Mon 27 Jul 2026 / 15:32 ET
Kernel
Security 3 min read

AnMed malware outage closes clinics across South Carolina and Georgia

AnMed says malware disrupted its networks, closing imaging, OBGYN, primary care and medical group offices while urgent care remains open.

Mara Chen-Doyle

By Mara Chen-Doyle / Staff Writer

AnMed malware outage closes clinics across South Carolina and Georgia
img: The Record

AnMed malware outage disruptions have closed dozens of clinics and departments across the nonprofit health system’s South Carolina and Georgia service area, according to statements the organization posted Sunday and Monday.

AnMed said Sunday that it was dealing with a cybersecurity disruption involving malware and was working to bring systems back online while assessing the incident’s scope. Earlier that day, the health system said phone and internet service was down across its facilities.

The operational hit is the part patients will feel first. On Monday, AnMed posted a list of closures affecting dozens of facilities and departments. The health system said urgent care services remain open, but imaging, OBGYN and primary care clinics are closed. It also said all medical group offices are closed.

AnMed serves upstate South Carolina and northeast Georgia. The system operates four hospitals and more than 60 physician practices, according to the organization.

What AnMed offices are closed?

AnMed said all imaging, OBGYN and primary care clinics are closed, along with all medical group offices. Urgent care services remain open, according to the health system’s Monday update.

The organization did not say when normal operations would resume. It also did not say whether patient information was accessed, whether the malware was ransomware, or which internal systems were affected beyond the phone and internet outage it reported.

Malware is malicious software used to disrupt, damage or gain unauthorized access to computer systems. In a hospital or clinic network, that can spill over into scheduling, communications, imaging, billing and other systems that clinicians and front-desk staff rely on to move patients through care.

AnMed said it is working with emergency medical services, nearby hospitals and public safety agencies so patients can still get care in the appropriate setting. That coordination matters during a network disruption because a clinic closure or communications outage can push patients toward urgent care, emergency departments or other providers.

What has AnMed said about the malware incident?

AnMed has described the event as a cybersecurity disruption involving malware. The health system said it is focused on restoring systems and determining the scope of the incident.

The public updates so far leave several basic questions unanswered: the type of malware, how it entered the network, whether outside investigators are involved and whether any data was taken. Those gaps are common early in healthcare cyber incidents, but they are not minor details for patients whose appointments, records or communications may be affected.

Healthcare organizations have remained a frequent target for cyberattacks this year. The Record reported that one recent case involved Iranian hackers attacking medical device company Stryker.

The cost of those incidents is also unusually high in healthcare. IBM reported that, for the 12th consecutive year, healthcare data breaches in 2025 were more expensive than breaches in any other industry, averaging $7.4 million per incident. IBM also found that healthcare breaches took 279 days to identify and contain, more than five weeks longer than the average incident.

AnMed has not announced a final timeline for recovery. Patients seeking care should rely on the health system’s current closure notices and urgent care availability updates rather than assuming a normal schedule.

This story draws on original reporting from The Record.

More Security/

view all ↗