Yaamlabs
Resilience

Luminis Health's 28-day outage and the paper fallback

Two Maryland hospitals ran on paper for four weeks after a cyber incident. What Luminis restored first, what is still unknown, and how to plan EHR downtime.

By Yaali. October 1, 2026, 7 min read, Resilience, Threat intel.

Cover illustration of a dark hospital nurses' station with a blank monitor and a lamp lighting a stack of paper charts, with the Yaamlabs logo and the text: Two Maryland hospitals ran on paper for four weeks, Day 17, patient portal back, read-only first

Luminis Health brought its MyChart patient portal fully back online on September 29, 28 days after it disclosed a cyber incident on the evening of September 1. Luminis runs Anne Arundel Medical Center in Annapolis and Doctors Community Medical Center in Lanham, and serves Anne Arundel and Prince George's counties and Maryland's Eastern Shore. For most of September, staff worked from paper medical records, phone lines were down for more than two weeks, and for several days ambulances carrying noncritical patients were sent to other hospitals. Both emergency departments stayed open throughout.

Almost nothing about the attack itself is public. Luminis has not said how the attackers got in, whether it was ransomware, or whether patient data was taken, and no ransomware or extortion group had claimed it as of September 30. The recovery, though, is well documented, and a four-week outage is longer than most hospital downtime plans are written for.

Timeline of the Luminis Health outage from disclosure on September 1 to full MyChart restoration on September 29, with what is still undisclosed

What is known, and what is not

Luminis says the incident "did not affect the system that stores our patient records". That statement is about the record store only. It says nothing about whether clinicians could reach the EHR, and Luminis still ran on its downtime procedures, including paper records, for most of the month.

The recovery came back in three visible stages. Telephone service returned across all locations by September 17, after more than two weeks. On September 18 MyChart came back in read-only mode: patients could view their information, but scheduling and messaging stayed off. On September 29 scheduling, prescription refill requests and provider messages returned. Notes, lab results and imaging produced during the downtime are still being scanned and added, so some of it may not show in MyChart yet.

The investigation is being run with legal counsel and outside cybersecurity experts, and Luminis says it is still determining "the nature and scope of the incident". Patients have already filed a class action lawsuit claiming the health system failed to protect their data.

Why the recovery order matters

MyChart is the patient portal for Epic's electronic health record (EHR), so the portal is a front end to the same clinical system staff use. Bringing it back read-only first is the sensible pattern after an intrusion. Viewing data from a restored system carries little risk, while letting thousands of users and connected systems write to it before it is trusted can spread a bad restore into new orders, messages and appointments. A read-only period gives the team time to find problems first.

The phones coming back before the portal matters too. For more than two weeks patients could not book, ask for refills or message their doctor, and for most of that time they could not phone the office either. Luminis later told patients to phone their doctor's office directly for scheduling, test results and prescriptions, which only works once the phones are up. The incident shows how much of a hospital's patient communication shares fate with its IT network. Luminis has not said whether its phones run on voice over IP (VoIP), so treat the dependency as a question to ask of your own setup.

The slowest stage is getting four weeks of paper back into the record. Every order, medication given, lab result and note written during downtime has to be entered or scanned, and every patient registered under a temporary number has to be merged with the right chart. Luminis was still doing this after the portal came back.

What a downtime plan should already have

The federal SAFER Guides (Safety Assurance Factors for EHR Resilience), updated in 2025 by ASTP/ONC, the office at the US Department of Health and Human Services that sets health IT policy, include a Contingency Planning checklist.

Downtime readiness checklist from the 2025 SAFER Contingency Planning guide, split into before, during and recovery, with five key timing targets

Paper and read-only access. Each patient care area should hold enough paper forms for at least 8 hours, covering orders and the administration of medications, lab and radiology tests. A read-only backup copy of the EHR should be refreshed at least hourly, tested at least weekly, and able to print. In Epic sites this is Business Continuity Access (BCA): a shadow read-only copy of the full chart, a BCA Web view of limited data, and BCA PCs that hold printable downtime reports up to the moment the outage started. All three are read-only by default, so most documentation still goes on paper. Check that clinicians know the separate downtime logins, and that BCA PCs sit on an uninterruptible power supply (UPS) or a generator-backed outlet.

Communication that does not share the network. The guide says to notify staff by a method that does not rely on the EHR's own infrastructure, and names email, the website and VoIP as examples of what not to rely on. A mobile phone call tree is its example of what works. Keep a paper copy of the downtime and recovery policy on every clinical unit and another off site.

Backups an attacker cannot reach. SAFER asks for a daily, off-site, encrypted, complete backup of patient data; full restore tests, ideally monthly; multiple backups taken at different times; and backup media separate from normal storage, such as an air gap, so ransomware cannot reach them. Back up system configuration too, ideally monthly and before every upgrade, since restored data is no use until the application settings around it are rebuilt.

A warm site and a clock. Large 24-hour organizations should have a warm site that can run the whole EHR within 8 hours, tested at least quarterly, and the downtime policy should say when to switch to it, ideally before the system has been down for 2 hours. After an intrusion a warm site that replicates from production may carry the same compromise, so the policy needs a separate branch for cyber events where the replica has to be checked before anyone fails over.

During and after: the parts that go wrong

Patient identification breaks first. Register new arrivals with unique temporary record numbers and keep the list of who got which number, so they can be reconciled to real charts later.

Interfaces are the second trap. Lab, pharmacy and imaging systems keep producing data while the EHR is down. SAFER asks for a current list of every system-to-system interface, reviewed every six months to a year; buffers large enough that queued messages are not lost; and a written procedure to stop and restart each interface in order, with buffers empty before the restart and a way to tell users when an interface is not working.

Back-entry needs its own owner and plan. Orders should be entered as coded data and the rest scanned. Luminis's experience suggests budgeting weeks, not days, for that backlog after a month on paper.

Finally, train staff for the social engineering that follows a public outage. Luminis warned patients to be careful with unsolicited calls or messages asking for personal or financial information, and SAFER asks that staff be trained to spot fraudulent callers asking for login access. Any downtime longer than 24 hours should get a formal root-cause review with clinicians and IT in the room.

What to check this quarter

Run an unannounced downtime drill; SAFER asks for at least one a year. Time how long it takes a nurse on a night shift to find the downtime login, print a medication administration report from a BCA PC, and place an order on paper. Then run a tabletop exercise for a 28-day outage with phones down for the first two weeks. Note when paper forms run short, who answers patients when the phones are dead, and how many staff hours the back-entry would take.

Our on-demand risk reduction work reviews downtime and recovery plans against exercises like this, and our security operations team watches for the early signs of an intrusion before it becomes an outage. Open the chat and Yaali, our AI agent, will pass your question to an engineer.


Sources: Luminis Health cybersecurity incident update, The Baltimore Banner, The Baltimore Banner, MyChart restored, CBS News Baltimore, WYPR, September 2, WYPR, September 22, WTOP, Becker's Hospital Review, HIPAA Journal, Tech Insider, ASTP/ONC SAFER Guide: Contingency Planning, Surety Systems, Epic downtime overview, University of Iowa, Epic BCA Web.

Read next

Back to the blog, or tell us about your system in the chat. Yaali, our AI agent, answers first and brings in an engineer.