Luminis Health brought its MyChart patient portal back online on September 29, 2026, closing out a four-week disruption that started with a cyberattack disclosed on September 1. The Maryland-based health system says patients can again schedule appointments, request prescription refills, message providers, and view parts of their health information through the portal. Phone service has also been restored across all Luminis Health locations.
The outage forced clinicians at Luminis Health’s hospitals back onto paper charts for nearly a month, a scenario that has become uncomfortably familiar across US healthcare since the Change Healthcare breach upended claims processing nationwide in 2024. What makes the Luminis Health incident worth watching isn’t just the outage length. It’s what the health system is (and isn’t) saying about what happened, and how that gap compares with a stretch of 2026 that has already produced multiple healthcare-adjacent breach disclosures on shattered.io’s security desk.
What Happened to Luminis Health’s MyChart
Luminis Health first disclosed the cybersecurity incident on September 1, 2026, according to the health system’s own incident-update page and reporting from local outlets. The disruption knocked MyChart offline for patients across the system’s Maryland footprint and cut phone lines at its facilities. For close to four weeks, staff relied on manual, paper-based processes to keep care moving while investigators worked through the network.
Luminis Health has not named a suspect or a ransomware group, and it has not said publicly which systems were compromised beyond the patient-facing effects on MyChart and phone service. That’s a narrower disclosure than some peers have made this year. Astrana Health’s SEC filing on its own hack, for instance, laid out a specific regulatory timeline. Luminis Health, by contrast, has stuck to short operational updates rather than a detailed forensic account, and the investigation remains open.
The Restoration: What’s Back Online Now
In its September 29 update, Luminis Health said it continues to make progress in restoring affected systems, and that it is pleased to share that MyChart is now available for patient use, per the official incident-update page. The system confirmed that telephone service has been restored across all Luminis Health locations, and MyChart is available for patient use.
Practically, that means patients can log in to book appointments, request prescription refills, and message their care teams again. Those three functions cover most of the day-to-day reasons people open a hospital portal, so restoring them ends the worst of the disruption even though the recovery work continues behind the scenes.
What’s Still Missing From the Portal
MyChart’s return doesn’t mean every record is current. Luminis Health said that as recovery continues, some information, including patient notes, lab results and imaging results, may not yet be available in MyChart. The health system says data generated during the outage is being scanned in and added as the recovery effort continues, which suggests a manual, staff-driven backfill process rather than an automated restore.
That gap matters for patients who had appointments, tests, or imaging done in September. If a scan or lab result from the outage window isn’t visible yet, it likely hasn’t been digitized rather than lost outright, though Luminis Health hasn’t published a date by which the backlog will be fully caught up.
Luminis Health’s Statement on Patient Records
The most consequential line in Luminis Health’s public messaging is its claim about scope. The health system has said the recent cyber incident did not affect the system that stores our patient records, drawing a distinction between the portal and phone systems that went dark and the underlying electronic health record database.
That’s a meaningful claim if it holds up, since it would mean the incident disrupted access and availability without necessarily exposing or altering the records themselves. It’s also, so far, an assertion rather than a finding: Luminis Health has said its investigation into the incident remains ongoing, and it hasn’t published third-party forensic conclusions confirming what data was or wasn’t touched. Readers should treat the statement as the health system’s current position, not a closed case.
Four Weeks on Paper: How Hospitals Cope Without Their EHR
During the cybersecurity incident, the company utilized established downtime procedures, including using paper medical records, Luminis Health told reporters, a detail captured in Fox Baltimore’s coverage of the restoration. Downtime procedures are standard playbooks that hospitals rehearse for exactly this scenario: a power outage, a system failure, or a cyberattack that takes the electronic health record offline.
Why paper charting slows everything down
Paper charting works, but it’s slower and more error-prone than an EHR at scale. Nurses and physicians lose instant access to a patient’s full history, drug-interaction alerts, and lab trends. Reconciling paper notes back into the digital record afterward, the “scanning” work Luminis Health referenced, is itself a multi-week project, which is part of why a month-long outage doesn’t end the moment the portal comes back online.
Timeline of the Luminis Health Cyberattack
Here’s how the incident has unfolded based on Luminis Health’s public statements and contemporaneous local reporting.
| Date | Development |
|---|---|
| September 1, 2026 | Luminis Health discloses a cybersecurity incident. MyChart and phone service go down |
| September 1–28, 2026 | Hospitals operate on paper-based downtime procedures. Investigation begins with legal counsel and third-party cybersecurity experts |
| September 29, 2026 | Luminis Health restores MyChart for patient use and confirms phone service is back across all locations |
| Ongoing | Information from the downtime period is scanned and added to MyChart. Investigation into scope and cause continues |
The Litigation Angle: What Local Reports Say
Fox Baltimore’s report on the restoration ties the incident to litigation touching Luminis Health’s Anne Arundel and Prince George’s county service area, though case specifics, including plaintiffs and claims, were not detailed in the coverage reviewed for this article. Healthcare breach disclosures routinely draw lawsuits within days, a pattern this site has tracked elsewhere this year, including the suit filed against Gold Star Mortgage just three days after its BrainCipher ransomware hit. Whether the Luminis Health litigation follows a similar track will depend on what the investigation ultimately confirms about what data, if any, was accessed.
How Luminis Health Compares to Other 2026 Healthcare Breaches
Luminis Health’s incident lands in a year that has already produced several healthcare and health-data disclosures. The comparison below uses figures already reported on each respective incident.
| Incident | What’s confirmed | Disclosure timing |
|---|---|---|
| Luminis Health (2026) | MyChart and phone outage. Patient record database reportedly unaffected. Scope of any data access unconfirmed | Disclosed Sept. 1, 2026. Portal restored Sept. 29, 2026 |
| Astrana Health | Data breach disclosed via SEC filing | Filing landed Sept. 22, 2026 |
| DC Medicaid (DHCF) | Data exposure affecting 399,086 people | Reported 2026 |
| Telmate | Data breach settlement reached | Settlement value: $4.23 million |
| Change Healthcare (2024, for scale) | Largest healthcare breach on record | Final HHS-confirmed count: 192.7 million individuals |
Set against that backdrop, Luminis Health’s disclosure is notable for what it hasn’t confirmed rather than for a headline number. No patient count has been published. No attacker has been named. That’s a different posture than Astrana Health’s SEC-driven disclosure, which came with a regulatory paper trail attached, and it leaves outside observers largely dependent on the health system’s own updates for now.
Why a Portal Outage Isn’t the Same as a Data Breach
It’s worth separating two different things that often get flattened into one headline: an attack that takes a system offline, and an attack that steals data from it. Luminis Health’s public position describes the first without confirming the second. A four-week MyChart outage is disruptive and costly on its own, since it strips patients of self-service tools and pushes staff back onto slower manual workflows. That happens whether or not any data ever left the network.
Ransomware groups increasingly run both plays at once: they encrypt systems to force an outage and quietly copy data beforehand to use as leverage. Luminis Health hasn’t said whether that happened here, and until the investigation concludes, the honest answer is that the outage and the exposure question are two separate open items, not one confirmed event.
A Pattern Going Back to Change Healthcare
Healthcare has been the most disruptive sector for ransomware and cyber incidents in the US for several years running, and the numbers back that up even where they’re trending down. Per HIPAA Journal’s tracking, almost 34 million individuals had protected health information exposed, stolen, or impermissibly disclosed in 2026 through the data available so far, a 37.7% drop from the 54.4 million-person high in 2024 and a 22.1% decline from 2025. Ransomware groups were still behind 201 confirmed healthcare attacks in the first quarter of 2026 alone, and regulators logged 252 large breaches with the Office for Civil Rights through the end of April.
Change Healthcare remains the reference point for how bad a single incident can get: a February 2024 attack, attributed to the BlackCat ransomware group, eventually grew to a confirmed 192.7 million affected individuals once UnitedHealth Group finished its count in 2025, according to Paubox’s reporting on the final HHS tally. That breach also disrupted claims processing for hospitals and pharmacies across the country for weeks, a downstream effect that echoes, at a smaller scale, what Luminis Health’s own patients experienced with paper charting.
The MyChart Factor: One Vendor, Thousands of Hospitals
MyChart is built by Epic Systems, one of the largest electronic health record vendors in the country, and it’s the patient-facing portal at a large share of US hospitals and health systems. That shared software layer is part of why a single-system outage like this one draws national attention rather than staying a local story.
It also means the fix for one hospital’s MyChart problem doesn’t come from Epic pushing a patch. Luminis Health’s outage was rooted in its own network, not in the MyChart software itself, so the recovery timeline depended entirely on how fast Luminis Health’s own IT and security teams, working with outside cybersecurity experts, could rebuild trust in the surrounding systems before reconnecting the portal.
Market and Regulatory Impact
A month-long portal outage at a regional health system doesn’t move markets the way a breach at a national claims clearinghouse does. But it adds to a cumulative pressure that insurers, regulators, and hospital boards are all tracking closely in 2026, especially with several other health-data disclosures already on the books this year.
Cyber insurance pressure
Every hospital-system outage that stretches past a week or two reinforces underwriters’ case for tighter terms and higher premiums on healthcare cyber policies, a trend insurers have been pushing since Change Healthcare. Luminis Health hasn’t disclosed whether it carries cyber insurance or what its claims process looks like, but the length of this outage, four weeks from disclosure to portal restoration, sits at the longer end of what health systems have reported this year.
Regulatory scrutiny under HIPAA
If Luminis Health’s investigation eventually confirms that patient data was accessed, the health system would need to notify the HHS Office for Civil Rights and affected individuals under the federal health breach notification framework. So far, the health system’s public statements have focused on operational recovery rather than a breach notification, consistent with its position that the record-storage system wasn’t affected. That position will face more scrutiny if the investigation later broadens.
What Security Teams Should Take From This
For security and IT leaders outside healthcare, the Luminis Health incident is a reminder that patient-portal and telephony outages can persist for weeks even when the core data layer is reportedly untouched. Segmenting patient records from front-end access systems clearly helped limit the worst-case scenario here, at least based on what’s been disclosed. It didn’t, however, prevent a month of degraded service.
The broader trend is one this site has covered repeatedly this year: attackers increasingly favor slower, quieter exfiltration methods over smash-and-grab encryption, a shift detailed in shattered.io’s look at encrypted exfiltration tactics. Whether that pattern applies here is unconfirmed, since Luminis Health hasn’t named a technique or an attacker, but the extended, methodical recovery timeline is consistent with incidents that require a full network rebuild rather than a quick patch.
Predictions: Where This Goes From Here
- Expect Luminis Health to publish a more detailed incident summary, and possibly a formal breach notification, once its third-party forensic review concludes, likely within the next one to two months.
- The litigation referenced by Fox Baltimore will probably expand into additional filings if any patient data is confirmed accessed, following the pattern seen with Gold Star Mortgage’s BrainCipher lawsuit earlier this year.
- Backfilling scanned records into MyChart will likely take several more weeks beyond the portal’s relaunch, based on how long similar EHR catch-up efforts have taken at other health systems after comparable outages.
- Regional and mid-size health systems will keep facing outsized scrutiny in 2026 even as overall breach volumes fall, since HIPAA Journal’s own data shows ransomware groups still drove 201 healthcare attacks in Q1 alone.
- Cyber insurers will likely cite incidents like this one, alongside Astrana Health’s and DC Medicaid’s disclosures, when justifying renewal terms for healthcare clients at their next policy cycle.
What Patients Should Do Now
Patients with a Luminis Health MyChart account can log back in to manage appointments, refill requests, and provider messages. Anyone who had a lab test, scan, or visit during the September outage window and doesn’t see results yet shouldn’t assume the data is lost. Luminis Health has said that information is still being scanned into the system.
It’s reasonable for patients to watch for a formal notification letter in the mail or email if the investigation later determines personal or medical information was accessed. Until Luminis Health says otherwise, the health system’s position is that the record-storage system itself wasn’t affected, but that finding hasn’t been independently confirmed by a third party in public reporting so far.
Frequently Asked Questions
Is MyChart back online for Luminis Health patients?
Yes. Luminis Health restored MyChart for patient use on September 29, 2026, along with phone service across all its locations.
When did the Luminis Health cyberattack start?
Luminis Health first disclosed the cybersecurity incident on September 1, 2026. The MyChart outage lasted roughly four weeks.
Did hackers access patient records at Luminis Health?
Luminis Health says the incident did not affect the system that stores patient records. The investigation is ongoing, and whether any data was accessed hasn’t been publicly confirmed.
What can patients do in MyChart now?
Patients can schedule appointments, request prescription refills, message providers, and access parts of their health information.
What information might still be missing from MyChart?
Luminis Health says some patient notes, lab results, and imaging results generated during the outage may not yet appear, as that data is still being scanned into the system.
Who was behind the Luminis Health cyberattack?
Luminis Health has not named who is responsible. That detail remains unconfirmed as the investigation continues with legal counsel and third-party cybersecurity experts.
Has Luminis Health faced legal action over the breach?
Local reporting from Fox Baltimore has tied the incident to litigation touching Luminis Health’s Maryland service area, though specific case details were not available in the coverage reviewed for this article.
How does this compare to the Change Healthcare breach?
Change Healthcare’s 2024 breach is far larger in scale, with a final confirmed count of 192.7 million affected individuals, making it the largest healthcare breach ever reported to HHS. Luminis Health hasn’t published a patient count, and its own statements say the record-storage system was not affected.




