continuity. It assumes the outage is short, and recent attacks have not been short.

 

A downtime plan that holds up under a two-week blackout has to answer a harder question: can clinicians keep placing orders, viewing current records, and documenting care while the primary EHR is unreachable, and can that work sync back cleanly once systems return?

 

This is the gap Spare Tire® was built to close. It’s an EHR downtime resilience layer, kept architecturally separate from the systems it protects, so an attack that reaches the primary EHR doesn’t take the fallback down with it. Clinicians keep working against current data over standard HL7 interfaces, and validated records sync back when the EHR is restored. The goal is narrow and specific: keep clinical work moving during the exact window when a hospital is most exposed.

 

Luminis will recover. The harder question for every other health system watching is the one to answer before the notice goes up on your own site: when your EHR goes dark for two weeks, what keeps your clinicians working?

FAQ

What happened in the Luminis Health cyberattack?

Luminis Health confirmed a cybersecurity incident on September 1, 2026, that took certain systems and patient portals offline across facilities including Anne Arundel Medical Center and Doctors Community Medical Center. The system is investigating with outside cybersecurity experts and has asked patients to call ahead to confirm appointments.

As of publication, Luminis Health has not said whether patient data was accessed or removed. Its investigation is ongoing, and the system says it will notify affected individuals if the investigation determines that notification is required.

Reported facilities include Luminis Health Anne Arundel Medical Center in Annapolis and Luminis Health Doctors Community Medical Center in Lanham, along with sites on Maryland’s Eastern Shore.

It varies, but recent attacks show outages measured in weeks, not hours. Ascension needed roughly six weeks to restore EHR access after its May 2024 attack, and some CommonSpirit systems were still offline about a month after its October 2022 attack.

A downtime plan that only provides paper forms assumes a short outage. Keeping clinical work moving during a multi-day blackout requires a fallback that stays available when the primary EHR is down and that lets validated records sync back once systems recover. This is the function of an EHR downtime resilience layer such as Spare Tire®.