When Ransomware Turns Off the HVAC: Lessons from the Winnipeg Hospital Incident

When Ransomware Turns Off the HVAC: Lessons from the Winnipeg Hospital Incident

On August 10, Manitoba's largest hospital disclosed something the industry rarely sees stated so plainly. Shared Health, the Canadian province’s health authority, confirmed that Winnipeg's Health Sciences Centre (HSC) was responding to "a ransomware incident affecting certain facility maintenance systems, including HVAC and door access controls." Patient care and clinical operations continued uninterrupted, the province was notified and third-party experts were engaged. As of this writing, no threat actor has claimed responsibility and the initial access vector has not been made public.

Read Shared Health’s statement again. The systems named are not the IT systems like file servers or billing databases typically impacted by ransomware attacks, nor was this a targeted attack on patient care systems brimming with protected health information, which often prompts healthcare providers to pay quickly. This incident directly impacted building management systems — the OT and IoT systems that keep the building powered, move air through operating suites and control who can walk through which door. In a hospital, the building is part of the care team, and the impact of an attack like this could have been devastating.

Among so-called smart buildings, healthcare facilities are some of the smartest. Hospital HVAC systems aren’t just for comfort control; they provide infection control. Nowhere is the “V” in HVAC more important.

Healthcare Facility Maintenance Systems Are Clinical Systems

There is a reflex in incident reporting to treat attacks on facility maintenance or building management systems as a footnote, a softer target than electronic health records. That reflex is wrong. Among so-called smart buildings, healthcare facilities are some of the smartest.  

Hospital HVAC systems aren’t just for comfort control; they provide infection control. Nowhere is the “V” in HVAC more important. Healthcare ventilation standards such as ANSI/ASHRAE/ASHE 170-2025 prescribe pressure relationships, filtration levels and air changes per hour, room by room. Surgical suites add higher filtration and airflow on top of that, and airborne infection isolation rooms are held at negative pressure so that what a contagious patient exhales stays contained.  

While the 170-25 standard specifically addresses room requirements and pressure relationships between rooms, a common medical facility HVAC design practice is to have the building operate at slightly positive pressure overall so unfiltered outside air cannot infiltrate the space. The whole design exists to prevent hospital-acquired (or nosocomial) infections. Door access control matters too, governing pharmacies, infant wards and behavioral health units. But losing control of the air is arguably worse: a door failure is a risk; an air failure is already a live infection-control event. Lose the ability to monitor or manage these systems and staff fall back to manual rounds, physical keys and paper logs while the clock runs.

To their credit, HSC's clinical operations stayed online, which suggests the segmentation between clinical networks and facility networks held. That’s the good news in this story. The uncomfortable question is why the facility network was reachable at all.

Why BMS and Facility Maintenance Systems Are Attractive Targets  

We have written before about why BMS keep falling through the cracks:  

  • Physical plant assets often sit outside the scope of corporate IT.
  • The protocols underneath them (BACnet chief among them) were designed for interoperability rather than security.
  • The controllers themselves often run for a decade or more without a patch.  
  • Facilities teams own the equipment, IT owns the overall network, but no one owns the facilities side of the network.

Hospital environments can amplify this challenge. As we noted in our guide to healthcare cybersecurity, a modern hospital layers IP-connected building automation, CCTV, elevators and physical security systems on top of legacy clinical equipment. Much of it is unmanaged, runs on embedded operating systems and may have reached end-of-life years ago. Every one of those devices is an asset someone has to know about before anyone can defend it.

Is the Winnipeg Hospital Ransomware Attack Precedent or Prediction?

It would be a mistake to read the Winnipeg incident as proof that attackers are now specifically targeting building management systems, at hospitals or anywhere else. The correct framing is more about consequence than intent: whether or not a building network is the target, it can end up as the casualty. Here are two examples that made the news:

  • In 2016, a DDoS attack on two apartment buildings in Lappeenranta, Finland, left building automation controllers stuck in a reboot loop, cutting central heating in sub-zero weather until operators switched to manual control.  
  • In 2021, the FBI disrupted an attempted attack on Boston Children's Hospital by Iranian government-sponsored actors, an attempted system-wide shutdown that FBI Director Christopher Wray later called one of the most despicable cyberattacks he had seen.  

Different attackers, different motives, same underlying exposure. Connected building systems inherit every risk of the networks they touch.

Defense Starts with Visibility into your BMS Assets and Their Behavior

Here’s the challenge for every hospital cybersecurity leader reading the Winnipeg coverage: could you produce, today, a complete inventory of the devices on your facility network, and a map of how and with whom they’re communicating? Think air handlers, door controllers, chillers — and the vendor remote access paths that keep them maintained. If the answer is no, you can’t say with confidence what an intruder could reach, and neither could your incident responders at 2 a.m. on a Monday.

Here’s the broader OT/IoT cybersecurity playbook:

  1. Just as with medical device asset management, you want to build and maintain your asset inventory automatically. A spreadsheet won’t suffice.
  2. Once you know what’s on your network and how it’s communicating, you can see how to segment your facility systems from IT networks and clinical networks. Continuous monitoring enables you to verify segmentation policies are working as designed.  
  3. Baseline normal asset behavior, and monitor BMS protocols in network traffic for anomalies the way you monitor IT traffic, because a controller that starts talking to new destinations is telling you something.  

HSC's outcome, disrupted building systems but uninterrupted care, is what reasonable segmentation buys you. Full visibility and threat and anomaly detection on the BMS network itself can help stop threats before the HVAC, physical access and other critical building system are impacted.

Our own telemetry shows what this looks like in practice. At one healthcare organization monitored by Nozomi Networks sensors, a single day this July generated more than 160 alerts across its facility and OT networks: dozens of controller program changes from 15 different engineering workstations, internal port scans and ping sweeps from 16 sources, program downloads to field controllers, and repeated failed SMB logins consistent with brute-force attempts. Most of that activity was probably routine maintenance, but that’s the point: without monitoring, you can’t make that determination.

Get Started Securing Your BMS Assets

Nozomi Networks helps healthcare organizations do exactly this: continuous visibility, threat detection and risk analysis across building automation, IoMT and OT environments from a single platform, proven in thousands of implementations in buildings across government and critical infrastructure facilities.

To learn how we can help you secure your facilities maintenance and building management systems, contact us today.

No items found.
No items found.
No items found.