AnMed is continuing to restore its systems after a malware-related cyberattack on July 26, 2026, an incident that forced the Anderson, South Carolina-based nonprofit health system to temporarily close 83 of its 106 facilities and disrupted patient services across its network.
The health system said it remains open under downtime procedures and is still providing care at its locations, though some patients are experiencing delays. According to AnMed, doctors have access to medical records, and patient safety is guiding decisions on appointments, procedures, transfers, and diversions.
Recovery continues after malware incident
AnMed said the attack caused outages affecting computer systems, phone lines, and Internet connectivity. On July 26, 2026, the organization confirmed it had experienced "a cybersecurity disruption involving malware", prompting temporary closures at AnMed Medical Group offices and AnMed Imaging Services.
While those offices were closed, AnMed said care teams remained on site and continued seeing patients in the emergency room. The health system also said AnMed Urgent Care locations, AnMed Kids Care, AnMed Integrated Therapy locations, and AnMed Laboratory Services would open as scheduled.
Some scheduled appointments have been postponed, and patients with elective procedures were being contacted directly about whether those procedures would move forward or be delayed. AnMed said it could not provide a timeline for when systems would be recovered, offices would reopen, or normal services would resume.
sbb-itb-535baee
Warning issued over patient messages
As recovery efforts continued, AnMed issued a patient warning on July 30, 2026, about communications that appeared to come from the health system, including MyChart appointment reminders.
According to the warning, "During our response to the cybersecurity incident, certain appointment reminders generated outside of our internal systems may continue to be delivered by text message. Patients are not required to confirm appointments electronically at this time."
AnMed said it had not found evidence that patients were being targeted maliciously because of the incident, but advised them to be cautious with electronic messages that appear to come from the system.
Investigation remains underway
AnMed said cybersecurity partners are working to restore access to systems and data as quickly as possible. The health system has also launched an investigation into the nature and scope of the incident, though it said it is too early to determine to what extent, if any, patient data was involved.
No threat group appears to have claimed responsibility for the incident.
As of the latest update, AnMed said it is still making progress on recovery while coordinating with emergency medical services, regional hospitals, and public safety partners to help ensure patients receive care in the most appropriate setting.