Key Takeaways
- AnMed Health System, which operates hospitals and clinics across Anderson County, South Carolina, and Northeast Georgia, is experiencing a widespread phone and internet outage.
- Internal sources confirm the disruption stems from a cyberattack involving malware that has compromised the network.
- AnMed’s official statement emphasizes that patient safety remains the top priority while they work with third‑party cybersecurity experts and state/federal agencies to restore services.
- Non‑essential services—including AnMed Medical Group offices, Imaging Services, and elective procedures scheduled for Monday, July 27—are postponed or closed, while urgent care, kids care, therapy, laboratory, and emergency departments remain operational.
- The health system is coordinating with EMS, regional hospitals, and public‑safety partners to ensure continuity of care and to keep the community informed through official channels and social media.
- AnMed thanks its staff, physicians, nurses, and regional partners for their flexibility and dedication during the incident.
Impact on Operations
The phone and internet outage has affected every AnMed location, hindering routine communication channels that staff rely on for scheduling, internal coordination, and patient outreach. While the emergency departments continue to function and care teams remain on‑site, the loss of reliable telephony and data connectivity has forced the system to revert to manual processes for many administrative tasks. This includes patient check‑in, prescription ordering, and inter‑departmental messaging, which now rely on paper‑based logs or limited backup systems. The outage has also disrupted external communications, making it difficult for patients to reach the hospital for non‑urgent inquiries or to receive updates about appointment changes.
Nature of the Cyber Incident
According to sources within the hospital, the outage resulted from a malware infection that infiltrated AnMed’s network. Although the specific strain or attack vector has not been publicly disclosed, the description aligns with ransomware‑type malware that can encrypt files, disrupt services, and demand payment for restoration. The presence of malware suggests that threat actors may have gained unauthorized access through phishing, compromised credentials, or exploiting unpatched vulnerabilities. The incident is being treated as a cybersecurity disruption rather than a simple technical failure, prompting involvement of specialized cyber‑security firms and law‑enforcement agencies.
Official Statement from AnMed Leadership
AnMed released a formal statement acknowledging the cybersecurity disruption and outlining its response strategy. The health system emphasized that protecting patients and delivering safe, high‑quality care remain its highest priorities. It noted that decisions regarding procedures, patient transfers, diversions, and other operational processes are being guided strictly by patient safety considerations. AnMed also confirmed that it is collaborating with third‑party cybersecurity specialists, as well as state and federal authorities, to investigate the incident, contain the threat, and restore full functionality as quickly as possible. The statement aimed to reassure the public while being transparent about the ongoing challenges.
Service Adjustments and Closures
In response to the outage, AnMed announced specific operational changes for Monday, July 27. All AnMed Medical Group offices will be closed, and patients with elective procedures scheduled for that day will be contacted directly by staff to reschedule or receive further instructions. AnMed Imaging Services will also be shut down for the day. Conversely, essential services such as AnMed Urgent Care centers, AnMed Kids Care, AnMed Integrated Therapy locations, and AnMed Laboratory Services will remain open as scheduled. Emergency departments continue to operate, and care teams are present on‑site to attend to patients needing immediate attention. These adjustments aim to balance the need for continued critical care with the limitations imposed by the network disruption.
Coordination with External Partners
AnMed highlighted its close coordination with emergency medical services (EMS), regional hospitals, and public‑safety partners to ensure that patients continue to receive appropriate care despite the outage. By sharing situational updates and leveraging mutual aid agreements, the health system can redirect patients to alternate facilities when necessary and maintain a cohesive regional response. This collaboration helps mitigate the impact of disrupted internal communications and ensures that ambulance crews and first responders have reliable points of contact for patient transfers and emergency notifications.
Appreciation for Staff and Community
The health system expressed sincere gratitude to its physicians, nurses, advanced practice providers, clinical teams, and all employees for their professionalism, flexibility, and extraordinary efforts during the crisis. AnMed also thanked the Upstate community for its collaboration, patience, and support, acknowledging that the collective response of staff and residents is vital to navigating the incident successfully. This recognition underscores the human element of healthcare delivery, especially when technological infrastructure is compromised.
Communication Channels and Public Updates
To keep the public informed, AnMed has been using its official Facebook page to post updates, including a Sunday morning message confirming the phone and internet outage and reassuring followers that care teams remain on‑site. The health system encouraged residents to download the WYFF News 4 app for real‑time news and updates about the situation. By leveraging social media and local news outlets, AnMed aims to counteract the lack of internal communication channels and provide transparent, timely information to patients, families, and the broader community.
Future Outlook and Lessons Learned
Although AnMed has not disclosed a timeline for full restoration, the involvement of cyber‑security experts and governmental agencies suggests a structured incident‑response process is underway. The event serves as a stark reminder of the growing cyber threat landscape facing healthcare organizations, where ransomware and malware can directly affect patient care delivery. Moving forward, AnMed will likely review its network defenses, employee training on phishing awareness, backup and disaster‑recovery protocols, and incident‑response plans to strengthen resilience against similar attacks. The experience may also prompt broader discussions within the industry about investing in robust cyber‑security infrastructure and fostering greater information‑sharing among healthcare providers to preempt and mitigate future disruptions.

