Published September 12, 2026 — Annapolis, Maryland. Luminis Health, a Maryland-based health system operating primarily in central Maryland and on the Eastern Shore, is grappling with a cybersecurity incident that has knocked certain computer systems offline. The incident affects Luminis Health Anne Arundel Medical Center (Annapolis) and Luminis Health Doctors Community Medical Center (Lanham). The health system established a dedicated patient helpline (443-222-0193) and engaged third-party cybersecurity specialists for forensic investigation.
Data last verified September 12, 2026 from Hoodline reporting on the Luminis Health cyberattack (September 2, 2026), Luminis Health official statements, and HIPAA / Maryland Personal Information Protection Act requirements.
Quick Answer
Luminis Health, a Maryland-based health system, was hit by a cyberattack disclosed around September 2, 2026. The incident affects Anne Arundel Medical Center (Annapolis) and Doctors Community Medical Center (Lanham) — the system's two main hospitals. Computer systems are offline; a dedicated patient helpline (443-222-0193) has been activated. Luminis Health has 790 licensed beds and 6,100+ employees across 8 Maryland counties. Whether patient records were compromised is unconfirmed. The incident comes two weeks after both hospitals were placed on Code Black lockdowns following a telephoned threat (Hoodline, September 2, 2026).
What we know about the Luminis Health cyberattack
| Detail | Information |
|---|---|
| Victim | Luminis Health (Maryland health system) |
| Disclosed | Around September 2, 2026 (Facebook post ~6:45 PM) |
| Affected facilities | Anne Arundel Medical Center (Annapolis), Doctors Community Medical Center (Lanham) |
| Impact | Computer systems offline; some operations disrupted |
| Patient helpline | 443-222-0193 |
| Data exfiltration | Not yet confirmed |
| Threat actor | Not publicly attributed |
| Reporting source | Hoodline, citing Luminis Health statements |
Source: Hoodline (September 2, 2026); Luminis Health official statements.
About Luminis Health
Luminis Health is the merged entity of Anne Arundel Health System and Doctors Community Health System, formed in 2019. The system operates:
- Hospitals: Anne Arundel Medical Center (Annapolis), Doctors Community Medical Center (Lanham), plus several community hospitals.
- Licensed beds: ~790.
- Employees: 6,100+.
- Geographic footprint: 8 Maryland counties (Anne Arundel, Prince George's, Charles, Calvert, St. Mary's, Talbot, Queen Anne's, Caroline).
- Service lines: Primary care, specialty care, emergency services, women's health, orthopedics, oncology, behavioral health, and outpatient services.
Luminis Health is one of Maryland's largest non-profit health systems and a critical community resource. The cyberattack disrupts services for hundreds of thousands of Maryland residents (Luminis Health, 2026; Hoodline, September 2, 2026).
Healthcare cybersecurity: a chronic crisis
Healthcare is the most-attacked industry in 2025-2026, and Luminis Health's incident is one of dozens of major hospital cyberattacks this year. Key statistics:
| Healthcare cybersecurity metric | 2025-2026 figure |
|---|---|
| Average cost of a healthcare data breach | $10.93 million (highest of any industry for the 14th year) |
| Average ransom demand | $900,000-$5M for mid-sized hospitals; $10M+ for large systems |
| Mean downtime after ransomware attack | 21 days |
| % of breaches involving ransomware | ~70% |
| Healthcare breaches in 2025 | ~700+ breaches affecting 200M+ individuals |
Source: IBM Cost of a Data Breach Report (2025); Verizon DBIR (2026); HIPAA Journal breach tracking (2025-2026).
Hospitals are particularly attractive targets because:
- Critical care continuity: patient safety creates urgency to pay ransoms quickly.
- Rich data: medical records contain PII, PHI, financial data, and insurance details - highly valuable on dark web markets ($250-$1,000 per record vs $5-$15 for credit card data).
- Legacy systems: many hospitals run older Windows, EHR, and medical-device systems that are difficult to patch.
- Connected devices: infusion pumps, MRI machines, and patient monitors are increasingly IP-connected but rarely patched.
- Limited IT budgets: underfunded cybersecurity teams relative to the threat landscape.
- HIPAA pressure: regulatory pressure to report breaches can be weaponized by attackers threatening public disclosure.
Impact on patients and the community
The Luminis Health cyberattack affects patients across central Maryland. Specific impacts:
- Appointment scheduling: may be disrupted for non-emergency visits; patients are directed to call the helpline.
- Electronic health records: potentially inaccessible; clinicians may rely on downtime procedures (paper records, manual orders).
- Emergency services: emergency departments remain open but may have reduced capability for some procedures.
- Prescription refills: may be delayed or require additional verification.
- Lab results: may be delayed if lab information systems are affected.
- Medical imaging: imaging systems (PACS) may be down; emergency imaging may use backup modalities.
- Billing and insurance: billing systems may be disrupted; patients may receive delayed bills or no bills.
For emergency medical needs, patients should still call 911 or go to the nearest emergency department. For non-emergency questions related to the cyberattack, call the helpline 443-222-0193 (Luminis Health, 2026).
Regulatory implications
The Luminis Health cyberattack triggers multiple regulatory obligations:
| Regulation | Requirement | Trigger |
|---|---|---|
| HIPAA Breach Notification Rule (45 CFR § 164.404) | Notify affected individuals within 60 days | Unauthorized access to PHI |
| HIPAA HHS Notification (45 CFR § 164.408) | Notify HHS Secretary within 60 days (500+ individuals) | Breach affecting 500+ individuals |
| Maryland Personal Information Protection Act (Md. Code Com. Law § 14-3504) | Notify Maryland residents within 45 days; notify MD AG | Unauthorized access to PII (name + SSN, etc.) |
| SEC Cybersecurity Disclosure Rules | Disclose material cyber incidents within 4 business days (Form 8-K) | Material impact on public companies |
| OCR Breach Portal | Post to OCR's online breach portal | Breach affecting 500+ individuals |
Source: HIPAA Privacy Rule (45 CFR § 164); Maryland Personal Information Protection Act; SEC Cybersecurity Disclosure Rules (effective 2023).
The prior bomb threats
The cyberattack comes two weeks after both Anne Arundel Medical Center and Doctors Community Medical Center were placed on temporary Code Black lockdowns following an unverified telephoned bomb threat in late August 2026. Code Black is the highest-security hospital status, restricting all access to the facility until the threat is resolved. While the cyberattack and the bomb threats appear operationally distinct, the back-to-back nature highlights the security pressures facing Maryland hospitals (Hoodline, September 2, 2026).
What Luminis Health patients should do
- Call the helpline (443-222-0193) for questions about appointments, prescriptions, or medical records.
- Request medical records copies when systems are restored. Under HIPAA, patients have the right to copies of their medical records within 30 days.
- Monitor financial accounts and credit reports if personal information was potentially exposed.
- Be alert for phishing emails claiming to be from Luminis Health. Attackers often follow hospital breaches with phishing campaigns using stolen contact data.
- Watch for medical billing fraud if health insurance information was exposed. Verify all medical bills and Explanation of Benefits statements.
- Consider identity theft protection if a HIPAA breach notice is received from Luminis Health.
FAQ
Is the Luminis Health cyberattack related to ransomware?
Luminis Health has not disclosed the specific nature of the attack. The systems-offline impact is consistent with ransomware or a similar destructive attack, but could also be a network compromise where systems were taken offline as a precaution. The investigation will determine the specifics (Hoodline, September 2, 2026).
Can patients still receive emergency care?
Yes. Emergency departments at Anne Arundel Medical Center and Doctors Community Medical Center remain open. The cyberattack affects administrative and electronic systems; emergency clinical care is maintained through downtime procedures. For life-threatening emergencies, call 911 (Luminis Health, 2026).
When will systems be restored?
Luminis Health has not provided a specific timeline. Healthcare ransomware attacks typically have 14-30 day recovery periods, depending on the attack's scope and the organization's backup posture. The hospital system will likely operate in degraded mode for weeks as systems are methodically restored and verified (IBM Cost of a Data Breach Report, 2026).
Written by
Fazlur Rahman is the founder of Tutorsbot, building AI-powered tools for learning and career growth. He writes about applying AI in real products and the practi… Read more
Fazlur Rahman is the founder of Tutorsbot, building AI-powered tools for learning and career growth. He writes about applying AI in real products and the practical side of building an ed-tech startup.







