Paying a Ransom: Questions Leadership Should Debate in Advance

No one wants to imagine the moment. Systems are locked, a message demands payment, residents need care, and the clock is running. In that moment, someone will ask whether to pay. The worst time to have that debate for the first time is while the building is in crisis.

This article does not tell you what to decide. It lays out the questions leadership should discuss in advance, ideally with legal counsel, your cyber insurer and your technical advisors present. It is general information, not legal advice.

Why decide early

Under pressure, people make faster and often worse choices. Pre-agreed principles give you a framework, even if you ultimately choose differently on the day. They also clarify who has authority to decide, which saves hours when hours matter.

Legal questions

Is payment permitted?

Payments to certain individuals and groups can violate sanctions administered by the U.S. Treasury's Office of Foreign Assets Control. Paying a sanctioned party can create liability even if you did not know. Counsel and specialist negotiators can help assess this, and federal agencies have advised organizations to consult them and law enforcement.

What reporting duties apply?

A ransomware incident may be a reportable breach under HIPAA if protected health information was accessed or acquired. State laws and contracts may add obligations. Whether or not you pay, notification duties likely remain. Paying does not make a breach disappear.

Should law enforcement be involved?

The FBI and CISA encourage victims to report ransomware incidents. Decide in advance who contacts them and when.

Insurance questions

Does your cyber policy cover ransom payments, and under what conditions?

Does it require insurer approval before negotiating or paying?

Does it provide a panel of response firms you must use?

What exclusions or sublimits apply?

Many policies require notice within a short window, so keep the claim hotline number where you can find it offline.

Operational and ethical questions

What is the impact on residents?

In long-term care, downtime is not just inconvenient. Medication administration, care plans, allergies and contact information may be unavailable. Discuss what downtime procedures exist, such as paper medication records and printed face sheets, and how long you can operate safely without systems.

Can we recover without paying?

The answer depends on your backups. Consider:

Are backups isolated from the main network so attackers cannot encrypt or delete them?

Have you tested a full restore recently?

How long would restoring take, in days rather than hours?

Do you know which systems must return first?

Strong, tested backups give you options. Weak backups can leave you feeling you have none.

Will payment guarantee recovery?

It does not. Decryption tools can be slow or incomplete, and criminals may not deliver. Payment also does not guarantee that stolen data will be deleted, and it does not remove the attackers' access. Systems must still be rebuilt or thoroughly verified.

Does paying encourage more attacks?

Many authorities discourage payment because it funds criminal operations and can mark an organization as willing to pay. Others recognize that leaders face real harm and must make hard choices. Your board should discuss where your organization stands.

Governance questions

Who decides? Name the decision makers and their backups.

Who advises? Include counsel, insurer, incident response firm and technical lead.

What is the process? Write down steps for assessing the situation, verifying backups and evaluating options.

How do we communicate? Plan for staff, residents, families, regulators and media.

How do we pay, if ever? Cryptocurrency payment requires specialized handling and cannot be improvised.

Reduce the odds you ever face the question

The best strategy is to make the question unnecessary:

Maintain offline or immutable backups and test restores

Require MFA everywhere, especially remote access and email

Patch internet-facing systems promptly

Train staff to recognize phishing

Segment networks so one infected computer cannot reach everything

Rehearse your incident plan in a tabletop exercise

Document the decision

Whatever your leadership concludes, record the reasoning in a short written policy and review it annually. Revisit it after any change in insurance, regulation or business.

Working with UnityCare IT

UnityCare IT helps healthcare organizations strengthen backups, tighten defenses and run tabletop exercises so that, if the worst happens, your options are broader than a ransom note suggests.

Related service

An outsourced IT department with proactive maintenance and one number to call.

Related articles

Keep reading

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172