Categories: Canada

Ontario government home care vendor paid ransom to regain access to its servers: report


A medical supplies vendor, contracted by Ontario’s taxpayer-funded home care agency, paid out a ransom demand last year, after its systems were accessed and data belonging to as many as 200,000 patients was locked, according to an Ontario government agency report.

In April 2025, servers belonging to Ontario Medical Supply — which works with Crown agency Ontario Health atHome to deliver equipment to homecare patients — were locked after a ransomware attack.

A ransomware attack generally takes place when a malicious actor enters a system, stealing its files and locking them. A ransom is then demanded for the company to get access to their files again.

While the Ministry of Health initially said no ransom had been demanded from or paid by either the government or Ontario Health atHome, internal government documents reveal the full picture.

Emails and other records obtained by Global News using freedom of information law indicate that a ransom was paid — potentially by the vendor, OMS.

Story continues below advertisement

The revelation appears in a report submitted by Ontario Health atHome to the Information and Privacy Commissioner in late May 2025, with details of the ransomware attack along with confirmation that money was paid to the attackers to regain access.

Get weekly health news

Receive the latest medical news and health information delivered to you every Sunday.

“Other servers were unencrypted with the key provided upon payment of the ransom,” the report said.

Global News attempted to contact OMS by phone and email, but did not receive a response ahead of publication.

“We have determined that a limited amount of incomplete data was exfiltrated during the incident … there is no evidence that any personal financial information or critical health data was exfiltrated. There is also no evidence that any of the information has been misused,” the company said in a statement on its website after the attack last year.

“Safeguarding the personal health information entrusted to us is our top priority, and we are committed to supporting any customers who have concerns or may have been affected by this incident.”

Ontario Liberal MPP Adil Shamji has raised concerns about whether the ransom was paid and if it, even indirectly, involved taxpayer money.

“This constituted malicious actors with sinister interests shaking down our province and our health-care system,” he said. “(It) only underscores how swiftly the government should have acted in order to fulfil their legal obligation.”

Story continues below advertisement

The documents show that the ransomware is thought to have first entered the OMS system around March 17. It was activated on April 13, when the company’s servers were locked.

The report is not clear when the ransom was said to be paid to unlock the servers, but it took weeks for Ontario Health atHome and OMS to try and work out what data had been compromised.

By May 30, Ontario Health atHome submitted a report to the province’s privacy watchdog.

“OMS advised that a ransomware variant had been used to infiltrate encrypted servers storing electronic medical records,” the report, accessed using freedom of information laws, explained.

“Initially, OMS reported that no PHI appeared to be involved. Their subsequent investigation, supported by their cybersecurity experts, determined that there was PHI on the servers and that an ex-filtration of patient information was found.”

The report said that at the time OMS “had not been able to identify specific patients affected” by the breach.

&copy 2026 Global News, a division of Corus Entertainment Inc.



Source link

admin2

Share
Published by
admin2

Recent Posts

Prairie Harm Reduction’s operations suspended amid financial woes – Saskatoon

Descrease article font size Increase article font size Prairie Harm Reduction says it has had…

10 minutes ago

Cost of Premier Doug Ford’s top staff grew by 11% in 2025

Premier Doug Ford’s office grew in size and salaries in 2025, according to the latest…

3 hours ago

New Nuclear ETF Swaps TSM for Broadcom in Rebalance

The ALPS Nautilus SMR, Nuclear & Technology ETF (SMRF) replaced Taiwan Semiconductor Manufacturing Co. (TSM)…

4 hours ago

Land Day in Gaza: Between memory and the fight for what remains | Gaza

Gaza City, Gaza Strip – Inside a tent pitched on a small patch of land,…

4 hours ago

Cardano Founder Just Released A Free Book On Zero-Knowledge

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure Cardano founder…

4 hours ago

Angus, the C. difficile sniffing dog, celebrated as he retires after a decade

Nearly 10 years after he began his hunt for a superbug known as C. difficile…

6 hours ago