An estimated 200,000 Ontario home care patients were affected by a ransomware attack on a medical supply vendor, but the provincial home care agency spent weeks trying to establish whose information had been compromised, Global News reported.

Internal emails and reports obtained through freedom of information laws show Ontario Health atHome repeatedly sought details from Ontario Medical Supply (OMS) after the company disclosed a breach in April 2025. By mid-June, the agency’s lawyers were still asking for a breakdown of affected patients and the information taken.

The Ministry of Health did not publicly disclose the cyberattack until Ontario Liberal MPP Adil Shamji raised it in late June 2025, according to the report.

The records suggest the ransomware gained access to servers used by OMS in mid-March 2025 without being detected. It remained inactive for about a month before activating on April 13 and locking a substantial portion of the company’s servers.

OMS notified Ontario Health atHome the following day. Its initial assessment described the risk to the agency and health-care services as low, according to correspondence reviewed by Global News.

Ontario Health atHome began seeking further information days later. A letter from the agency’s lawyers said OMS required questions to be submitted in writing before it would respond.

Weeks of uncertainty over patient information

For more than two weeks after the attack, the records indicate neither organization appeared to believe personal health records had been accessed. On May 6, OMS first disclosed that patient information might have been taken.

Confirmation that health data had been taken came on May 21, according to the legal letter and the provincial government.

In a May 23 email, the OMS chief executive estimated that 200,000 patients were affected, while saying it was difficult to identify individual patients and that a more precise estimate was unlikely.

Ontario Health atHome continued requesting names and numbers so patients could be contacted. A June 13 letter from its lawyers said OMS had not provided a breakdown showing how many affected people were agency patients, or specifics about the personal and health information compromised.

Meanwhile, OMS remained disconnected from Ontario Health atHome’s systems while cybersecurity staff assessed whether access could safely resume. On June 11, the company’s chief executive complained that the continued separation was harming patient care and preventing stockout notifications.

A government report suggests OMS paid the ransom to regain server access. The amount remains unknown, and the government has not supplied a more detailed patient count than 200,000.

OMS did not respond to Global News’ questions before publication. The Ministry of Health provided a statement but did not address the outlet’s questions.