
- A malware attack forced AnMed to close roughly 80 healthcare facilities across South Carolina and Georgia over the weekend, disrupting patient care and knocking out phone and internet systems network-wide.
- Cybercrime carries steep costs for everyone involved: healthcare breaches average $7.42 million each, and 72% of affected organizations report disruptions to patient care.
- A current, thorough HIPAA risk analysis — paired with ongoing risk management — is the most effective safeguard against incidents like this one, not a one-time compliance exercise.
- Because both the threat landscape and HIPAA requirements keep evolving, organizations need to stay on top of regulatory changes and refresh their defenses accordingly.
This week’s cybersecurity headline from the Carolinas is a stark reminder of how vulnerable healthcare organizations remain — regardless of size or resources.
On July 26, 2026, AnMed, a nonprofit health system serving upstate South Carolina and northeast Georgia, confirmed a “cybersecurity disruption involving malware.” The impact was sudden and severe: roughly 80 care facilities, including primary care offices, imaging centers, oncology services, and women’s care locations, were forced to close. Phone and internet systems across the network went down. Elective procedures were postponed, and patients were asked to bring their medications in the original containers and be ready to recite their medical histories because staff couldn’t access electronic health records.
Emergency departments remained open, and AnMed’s care teams continued treating patients despite the chaos. But this was an outright operational crisis, not a minor IT hiccup. State and federal law enforcement are now involved.
AnMed has not yet confirmed whether patient data was accessed or stolen, and legal teams are already exploring class-action litigation on behalf of patients and employees. For compliance managers, IT professionals, and healthcare business owners — especially those running small and mid-sized organizations — the AnMed incident isn’t just a preventive headline. It’s a case study in the very risks the HIPAA Security Rule was designed to address.
By July 28, AnMed was beginning to reopen some locations, while others remained closed.
Cybercrime Is Extraordinarily Costly — for Patients and for Providers
It’s tempting to view a cyberattack as primarily an IT problem, but the true cost is measured in dollars, disrupted care, and weakened trust. According to IBM’s 2025 Cost of a Data Breach Report, healthcare has held the unenviable title of the most expensive industry for data breaches for 14 consecutive years, and the average incident now costs $7.42 million. Breaches in the sector also take an average of 279 days to identify and contain — nearly nine months during which attackers may have unrestricted access to protected health information (PHI).
The human cost is even more sobering. Research by the Ponemon Institute and Proofpoint, published in 2025, found that 72% of healthcare organizations hit by a cybersecurity incident reported disruptions to patient care, and nearly a third reported increased patient mortality. When systems go down, as they did across AnMed’s network, clinicians lose access to medication histories, lab results, and imaging — and patients lose access to care altogether, as evidenced by the dozens of AnMed locations that couldn’t open their doors.
For a small or mid-sized covered entity or business associate, a breach of this scale could be existential. Beyond the immediate costs of forensic investigation, system restoration, and legal fees, organizations face potential OCR enforcement, state attorney general actions, patient notification obligations, reputational damage, and — increasingly — class action lawsuits, as AnMed is now facing. There is no “cheap” version of a cyberattack.
HIPAA Compliance Is Your First Line of Defense
This is precisely why HIPAA compliance cannot be treated as a paperwork exercise or a once-a-year checkbox. The HIPAA Security Rule exists to ensure that organizations handling PHI have implemented the administrative, physical, and technical safeguards needed to prevent incidents like AnMed’s — or, at a minimum, to limit the damage when an attacker does get in.
Notably, one of the contributing factors in many healthcare breaches is the human element: phishing emails and malicious attachments remain among the most common entry points for malware. The HIPAA Privacy Rule’s administrative requirements under §164.530 require covered entities to train their entire workforce on privacy and breach notification policies and procedures — and that training must include practical, ongoing education on recognizing and reporting suspicious emails and links. Security software alone isn’t enough; it’s only as good as its configuration and update cadence, and it can still be evaded. Your staff are both your biggest vulnerability and your best line of defense, depending on how well they’re trained.
The Risk Analysis Is Not Optional — It’s the Foundation
If there’s one HIPAA requirement that consistently separates organizations that weather an attack from those that are devastated by one, it’s the Security Rule’s mandate for a thorough, accurate risk analysis. Under 45 CFR §164.308(a)(1)(ii)(A), covered entities and business associates must conduct an accurate and complete assessment of potential threats and vulnerabilities to the confidentiality, integrity, and availability of the ePHI they hold.
This isn’t a one-time task you complete when you first open for business and then file away. A risk analysis is only useful if it reflects your current environment — including your network architecture, vendors, devices, remote access points, and threat landscape. Attackers constantly evolve their tactics, so your risk analysis and risk management plan must evolve as well. Ask yourself: When was your last risk analysis conducted? Does it cover every system that touches PHI, including imaging, scheduling, and billing platforms? Have you implemented a risk management plan to address what it identified, or is it still sitting in a drawer?
Continuous risk management means continuously monitoring for new vulnerabilities, promptly patching systems, segmenting networks so that a single point of failure can’t take down an entire organization, maintaining tested backup and disaster recovery procedures, and validating that business associates handling your PHI are equally diligent. An 80-facility shutdown is the kind of outcome that secure network segmentation and incident response planning are designed to prevent or contain.
Keeping Current on HIPAA Changes Is Essential
HIPAA is not static, and neither is the threat environment it was designed to address. OCR has continued to signal heightened enforcement priorities regarding risk analysis deficiencies, and proposed updates to the Security Rule — including more prescriptive technical requirements — are under active discussion. Organizations that treat compliance as a static, check-the-box exercise are most likely to be caught flat-footed by regulators and attackers alike, especially when defenses are outdated.
Keeping current means regularly reviewing OCR guidance, tracking rule changes, updating policies accordingly, and refreshing workforce training to reflect emerging threats. It also means learning from incidents like AnMed’s — not with an attitude of “that won’t happen to us,” but by asking what safeguards might have limited the damage and whether your organization has those safeguards in place today.
The Bottom Line
The AnMed attack is still unfolding, and we don’t yet know the full scope of what was compromised. But the operational and financial toll is already clear. It underscores a truth that should guide every healthcare organization’s compliance strategy: cybercrime is costly, patient safety is at stake, and HIPAA compliance — grounded in a current, in-depth risk analysis and sustained by continuous risk management — is the most effective tool for reducing your risk.
If it’s been a while since your organization completed a comprehensive HIPAA risk analysis, now is the time to revisit it.

