No one wants to imagine the moment. Systems are locked, a message demands payment, residents need care, and the clock is running. In that moment, someone will ask whether to pay. The worst time to have that debate for the first time is while the building is in crisis.
This article does not tell you what to decide. It lays out the questions leadership should discuss in advance, ideally with legal counsel, your cyber insurer and your technical advisors present. It is general information, not legal advice.
Under pressure, people make faster and often worse choices. Pre-agreed principles give you a framework, even if you ultimately choose differently on the day. They also clarify who has authority to decide, which saves hours when hours matter.
Payments to certain individuals and groups can violate sanctions administered by the U.S. Treasury's Office of Foreign Assets Control. Paying a sanctioned party can create liability even if you did not know. Counsel and specialist negotiators can help assess this, and federal agencies have advised organizations to consult them and law enforcement.
A ransomware incident may be a reportable breach under HIPAA if protected health information was accessed or acquired. State laws and contracts may add obligations. Whether or not you pay, notification duties likely remain. Paying does not make a breach disappear.
The FBI and CISA encourage victims to report ransomware incidents. Decide in advance who contacts them and when.
Does your cyber policy cover ransom payments, and under what conditions?
Does it require insurer approval before negotiating or paying?
Does it provide a panel of response firms you must use?
What exclusions or sublimits apply?
Many policies require notice within a short window, so keep the claim hotline number where you can find it offline.
In long-term care, downtime is not just inconvenient. Medication administration, care plans, allergies and contact information may be unavailable. Discuss what downtime procedures exist, such as paper medication records and printed face sheets, and how long you can operate safely without systems.
The answer depends on your backups. Consider:
Are backups isolated from the main network so attackers cannot encrypt or delete them?
Have you tested a full restore recently?
How long would restoring take, in days rather than hours?
Do you know which systems must return first?
Strong, tested backups give you options. Weak backups can leave you feeling you have none.
It does not. Decryption tools can be slow or incomplete, and criminals may not deliver. Payment also does not guarantee that stolen data will be deleted, and it does not remove the attackers' access. Systems must still be rebuilt or thoroughly verified.
Many authorities discourage payment because it funds criminal operations and can mark an organization as willing to pay. Others recognize that leaders face real harm and must make hard choices. Your board should discuss where your organization stands.
Who decides? Name the decision makers and their backups.
Who advises? Include counsel, insurer, incident response firm and technical lead.
What is the process? Write down steps for assessing the situation, verifying backups and evaluating options.
How do we communicate? Plan for staff, residents, families, regulators and media.
How do we pay, if ever? Cryptocurrency payment requires specialized handling and cannot be improvised.
The best strategy is to make the question unnecessary:
Maintain offline or immutable backups and test restores
Require MFA everywhere, especially remote access and email
Patch internet-facing systems promptly
Train staff to recognize phishing
Segment networks so one infected computer cannot reach everything
Rehearse your incident plan in a tabletop exercise
Whatever your leadership concludes, record the reasoning in a short written policy and review it annually. Revisit it after any change in insurance, regulation or business.
UnityCare IT helps healthcare organizations strengthen backups, tighten defenses and run tabletop exercises so that, if the worst happens, your options are broader than a ransom note suggests.
An outsourced IT department with proactive maintenance and one number to call.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172