AnMed, a nonprofit health system serving upstate South Carolina and northeast Georgia, closed 79 of its 106 facilities on Monday after a cyberattack knocked out computer systems, phone lines and internet connectivity across its network, one of the more disruptive assaults on an American hospital operator this year. Emergency departments at the system's Cannon, Medical Center and Piedmont campuses remained open, but imaging centers, OBGYN and primary care clinics, and all medical group offices went dark while investigators assessed the damage, according to the HIPAA Journal.
Trouble began on Sunday, July 26, when patients and staff across all AnMed locations lost phone and internet service, Fox Carolina reported. Later that day the health system confirmed the outage was not an accident, describing in a website notice a cybersecurity disruption "involving malware" and announcing sweeping closures for the following day, according to The Record. AnMed operates four hospitals and more than 60 physician practices across its two-state footprint, anchored by its flagship medical center in Anderson, South Carolina.
Ransom Deadline Reported on Hospital Screens
AnMed has not publicly characterized the incident as ransomware, but patient accounts suggest extortion is in play. Healthcare IT News reported that a message displayed on hospital computers gave AnMed 72 hours to respond to demands, with a patient recounting that the attackers threatened to leak personal information belonging to everyone in the system if payment was not made. As of Monday, no cybercrime group had claimed responsibility on dark web leak sites, the outlet reported, and AnMed has not disclosed whether patient data was accessed or taken.
Officials said the system is working with third-party cybersecurity specialists as well as state and federal authorities to investigate and restore operations, per Fox Carolina. No timeline has been offered for reopening the shuttered facilities, and the HIPAA Journal reported that decisions about procedures would be made "with patient safety as the guiding principle." Scheduled appointments were postponed, elective procedures were rescheduled, and the system said affected patients would be contacted directly.
Silence on attribution is typical at this stage of a hospital intrusion. Ransomware groups frequently delay claiming victims while negotiations are active, and victims avoid confirming extortion demands to preserve leverage. If negotiations collapse, a listing on a leak site with sample data often follows. That sequence has played out at dozens of American health systems over the past three years, which is why the 72-hour deadline described by patients is being read by security observers as a familiar opening move rather than an anomaly.
Care Diverted Toward Greenville
While emergency rooms stayed open with care teams on site, the loss of digital infrastructure forced AnMed to move some patients elsewhere. Staff accounts cited by Fox Carolina described ambulances and transfers being redirected to hospitals in Greenville, including facilities operated by Prisma Health, roughly 30 miles from AnMed's Anderson base. Urgent care locations, AnMed Kids Care, integrated therapy and laboratory services continued operating. AnMed said it was coordinating closely with emergency medical services, regional hospitals and public safety partners to keep patients in appropriate care settings, according to The Record.
This report is open to every reader. Subscribers unlock the full Speedway Scene archive and keep independent, rigorous journalism on the forces that move markets and power on its feet. Get the Briefing
Diversions of this kind carry clinical stakes that outlast the outage itself. Studies of prior hospital ransomware incidents have documented longer ambulance runs, delayed treatment for time-sensitive conditions such as stroke and cardiac arrest, and spillover strain on neighboring facilities that absorb the redirected volume. Federal agencies now treat attacks on hospitals as threats to patient safety rather than purely data crimes, and the AnMed cyberattack fits the pattern that produced that shift: a regional system with a large rural catchment area, suddenly operating on paper while its nearest large-city alternative sits half an hour away.
Healthcare Remains the Costliest Target
AnMed joins a lengthening list of health systems disrupted by intrusions in 2026, and the economics explain the targeting. Healthcare breaches averaged 7.4 million dollars per incident in 2025, the highest of any industry for the twelfth consecutive year, according to an IBM report cited by The Record. Detection and containment in healthcare took an average of 279 days, roughly five weeks longer than in other sectors, a gap attributed to sprawling networks of legacy medical devices, thin security staffing and the impossibility of taking clinical systems offline for routine maintenance.
Precedent also explains the anxiety. The 2024 attack on Change Healthcare, the claims-processing arm of UnitedHealth Group, disrupted payments across much of the American healthcare system and ultimately exposed data belonging to a substantial share of the US population. The same year, an intrusion at Ascension, one of the country's largest Catholic health systems, forced nurses onto paper charting for weeks. Both episodes pushed federal regulators toward tougher expectations for hospital cybersecurity, though mandatory baseline standards remain a work in progress. Hospital operators face a pressure that most ransomware victims do not: every hour of downtime degrades patient care, and attackers price that urgency into their demands. Federal advisories urge health systems against paying, noting that payment funds further attacks and offers no guarantee stolen data is destroyed.
Recovery Will Be Measured in Weeks
For now, AnMed's public guidance directs patients to check its website for facility status and to use emergency departments for urgent needs. If precedent holds, restoration will proceed in phases, with clinical systems validated individually before facilities reopen. Under federal health privacy rules, a formal breach notification to regulators and affected individuals would follow within 60 days of confirming that protected health information was compromised, and class action attorneys began advertising for potential AnMed clients within a day of the disclosure, according to ClassAction.org.
Questions that will define the severity of the AnMed cyberattack remain open: how the intruders got in, how much data left the network, and whether the system engages with the extortion deadline reported by its own patients. What is already clear is the operational lesson. One intrusion took nearly three quarters of a regional health system's facilities offline in a single day, and the safety net for its patients depended on hospitals 30 miles up the road.