On Sunday, July 26, 2026, AnMed — South Carolina’s largest independent, not-for-profit health system, anchored by the 461-bed AnMed Medical Center in Anderson and operating roughly 648 licensed beds across upstate South Carolina and northeast Georgia — confirmed “a cybersecurity disruption involving malware.” Computer systems, phone lines, and internet connectivity went down across all locations. By Monday, 83 of AnMed’s 106 facilities were temporarily closed, including AnMed Medical Group physician offices and AnMed Imaging Services. Emergency departments stayed open and the system ran on established downtime procedures.
The disruption did not resolve in days. A week after the attack, ten facilities remained closed. On August 11, AnMed reported “significant progress,” with care teams regaining full read and write access to electronic health records — sixteen days after the incident began. On August 13, eleven facilities were still closed to appointments and the patient portal was only partially restored. Also on August 11, the ransomware group The Gentlemen hijacked AnMed’s Facebook page and posted a 72-hour ultimatum, claiming 6 terabytes of data including Social Security numbers, HIV status, mental health records, genetic data, and records relating to sexual assault and harassment. AnMed said the claims “have not been verified and are under investigation.”
Then, on Friday, August 21, 2026, CEO William Kenley confirmed what the forensics had found: “the investigation has now confirmed cybercriminals did obtain some information from AnMed.” A detailed review is underway to determine what was taken and who was affected; individuals will be notified directly. Kenley added: “I recognize the concern, frustration and disruption the incident has caused, and I’m deeply sorry.”
Twenty-six days separate the attack from the confirmation of data theft. That interval is the subject of this article — because under the HIPAA Breach Notification Rule, the clock that matters did not start on August 21.
What Is Confirmed and What Is Not
Discipline about the evidentiary record matters here, given the sensitivity of the categories the attackers named.
Confirmed: an incident beginning July 26, 2026; malware; system-wide loss of computing, telephony, and network availability; closure of 83 of 106 facilities; multi-week degradation of imaging, outpatient, and portal services; operation under downtime procedures; involvement of the Anderson Police Department, SLED, and the FBI; fraudulent appointment-reminder texts from July 30 onward; and, on August 21, that “some information” was obtained.
Claimed but unverified: the 6 TB volume and every data category The Gentlemen listed; no sample set has been publicly validated. Not yet public: the number of individuals affected, the specific data elements, the initial access vector, and — as of this writing — any entry on the HHS Office for Civil Rights breach portal. That portal is not a reliable near-term indicator: OCR is running roughly three months behind on publication, a backlog widely attributed to the 43-day federal shutdown of late 2025.
The Gentlemen is a ransomware-as-a-service operation that emerged in late 2025, reportedly founded by a former Qilin affiliate using the handle “hastalamuerte.” Check Point attributed 332 victims to it in the first five months of 2026; other trackers ranked it third most active in Q2 2026. Its documented tradecraft is unglamorous and highly relevant here: initial access through internet-facing edge devices — firewalls and VPN appliances — via credential brute-forcing and vulnerability exploitation, followed by disabling security tooling. That is a control-failure profile, not an act of god.
The Discovery Clock: 45 CFR 164.404(a)(2) Is Not a Forensics Milestone
The most common compliance error in incidents of this shape is treating the day the forensic firm confirms exfiltration as the day the notification clock starts. That is not what the rule says.
45 CFR 164.404(b) requires individual notification “without unreasonable delay and in no case later than 60 calendar days after discovery of a breach.” Two things follow that most organizations underweight.
First, 60 days is a ceiling, not a target. The operative standard is without unreasonable delay. An entity that identifies affected individuals on day 12 and mails on day 58 has satisfied the outer limit and failed the actual standard. OCR has enforced this — the Presence Health settlement remains the canonical penalty imposed for untimeliness alone, with no allegation of deficient safeguards. Regulators reading a letter postmarked at day 59 will ask what happened on days 13 through 58.
Second, discovery is constructive, not actual. Under 164.404(a)(2), a breach is “treated as discovered” on “the first day on which such breach is known to the covered entity, or, by exercising reasonable diligence, would have been known,” with knowledge imputed from any workforce member other than the person who committed the breach. The rule does not require certainty. It requires reasonable diligence.
Apply that to an incident that took down computing, telephony, and connectivity across a 106-facility health system and forced 83 closures. An actor with sufficient access to destroy availability across the estate had, by definition, sufficient access to read data. Availability loss at that scale is not evidence of exfiltration, but it is unambiguous evidence that exfiltration is plausible enough to demand investigation. A defensible position is that the reasonable-diligence clock engaged in late July, not on August 21 — moving the outer limit for individual notification from roughly October 20 to late September.
Any organization in this position should document, contemporaneously, when it concluded a reportable breach had occurred and what facts drove that conclusion. The CareCloud notification-delay analysis shows what happens when that reasoning is reconstructed after the fact rather than recorded in real time.
There is a ransomware-specific corollary. OCR’s guidance treats ransomware on a system containing ePHI as a presumptive breach unless the entity demonstrates a low probability of compromise through the four-factor assessment at 164.402(2): the nature and extent of the PHI, the unauthorized person involved, whether the PHI was actually acquired or viewed, and the extent to which risk has been mitigated. The burden runs against the covered entity. Silence in the forensic record is not a finding of “no acquisition”; it is an absence of evidence the entity must overcome.
The 500-Threshold Machinery, and South Carolina’s Own Clock
Once the population is scoped, the downstream obligations are mechanical, and a system of AnMed’s size will cross every threshold.
Individual notice — 164.404. Written notice by first-class mail (or email where agreed), containing the five content elements at 164.404(c): what happened including dates of breach and discovery, the types of information involved, steps individuals should take, what the entity is doing to investigate and mitigate, and contact procedures.
Media notice — 164.406. For a breach affecting more than 500 residents of a state or jurisdiction, notice to prominent media outlets serving it, on the same 60-day outer clock. AnMed’s catchment spans South Carolina and northeast Georgia, so this analysis runs per jurisdiction.
HHS notice — 164.408(b). For breaches affecting 500 or more individuals, notice to the Secretary “contemporaneously with the notice required by 164.404(a)” — not at the end of the calendar year. The annual-log route at 164.408(c) applies only to breaches under 500.
Substitute notice — 164.404(d)(2). If contact information is insufficient for ten or more individuals, a conspicuous 90-day homepage posting or major media notice, plus a 90-day toll-free number — feasibility worth planning where web and phone infrastructure was itself degraded for weeks.
State law runs in parallel. S.C. Code § 39-1-90 requires notice to affected residents “in the most expedient time possible and without unreasonable delay,” and — above 1,000 residents — notice to the Consumer Protection Division of the South Carolina Department of Consumer Affairs and to nationwide consumer reporting agencies. Knowing and willful violation carries an administrative fine of $1,000 per affected South Carolina resident, materially different arithmetic from HIPAA’s tiered penalties. Georgia residents pull in a second regime. HIPAA does not preempt more stringent state law, so the calendar has several clocks on it, not one.
One further wrinkle, given the categories the attackers claimed: following the 2024 Part 2 alignment rule, 42 CFR Part 2 substance use disorder records now fall within the HIPAA Breach Notification Rule, and the OCR portal accepts them — see our Part 2 enforcement analysis.
The Security Rule Landscape in August 2026: Still Proposed
It is worth being precise about the regulatory state of play, because much vendor marketing is not.
OCR published its Notice of Proposed Rulemaking to modernize the HIPAA Security Rule on January 6, 2025. The comment period closed March 7, 2025, drawing close to 5,000 comments, including organized opposition — eight associations, among them CHIME and the American Health Care Association, asked that the proposal be rescinded. The Spring 2025 regulatory agenda pointed to a May 2026 final rule. That did not happen. The Unified Agenda now shows the final rule slipping to July 2027, and as of August 2026 no final rule exists; it could still be finalized as proposed, modified, republished, or withdrawn. We track that uncertainty in our analysis of the missed May 2026 deadline.
What the NPRM proposed is nonetheless the best available statement of where OCR’s enforcement thinking sits: eliminating the “addressable” versus “required” distinction so that every implementation specification becomes mandatory subject to narrow exceptions; mandatory multi-factor authentication; encryption of ePHI at rest and in transit; an annually updated written asset inventory and network map; network segmentation; six-monthly vulnerability scanning and annual penetration testing; annual compliance audits; and restoration of critical systems and data within 72 hours of a loss.
Map those against the tradecraft attributed to The Gentlemen. MFA defeats brute-forcing against a VPN appliance. An asset inventory tells you the appliance exists and needs patching. Segmentation is the difference between one compromised edge device and 83 closed facilities. A 72-hour restoration objective is a very different posture from sixteen days to full EHR read/write.
Critically, none of this requires the final rule to be enforceable today. The current Security Rule already mandates risk analysis at 164.308(a)(1)(ii)(A), risk management at 164.308(a)(1)(ii)(B), and access controls at 164.312(a). OCR’s Risk Analysis Initiative has produced a run of ransomware settlements built on exactly those provisions — see our coverage of four ransomware-driven HIPAA settlements. Waiting for 2027 to implement MFA is not a compliance strategy.
The Finding Nobody Discusses: 164.308(a)(7) Contingency Planning
Here is the part of this incident that is a compliance finding regardless of whether a single record was exfiltrated.
45 CFR 164.308(a)(7) requires policies and procedures “for responding to an emergency or other occurrence (for example, fire, vandalism, system failure, and natural disaster) that damages systems that contain electronic protected health information.” Its implementation specifications are:
- (ii)(A) — Data backup plan (required): retrievable exact copies of ePHI.
- (ii)(B) — Disaster recovery plan (required): procedures to restore any loss of data.
- (ii)(C) — Emergency mode operation plan (required): continuation of critical business processes protecting ePHI security while in emergency mode.
- (ii)(D) — Testing and revision procedures (addressable).
- (ii)(E) — Applications and data criticality analysis (addressable).
Three of those five are required, not addressable. And the standard is not a privacy control but an availability control. HIPAA’s general requirement at 164.306(a)(1) obliges covered entities to ensure the confidentiality, integrity, and availability of all ePHI. Availability is a first-class obligation the profession routinely treats as an IT concern rather than a compliance one.
Weeks of closed imaging services, unavailable outpatient appointments, and degraded portal access is, on its face, a question about (ii)(C) and (D). Did the emergency mode operation plan contemplate simultaneous loss of computing, telephony, and internet across the whole estate? Had it been tested at that scope, or only as a tabletop for a single application? Did the criticality analysis under (E) rank imaging and scheduling, or only the EHR? OCR asks these questions.
An organization that cannot state, from a dated test record, how long it takes to restore its top twenty clinical applications does not have a contingency plan. It has a document.
Availability Is a Patient Safety Problem, Not Only a Privacy One
The evidence base linking hospital ransomware to clinical harm is no longer thin, and compliance functions should be citing it in board materials.
McGlave, Neprash, and Nikpay — publishing in the American Economic Journal: Economic Policy in February 2026 — found that among patients already admitted when a ransomware attack begins, in-hospital mortality rises by 34 to 38 percent, with hospital volume falling 17 to 24 percent during the attack week. Dameff and colleagues, in JAMA Network Open (2023;6(5):e2312270), documented that an attack at one hospital produced measurable disruption at adjacent, uninfected emergency departments — higher census, more patients leaving without being seen, longer stays. Ransomware is a regional care-capacity event, not a single-institution IT event.
That reframes several obligations. CMS Conditions of Participation at 42 CFR 482.15 require an emergency preparedness program addressing “man-made” emergencies, including continuity of operations and a communications plan — and a communications plan assuming working telephony is a plan that failed on July 26. The Joint Commission’s emergency management standards similarly expect hospitals to plan for loss of information technology and to demonstrate through exercises that clinical operations continue. Downtime procedures, paper fallback, manual order entry, hand-carried imaging results, and diversion protocols are patient safety infrastructure, testable in advance.
AnMed emphasized that clinicians retained access to medical records and that safe care was the priority, and keeping emergency departments open through a multi-week outage suggests its downtime procedures functioned. But the lesson generalizes: the quality of your paper fallback on day one is determined by what you rehearsed in the preceding year.
Nonprofit and Regional Systems: The Recognized Practices Safe Harbour
AnMed is an independent, not-for-profit system of roughly 3,600 employees and about $643 million in annual revenue, and the largest employer in Anderson County. That profile — regionally essential, independent, without the security budget of a multi-state system — describes a large share of American hospital capacity, and it is precisely the population ransomware groups have learned to target. Two federal instruments address this, and both are underused.
The HHS Healthcare and Public Health Sector Cybersecurity Performance Goals (CPGs), published in January 2024, split into essential goals (mitigate known vulnerabilities, email security, MFA, basic training, strong encryption, revoke credentials on departure, basic incident preparedness, unique credentials, separate privileged accounts, vendor requirements) and enhanced goals (asset inventory, third-party vulnerability disclosure and incident reporting, network segmentation, centralized log collection and incident preparedness, configuration management). They are voluntary, but they are the clearest statement of what HHS considers a floor, and the essential list maps almost item-for-item onto edge-device intrusion failure modes.
Recognized security practices are a statutory safe harbour. Under Public Law 116-321, signed January 5, 2021, amending section 13412 of the HITECH Act, HHS must consider whether a regulated entity has had recognized security practices in place for the previous 12 months when determining civil money penalties, calculating remedies, and deciding the length and extent of an audit. Qualifying practices are the NIST Cybersecurity Framework, the section 405(d) Health Industry Cybersecurity Practices (HICP), and other statutorily recognized programs.
The safe harbour is real, and also the most commonly botched claim in OCR correspondence, because entities assert it without evidencing it. To document twelve months of recognized practices:
- Declare the framework in writing — a dated, executive-approved policy stating that the organization has adopted 405(d) HICP (specifying small, medium, or large practice volume) or the NIST CSF as its security program basis.
- Map controls to the framework, with owners — a maintained crosswalk from each HICP practice or CSF subcategory to the specific control, system, and accountable individual.
- Keep dated operational evidence across the whole 12 months, not a snapshot — scan reports, patch cycle records, MFA enrollment over time, phishing simulation results, monthly training completion, access review sign-offs, backup test restores, tabletop after-action reports.
- Show the gaps and the remediation path. A risk register with dated entries, decisions, and closure evidence is more persuasive than a claim of full compliance.
- Retain it for six years consistent with 164.316(b)(2)(i), and assemble the package before you need it. Reconstructing twelve months of evidence during an OCR data request is too late.
Post-Incident Checklist: The First 30 Days and the Board’s Questions
Preserve, immediately:
- Forensic images, EDR telemetry, firewall and VPN logs, authentication logs, and egress/netflow data covering the full pre-incident dwell window — not just the detection date forward. Suspend log rotation by written order.
- The ransom note, extortion communications, social-media hijack artifacts, and dated screenshots of the leak-site listing.
- A contemporaneous incident timeline with named decision-makers, recording when each material fact became known — the primary defense on the discovery question.
- Legal-hold notices to IT, clinical operations, communications, and the executive team.
File and notify:
- Determine and document in writing the discovery date under 164.404(a)(2) and the reasoning behind it.
- Complete the 164.402(2) four-factor risk assessment for each affected data population, recording why the presumption of breach was or was not rebutted.
- Individual notice under 164.404 with all five content elements; HHS notice under 164.408(b) contemporaneously; media notice under 164.406 per jurisdiction over 500.
- State filings: S.C. Code § 39-1-90 Consumer Protection Division notice above 1,000 residents, plus consumer reporting agencies; the equivalent Georgia analysis; any other state of residence.
- Business associate notifications under 164.410 in both directions, and coordination with law enforcement already involved.
What the board should be asking:
- What is our documented discovery date, and can we defend it?
- When was our emergency mode operation plan last tested at full-system scope, and what did the after-action report say?
- What is our measured restoration time for the top twenty clinical applications against a 72-hour objective?
- Do we have MFA on every internet-facing service, including VPN and remote administration? If exceptions exist, who approved them and when?
- Do we have a current asset inventory and network map, and does it include edge devices?
- Can we produce, today, twelve months of dated evidence of recognized security practices under PL 116-321?
- What is our patient-safety plan for a four-week degradation — not a four-hour one — and have clinical leaders signed off on it?
Conclusion
The arc of the AnMed incident is one healthcare has seen dozens of times: an intrusion, a system-wide availability collapse, weeks of degraded clinical services, an extortion group making maximalist claims about the most sensitive categories of health information, and — a month later — confirmation that data was taken, scope still unknown.
Two lessons are worth extracting while the notification work is still in progress. The first is legal: the 60-day clock at 164.404(b) runs from constructive discovery, not from forensic confirmation, and it is an outer limit rather than a schedule. An organization that starts counting on the day the report lands has given away weeks of defensible position, and the documentation that would prove otherwise cannot be created retroactively.
The second is structural. Availability is a HIPAA obligation. 164.306(a)(1) says so, 164.308(a)(7) operationalizes it, and the mortality literature has attached a number to the consequence of failing it. Weeks of closed imaging services and unavailable outpatient care is a contingency-planning finding whether or not a single record ever surfaces on a leak site. The organizations that come through incidents like this best are not the ones with the thickest breach-response binders. They are the ones that rehearsed operating without their systems, and can prove it with a dated after-action report.
Sources: HIPAA Journal — AnMed Investigating Ransomware Group’s Data Theft Claims, Fox Carolina — AnMed confirms data stolen during July cybersecurity incident, The Record — Ransomware group hijacks hospital system’s Facebook page, Healthcare Dive — 10 AnMed facilities remain closed a week after cyberattack, Healthcare IT News — AnMed given 72 hours to respond to demands in ransomware incident, Modern Healthcare — AnMed cybersecurity incident triggers facility closures, HHS OCR Breach Portal, S.C. Code § 39-1-90, McGlave, Neprash & Nikpay — Hacked to Pieces? The Effects of Ransomware Attacks on Hospitals and Patients, Dameff et al. — Ransomware Attack Associated With Disruptions at Adjacent Emergency Departments, JAMA Netw Open 2023
This article is provided for informational purposes only and does not constitute legal advice.



