
AnMed Medical Center has confirmed a cybersecurity disruption involving malware that has taken down phone and internet services across its hospital locations, forcing operational changes including diversion of some patients and temporary closures of outpatient services. The outage has affected patient access to MyChart and other networked systems while third‑party cybersecurity specialists and state and federal authorities work on containment and recovery.
AnMed confirms malware disrupted communications and network
In a statement posted July 26, AnMed said: “We are currently experiencing a cybersecurity disruption involving malware that is impacting our network.” The system-wide outage has affected telephone and internet connectivity at all hospital locations and disrupted electronic patient services such as MyChart, a patient quoted in the FOX Carolina report said she could not get paperwork and that MyChart was down.
AnMed said emergency departments remain open and care teams are on site. The hospital system is working “diligently to return our systems to full functionality” with the assistance of third‑party cybersecurity specialists and “state and federal authorities.” The Anderson Police Department confirmed that the South Carolina Law Enforcement Division (SLED) and the FBI are assisting the investigation.
Operational impact and immediate changes at AnMed
AnMed’s statement and local reporting list concrete operational effects. Phone and internet outages have limited electronic workflows and patient access to online records, leading staff to fall back to manual processes in some areas. The system announced multiple service adjustments for the immediate period following the disruption:
- AnMed Medical Group offices and AnMed Imaging Services were scheduled to be closed on Monday, July 27.
- Patients with elective procedures scheduled for that day were to be contacted directly by AnMed staff.
- AnMed Urgent Care locations, AnMed Kids Care, AnMed Integrated Therapy and AnMed Laboratory Services were listed as open as scheduled.
- The AnMed Education and Technology Center groundbreaking ceremony was postponed, although construction remains on schedule.
Local reporting also noted that some patients were being diverted to other hospitals in the region, with a patient telling FOX Carolina that transfers to Prisma were occurring. AnMed said it is coordinating with emergency medical services, regional hospitals and public safety partners to maintain patient care during the response.
Why it matters
The incident highlights how malware that disrupts networking and communications can immediately affect hospital operations, patient access to records and elective services. Phones and internet connectivity are central to scheduling, test ordering, clinician communication and patient messaging portals such as MyChart; when those systems go offline, hospitals must shift to manual workflows and alter patient flow, including diversions and postponement of non‑urgent care.
For patients and families, the outage has tangible consequences: inability to retrieve discharge paperwork or access online records, uncertainty about scheduled procedures, and potential transfers to other facilities. For clinicians and clinical staff, loss of networked systems increases administrative burden and can complicate coordination of care even when emergency departments remain open.
Context and implications for response and recovery
AnMed’s public account provides a snapshot of an active incident response: engagement of external cybersecurity specialists, coordination with SLED and the FBI, selective closures and patient notifications. Those steps indicate the hospital system is treating the event as a serious network compromise that requires forensic investigation and remediation before full systems can be restored.
The statement does not specify the malware family, how the malware entered AnMed’s environment, whether backups are available, or whether patient data were accessed or exfiltrated. Because those details have not been disclosed, questions remain about the intrusion’s scope and the timeline for restoring normal operations. The involvement of federal and state authorities means investigative findings and recovery guidance may be shared publicly at a later stage.
What to watch next
Key unresolved items to monitor in AnMed’s response include:
- Whether AnMed will confirm the specific malware type or attack vector and whether the incident involved data exposure or exfiltration.
- The timeline for restoring phone, internet and patient portal services and when elective procedures and imaging will fully resume.
- Findings from the SLED and FBI investigation and any technical or operational recommendations that may follow.
- How AnMed communicates operational plans and patient notifications in the coming days; the hospital said it will share additional updates “as more information becomes available.”
Until those details are released, AnMed’s published actions—bringing in outside cybersecurity help, coordinating with regional healthcare partners, and curtailing select services—are the visible steps being taken to maintain patient care while pursuing remediation.
The immediate consequence is that AnMed patients and clinicians must operate without customary digital tools until the health system restores networked services and clarifies whether the incident affected patient data.
Source: FOX Carolina News
