AnMed Closes Almost 80 Facilities While it Grapples with Cyberattack
AnMed, formerly AnMed Health, a nonprofit health system serving patients in upstate South Carolina and Northeast Georgia, has been forced to temporarily close 79 of its 106 facilities while it deals with cyberattack-related disruption to its IT systems. Computer systems, phone lines, and Internet connectivity are down.
On Sunday, July 26, 2026, the health system confirmed that it had experienced “a cybersecurity disruption involving malware,” which forced it to close AnMed Medical Group offices and AnMed Imaging Services on Monday. AnMed Urgent Care locations, AnMed Kids Care, AnMed Integrated Therapy locations, and AnMed Laboratory Services will open as scheduled on Monday. While offices have been temporarily closed, AnMed said its care teams remain on site and will continue to see patients in the emergency room.
The attack has resulted in disruption to patient services, with some scheduled appointments postponed. Patients who had elective procedures scheduled for Monday are being contacted directly to advise them if their procedures will go ahead as planned or will have to be postponed. Decisions about procedures, patient transfers, diversions, and operational processes are being made with patient safety as the guiding principle.
AnMed said it is coordinating with the emergency medical services, regional hospitals, and public safety partners to ensure that patients receive the care they need in the most appropriate setting. AnMed is currently unable to provide a timeline for when computer systems will be recovered, when its offices will reopen, and when normal services will resume.
Get The FREE
HIPAA Compliance Checklist
Immediate Delivery of Checklist Link To Your Email Address
Please Enter Correct Email Address
Your Privacy Respected
HIPAA Journal Privacy Policy
Updates will be provided via its website, including operational plans for the coming days. Cybersecurity partners are working on restoring access to systems and data as quickly as possible. An investigation has been launched to determine the nature and scope of the incident, but it is too early to tell to what extent, if any, patient data was involved. No threat group appears to have claimed responsibility for the incident.


