The Health Sciences Centre (HSC) in Winnipeg, Manitoba, has been hit by a ransomware attack that affected several facility maintenance systems, including door access controls and heating, ventilation and air conditioning (HVAC) systems.
The incident was disclosed on August 10th, 2026, with HSC stating that clinical services remained operational and there was no indication, based on the investigation to that point, that patients had been affected. The hospital said it was investigating the cause of the breach and had engaged external cybersecurity experts to help resolve the incident.
Although the attack has not been reported as disrupting clinical care, the incident demonstrates an increasingly important cybersecurity reality: hospitals are not dependent solely on electronic medical records and clinical applications. Modern healthcare facilities rely on interconnected digital systems for everything from building access to environmental controls.
When attackers compromise those systems, the consequences can extend beyond computers and data.
What Happened in the Winnipeg Health Sciences Center Ransomware Attack?
Health Sciences Center Winnipeg announced that it had experienced a ransomware incident affecting a number of facility maintenance systems.
Among the systems affected were:
HSC said clinical services were continuing uninterrupted and advised patients who needed care to attend the hospital as normal. The facility remained accessible to patients and staff, although some entrances were affected.
The hospital also stated that, based on the investigation conducted at the time, there was no indication that patients had been affected.
The province was notified about the incident, and HSC said it had engaged third-party experts to investigate and help resolve the ransomware attack. Winnipeg police had also been contacted for comment, although no further information was immediately available.
At this stage, important details remain unknown, including the identity of the attackers, the initial access method, whether information was stolen, whether a ransom demand was made and how long remediation will take.
Those details matter because ransomware attacks can involve several different stages: a criminal group may encrypt systems, steal information, threaten to publish stolen data or use a combination of these tactics.
Why Are Healthcare Organizations Ransomware Targets?
Healthcare organizations are attractive targets for cybercriminals because they possess a combination of valuable information, complex technology, and operational pressure.
Hospitals hold enormous amounts of sensitive information, including:
Unlike many businesses, hospitals also operate around the clock. They cannot simply shut down operations while IT teams investigate a security incident.
This creates significant pressure during a ransomware attack.
Cybercriminals understand that healthcare organizations have a particularly strong incentive to restore systems quickly. An attack that prevents access to important systems can potentially affect appointments, diagnostics, communications, medical records and other essential services.
In the case of HSC, the reported impact on facility systems illustrates another dimension of the problem.
The attackers did not simply target a conventional business application. Systems controlling physical infrastructure were affected.
Ransomware is Not an "IT Problem"
One of the most important lessons from the 2026 Health Sciences Center incident is that cybersecurity and physical infrastructure are increasingly connected.
HVAC and access-control systems are examples of operational technology, or OT. These technologies control physical environments rather than simply processing information.
Hospitals can use connected technology to manage:
Heating and cooling
Ventilation
Building access
Security systems
Elevators
Power systems
Lighting
Medical equipment
Environmental monitoring
Many of these systems are now network-connected because connectivity makes them easier to monitor and manage.
However, connectivity can also introduce cybersecurity risk.
If a threat actor gains access to a network and is able to move laterally into building-management systems, the consequences can become physical.
An attack against an HVAC system could potentially affect environmental conditions. An attack against door access systems could affect how staff and patients move through a facility.
The HSC incident therefore highlights why cybersecurity assessments need to consider more than traditional corporate IT environments.
The Importance of Healthcare Cybersecurity
Healthcare cybersecurity presents a unique challenge because organizations must balance security with accessibility.
A hospital employee may need immediate access to information in an emergency. Security controls cannot simply make systems inaccessible in the name of protection.
At the same time, overly permissive access can give attackers more opportunities if an account is compromised.
Healthcare organizations therefore need layered security controls that protect systems while allowing authorized employees to perform their jobs.
These controls can include:
Multi-factor authentication
Network segmentation
Privileged-access management
Endpoint detection and response
Security monitoring
Strong identity management
Regular vulnerability scanning
Secure backups
Offline or immutable backups
Employee security awareness training
Incident response planning
Regular penetration testing
No individual security control can eliminate ransomware risk.
Instead, organizations need multiple defensive layers that make it difficult for an attacker to enter, move through the environment and achieve their objective.
Penetration Testing Identifies Weaknesses Before Attackers Do
One of the most effective ways organizations can evaluate their defenses is through penetration testing.
A vulnerability scan can identify known technical weaknesses. Penetration testing goes further by simulating how a real threat actor could potentially exploit vulnerabilities and combine multiple weaknesses to gain access.
For a healthcare organization, that could mean testing more than externally facing websites.
A comprehensive penetration testing program can examine areas such as:
External Attack Surface
Ethical hackers can assess systems that are accessible from the internet and identify vulnerabilities that could provide attackers with an initial entry point.
This may include web applications, remote-access infrastructure, VPNs, cloud environments and externally exposed services.
Internal Networks
An attacker who compromises one employee account should not automatically be able to access everything on the network.
Internal penetration testing can examine whether an attacker could move from an initial foothold to sensitive systems.
This is particularly important in healthcare environments where administrative systems, clinical systems and building-management technologies may coexist within complex technology environments.
Identity and Access Controls
Compromised credentials are frequently involved in cyberattacks.
Testing can determine whether standard user accounts have excessive privileges and whether attackers could escalate privileges after obtaining an initial foothold.
Network Segmentation
Network segmentation is especially important for organizations operating critical infrastructure.
Penetration testers can assess whether sensitive systems are appropriately isolated and whether a compromise of one network segment could provide access to another.
Physical Security
Healthcare penetration testing can also incorporate physical security assessments.
Depending on the scope and authorization, ethical hackers may test whether unauthorized individuals could gain access to restricted areas, obtain employee credentials or exploit weaknesses in physical access controls.
The objective is not to cause disruption. It is to identify weaknesses under controlled conditions so they can be fixed before a criminal attacker discovers them.
The Shared Health Cybersecurity Warning
The ransomware attack at HSC also comes against the backdrop of previous concerns about cybersecurity preparedness within Manitoba's healthcare system.
In December 2024, Manitoba's auditor general released an audit examining Shared Health's cybersecurity incident response process.
The audit found that Shared Health had a plan and resources to respond to a successful cyberattack, but identified several areas requiring improvement.
Among the recommendations were conducting exercises to test the cybersecurity incident response plan, improving training and completing an external communications plan. The audit specifically noted that scenarios such as ransomware and data theft had not been tested, making it difficult to evaluate how effective the response process would be during a major cybersecurity event.
Shared Health said it would implement the recommendations.
The 2024 audit does not establish a connection between those findings and the 2026 ransomware incident. However, it demonstrates why cybersecurity preparedness is about more than having security technology in place.
Why Cybersecurity Exercises Matter
A written incident response plan can look comprehensive on paper but fail under real-world pressure.
A ransomware exercise can reveal problems such as:
Unclear decision-making authority
Delayed escalation
Poor communication between IT and clinical teams
Missing emergency contact information
Inadequate backup procedures
Unclear responsibilities
Difficulty communicating with patients
Problems isolating compromised systems
Insufficient cybersecurity staffing
Testing these processes before an actual incident gives organizations an opportunity to identify weaknesses without the pressure of an active attack.
For hospitals, this is particularly important because a cyber incident can become a patient-safety issue.
The goal should not simply be to restore computers.
The goal should be to maintain safe patient care while systems are being investigated, isolated and restored.
What Hospitals Can Learn From the HSC Ransomware Attack
The HSC incident offers several important lessons for healthcare organizations across Canada.
1. Protect Operational Technology
Cybersecurity programs should include building-management systems and other operational technology, not just conventional IT infrastructure.
2. Segment Critical Systems
Networks should be designed so that compromising one system does not automatically provide access to critical infrastructure.
3. Test Incident Response Plans
Organizations should regularly simulate ransomware attacks and other cyber incidents to determine whether their response plans work in practice.
4. Maintain Reliable Backups
Backups should be protected from attackers and regularly tested to ensure they can actually be restored.
5. Monitor for Lateral Movement
Detecting an initial compromise is important, but organizations also need to identify attempts to move deeper into the network.
6. Test Human Security Controls
Employees are an important component of cybersecurity. Security awareness training should be supported by controlled testing that identifies where processes can be improved.
7. Conduct Regular Penetration Tests
Penetration testing provides an attacker-focused assessment of security controls and can identify attack paths that conventional vulnerability scanning may not reveal.
What Happens Next at Health Sciences Centre?
The immediate priority for HSC will be investigation, containment, and restoration.
The hospital has said it is working with external experts to resolve the incident and investigate its cause. It has also stated that clinical services remain uninterrupted and that there was no indication that patients had been affected based on the investigation conducted at the time of the announcement.
More information may emerge as the investigation progresses.
Key questions will include whether patient or employee information was accessed or stolen, how the attackers gained entry, which systems were compromised and whether the incident was limited to facility-management infrastructure.
These answers will help determine the full significance of the attack.
The Growing Cybersecurity Risk to Canadian Healthcare
The HSC ransomware incident is another reminder that healthcare cybersecurity is now an operational necessity.
Hospitals are increasingly dependent on digital systems, connected medical technologies and networked infrastructure. That dependence can improve patient care and operational efficiency, but it also expands the potential attack surface.
The challenge is particularly significant for large healthcare facilities because their environments are complex. They may contain decades-old technologies alongside modern cloud services, connected devices, electronic health records and building-management systems.
Rather than waiting for ransomware attackers to discover weaknesses, healthcare organizations can use penetration testing, vulnerability assessments, red-team exercises and incident-response simulations to identify weaknesses in controlled environments.
The objective is not to guarantee that an organization can never be hacked. Instead, the objective is to make successful attacks harder, detect them earlier, contain them faster, and recover with minimal disruption.
Conclusion
The ransomware attack affecting Winnipeg's Health Sciences Centre demonstrates how cybersecurity threats can reach beyond computers and data.
The reported impact on HVAC and door access systems shows that modern hospitals are interconnected environments where digital security and physical operations increasingly overlap. While HSC has said clinical services remain uninterrupted and there is currently no indication that patients have been affected, the incident highlights the potential consequences of attacks against healthcare infrastructure.
For healthcare organizations, cybersecurity cannot be treated as an occasional IT exercise. It needs to be part of operational risk management and patient safety.
Regular penetration testing, network segmentation, strong access controls, reliable backups and tested incident-response plans can help organizations find vulnerabilities before criminals do.
The most effective time to discover a cybersecurity weakness is during a controlled security assessment, not during a ransomware attack.
Frequently Asked Questions About the Health Sciences Centre Ransomware Attack
Was Health Sciences Centre hit by ransomware?
Yes. Health Sciences Centre Winnipeg reported a ransomware incident on August 10, 2026. The attack affected several facility maintenance systems, including HVAC and door access systems.
Did the ransomware attack affect patient care?
HSC said clinical services were continuing uninterrupted and advised patients who needed care to attend the hospital. Based on the investigation conducted at the time, the hospital said there was no indication that patients had been affected.
Did the ransomware attack affect hospital doors?
Yes. HSC reported that door access systems were among the facility maintenance systems affected by the ransomware incident. Some exterior entrances were closed or redirected, although the hospital remained accessible to patients and staff.
Did the ransomware attack affect the hospital's HVAC system?
Yes. HSC said its HVAC system was among the facility maintenance systems affected by the attack.
Was patient data stolen?
There has been no public confirmation that patient information was stolen in the incident. HSC said that, based on its investigation to that point, there was no indication that patients had been affected. The investigation was ongoing at the time of the announcement.
Who carried out the Health Sciences Centre ransomware attack?
The identity of the attackers has not been publicly established in the information released so far.
Did Health Sciences Centre pay a ransom?
There has been no public confirmation that a ransom was paid.
How can hospitals prevent ransomware attacks?
Hospitals can reduce ransomware risk through layered cybersecurity controls, including multi-factor authentication, network segmentation, endpoint monitoring, secure backups, employee training, vulnerability management, penetration testing and regular incident-response exercises.
Why is penetration testing important for hospitals?
Penetration testing allows ethical hackers to simulate realistic attack scenarios under controlled conditions. Testing can uncover vulnerabilities in external systems, internal networks, identity controls, segmentation and other security mechanisms before criminal attackers exploit them.
Can penetration testing prevent ransomware?
No cybersecurity measure can guarantee that ransomware will never occur. However, penetration testing can identify weaknesses that attackers could potentially exploit and help organizations strengthen their defenses, reduce attack paths and improve their ability to detect and contain intrusions.