AnMed Temporarily Closes 79 Facilities Following Cybersecurity Disruption

AnMed has temporarily closed 79 of its 106 facilities after a cybersecurity disruption involving malware affected its information technology systems and interrupted computer systems, phone lines, and Internet connectivity.

Cybersecurity Disruption Affected Multiple Systems

AnMed, formerly AnMed Health, is a nonprofit health system that serves patients in upstate South Carolina and Northeast Georgia. On Sunday, July 26, 2026, the health system confirmed that it experienced a cybersecurity disruption involving malware. The incident affected information technology operations and resulted in outages involving computer systems, phone lines, and Internet connectivity.

The disruption led AnMed to temporarily close AnMed Medical Group offices and AnMed Imaging Services on Monday. The temporary closures affected 79 of the organization’s 106 facilities.

AnMed stated that several patient care locations continued operating despite the disruption. AnMed Urgent Care locations, AnMed Kids Care, AnMed Laboratory Services, and AnMed Integrated Therapy locations were scheduled to open.

The health system also stated that care teams remained on site and continued providing treatment in the emergency room while office closures remained in effect.

The cybersecurity disruption affected patient services across the health system. Some scheduled appointments were postponed because of the operational impact. Patients with elective procedures scheduled for Monday were contacted directly to inform them whether their procedures would proceed as planned or require postponement.

AnMed stated that decisions involving procedures, patient transfers, diversions, and operational processes were being made with patient safety serving as the guiding principle.

AnMed stated that it was coordinating with emergency medical services, regional hospitals, and public safety partners while responding to the disruption. The coordination was intended to help patients receive care in the most appropriate setting while operational limitations remained in place.

Recovery Efforts Remain Underway

AnMed stated that cybersecurity partners were working to restore access to systems and data as quickly as possible. The health system could not provide a timeline for recovery of computer systems, reopening of offices, or restoration of normal services. Operational updates for the coming days will be provided through the organization’s website.

AnMed launched an investigation to determine the nature and scope of the cybersecurity incident. It is still too early to determine whether patient data was involved or to what extent any information may have been affected. If confirmed, the OCR and affected patients will be notified.  No threat group appeared to have claimed responsibility for the incident to date.

About Thomas Brown
Thomas Brown worked as a reporter for several years on ComplianceHome. Thomas is a seasoned journalist with several years experience in the healthcare sector and has contributed to healthcare and information technology news publishers. Thomas has a particular interest in the application of healthcare information technology to better serve the interest of patients, including areas such as data protection and innovations such as telehealth. Follow Thomas on X https://x.com/Thomas7Brown