Experts Highlight Operational Technology Risks Following Ransomware Attack on Canadian Hospital
A ransomware attack targeting facility management systems at Winnipeg’s Health Sciences Centre, Ontario’s largest hospital, has raised significant concerns regarding the cybersecurity vulnerabilities facing operational technology (OT) in healthcare environments. The incident, which impacted crucial systems including building access controls and HVAC operations, has prompted experts to emphasize the urgent need for enhanced cybersecurity measures within healthcare organizations, reflecting the evolving landscape of cyber threats.
The attack, reported this week, has placed the facility operated by Shared Health under investigation, with hospital representatives indicating that the incident is being treated as a high priority. A spokesperson mentioned that preliminary investigations suggest the attack has only affected specific facility maintenance systems. Fortunately, there have been no indications that patient care or safety has been compromised.
Shared Health is committed to addressing the situation as swiftly and securely as possible, ensuring continuity in clinical operations and patient care. The organization has already communicated with the Government of Manitoba and is working closely with external experts to facilitate the remediation process.
Despite this, the incident has raised alarms within the healthcare community. Darlene Jackson, president of the Manitoba Nurses Union, expressed grave concerns about the safety of hospital environments, recalling how the union deemed the hospital too dangerous for workers last year due to unsecured doors and the risk of unauthorized entry. Jackson’s worries have only intensified given the current situation.
The Health Sciences Centre, which serves as Manitoba’s provincial tertiary hospital for critical services like trauma care, transplants, neurosurgery, and complex cancer treatments, operates the largest and busiest emergency department in the province. It treats more than 570,000 patients annually, underscoring the vital role the facility plays in the healthcare system.
Experts in the field argue that incidents involving OT and facilities management systems are likely to become more prevalent. Jason Elrod, Chief Information Security Officer (CISO) at MultiCare Health System and a senior advisor at security firm Elisity, pointed out that as monetizing stolen data or encrypting traditional IT systems becomes increasingly difficult for cybercriminals, they will likely shift their focus to more vulnerable areas. He asserted that disrupting the physical environment of hospitals can create immediate and urgent pressures, fundamentally affecting patient care.
Elrod emphasized that assuming the ethical standards of potential attackers can lead to critical oversights in security planning. Motivations driving cybercriminals often fall into three categories: financial gain, ideological causes, or creating chaos; and none guarantee consideration for patient safety. This reality necessitates that healthcare organizations prepare for the possibility that systems capable of disrupting operations or affecting patient care may become targets for future attacks.
John Strand, owner of Black Hills Information Security, echoed this sentiment, stressing the importance of extending rigorous cybersecurity measures to facilities management systems. He lamented that for too long, operational systems have been regarded as outside the scope of cybersecurity evaluations. The recent Winnipeg incident starkly illustrates why such a viewpoint is outdated; systems like HVAC, elevators, and access controls are as vital to patient care as any clinical data systems.
Although Shared Health has not disclosed how the attackers gained unauthorised access to the affected systems, experts caution that facilities personnel, contractors, and vendors with privileged access may inadvertently be targeted through sophisticated spear-phishing techniques or fake login sites. Kevin Surace, CEO of security firm Token, urged organizations to adopt stringent authentication protocols for individuals capable of affecting physical environments.
Surace’s recommendations include employing hardware-bound, phishing-resistant authentication methods coupled with biometric verification, as traditional multifactor authentication techniques are becoming increasingly vulnerable. Organizations must also eliminate weaker fallback methods, enforce stringent privilege limitations, and isolate OT systems from standard corporate networks to bolster security.
In conclusion, healthcare organizations are urged to identify critical OT systems whose failure could directly impact patient care. Elrod suggests that organizations should segment and isolate these systems appropriately, implement strict controls on remote and vendor access, maintain comprehensive asset inventories, and monitor for any signs of unusual activity. Additionally, robust recovery plans should be tested regularly to ensure readiness in the event of an incident similar to the one recently experienced at Winnipeg’s Health Sciences Centre.
As this situation unfolds, the imperative for the healthcare sector to reconsider its cybersecurity frameworks, particularly regarding operational technology, has never been more critical.

