A cybersecurity incident at Luminis Health disrupted online patient services across the Maryland health system, with outpatient delays possible as recovery efforts continued Wednesday.
The nonprofit health system said patient care continued, although some operations depended on system availability. Outpatient appointments were scheduled to proceed unless Luminis contacted patients directly.
Luminis first disclosed the incident Tuesday, saying it took immediate steps to respond and opened an investigation with legal counsel and outside cybersecurity specialists. It has not said when the underlying activity began or how its systems were accessed.
MyChart and CareConnectNow remained unavailable Wednesday. MyChart lets patients view medical records and test results, communicate with care teams, schedule appointments, request prescription refills and join video visits. CareConnectNow provides virtual urgent care to patients across Maryland.
Eye On Annapolis reported that employees were sent home and a hospital entered Code Black amid widespread system failures Monday. The publication said it could not determine whether those disruptions were connected to the cybersecurity incident disclosed Tuesday.
Luminis said it is reviewing whether patient information was accessed or affected and would notify individuals if required.
The health system serves 1.8 million people through three hospitals and more than 100 practice locations, according to Luminis. It operates hospitals in Annapolis and Lanham, while the affected patient platforms support the broader organization.
Luminis has not reported the ambulance diversions or emergency-admission restrictions seen during a January 2025 ransomware attack at Maryland’s Frederick Health. It also has not identified the incident as ransomware.
As of Wednesday, Luminis had not announced a restoration timeline or disclosed how the incident occurred. Its notice remained online, but the health system did not respond by publication time to questions about whether the Code Black was tied to the incident, which clinical services were affected and whether anyone gained unauthorized access to patient information.