[BREACH] Code Blue in Annapolis: Cyberattack Knocks Two Maryland Hospitals Offline
$ ./hospital_downtime_monitor.sh --system=luminis --verify=2026-09-03
> Pulling luminishealth.org incident page [2026-09-01 17:30]...
> Pulling Baltimore Sun / WYPR / CBS Baltimore reporting...
> Separating CONFIRMED from UNKNOWN...
[INCIDENT_ACTIVE]
AFFECTED SYSTEM:
> Luminis Health -- two hospitals:
- Luminis Health Anne Arundel Medical Center
(Annapolis)
- Luminis Health Doctors Community Medical Center
(Lanham, Prince George's County)
> Service area: Anne Arundel County, Prince George's
County, Maryland's Eastern Shore
CONFIRMED TIMELINE (as of Thu 2026-09-03):
$ timeline --source=primary_and_local_press
> Tue 09-01 17:30 Luminis posts incident page:
"cybersecurity incident affecting
certain systems across our
organization"
> Tue 09-01 ~18:45 Facebook post confirms incident
> Tue 09-01 19:30 Online patient portal down
> Wed 09-02 CBS Baltimore: systems still
unavailable; legal counsel and
third-party cyber experts engaged
> Wed 09-02 -> 09-03 WYPR: some ambulances rerouting
non-critical patients to other
facilities
> Thu 09-03 Baltimore Sun: electronic records
down at AAMC; doctors on paper
charts; some patients rerouted;
one patient: "a little bit chaotic"
WHAT LUMINIS HAS SAID:
> "certain systems are currently unavailable"
> MyChart named in its FAQ as an affected system
> Call 443-222-0193 (business hours) BEFORE arriving
for any appointment or scheduled service
> Data: "Our investigation is ongoing. If the
investigation determines that individuals need to
be notified, we will take appropriate steps"
> Restoration: "as quickly and safely as possible"
NOT KNOWN AS OF 2026-09-03:
$ unknowns --list
> When the intrusion began (reps would not say)
> Attribution: no ransomware group claim found
> Whether patient data was accessed or exfiltrated
> Restoration date: none given
> Which EMS agencies are diverting, and to where
> Whether this is ransomware at all -- Luminis has
said only "cybersecurity incident"
[VERDICT: DOWNTIME_MODE // DATA_STATUS_UNKNOWN]
This one is still moving, so here is only what is confirmed as of Thursday, September 3. At 5:30 p.m. on Tuesday, September 1, Luminis Health posted an incident page saying it was "responding to a cybersecurity incident affecting certain systems across our organization" and had "launched an investigation with the support of legal counsel and third-party cybersecurity experts." A Facebook post followed around 6:45 p.m., and by 7:30 p.m. The Baltimore Sun found the online patient portal down. Luminis runs two hospitals: Luminis Health Anne Arundel Medical Center in Annapolis and Luminis Health Doctors Community Medical Center in Lanham, in Prince George's County, and it serves patients across Anne Arundel, Prince George's and the Eastern Shore. Its FAQ names MyChart among the systems patients may not be able to reach and tells anyone with an appointment to call 443-222-0193 during business hours before showing up.
By Wednesday and Thursday the operational picture had filled in. WYPR reported that the attack was causing some ambulances to reroute non-critical patients to other facilities. The Sun reported Thursday afternoon that electronic records were down at Anne Arundel Medical Center, that doctors had gone to paper charts, and that some patients were being rerouted; one patient called the experience "a little bit chaotic" but said it did not affect their care. That is what a hospital in downtime mode looks like from the inside: the building is open, clinicians are working, and every process that assumed a screen is being done by hand. Luminis says its teams are working to restore systems "as quickly and safely as possible" and has not offered a date.
Now the list of what is not known, because it is longer than the list of what is. Luminis has not said when the intrusion began; representatives were not available to answer the Sun's question on Tuesday night. No ransomware group has claimed the attack in any leak-site listing or press report we could find as of Thursday, and Luminis has used only the phrase "cybersecurity incident," so calling this ransomware is speculation. Whether any patient data was accessed or taken is under investigation, with the standard language that individuals will be notified "in accordance with applicable requirements" if the investigation warrants it. Which EMS agencies are diverting and where the patients are going has not been published. Any post you read this week that fills in those blanks with confidence is guessing.
The reason this is a small-business story and not just a hospital story is geography. Anne Arundel Medical Center and Doctors Community Medical Center anchor the medical economies of Annapolis and the Route 50 corridor into Prince George's County. The independent practices with admitting privileges, the imaging centers and labs that receive their referrals, the home-health agencies, medical couriers, staffing firms and billing companies that live on their portals and their fax lines are all absorbing this outage with them, and none of them got a heads-up. If your practice sends patients to either hospital, your phones are already busier. If your business sells to either, your invoices and purchase orders are sitting in a system nobody can log into. And a public incident is bait: expect calls and emails this week impersonating Luminis, asking patients to "confirm" appointments or insurance details. The real number is 443-222-0193; anything else is a question.
The downtime and vendor-dependency checklist for a 5-to-75-person practice or business in the AAMC and Doctors Community orbit:
- Write the paper day. Print a week of schedules, intake forms, a superbill or order form, and a contact list for staff, key vendors and referral partners. Store a copy off the network. Luminis went to paper charts; a practice with no paper plan simply closes.
- Map your single points of failure. List every system a patient visit or a sale depends on -- EHR, e-prescribing, referral portal, payment terminal, hospital MyChart links -- and who owns it. For each, write one line: what we do if it is dark for three days.
- Keep an offline copy of what you cannot work without. The current patient or customer roster, active orders, insurance and vendor contacts, exported weekly to encrypted storage that is not attached to your main login.
- Decide in advance who calls the divert. Name the person who can send patients or deliveries elsewhere, and the threshold. EMS rerouting non-critical patients away from a hospital is that decision made in advance. Your office should have one too.
- Verify every incident-related contact through the number you already had. Tell staff and patients that appointment changes come only through the practice's own line, and that hospital notices are confirmed by calling the hospital's published number, not one supplied in an email.
We will update this post as Luminis confirms more. Until then, the useful question for every practice and business from Annapolis to Lanham is not who attacked the hospital. It is whether, if your own EHR or ordering system went dark tonight at 5:30 p.m., you would still be open on Wednesday morning.
[SOURCES]
- Luminis Health Cybersecurity Incident Update — Luminis Health, 2026-09-01
- Luminis Health facilities dealing with a cyberattack — The Baltimore Sun (via Yahoo News), 2026-09-01
- Maryland's Luminis Health says some systems are unavailable after cybersecurity attack — CBS News Baltimore, 2026-09-02
- Two Maryland hospitals hit by cyberattack, compromising systems — Baltimore Fishbowl (Scott Maucione, WYPR), 2026-09-03
- Electronic records down, some patients rerouted amid Luminis Health cybersecurity incident — The Baltimore Sun, 2026-09-03