>Not to mention every law should first be measured on whether it is at all practical to meaningfully enforce. I guarantee there has been 100x more companies who've paid the ransom and didn't release a press release like this one did.
Let's say you're the in C-suite of a hospital that's held for $1M ransom, and you want to pay. How are you going to send the funds without someone in finance/accounting finding out? Maybe you try to convince them to keep quiet? Such a transaction will almost surely generate a suspicious activity report from the bank. Are you going to try structuring the transaction? How are you going to hide that $1M defect in your quarterly/annual reports? Are you just going to hope it doesn't get noticed by the IRS or the accountants auditing your report? The whole thing is going to unravel because of how many people you need to be "in" on the criminal conspiracy, and the amount of noise it generates. If you're caught, the amount of papertrail you left behind (from literally every step of paying the ransom) would make it very easy to prosecute.
You could try laundering your activities to a third party firm that does "ransomware recovery" (ie. they take your money and pay the ransom for you), but I'd imagine that if paying ransoms were illegal, the activities of those companies would be closely scrutinized.