Patient drops request to compel hospital group to pay ransom
wsj.com
wsj.com
Even if you assume some ransom payments would still happen under the table, the amounts would have to be drastically lower (there's a limit to how much can be hidden on a company's balance sheet) meaning much less profit for the hackers and less incentive to attack.
Paying a ransom should be a business decision. There are already many business constructs such as key man insurance, cybercrime insurance etc., that are b2b contractual agreements to protect against such losses. How does one reconcile the existence of such agreements while (potentially) outlawing this?
It is horrifying to be on the receiving end of a business' data security and confidentiality mess.
IANAL, but the patient should have sued under PHI disclosure by the covered entity to an unauthorized party without patient consent. This in addition to the federal HIPAA violations and state civil penalties and other legal remedies the patient is entitled to. [1]
[1]: https://www.hipaajournal.com/what-is-the-maximum-penalty-for...
These already exist.
[1]: https://www.travelers.co.uk/iw-documents/uk/documents/kidnap...