Three hospitals within the Johns Hopkins Health System were listed under “Code Black” status for a stretch Tuesday afternoon, which effectively closed the emergency departments to patients arriving by ambulance, according to the Maryland Emergency Department Advisory System.

It was the second time in two days the emergency departments were listed.

The status first went into effect about 10:30 a.m. Monday at Howard County Medical Center in Columbia, Suburban Hospital in Bethesda and Sibley Memorial Hospital in Washington, D.C., according to the statewide dashboard.

Services returned to normal by about 3 p.m. as Hopkins officials dealt with a system-wide, information-technology issue, a hospital official said. The emergency department status at its two hospitals in Baltimore were unchanged.

Advertise with us

A day later, the three hospitals were again closed to ambulances due to the same IT issue, though a Hopkins official said the issues were resolved and all emergency departments were expected to reopen fully in the evening.

The state defines Code Black as when a hospital’s “emergency department is effectively closed to EMS traffic due to unsafe conditions (e.g., utility failure, fire, other threat).”

Patients typically are sent to other nearby emergency departments, though the hospitals can still accept critical patients who need immediate attention. The hospitals did not turn away walk-in patients, and the emergency departments did not close, hospital officials had said.

“We have restored full functionality. This was not a cyber-attack,” Kim Hoppe, a hospital system spokeswoman, said in a statement after the first closure.

The events over two days highlight hospitals’ heavy and increasing reliance on technology. They came about a week after other hospitals in the state rerouted emergency patients following a cyberattack.

Advertise with us

The attacks at Anne Arundel Medical Center in Annapolis and Doctors Community Medical Center in Lanham were confirmed by Luminis Health, the hospitals’ parent company. Officials there did not respond Tuesday to a request for an update on the situation.

In recent years, there have been other such cyberattacks, including at Saint Agnes in Baltimore in 2024 and Greater Baltimore Medical Center in 2020. Hopkins also suffered an attack in 2023.

In times when emergency departments need to close, or reduce the patient loads because they are over-capacity, the Maryland Institute for Emergency Medical Services Systems, which operates the dashboard, monitors conditions and deploys officers to help coordinate ambulances statewide to ensure patients get the most appropriate care as quickly as possible.

“EMS clinicians generally reroute patients to alternative hospitals unless the affected hospital remains the most appropriate destination for the patient’s needs,” said Todd Abramovitz, a spokesman for the state agency.

Other statewide offices coordinate with hospitals and others during emergencies but also at other times to make sure all the facilities are prepared, and defended if needed.

Advertise with us

The state agencies share information and analysis of cybersecurity threats, and “help organizations address vulnerabilities before threat actors can exploit them and cause a cybersecurity incident,” said Emma Ritter, a spokeswoman for the Maryland Department of Emergency Management, which was coordinating the response to the recent incidents.

The cyberattacks are concerning as they grow in scale and sophistication, according to the American Hospital Association.

Nationally, the association said, from 2020 to 2025, there were about 3,400 breaches reported to federal health authorities, impacting 730 million Americans, which officials said means every American has had at least some records stolen an average of two times.

About a third of the attacks have been ransomware attacks.

While hospitals remain a target, the majority of the attacks have targeted third-party providers. That included a highly disruptive 2024 attack on Change Healthcare, a nationwide technology firm owned by insurance giant UnitedHealth Group and broadly used by doctors, pharmacies and hospitals in Maryland.

Advertise with us

Officials at the medical association said that in addition to third-party and supply chain vulnerabilities, there also are now concerns related to political cyber activity and artificial intelligence’s potential to overcome cyber defenses.

Hospitals and health systems don’t typically disclose their internal security measures, and cyber crime experts have said that health systems have historically had fewer resources dedicated than the more fortified financial service sector.

Hoppe said in a statement that though the issues were not tied to a cyberattack, there are “robust emergency preparedness and downtime protocols in place that ensure the health system is able to maintain continuity in our operations and ability to continue to provide safe, high quality care in the event of a network outage, cellular interruption or other emergency event.”

This story has been updated.