Data Privacy,
Data Security,
Fraud Management & Cybercrime
Nonprofit Health System in SC and Georgia Reports Email, Phones, and Portal Outages

In a significant cybersecurity incident, AnMed, a nonprofit health system serving upstate South Carolina and Northeast Georgia, has made the decision to temporarily close numerous medical offices and care facilities. This action follows an apparent ransomware attack that occurred over the recent weekend, leading to major disruptions within its IT infrastructure.
AnMed publicly acknowledged the situation in a statement released on its website Monday, confirming that the organization was grappling with a cybersecurity disruption involving malware. This attack has severely affected various aspects of the health system’s IT network, including its email communications, telephone systems, and the MyChart patient portal that many patients utilize to manage their healthcare needs.
In the statement, AnMed emphasized, “We are working diligently to assess our systems, investigate the full nature and scope of the issue, and securely restore our systems to full functionality as quickly as possible. This effort includes the assistance of third-party cybersecurity specialists, as well as state and federal authorities.” This proactive approach illustrates the organization’s commitment to addressing the crisis effectively and ensuring the safety of its patient data.
During the weekend, a patient visiting one of AnMed’s facilities revealed to local NBC affiliate WYFF that a hospital staff member had informed her about alarming developments. Reportedly, hackers managed to infiltrate AnMed’s network and projected a message across the screens of the organization’s computers. This message purportedly threatened to leak sensitive patient information unless the organization complied with an extortion demand within 72 hours.
In terms of immediate impact, AnMed listed the closure of approximately 80 care facilities. These facilities provide an array of medical services covering primary care, pediatric needs, sleep diagnostics, women’s health, oncology, medical imaging, and several other areas crucial for community health. Additionally, AnMed stated that patients who had electives procedures scheduled for Monday would receive direct communication regarding necessary rescheduling.
Patient safety has emerged as the guiding principle in the decision-making processes regarding procedures, patient transfers, and operational strategies as the organization navigates this challenging scenario. AnMed reinforced its commitment to safeguarding its patients and ensuring that their health and wellbeing remain a top priority.
Despite the severity of the incident, AnMed has not provided additional details regarding the specific nature of the cyber event, nor has it communicated any updates about potential patient data breaches to the Information Security Media Group (ISMG) as of press time. This lack of transparency underscores the complexities often faced during such security breaches, where organizations must balance operational response with their commitment to privacy and compliance.
AnMed’s history is rooted in community healthcare, with origins tracing back to the establishment of its first hospital in 1908. Currently, the organization boasts a medical staff of 620 physicians and employs around 3,600 individuals. The AnMed Medical Center, its flagship facility, operates as a 495-bed acute-care center in Anderson, South Carolina, now facing significant operational challenges due to this cyber attack.
As of Monday, there has been no attribution of responsibility for the AnMed cyberattack, with no cybercrime group claiming involvement on the dark web. This incident falls in line with a disturbing trend of increasing cyber threats targeting healthcare providers, forcing many organizations to take their IT systems offline and consequently leading to the cancellation or postponement of medical services and surgical procedures. AnMed is part of a growing list of healthcare systems adversely affected by cybercriminal activity.
In a parallel situation earlier this year, Signature Healthcare in Massachusetts had to revert to paper charting for several weeks due to a cyberattack. The lengthy recovery process entailed digitizing patient records once IT systems were restored. This highlights the broader implications of such cyber incidents on healthcare organizations, not just from a financial standpoint but also in terms of patient care and trust.

