NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Luminis Health Working to Restore Systems After Cyberattack

Luminis Health in Maryland is investigating a cyberattack that has taken certain systems offline. Data breaches have been announced by Texas Orthopedic surgeon Jeffrey David Reuben, M.D, Well Child in Tennessee, and Horizon Eye Care Laser & Eye Surgery Center in New Jersey.

Luminis Health, Maryland

Luminis Health, a nonprofit health system that includes Anne Arundel Medical Center in Annapolis and Doctors Community Medical Center in Lanham, announced on September 4, 2026, that it has fallen victim to a cyberattack. The incident has affected both hospitals, which continue to serve patients, although certain appointments have had to be rescheduled. Currently, the phone system and MyChart patient portal remain offline.

Luminis Health said the priority continues to be providing safe, high-quality care to patients; meanwhile, third-party cybersecurity and legal experts have been engaged to investigate and rectify the incident and safely and securely restore access to the affected systems. The health system is currently unable to provide a timeline for how long those processes will take, and it is too soon to tell what extent, if any, that patient data was involved. Should it be determined that patient data was exposed or stolen, patients will be notified in due course. At present, no ransomware or data extortion group appears to have claimed responsibility for the attack.

Jeffrey David Reuben, M.D.

Jeffrey David Reuben, M.D., a Texas-based orthopedic surgeon serving patients at NW Surgery in Houston and medical centers in Bellaire, has recently reported a data security incident that has affected 17,017 current and former patients. The incident was identified on or around April 27, 2026, and assisted by third party cybersecurity professionals, it was confirmed that an unauthorized third party accessed systems containing patient information between April 18 and April 19, 2026.

The investigation and data review were completed on or around July 15, 2026, when it was confirmed that the exposed data included names, Social Security numbers, driver’s license numbers, government-issued ID numbers, and financial information. While no actual or attempted misuse of the affected data has been identified, the affected individuals have been offered complimentary credit monitoring and identity theft protection services for 12 months.

Well Child

Well Child, a provider of school-based healthcare services through partnerships with school districts in Tennessee and Mississippi, has announced a cybersecurity incident that was first identified on June 1, 2026. All servers were immediately taken offline when the incident was identified to prevent further unauthorized access, and an investigation was launched to determine the nature and scope of the unauthorized activity. On June 5, 2026, the investigation confirmed that files containing sensitive personal information had been exfiltrated from a temporary storage server.

The investigation and data review are ongoing; however, it has been determined that the exfiltrated data included Vision Screening Reports, Vision Screening Data Files, Available Students Lists, and PEDS (Parents’ Evaluation of Developmental Status) assessment documents. In addition to student names, the files contained protected health information such as birth dates, medical record numbers, provider names, diagnoses, assessment/test results, treatment dates, and billing and/or procedure codes. For a limited number of individuals, Social Security numbers were also involved. The incident has been reported to the HHS’ Office for Civil Rights using a placeholder figure of at least 500 individuals. The total will be updated when the data review is concluded.

Horizon Eye Care Laser & Eye Surgery Center

Horizon Eye Care Laser & Eye Surgery Center, an ophthalmology practice and eye surgery center with six locations in New Jersey, is investigating a network server hacking incident. Suspicious network activity was identified on or around June 8, 2026. Immediate action was taken to isolate the affected systems, and third-party cybersecurity experts were engaged to investigate the incident.

The investigation and data review are ongoing; however, it has now been confirmed that patient data was compromised in the incident, including names, demographic information, treatment information, and health insurance information. The breach has been reported to the HHS’ Office for Civil Rights using a placeholder figure of at least 501 affected individuals, as the number of affected individuals has yet to be determined.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist