AnMed Health System Disrupted by Malware, Closes Dozens of Facilities
AnMed, a health system serving South Carolina and Georgia, has shut down numerous departments and clinics due to a malware-induced cybersecurity disruption, impacting patient care.

AnMed, a non-profit health system operating across South Carolina and Georgia, is currently grappling with a significant cybersecurity incident involving malware that has forced the closure of dozens of its departments and clinics. The organization announced the disruption on Sunday, stating that it was actively working to restore affected systems and assess the full scope of the incident. This cyberattack has led to widespread service interruptions, affecting patient access to essential healthcare.
Earlier on Sunday, AnMed had alerted the public to a phone and internet outage impacting all of its facilities, foreshadowing the broader operational impact. By Monday, the health system provided a detailed list of the numerous facilities and departments that were temporarily shuttered. While urgent care services remained operational, all imaging, OBGYN, and primary care clinics, along with all medical group offices, were closed to patients. The affected network encompasses four hospitals and over 60 physician practices, serving the northeast Georgia and upstate South Carolina regions.
In response to the disruptions, AnMed emphasized its commitment to ensuring continuity of care. "We are coordinating closely with emergency medical services, regional hospitals and public safety partners to ensure patients continue to receive the care they need in the most appropriate setting," the health system stated. This proactive coordination aims to mitigate the immediate impact on patient health by redirecting critical cases to available resources.
The healthcare sector continues to be a prime target for cybercriminals, with numerous high-profile attacks reported this year. These incidents have frequently disrupted patient care and compromised sensitive health information. For instance, the medical device company Stryker recently fell victim to a cyberattack attributed to Iranian hackers, highlighting the persistent threats faced by healthcare organizations.
Compounding the concern, a recent report by IBM underscores the financial severity of data breaches within the healthcare industry. For the twelfth consecutive year, healthcare organizations experienced the highest average cost per incident, reaching an estimated $7.4 million in 2025. Furthermore, the report noted that breaches in the medical sector take significantly longer to detect and resolve, averaging 279 days – over five weeks longer than the industry average.
The specific type of malware used in the AnMed attack and the initial point of compromise have not yet been disclosed. Investigations are ongoing to determine the full extent of the breach, including whether any patient data was accessed or exfiltrated. The health system's focus remains on restoring normal operations and ensuring the security of its networks and patient information.
This incident serves as a stark reminder of the vulnerabilities within the healthcare infrastructure and the critical need for robust cybersecurity measures. The prolonged downtime and potential data exposure pose significant risks to patient trust and operational stability, underscoring the ongoing challenges in protecting sensitive health data from evolving cyber threats.
The attack on AnMed has led to the closure of approximately 80 care facilities across South Carolina and Georgia, impacting services ranging from primary care to oncology. Initial reports from patients suggest that hackers claimed to have stolen patient information and threatened to leak it if a ransom demand was not met within 72 hours, though no group has yet claimed responsibility.