The FBI and HHS discourage ransom payments. In the abstract, of course hospitals shouldn’t pay extortionists. Payouts encourage future attacks and perpetuate the cycle. Still, when the patients you’ve given an oath to protect are at risk, how do you say no?
Regulators identify hospitals as critical infrastructure, and yet they are treated as individual businesses who are largely responsible for their own cybersecurity. HIPAA-regulated hospitals are required to use “reasonable and appropriate” safeguards to protect confidentiality and availability of protected health information. What the rules don’t prescribe is specific architecture or technologies.
HHS’s Healthcare Cybersecurity Performance Goals are more detailed but voluntary. They urge hospitals to consider offline backups inaccessible from their main networks, multi-factor authentication, and incident response planning. Many of these recommendations are part of a proposed overhaul of HIPAA security, which was put forth in December 2024. The plan has met major pushback from within the healthcare industry due to the cost of the changes, which are predicted to top $20 billion within the first 3 years. Final action on the proposal is now targeted for July 2027.
Even disclosure of an attack is partly at the discretion of the hospital. Patients whose protected health information has been exposed in a breach must be notified along with HHS, and if over 500 patients are involved the healthcare entity is required to report the incident to the media. Law enforcement involvement is currently voluntary. The Cyber Incident Reporting for Critical Infrastructure Act of 2022 would make it mandatory to report cyber incidents to the Cybersecurity and Infrastructure Security Agency within 72 hours and ransom payments within 24 hours. It’s yet to be implemented 4 years later.
The patchwork nature and competing interests of our healthcare system make sweeping changes difficult. But these problems aren’t going away: they’re accelerating. Large language models will soon allow small groups of criminals to automate large-scale ransomware attacks. And your local hospital probably isn’t ready for it.
But you know who could be? The national institutions designed to protect critical infrastructure.
It’s time to institute the Health Insurance Portability and Accountability Act (HIPAA) security overhaul. Require all hospitals to have the ability to maintain clinical continuity during a cyberattack. Set clear technological standards. Federally subsidize their implementation, so that small rural hospitals aren’t forced to choose between security and solvency. Mandate not only government reporting but federal assistance in ransomware negotiations.
We assume hostage negotiations are handled by law enforcement as a matter of course: it would seem bizarre if a regional bank manager was haggling for the release of 10 employees being held at gunpoint. Lives are on the line here too. And right now, a health system’s best option may be to hire a breach response company or specialized negotiation services in the case of an attack — but this can require time and extensive resources.
Centralizing negotiations would recruit the expertise of organizations experienced in cyber defense. It would aggregate intelligence and allow coordinated responses across multiple events. A private negotiator or cyber insurance firm may be able to lower a ransom demand. They can’t seize a crypto wallet or extradite the offender.
Relinquishing control can be uncomfortable, but we do it all the time in healthcare. We measure the quality of our care against guidelines set by our professional societies. We order consults and send our patients to operating rooms and intensive care units where critical choices are in the hands of other physicians. We delegate these decisions because we understand that standardization and domain expertise protect our patients from injury and us from error. Cyber defense and ransom negotiations should be no different.
None of this is guaranteed to stop the potential release of sensitive patient data. Even if attackers are paid, even if they claim they’ve destroyed the records, protected health information can be used to target individual victims for additional financial gain. The only way to genuinely protect patients is to prevent future attacks. Hospitals can’t do that alone. Deterrence requires the resources of the federal government.
I’m standing in the OR, about to operate. I ask the nurse to pull up the CT. I’ve seen it already, but I always check one last time for good measure. She clicks on the link. Nothing happens.







