Luminis Health, the Maryland nonprofit that runs Anne Arundel Medical Center and Doctors Community Medical Center, posted an alert on the evening of 1 September 2026 and took its phone systems and MyChart portal offline. It described the cause on 4 September as an unauthorised criminal actor and moved both hospitals to paper downtime procedures. Non-critical ambulance patients were rerouted to other hospitals for several days. Emergency departments, surgeries and deliveries continued.
Phones came back around 16 September. MyChart was restored by 29 September, according to the system’s own update, with some systems still being rebuilt. Luminis says the platform that stores patient records was not affected and that whether data was accessed remains under investigation. No ransomware or extortion group had claimed the attack by the end of the month, and the system has not used the word ransomware.
The Outage Is The Incident
The corpus argues at 25-0708 that availability is the half of security nobody files, because it produces no notification letter. This is the case in point. Two hospitals serving about 1.8 million patients spent two weeks without phones or a portal, diverting ambulances, on paper. If no data was taken there will be no breach report, no count and no regulatory record, and the event will exist only in local news and one class action filed on 11 September alleging negligent data protection before anyone knew whether data was involved.
No Name On It
An attack with this footprint and no leak-site listing after four weeks is unusual. The possibilities the record allows are a victim that paid quietly, an operator waiting, an intrusion contained before extortion, or destruction without a demand. Luminis has said nothing that resolves it. The file is graded medium because the mechanism, the actor and the data question are all open; the outage itself is documented day by day.
Paper As A Wasting Asset
The corpus recorded at 24-0624 what a pathology outage did to London hospitals and at 26-0715b what an insurer’s network shutdown reached. Two weeks of manual fallback in a hospital system is at the limit of what paper procedures are designed for. Staff who have never used them are running them, and the errors that follow do not appear in any breach statistic either.
Compiled from Luminis Health’s incident updates and contemporaneous local and trade reporting, listed below. Dates for phone and portal restoration are from the system and local press. Ransomware is not confirmed by the victim and is not asserted here. Graded medium. Corrections: corrections@forensicpost.com.
- Cybersecurity Incident UpdateLuminis Health
- Luminis Health cyberattack: What we knowThe Baltimore Banner
- Two Maryland hospitals still dealing with system issues after cyberattackWYPR
- Luminis Health Working to Restore Systems After CyberattackHIPAA Journal