An attack on facility maintenance systems left clinical services running while staff moved to manual control of access, elevators, and air handling.

 

What happened

Health Sciences Centre, the largest hospital in Manitoba, is responding to a ransomware attack that affected its facility maintenance systems, including door access controls and heating, ventilation, and air conditioning equipment, CBC News reported on August 10, 2026. Shared Health, the authority operating the facility, said clinical services continued uninterrupted and that its investigation to date found no indication patients had been affected, urging anyone needing to attend the hospital to do so. Elevators and identification card operations were also disrupted, with staff moving to local monitoring and manual workarounds while recovery continues. No group has claimed responsibility, DataBreaches.net noted, and the initial access method, any ransom demand, and whether data was taken remain unconfirmed.

 

Going deeper

Building management systems sit in a category most healthcare security programs treat separately from clinical technology, which is how they end up reachable. The controllers running air handling, door access, elevators, and temperature monitoring are computers with network connections, and they get linked to corporate networks so facilities staff can monitor them centrally, receive alerts, and let vendors perform remote maintenance. Many run software that predates current security expectations and cannot be patched on the schedule applied to workstations, since taking an air handling controller offline during business hours is not a routine action. Once an intruder reaches a flat network, nothing distinguishes a ventilation controller from a file server as a target. Some experts said the incident shows how cyberattacks can affect the systems that keep healthcare facilities running, such as heating, ventilation and access controls, according to BankInfoSecurity.

 

What was said

"Clinical services continue uninterrupted, and based on the investigation conducted to date, there is no indication that patients have been affected," Shared Health said in a statement provided to CBC News by spokesperson Tara Seel, published August 10, 2026. The authority described the event as a ransomware incident affecting certain facility maintenance systems and said it had launched an investigation and brought in outside cybersecurity assistance.

 

In the know

Federal guidance for US healthcare organizations puts inventory before everything else, and building systems are frequently missing from it. The Cybersecurity and Infrastructure Security Agency's mitigation guidance for the healthcare and public health sector directs organizations to build a complete and accurate asset inventory, then segment networks so that connected devices sit apart from general IT, which prevents an intruder who compromises ordinary systems from reaching the rest. Asset inventories assembled by IT departments typically capture servers, endpoints, and medical devices while omitting equipment procured and managed by facilities, since nobody in either group considers an elevator controller their responsibility. Organizations reviewing their own exposure should start by asking which building systems have network connections, who administers them, whether vendor remote access remains enabled, and what network path exists between those systems and the clinical environment.

 

The big picture

An attack of this kind produces a different regulatory picture than a records breach. If no protected health information was accessed, the Breach Notification Rule may not engage at all, while the patient safety and continuity exposure remains real, since air handling supports isolation rooms and operating theatres and door controls govern access to pharmacies and controlled substances. Requirements are moving toward covering this ground, with the proposed HIPAA Security Rule update calling for a written technology asset inventory and network map alongside mandatory network segmentation, though that rule has been pushed to 2027. Emergency operations plans generally address losing power or losing the electronic health record, and losing centralized control of doors and ventilation for an extended period is a scenario fewer organizations have rehearsed.

 

FAQs

Does an attack on building systems trigger HIPAA breach notification?

Only if protected health information was accessed, acquired, used, or disclosed without authorization. An intrusion confined to facility controllers may create no notification duty, though the organization still documents its analysis, and any evidence the attacker moved laterally toward systems holding PHI changes the assessment.

 

Why are building management systems connected to the network at all?

Central monitoring lets a small facilities team oversee an entire campus, receive alerts when equipment fails, and adjust settings remotely, which is considerably cheaper than manual rounds. Vendors also rely on remote connections for diagnostics and updates, and those connections frequently stay enabled long after installation.

 

What does manual operation of these systems involve?

Staff physically attend equipment rooms to read gauges and adjust controls, doors revert to keys or are propped and monitored, and elevators may run on independent controls. The work is possible but consumes staff hours continuously, which is why extended recovery periods carry an operational cost even when nothing clinical stops.

 

How should facilities and IT divide responsibility for these systems?

Ownership should be documented explicitly rather than assumed, covering who maintains the inventory, who applies updates, who approves vendor access, and who receives security alerts. Incidents in this category often reveal that both departments believed the other was responsible.

 

What can be segmented without disrupting operations?

Building systems rarely need to reach clinical networks or the internet, so restricting them to a defined management network with controlled gateways is usually achievable without affecting function. Mapping existing traffic before enforcing rules identifies the connections that genuinely exist, which is the step that prevents an outage during implementation.