These questions come from conversations with healthcare CISOs and facility security teams after the ransomware attack on Winnipeg's Health Sciences Centre. Attackers compromised the facility management system controlling doors and HVAC. The hospital treats over 570,000 patients annually, and the incident forced teams to confront an uncomfortable truth: operational technology is largely unprotected, and most security programs don't know where to start.
The questions below reflect what you're asking in private channels and hallway conversations. The answers cite specific requirements and frameworks, because vague advice won't help you brief your board next week.
Q1: Our facility management system isn't on our network diagram. How do we even inventory OT assets?
Start with the physical plant. Walk the building with your facilities director and document every system that connects to a network, even if it's "just" for remote monitoring. Look for HVAC controllers, door access systems, elevators, medical gas monitoring, fire suppression panels, and building automation systems.
Cross-reference vendor maintenance contracts. If a contractor dials in remotely to adjust your chiller settings, that's a network connection you need to document. NIST SP 800-53 control CM-8 requires you to maintain an inventory of system components, including OT assets that affect your ability to deliver services.
Most healthcare organizations discover they have 3-5 times more networked OT devices than they thought. Document the make, model, firmware version, network segment, and vendor access method for each one. You can't secure what you can't see.
Q2: We segment clinical systems, but facilities runs on the same corporate network. Is that actually a problem?
Yes, and it's a measurable problem in patient safety terms. If an attacker pivots from a compromised workstation to your building automation system, they can disable door locks, shut down HVAC in operating rooms, or trigger false fire alarms during a procedure.
ANSI/ISA-62443 provides clear guidance: OT systems should be segmented into zones based on criticality and consequence of compromise. At minimum, your facility management systems need their own VLAN with strict firewall rules limiting communication.
The Winnipeg incident shows why this matters. When your doors won't lock and your HVAC fails, you can't safely operate. That's a direct patient care impact, which means these systems deserve the same isolation you'd apply to your electronic health record.
Q3: Our HVAC vendor needs remote access 24/7. How do we secure that without breaking our maintenance contract?
You don't need to eliminate vendor access; you need to control it with the same rigor you'd apply to privileged access on clinical systems. NIST Cybersecurity Framework (CSF) 2.0 function PR.AC-4 addresses managing access for external parties.
Implement Just-in-Time Access for vendor connections. Your vendor doesn't need standing access; they need time-limited access when there's an actual maintenance need. Use a privileged access management solution that requires approval, logs every action, and automatically terminates the session after a defined period.
For identities with access to systems controlling physical environments, require phishing-resistant authentication. This means FIDO2 security keys or platform authenticators, not SMS codes or push notifications. Attackers are using AI-generated phishing to target facility contractors because these accounts often have broad access and weak authentication.
Review your vendor contracts. You can require specific security controls without violating the agreement. If your vendor balks at using MFA, find a different vendor.
Q4: What's the actual regulatory requirement here? HIPAA doesn't mention HVAC systems.
You're right that HIPAA doesn't explicitly name HVAC or door systems, but the HIPAA Security Rule §164.308(a)(7) requires you to have a contingency plan, and §164.310 covers physical safeguards. If a cyberattack on your facility systems prevents you from safely treating patients, you've failed both requirements.
More directly: if you can't lock doors, you can't control physical access to areas where protected health information is stored or processed. If you can't maintain appropriate temperature and humidity, you can't safely store medications or operate imaging equipment.
Beyond HIPAA, if you're pursuing HITRUST CSF certification, control 01.s (Secure Areas) and 09.s (Physical and Environmental Security) require you to protect systems that maintain physical security and environmental controls. That includes your building automation systems.
Q5: Our facilities team says these systems are "air-gapped." Should I believe them?
Probably not, but verify rather than argue. Ask three specific questions:
- How do you receive firmware updates for the controllers?
- How does your vendor perform remote diagnostics?
- Do any of these systems send alerts to your phone or email?
If the answer to any of those is anything other than "we physically walk to the device with a USB drive," the system isn't air-gapped. Most modern building automation systems have some form of network connectivity, even if it's just a cellular modem for monitoring.
Even truly air-gapped OT systems aren't immune. An attacker who gains physical access or compromises a maintenance laptop can still reach them. The Winnipeg incident is still under investigation, so we don't know the initial access vector, but facilities contractors are high-value targets because their access is often under-secured.
Q6: We're a small hospital. Do we really need to treat our door system like it's critical infrastructure?
Yes, because the consequence of failure is the same regardless of your organization's size. If your doors won't lock and your HVAC fails, you can't safely admit patients. That's true whether you're a 50-bed community hospital or a 500-bed tertiary center.
The NIST Cybersecurity Framework (CSF) 2.0 is built around identifying and managing risk based on potential impact, not organization size. Your door and HVAC systems directly affect your ability to deliver patient care, which makes them high-impact assets under any reasonable risk assessment.
Start with the basics: inventory your OT assets, segment them from general IT networks, require strong authentication for anyone with access, and include them in your incident response plan. You don't need a massive budget to do those four things, but you do need to acknowledge that these systems are in scope for your security program.
Q7: Should OT security be IT's problem or facilities' problem?
It's a shared responsibility that requires a formal governance structure. Your facilities team understands the operational requirements and vendor relationships. Your IT security team understands network architecture and threat modeling. Neither can do this alone.
Create a cross-functional working group with representatives from facilities, IT security, clinical engineering, and risk management. Define clear ownership: facilities owns operational decisions about the systems, IT security owns the security architecture and monitoring, and both collaborate on vendor management and incident response.
Document this in your risk management program. ISO/IEC 27001 control 5.3 requires you to assign information security responsibilities, and that includes OT systems. Make it explicit who approves new OT connections, who reviews vendor access logs, and who gets paged when your building automation system starts behaving abnormally.
Where to go for more
ANSI/ISA-62443 provides the most comprehensive framework for securing industrial control systems, and most of its guidance applies directly to healthcare facility systems. Start with ISA-62443-2-1 for establishing a security program.
The Health Information Trust Alliance (HITRUST) released OT-specific implementation guidance in their CSF that maps building and facility systems to security controls. If you're already working toward HITRUST certification, this gives you a clear path.
For immediate tactical steps, review NIST SP 800-82, "Guide to Operational Technology Security." It's written for industrial environments but translates directly to healthcare facility systems. Focus on sections covering network segmentation, access control, and monitoring.
Your facilities vendors may also have security guidance, though quality varies widely. Ask them specifically about their authentication requirements, remote access procedures, and how they handle security patches. If they can't answer those questions clearly, that's a vendor risk you need to document and escalate.





