A recent hospital cyberattack in Maryland has once again shown how quickly a cybersecurity incident can disrupt patient care and how exposed even established health systems are. In early September 2026, Luminis Health, a nonprofit regional health system, disclosed a cybersecurity incident that took patient-facing systems offline across both of its hospitals. Appointments were cancelled, patients were rerouted to other facilities, and the organization brought in legal counsel and outside cybersecurity experts to investigate (source: Inc., September 2026). For every healthcare provider watching, the message is clear: this could happen to you, and preparation is the only real protection.
What makes this incident so instructive is not that a large system was targeted, but how ordinary the disruption looked. Patient portals went dark. Scheduled care was interrupted. Staff had to reroute patients and set up phone lines for basic questions. These are the real, human consequences of a healthcare cyberattack, and they land hardest on the patients who depend on their providers.
This article looks at what happened, why healthcare is under such sustained attack, and, most importantly, the specific steps every healthcare provider should take to avoid becoming the next headline. Whether you run a small clinic or a larger practice, the lessons from this hospital cyberattack apply directly to you.
In September 2026, Maryland’s Luminis Health system disclosed a cyberattack that took patient portals and other systems offline across two hospitals, cancelling appointments and rerouting patients. The incident is part of a broader wave of healthcare cyberattacks, including breaches affecting millions of patients. The key lessons for every healthcare provider are: assume you are a target, have a tested incident response plan, deploy core controls like MFA and endpoint detection, maintain tested backups, conduct a current risk analysis, and manage vendor risk. Preparation before an attack determines how badly it disrupts patient care.
Table of Contents
ToggleWhat Happened at Luminis Health
Here is what is publicly known about the incident, based on the health system’s own disclosures and reporting. In early September 2026, Luminis Health announced it had experienced a cybersecurity incident affecting both of its hospitals, Anne Arundel Medical Center in Annapolis and Doctors Community Medical Center in Lanham (source: Inc., September 2026).
The attack took online systems offline, including MyChart and other patient portals. The organization said it was working urgently to resolve the issue and was investigating with the support of legal counsel and third-party cybersecurity experts. As of the reporting, the health system had not disclosed the cause of the incident or a timeline for full restoration.
The patient impact was immediate and tangible. Some patients were rerouted to other hospitals for care, some appointments were cancelled, and the system set up a dedicated phone line for questions about upcoming appointments. The organization also noted that it had not yet confirmed whether patient records were accessed, and that it would notify patients if their information was found to be compromised. This response, bringing in experts, communicating with patients, and investigating carefully, reflects how a healthcare cyberattack unfolds in real time.
Why Healthcare Is Under Constant Attack
This incident did not happen in isolation. It is part of a sustained wave of attacks targeting healthcare, and understanding why helps explain the urgency for every provider.
Healthcare organizations are prime targets because they hold enormously valuable data and cannot afford downtime. Patient records sell for far more than credit card numbers because they enable long-term fraud, and when systems go down, patient care is directly affected, which creates pressure to pay ransoms quickly. This combination makes healthcare uniquely attractive to attackers.
The scale of the current wave is striking. Recent healthcare incidents include a breach affecting up to 3.8 million people and another reaching more than 25 million victims (source: Inc., 2026). Attackers are also growing more sophisticated, using AI and even voice-cloning technology in some campaigns. This escalation is why cybersecurity experts have been sounding the alarm about the risk to essential services, including hospitals. For providers, the takeaway is that the threat is not slowing down, which makes preparation more important than ever. Our work with medical clinics is built entirely around this reality.
Lesson 1: Assume You Are a Target
The most important mindset shift for any healthcare provider is to stop assuming that attacks only happen to large hospital systems. Small and mid-sized practices are targeted constantly, often precisely because their defenses are thinner.
While the Luminis incident involved a regional health system, the same attack patterns hit small clinics every week. In fact, smaller practices are frequently easier targets because they lack dedicated security teams and may have weaker defenses. Attackers know this and act accordingly. The question is not whether your organization is worth attacking; if you hold patient data, you are.
Accepting that you are a target is the foundation of real preparation. It moves cybersecurity from an afterthought to a priority, and it is the mindset that separates providers who weather an attack from those who are devastated by one. This is exactly the gap our free risk assessment is designed to reveal and close.
Lesson 2: Have a Tested Incident Response Plan
Notice that Luminis Health’s first moves were to bring in legal counsel and cybersecurity experts and to communicate with patients. That kind of coordinated response is far easier when it is planned in advance rather than improvised during a crisis.
When an attack hits, the first hours are chaotic and consequential. Providers with a written, tested incident response plan know immediately who to call, what to shut down, how to communicate, and what their legal and notification obligations are. Providers without one lose precious time and make costly mistakes under pressure.
Every healthcare organization needs an incident response plan that names roles, lists key contacts for legal, insurance, and technical support, and is tested at least annually. Our incident response service provides exactly this, and our guide to running a tabletop exercise shows how to practice the plan so it works when a real hospital cyberattack scenario unfolds.
Lesson 3: Deploy the Core Technical Controls
Behind most healthcare breaches are a handful of missing fundamentals. The specific cause of the Luminis incident has not been disclosed, but across the healthcare sector, the same core controls prevent the majority of successful attacks.
Multi-factor authentication stops the stolen credentials behind most breaches. Endpoint detection and response catches ransomware and advanced threats that traditional antivirus misses. Network segmentation contains an attack so a single compromised device cannot take down everything. Email security and staff training stop the phishing that begins most incidents. None of these is exotic or expensive, yet their absence is what turns a probe into a breach.
For a healthcare provider, these controls are the practical difference between an attempted attack that fails and one that takes your systems offline. Our network and endpoint security and security awareness training services deliver these fundamentals as an integrated program, sized for practices that do not have their own security teams.
Lesson 4: Maintain Tested, Recoverable Backups
When patient systems go offline, the ability to recover quickly depends entirely on backups that actually work. This is one of the most important protections against the operational paralysis a cyberattack causes.
Ransomware specifically targets backup systems, because attackers know that a provider without working backups is far more likely to pay. And backups that have never been tested may fail exactly when they are needed most. The goal is not just to have backups, but to have tested, encrypted, ransomware-resistant backups that let you restore operations on your own terms.
For a healthcare provider, tested backups can be the difference between a disruption measured in hours and one measured in weeks. Our disaster recovery and backup service ensures your recovery works the first time you need it, which is exactly the moment a hospital cyberattack forces the question.
Lesson 5: Keep Your Risk Analysis Current and Manage Vendors
Two final lessons round out what every provider should take from this incident. First, a current security risk analysis is the foundation that reveals your specific vulnerabilities before an attacker finds them. It is also the single most frequently cited deficiency in HIPAA enforcement, making it both a security and a compliance essential. Many providers have a risk analysis that is years out of date and no longer reflects their actual systems.
Second, vendor risk matters enormously. A significant share of healthcare breaches now originate with third-party vendors and business associates rather than the provider itself. The recent wave of healthcare incidents includes breaches at vendors that affected millions of patients across many providers. Managing your vendors, keeping business associate agreements current, and verifying their security is now essential.
Both of these connect directly to HIPAA compliance, and both are areas where a knowledgeable partner adds significant value. Our HIPAA compliance service keeps your risk analysis current and your vendor relationships managed, and our guide on the business associate agreement explains the vendor side in depth.
Note Worthy Info
- A Maryland health system was taken offline by a cyberattack in September 2026, disrupting patient care.
- The real impact was human: cancelled appointments, rerouted patients, offline portals.
- Healthcare is a prime target because patient data is valuable and downtime pressures providers to pay.
- Recent healthcare breaches have affected millions, and attackers are using AI to grow more sophisticated.
- Small practices are targeted too, often because their defenses are thinner than large systems.
- A tested incident response plan and core controls are what separate a manageable event from a crisis.
- Your risk analysis and vendor management are both security essentials and HIPAA requirements.
The Bottom Line
The Maryland hospital cyberattack is a stark reminder that no healthcare provider is immune, and that the consequences land directly on patient care. When systems go offline, appointments are cancelled and patients are rerouted, the harm is immediate and real. But the providers who weather these attacks are the ones who prepared before them, with tested incident response plans, core security controls, recoverable backups, current risk analyses, and managed vendor relationships.
You do not need to be a large health system to protect yourself, and you do not need a security team of your own. You need the right fundamentals in place and a partner who understands healthcare. If this incident has you wondering how your organization would fare against a similar hospital cyberattack, request a free risk assessment and we will show you exactly where you stand and how to close the gaps before an attacker finds them. Preparation is the one thing you can control, and it makes all the difference.
Frequently Asked Questions
1. What happened in the Maryland hospital cyberattack?
In early September 2026, Luminis Health, a nonprofit regional health system in Maryland, disclosed a cybersecurity incident affecting both of its hospitals, Anne Arundel Medical Center and Doctors Community Medical Center. The attack took patient-facing systems offline, including the MyChart portal, leading to cancelled appointments and patients being rerouted to other facilities. The organization brought in legal counsel and third-party cybersecurity experts to investigate. As of reporting, it had not disclosed the cause or a full restoration timeline, and had not confirmed whether patient records were accessed.
2. Why are healthcare organizations such frequent targets?
Healthcare organizations are prime targets because they hold extremely valuable data and cannot tolerate downtime. Patient records sell for far more than credit card numbers because they enable long-term fraud and cannot be canceled. When systems go offline, patient care is directly affected, which pressures organizations to pay ransoms quickly to restore operations. This combination of valuable data and low tolerance for disruption makes healthcare uniquely attractive to attackers, which is why the sector has faced a sustained wave of increasingly sophisticated attacks.
3. Are small clinics at risk, or just large hospitals?
Small clinics are absolutely at risk, and are often easier targets than large hospitals. While incidents at large health systems make headlines, small and mid-sized practices are attacked constantly, frequently because they lack dedicated security teams and have thinner defenses. Attackers value patient data regardless of the size of the organization holding it. Any provider that holds patient information is a potential target, so assuming that attacks only happen to large systems is one of the most dangerous mistakes a small practice can make.
4. What is the single most important thing a provider can do to prepare?
Having a tested incident response plan is among the most important preparations, because the first hours of an attack are chaotic and consequential. A written plan that names roles, lists key contacts for legal, insurance, and technical support, and has been practiced through a tabletop exercise lets your team respond quickly and correctly instead of improvising under pressure. Beyond that, deploying core controls like multi-factor authentication and maintaining tested backups are essential. Preparation before an attack largely determines how badly it disrupts patient care.
5. How do tested backups help during a cyberattack?
Tested backups are what allow a provider to recover quickly and on their own terms rather than being forced to pay a ransom. Ransomware specifically targets backup systems because attackers know a provider without working backups is more likely to pay. Critically, backups that have never been restored may fail when needed most. Having tested, encrypted, ransomware-resistant backups can be the difference between a disruption measured in hours and one measured in weeks, which is exactly what matters when patient systems go offline.
6. Could a vendor cause a breach at our practice?
Yes, and it is increasingly common. A significant share of healthcare breaches now originate with third-party vendors and business associates rather than the healthcare provider itself. The recent wave of healthcare incidents includes breaches at vendors that affected millions of patients across many different providers at once. This is why managing vendor risk, keeping business associate agreements current, and verifying that your vendors maintain strong security are now essential parts of protecting your practice and your patients.
7. How can a small practice protect itself without an IT team?
A small practice does not need its own security team to be well protected. The practical path is to put the right fundamentals in place, a current risk analysis, multi-factor authentication, endpoint detection, tested backups, staff training, a tested incident response plan, and vendor management, ideally with a partner who understands healthcare. A managed IT and cybersecurity provider can deliver all of these as an integrated program sized for a small practice, giving you enterprise-grade protection without the cost of building an internal security team.