Ransomware Notification: The Federal and Sectoral Obligations an Extortion Incident Triggers
Key Takeaways
- HHS treats ransomware encryption of electronic protected health information as an acquisition and therefore a presumed breach, rebuttable only by a documented low-probability-of-compromise assessment
- OFAC applies strict civil liability to sanctions violations, so a payment can breach sanctions law even where the payer did not know and had no reason to know the recipient was designated
- A public company must file a Form 8-K under Item 1.05 within four business days of determining an incident is material, subject to an Attorney General national-security delay
- CIRCIA's 72-hour incident and 24-hour ransom-payment reports are enacted but not yet in force: the statute makes them effective only on dates set by a final rule CISA has not issued
- The New York Department of Financial Services requires notice of an extortion payment within 24 hours and a written explanation within 30 days, including the OFAC diligence performed
What This Guide Covers
Every state has a data breach notification statute, and those statutes apply to ransomware like any other security incident. This guide is not about them. The individual-notice deadlines, regulator thresholds and encryption safe harbours that vary state by state are charted separately in the guide to state breach notification requirements, and repeating them here would obscure the point.
What follows is the other track: the federal and sectoral obligations that attach specifically because an incident is an extortion event. They are structurally different from the state statutes in three ways. Several are triggered by encryption itself rather than by exfiltration, so they can attach before anyone knows whether data left the building. Several are triggered by the payment rather than by the incident, so they attach only if a ransom is paid, and they run on much shorter clocks. And their enforcers are federal agencies and sector regulators rather than state attorneys general.
The HIPAA Presumption: Encryption as Acquisition
For entities handling protected health information, the analytically hardest question is whether encryption without exfiltration is a breach at all. The HHS Office for Civil Rights answered it in its fact sheet on ransomware and HIPAA, and the answer is that it generally is:
That reasoning treats the attacker's control over the data as the acquisition, which means the reportable event is complete at the moment of encryption. It does not depend on the attacker reading, copying or publishing anything.
The regulation then supplies a presumption rather than a conclusion. Under 45 C.F.R. part 164 subpart D, an impermissible acquisition, access, use or disclosure "is presumed to be a breach unless the covered entity or business associate, as applicable, demonstrates that there is a low probability that the protected health information has been compromised based on a risk assessment" of the specified factors. The fact sheet states the same allocation: unless low probability of compromise is demonstrated, "a breach of PHI is presumed to have occurred."
The burden therefore sits on the entity, and the default is notification. Where the presumption is not rebutted, subpart D sets notice to affected individuals without unreasonable delay and no later than 60 calendar days after discovery, with parallel notice to the Secretary of HHS and, for breaches affecting 500 or more individuals, to the media.
Sanctions Exposure Attaches to the Payment
The payment decision is governed by sanctions law rather than by any privacy statute. The Treasury Department's Office of Foreign Assets Control set out its position in an updated advisory dated September 21, 2021, which states that the U.S. government "strongly discourages all private companies and citizens from paying ransom or extortion demands."
The operative legal point is the standard of liability. Payments to a designated person, or one in a comprehensively embargoed jurisdiction, are prohibited under the International Emergency Economic Powers Act, and the advisory describes the consequence in terms that do not turn on intent:
Because ransomware actors are pseudonymous and rebrand frequently, attribution is often unavailable at the moment of payment, and strict liability means that uncertainty does not itself excuse a violation. The exposure also runs beyond the victim. The advisory identifies financial institutions, cyber insurance firms and digital forensics and incident response companies as facing the same risk when they facilitate a payment on a victim's behalf.
The advisory identifies factors OFAC treats as mitigating in an enforcement response: an adequate risk-based sanctions compliance programme, meaningful improvements to cybersecurity practices, and reporting. On the last, OFAC states it will consider "a company's self-initiated and complete report of a ransomware attack to law enforcement or other relevant U.S. government agencies, such as CISA or the U.S. Department of the Treasury's Office of Cybersecurity and Critical Infrastructure Protection (OCCIP), made as soon as possible after discovery of an attack, to be a voluntary self-disclosure and a significant mitigating factor." Applications for a licence to make a payment with a sanctions nexus are reviewed "on a case-by-case basis with a presumption of denial."
The Financial-System Overlay
FinCEN addresses the same payment from the anti-money-laundering side in Advisory FIN-2021-A004, issued November 8, 2021, which replaced an October 2020 advisory of the same name.
Its consequential passage concerns intermediaries. Where incident response firms, cyber insurers or virtual-currency businesses receive a customer's funds, convert them and transfer value to an attacker-controlled account, the advisory states that "[d]epending on the particular facts and circumstances, this activity could constitute money transmission," and that entities engaged in money services business activities "are required to register as an MSB with FinCEN, and are subject to BSA obligations, including filing SARs."
For financial institutions themselves, the advisory restates the suspicious activity reporting duty and applies it in both directions — to ransomware activity conducted by, at or through the institution, and to "ransom payments made by financial institutions that are victims of ransomware." An institution that is itself the victim can therefore have a reporting obligation arising from its own payment. The advisory also cross-references the OFAC advisory directly, noting that persons involved in ransomware payments "must also be aware of any Office of Foreign Assets Control (OFAC)-related obligations that may arise from that activity."
Securities Disclosure for Public Companies
Public companies carry a disclosure obligation that runs to investors rather than to a regulator or to affected individuals. The Securities and Exchange Commission adopted it in Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure, 88 Fed. Reg. 51896 (Aug. 4, 2023).
New Item 1.05 of Form 8-K provides that if a registrant "experiences a cybersecurity incident that is determined by the registrant to be material," it must "describe the material aspects of the nature, scope, and timing of the incident, and the material impact or reasonably likely material impact on the registrant, including its financial condition and results of operations." The filing is due within four business days.
The trigger is worth reading closely, because it is not the incident. The four business days run from the determination of materiality, not from discovery, detection or containment — a structure that differs from every other clock described here. The rule also requires a registrant to amend a prior Item 1.05 filing to supply information that was undetermined or unavailable when the original was filed.
One delay mechanism exists, and it is narrow: a registrant may delay filing if the United States Attorney General "determines immediate disclosure would pose a substantial risk to national security or public safety" and notifies the Commission. Separately, Item 106 of Regulation S-K requires annual disclosure of processes for assessing and managing material cybersecurity risks, board oversight of those risks, and management's role — an ongoing obligation independent of any incident.
CIRCIA: Enacted, Not Yet in Force
The Cyber Incident Reporting for Critical Infrastructure Act is the most frequently described federal ransomware reporting obligation, and as of publication it does not yet bind anyone. That distinction matters more than the deadlines themselves.
The statute, codified at 6 U.S.C. § 681b, sets two clocks. A covered entity experiencing a covered cyber incident "shall report the covered cyber incident to the Agency not later than 72 hours after the covered entity reasonably believes that the covered cyber incident has occurred." Separately, a covered entity "that makes a ransom payment as the result of a ransomware attack against the covered entity shall report the payment to the Agency not later than 24 hours after the ransom payment has been made," and that duty "shall apply even if the ransomware attack is not a covered cyber incident" otherwise reportable.
Both are suspended on a rulemaking. Section 681b(a)(7) provides that the reporting paragraphs "shall take effect on the dates prescribed in the final rule issued pursuant to subsection (b)." A search of the Federal Register conducted for this guide returned no final CIRCIA rule; the most recent CIRCIA rulemaking documents are notices of town hall meetings published at 91 Fed. Reg. 6794 (Feb. 13, 2026) and 91 Fed. Reg. 30498 (May 26, 2026). Until a final rule issues, the statutory clocks have no start date, and the definition of "covered entity" that determines who they reach has not been fixed.
Sector Regulators Impose Their Own Filings
Below the cross-cutting federal layer, individual regulators impose filings on the entities they supervise, on clocks shorter than the state statutes generally set.
The Federal Trade Commission's Safeguards Rule requires a non-banking financial institution to notify the Commission of a notification event involving the information of at least 500 consumers "as soon as possible, and no later than 30 days after discovery of the event," under 16 C.F.R. § 314.4(j). The rule prescribes the contents, including the number of consumers affected or potentially affected, and provides for law-enforcement delay of up to 30 days, extendable by a further 60.
The federal banking agencies run the shortest clock of any obligation described here. Under 12 C.F.R. part 53, a supervised banking organisation must notify its regulator "as soon as possible and no later than 36 hours after the banking organization determines that a notification incident has occurred." The same part places a distinct duty on bank service providers to notify affected banking organisation customers.
New York's Department of Financial Services is the regulator that addresses extortion payments most directly. Under the second amendment to 23 NYCRR Part 500, section 500.17(a) requires notice to the Superintendent "as promptly as possible but in no event later than 72 hours after determining that a cybersecurity incident has occurred," including incidents at affiliates or third-party service providers. Section 500.17(c) then adds a payment-specific duty: notice of an extortion payment within 24 hours, followed within 30 days by "a written description of the reasons payment was necessary, a description of alternatives to payment considered, all diligence performed to find alternatives to payment and all diligence performed to ensure compliance with applicable rules and regulations including those of the Office of Foreign Assets Control."
That last clause makes the OFAC analysis a documented filing obligation for covered entities rather than an internal question, and it is the clearest example of one regime incorporating another by reference.
How These Clocks Interact With the State Clocks
The federal and sectoral duties described here do not displace the state breach notification statutes; they run alongside them, and the two sets are triggered by different facts and measured from different starting points.
Three structural differences account for most of the divergence. State statutes generally key notification to a determination that personal information was acquired or, in many states, that acquisition creates a risk of harm — an analysis about exfiltration. The HIPAA presumption and the banking rules key to the incident and to the entity's own determination, which can be satisfied by encryption alone. Second, the payment-triggered duties under CIRCIA and section 500.17(c) have no analogue in state breach law at all, because a ransom payment is not a disclosure of personal information. Third, the SEC obligation runs from a materiality judgement about the company, not a factual finding about records, so it can attach where no personal information was involved.
The practical consequence is that a single incident can produce a 24-hour clock, a 36-hour clock, a 72-hour clock, a four-business-day clock, a 30-day clock and a 60-day clock, each starting from a different event.
Where the Record Is Incomplete
Two things this guide does not supply, because the sources do not.
It does not chart enforcement history. No OFAC civil penalty specifically for a ransomware payment was located in the sources fetched for this guide, and the advisory describes the enforcement framework rather than any applied outcome. Under this site's sourcing rules, describing the framework is not a substitute for enforcement history, and none is claimed here.
It also does not state which entities CIRCIA will reach. The statute leaves the definition of covered entity to the rulemaking, and that rule has not issued, so any figure for how many organisations fall within it would be drawn from a proposal rather than from a rule in force.
Insurance coverage disputes over ransom payments and business interruption losses are litigated primarily under policy wording rather than statute, and no coverage decision was fetched and read for this guide, so no coverage position is described.
Background
For the underlying law rather than this development: Healthcare privacy law, Financial Services privacy law.
Frequently Asked Questions
Is a ransomware attack a breach if no data was stolen?
Is paying a ransom illegal?
When must a public company report a ransomware incident to the SEC?
Does CIRCIA require reporting a ransom payment within 24 hours?
Which regulator has the shortest reporting deadline?
Do incident response firms and cyber insurers have their own obligations?
Sources
Everything above is reported from these documents. Follow them to verify.
- OFAC — Updated Advisory on Potential Sanctions Risks for Facilitating Ransomware Payments (September 21, 2021) agency guidance
- FinCEN Advisory FIN-2021-A004 — Ransomware and the Use of the Financial System to Facilitate Ransom Payments (November 8, 2021) agency guidance
- SEC — Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure, 88 Fed. Reg. 51896 (final rule, Form 8-K Item 1.05) (August 4, 2023) regulation
- 6 U.S.C. § 681b — Required reporting of certain cyber incidents and ransom payments (CIRCIA) (March 15, 2022) statute
- HHS Office for Civil Rights — FACT SHEET: Ransomware and HIPAA (July 11, 2016) agency guidance
- 45 C.F.R. part 164 subpart D — Notification in the Case of Breach of Unsecured Protected Health Information (August 24, 2026) regulation
- 16 C.F.R. § 314.4(j) — FTC Safeguards Rule notification of a notification event (August 24, 2026) regulation
- 12 C.F.R. part 53 — Computer-Security Incident Notification (36-hour rule) (August 24, 2026) regulation
- 23 NYCRR Part 500 — Second Amendment as adopted, including § 500.17 notice and extortion payment provisions (November 1, 2023) regulation
Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.