Executive Summary

AnMed Health, a regional hospital system in South Carolina (US), has remained 5 days with 13 clinical services closed and sent suspicious messages to patients following a cybersecurity incident. The case illustrates the direct operational impact of a cyberattack on a medium hospital: it’s not just about data, but about patient care.

AnMed has not publicly confirmed whether this is ransomware, but the symptoms (closed services, suspicious messages) are consistent with an encryption attack. The investigation is ongoing with federal support.

Key Points

  • Closed services: 13 for 5 consecutive days, including outpatient consultations, elective surgery, and some diagnostic areas
  • Suspicious messages: patients received anomalous communications, possibly as a consequence of data exfiltration
  • Incident duration: 5+ days without restored operational normality
  • Affected system: AnMed operates 2 hospitals + clinic network in the Upstate of South Carolina
  • Patient notification: initiated but without confirming scope of compromised PHI

Regulatory Implications

HIPAA: Closure of clinical services for 5+ days constitutes a major operational disruption that must be documented as part of the breach analysis. If PHI was compromised, notification to patients within 60 days per §164.404.

Business Continuity (BCP): This case demonstrates that the RTO (Recovery Time Objective) of clinical systems should be less than 24h, not days. Continuity plans should include ransomware scenarios with degraded service.

NIS2: Closure of services for 5 days affects essential service continuity, activating the NIS2 art. 23 notification obligation: early warning <24h, incident notification <72h, final report <30 days.

MDR: If the compromised medical devices are critical (ventilators, infusion pumps, monitors), the manufacturer must evaluate impact on their MDR §10.4 (post-market surveillance).

Recommendation

  1. Clinical Continuity Plan (CCSP): have a specific plan for “what to do when IT systems are down but patients keep arriving”. Paper, manual procedures, emergency roles.
  2. Realistic RTO: target <4h for critical systems, <24h for non-critical. Plans must be tested with annual drills.
  3. Offline backup of critical systems: air-gapped backups that ransomware cannot encrypt. Recovery must be tested, not assumed.
  4. Patient communication: have pre-approved templates for different scenarios (appointment cancellation, possible data compromise, etc.).
  5. Coordination with authorities: FBI, HHS, NCC (if applicable), state regulatory agencies. Have contacts in the playbook.

Source: Becker’s Hospital Review - AnMed cybersecurity incident

This analysis is part of HealthSec, the weekly briefing on healthcare cybersecurity.