AnMed, a nonprofit health system with more than 4,000 employees and 648 beds serving upstate South Carolina and northeast Georgia, suffered a ransomware attack that began Sunday, July 26, 2026. An anonymous patient told WYFF of a message on hospital computers: 72 hours to pay, or data would be published. That deadline overlaps with the 72-hour window mandated by CIRCIA for reporting to CISA, creating a time compression between criminal extortion and legal obligation.
- The incident began July 26, 2026 with malware on the AnMed network; the health system's official statement confirms a "cybersecurity disruption involving malware" but does not use the term ransomware
- An anonymous patient reported to WYFF a 72-hour payment ultimatum with a threat to leak data; AnMed has not officially confirmed this deadline
- AnMed shut down select clinical services: oncology, radiation therapy, imaging, elective procedures, and the Medical Group, while keeping the emergency department, laboratory, and integrated therapy operational
- The health system is operating with assistance from third-party cybersecurity specialists and state and federal authorities
The Message on the Monitors: What the Patient Describes
The primary source for the 72-hour deadline is an anonymous patient interviewed by WYFF, cited by Healthcare IT News. According to that account, the message displayed on hospital computers read: "AnMed has 72 hours to pay, and if not, everybody's information would be leaked." This is the only available evidence of the time the attackers allowed. AnMed's official statement on July 26, 2026 mentions neither the deadline nor the threat to publish data.
Reliance on an indirect, secondary source for a central element of the incident reveals the information gaps typical of the early stages of a healthcare crisis. The patient is not an institutional spokesperson or an investigator; their testimony, while the most detailed on the extortion mechanism, cannot be independently verified at this time. The dossier does not specify whether other patients or staff corroborated the same display.
Selective Shutdown and the Patient Safety Principle
AnMed implemented a differentiated service closure based on patient safety criteria. On Monday, July 27, 2026, the following were suspended: oncology services, radiation therapy, AnMed Medical Group, all imaging services, and elective procedures. Urgent care, laboratory, integrated therapy, AnMed Kids Care, and emergency departments remain operational.
According to AnMed's official statement, "decisions regarding procedures, patient transfers, diversions and operational processes are being made with patient safety as the guiding principle." The health system also stated: "We are coordinating closely with emergency medical services, regional hospitals and public safety partners to ensure patients continue to receive the care they need in the most appropriate setting." This decision architecture reflects the standard healthcare business continuity protocol: keep open what saves lives, close what can be deferred without immediate risk.
The Dual 72-Hour Clock: CIRCIA vs. Criminal Ultimatum
The AnMed incident produces a potentially conflicting temporal overlap. On one side, the patient-reported threat imposes 72 hours to pay the ransom. On the other, the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) requires covered entities to report significant cyber incidents to CISA within 72 hours. The CISA source, while not specific to AnMed, documents this statutory deadline as a binding obligation for critical infrastructure.
The numerical convergence is coincidental; the systemic effect is not. Leadership resources at a healthcare organization in crisis must allocate legal, technical, and communications expertise simultaneously toward two counters expiring together. The brief does not document whether AnMed has already submitted the CIRCIA report, nor whether the criminal and regulatory deadlines were managed sequentially or in parallel.
TechTarget reports the temporary closure of 83 AnMed facilities; this figure is not corroborated by other sources in the dossier and remains isolated. The most solid operational data remains the list of closed services published by AnMed itself and cited by Healthcare IT News.
What to Do Now
For AnMed patients, immediate actions depend on the type of service needed. Emergency departments, urgent care, laboratory, and integrated therapy remain operational; patients with appointments for imaging, oncology, radiation therapy, or elective procedures should contact AnMed to reconfirm or reschedule. AnMed launched a dedicated phone line on August 3, 2026 for information and support.
For healthcare organizations with a profile similar to AnMed, the incident highlights three verification areas: the ability to keep critical services operational during an IT disruption, the availability of alternative patient communication channels within 48 hours of an incident, and preparation of CIRCIA reporting documentation without waiting for full emergency resolution. The brief does not document technical remediation measures taken by AnMed, nor does it provide details on the initial access vector or attack techniques.
The dossier does not specify whether AnMed paid the ransom, nor does it quantify compromised data. The identity of the ransomware group remains unknown. The latest update from primary sources is August 3, 2026; the actual state of IT systems at that time is not documented textually.
"AnMed has 72 hours to pay, and if not, everybody's information would be leaked" — Unnamed patient, reported by WYFF via Healthcare IT News
Questions and Answers
Has AnMed confirmed the attack is ransomware?
No. The official statement of July 26, 2026 describes "a cybersecurity disruption involving malware." The term ransomware does not appear in the institutional documents cited in the dossier. The extortion nature of the incident is reported only through the anonymous patient's testimony.
How many facilities were closed?
Healthcare IT News lists categories of suspended services without providing a structural count. TechTarget reports 83 facilities temporarily closed; this number is not corroborated by other sources in the dossier. The AnMed statement confirms selective closure but does not quantify.
Has the ransomware group been identified?
No. The dossier contains no attribution, no group mentions, and no indicators of compromise that would allow identification. The operators' identity remains unknown.
Information has been verified against cited sources and is current as of publication.
Sources
- https://www.healthcareitnews.com/news/anmed-given-72-hours-respond-demands-ransomware-incident
- https://www.kobaran.com/anmed-faces-72-hour-ransomware-deadline-as-hospital-systems-stay-down/
- https://www.techtarget.com/healthtechsecurity/news/366646219/Cyberattack-forces-temporary-closure-of-83-AnMed-facilities
- https://www.cisa.gov/topics/cyber-threats-and-advisories/information-sharing/cyber-incident-reporting-critical-infrastructure-act-2022-circia
- https://anmed.org/about/news-media/news/anmed-systems-disruption
- https://anmed.org/about/news-media/news/closings-2026-07-27?fbclid=IwY2xjawTUHS5leHRuA2FlbQIxMABicmlkETFBWGI3MWhjQnh2Y2RDVkd6c3J0YwZhcHBfaWQQMjIyMDM5MTc4ODIwMDg5MgABHmTt9X-ZwP1Y_7NEpG5p_pr-CIHWV3aWREibqvKouD9FghoCt-IwWRIiMzva_aem_CXCT5XF2oY3FU0QGTig9rQ
- https://www.wyff4.com/article/anmed-cybersecurity-disruption-closures/73271067
- https://anmed.org/about/news-media/news/closings-2026-07-27
- https://www.healthcareitnews.com/news/stopping-ransomware-disruption-better-planning