Luminis Health cyberattack: Patients still waiting for care, answers nearly 2 weeks later
Luminis Health Doctors Community Medical Center (SBG)
MARYLAND (WBFF) —Nearly two weeks after a cyberattackdisrupted phone lines and computer systems across Luminis Health, patients are still dealing with canceled appointments, delayed test results and other interruptions to care as the health system works to restore its network.
Luminis Health CEO Tori Bayless said in a new update that the health system is “making progress,” but acknowledged “there is still work ahead.”
Bayless said Luminis continues to prioritize patient care while working with outside specialists to restore its systems. However, the health system has still not provided a timeline for full recovery, identified who was behind the attack, or said whether patient information was accessed or stolen.
ALSO READ | Patients struggle to access care more than a week after Luminis Health cyberattack
Anupam Joshi, director of the UMBC Cybersecurity Institute and the university’s vice provost and chief AI officer, told FOX45 News the length of the disruption could offer some indication of its severity.
“It was probably somewhat serious, right? Just given the amount of time that they’re taking to recover from it,” Joshi said. “They’re being very stingy with the information that they’re sharing.”
The potential reach of the disruption is also significant. Luminis Health said its network serves roughly 1.8 million people across the region. At Anne Arundel Medical Center, one of the health system’s largest facilities, patients have reported continued disruptions while providers rely on paper records.
On social media, one patient said they were still waiting for the results of a gallbladder ultrasound while continuing to experience pain under their ribs. Another said they did not learn their appointment had been canceled until they arrived and that it had yet to be rescheduled.
Multiple people identifying themselves as cancer patients have also raised concerns online about canceled or interrupted chemotherapy treatments.
FOX45 News asked Luminis Health how many patients have been impacted by the cyberattack and specifically whether cancer treatments have been interrupted, but had not received a response as of Monday afternoon.
Joshi said there are several possibilities for what an attacker could be doing once inside a health care network, but cautioned that without more information from Luminis, it is impossible to know what occurred in this case.
“They could be exfiltrating data. They could just be shutting down systems. They could be doing ransomware,” Joshi said. “We can speculate wildly.”
If protected health information was compromised, federal HIPAA rules generally require affected individuals to be notified without unreasonable delay and no later than 60 days after discovery of a qualifying breach.
So far, Luminis Health has said only that an “unauthorized criminal actor” was responsible for the attack. Joshi said health care organizations are becoming increasingly attractive targets for all kinds of cyber threats.
“They tend to go after where money is, and healthcare has money and, you know, data that is sensitive,” Joshi said.
He adds other hospital systems are likely paying close attention to the attack and reviewing their own defenses.
3
Maryland high school teacher facing child pornography charges5
Baltimore deputy police commissioner suspended pending investigation3
Man’s death declared homicide weeks after Prince George’s County shooting3
Luminis Health cyberattack: Patients still waiting for care, answers nearly 2 weeks later
