Overview
AnMed, an independent, not-for-profit health system serving Upstate South Carolina and northeast Georgia, reported a simultaneous phone and internet outage affecting all four of its hospital locations on July 26, 2026. The affected facilities include AnMed Medical Center, AnMed Cannon, AnMed Rehabilitation Hospital, and Regency Hospital – Upstate. Emergency rooms at the affected sites remained open and continued seeing patients during the outage.
Details on the cause of the disruption had not been publicly confirmed at the time of initial reporting. It is not yet known whether the outage stems from a cyberattack, infrastructure failure, or a third-party network provider incident. AnMed had not issued a formal statement describing the technical origin or expected restoration timeline as of the time of publication.
The breadth of the outage — spanning phone and internet simultaneously across all locations — raises immediate questions about whether clinical operations, electronic health record access, and patient data systems were affected alongside communications infrastructure.
Key developments
Total communications loss across a multi-hospital system. The simultaneous failure of both phone and internet services across four geographically distributed hospitals points to either a centralized network dependency or a coordinated disruption. Single-point failures of this scale are a recognized risk in health systems that consolidate network routing through shared infrastructure.
Emergency departments remained operational. AnMed confirmed that ERs continued to receive and treat patients, suggesting clinical staff activated downtime procedures. Whether those procedures included paper-based documentation, offline clinical decision support, or diversion of non-emergency cases was not reported.
Cause and scope remain unconfirmed. As of the time of publication, AnMed had not attributed the outage to a specific cause. The pattern — full phone and internet loss across all sites — is consistent with both ransomware-initiated network isolation and with unplanned infrastructure failures, and investigators and hospital staff were still assessing the situation.
PHI exposure risk is undetermined. Until the cause is confirmed, the question of whether protected health information was accessed, exfiltrated, or encrypted cannot be answered. If a cyber incident is ultimately identified, HIPAA breach notification obligations under 45 C.F.R. § 164.400–414 would apply, requiring notification to HHS and affected individuals within specified timeframes.
Industry impact
Health system outages that disable communications across multiple facilities simultaneously have become a recognized pattern in healthcare cybersecurity incidents. HHS's Office for Civil Rights and the Health Sector Cybersecurity Coordination Center (HC3) have both documented that ransomware and network intrusions frequently begin with the disruption or isolation of network connectivity before operators detect malicious activity.
According to IBM's Cost of a Data Breach Report, healthcare has ranked as the most expensive sector for breach costs for more than a decade, with the 2023 report placing the average healthcare breach cost at $10.93 million — more than double the cross-industry average. Operational disruptions compound direct breach costs through clinical delays, staff overtime, and recovery infrastructure expenses.
Multi-hospital systems operating on shared network backbones face amplified exposure: a single compromised network segment can cascade outward to affect all connected facilities. The Joint Commission and HHS have both issued guidance emphasizing the need for facility-level downtime procedures precisely because centralized connectivity creates shared failure points.
What this means for independent practices
- Activate and review downtime procedures now. Independent practices should confirm that written, paper-based downtime procedures exist, are current, and are physically accessible to clinical staff without internet or EHR access. - Audit single points of network failure. Practices sharing internet or phone infrastructure through a single provider or routing hub should evaluate whether a loss of that connection would disable all clinical and communications operations simultaneously.
- Verify that backup communications are functional. Cellular-based backup lines, out-of-band contact methods for staff, and emergency contact lists for patients should be tested periodically, not only documented.
- Confirm business associate notification obligations. If a practice uses cloud-based EHR, billing, or scheduling systems, review business associate agreements to understand how quickly vendors must notify the practice of connectivity disruptions that could affect PHI availability or integrity.
- Monitor the AnMed situation for HIPAA breach implications. If AnMed's outage is attributed to a cyber incident, the regulatory response and timeline will be instructive for how multi-site systems are expected to handle notification and remediation.
Regardless of the final cause determination at AnMed, the incident demonstrates that communications infrastructure and clinical data systems are deeply interdependent in modern health settings. Independent practices that have not tested what operations look like without internet or phone access are effectively deferring that test to a moment of actual crisis. Building and rehearsing downtime workflows — including how staff document care, communicate internally, and reach patients — is an operational discipline, not a contingency to defer.
What would have prevented this
Network segmentation: Designing hospital networks so that a failure or compromise in one segment does not automatically propagate to all facilities limits the blast radius of both infrastructure failures and malicious intrusions. Each facility or functional unit should be capable of isolated operation.
Redundant communications infrastructure: Maintaining independent, carrier-diverse internet and phone connections — including cellular failover — ensures that the loss of one provider or routing path does not eliminate all external and internal communications simultaneously.
Tested downtime procedures: Documented procedures for operating without EHR, internet, or phone access are only effective if staff have practiced them. Scheduled downtime drills reveal gaps in paper-based workflows before those gaps become patient-safety issues during an actual event.
Out-of-band network monitoring: Monitoring tools that operate on a separate network path from production systems can detect anomalies and alert administrators even when primary infrastructure is disabled, enabling faster diagnosis of whether an outage is a technical failure or an active incident.
Privileged access controls with anomaly detection: Restricting which accounts and devices can modify core network routing and firewall configurations — and alerting on unusual changes — reduces the ability of an attacker or misconfiguration to take down system-wide connectivity without detection.