Paying a ransom should be a business decision. There are already many business constructs such as key man insurance, cybercrime insurance etc., that are b2b contractual agreements to protect against such losses. How does one reconcile the existence of such agreements while (potentially) outlawing this?
It is horrifying to be on the receiving end of a business' data security and confidentiality mess.
IANAL, but the patient should have sued under PHI disclosure by the covered entity to an unauthorized party without patient consent. This in addition to the federal HIPAA violations and state civil penalties and other legal remedies the patient is entitled to. [1]
[1]: https://www.hipaajournal.com/what-is-the-maximum-penalty-for...