Luminis Health does not currently have a timeline for recovery. The organization also doesn't know who attacked them or if patient data was taken.

 

What happened

Patients across Luminis Health are still facing canceled appointments, delayed test results, and interrupted care nearly two weeks after a cyberattack disrupted phone lines and computer systems, FOX45 News reported on September 15, 2026. Chief Executive Tori Bayless said the health system is making progress while acknowledging work remains. Luminis has not given a recovery timeline, identified who carried out the attack, or stated whether patient information was accessed, describing the party responsible only as an unauthorized criminal actor. Its network serves roughly 1.8 million people across the region. At Anne Arundel Medical Center, one of its largest facilities, clinicians have been working from paper records.

 

Going deeper

The system first told patients that MyChart and CareConnectNow were unavailable, warning of possible delays while saying outpatient appointments would continue unless individuals were contacted directly, according to WUSA9. It publicly identified the disruption as a cybersecurity incident the following day. Patients have since described the effects publicly, including one still waiting on results from a gallbladder ultrasound while experiencing pain, and another who learned of a cancellation only on arriving for the appointment. Several people identifying themselves as cancer patients have raised concerns about canceled or interrupted chemotherapy. FOX45 asked Luminis how many patients have been affected and whether cancer treatments were interrupted, but they have not yet received a response.

 

What was said

"It was probably somewhat serious, right? Just given the amount of time that they're taking to recover from it," said Anupam Joshi, director of the UMBC Cybersecurity Institute and the university's vice provost and chief AI officer, speaking to FOX45 News. He added that the organization is "being very stingy with the information that they're sharing." On what an attacker might be doing inside a network of this kind, Joshi said, "They could be exfiltrating data. They could just be shutting down systems. They could be doing ransomware. We can speculate wildly."

 

In the know

Recovery duration functions as one of the few external indicators available while an investigation is closed. Nothing requires an organization to disclose the attack type, the responsible party, or a restoration timeline during a live incident, and counsel generally advises against it while forensic work continues and law enforcement is involved. What HIPAA does require applies later, since affected individuals must be notified without unreasonable delay and no later than 60 days after discovery that a qualifying breach occurred, under the Breach Notification Rule. That clock runs from discovery rather than from the completion of the review, so silence about data exposure now is consistent with an investigation still establishing what was reached.

 

The big picture

Hospital volume falls 17% to 24% during the first week of a ransomware attack, with recovery taking about three weeks, and in-hospital mortality rises 34% to 38% among patients already admitted when the attack begins, according to research linking hospital attack records to Medicare claims published in American Economic Journal: Economic Policy. The authors measured this by comparing attacked hospitals against a control group facing attacks weeks later. Their findings describe the operational disruption Luminis patients are now reporting, covering diverted care, postponed procedures, and clinicians working without the systems they rely on. Downtime procedures at most hospitals are built for hours or a day rather than a fortnight, which is the gap this incident illustrates. Organizations reviewing their own plans should establish how long they could run on paper, which systems would need manual workarounds first, and who tracks the patients whose care slipped during the outage so they can be brought back once systems return.

 

FAQs

Why would a health system withhold details during an active incident?

Forensic investigations take weeks, and early statements frequently prove wrong as evidence accumulates. Law enforcement involvement, insurance requirements, and the risk of giving attackers useful information all weigh against disclosure before the facts are settled.

 

Does an operational outage automatically mean a data breach occurred?

No. Encryption or system disruption can occur without data being taken, and the notification obligation turns on whether protected health information was accessed or acquired. Organizations complete a risk assessment before determining that, which is why availability and confidentiality questions resolve on different timelines.

 

What happens to test results during a system outage?

Results generated before the outage may be inaccessible, and new results often arrive on paper or by telephone rather than reaching the record. Reconciling that backlog once systems return is among the longest tasks in recovery, and it is where delayed diagnoses tend to originate.

 

How should a patient handle a canceled appointment during an outage?

Contact the practice directly through a published number rather than waiting for a call, keep a written record of the original appointment and any symptoms, and ask specifically about urgency if the appointment involved ongoing treatment. Systems for rescheduling are frequently among the last restored.

 

What does the three-week recovery figure represent?

The period over which hospital volume returned to normal levels in the studied attacks, not the point at which systems came back online. Backlogged imaging, delayed results, and record reconciliation continue past the technical restoration, which is why the operational effect outlasts the outage itself.