Were you recently affected by a data breach?

AnMed Data Breach

AnMed, a South Carolina and Georgia hospital system, suffered a malware-related cybersecurity disruption that forced the closure of dozens of facilities and disrupted phone and internet service. The investigation is ongoing, and AnMed has not yet disclosed whether patient or employee data was compromised.

AnMed
Date of Breach: July 26, 2026
CAU logo

Who was affected:

Clients of AnMed

Impacted Data:

Not yet publicly disclosed

AnMed, a hospital system operating in Anderson, Clemson, and surrounding areas of South Carolina and northeast Georgia, experienced a significant cybersecurity disruption in late July 2026 that forced the closure of dozens of its facilities and knocked out phone and internet connectivity across its network. While AnMed has confirmed the incident involved malware, the company has not yet said whether patient, employee, or other personal information was accessed or stolen.

Hospital systems handle enormous volumes of highly sensitive personal and medical information, and when a cybersecurity incident disrupts core operations to this degree, the organization has a responsibility to determine quickly whether that data was compromised and to notify anyone affected without unreasonable delay.

AnMed’s Data Breach Investigation

According to AnMed’s own public statements and multiple news outlets covering the incident, the disruption began over the weekend of July 25-26, 2026, when AnMed detected a “cybersecurity disruption involving malware” impacting its computer network. In response, AnMed closed or canceled services at a large majority of its locations, with reports indicating that as many as 79 of the health system’s 106 facilities were affected by the closures. Phone lines and internet connectivity across the network were reportedly knocked offline as a result of the incident.

AnMed has stated that emergency rooms remained open throughout the disruption and that care teams continued to see patients on-site despite the network outage. Patients with elective procedures scheduled during the disruption were reportedly contacted directly by AnMed staff regarding rescheduling. As of this writing, AnMed has not confirmed the specific cause of the malware infection, the scope of any data accessed, or whether the incident meets the legal definition of a data breach under applicable state and federal notification laws.

Malware-driven disruptions of this scale at hospital systems are frequently associated with attempts to encrypt or exfiltrate data for extortion purposes, though AnMed has not specifically characterized the incident as a ransomware attack in its public statements. Regardless of the specific type of malware involved, incidents that force a healthcare provider to shut down electronic systems on this scale often indicate that attackers gained meaningful access to internal networks, which raises the possibility that patient records, employee data, or other sensitive information could have been viewed, copied, or encrypted during the attack.

Healthcare organizations remain one of the most frequently targeted sectors for cyberattacks because the data they hold, including Social Security numbers, insurance information, medical histories, and payment details, carries high value on illicit markets and can be used for a wide range of fraud, from opening new lines of credit to submitting fraudulent insurance claims. The scale of AnMed’s outage, spanning nearly three-quarters of its facilities, is also consistent with attacks that specifically target the availability of hospital systems, since disrupting patient care can pressure an organization to respond more quickly to attacker demands.

AnMed has said it will continue providing updates as its investigation progresses. Until AnMed or an official notification confirms what specific data, if any, was compromised, individuals who have received care from or been employed by AnMed should remain alert for any further communications from the health system and monitor their accounts and medical records for signs of unusual activity.

When Did This Breach Occur?

AnMed first publicly acknowledged the cybersecurity disruption on July 26, 2026, with continued closures and service disruptions reported into July 27, 2026. The health system has not yet disclosed when the malware first infiltrated its systems, only that the disruption became apparent and was publicly confirmed over that weekend.

What Information Was Breached?

As of this writing, AnMed has not publicly disclosed whether any specific categories of patient, employee, or other personal information were accessed, copied, or stolen as a result of the malware incident. The investigation into the scope of the disruption remains ongoing, and AnMed has indicated it will provide updates as more information becomes available.

What You Can Do

If you are a current or former AnMed patient or employee, consider taking the following precautions while the investigation continues:

  • Monitor AnMed’s official website and social media channels for updates on the incident and any formal notification of a data breach
  • Watch your financial accounts, insurance statements, and medical records closely for any unfamiliar activity
  • Be cautious of any unsolicited phone calls, emails, or texts claiming to be from AnMed asking for personal or financial information
  • Consider placing a fraud alert or credit freeze with the major credit bureaus as a precaution
  • Keep any communications you receive from AnMed regarding this incident, as they may be relevant if a formal breach notification follows

File a Data Breach Lawsuit Against AnMed

If AnMed later confirms that your personal or medical information was compromised as a result of this cybersecurity incident, you may have legal options available to you. Healthcare providers that collect and store sensitive patient data have a legal obligation to implement reasonable safeguards to protect that information, and when a breach occurs, affected individuals may be entitled to compensation.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: May 27, 2026
Date of Breach: May 25, 2026
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.