On July 26, AnMed found malware on its network and took the network down on purpose. By the end of that day, 83 of its 106 facilities were closed. Ten days later, ten were still shut, most of them outpatient imaging.
Most of the coverage read this as a security story. Who got in, how they got in, what they wanted, whether anyone paid. Those questions belong to the people running the investigation. They are not the questions I would put in front of an operations committee this month.
Here is the one I would. AnMed's emergency departments stayed open the whole time, and so did urgent care, the lab, and the therapy sites. Nearly everything else went dark, and the system ran on paper for the better part of two weeks. Ask your leadership which of your own sites could do that. Then ask when anyone last checked.
When malware is confirmed on a hospital network, taking the network offline is containment. AnMed shut down its own systems, including the patient portal, to stop the spread. That decision buys safety and charges for it immediately, because every downstream workflow was built on the assumption of a live network.
Which is nearly all of them.
Clinical work does not sit inside one application. It is spread across scheduling, results routing, medication reconciliation, prior imaging retrieval, the label printer at the phlebotomy station, and the phone tree a patient calls to find out whether her appointment still exists. Take the network away and the electronic record is not what you miss first.
You miss the small machines.
"Downtime is not the record going away. It is fifty small dependencies going away at once, and only some of them are on your list."
That ratio is the number worth sitting with. Emergency, urgent care, lab, and therapy kept running. Most of the outpatient footprint closed, and imaging stayed closed longest.
Read it as a triage decision made under pressure, because that is what it was. Sites that can function on paper with a known patient in the room stayed open. Sites whose work depends on retrieving prior data, routing a result somewhere, or coordinating a schedule across locations did not.
Your footprint sorts the same way. It sorts that way whether or not anyone has written it down, and the unwritten version is the one you will discover at two in the morning on a Sunday.
Ten days out, ten locations were still closed. Restoring the network is not the finish line. Everything documented on paper has to be reconciled back into the record. Results that queued up during the outage have to reach a human who acts on them. Every deferred appointment has to be rebooked into a schedule that was already full before any of this started.
The backlog outlasts the outage by weeks. It carries its own clinical risk, and that risk shows up after incident command has stood down and everyone has gone back to their regular jobs.
When did we last run a downtime drill longer than four hours? A two-hour tabletop tests the plan. It does not test the second shift, the paper supply, or whether anyone remembers where the downtime forms are kept.
Who reconciles the paper back in, and what is that person doing right now? Recovery is real labor. With no owner and no budget line, it comes out of clinical time.
Which of our sites can see a patient with no prior data available? That is the working definition of "stays open," and the honest list is shorter than most leadership teams expect.
How do patients reach us when the phones are part of the outage? AnMed's phone and internet went down together. Patients spent days unable to confirm whether an appointment existed at all.
I spend most of my advisory time on clinical AI governance, and this sits closer to that work than it looks. Every model you deploy adds a dependency. An ambient documentation tool your clinicians now lean on has quietly become part of the downtime plan. So has the sepsis alert that someone stopped watching for, because the alert was watching for them.
None of that lands in the outage playbook at go-live. The vendor questionnaire asks about uptime and service credits. It rarely asks the operational question, which is what your clinicians do for two weeks without the tool, and whether they still remember how.
That question belongs in the contract review, not the incident debrief.
AnMed will recover. It is recovering now, site by site, and the people doing that work are having a considerably worse summer than the rest of us.
The lesson to take is not about security. It is smaller and harder to schedule around. Somewhere in your organization there is a binder of downtime procedures, and one person knows exactly where it is.
Find out whether that person still works there.
I am a surgery-trained physician-executive currently practicing internal medicine (charity care), with experience building clinical strategy and governance frameworks during the Cerner acquisition at Oracle Health. I advise health systems on clinical AI strategy, implementation, and the operational plumbing underneath both. For a 20-minute scoping conversation: calendly.com/sarahmattmd
If your last downtime drill was a tabletop and your last vendor review skipped the outage question, that gap is worth closing before it gets tested for you. I build that view with leadership teams in four to six weeks.