AnMed Cyberattack Results in Temporary Closure of More Than 80 Facilities
AnMed, a nonprofit health system that serves patients in upstate South Carolina and Northeast Georgia, has been forced to close more than 80 of its facilities as a result of a cyberattack.
According to an announcement on the company website, the attack was detected on Sunday, July 26, 2026. The incident was not described as a ransomware attack, but rather an attack involving malware. Phone systems, Internet access, and its network were impacted, and the decision was taken to close 83 AnMed Medical Group offices and AnMed imaging services on Monday, July 27, 2026. AnMed’s urgent care, emergency services, laboratory services, and integrated therapy locations are remaining open.
AnMed explained that it is working diligently to assess the nature and scope of the incident and restore systems to full functionality safely and securely. AnMed said patients who had elective procedures scheduled for Monday will be contacted directly to advise them whether their procedures have been postponed or will proceed as scheduled. AnMed is working with emergency medical services, regional hospitals, and public safety partners to ensure patients receive the care they need.
Cyberattacks on healthcare providers often result in systems being taken offline, and when electronic medical records cannot be accessed, procedures are often postponed out of safety concerns. It is relatively unusual for such widespread closures of facilities. AnMed said that decisions are being made about procedures, patient transfers, diversions, and operational processes with patient safety as the guiding principle.
AnMed will issue operational plans for the coming days via its website, along with updates as the investigation and recovery progresses. “We are grateful to our healthcare partners across the region and to the Upstate community for their collaboration, patience and support,” AnMed said. “We also extend sincere thanks to its physicians, nurses, advanced practice providers, clinical teams and all employees whose professionalism, flexibility and extraordinary efforts are helping ensure patients continue to receive safe care during this response.”
Since the investigation is still in the early stages, it is too soon to tell whether patient data has been exposed. The threat group behind the attack is currently unknown.
