Luminis Health
bd_1cddbce7a40d7984 · schema v1 · pii pii-v1
Full breach record for Luminis Health →Luminis Health, Inc., a Maryland-based non-profit healthcare provider, notified the Maryland Attorney General of a security incident affecting approximately 349 Maryland residents. An unauthorized party accessed the company's payroll software system on or about December 11, 2024, by obtaining access to a third-party consultant's account. The incident potentially exposed personal information including names, bank account and routing numbers, and Social Security numbers. Luminis Health contained the incident, engaged cybersecurity experts, and is offering one year of complimentary credit monitoring to affected individuals.
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376543.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 12, 2025
- Raw hash
- c1b4bb9141ed9b1f20f1bde562c860e2b4b50f85717ec01b6bf05bc538b5463e
Reporting entity
- Name
- MCDONALD HOPKINS LLCnorm: mcdonald hopkins
Victim entity
- Name
- Luminis Healthnorm: luminis health
- Domain
- luminishealth.org
Incident
- Discovered
- Dec 16, 2024
- Materiality determined
- —
- Notification sent
- Mar 11, 2025
- Affected individuals
- 349
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Maryland Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 12 weeks(86 days from discovery to filing)
- Compliance flags
- MD AG >30d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.