AnMed Cyberattack: EHR Restored Day 16, 11 Sites Still Closed

AnMed's EHR Came Back on Day 16. Eleven Facilities Were Still Closed on Day 18.

A South Carolina health system closed 83 of its 106 facilities after a malware attack. Sixteen days later the electronic health record was working again. The closed-facility count went up.

The Short Answer

AnMed, a health system in Anderson, South Carolina, lost its network to malware on July 26, 2026 and closed 83 of its 106 facilities the next morning. Full read-write access to its electronic health record was restored on August 11, day 16. Two days later, on August 13, eleven facilities were still closed.

What happened in the AnMed cyberattack?

On Sunday, July 26, 2026, AnMed lost its network. The phones and the internet went with it. AnMed described the cause as malware and began publishing numbered public updates the same day (Fox Carolina).

 

By Monday morning, AnMed had closed 83 of its 106 facilities (HIPAA Journal). At the outset, emergency departments, urgent care, laboratory services and integrated therapy locations stayed open (TechTarget). Radiation oncology and imaging closed. AnMed canceled elective procedures and limited infusions.

 

Four days in, physicians were still working from downtime procedures that gave them only limited access to medical records. MyChart was offline. AnMed asked patients to bring all medications to their appointments in the original containers, “because phone, internet and computer systems remain disrupted” (Anderson Independent Mail, July 30, 2026).

 

A system built around the 461-bed AnMed Medical Center, with more than 60 physician practices across South Carolina and Georgia (Healthcare Dive), was asking patients to carry their own medication history in a pill bottle. That is what happens when the only place a med list lives is inside the system that just went dark.

How long was AnMed's EHR down?

Sixteen days. Fox Carolina reported on August 11, 2026 that AnMed care teams had “full read and write access to patient’s electronic health records.” Phone lines were restored the same day. MyChart login came back, with some features still unavailable.

AnMed cyberattack timeline: facility closures and EHR restoration, July 26 to August 13, 2026.
DayDateStatusSource
Day 0Jul 26Network, phones and internet down system-wide.Fox Carolina
Day 1Jul 2783 of 106 facilities closed.HIPAA Journal
Day 4Jul 3013 sites closed. MyChart offline. Downtime procedures running.Anderson Independent Mail
Day 10Aug 510 facilities closed, several of them outpatient imaging.Healthcare Dive
Day 15Aug 1010 facilities still closed.Becker's Hospital Review
Day 16Aug 11Full read-write EHR access restored. Phone lines back. MyChart login restored, some features still unavailable.Fox Carolina; AnMed Update 13
Day 18Aug 1311 facilities still closed.HIPAA Journal; AnMed status page

Read the last two rows together. The electronic health record was working again, and the closed-facility count went up, from ten on August 10 to eleven on August 13. No published source explains the increase, and AnMed has not declared full restoration. Every figure above is dated because the situation is still moving.

Restoring the system and restoring the operation are two different projects. Only one of them was staffed.

Why did AnMed close 83 of its 106 facilities?

Because there was nothing underneath. When the network went down, the sites that depend on it had no other way to see a patient, pull a chart, or receive an order.

This is worth stating plainly, because the alternative explanation gets offered often and is wrong: AnMed did not close 83 facilities because its incident response was poor. The response was competent. Emergency departments never closed. AnMed stood up a patient support line, published numbered public updates, coordinated with EMS and regional hospitals, and brought in third-party cybersecurity specialists alongside state and federal authorities. Anderson Police confirmed that the South Carolina Law Enforcement Division and the FBI were assisting (Fox Carolina, August 11, 2026).

The closures happened anyway, because incident response and clinical continuity are different capabilities. One manages the event. The other keeps care delivery running during it. AnMed had the first.

Which AnMed facilities stayed closed the longest?

The outpatient ones. Becker’s Hospital Review published the August 10 closure list: imaging at Anderson Medical Center, North Campus, Cannon, Clemson and Piedmont; Laboratory Services on Fant Street; Heart and Vascular Diagnostics in Clemson; Women’s Diagnostics; Lung and Sleep; TMS and Sleep Diagnostics.

 

Every one of those is an outpatient site.

 

Downtime planning in American healthcare is built around the inpatient hospital and the emergency department. That is where the drills run and where the paper kits are stocked. It is the right place to start and the wrong place to stop.

 

An imaging center has no downtime muscle. It has a schedule, a modality, a PACS connection, and an order that has to arrive from somewhere. Cut the network and the door stays locked. Multiply that by the eighty-odd sites arranged around a single hospital and the Monday morning closure list writes itself.

What is the difference between disaster recovery and clinical continuity?

Disaster recovery restores systems after they fail. Clinical continuity keeps clinicians working while the systems are still down. A health system can execute the first perfectly and still close facilities for weeks, which is what the AnMed timeline documents.

Disaster recovery

Backups, immutable snapshots, replication targets, recovery time objectives. The unit of measurement is how quickly the environment comes back. The work happens in IT. Care is paused while it runs.

Clinical continuity

A clinical workspace that is already live on separate infrastructure when the outage begins. The unit of measurement is whether care delivery stops. The work happens at the bedside and in the clinic. Nothing has to be restored first.

Disaster recovery vs. clinical continuity, compared across five dimensions.
Disaster recoveryClinical continuity
TimingActivated after failureAlready running before failure
Measured byRecovery time objectiveWhether care delivery stops
LocationOften the same network and credential domain as the primarySeparate cloud, separate credentials, outside the blast radius
Clinician experiencePaper, then re-entryBrowser or mobile, documenting and ordering as normal
After the eventManual reconciliation of downtime recordsAutomated sync-back with audit trail preserved
AnMed analogueWorked. Record restored day 16.Absent. Eleven sites closed day 18.

Why do hospital downtime procedures fail past 72 hours?

Because they were designed for a different length of event. Paper downtime kits, runner protocols and manual order sets are built and drilled for outages measured in hours. They assume a small number of affected units, a staffed command center, and a return to normal inside a shift or two.

 

Extend the same procedures across 106 sites for more than two weeks and the failure modes compound. Physicians get “limited access to medical records,” in AnMed’s own phrasing, rather than the chart. Medication histories become whatever the patient can carry. Results have nowhere to route. Every hour of documentation created on paper becomes an hour of re-entry after restoration, which is why reconciliation projects outlive the outage that caused them.

 

Baxter Lee, president of the healthcare cybersecurity firm Clearwater, told Healthcare Dive: “When recovery stretches this far, it is usually a sign that something in the preparation, whether that is the backups, incident response planning and testing, was not where it needed to be. That is a gap our industry has to close, not something we should keep excusing as normal.”

What did the ransomware group do to AnMed's communications?

On August 11, 2026, the same day AnMed announced EHR access was restored, a ransomware group calling itself The Gentlemen posted extortion demands on AnMed’s own Facebook page (The Record). AnMed removed the posts, disabled platform access, and stated that the claims “have not been verified and are under investigation.”

 

The group’s claims about what it took remain unverified and are not repeated here. The mechanism is the part worth naming. AnMed had spent two weeks using its website and social accounts to tell patients which locations were open. On day 16, the attackers took the microphone.

 

The Gentlemen is not a marginal actor. Dragos counted 125 attacks by the group against industrial organizations in Q2 2026, up from 83 in Q1, the largest quarter-over-quarter gain among established groups (Dragos Industrial Ransomware Analysis, Q2 2026). Other Q2 trackers rank the group higher still.

Key Figures

Key figures: AnMed and the healthcare ransomware context.
83AnMed facilities closed on July 27, 2026, out of 106 total.
16 daysFrom the July 26, 2026 malware attack to full read-write EHR restoration on August 11, 2026.
11AnMed facilities still closed on August 13, 2026, two days after the EHR was restored. The count had been 10 on August 10.
125Attacks attributed to The Gentlemen against industrial organizations in Q2 2026, up from 83 in Q1.
67%Share of healthcare organizations reporting a ransomware attack, a four-year high at the time of the survey.
51%Share of healthcare organizations using backups to recover, down from 72%.
$160MAdverse financial impact CommonSpirit Health reported from its October 2022 attack, exclusive of insurance recoveries.
37 daysFrom Ascension's May 8, 2024 attack to restored EHR access across all hospitals on June 14, 2024.

How long do hospital EHR outages actually last?

AnMed’s sixteen days is not an outlier. It sits in the middle of the range that named US health systems have disclosed since 2020. The table below uses only figures the operators themselves published or that appear in SEC filings and peer-reviewed research.

Disclosed EHR downtime and financial impact at six US health systems, 2020 to 2026.
OrganizationEHR downtimeDisclosed financial impact
Ardent HealthNov 202313 days. Network offline Nov 23, Epic restored Dec 6."Approximately $74 million" adverse pre-tax impact for 2023 (Form 10-Q, Q2 2024).
Scripps HealthMay 2021Epic restored day 25. Operational disruption persisted four weeks (JAMA Network Open, 2023).$91.6M lost revenue plus $21.1M incremental cost as of June 30, 2021, before insurance.
Universal Health ServicesSep 2020About three weeks, rolling restoration across 250 US care sites."Approximately $67 million" aggregate unfavorable pre-tax impact for 2020.
AscensionMay 202437 days. Discovered May 8, EHR restored across all hospitals June 14.Never quantified. Ascension cites only "reduced revenues from the associated business interruption."
CommonSpirit HealthOct 2022Hit Oct 2. EHR restored across most markets Nov 9, a 38-day span, some facilities longer."Approximately $160 million" estimated adverse impact, exclusive of insurance (FY2023 Annual Report).
AnMedJul 202616 days to full read-write EHR access. 11 facilities still closed on day 18.Not disclosed.

Two cautions about the numbers that circulate in this space. A widely repeated figure putting average healthcare ransomware downtime at 24 days traces to a Coveware quarterly report covering all industries in a single quarter of 2022, not healthcare. And the $1.8 billion sometimes attached to Ascension is that system’s full-year FY2024 operating loss across all causes, which was itself a $1.2 billion improvement on the prior year. Neither belongs in a downtime argument.

 

The more useful pattern in the table is what is missing from it. Every organization above disclosed a date when the EHR came back. None disclosed how long individual clinics and outpatient sites stayed closed after that date. AnMed is unusual only in that it published a facility-status page, which is why the gap is visible at all. The gap almost certainly existed in the other five.

What does a continuity layer actually change?

ShelterZoom builds Spare Tire, a healthcare downtime resilience layer, and has a commercial interest in what follows. Read this section as the vendor’s disclosed argument. Its analytical core is a category distinction: a continuity layer is not disaster recovery.

The layer is hosted on a different vendor’s cloud under separate credentials, architecturally separated from the systems it protects, so lateral movement from a compromised EHR environment has nowhere to go. It runs in parallel with the primary EHR over bi-directional HL7 sync, which puts the chart in place before the network fails. Clinicians work from a browser on web or mobile, documenting and ordering as usual. When the primary system returns, records created during the outage sync back with timestamps and audit trail intact, so the manual reconciliation that normally follows an outage does not accumulate.

Applied to the AnMed timeline, the change is narrow and specific. Recovery still takes sixteen days, because recovery is a separate problem and a continuity layer does not shorten it. What changes is the closure list. An imaging center with a continuity layer does not lock the door on Monday. It opens with a worklist.

What would a continuity layer have changed at AnMed?

This is counterfactual and worth labeling as one. ShelterZoom has no visibility into AnMed’s environment beyond what AnMed and the press have published, and no vendor can honestly claim to know how another organization’s incident would have run. What follows is bounded by the public record.

 

Start with what a continuity layer would not have changed, because that list is longer than most vendors admit. It would not have prevented the intrusion; it is not a security control and nothing in the category claims to be. It would not have shortened the recovery. AnMed’s sixteen days to full read-write EHR access was a restoration problem, and restoration would have taken just as long. It would not have stopped the data-theft claims or the August 11 compromise of AnMed’s social accounts, and it would not have brought back MyChart, the phones, or internet access.

 

What it changes is narrower, and it lands almost entirely on the Monday morning.

What a continuity layer changes, mapped to the AnMed timeline.
DateWhat happenedWhat a continuity layer changes
Jul 2783 of 106 facilities closed. Sites with no way to see a patient without the network locked their doors.Clinicians open a browser on web or mobile and work from the continuity layer. The sites that closed for lack of access to a record stay open.
Jul 30Physicians had "limited access to medical records." Patients were asked to bring all medications in the original containers.Medication list, allergies, problem list and recent results are already resident, synced daily over HL7. No patient carries their own history in a pill bottle.
Jul 26 to Aug 11Sixteen days of clinical documentation produced on paper across a 106-site system.Documentation, orders and medication verification captured in the continuity layer with timestamps and audit trail preserved.
Aug 11EHR restored. Reconciling two weeks of paper back into the record begins.Records created during the outage sync back automatically. The reconciliation project does not exist.
Aug 13Eleven facilities still closed, all outpatient.Whatever remains closed is closed for physical or staffing reasons, not because the record is unreachable.

One detail of the AnMed outage makes the architectural requirement concrete. The network, the phones and the internet went down together. Any continuity capability living inside that same environment, on the same network behind the same credentials, went down with it. That is the reason the continuity layer has to sit on separate infrastructure with separate authentication rather than in a partition of the system it is meant to cover.

 

The honest summary is this. A continuity layer would not have made AnMed’s incident smaller. It would have made the incident invisible to most of the patients on the schedule.

Frequently asked questions

How long was AnMed's EHR down?

Sixteen days. Malware took down AnMed’s network on July 26, 2026. Fox Carolina reported on August 11, 2026 that care teams had regained full read and write access to patient electronic health records. MyChart login was restored the same day, with some features still unavailable.

83 of AnMed’s 106 facilities closed on Monday, July 27, 2026, the day after the incident began, according to HIPAA Journal. Emergency departments and urgent care locations remained open throughout.

Yes. Eleven facilities were still closed on August 13, 2026, two days after full read-write EHR access was restored. The count had been ten on August 10, so it increased after the record came back. No published source explains the increase.

Outpatient sites. Becker’s Hospital Review listed imaging at Anderson Medical Center, North Campus, Cannon, Clemson and Piedmont, plus Laboratory Services on Fant Street, Heart and Vascular Diagnostics in Clemson, Women’s Diagnostics, Lung and Sleep, and TMS and Sleep Diagnostics.

A ransomware group calling itself The Gentlemen posted extortion demands on AnMed’s own Facebook page on August 11, 2026 and claimed to have taken six terabytes of data. AnMed stated the claims “have not been verified and are under investigation.” The claims remain unverified.

Disaster recovery restores systems after they fail and is measured in recovery time objectives. Clinical continuity keeps clinicians documenting, ordering and treating while the primary system is still down, and is measured in whether care delivery stops. A hospital can have a working disaster recovery plan and still close facilities, which is what the AnMed timeline shows.

Paper downtime procedures are designed and drilled for outages measured in hours. AnMed ran them across a 106-facility system for more than two weeks. By July 30, physicians had only limited access to medical records and patients were asked to bring all medications to appointments in the original containers.

No. A clinical continuity layer is not a security control and does not prevent intrusion, stop data exfiltration, or shorten system recovery. It addresses a different failure: whether clinicians can keep documenting, ordering and treating while the primary EHR is unavailable. In the AnMed case, recovery would still have taken sixteen days. What changes is the facility closure list.

Disclosed outages at major US health systems have run from about two weeks to about five. Ardent Health restored Epic 13 days after taking its network offline in November 2023. Scripps Health restored Epic on day 25 in 2021, with operational disruption persisting four weeks. Ascension took 37 days in 2024. AnMed took 16 days in 2026. Widely circulated “average downtime” figures for healthcare are unreliable; the named incidents are better evidence.

Zero-downtime continuity is a category of healthcare software in which a clinical workspace runs continuously in parallel with the primary EHR, on separate infrastructure with separate credentials, so clinicians keep working during an outage rather than waiting for recovery. Spare Tire by ShelterZoom is the anchor product in the category.

Disclosure

ShelterZoom builds Spare Tire, a continuity layer for EHR downtime. The company has a commercial interest in the argument made here and states it before making it. Nothing above relies on non-public information, and every factual claim is sourced to named public reporting so readers can check it independently. AnMed is not a ShelterZoom customer and has not reviewed or endorsed this analysis.