The Health Sciences Centre is responding to a ransomware incident that has affected certain facility maintenance systems, including HVAC and door access controls, Shared Health confirmed Monday. The provincial health authority said patient care and clinical operations remain unaffected and fully operational at HSC, Manitoba’s largest hospital. It adds anyone needing care should continue to attend the hospital as normal. An investigation was launched immediately after the incident was discovered to determine its scope and impact. “At this time, the incident appears to have only impacted certain facility maintenance systems and our investigation is ongoing,” Shared Health said in a Monday evening news release, adding that the investigation to date has found no indication patients have been affected. “HSC is working diligently to address the situation as safely and securely as possible, while maintaining continuity of patient care and clinical operations.” Shared Health said the hospital has notified the provincial government and has brought in third-party experts to assist with the response. Auditor general warned of cybersecurity gaps in 2024 The breach comes roughly two years after Manitoba’s auditor general flagged gaps in Shared Health’s cybersecurity readiness, noting the agency wasn’t conducting the kind of testing needed to ensure a swift response to an attack. The warning stems from a December 2024 report by the Office of the Auditor General, which examined whether Shared Health could promptly respond to and manage cybersecurity incidents between April 2022 and March 2024. Auditors found the health authority had a documented incident response plan and dedicated response team in place, but had “not conducted any tests for any incident scenarios including ransomware, data theft, or denial of service attacks” during the audit period — despite an internal standard requiring an annual review or test. The report also flagged gaps in staff training, an unfinished plan for communicating with the public and other outside parties during an attack, and the absence of specific requirements for data and evidence retention related to cybersecurity incidents. Auditor General Tyson Shtykalo’s office made four recommendations, including that Shared Health test its incident response plan annually and train team members on their roles under the plan. Without that groundwork, the report notes, “there could be delays in responding to cybersecurity incidents at Shared Health.” In its written response included in the report, Shared Health agreed with all four recommendations, saying it was building a training course for incident-response staff and would develop a testing strategy with regular tabletop exercises and walkthroughs going forward. A spokesperson for the provincial health agency confirmed to CTV News Tuesday it is actively implementing the changes. In a statement, Uzoma Asagwara, Manitoba’s Health, Seniors and Long-Term Care minister, said the report’s recommendations were taken seriously. “It’s really important for us across government that cybersecurity is a top priority,” the statement reads. “We want to make sure that Manitobans’ information is protected.” With files from CTV’s Danton Unger