Patients at Luminis Health are suing the Maryland system while its networks remain partly dark, nearly three weeks after the first signs of a cyberattack.
Three patients filed a proposed class action in federal court, accusing the Annapolis-based nonprofit of storing sensitive details in an “unencrypted, Internet-accessible environment.” The complaint argues those affected now face elevated risks of identity theft, fraud and lost medical privacy. Luminis says the systems that store and host patient records were untouched, and that it will notify anyone whose protected information turns out to be involved.
Operationally, the system that runs Anne Arundel Medical Center and Doctors Community Medical Center in Lanham is still limping. Phone lines are back, but the patient portal stays down, delaying some elective care and blocking access to test results. Executives have offered no restoration timeline and no attribution for the intrusion, which surfaced publicly on September 1.
Analysts caution that the lawsuit still has to clear a high bar. Anupam Joshi, who directs the UMBC Cybersecurity Institute, said plaintiffs must show their information was actually reached and that real harm followed, and that the intruder’s intent remains unclear – whether data theft, ransomware or simple disruption.
For hospitals, the case is a reminder that downtime itself carries legal exposure, and that HIPAA notification windows can run up to 60 days once data loss is confirmed.