Healthcare Cybersecurity week 31, 2026

Malware forced South Carolina health system AnMed to close 83 facilities this week, while billing vendor Craneware and EHR platform CareCloud disclosed data theft affecting thousands of hospitals and hundreds of thousands of patients.
healthcare
Published

August 4, 2026

Executive Summary

The most disruptive event of the week was a malware attack on AnMed, a nonprofit health system serving upstate South Carolina and northeast Georgia, which forced the temporary closure of 83 of its 106 facilities and knocked out phone and internet connectivity. Two health IT supply chain incidents also dominated coverage: Craneware, a UK-based billing and financial governance software maker used by more than 2,000 hospitals and nearly 10,000 pharmacies and clinics in the United States, confirmed hackers stole a significant volume of customer data, while CareCloud began formally notifying roughly 350,000 patients about a cloud EHR breach first detected in March. Fresh research from Flare highlighted just how deliberately ransomware groups are working through the healthcare supply chain, identifying 14 distinct groups — including Qilin, LockBit 3.0, RansomHub, DragonForce, and a newly emerged gang called Kazu — targeting hospitals, pharmacies, diagnostic labs, and healthcare software vendors across EMEA and, increasingly, Latin America. Meanwhile, the healthcare sector remains explicitly named as high-risk under a joint US and allied advisory covering Russian FSB Center 16 exploitation of poorly hardened network routers.

This report covers cybersecurity threats to the healthcare sector including hospitals, medical devices, health IT systems, and pharmaceutical supply chains.


Week of July 24 - July 31, 2026

Hospital & Health System Attacks

AnMed disclosed a malware-related cyberattack on July 26 that ultimately forced the closure of 83 of its 106 care locations across upstate South Carolina and northeast Georgia, spanning primary care, pediatric care, sleep diagnostics, women’s care, oncology, and medical imaging services. Urgent care, emergency departments, laboratory services, and integrated therapy locations remained open throughout the disruption. Phone lines and internet connectivity were down for an extended period, though the health system said physicians retained access to electronic medical records and framed continuity of safe care as its top priority. By July 30, AnMed had begun warning patients about suspicious communications attempting to exploit confusion around the outage — a reminder that opportunistic phishing and smishing campaigns routinely piggyback on the public confusion generated by a hospital cyberattack. AnMed has not yet disclosed whether patient or employee data was compromised, and the investigation into the malware’s origin and scope remains ongoing.

The incident lands against a backdrop of accelerating ransomware volume against the sector. A report published in early July found that healthcare organizations worldwide faced 410 ransomware attacks in the first half of 2026, up nearly 14 percent from the second half of 2025, with 247 of those attacks striking hospitals and clinics directly and the remainder hitting healthcare businesses such as pharmaceutical manufacturers and billing firms. Median ransom demands for healthcare providers reached 310,000 dollars. Qilin continued to add healthcare victims to its leak site in the days leading into this reporting window, listing City Ambulance Service in the United States on July 19 and Infina Health on July 22, both under the group’s now-familiar double-extortion playbook of exfiltration followed by a leak-site countdown.

Medical Device Vulnerabilities

No major new CISA medical device advisory landed during the week, but the sector is still working through a cluster of disclosures affecting open-source DICOM imaging libraries published in late June — the OFFIS DCMTK toolkit, the pydicom and pynetdicom Python libraries, and the OHIF Viewers project. All three are widely embedded inside commercial picture archiving and communication systems and radiology viewer products, meaning hospitals and imaging centers that assume their PACS vendor is unaffected may still be exposed through an unpatched upstream dependency. Imaging and biomedical engineering teams should treat software bill-of-materials review for these components as unfinished business heading into August, rather than a closed item from June’s advisory cycle.

EHR, Health IT & Cloud Breaches

Craneware, whose billing, financial performance, and governance software underpins operations at more than 2,000 US hospitals and nearly 10,000 retail pharmacies and clinics, confirmed that attackers gained unauthorized access to part of its network and exfiltrated a significant amount of data, including a portion of employee records and a subset of customer and partner information. The company said much of what was taken is non-sensitive or already public regulatory data, but it has not yet confirmed how many patient records, if any, were involved. Craneware said the attackers appear to have been expelled from its systems and that both British and American authorities, including the FBI, have been notified, though the investigation continues.

CareCloud, a New Jersey-based healthcare technology firm that stores patient records for more than 45,000 providers, began mailing breach notification letters that reached the public on July 30, formally disclosing details of a March 2026 intrusion in which a threat actor accessed one of six AWS-hosted electronic health record environments for approximately eight hours. State attorney general filings put the confirmed toll at roughly 345,000 to 350,000 individuals so far, including more than 270,000 Texas residents, with personal, financial, and medical data exposed. The four-month gap between detection and public notification illustrates how long health IT vendor breaches can take to surface in patient-facing disclosures.

Separately, Unlimited Systems, a practice management and revenue cycle software vendor, continued notifying patients this week following letters that began going out on July 21 for a ransomware attack the company traced back to October 2025. More than 442,000 patients are affected. The company said full medical records, diagnostic imaging, and financial account numbers were not involved, and it is offering 24 months of identity monitoring to affected individuals.

Pharmacy & Supply Chain

Research published by Flare on July 24 mapped ransomware leak-site activity against EMEA healthcare organizations between 2024 and 2026 and found that groups are working the entire supply chain rather than concentrating on hospitals alone. The dataset spanned hospitals and clinics, telemedicine providers, diagnostic laboratories, pharmacies, rehabilitation services, healthcare software vendors, staffing agencies, medical equipment suppliers, and public health agencies. Some organizations are hit directly because operational disruption puts patient safety on the line and increases the odds of a fast payout; others are targeted as a stepping stone toward larger, better-defended hospitals that depend on them for records, equipment, or connected systems. Flare counted 14 distinct threat actor groups active against EMEA healthcare targets, among them Qilin, LockBit 3.0, RansomHub, DragonForce, Gunra, NightSpire, and 3AM. The research also flagged Kazu, a smaller ransomware and extortion gang that emerged in mid-2025 initially focused on government and public-sector victims. Kazu first surfaced in the healthcare dataset through an attack on an Italian telemedicine provider, and researchers subsequently found a string of new Kazu victim postings — all healthcare, and all located outside the original EMEA scope in Latin America — suggesting the group is actively expanding its healthcare targeting into new geographies.

On the medical equipment side, AdaptHealth, a nationwide durable medical equipment and home healthcare supplier, disclosed in a July 2 filing with the Securities and Exchange Commission that hackers stole data from customers, with the company’s investigation pointing toward its cloud-based business applications used to store and manage documentation for patients it services with medical devices.

Regulatory & Compliance

Healthcare organizations are still working through the implications of joint advisory AA26-194A, issued July 13 by the NSA, CISA, FBI, and Defense Cyber Crime Center alongside 19 allied international agencies, which details how threat actors linked to the Russian Federal Security Service’s Center 16 continue to exploit poorly configured and unpatched networking devices worldwide. Healthcare and Public Health is explicitly named among the six critical infrastructure sectors most at risk, alongside communications, defense, energy, financial services, and government. The advisory describes attackers scanning for routers accepting default or weak SNMPv1/v2 community strings, then using spoofed SNMP Set-Requests to copy device configurations for exfiltration over TFTP, with additional abuse of exposed Cisco Smart Install functionality. Recommended fixes — disabling Cisco Smart Install, migrating to SNMPv3 with authentication and privacy enabled, blocking UDP port 69 and TCP port 4786 at the network edge, and alerting on configuration-copy operations — apply directly to the router and switch infrastructure underpinning hospital networks, clinical VPNs, and connected medical device segments.

On the enforcement side, HHS’ Office for Civil Rights has resolved six investigations with financial penalties in 2026 through its Risk Analysis Initiative, collecting 1,278,000 dollars as of May, with settled entities including BST & Co., MMG Fusion, Elgon Information Systems, VPN Solutions, Health Fitness Corporation, and Comstar. The pattern across nearly every recent ransomware-related settlement remains the same: a failure to conduct an adequate HIPAA Security Rule risk analysis before the incident occurred. No new marquee settlement was announced during the week, but the volume of individuals affected by the Craneware, CareCloud, and Unlimited Systems disclosures makes each a plausible future subject of OCR scrutiny under that same enforcement pattern.

Threat Actor Activity

Qilin remains the most consistently active ransomware operator against healthcare, appearing both in Flare’s EMEA supply chain dataset and in fresh leak-site postings against a US ambulance service and a healthcare provider in the days surrounding this reporting window. The group’s double-extortion model — exfiltration followed by a leak-site countdown rather than an immediate demand for negotiation — continues to prove effective against organizations that cannot tolerate prolonged downtime.

Kazu’s expansion is the notable new development this week. A group that began mid-2025 with government and public-sector targeting has pivoted decisively toward healthcare, and its documented victim list now runs from an Italian telemedicine provider to a cluster of Latin American healthcare organizations outside its original EMEA footprint — a pattern worth monitoring for hospitals and clinics in that region that may not yet be tracking a relatively obscure group.

FSB Center 16 rounds out the week’s most consequential threat activity, not through a healthcare-specific campaign but through the kind of opportunistic, sector-agnostic network device exploitation that lands wherever poor router hygiene exists — and healthcare’s explicit inclusion in AA26-194A’s list of at-risk sectors confirms that state-linked actors continue to view hospital network infrastructure as fair game for prepositioning and credential harvesting.

Defensive Recommendations

Network and infrastructure teams should treat AA26-194A as an action item rather than background reading: disable Cisco Smart Install where it is not explicitly required, migrate SNMP-managed devices to SNMPv3 with authentication and privacy enabled, block UDP 69 and TCP 4786 at the network perimeter, and configure alerting on router configuration-copy operations across clinical and administrative network segments alike.

Given the Craneware, CareCloud, and Unlimited Systems disclosures, healthcare organizations should refresh their inventory of billing, EHR, and revenue-cycle software vendors that hold PHI, confirm each vendor’s incident notification timeline commitments, and verify that business associate agreements specify reasonable disclosure windows — CareCloud’s four-month gap between detection and public notification is a useful benchmark for what “reasonable” should not look like.

AnMed’s post-incident warning about scam communications is a template worth pre-building rather than improvising during a live incident: organizations should have a ready-to-publish patient communication addressing phishing and smishing risk that can be deployed within hours of any large-scale outage or facility closure, before opportunistic actors get ahead of the health system’s own messaging.

Imaging and biomedical engineering teams should complete software bill-of-materials review against the OFFIS DCMTK, pydicom/pynetdicom, and OHIF Viewers disclosures from late June, since these open-source components are frequently embedded inside commercial PACS and viewer products without hospital IT teams realizing the dependency exists.

Finally, with OCR’s Risk Analysis Initiative continuing to generate settlements rooted in inadequate HIPAA Security Rule risk analyses, compliance teams should treat a current, documented risk analysis as the single highest-leverage artifact to have in place before, not after, an incident draws regulatory attention.

Sources Referenced

  • HIPAA Journal: Patients Warned About AnMed Communications After Cyberattack Closes 83 Facilities, July 30, 2026
  • TechTarget: Cyberattack forces temporary closure of 83 AnMed facilities, July 2026
  • The Record from Recorded Future News: Health system in South Carolina, Georgia closes offices after malware affects networks, July 2026
  • BankInfoSecurity: AnMed Closes Care Facilities As it Deals with Malware Attack, July 2026
  • TechCrunch: Hackers stole “significant” amount of data from tech firm relied on by thousands of US hospitals and pharmacies, July 20, 2026
  • Cybersecurity Dive: Hackers steal customer data from major hospital software vendor, July 2026
  • HIPAA Journal: Major Healthcare Software Vendor Investigating Cyberattack (Craneware), July 2026
  • Cybersecurity Insiders: Healthcare Data Breach Craneware Puts 2,000 Hospitals at Risk, July 2026
  • TechCrunch: CareCloud begins to notify hundreds of thousands after hackers stole medical records, July 30, 2026
  • HIPAA Journal: CareCloud Notifies More Than 345,000 Patients About Cyberattack Data Theft, July 2026
  • HALOCK: CareCloud EHR Breach, July 2026
  • Becker’s Hospital Review: Ransomware attack at health IT vendor exposes 442,000 patients’ data (Unlimited Systems), July 2026
  • Dotmed: Healthcare ransomware attacks rose 14% in first half of 2026, report finds, July 9, 2026
  • Cybersecurity Insiders: Healthcare Ransomware Attacks Shift — Businesses Up 35% While Hospitals Hold Flat, July 2026
  • GalaxyWarden: City Ambulance Service Listed by Qilin Ransomware Group, July 19, 2026
  • GalaxyWarden: Infina Health targeted by Qilin ransomware, July 22, 2026
  • Help Net Security: Ransomware gangs go after EMEA healthcare’s supply chain, July 24, 2026
  • Flare: Impact Analysis of Ransomware Attacks on EMEA Healthcare, July 2026
  • Medical Buyer: EMEA healthcare’s supply chain on ransomware gangs’ radar, July 2026
  • Daily Hodl: 1,261,464 Americans At Risk After Hackers Hit Third-Party Vendor for Healthcare Firms, July 29, 2026
  • CISA: AA26-194A — Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting, July 13, 2026
  • AttackIQ: Response to CISA Advisory AA26-194A, July 15, 2026
  • CISO Platform: Russian FSB Hackers Are Stealing Router Configs Over SNMP — 8 Fixes From Joint Advisory AA26-194A, July 2026
  • HIPAA Journal: Security Researcher Identifies Quintet of Bugs in Toolkit Used in DICOM Medical Imaging Software (OFFIS DCMTK), June 2026
  • CISA: pydicom pynetdicom Library — ICSMA-26-176-01, June 25, 2026
  • CISA: OHIF Viewers DICOM — ICSMA-26-176-02, June 25, 2026
  • Feldesman LLP: OCR’s New Initiative Yields Seven HIPAA Enforcement Actions, 2026
  • Forbes: Healthcare Is Undergoing A Cybersecurity Crisis, And It’s Not Slowing Down, July 28, 2026