Skip to main content
green back ground with gradient accents. The words "Your AI Agents Are Making Decisions. Can Your Security Team Explain Them?" And a "Download the Guide" button.
Hospital Doors That Won't Lock: A Ransomware TeardownIncident & Breach Response
5 min readFor CISOs

Hospital Doors That Won't Lock: A Ransomware Teardown

When ransomware hit Winnipeg's Health Sciences Centre this week, the attackers didn't encrypt patient records. They targeted the building itself.

The facility management system went down, affecting doors and HVAC equipment at Manitoba's largest hospital, which treats over 570,000 patients annually. The Manitoba Nurses Union had already flagged unsecured doors as a safety concern the previous year. Now those doors were compromised by code, not broken hardware.

This isn't a theoretical risk. It's operational technology under attack in a live healthcare environment.

What Happened

Shared Health, which operates the Health Sciences Centre, confirmed a ransomware attack on facility maintenance systems. The investigation found no indication that patients were affected, and clinical operations continued. The organization engaged third-party experts and notified the Government of Manitoba.

The attack specifically impacted building management systems controlling physical access and environmental controls. How attackers gained access remains under investigation.

Timeline

Shared Health has not released a detailed timeline. What's public:

  • Attack detected this week
  • Facility management systems affected, including doors and HVAC
  • Investigation launched immediately
  • Third-party incident response engaged
  • Clinical operations maintained throughout

The lack of a public timeline is itself a data point. Most healthcare organizations don't have pre-built communication protocols for OT incidents because they've historically treated these systems as out-of-scope for cybersecurity programs.

Which Controls Failed or Were Missing

We can't definitively map control failures without access to the incident report. But the attack surface tells us where to look.

Network segmentation. If ransomware reached facility management systems, those systems were either directly accessible from compromised IT networks or lacked adequate isolation. ANSI/ISA-62443-3-3 requires security zones and conduits between OT and IT networks. Most healthcare organizations don't apply this standard to building management systems.

Privileged access management. Facility management systems typically grant broad access to maintenance contractors, building automation vendors, and internal facilities teams. These accounts often lack multifactor authentication, let alone phishing-resistant credentials. The NIST Cybersecurity Framework (CSF) 2.0 function PR.AA (Identity Management, Authentication, and Access Control) requires authentication commensurate with risk. A credential that can unlock every door in a hospital carries material risk.

Asset inventory and visibility. You can't protect what you don't know exists. Most healthcare security teams maintain detailed inventories of medical devices and IT systems. Building management systems, door controllers, and HVAC equipment rarely appear in those inventories. ISO/IEC 27001 control 5.9 requires an inventory of information and associated assets. OT systems process information; they just don't process PHI.

Vendor and remote access controls. Building automation systems often include remote access for vendor support. These connections frequently bypass standard security controls. NIST SP 800-171 control 3.1.12 requires monitoring and control of remote access sessions. Healthcare organizations apply this to clinical system vendors but often overlook facilities vendors.

Incident response planning. Did the Health Sciences Centre's incident response plan include procedures for OT compromise? Most don't. The HIPAA Security Rule requires a contingency plan, but healthcare organizations typically scope that requirement to systems containing electronic protected health information. A door controller doesn't store PHI, so it falls outside the plan until ransomware locks the building.

What the Relevant Standard Requires

ANSI/ISA-62443 provides the clearest framework for OT security in industrial environments. Healthcare has been slow to adopt it, but the standard applies directly to building automation and facility management systems.

ISA-62443-3-3 requires:

  • Security levels assigned to zones based on consequence of compromise
  • Documented security zones and conduits
  • Access control at zone boundaries
  • Network segmentation between IT and OT environments

NIST Cybersecurity Framework (CSF) 2.0 maps to OT environments through the Govern, Identify, Protect, Detect, Respond, and Recover functions. For facility management systems:

  • ID.AM (Asset Management): Maintain inventories of OT assets, including building systems
  • PR.AA (Identity Management, Authentication, and Access Control): Implement phishing-resistant authentication for privileged facility system access
  • PR.AC (Access Control): Enforce Principle of Least Privilege for vendor and contractor accounts
  • PR.DS (Data Security): Segment OT networks from corporate IT networks
  • DE.CM (Continuous Monitoring): Monitor facility management networks for anomalous activity

ISO/IEC 27001 control 8.22 (Segregation of networks) requires organizations to segregate networks into groups based on trust levels, security requirements, and criticality. A hospital's door control network meets all three criteria for segregation.

The HIPAA Security Rule doesn't directly require OT security because facility management systems don't contain ePHI. But 45 CFR § 164.308(a)(7) requires a contingency plan to ensure continuation of critical business processes. If your doors won't lock and your HVAC fails, you can't deliver patient care. That makes these systems critical to HIPAA compliance, even if they're not technically in scope.

Lessons and Action Items for Your Team

Inventory your OT attack surface. Start with systems whose failure would materially affect patient care. Include building management, door controllers, HVAC, elevators, medical gas systems, generators, and fire suppression. Document network connections, vendor access points, and authentication mechanisms. If you're using ISO/IEC 27001, add these assets to your Statement of Applicability scope.

Segment facility management networks. Apply the same network segmentation you use for medical devices. ANSI/ISA-62443-3-3 provides the framework. At minimum, isolate building automation systems from general corporate networks and implement monitored access control points between zones.

Require phishing-resistant authentication for OT access. Use passkeys and hardware-bound credentials with biometric verification for any account that can affect physical building systems. Eliminate SMS-based MFA and knowledge-based fallback methods for these accounts. Map this to NIST Cybersecurity Framework (CSF) 2.0 2.0 PR.AA-06 (physical access is managed and protected).

Audit vendor and contractor access. Review every remote access connection to facility management systems. Require Just-in-Time Access for vendor support sessions. Monitor and log all remote sessions. Revoke dormant accounts. This maps directly to NIST SP 800-171 control 3.1.12.

Update your incident response plan. Add OT compromise scenarios. Define decision trees for when physical building systems are affected. Identify who has authority to isolate building networks if ransomware spreads. Test the plan. The HIPAA Security Rule requires this at 45 CFR § 164.308(a)(7)(ii)(B).

Train your security team on OT. Most healthcare security professionals come from IT backgrounds. They understand database encryption and endpoint detection. They don't necessarily understand building automation protocols, industrial control systems, or the operational constraints of systems that can't be patched without scheduling building-wide shutdowns. Close that gap.

The Winnipeg incident demonstrates what happens when we treat facility management systems as someone else's problem. They're not. They're part of your attack surface, and attackers know it.

Promotional banner for the Pentest Readiness checklist download

You Might Also Like