On July 26, 2026, AnMed announced it was responding to a cybersecurity disruption involving malware affecting its network.
What happened
The South Carolina health system said it began assessing the incident and working with third-party cybersecurity specialists and state and federal authorities to restore its systems. AnMed Medical Group offices and AnMed Imaging Services closed on July 27, while urgent care locations, Kids Care, integrated therapy sites, laboratories, and emergency services continued operating. Elective procedures and appointments were postponed or rescheduled.
In a July 27 update, AnMed said its phone, internet, and computer systems remained offline and that clinical teams were providing care during the downtime. The organization continued coordinating with emergency medical services, regional hospitals, and public safety partners, with decisions about procedures, patient transfers, diversions, and operations guided by patient safety. On July 30, AnMed warned that patients could continue receiving appointment reminders generated outside its internal systems, including MyChart text messages. It said patients did not need to confirm appointments and advised them to exercise caution with messages appearing to originate from AnMed.
What was said
According to AnMed’s August 3 systems-disruption update, “Because our teams are using temporary downtime procedures, some requests may take longer than usual to complete, whether by phone or during your visit.”
Why it matters
When phones, internet access, scheduling platforms, medical records, and other systems become unavailable, providers may have to postpone appointments, rely on manual procedures, redirect patients, and complete routine tasks more slowly. Even if an investigation has not established that patient data was exposed, prolonged system downtime can still affect care coordination, medication requests, test results, referrals, and communication between patients and their providers. HHS summarizes the connection as, “In health care, cyber risks are patient risks.”
A similar disruption occurred during the April 2026 cyberattack on Signature Healthcare Brockton Hospital. As Paubox reported, the hospital diverted ambulances, temporarily canceled chemotherapy treatments, and experienced problems dispensing medication through its retail pharmacies. Inpatient and walk-in emergency services continued, but some testing, surgeries, and other services faced delays. Both incidents demonstrate that remaining open does not necessarily mean operating normally. Downtime procedures can preserve essential services, but they may also place additional pressure on clinicians, administrative employees, neighboring hospitals, and patients.
See also: HIPAA Compliant Email: The Definitive Guide (2026 Update)
FAQs
Does HIPAA override state breach-notification laws?
The HHS describes HIPAA as providing a federal floor of privacy protection. State requirements that provide greater protections may continue to apply, meaning healthcare organizations may need to satisfy both HIPAA and applicable state notification laws.
Which state’s law applies when patients live in different states?
An organization may need to assess the laws of every state in which affected individuals reside. Definitions of personal information, notification deadlines, regulator-notice thresholds, and required contents differ between states. A breach involving patients across several states can therefore create multiple parallel reporting obligations.
Can law enforcement delay breach notification?
Yes, but the delay must meet specific requirements. Under HIPAA, a law-enforcement official may delay notification if he or she states that notice would impede a criminal investigation or damage national security.
