decisionhealth Newsletters, Part B News - 2021 Issue 11 (November)
Paying a hacking ransom could bring trouble; take steps to stay safe
Subscribe or sign in to view the full article.
Article Overview
This article explains the risks health care organizations may face when deciding whether to pay a ransomware demand. It focuses on federal guidance from law enforcement and sanctions authorities, the need to evaluate potential sanctions exposure, and the importance of involving legal, forensic, and compliance resources before any payment is made. It is relevant to providers, compliance teams, counsel, and security professionals who manage ransomware response and reporting obligations.
Why This Topic Matters
Ransomware can disrupt patient care and operations, but payment decisions may create separate legal and regulatory exposure. The article helps readers understand the broad categories of federal guidance and the kinds of checks and consultations that are discussed in ransomware response planning.
Article Sections
-
Ransomware and federal enforcement concerns
Introduces the topic of ransomware in health care and summarizes the general position taken by federal law enforcement and sanctions authorities.
-
Check and call
Describes the article’s discussion of sanctions screening, notification to government agencies, and the involvement of outside vendors, counsel, and forensic resources in response planning.
-
Pay anyway?
Covers the article’s discussion of seeking federal authorization, weighing urgent operational concerns, and considering broader circumstances that may affect response decisions.
-
Further legal issues
Addresses additional regulatory concerns that may arise beyond sanctions issues, including health care privacy and breach-reporting implications.
-
Resources
Lists external government and agency resources referenced by the article for ransomware, sanctions, and related guidance.
What You Will Learn
- How the article frames ransomware risk in the health care setting
- What types of federal agencies and guidance are discussed
- Why sanctions screening and agency consultation are emphasized
- What broader compliance issues may arise after a ransomware incident
- Which kinds of response teams and resources the article references
Who Should Read This
- Health care providers
- Practice managers
- Compliance officers
- Health care attorneys
- Privacy and security professionals
- Revenue cycle and operations leaders
Subscribe or sign in to view the full article.


Quick, Current, Complete - www.findacode.com