{"id":860371,"date":"2026-09-25T16:46:15","date_gmt":"2026-09-25T16:46:15","guid":{"rendered":"https:\/\/www.newsbeep.com\/us\/860371\/"},"modified":"2026-09-25T16:46:15","modified_gmt":"2026-09-25T16:46:15","slug":"heres-what-luminis-health-wont-say-about-its-cyberattack","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/us\/860371\/","title":{"rendered":"Here\u2019s what Luminis Health won\u2019t say about its cyberattack"},"content":{"rendered":"<p data-testid=\"text-container\">Cybercriminals who attacked Luminis Health might not have targeted patients\u2019 credit cards, Social Security numbers or other valuable information in its system. <\/p>\n<p data-testid=\"text-container\">Instead, they likely wanted a more direct payday.<\/p>\n<p data-testid=\"text-container\">Ransom.<\/p>\n<p data-testid=\"text-container\">\u201cWhat they\u2019re looking for is leverage over an entity that can then potentially give them a big payout,\u201d said Nate Apathy, who studies hospital cyberattacks as an assistant professor at the University of Maryland School of Public Health. \u201c\u2018We\u2019ve crippled your system. Pay us however much Bitcoin,\u2019 or whatever, \u2018and we\u2019ll allow you to have your system back, and we won\u2019t do anything nefarious.\u2019\u201d<\/p>\n<p data-testid=\"text-container\">It\u2019s been more than three weeks since Luminis, which operates Anne Arundel Medical Center in Annapolis, Doctors Community Hospital in Lanham and several outpatient centers, revealed it was the target of an \u201cincident.\u201d<\/p>\n<p data-testid=\"text-container\">The not-for-profit hospital group\u2019s public statements have focused on efforts to restore its healthcare systems for its 1.8 million patients. By last week, emergency rooms were open, surgeries were going as scheduled, phones were working again and patient records were back, but only in \u201cread-only\u201d mode.<\/p>\n<p data-testid=\"text-container\">Luminis hasn\u2019t detailed what happened or its response, so trying to figure out what happened involves looking at national patterns. If it was a ransomware attack, the disruption is a strong sign the company didn\u2019t pay. <\/p>\n<p data-testid=\"text-container\">But it may never explain exactly what happened.<\/p>\n<p data-testid=\"text-container\">Hospitals increasingly rely on outside software vendors to protect them from cybercriminals.<\/p>\n<p data-testid=\"text-container\">\u201cThe vendors know that that\u2019s their whole business, right?\u201d Apathy said. \u201cIf they can\u2019t be credibly secure, then what business do they have selling a system to anyone?\u201d<\/p>\n<p data-testid=\"text-container\">The attack appears to be different from a summer phishing campaign aimed at the electronic health record-keeping system Luminis uses, MyChart.<\/p>\n<p data-testid=\"text-container\">After that attack, the app, sold by Epic Systems, locked out patients and providers at Luminis\u2019 hospitals, outpatient centers and affiliated medical practices across eight counties.<\/p>\n<p data-testid=\"text-container\">MyChart warned customers about an increase in bogus emails asking users to log in using their passwords.<\/p>\n<p data-testid=\"text-container\">\u201cSome might try to steal your login information or promise free gifts if you enter payment details,\u201d wrote Trevor Berceau, Luminis\u2019 research and development director, on <a href=\"https:\/\/www.mychart.org\/l\/en-us\/news\/staying-safe-from-scams-and-fraud\/\" target=\"_self\" rel=\"nofollow noopener\" title=\"https:\/\/www.mychart.org\/l\/en-us\/news\/staying-safe-from-scams-and-fraud\/\">the company website<\/a> in July. \u201cThe increase in attempts is due to scammers taking advantage of the popularity of the MyChart brand rather than any security concern, so you can continue to use MyChart as normal.\u201d<\/p>\n<p data-testid=\"text-container\">A week before the Aug. 31 attack on Luminis, Epic Systems <a href=\"https:\/\/www.mychart.org\/l\/en-us\/help\/staying-safe-from-scams-and-fraud\/\" target=\"_self\" rel=\"nofollow noopener\" title=\"https:\/\/www.mychart.org\/l\/en-us\/help\/staying-safe-from-scams-and-fraud\/\">updated its warning<\/a> with examples that seem aimed at patients rather than providers.<\/p>\n<p data-testid=\"text-container\">One phishing email was titled \u201cYour recent results are ready.\u201d Users were asked to enter a command to identify themselves, but the key combination secretly opened a coding window on the computer.<\/p>\n<p data-testid=\"text-container\">Epic spokesperson Coral Graszer declined to comment but pointed to public statements by the hospital and the software company. <\/p>\n<p data-testid=\"text-container\">But companies such as Epic have their own vulnerabilities, including reliance on other companies to develop parts of an app, store code or provide cloud data services that the various systems use to operate.<\/p>\n<p data-testid=\"text-container\">\u201cEvery transaction point is a potential point of failure,\u201d Apathy said.<\/p>\n<p data-testid=\"text-container\">The result, he said, is a daisy chain of potential openings. <\/p>\n<p data-testid=\"text-container\">In 2022, Oracle Health bought one of the pioneers of electronic health records, Cerner. Three years later, Oracle was still updating Cerner\u2019s software when hackers discovered compromised passwords and used them to break into the system.<\/p>\n<p data-testid=\"text-container\">The data breach exposed patient records at hospital systems nationwide, including LifeBridge Health in Baltimore. <\/p>\n<p data-testid=\"text-container\">\u201cYou go further up the chain and it gets even more centralized,\u201d Apathy said. \u201cAmazon Web Services is supplying the backend database architecture for hundreds, maybe thousands of health systems to run their cloud-based applications.\u201d<\/p>\n<p data-testid=\"text-container\">Just as IT system integration created vulnerabilities, Luminis\u2019 years of expansion spread the attack\u2019s impact beyond its two hospitals.<\/p>\n<p data-testid=\"text-container\">Anne Arundel Medical Center adopted the name Luminis Health in 2019, reflecting its acquisition of Doctors Community Hospital. Long before that, though, the system was buying up specialty medical practices, adding vertical healthcare services such as heart surgery and building outpatient centers and medical office buildings. <\/p>\n<p data-testid=\"text-container\">The result is a system deeply connected to medical practices, lab services and other healthcare providers \u2014 all of which were affected by the attack.<\/p>\n<p data-testid=\"text-container\">If the attack compromised individual records, Maryland law requires healthcare companies to notify patients whose data was exposed. Far harder to detect will be the impact on the healthcare itself.<\/p>\n<p data-testid=\"text-container\">Hannah Neprash, a professor at the University of Minnesota, led one of the first attempts to quantify harm to patients from hospital cyberattacks. She and her colleagues created a national database stretching back to 2016.<\/p>\n<p data-testid=\"text-container\">\u201cWe\u2019ve recently updated our data through 2025 and each year saw an increase in ransomware attacks on health care providers,\u201d she wrote in an email.<\/p>\n<p data-testid=\"text-container\">Published in the <a href=\"https:\/\/www.aeaweb.org\/articles?id=10.1257\/pol.20240594\" target=\"_self\" rel=\"nofollow noopener\" title=\"https:\/\/www.aeaweb.org\/articles?id=10.1257\/pol.20240594\">American Economic Journal<\/a>, Neprash\u2019s research used Medicare data to track hospital deaths after an attack. Delayed surgeries, rerouted ambulances and care interruptions for chronic conditions all contributed to an increase.<\/p>\n<p data-testid=\"text-container\">\u201cRansomware attacks increase in-hospital mortality for patients already admitted to ransomware-attacked hospitals when the attack begins, compared to patients whose admissions concluded in the five weeks prior,\u201d Neprash wrote. <\/p>\n<p data-testid=\"text-container\">Luminis has not said whether surgeries were affected, but ambulances carrying \u201cnoncritical\u201d patients were rerouted to other hospitals.<\/p>\n<p data-testid=\"text-container\">The company has said it is working with outside cybersecurity firms on its recovery, but it undoubtedly had plans in place to cope with the loss of IT systems.<\/p>\n<p data-testid=\"text-container\">\u201cEvery health system has these plans, and they can activate them whenever they need to,\u201d Apathy said.<\/p>\n<p data-testid=\"text-container\">No national policy exists to improve hospital cybersecurity. An agency within the U.S. Department of Health and Human Services regulates data-sharing rules but not safeguards. <\/p>\n<p data-testid=\"text-container\">Apathy and other researchers last year <a href=\"https:\/\/pubmed.ncbi.nlm.nih.gov\/40896382\/\" target=\"_self\" rel=\"nofollow noopener\" title=\"https:\/\/pubmed.ncbi.nlm.nih.gov\/40896382\/\">called on the agency to set minimum safety standards<\/a>. The called-for rules build on existing cyber tools to improve protections that electronic health record companies such as Epic and Oracle must provide.<\/p>\n<p data-testid=\"text-container\">And while the FBI and other agencies will investigate the attack, the criminals have likely moved on in search of another target.<\/p>\n<p data-testid=\"text-container\">\u201cIt\u2019s fairly sophisticated organizations that are clearly intentionally targeting health systems for the value and quantity of data that health systems have,\u201d Apathy said.<\/p>\n","protected":false},"excerpt":{"rendered":"Cybercriminals who attacked Luminis Health might not have targeted patients\u2019 credit cards, Social Security numbers or other valuable&hellip;\n","protected":false},"author":2,"featured_media":860372,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[59],"tags":[77847,11827,363146,97,252,253,4379],"class_list":["post-860371","post","type-post","status-publish","format-standard","has-post-thumbnail","category-health-care","tag-anne-arundel-county","tag-army","tag-fort-meade","tag-health","tag-health-care","tag-healthcare","tag-military"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts\/860371","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/comments?post=860371"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts\/860371\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/media\/860372"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/media?parent=860371"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/categories?post=860371"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/tags?post=860371"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}