AnMed, a hospital system operating in Anderson, Clemson, and surrounding areas of South Carolina and northeast Georgia, experienced a significant cybersecurity disruption in late July 2026 that forced the closure of dozens of its facilities and knocked out phone and internet connectivity across its network. While AnMed has confirmed the incident involved malware, the company has not yet said whether patient, employee, or other personal information was accessed or stolen.
Hospital systems handle enormous volumes of highly sensitive personal and medical information, and when a cybersecurity incident disrupts core operations to this degree, the organization has a responsibility to determine quickly whether that data was compromised and to notify anyone affected without unreasonable delay.
AnMed’s Data Breach Investigation
According to AnMed’s own public statements and multiple news outlets covering the incident, the disruption began over the weekend of July 25-26, 2026, when AnMed detected a “cybersecurity disruption involving malware” impacting its computer network. In response, AnMed closed or canceled services at a large majority of its locations, with reports indicating that as many as 79 of the health system’s 106 facilities were affected by the closures. Phone lines and internet connectivity across the network were reportedly knocked offline as a result of the incident.
AnMed has stated that emergency rooms remained open throughout the disruption and that care teams continued to see patients on-site despite the network outage. Patients with elective procedures scheduled during the disruption were reportedly contacted directly by AnMed staff regarding rescheduling. As of this writing, AnMed has not confirmed the specific cause of the malware infection, the scope of any data accessed, or whether the incident meets the legal definition of a data breach under applicable state and federal notification laws.
Malware-driven disruptions of this scale at hospital systems are frequently associated with attempts to encrypt or exfiltrate data for extortion purposes, though AnMed has not specifically characterized the incident as a ransomware attack in its public statements. Regardless of the specific type of malware involved, incidents that force a healthcare provider to shut down electronic systems on this scale often indicate that attackers gained meaningful access to internal networks, which raises the possibility that patient records, employee data, or other sensitive information could have been viewed, copied, or encrypted during the attack.
Healthcare organizations remain one of the most frequently targeted sectors for cyberattacks because the data they hold, including Social Security numbers, insurance information, medical histories, and payment details, carries high value on illicit markets and can be used for a wide range of fraud, from opening new lines of credit to submitting fraudulent insurance claims. The scale of AnMed’s outage, spanning nearly three-quarters of its facilities, is also consistent with attacks that specifically target the availability of hospital systems, since disrupting patient care can pressure an organization to respond more quickly to attacker demands.
AnMed has said it will continue providing updates as its investigation progresses. Until AnMed or an official notification confirms what specific data, if any, was compromised, individuals who have received care from or been employed by AnMed should remain alert for any further communications from the health system and monitor their accounts and medical records for signs of unusual activity.
When Did This Breach Occur?
AnMed first publicly acknowledged the cybersecurity disruption on July 26, 2026, with continued closures and service disruptions reported into July 27, 2026. The health system has not yet disclosed when the malware first infiltrated its systems, only that the disruption became apparent and was publicly confirmed over that weekend.
What Information Was Breached?
As of this writing, AnMed has not publicly disclosed whether any specific categories of patient, employee, or other personal information were accessed, copied, or stolen as a result of the malware incident. The investigation into the scope of the disruption remains ongoing, and AnMed has indicated it will provide updates as more information becomes available.
What You Can Do
If you are a current or former AnMed patient or employee, consider taking the following precautions while the investigation continues:
- Monitor AnMed’s official website and social media channels for updates on the incident and any formal notification of a data breach
- Watch your financial accounts, insurance statements, and medical records closely for any unfamiliar activity
- Be cautious of any unsolicited phone calls, emails, or texts claiming to be from AnMed asking for personal or financial information
- Consider placing a fraud alert or credit freeze with the major credit bureaus as a precaution
- Keep any communications you receive from AnMed regarding this incident, as they may be relevant if a formal breach notification follows
File a Data Breach Lawsuit Against AnMed
If AnMed later confirms that your personal or medical information was compromised as a result of this cybersecurity incident, you may have legal options available to you. Healthcare providers that collect and store sensitive patient data have a legal obligation to implement reasonable safeguards to protect that information, and when a breach occurs, affected individuals may be entitled to compensation.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.