Get all your news in one place.
100's of premium titles.
One app.
Start reading
Medical Daily
Medical Daily
Joseph James

South Carolina Health System Still Running Limited Services 10 Days After Malware Attack

Ten days after malware disrupted its network, the South Carolina health system AnMed is still operating in a limited capacity, with ten locations remaining closed, including outpatient imaging.

The nonprofit system confirmed on July 26, 2026, that it was experiencing a cybersecurity disruption involving malware, and closed roughly 80 of its 106 facilities the following day while taking down its MyChart patient portal along with computer systems, phone lines, and internet connectivity. Most locations have since reopened, but the system has not said when it expects to fully restore operations.

For patients across the Anderson area and into northeast Georgia, the practical question is not whether the network is fixed but whether the specific service they need is running today, and that has changed almost daily.


Services Still Affected 10 Days In

AnMed operates the 461-bed AnMed Medical Center in Anderson, South Carolina, along with additional hospital facilities and more than 60 physician practices across South Carolina and Georgia. Emergency departments and urgent care locations have remained open throughout the incident.

The pattern of closures tells you what depends most on networked systems. Imaging services went down first and are among the last to return, because diagnostic imaging relies on digital storage and transmission rather than anything that can be done on paper. Medical group offices, obstetrics and gynecology, and primary care clinics were also closed, while laboratory services, integrated therapy and pediatric urgent care stayed open.

In the first days, elective procedures scheduled for the Monday after the attack were postponed and patients contacted individually, oncology and radiation services were closed, and infusions were limited. The system said it was coordinating with emergency medical services and regional hospitals and public safety partners, stating: "We are coordinating closely with emergency medical services."

AnMed has confirmed malware but has not publicly characterized the incident as ransomware or confirmed any extortion demand. A report that attackers gave the system 72 hours to respond originated with an alleged ransom note reported by a patient to a local television station, along with a screenshot shared with Healthcare IT News. That account has not been confirmed by the health system, and readers should treat it as unverified. Separately, the FBI's Columbia field office was notified of the incident but declined to provide details.


Care Continuity Under Paper-Based Downtime Procedures

When electronic records become unavailable, hospitals fall back on established downtime procedures. Staff revert to paper charting, medication administration records move to printed forms, orders are written by hand and hand-carried, and laboratory and imaging results are delivered physically rather than posted to a chart.

These procedures work, and hospitals are required to have them. They are also slower and more error-prone than the systems they replace. A clinician working from paper cannot see a patient's full medication history, prior imaging or allergy list with a click, which is why systems in this situation prioritize emergency and urgent care and defer elective work.

That prioritization explains the closure pattern rather than indicating that closed services were unimportant. Postponing a screening mammogram is a manageable delay. Diverting an emergency patient is not, which is why those services stayed open.

The other cost is invisible in closure lists. Every canceled appointment becomes a rescheduled appointment, and a system already at capacity absorbs that backlog over weeks or months.


Open Question About Patient Data

The forensic review has not concluded whether patient information was accessed or taken. AnMed has said it is working with third-party cybersecurity specialists and state and federal authorities, and is providing updates through its website.

This is the part patients should treat as unresolved rather than reassuring. Investigations of this kind commonly take weeks, and under federal breach notification rules, individuals are notified after an organization determines that protected health information was involved. Absence of notification at this stage is not evidence that nothing was taken.

The health system has warned patients to be cautious about communications that appear to come from AnMed, including MyChart appointment reminders. That warning is not hypothetical: some patients reported being contacted about setting up payments in the aftermath of the attack. After publicized health system incidents, patients frequently receive phishing calls, texts and emails referencing the attack and requesting personal or payment information.

Neither the health system nor any legitimate agency will call and ask for a Social Security number, banking details or a payment to protect an account.


Steps for Patients with Appointments or Records Requests

Anyone with an upcoming AnMed appointment should check the health system's website for current operating status before traveling, since the list of open and closed locations has been updated repeatedly. Phone lines have been affected, though the system has added dedicated phone services during recovery.

Patients who need records for a referral, a specialist visit or a procedure elsewhere should expect delays and start the request earlier than usual. Bringing a written list of current medications, doses, allergies and recent test results to any appointment is genuinely useful when a clinician cannot pull up a chart.

People needing emergency or urgent care should still seek it. Emergency departments and urgent care locations have remained open, and no one should delay care for chest pain, difficulty breathing, signs of stroke, severe bleeding or a rapidly worsening condition because of a systems outage.

Patients concerned about data should watch for unfamiliar medical bills or explanation-of-benefit statements, treat unsolicited contact about the incident with skepticism, and wait for official written notification rather than acting on a phone call.

What happens next depends on the forensic review, any regulatory filing with federal health authorities, and AnMed's own restoration timeline, none of which has been publicly dated. MedicalDaily will report confirmed developments.

The bottom line: the newest confirmed detail is that 10 locations remain closed 10 days after the attack; the people most affected are outpatients with imaging and specialty appointments in the Anderson region; emergency care remains available; and whether patient data was compromised is still unknown.


Frequently Asked Questions

What happened? AnMed, a nonprofit health system serving upstate South Carolina and northeast Georgia, experienced a malware-related cybersecurity disruption confirmed on July 26, 2026, that took down computer systems, phone lines, and internet connectivity.

Which services are still affected? As of August 5, ten locations remained closed, including several outpatient imaging facilities. Most of the roughly 80 initially closed facilities have reopened.

Are emergency rooms open? Yes. Emergency departments and urgent care locations have remained open throughout the incident.

Was patient data stolen? Unknown. The forensic review has not concluded, and AnMed has not said whether information was accessed. Federal rules require individual notification if protected health information was involved.

Was this ransomware? AnMed has confirmed malware but has not publicly confirmed ransomware or any demand. A reported 72-hour ultimatum came from a patient's account and an alleged screenshot, not from the health system.

How do hospitals treat patients without electronic records? Through established downtime procedures, including paper charting, handwritten orders and physical delivery of results. These are slower and are why elective services are deferred first.

What should patients do before an appointment? Check the health system's website for current status, bring a written list of medications and allergies, and be skeptical of unsolicited calls, texts or payment requests referencing the incident.

Sign up to read this article
Read news from 100's of titles, curated specifically for you.
Already a member? Sign in here
Related Stories
Top stories on inkl right now
One subscription that gives you access to news from hundreds of sites
Already a member? Sign in here
Our Picks
Fourteen days free
Download the app
One app. One membership.
100+ trusted global sources.