Luminis Cybersecurity Incident Highlights ‘Concerning’ Rise in Attacks on Healthcare

Luminis Cybersecurity Incident Highlights ‘Concerning’ Rise in Attacks on Healthcare

Cyberattacks on the healthcare industry, like the one that hit an Anne Arundel County hospital last week, are becoming increasingly common and state-level policymakers should prepare for even more, an expert said Tuesday. “I think it’s incumbent upon people who have influence over policy, especially at the state level, to start thinking about what the state can do to improve coordination, to improve readiness, to make sure that when the inevitable happens we are as prepared as we possibly can be,” said Benjamin Yelin. He is the public policy and external affairs program director with the University of Maryland, Baltimore’s Center for Cyber, Health and Hazard Strategies. His comments come just days after Luminis Health facilities last week announced a “cyber incident by an unauthorized criminal actor” that disrupted certain medical appointments and services. Luminis hospitals remained open while an investigation into the attack continues, but some of their systems were nonoperational, which could impact appointments and services. Luminis Health operates Anne Arundel Medical Center in Annapolis among its many other facilities. (Photo by Danielle J. Brown/Maryland Matters) “As a result of the incident, certain systems are currently unavailable, which may affect some appointments and services. Our teams are working urgently to restore affected systems as quickly and safely as possible,” the Luminis notice says. “Our top priority remains providing safe, high-quality care to our patients while responding to this incident,” it said. “We understand the concern and inconvenience this disruption may cause, and we sincerely appreciate your understanding and patience with our teams.” Luminis did not immediately respond to request for an update on the on the incident or the ongoing investigation. As of Tuesday, the health system’s website still warns that patients may be facing disruptions in services due to the incident. But Luminis is just the latest example in what seems to be a rise in cybersecurity threats facing the healthcare industry. FBI data on reported ransomware attacks on “critical infrastructure” in 2025 shows that the healthcare industry was the largest target for ransomware that year, with 460 of 2,118 reported ransomware attacks targeting the the healthcare and public health sphere. “It’s a threat that we have to take very seriously,” Yelin said. “It’s [the Luminis attack] adding to a series of disturbing incidents going back 10 years to the MedStar cyber incident.” He’s referring to a large ransomware attack in 2016 which included MedStar Health along with municipalities and public institutions across the United States. Attacks on the healthcare sphere have continued since. In 2021, the Maryland Department of Health and local departments faced a ransomware attack that disrupted operations for weeks. And in 2024, a ransomware attack on Ascension hospitals affected facilities in Baltimore. Hospitals and related entities like insurance companies are a favorite target among cybercriminals who find the sensitive and personal health information sheltered in those institutions and hold it for ransom, locking those types of healthcare institutions out of their own systems with a demand for payment. “Hospitals have this enhanced risk. Not only are they interconnected, but just the quality of the data they have makes them more attractive to cyber criminals,” Yelin said. Meanwhile, direct interference in the technical infrastructure at hospitals, such as through a denial-of-service attack, can disrupt the medical care at hospitals, and can have ripple effects on other spokes of the healthcare industry. “Any downtime is potentially risking lives. Cybercriminals know that. They know the level of desperation that’s so unique to these hospitals,” Yelin said. “If there’s any kind of delayed treatment, or if you’re forcing medical staff to lose access to electronic health records … if there are are delays in lab results, if you can’t see the interactions between drug medications, you’re going to feel the impacts. “You can understand why this sector is so popular for cybercriminals,” he said. Top Photo: Luminis Health operates Anne Arundel Medical Center in Annapolis among its many other facilities. (Photo by Danielle J. Brown/Maryland Matters) Maryland Matters is part of States Newsroom, a network of news bureaus supported by grants and a coalition of donors as a 501(c)(3) public charity. Maryland Matters maintains editorial independence. Topics Cyber

Original Source

Read the full article at Insurancejournal →

KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.