Health Sciences Centre in Winnipeg — Manitoba’s largest hospital — disclosed on August 10, 2026 that a ransomware attack had disrupted its facility-management systems. Door access control, elevators, and heating, ventilation and air-conditioning were all affected.

Clinical operations were not. Shared Health stated that patient care continued uninterrupted, clinical services ran normally, and there was no indication at the time of investigation that patient information was affected. The hospital urged anyone who needed care to come in as usual.

Instead, HSC told staff in an internal memo that it had increased the presence of security and institutional safety officers at hospital entrances — because the doors were still down.

A week after discovery, recovery was still in progress. External cybersecurity experts were engaged and Winnipeg police were notified. No threat actor has been publicly identified, and no ransom demand has been confirmed.

Human Guards Replacing Digital Locks

The security-officer detail is the whole story compressed into one operational decision.

A modern hospital’s access control system is not a convenience. It is the mechanism that keeps unauthorized people out of pharmacy stores, neonatal units, psychiatric wards, morgues and medical gas rooms. It logs who went where. It enforces badge-level segmentation between the public atrium and the surgical corridor.

When it goes down, that segmentation does not degrade gracefully. It disappears, and the only substitute is a person standing in the doorway checking badges by eye. HSC scaled up staffing to do exactly that, at a facility with more than a hundred entry points, on no notice.

Elevators matter for the same reason. In a large hospital, elevator banks are segmented by function — service, patient transport, public — and access is often card-controlled. Losing that control does not stop the elevators; it stops the hospital from knowing and constraining who is using them.

HVAC is the one with clinical consequences. Operating theatres, isolation rooms and pharmacy compounding areas depend on precise pressure differentials and air-change rates. A negative-pressure isolation room that loses its pressure differential stops being an isolation room. HSC has not detailed which HVAC zones were affected or for how long, and that is the outstanding question in this incident.

Building Management Is the Unguarded Half of Healthcare OT

Healthcare cybersecurity spends its attention on two things: the electronic health record, and connected medical devices. Both are heavily regulated, heavily audited and heavily discussed.

Building management systems are neither. They run on separate networks with separate vendors, separate maintenance contracts and separate — usually thinner — patching regimes. They are commissioned by facilities departments, not IT. The controllers frequently run embedded operating systems that were current when the building was built, and the remote-access channel exists so a contractor in another city can adjust a chiller setpoint without driving to site.

That is the profile of a target, and this incident is what happens when someone takes it.

It also inverts the assumption healthcare defenders normally work from. The usual ransomware playbook against a hospital hits the EHR, forces downtime procedures, and produces the patient-safety consequences we have documented repeatedly through 2026. HSC’s clinical systems came through intact. The attack still degraded the physical safety of the building.

Segmentation worked here — the clinical network survived — which means the facilities network was reachable independently. Either it was compromised directly, or it was never as separate as the architecture diagram claimed.

The Audit That Warned About This

Manitoba’s auditor general reviewed Shared Health’s cyber incident response capability in December 2024 and found that while response capabilities existed, they had gaps. The finding that reads worst now: ransomware and data-theft scenarios had not been tested, which made it impossible for the auditor to evaluate how effective the response would actually be.

Twenty months later, Shared Health found out.

This is not unique to Manitoba. Public health systems across North America carry the same structure — an untested plan, a facilities network nobody scoped into the tabletop, and a building-management vendor who is not in the incident response contact list. HSC’s saving grace is that the attack landed on the systems that inconvenience rather than the systems that kill. That was not a control. That was where the attacker happened to end up.

What This Should Change

Three things, and none of them are novel:

Scope facilities into the asset inventory. If the building management system, access control and elevator controllers are not in the CMDB with named owners and patch status, they are not being defended. Most hospitals cannot currently produce that list.

Test the manual fallback before you need it. HSC’s answer to failed access control was human guards. That worked because the hospital could surge staff. The tabletop question is: how many officers, at which doors, for how many days, and who pays for it? Answering that during the incident is expensive.

Treat pressure-dependent clinical spaces as a separate tier. Operating theatres and isolation rooms have HVAC dependencies with direct patient-safety implications. Those zones need either manual control fallback or an independent control path that a compromise of the main BMS cannot reach.

The attack on HSC will be filed as a minor incident because nobody was harmed and the EHR stayed up. The correct reading is narrower and less comfortable: an attacker got control of the physical environment of a major hospital, and the response was to post guards at the doors and hope the air handlers held.

Sources