AnMed Ransomware Attack Reflects Growing Trend
Greg Wilson/Anderson Observer
AnMed Health’s ransomware scare reads like a Netflix hospital series episode in which the machinery of care is briefly forced back into the nineteenth century, and everyone is reminded how thin the membrane is between digital normalcy and clinical improvisation. This week, AnMed joined a growing list of healthcare systems hit by ransomware, and the attack shut down systems, forced some closures, and delayed treatments and procedures.
AnMed closed offices on Monday and reopened Tuesday with paper charts, paper routines, and the patient safety choreography that hospitals hold in reserve for exactly this kind of breakdown. The hospital insists care continues through established downtime procedures, with transfers, diversions, and triage decisions guided by safety rather than software, while administrative staff work through the backlog of missed appointments.
For local physicians and those charged with taking care of patients, it is an anxious time.
One local physician said these challenges must be particularly concerning for young doctors, and for those who have practiced for decades recalls the days of paper charts, clipboards and typewriters - but without landline phones to which they had access in days those days.
The lack of access to information can be more than an inconvenience, placing caregivers at a greater risk of making mistakes that software can normally help protect against.
Pharmacy issues are also a potential problem without access to internet or phone-in refills, which AnMed sought to offer some remedy by setting up a series of phone numbers which are working for patients to call to inquire about prescription refill requests between 9 a.m.-4 p.m. Monday-Friday. For a list of those phone numbers and the latest information released by AnMed, visit go.anmed.org/latest-updates.
AnMed has been tight on information about the attack and status of restoring order. In a release late Tuesday, they stated:
“We are making progress in restoring systems safely and securely while working alongside federal and state authorities and third-party specialists in response to a cybersecurity incident involving malware. Protecting patients and providing safe care remain our highest priorities.
We understand the community has many questions, and we want to reassure you that your care and safety remain our highest priorities. As our response to this cybersecurity incident continues, we appreciate your patience and understanding. To keep you fully informed, we’ve created a single, centralized resource where you can find the latest updates, guidance and answers to the most common questions we’re hearing. Please visit go.anmed.org/latest-updates for the latest.
For the most current list of service and practice closings, please visit go.anmed.org/latest-updates.
Teams are working around the clock to restore systems safely. Additional updates will be shared as more information becomes available.”
These general comments do not address the cause(s) of the cyber attack, a timetable for returning to regular service, whether any patients have been put at risk by the situation or what patient data is potentially at risk.
AnMed is not alone in such an event. The episode arrives against a grim backdrop. The FBI said healthcare was the No. 1 targeted sector in 2025, with 460 ransomware attacks and 182 data breaches, and industry reporting suggests the pressure has not eased in 2026. In the first half of this year alone, one tracker recorded 410 healthcare ransomware attacks, most aimed at hospitals, clinics, and direct care providers.
The broader pattern is by now familiar enough to feel almost ritualized. Attackers gain entry through phishing, stolen credentials, exposed remote access, or unpatched software; they move laterally, encrypt files, and often steal data first so they can demand payment twice, once for restoration and once to prevent publication. In healthcare, that can mean EHRs, scheduling, billing, lab systems, pharmacy workflows, and communication tools go dark all at once.
That is what makes these attacks so unnerving: the damage is not limited to computers. It can delay tests, cancel procedures, divert ambulances, and force clinicians into manual workarounds that make the practice of medicine slower and riskier. Industry groups say these are not merely financial crimes but patient-safety events, because a hospital without its systems is still a hospital, but one practicing under duress.
Artificial Intelligence is part of the reason the attacks are getting more efficient, though not the only reason. Attackers are using AI-enabled tools to speed reconnaissance, improve phishing, automate attack steps, and make social engineering more convincing, while the old vulnerabilities — weak credentials, vendor exposure, legacy software, and systems that cannot easily be taken offline — continue to supply the real weak points.
The result, in AnMed’s case and in healthcare more broadly, is a grim kind of operational theater: telephones go silent, the internet becomes theoretical, and paper returns as a temporary civic technology. What remains is the one thing the hospitals insist on preserving: continuity of care, however analog, however anxious, however dependent on the endurance of the people holding the clipboard.
Experts say one of the biggest misconceptions is that organizations can completely prevent ransomware attacks, but some added precautions can help.
“Hospitals can make themselves harder targets through multi-factor authentication, timely patching, network segmentation, continuous monitoring, security training, and offline backups,” Dheeraj Nayak, a cybersecurity engineer in Virginia told The Anderson Observer. “Most ransomware groups look for the path of least resistance.”
“The reality is that healthcare systems are among the most heavily targeted industries because they manage critical services that can't simply stop operating,” said Nayak. “The objective isn't to become impossible to attack, but to become resilient enough that an attack is either detected early or fails to significantly disrupt patient care.”
He said a good takeaway is that a ransomware attack should be treated as a forensic lesson, not just a technical cleanup. The real work begins after the systems are back up: figuring out how the attackers got in, what they touched, whether data left the network, and how to harden the hospital so the same weakness does not reappear. Cybersecurity, in that sense, is less a purchase than a discipline.
On ransom payments, Nayak said the point is not that organizations never feel pressure to pay; it is that payment offers no sure escape. Sometimes a decryption tool works, sometimes recovery is partial or slow, and sometimes stolen data still ends up leaked or sold. That is why law enforcement generally discourages payment when a hospital has tested backups and a viable recovery plan, because the strongest position is one that does not depend on the attacker’s goodwill.
The larger lesson is that this is not merely an IT problem. When systems fail, hospitals can revert to downtime procedures, but every minute spent on paper increases strain on staff and raises the risk to patients. In that way, cybersecurity becomes part of clinical care itself, and investment in it becomes investment in continuity of care.
The story is developing…