AnMed
Incident posture
Timeline
Summary
AnMed experienced a malware cyberattack that disrupted its network, leading to the closure of numerous facilities, loss of phone and internet service, and the takedown of its MyChart patient portal. Emergency departments remained open while the health system operated under downtime procedures, using paper forms and rescheduling appointments, with some patients diverted to nearby hospitals. Suspicious communications resembling appointment reminders were reported to have originated outside the system, prompting warnings for patients to remain cautious. The FBI and state law enforcement are assisting an ongoing investigation to determine whether any patient data was compromised, though no evidence of malicious targeting has been found. Recovery efforts continue as specialists work to restore systems and normal services.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On July 26, 2026, AnMed experienced a cybersecurity disruption involving malware that caused a phone and internet outage across all hospital locations, prompting the health system to close its facilities while keeping emergency rooms open and care teams on site. The attack forced AnMed to take down its MyChart patient portal and other computer systems, leading to the initial closure of 83 facilities including outpatient imaging services, urgent care locations, kids care centers, integrated therapy sites, and laboratory services. Patients reported being unable to obtain discharge paperwork and described heightened anxiety due to the loss of electronic communications and records. AnMed announced the postponement of a groundbreaking ceremony for the AnMed Education and Technology Center, noting that construction remained on schedule despite the disruption.
In the days following the attack, AnMed implemented established downtime procedures, switching to manual processes such as paper forms and records to continue providing care where possible. By August 5, ten facilities remained closed a week after the incident, while others had reopened under limited operations, with patients experiencing delays, limited portal access, and rescheduled appointments. The health system warned patients on July 30 that appointment reminders generated outside of its internal systems might continue to be delivered by text message, advising that electronic confirmation was not required at that time. AnMed also launched a centralized phone line on August 2, staffed weekdays from 9 a.m. to 4 p.m., to handle scheduling, prescription refill, and non‑urgent medical concerns, and added dedicated billing numbers effective August 4 for patient inquiries.
To manage the situation, AnMed coordinated with emergency medical services, regional hospitals, and public safety partners to ensure patients received appropriate care, including ambulance diversions to other facilities when necessary. The health system provided ongoing updates via its website and stated that its doctors retained access to medical records, emphasizing that safe care remained the highest priority. AnMed reported that it had found no evidence of patients being targeted with malicious intent as a result of the incident, though it urged caution regarding electronic messages appearing to originate from the organization. The FBI’s Columbia field office and the South Carolina Law Enforcement Division were confirmed to be assisting with the investigation, which remained ongoing with no threat group claiming responsibility and no determination yet made about the extent of any patient data involvement.
Sources
Sources available to members: 7 sources.