Cybersecurity

When the Hospital Next Door Is Hit: AnMed, Data Theft, and the Patient Scam Wave

AnMed (SC/northeast GA) confirmed July 2026 file locking and unauthorized copying, plus patient scam warnings. A regional playbook for practices that share care pathways—and patients.

When a regional health system goes dark, the shockwave is not only clinical. It is operational, reputational, and—weeks later—a fraud problem for every patient who might get a phone call that sounds official. That is the story behind AnMed, the nonprofit system serving upstate South Carolina and northeast Georgia, after a July 2026 cyberattack that disrupted care for weeks and then turned into a confirmed data-theft investigation.

According to AnMed's public updates and reporting from HealthInfoSec / BankInfoSecurity (August 24, 2026), the incident was first detected on July 26, 2026. CEO William Kenley described attackers motivated by financial gain and a "complicated and rapidly changing situation." AnMed later confirmed that a computer virus locked access to network files and that files on certain systems were copied without permission. Its August 27 data-security notice said the network had been securely restored, that electronic health records hosted in a separate cloud environment were not affected, and that locally stored patient-care files may include identifying, clinical, insurance, and financial details still under review.

Disruption first, then the secondary attack

Operational impact was severe across the footprint. Outpatient, imaging, and specialty locations closed or limited services; staff used downtime workflows; phones, internet, computers, and MyChart were unavailable for stretches of the recovery. DysruptionHub's open timeline notes staged restoration through mid-to-late August, with AnMed confirming read/write EHR access around August 11 and broader network restoration by late August.

Then came pressure beyond encryption. Threat actors publicly claimed large-scale theft—The Gentlemen asserted roughly 6 terabytes of corporate and patient information in coverage AnMed has said is too general to treat as definitive. AnMed also confirmed unauthorized posts on its Facebook account in the days after the attack, then took social pages down while securing access. Separately, researchers have described conflicting attribution signals (including Interlock-linked negotiation evidence versus Gentlemen leak-site claims). For practice leaders, the actionable point is not picking a gang name. It is recognizing that modern healthcare ransomware is a multi-channel campaign: systems, stolen files, leak sites, and hijacked brand channels.

Why northeast Georgia practices should treat this as local news

AnMed is not a distant mega-breach headline. It is a regional provider with Georgia locations in the mix—including Hartwell among communities listed in public disruption reporting. Patients, referring clinics, and employers in Northwest Georgia already share care pathways with upstate South Carolina systems. When a neighbor confirms file copying and warns the community about scams, your front desk and billing team will field the fallout even if your LAN was never touched.

AnMed's warning is explicit: criminals may attempt to publish information, contact patients or employees, or make additional public claims. Anyone who receives an unexpected communication claiming to involve AnMed information should not respond, click links, open attachments, provide personal information, or make a payment—and direct threats should be reported to law enforcement. That script is the same one every dental and medical practice needs after a vendor or regional partner breach.

Clear takeaway

Treat post-incident patient and staff outreach as part of the attack surface—not as PR afterthought. If attackers have (or claim) PHI, the second wave is social engineering dressed as "breach support," billing, or identity protection.

Actions to take this week

  1. Write a patient-scam script now. Give front desk and call center a one-page card: we will never ask for passwords, gift cards, or remote-access software over the phone; verify callback numbers from the website, not from a text.
  2. Lock down social and brand channels. Enforce MFA on Facebook, Instagram, Google Business, and any marketing tools. Document who can post, and how you revoke access in an incident.
  3. Separate cloud EHR from "local leftovers." Inventory where patient-care files still live on file shares, imaging workstations, or legacy servers—the AnMed distinction between unaffected cloud EHR and local copies is the risk map many clinics still skip.
  4. Rehearse downtime and diversion. Know which partners you send patients to, how paper workflows work for 72 hours, and who talks to cyber insurance and counsel.
  5. Watch for secondary phishing themes. After regional news breaks, expect emails spoofing the affected organization. Brief staff once; keep a sample phishing screenshot on the break-room wall.

Brotherly Technology helps practices across Rome and Northwest Georgia harden the stack that matters in moments like this: MFA and remote access, backup and restore discipline, monitoring, and calm incident playbooks that include patient communications—not only server recovery. AnMed's confirmed file copying and scam warning are the regional reminder: recovery is not the finish line. Fraud prevention is.

Sources:

One accountable technology partner.

Tell us what's slowing your team down. We'll show you exactly how we'd fix it — no pressure, no jargon.

Book a Free Consultation
Book a Free Consultation