When ransomware locks your systems, you're faced with a decision that has immediate financial, operational, and compliance consequences. You need a framework before the attack happens, not while your clinical systems are down and patients can't access care.
The Decision You Are Facing
You're choosing between three paths: pay the ransom and hope for decryption, refuse payment and restore from backups, or refuse payment and rebuild affected systems entirely. Each path carries different cost structures, recovery timelines, regulatory implications, and long-term security outcomes.
This isn't a moral question. It's a risk calculation that balances HIPAA Security Rule obligations (specifically 45 CFR § 164.308(a)(7) for contingency planning) against operational reality. The HIPAA Security Rule doesn't prohibit ransom payments, but it does require you to maintain retrievable exact copies of ePHI and test your recovery procedures.
Key Factors That Affect Your Choice
Backup integrity and recency. If your last verified backup predates your most recent patient encounters by more than 24 hours, you're looking at data loss regardless of which path you choose. The Security Rule's addressable specification at § 164.308(a)(7)(ii)(A) requires data backup plans, but "addressable" doesn't mean optional. It means you must implement the control or document equivalent measures.
Encryption scope. Cornerstone Behavioral Healthcare in Maine blocked attacker access within an hour of discovery in May 2026, limiting encryption to less than 10% of data on affected systems. That containment speed changed their calculus entirely. If your incident response can isolate the attack before widespread encryption, rebuilding becomes feasible.
Data exfiltration confirmation. The INC Ransom group exfiltrated 26 GB from Alta Orthopaedics in California before encrypting files. Paying the ransom gets you decryption keys, not data deletion. If the attacker has already copied your files, payment doesn't reduce your Breach Notification Rule obligations under 45 CFR § 164.404. You're still reporting to OCR and notifying affected individuals.
System age and replacement cost. Cornerstone purchased new computers rather than decrypt compromised machines. If your hardware is approaching end-of-life, replacement cost may be lower than you expect, especially when you factor in the time cost of decryption and re-validation.
Insurance coverage terms. Review your cyber liability policy before the incident. Some carriers cover ransom payments; others don't. Some require you to exhaust restoration options first. Know your coverage limits and notification requirements now.
Path A: Pay the Ransom (When Recovery Time Is Critical)
Choose this path when:
- You have no recent, verified backups and face catastrophic data loss
- Your systems support life-sustaining treatment or emergency services with no failover capacity
- Restoration from backup would take longer than decryption
- Your cyber insurance covers the payment and you've confirmed this with your carrier
- You have legal counsel advising on OFAC sanctions compliance (some ransomware groups are sanctioned entities, making payment illegal)
Implementation steps:
Engage a third-party negotiation firm experienced in healthcare ransomware. Don't negotiate directly. Verify the decryption key works on a test system before final payment. Document every decision and the operational necessity that drove it. Notify OCR within 60 days if the incident affects 500 or more individuals, regardless of payment.
What this path doesn't solve:
The attacker still has your data. Alta Orthopaedics paid, and the stolen information was published anyway. You must still conduct the full breach investigation, notify affected individuals, and offer credit monitoring services. The Security Rule's incident response requirements at § 164.308(a)(6) apply whether you pay or not.
Path B: Restore from Backup (When Your Contingency Plan Works)
Choose this path when:
- You have verified, tested backups less than 24 hours old
- Your backup storage is segregated from production networks (attackers can't encrypt it)
- You've practiced restoration procedures in the past 12 months
- You can tolerate the restoration time window without compromising patient safety
- The attack didn't exfiltrate data before encryption (confirmed through forensic analysis)
Implementation steps:
Isolate compromised systems immediately. Wipe affected machines before restoration to ensure no remnant malware. Restore from the most recent clean backup. Validate data integrity before bringing systems back online. Change all administrative credentials and service account passwords. Review firewall rules and disable unnecessary remote access.
Testing requirement:
The Security Rule's addressable specification at § 164.308(a)(7)(ii)(E) requires disaster recovery plan testing. If you've never actually restored from backup under time pressure, you don't know if this path works. Schedule annual restoration drills that simulate ransomware scenarios.
Path C: Rebuild Systems (When Containment Was Fast)
Choose this path when:
- Encryption affected less than 10-15% of your systems
- The cost of new hardware is comparable to decryption and validation time
- Your affected systems are aging and due for replacement
- You want guaranteed clean systems without residual malware risk
- You have sufficient budget or insurance coverage for hardware replacement
Implementation steps:
Cornerstone Behavioral Healthcare wiped affected computers, purchased new ones, and reviewed all systems, policies, and procedures. They provided special workforce training on ransomware recognition. This is the path that lets you implement security improvements during rebuild rather than restoring vulnerable configurations.
Purchase new hardware. Install fresh operating systems and applications. Restore only data (not system files) from verified clean backups. Implement additional security controls before going live: multi-factor authentication for remote access, network segmentation, endpoint detection and response tools, and privileged access management.
Summary Matrix
| Factor | Pay Ransom | Restore Backup | Rebuild Systems |
|---|---|---|---|
| Recovery time | 2-7 days | 1-5 days | 7-21 days |
| Upfront cost | $50K-$500K+ ransom | Minimal | $25K-$200K hardware |
| Data loss risk | Low (if key works) | Depends on backup age | Depends on backup age |
| Residual malware risk | High | Medium | Minimal |
| Breach notification required | Usually yes | Maybe (depends on exfiltration) | Maybe (depends on exfiltration) |
| Long-term security improvement | None | Limited | Significant opportunity |
| HIPAA compliance posture | Weakest | Adequate if tested | Strongest |
The decision tree assumes you're making this choice during an active incident. The better decision is made months earlier: implement the Security Rule's Required Specifications for access controls (§ 164.312(a)(1)), maintain and test your contingency plan, and train your workforce to recognize phishing attempts that deliver ransomware.
Cameron Regional Medical Center in Missouri is still investigating an attack detected in June 2026, with the Anubis group claiming 500 GB of data exfiltration. That investigation timeline stretches beyond two months because they didn't have the forensic readiness to answer basic questions quickly. Your decision-making speed depends on preparation you do now, not crisis response you improvise later.



