AnMed Crisis Communications Lacking
Greg Wilson/Anderson Observer
AnMed Health, which has spent much of the past week attempting to navigate a ransomware attack with the sort of measured caution usually reserved for disaster drills and coronations, now warns that some patients may be receiving bills, appointment reminders, or other messages that are themselves part of the breach. The hospital’s advice is, in effect, to distrust anything that appears to have come from the system.
That admonition is necessary, but also faintly unnerving. AnMed has offered little more than the standard language of institutional regret — the sort of statement that promises concern without quite yielding information — and has said almost nothing about when the attack will be resolved, how many patients have been affected (and how), or what surgeries and treatments may have been delayed in the process.
The result, predictably, is a vacuum, and vacuums in moments like these do not remain empty for long. They fill with rumor, conjecture, and the small, corrosive suspicions that bloom when a hospital appears to be speaking in the passive voice while patients are left to wonder what, exactly, has happened to their records, their appointments, and their confidence in the system.
No one imagines that a hospital can make itself invulnerable from such attacks (see yesterday’s story in The Anderson Observer). But there is a difference between acknowledging the impossibility of perfect security and accepting silence as a substitute for stewardship. Medicine, at least in the old and honorable understanding of it, is built on trust: the patient crosses the threshold, and in doing so entrusts the institution with bodily privacy, emotional vulnerability, and often the family’s finances as well.
When that trust is shaken by a cyberattack, candor becomes a clinical necessity. People do not merely want updates; they need reassurance that the institution is attending to the crisis rather than hiding behind it. Instead, AnMed’s public communications have done something less useful and more familiar, instead producing just enough information to raise concern, and too little to calm it.
As one person in the healthcare field locally told me: “It really looks like they do not care for their patients, which I know is patently not true. My doctors care about me.”
That is why the hospital’s present posture feels less like caution than like a lesson in what not to do. It is still possible, after nearly a week, to repair some of the damage by speaking plainly, naming the extent of the disruption, and explaining what patients should expect next regarding not only their health but the exposure of their data. But trust, unlike a server, does not reboot on command, and its clock has already been running for days.