Ransomware raises legal questions that ordinary breaches do not, including whether paying creates sanctions exposure and when encryption alone triggers notification. This hub covers the regulatory and litigation side rather than the technical one.
Ransomware
September 14, 2026
The Cyber Incident Reporting for Critical Infrastructure Act of 2022 wrote two reporting clocks into federal law but left their start date, and the definitions of who reports and what, to a CISA rulemaking that was due in October 2025. This sets out what the statute fixes, what the 2024 proposal would add, and where the rulemaking stood on September 14, 2026.
Read more →
Ransomware
September 14, 2026
HHS does not treat ransomware as a mere outage outside the breach rules. Its Office for Civil Rights reads encryption by an attacker as an acquisition of the data, which brings the incident within the regulatory presumption of breach at 45 CFR 164.402. This sets out where that presumption came from, what rebutting it involves, and the clocks that follow when it stands.
Read more →
Ransomware
August 24, 2026
A ransomware incident sets off obligations that sit outside the state breach statutes entirely. Encryption alone can be a reportable event under HIPAA before any record leaves the building, and the decision to pay opens a separate track running through sanctions law, bank secrecy reporting and securities disclosure. This guide charts those duties and where each clock starts.
Read more →