2026 AnMed — malware/ransomware disruption; leak-site PHI claim under investigation (count TBD)
Data compromised
Operational IT/phone disruption confirmed; ransomware leak-site/Facebook posts allege HIV+/mental-health/SSN and other PHI (~6TB) — AnMed has not verified theft census; recordsAffected 0 pending notifications
Technical writeup
Verified health-system cyberattack — disclosed July 26, 2026; HIPAA Journal updates through August 2026. AnMed (upstate South Carolina / Northeast Georgia) confirmed a malware “cybersecurity disruption” that forced temporary closure of dozens of facilities (early reports ~79–83 of 106). Systems, phones, and Internet were disrupted; MyChart and EHR access were later partially restored with added SMS verification. A ransomware group added AnMed to a leak site and briefly posted on AnMed’s Facebook page on August 11 alleging ~6TB of sensitive PHI (including HIV+, suicide registries, sexual-assault records, and SSNs). AnMed said the same day that unauthorized social posts’ claims “have not been verified and are under investigation,” and that it will notify if data theft is confirmed. recordsAffected remains 0 pending an attested PHI census; companyConfirmed true for the malware incident, not for the actor’s volume claims.
Root cause
Company-confirmed malware cybersecurity disruption (Jul 26, 2026); ransomware group later claimed ~6TB PHI exfiltration — AnMed says claims unverified