Key Takeaways

  • AnMed will open a centralized patient phone line on Aug. 3 for appointment, prescription and physician-office questions.
  • The malware incident disrupted phones, internet access and electronic health records, prompting closures and manual clinical workflows.
  • AnMed’s response illustrates why healthcare cyber plans increasingly include paper processes, fallback voice channels and regional care coordination.

AnMed is consolidating patient inquiries into a new phone line as it continues restoring systems affected by a malware-related cyberattack. Beginning Monday, Aug. 3, patients can call 864-824-3850 between 9 a.m. and 4 p.m. Monday through Friday for information about appointments, prescription refills and other questions normally directed to doctors’ offices.

The number replaces six phone lines that AnMed previously used only for prescription refill requests. AnMed stated its teams will provide the most complete verified information available while federal, state and third-party investigations continue.

During a hospital outage, a working phone number transforms from a modest operational change into essential communication infrastructure to manage patient flow.

AnMed operates hospitals across the Upstate and Northeast Georgia, with much of its presence concentrated in and around Anderson County. The incident disrupted phones, internet connectivity and access to electronic health records, according to WYFF News 4. Many AnMed Medical Group offices and AnMed Imaging Services closed while emergency care continued under manual downtime procedures.

Some services remained available. AnMed Urgent Care locations, AnMed Kids Care, AnMed Integrated Therapy locations and AnMed Laboratory Services were scheduled to operate. AnMed also coordinated with emergency medical services, public safety agencies and regional hospitals over patient transfers, diversions and care decisions.

Healthcare downtime operates fundamentally differently than an ordinary corporate IT interruption. Clinicians may simultaneously lose access to medication histories, diagnostic images, test results and established communication channels. Work does not simply pause; it shifts to paper, telephone calls and face-to-face coordination under significant time pressure.

Patients described that shift in stark terms. One patient, who was experiencing debilitating stomach pain, reported that a doctor had to write discharge instructions by hand and direct her toward Prisma or St. Francis because AnMed personnel could not access systems needed for tests and scans. Another patient stated that emergency-room computer screens displayed a ransom demand threatening the release of information if AnMed did not pay within 72 hours.

Those accounts point toward ransomware, and the Anderson Observer characterized the event within the broader rise of ransomware attacks on healthcare providers. AnMed publicly described the incident as a cybersecurity disruption involving malware. The investigations remain ongoing, so conclusions about the attacker, the extent of any data access and the credibility of the reported leak threat remain preliminary.

For healthcare technology leaders, the communication problem requires as much attention as system restoration. When portals, office numbers and internal scheduling tools are unavailable, a centralized hotline creates one controlled route for distributing approved information. This reduces the chance that patients will rely on outdated social posts, disconnected numbers or potentially fraudulent messages.

However, a hotline relies on a sound supporting process. Call teams need regularly updated operating information, defined escalation paths and a method for documenting requests when normal applications are unavailable. Staffing also matters; a single public number can simplify access, but it concentrates demand and creates long queues if capacity does not match call volume.

Formal downtime planning is widespread across hospitals, with HIMSS industry survey data indicating that 80% to 90% of facilities maintain procedures such as paper documentation and alternative communication workflows (source). Federal guidance also treats resilient communications, incident response and manual fallback processes as core elements of healthcare security planning under the HIPAA Security Rule and the NIST Cybersecurity Framework.

These disruptions have direct operational consequences. According to the American Hospital Association, more than a third of significant healthcare cyber incidents have caused patient diversions or care delays. Federal data from HHS shows ransomware incidents against U.S. healthcare organizations increased by more than 200% between 2018 and 2023. Becker’s Hospital Review has likewise tracked the operational fallout of cyberattacks for hospitals, where technology failures quickly become clinical and capacity-management problems.

AnMed reported it is taking a deliberate approach to restoring secure access rather than reconnecting systems prematurely. Current information about openings, service changes and frequently asked questions remains available through AnMed’s update page. For medical emergencies, patients are still directed to call 911. When sophisticated clinical systems go dark, continuity of care often depends on comparatively simple tools, provided those tools were planned, staffed and tested before the crisis arrived.