
Two American hospitals in the state of Maryland have been hit by a cyberattack and have spent almost a month restoring patients' access to the facilities' online systems. We explain how it happened and what steps organizations should take to make their IT systems more secure.
What happened
In early September, a cyberattack disrupted the IT systems of the Luminis Health medical network in Maryland. The patient portal and the phone system became unavailable, doctors in some cases had to switch to paper charts, and some ambulances were diverted to other facilities. The phone system was later restored, but for some time the portal continued to work in view-only mode: patients couldn't book appointments or request prescriptions remotely.
It's still unknown whether the attackers gained access to the personal data of patients and employees. In its statement, Luminis Health doesn't say how exactly the hackers got into its systems or what data was compromised.
Why the healthcare sector is a target for cyberattacks
Medical institutions are an attractive target for hackers because of the large volume of sensitive information they hold. Their systems store ID details, contact information, diagnoses, and test results. This data can be used for blackmail and phishing attacks, or sold on the black market.
An additional risk comes from the complex and heterogeneous IT infrastructure of clinics. Hospitals may run modern systems alongside outdated software that is hard to update because of the risk of breaking compatibility with medical equipment. An even more mundane reason is that replacing such software is very expensive.
Outdated software almost certainly contains vulnerabilities that remain unpatched for a long time. Attackers can gain access to a clinic's entire internal network by exploiting a vulnerability in just one module.
With Kaspersky Premium, your personal data, payments, and devices stay protected from malware, phishing, and other online threats.
Try for freeThe scale of the problem
Medical institutions have been targeted by hackers many times before. For example, in February 2024, a cyberattack knocked out part of the infrastructure of Change Healthcare, a major technology intermediary in the US healthcare system.
Through the company's services, clinics, pharmacies, and insurers exchange data, submit insurance claims, and process payments for medical services. The company had to take some of its systems offline, which left healthcare providers across the country unable to send bills to insurers on time and get paid for care they had already delivered.
The disruption was so large that some clinics ran into cash flow problems, and federal authorities had to launch a program of advance payments to healthcare providers. It later emerged that the attackers had gained access to the personal and medical data of 193 million patients.
A similar story played out at the American hospital network Ascension in May 2024. After the cyberattack, the company had to take some of its IT systems offline: at a number of hospitals, staff temporarily switched to paper-based record keeping, and there were problems accessing electronic medical records and other internal services. Ascension later reported that the data of approximately 5.6 million people had been compromised in the attack.
Class action lawsuits and corporate liability
Besides financial losses, the companies faced litigation. In November 2024, legal proceedings began against Ascension: patients filed a class action lawsuit against the company, demanding monetary compensation and stronger data protection measures. The plaintiffs alleged that the company hadn't made sufficient efforts to protect its systems, which is how the data ended up in the hands of hackers.
In the United States, healthcare organizations are regulated under HIPAA, the Health Insurance Portability and Accountability Act. Its Security Rule requires hospitals, insurers, and their business partners to protect electronic health information with administrative, physical, and technical safeguards: run regular risk analyses, control access to systems, and monitor for unauthorized activity. This is especially important for healthcare organizations, since information about a person's health is among the most sensitive categories of personal data.
HIPAA also requires organizations to report breaches. Affected individuals must be notified without unreasonable delay and no later than 60 days after the breach is discovered, and the incident must be reported to the U.S. Department of Health and Human Services (HHS). Breaches affecting 500 or more people must also be reported to the media.
HIPAA violations carry serious financial and legal consequences. The HHS Office for Civil Rights (OCR) can impose civil penalties that scale with the organization's level of culpability, from violations it didn't know about to willful neglect that was never corrected. These amounts are adjusted annually for inflation. As of 2026, fines for the lower tiers range from $145 to $73,011 per violation, while willful neglect that isn't corrected within 30 days costs at least $73,011 per violation and up to about $2.19 million, which is also the annual cap for identical violations. In the most serious cases, knowingly obtaining or disclosing health information can lead to criminal prosecution, with prison terms of up to 10 years. State attorneys general can also bring enforcement actions over data breaches.
Useful articles:
- Preventing cyberattacks
- 10 tips for protecting your personal data online
- Handling personal data safely
Recommended products:
