Experts: Incident Underscores OT Risks in Healthcare Environments
A Canadian hospital is dealing with a ransomware attack on its facility management systems that has affected the building’s doors and heating, ventilation and air conditioning equipment. Some experts said the incident underscores growing cyberthreats involving operational technology in healthcare.
See Also: Open-Weight Model Antares Delivers Stronger Code Security
The attack this week on Manitoba, Ontario’s largest hospital – Winnipeg’s Health Sciences Centre, which is a facility operated by Shared Health, is under investigation, a Shared Health spokesperson told ISMG.
“At this time, the incident appears to have only impacted certain facility maintenance systems.” Based on the investigation conducted to date, there is no indication that patients have been affected, the spokesperson added.
“This incident is being treated as a high priority. HSC is working diligently to address the situation as safely and securely as possible, while maintaining continuity of patient care and clinical operations,” Shared Health told ISMG.
“HSC has notified the Government of Manitoba and partners, and we have engaged with expert third parties to resolve the incident as soon as possible.”
Shared Health did not immediately respond to ISMG’s request for additional details about the incident and how doors and HVAC systems are affected.
Darlene Jackson, president of the Manitoba Nurses Union, told local media that the union declared the hospital too dangerous for workers last year because of safety concerns related to unsecured doors and the potential for unauthorized people to walk into the hospital.
“If there has been a breach that allows doors to be unlocked, that is a big concern for us,” Jackson said.
The Health Sciences Centre is Manitoba’s provincial tertiary hospital for trauma, transplants, burns, neurosciences, complex cancer care and pediatric care, treating over 570,000 patients annually and operating the largest and busiest emergency departments in Manitoba, according to the HSC’s website.
Some experts said incidents involving OT and facilities management systems in healthcare could become more common.
“If it becomes harder to monetize stolen data or encrypt traditional IT systems, attackers will look for the next lever that creates urgency and pressure,” said Jason Elrod, CISO at MultiCare Health System and a senior advisor at security firm Elisity. “In healthcare, disrupting the physical environment can create enormous pressure very quickly,” he said.
“We make a mistake when we project our own ethics or sense of restraint onto criminals or nation-state threat actors. I tend to group their motivations into three buckets: cash, cause or chaos. None of those motivations guarantees any concern for patient safety,” he said. “That means healthcare organizations have to assume that anything capable of materially affecting operations or patient care may eventually become a target.”
Healthcare organizations need to apply the same level of security scrutiny to facilities management systems that they apply to systems processing protected health information, said John Strand, owner of security services firm Black Hills Information Security.
“For too long, many auditors, security firms and internal security teams have treated these operational systems as somehow outside the scope of cybersecurity,” he said.
“The Winnipeg incident demonstrates why that approach no longer works. These systems are every bit as essential to patient care as the clinical systems inside the hospital. If attackers can disrupt HVAC, elevators, access control or other building management technologies, they can directly impact a hospital’s ability to safely deliver care.”
Also, while Shared Health has not said how attackers gained access to the affected facilities systems, other organizations should assume that their facilities employees, contractors and vendors with privileged access could be targeted through convincing artificial intelligence-generated spear-phishing and spoofed login sites, said Kevin Surace, CEO of security at firmToken.
“For identities capable of affecting the physical environment, organizations should require dedicated, hardware bound, phishing-resistant authentication with biometric user verification, as multifactor authentication and even passkeys are regularly compromised,” he said. “They should also eliminate weaker fallback methods, strictly limit privileges and isolate operational systems from ordinary corporate networks.”
Healthcare organizations should identify the OT systems whose failure could materially affect patient care,” Elrod said. “Segment and isolate them appropriately, tightly control remote and vendor access, maintain accurate asset inventories, monitor them for abnormal activity and make sure recovery plans have actually been tested.”
