A malware-related network disruption forced AnMed to close 80 listed locations and services, interrupting appointments and diverting some patients while emergency departments remained open.
What happened
AnMed, an independent nonprofit health system serving Upstate South Carolina and northeast Georgia, announced on July 26 that it was experiencing a cybersecurity disruption involving malware. The incident affected AnMed’s network and was accompanied by phone and internet outages across its hospital locations.
AnMed closed its Medical Group offices and Imaging Services on Monday, July 27, and began contacting patients whose elective procedures could be affected. Its published operating-status table, last updated at 9:12 p.m. on July 26, listed 107 locations or services: 80 closed, 26 open, and one operating with limited service.
AnMed’s three emergency departments remained open, along with its urgent care centers, Kids Care, Integrated Therapy locations, laboratories and several other services. FOX Carolina reported that an official with ambulance provider Medshore confirmed that some patients were being diverted from AnMed to hospitals in Greenville.
What was said
In its public notice, AnMed stated, “We are currently experiencing a cybersecurity disruption involving malware that is impacting our network.”
AnMed said cybersecurity specialists were helping it assess and restore its systems and that additional operational updates would be published as more information became available. The Anderson Police Department separately told FOX Carolina that the FBI and the South Carolina Law Enforcement Division were assisting with the investigation.
Why it matters
Paubox’s Healthcare Email Security Maturity Index 2026 found that 58% of healthcare organizations had experienced an email-related breach during the previous 24 months, while 23% had been breached more than once. The report does not establish how the malware entered AnMed’s network, but it shows why neighboring providers cannot be treated as unlimited backup capacity: many are managing their own recurring security exposure.
A JAMA Network Open cohort study examined 19,857 visits to an unaffected emergency department located near four hospitals experiencing a month-long ransomware attack. During the attack and recovery period, the unaffected hospital recorded increases in patient numbers, ambulance arrivals, waiting room times, patients leaving without being seen and total lengths of stay. The researchers concluded that healthcare cyberattacks should be treated as disasters requiring coordinated regional planning.
The spillover effect is already visible in AnMed’s response. Its coordination with ambulance services, nearby hospitals and public-safety agencies is a part of preventing a technology outage at one health system from becoming a broader patient care problem.
See also: HIPAA Compliant Email: The Definitive Guide (2026 Update)
FAQs
Is malware the same thing as ransomware?
No, malware is a broad term for software designed to damage, disrupt or gain unauthorized access to systems. Ransomware is one type of malware that encrypts data or blocks access and typically demands payment.
Does a network outage mean patient information was stolen?
Not necessarily, malware can interrupt systems without removing data.
How can a hospital treat patients when its computers are unavailable?
Hospitals generally use downtime procedures such as paper documentation, manual patient registration and alternative communication methods. These procedures allow care to continue, but they can slow treatment and make coordination more difficult.
