Malware Attack Forces Temporary Closure of 79 AnMed Facilities
South Carolina’s largest independent nonprofit health system struggled to restore critical IT infrastructure after a severe cybersecurity disruption.
AnMed, South Carolina’s largest independent nonprofit health system, suffered a massive operational collapse after a malware-driven cybersecurity attack began on Sunday, July 26, 2026. The incident paralyzed the provider's digital infrastructure, forcing the immediate temporary closure of approximately 79 of its 106 facilities across upstate South Carolina and Northeast Georgia.
The disruption targeted critical IT systems, effectively cutting off phone lines and internet connectivity. This loss of communication and data access crippled outpatient operations, including Medical Group offices and Imaging Services. According to reports from the HIPAA Journal and Greenville News, the system was forced to suspend services at nearly 80 locations to maintain patient safety and secure data while technicians worked to purge the malware and restore connectivity.
Recovery and Residual Impact
Recovery efforts began in the days following the initial breach. By July 30, AnMed had successfully reduced the number of closed facilities to 13. However, the restoration process was not instantaneous; some locations remained shuttered for more than ten days following the initial attack. Despite the gradual reopening of physical clinics, the digital recovery lagged, with patient portals such as MyChart remaining unavailable throughout the recovery process.
Industry Implications
This incident underscores the acute vulnerability of regional healthcare networks to malware. When critical infrastructure—specifically telephony and internet—is compromised, the result is not merely a data breach but a physical cessation of care. The scale of the AnMed event demonstrates how a single IT failure can trigger a domino effect, necessitating the closure of dozens of clinics simultaneously. Furthermore, the prolonged outage of patient portals and subsequent warnings to patients regarding suspicious communications highlight the lasting reputational and operational risks inherent in healthcare cyberattacks.
Future Outlook
As AnMed continues to stabilize its network, the health system remains focused on the full restoration of its digital patient interfaces. While the majority of physical facilities have returned to service, the total duration of the MyChart outage and the full extent of the malware's reach remain key points of concern. Industry observers will be watching for a formal post-mortem on the breach to determine if specific security gaps led to the widespread failure of both data and communication systems.