AnMed: Hacker Ransom Posts on Facebook Unverified

According to AnMed, claims made in ransom messages posted to the health system’s Facebook page by suspected hackers on July 29 have not been verified, even as the organization continues to restore network operations following a cyberattack that began on July 26.

Facebook Ransom Claims and Ongoing Investigation

Suspected hackers posted nearly 100 ransom messages on AnMed’s Facebook page on Tuesday morning, alleging that six terabytes of critical information—including patient records, Social Security numbers, and medical histories—had been exfiltrated, according to system statements and local reporting by WYFF News 4. AnMed stated Tuesday afternoon that the claims contained in the posts remain unverified. Cybersecurity specialists removed the unauthorized content, disabled platform access, and are currently investigating the incident alongside the platform provider, according to official updates.

System Restoration and Patient Access

Patients with an active MyChart account and a mobile number on file can once again log in to access health information, receiving a text message with a verification code to complete the process, according to AnMed’s Wednesday release. The health system noted that patients do not need to click any links or provide personal information beyond the code. Additionally, beginning at 7 a.m. Wednesday, patients regained the ability to call doctors’ offices and departments directly during regular service hours. This follows an announcement Tuesday evening that care teams have regained full read and write access to electronic health records.

The cyberattack has placed operational strain on patients and neighboring healthcare facilities in the Upstate region. Patient Brian Cain told WYFF News 4 that he felt immediate panic upon seeing the Facebook ransom posts and described feeling left in limbo while waiting on urgent testing for his permanently disabled wife. Meanwhile, Prisma Health officials reported operating under downtime procedures with staff logging medications and vitals via pen and paper, though a Prisma spokesperson stated there is no indication their connectivity issues are tied to cybersecurity.

Expert Analysis on Hospital Vulnerabilities

Phil Yanov, a cybersecurity expert with Tech After 5, told WYFF News 4 that hospitals present large and complex threat surfaces due to numerous third-party vendors. Yanov explained that the ransom messages posted to social media were designed as pressure tactics to force payment. He also recommended that patients avoid suspicious links or messages appearing to come from AnMed while apps remain down, advising individuals to report suspicious activity immediately.

Did You Know?

According to cybersecurity experts, medical data is often targeted by criminal groups because personal information like Social Security numbers and medical histories cannot be changed the way a compromised credit card number can.

Frequently Asked Questions

Can patients currently access their MyChart accounts?

Yes. According to AnMed, patients with an active MyChart account and a mobile number on file can log in to access health information by using a secure text message verification code.

Are all MyChart features currently available?

No. AnMed stated that while patient access to health information has been restored, not all MyChart features are available yet.

What should patients do if they see suspicious messages or requests to pay bills?

Cybersecurity expert Phil Yanov recommends avoiding suspicious links or messages appearing as AnMed and checking directly with an AnMed representative to ensure you are not being targeted by a scam.

Join the Conversation

How has the recent system outage affected your healthcare routine in the Upstate? Share your thoughts or questions in the comments below, and subscribe to our newsletter for ongoing updates on local health system recoveries.

Facebook hack leads to safety concerns, fake posts

Leave a Comment