Key Takeaways

  • Shared Health says patient care continues despite ransomware affecting maintenance systems at Winnipeg’s Health Sciences Centre and Cancer Care Manitoba.
  • Central HVAC monitoring, elevators, door access, and ID card operations have faced disruption, prompting local monitoring and manual workarounds.
  • The incident highlights the exposure of hospital operational technology, not just clinical records and conventional IT systems.

Shared Health is continuing recovery work at Winnipeg’s Health Sciences Centre and Cancer Care Manitoba after ransomware disrupted building maintenance systems. The attack was discovered on Aug. 10, 2026, and the health authority said in an Aug. 17 update that patient care had not been affected.

The impact has nevertheless reached systems that keep a large hospital operating from hour to hour. Central monitoring of heating, ventilation, and cooling equipment was affected, although the equipment remained operational and was being monitored locally. Door access and elevators also experienced disruption, according to CBC News, requiring temporary workarounds while technical teams investigated and restored services.

There is a physical security component, too. The Health Sciences Centre security office was closed, and staff were unable to issue or update ID access cards. Shared Health added security personnel at the site as a precaution after the ransomware was discovered. Those measures illustrate how a cyber incident can quickly create staffing and facilities challenges, even when clinical applications remain available.

Hospital cybersecurity is often discussed in terms of electronic health records, diagnostic equipment, and patient privacy, but this incident points to a broader attack surface. Modern hospitals rely on interconnected building management systems for temperature control, access permissions, elevators, alarms, and other daily functions. Disruption may not immediately cancel patient care, but it can reduce operating flexibility and increase the burden on facilities and security teams.

Shared Health was still examining whether personal health information or financial information had been accessed. Its initial review suggested that neither category had been compromised, but the investigation remained open. That distinction matters. Ransomware investigations often involve separate questions about encryption, operational disruption, system access, and possible data theft. Early findings can provide reassurance, although forensic reviews tend to take time.

The wider trend is not encouraging. The European Union Agency for Cybersecurity found that ransomware accounted for 54% of all cybersecurity incidents in the health sector between 2021 and 2023, with hospitals representing 42% of reported cases. European Union Member States reported 309 cybersecurity incidents involving hospitals and healthcare providers in 2023, showing that attacks on health infrastructure are far from isolated.

The U.S. Department of Health and Human Services logged over 630 ransomware incidents affecting healthcare worldwide in 2023, including more than 460 involving the U.S. healthcare and public health sector. Meanwhile, France’s Cyberveille e-santé tracks cyber threats and security developments specific to healthcare, another sign that the sector now requires dedicated monitoring rather than generic enterprise defenses alone.

Why target facilities systems? In many hospitals, operational technology has long replacement cycles, specialized vendor access, and different maintenance practices from standard corporate IT. Network visibility may also be uneven. Attackers can exploit those gaps, while defenders face a difficult recovery decision: reconnect systems quickly or spend more time validating that affected environments are clean.

For Shared Health, the immediate priority is maintaining safe operations while determining the ransomware’s reach. Longer term, the incident could prompt closer scrutiny of network segmentation, third-party access, offline recovery procedures, and coordination between cybersecurity, facilities, and clinical teams. The Health Sciences Centre experience is a useful warning for hospital executives: keeping bedside systems online is only one part of cyber resilience. The doors, elevators, ventilation controls, and badges matter as well.