AnMed confirms data theft, downplays gang’s 6 TB leak claim

AnMed says cybercriminals obtained information during its July network incident and will notify patients after an independent review.

MedRisk Staff
By
2 Min Read

AnMed, the largest independent nonprofit health system in South Carolina, acknowledged on August 21 that the cyber incident which knocked out operations in late July did expose some of its data. Chief executive William Kenley delivered the disclosure in a recorded message aimed at patients, staff, and the wider community.

The organization is treating the attackers’ account of the theft with skepticism. A group that took over AnMed’s Facebook page on August 11 claimed to have made off with roughly 6 TB of records, but the health system says those assertions are too vague to establish which information was actually touched or whose data sits in the haul. An independent investigation must finish before AnMed draws conclusions or starts notifying people.

Recovery is well under way on the operational side. Telephone lines, read-write access to electronic health records, and the MyChart patient portal – restored on August 12, 17 days after the disruption began – are all back in service, and engineers are still working through the remaining systems.

The health system is also bracing patients and employees for possible follow-on activity from the intruders, who could leak material, reach out to individuals directly, or publish fresh claims. Anyone who receives an unsolicited message mentioning AnMed should not reply, follow links, open attachments, hand over personal details, or send money – and direct threats should go to law enforcement.

AnMed, built around a 461-bed medical center in Anderson, plans to contact affected individuals directly and offer support once the review wraps up.

Share This Article