Utopia Tech
Healthcare3 min read

Luminis Health Working to Restore Systems After Cyberattack

Luminis Health in Maryland is investigating a cyberattack that has taken certain systems offline. Data breaches have been announced by Texas Orthopedic surgeon Jeffrey David Reuben, M.D, Well Child in Tennessee, and Horizon Eye Care Laser & Eye Surgery Center in New Jersey. Luminis Health, Maryland Luminis Health, a nonprofit health system that includes Anne Arundel Medical Cen

UT

Utopia Tech

September 7, 2026 · 3 min read

Share

Luminis Health in Maryland is investigating a cyberattack that has taken certain systems offline. Data breaches have been announced by Texas Orthopedic surgeon Jeffrey David Reuben, M. D, Well Child in Tennessee, and Horizon Eye Care Laser & Eye Surgery Center in New Jersey.

Luminis Health, Maryland Luminis Health, a nonprofit health system that includes Anne Arundel Medical Center in Annapolis and Doctors Community Medical Center in Lanham, announced on September 4, 2026, that it has fallen victim to a cyberattack. The incident has affected both hospitals, which continue to serve patients, although certain appointments have had to be rescheduled.

Currently, the phone system and MyChart patient portal remain offline. Luminis Health said the priority continues to be providing safe, high-quality care to patients; meanwhile, third-party cybersecurity and legal experts have been engaged to investigate and rectify the incident and safely and securely restore access to the affected systems. The health system is currently unable to provide a timeline for how long those processes will take, and it is too soon to tell what extent, if any, that patient data was involved.

Should it be determined that patient data was exposed or stolen, patients will be notified in due course. At present, no ransomware or data extortion group appears to have claimed responsibility for the attack. Jeffrey David Reuben, M.

D. Jeffrey David Reuben, M. D.

, a Texas-based orthopedic surgeon serving patients at NW Surgery in Houston and medical centers in Bellaire, has recently reported a data security incident that has affected 17,017 current and former patients. The incident was identified on or around April 27, 2026, and assisted by third party cybersecurity professionals, it was confirmed that an unauthorized third party accessed systems containing patient information between April 18 and April 19, 2026.

Get The FREE HIPAA Compliance Checklist Immediate Delivery of Checklist Link To Your Email Address Please enable JavaScript in your browser to complete this form. Business Email * Name * First Last Number * Company Name * Get Free Checklist Please Enter Correct Email Address Your Privacy Respected HIPAA Journal Privacy Policy The investigation and data review were completed on or around July 15, 2026, when it was confirmed that the exposed data included names, Social Security numbers, driver’s license numbers, government-issued ID numbers, and financial information.

While no actual or attempted misuse of the affected data has been identified, the affected individuals have been offered complimentary credit monitoring and identity theft protection services for 12 months. Well Child Well Child, a provider of school-based healthcare services through partnerships with school districts in Tennessee and Mississippi, has announced a cybersecurity incident that was first identified on June 1, 2026.

All servers were immediately taken offline when the incident was identified to prevent further unauthorized access, and an investigation was launched to determine the nature and scope of the unauthorized activity. On June 5, 2026, the investigation confirmed that files containing sensitive personal information had been exfiltrated from a temporary storage server.

The investigation and data review are ongoing; however, it has been determined that the exfiltrated data included Vision Screening Reports, Vision Screening Data Files, Available Students Lists, and PEDS (Parents’ Evaluation of Developmental Status) assessment documents. In addition to student names, the files contained protected health information such as birth dates, medical record numbers, provider names, diagnoses, assessment/test results, treatment dates, and billing and/or procedure codes.

For a limited number of individuals, Social Security numbers were also involved. The incident has been reported to the HHS’ Office for Civil Rights using a placeholder figure of at least 500 individuals. The total will be updated when the data review is concluded.

Horizon Eye Care Laser & Eye Surgery Center Horizon Eye Care Laser & Eye Surgery Center, an ophthalmology practice and eye surgery center with six locations in New Jersey, is investigating a network server hacking incident. Suspicious network activity was identified on or around June 8, 2026. Immediate action was taken to isolate the affected systems, and third-party cybersecurity experts were engaged to investigate the incident.

The investigation and data review are ongoing; however, it has now been confirmed that patient data was compromised in the incident, including names, demographic information, treatment information, and health insurance information. The breach has been reported to the HHS’ Office for Civil Rights using a placeholder figure of at least 501 affected individuals, as the number of affected individuals has yet to be determined.

The post Luminis Health Working to Restore Systems After Cyberattack appeared first on The HIPAA Journal .

Originally published at hipaajournal.com

Share
▸ Want a deeper look?

Talk to an architect about applying this to your stack.

60-minute technical evaluation, no obligation. We'll map the ideas in this article to your environment.

Skip to main content