Overview
AnMed, an independent, not-for-profit health system serving Upstate South Carolina and northeast Georgia, reported a simultaneous loss of phone and internet connectivity across all four of its facilities on July 26, 2026. The affected locations include AnMed Medical Center, AnMed Cannon, AnMed Rehabilitation Hospital, and Regency Hospital – Upstate. Emergency rooms at each site remained open and continued to accept patients during the disruption.
The cause of the outage had not been publicly confirmed at the time of initial reporting. DataBreaches.net characterized the situation as developing, indicating that details about scope, duration, and origin were still emerging. Whether the disruption stems from a cyberattack, infrastructure failure, or third-party connectivity issue remained unclear.
System-wide outages of this kind — simultaneously cutting both voice and data communications across multiple facilities — are consistent with patterns seen in ransomware incidents targeting health systems, though they are also consistent with upstream network or ISP failures. The distinction carries significant compliance and reporting implications under HIPAA's Breach Notification Rule.
## Key developments
All facilities affected simultaneously. The outage spanned every AnMed location rather than a single site, which suggests either a centralized network failure point or a coordinated external event. Simultaneous multi-site disruption is a recognized indicator of network-layer compromise.
Emergency services continued without interruption. AnMed confirmed that emergency rooms remained open and patients were still being seen, indicating that clinical staff activated downtime procedures. This reflects an operational continuity capability, though the extent of EHR and clinical system availability during the outage was not publicly detailed.
Cause unconfirmed at time of reporting. AnMed had not attributed the outage to a specific cause in initial public statements. That silence is common in the early hours of a potentially security-related incident, as health systems typically conduct internal triage before making public attributions.
Regulatory clock may already be running. If the outage is determined to have resulted from unauthorized access to systems containing protected health information, HIPAA's 60-day breach notification window and OCR's 10-business-day threshold for notifying HHS of large breaches would apply from the date the system knew or reasonably should have known of the incident.
Industry impact
Health system outages — whether caused by cyberattack or infrastructure failure — carry significant financial and operational consequences. According to the American Hospital Association, cyberattacks that force hospitals into extended downtime have historically cost affected systems millions of dollars per day in diverted care, delayed procedures, and manual workaround labor. The 2024 IBM Cost of a Data Breach Report placed the average cost of a healthcare data breach at $9.77 million, the highest of any sector for the fourteenth consecutive year.
OCR enforcement data shows that health systems of all sizes face post-incident scrutiny not only for the breach itself but for the adequacy of their risk analysis, contingency planning, and downtime procedures under the HIPAA Security Rule. Facilities that lack documented and tested downtime protocols are at heightened risk of compounding enforcement exposure when an outage extends clinical disruption.
Multi-hospital outages also draw attention from state health regulators. South Carolina's Department of Health and Environmental Control has oversight authority over licensed hospital operations, and a prolonged communications failure affecting emergency services can trigger separate state-level review independent of any federal HIPAA action.
What this means for independent practices
- Review your own downtime procedures now. Independent practices that depend on a single internet provider or a single phone system carry the same single-point-of-failure risk visible in this incident. Documented downtime procedures are a HIPAA Security Rule requirement, not optional.
- Confirm you have a backup communication path. If your primary phone and internet fail simultaneously, staff need a tested, pre-approved alternative — whether a cellular backup line, a separate ISP circuit, or a pre-arranged contact protocol with your answering service.
- Know your breach-reporting trigger points. If an outage is later determined to involve unauthorized PHI access, the notification clock runs from when you knew or should have known — not from when the cause is confirmed. Waiting for certainty before engaging legal counsel can cost you reporting-window compliance.
- Audit your network architecture for single points of failure. A single router, switch, or upstream provider serving all clinical and administrative functions is an operational liability. Network segmentation and redundant connectivity reduce the blast radius of any single failure.
- Test contingency plans at least annually. HIPAA's Contingency Plan standard (45 CFR § 164.308(a)(7)) requires that covered entities test and revise their downtime procedures. A plan that exists only on paper provides no protection during an actual outage.
For ongoing operations, independent practices should treat communications infrastructure with the same discipline applied to EHR security. The capacity to receive patients, communicate with referring providers, access records, and report emergencies depends entirely on that infrastructure remaining available or having a tested fallback when it does not.
What would have prevented this
Redundant internet connectivity: Maintaining two independent ISP circuits — ideally using different physical paths and providers — ensures that a failure at one carrier or network layer does not simultaneously sever all connectivity. Automatic failover between circuits can reduce downtime to seconds rather than hours.
Out-of-band communication systems: A cellular-based or satellite backup communication system, kept independent of the primary network, allows staff to maintain voice contact with patients, providers, and emergency services even when primary phone and internet are fully down.
Network segmentation and tiered criticality design: Separating clinical systems, administrative systems, and external-facing networks limits the extent to which a single failure or compromise can propagate across all locations simultaneously. Critical clinical functions should operate on isolated segments with independent routing.
Documented and tested downtime procedures: HIPAA requires covered entities to maintain and test contingency plans. Procedures that are written but never practiced fail under pressure. Regular tabletop and live-drill exercises expose gaps before an actual event forces staff to improvise.
Incident response planning with pre-defined attribution thresholds: Establishing in advance the criteria that distinguish a cyberattack from an infrastructure failure — and the escalation steps for each — reduces the time between outage detection and appropriate response, including timely engagement of legal counsel if a HIPAA notification obligation may exist.