Cybersecurity downtime resilience: the metric boards now need
A multi-day outage at Luminis Health pushed clinicians back to paper charts and rerouted patients, showing why restoration time, not breach count, is the number healthcare boards should be watching.

When physicians at Luminis Health went back to paper charts and some patients were rerouted to other facilities, the story stopped being about a breach notice and became a question of healthcare cybersecurity downtime resilience. The Annapolis-based system disclosed the incident Sept. 1, and days later it had not said which systems remained offline or when full restoration was expected. For boards, that gap is the number that matters.
Becker's Hospital Review reporting and the HHS Office for Civil Rights breach portal. These are three reporting points across two separate incidents, not a time trend. The final two bars are the same Unlimited Systems incident at two disclosure stages.
| Value (individuals affected) | Individuals affected |
|---|---|
| Xsolis, reported June (7 health systems) | 1400000 individuals affected |
| Unlimited Systems, initial disclosure July | 442000 individuals affected |
| Unlimited Systems, figure posted by OCR August | 3800000 individuals affected |
What the Luminis Health outage actually disrupted
Luminis Health operates three hospitals, including Anne Arundel Medical Center, plus roughly 100 ambulatory sites across the Annapolis region, according to Becker's Hospital Review. The disruption was clinical rather than administrative: clinicians shifted to paper charting and some patients were rerouted while electronic systems stayed degraded.
The timeline matters as much as the scope. The Maryland Department of Health told WBAL-TV that the system flagged technology issues causing a reroute on Aug. 31, a day before public disclosure, and the Capital Gazette reported community members had already noticed systems down. State agencies have since met with Luminis leadership. As of the reporting available, the system has not confirmed ransomware, has not published a restoration date, and its review of whether patient data was affected remains ongoing.
None of those unknowns change the operational reality on the floor. Every hour on downtime procedures is an hour of slower order entry, manual medication reconciliation, delayed results and rebuilt documentation later. The incident label is a compliance artifact. The clock is the clinical event.
The incident notice is a compliance artifact. The operational clock is the clinical event.
Why breach counts are the wrong board dashboard metric
Most hospital board packets still lead with prevention and breach tallies: phishing click rates, patched vulnerabilities, number of reportable incidents. Those measures say almost nothing about whether the organization can keep admitting, operating and billing during a multi-day outage.
A downtime-first dashboard looks different. It carries mean time to clinical restoration by application tier, cumulative divert hours, days on paper charting, elective procedures postponed and the revenue cycle backlog created while systems were dark. Those figures are auditable, they translate directly into patient access and cash flow, and they give directors a way to ask a question management can actually answer.
The framing is not theoretical. After the March cyberattack on medtech firm Stryker's internal Microsoft environment, Loma Linda University Health changed how it manages Microsoft 365 and Intune access. Michigan Medicine CISO Jack Kufahl told Becker's the lesson was resiliency practice: downtime procedures and cross-organization communication, tested before they are needed.
Vendor incidents keep growing after the first disclosure
The second governance problem is that the exposure numbers leaders plan against are frequently provisional. Health IT vendor Unlimited Systems suffered a ransomware attack that encrypted systems in the datacenter hosting its g4-Centricity for Vector platform, forcing suspension of hosted access. Exposed data included Social Security numbers, medical record numbers, diagnosis details and scanned IDs, though the company said full records, imaging and financial account numbers were not involved.
The scale then moved. Unlimited Systems reported its total to the HHS Office for Civil Rights on July 21, and the figure OCR posted in August was roughly 8.6 times the initial disclosure, ranking it among the largest health data breaches reported this year. For a chief risk officer, that is a planning lesson: treat a vendor's first count as a floor, not a figure, and structure notification budgets and call-center capacity accordingly.
Health systems also inherit these events without ever having signed the contract. AI utilization vendor Xsolis reported an incident affecting seven health systems. The exposure arrives through a subcontractor, a hosted platform or a business associate of a business associate, which is precisely where most third-party inventories thin out.
Two governance moves for the next board cycle
First, add restoration time and divert hours to the enterprise risk dashboard next to breach counts, with a named executive owner and a tested target. If the organization cannot state how long its EHR downtime procedures are validated to hold, that is the finding.
Second, add a column to the third-party inventory that answers a single question: what breaks clinically if this vendor goes dark? Sort by that answer rather than by contract value. Transcription, imaging exchange, utilization review and revenue cycle platforms often outrank far larger spend categories once you score them on clinical dependency.
Both moves align with existing reference points leaders can cite in committee, including the HHS Healthcare and Public Health Cybersecurity Performance Goals, joint AHA and FBI advisories, and rating-agency work on cyber-driven operating disruption. The point is not another framework. It is making recovery a number the board sees every quarter.


