Ransomware raises legal questions that ordinary breaches do not, including whether paying creates sanctions exposure and when encryption alone triggers notification. This hub covers the regulatory and litigation side rather than the technical one.

Ransomware

When Ransomware Encrypts Health Data, HIPAA Presumes a Breach: How the Presumption Works

September 14, 2026

HHS does not treat ransomware as a mere outage outside the breach rules. Its Office for Civil Rights reads encryption by an attacker as an acquisition of the data, which brings the incident within the regulatory presumption of breach at 45 CFR 164.402. This sets out where that presumption came from, what rebutting it involves, and the clocks that follow when it stands.

Read more →
Ransomware

Ransomware Notification: The Federal and Sectoral Obligations an Extortion Incident Triggers

August 24, 2026

A ransomware incident sets off obligations that sit outside the state breach statutes entirely. Encryption alone can be a reportable event under HIPAA before any record leaves the building, and the decision to pay opens a separate track running through sanctions law, bank secrecy reporting and securities disclosure. This guide charts those duties and where each clock starts.

Read more →