>samit_hota
Back to security news
SN-2026-204HighOpen

AnMed Health System Halts Operations Across SC and GA After Malware Attack

Samit Hota·
CVE ID
N/A
Affected Products / Orgs
AnMed, AnMed Health Network
#news#malware#anmed

Regional healthcare provider AnMed has been forced to shut down dozens of clinical practices across upstate South Carolina and northeast Georgia following a weekend malware attack. The AnMed cyberattack, which initially manifested as widespread phone and internet outages across all network facilities, rapidly escalated into operational disruptions requiring the closure of primary care, OBGYN, and outpatient imaging centers. While hospital emergency departments and urgent care locations remain operational, the health system is working alongside emergency medical services (EMS) and regional public safety partners to coordinate patient diversion and mitigate risks to acute care delivery.

Disruptions Across Facilities and Outpatient Services

On Sunday, AnMed published an online advisory acknowledging that its networks were experiencing a “cybersecurity disruption involving malware.” The disclosure followed earlier warnings issued to patients regarding system-wide telephony and network access failures across all service locations. By Monday, the organization released an updated inventory of affected sites detailing widespread clinical closures.

The network, which encompasses four acute care hospitals and more than 60 physician practices throughout the region, was forced to suspend routine outpatient operations entirely. Specific impacts include:

  • Complete closure of primary care and specialty clinics: All medical group offices, primary care practices, and OBGYN facilities affiliated with the network have halted patient appointments.
  • Suspension of diagnostic services: Outpatient imaging services are unavailable across the affected locations.
  • Telecommunications failure: VoIP and digital communication infrastructure across facilities were severely impacted, severing direct external and inter-departmental communications.
  • Emergency care rerouting: While urgent care centers remain open, acute cases requiring specialized care or diagnostic imaging are being coordinated directly with regional public safety and neighboring health systems.

Infrastructure Impact and Clinical Blast Radius

When malware successfully proliferates across a regional health system, the operational blast radius extends far beyond corrupted workstations or server infrastructure. Modern hospital networks rely on centralized Active Directory trees, centralized Electronic Health Record (EHR) databases, lab information systems (LIS), and Picture Archiving and Communication Systems (PACS) to function safely.

When central domain controllers or core networking appliances are targeted or isolated to contain malware, the dependent medical ecosystem collapses into manual failover modes. Pen-and-paper charting can sustain emergency triage and basic urgent care for limited periods, but it cannot support high-throughput specialty clinics, complex diagnostic imaging, or routine primary care. Diagnostic equipment—such as MRI and CT scanners—frequently relies on networked PACS servers to ingest patient orders and transmit scan results. Without reliable, secure connections to these systems, clinical risks become unmanageable, leaving facility shutdowns as the only viable mitigation.

Furthermore, total telephony disruptions prevent remote facilities from contacting central pharmacies, blood banks, or off-site laboratory teams. This interconnected dependency explains why a malware infection residing on core corporate segments forces an immediate, broad shutdown across dozens of geographically dispersed outpatient sites.

Threat Landscape and Extended Recovery Timelines

The attack against AnMed highlights ongoing vulnerabilities across the healthcare sector, where extortion groups regularly exploit operational time-sensitivity to force payment demands or cause widespread disruption. Modern threat actors targeting health systems typically gain initial access through unpatched edge remote-access devices, compromised credentials, or spear-phishing campaigns. Once inside, operators deploy multi-stage malware payloads to perform internal reconnaissance, harvest privileged domain credentials, disable localized security agents, and move laterally across clinical subnet boundaries.

The incident reflects broader systemic challenges documented across medical IT infrastructure. IBM’s annual cost of a data breach analysis highlights that healthcare data breaches carry the highest financial impact of any sector, averaging $7.4 million per incident. Crucially, breaches in the healthcare industry take an average of 279 days to detect and fully contain—more than five weeks longer than the global cross-industry benchmark. This extended remediation lifecycle stems from the complexity of legacy medical systems, strict regulatory requirements around data preservation, and the necessity of individually validating and sanitizing specialized internet-of-medical-things (IoMT) devices before reconnecting them to restored core networks.

AnMed has not publicly attributed the malware to a specific threat actor family nor confirmed whether extortion demands were made. The health system continues recovery efforts to restore internal networks, bring clinical software back online, and assess the full scope of system impact.

Immediate Technical Actions for Healthcare Operators

Organizations managing distributed medical networks should implement immediate defensive controls targeting the common execution vectors of network-wide malware:

  • Enforce Strict Domain Segmentation: Isolate administrative Active Directory infrastructure from medical device VLANs, PACS imaging clusters, and EHR application tiers using host-based firewalls and microsegmentation.
  • Secure Remote Access Gateways: Require phishing-resistant multi-factor authentication (MFA) across all remote access endpoints, virtual desktop infrastructure (VDI), and vendor support portals.
  • Implement Immutable Offline Backups: Ensure operational database snapshots and active system state backups for EHR and diagnostic platforms are stored in isolated, air-gapped repositories that cannot be wiped or encrypted via compromised domain administrator accounts.

Found something similar in your stack?

Let's find out before it becomes an incident.

Book an advisory call