AnMed Health, a nonprofit health system serving upstate South Carolina and Northeast Georgia, was forced to close nearly 80 facilities following a cyberattack. While the organization hasn’t disclosed specifics, the scale of disruption — shutting down dozens of care locations — points to ransomware that encrypted critical systems across the network.
This is what happens when ransomware succeeds: patients turned away, procedures canceled, staff unable to access records, and an organization forced to choose between paying a ransom or rebuilding from backups while care delivery stops.
The Attack Chain Ransomware Depends On
Ransomware doesn’t just appear. It follows a sequence:
- Delivery — the payload arrives via phishing email, malicious download, or lateral movement from a compromised system
- Execution — the payload writes an executable file to disk
- Encryption — the malware encrypts files across accessible drives and network shares
- Extortion — the attacker demands payment to decrypt
Most security tools focus on step 3 or 4 — detecting the encryption behavior or identifying the ransomware signature after it’s already running. By then, the damage is underway.
FileSure stops it at step 2. The payload never lands.
How FileSure Blocks Ransomware Before Encryption Starts
FileSure Defend operates at the Windows kernel level via a filter driver. It intercepts every file system operation — open, read, write, create, delete, rename — before the operation reaches the disk.
A simple rule blocks most ransomware delivery:
Operation: Create, Write
File filter: *.exe, *.dll, *.bat, *.ps1, *.vbs, *.scr
Program filter: outlook.exe, chrome.exe, firefox.exe, msedge.exe, mstsc.exe
Action: Block and log
If Outlook tries to write an executable file, the operation is blocked. If a browser tries to save a .exe, it’s blocked. If a remote desktop session attempts to drop a payload, it’s blocked.
The ransomware payload never reaches the file system. No payload, no execution, no encryption.
The Legacy Medical Device Problem
Healthcare makes this harder. A significant portion of medical infrastructure runs on Windows versions that mainstream endpoint security vendors no longer support. Medical imaging systems (PACS), laboratory equipment, infusion pumps, pharmacy management systems — many of these are locked to Windows 7, Windows XP, or Server 2008 because the specialized software won’t run on anything newer.
Modern endpoint agents won’t install on those systems. So they sit on the network, unprotected, often with access to patient data.
FileSure installs on all of them. The same kernel filter driver runs on Windows XP through Windows 11 and Server 2022. The same policy enforcement. The same blocking and logging.
HIPAA Audit Trails That Actually Work
Every file access is logged: user name, program, machine, operation, file path, timestamp. Logs are encrypted, tamper-resistant, and stored separately from the files they record. If ransomware encrypts your file shares, your audit trail survives.
HIPAA’s Security Rule requires you to record and examine activity on systems containing ePHI. FileSure does that automatically, continuously, across every Windows system you deploy it on — including the legacy ones your compliance team worries about.
When OCR asks for your audit logs, they’re ready.
Start Protecting Your Systems
FileSure Defend runs on the Windows infrastructure you already have. No hardware purchases, no OS upgrades, no rip-and-replace. Start a free 21-day trial at bystorm.com and see how kernel-level file system control stops ransomware before it starts.
Source: AnMed Closes Almost 80 Facilities While it Grapples with Cyberattack
Category: Ransomware
Tags: ransomware, healthcare, legacy systems, hipaa compliance, kernel filter driver, file system security, medical devices, phi protection