Skip to main content

Nixon Peabody LLP

  • People
  • Capabilities
  • Insights
  • About
Trending Topics
    • People
    • Capabilities
    • Insights
    • About
    • Locations
    • Events
    • Careers
    • Alumni
    Practices

    View All

    • Affordable Housing
    • Community Development Finance
    • Corporate & Finance
    • Cybersecurity & Privacy
    • Entertainment & Media
    • Environmental
    • Franchising & Distribution
    • Government Investigations & White Collar Defense
    • Healthcare
    • Intellectual Property
    • International Services
    • Labor, Employment, and Benefits
    • Litigation
    • Private Wealth & Advisory
    • Project Finance
    • Public Finance
    • Real Estate
    • Regulatory & Government Relations
    Industries

    View All

    • Aviation
    • Cannabis
    • Consumer
    • Energy
    • Financial Services
    • Healthcare
    • Higher Education
    • Infrastructure
    • Manufacturing
    • Nonprofit Organizations
    • Real Estate
    • Sports & Stadiums
    • Technology
    Value-Added Services

    View All

    • Alternative Fee Arrangements

      Developing innovative pricing structures and alternative fee agreement models that deliver additional value for our clients.

    • Continuing Education

      Advancing professional knowledge and offering credits for attorneys, staff and other professionals.

    • Crisis Advisory

      Helping clients respond correctly when a crisis occurs.

    • DEI Strategic Services

      Providing our clients with legal, strategic, and practical advice to make transformational changes in their organizations.

    • eDiscovery

      Leveraging law and technology to deliver sound solutions.

    • Environmental, Social, and Governance (ESG)

      We help clients create positive return on investments in people, products, and the planet.

    • Global Services

      Delivering seamless service through partnerships across the globe.

    • Innovation

      Leveraging leading-edge technology to guide change and create seamless, collaborative experiences for clients and attorneys.

    • IPED

      Industry-leading conferences focused on affordable housing, tax credits, and more.

    • Legal Project Management

      Providing actionable information to support strategic decision-making.

    • Legally Green

      Teaming with clients to advance sustainable projects, mitigate the effects of climate change, and protect our planet.

    • Nixon Peabody Trust Company

      Offering a range of investment management and fiduciary services.

    • NP Capital Connector

      Bringing together companies and investors for tomorrow’s new deals.

    • NP Second Opinion

      Offering fresh insights on cases that are delayed, over budget, or off-target from the desired resolution.

    • NP Trial

      Courtroom-ready lawyers who can resolve disputes early on clients’ terms or prevail at trial before a judge or jury.

    • Social Impact

      Creating positive impact in our communities through increasing equity, access, and opportunity.

    • Women in Dealmaking

      We provide strategic counsel on complex corporate transactions and unite dynamic women in the dealmaking arena.

    1. Home
    2. Insights
    3. Articles
    4. Healthcare Cybersecurity: Responding to Ransomware

      Articles

    Article

    Healthcare Cybersecurity: Responding to Ransomware

    June 3, 2025

    LinkedInX (Twitter)EmailCopy URL

    By Valerie Montague, Jason Kravitz, Jenny Holmes and Meredith LaMaster

    Explore practical strategies to help healthcare organizations defend against ransomware, reduce breach impact, and meet evolving legal and compliance demands in 2025.

    Ransomware attacks on healthcare organizations surged in 2024, with nearly 400 US providers reporting incidents. Hospitals, clinics, and vendors remain prime targets due to the high value of patient data and the urgency of care delivery. According to IBM’s 2024 Cost of a Data Breach Report, healthcare breaches now average $9.77 million—the highest across all industries for the 14th year. The US Department of Health and Human Services also noted a sharp rise in ransomware cases, driven by outdated systems, misconfigured devices, and cloud vulnerabilities. These trends highlight the urgent need for stronger cybersecurity in healthcare.

    This article outlines key strategies for healthcare organizations to prevent, respond to, and recover from ransomware incidents—while minimizing legal exposure and reputational harm.

    Why Healthcare Is a Prime Ransomware Target

    Healthcare organizations are particularly vulnerable to ransomware for several reasons:

    • High-value data: Protected Health Information (PHI), particularly insurance and financial information, is lucrative on the black market.
    • Operational urgency: Disruptions to operating systems can endanger patient care, making organizations more likely to pay ransoms.
    • Legacy systems: Many providers rely on outdated infrastructure with limited cybersecurity defenses. Updating these systems requires significant investments in infrastructure and personnel.

    To Pay or Not to Pay?

    When ransomware strikes, one of the most difficult decisions is whether to pay the ransom. While paying may seem like the fastest route to restoring operations, it comes with significant risks:

    Pros:

    • Potential recovery of encrypted data
    • Potential avoidance of public disclosure
    • Possible protection of patient safety
    • Potential restoration of critical operating systems

    Cons:

    • No guarantee of full data recovery
    • Risk of repeat attacks (80% of victims are hit again)
    • Legal implications, including potential violations of OFAC regulations

    Ultimately, the decision is both a business and patient-care judgment. However, the FBI strongly discourages paying ransoms.

    Prevention Starts with Preparation

    Backups are your best defense. Maintain multiple backups of critical data, including one stored off-site or in the cloud. Regularly test backup integrity to ensure data can be restored quickly.

    Incident Response Plans. A well-documented and practiced incident response plan is essential. It should:

    • Define roles and responsibilities
    • Outline communication protocols
    • Include legal and regulatory response steps
    • Be tested regularly through tabletop exercises

    HIPAA Compliance and Risk Management. Ensure your HIPAA compliance program is up to date and reflects actual practices. Key components include:

    • Security risk analyses and management plans
    • Workforce training tailored to job functions
    • Business Associate Agreements (BAAs) with clear breach reporting terms
    • Designated Privacy and Security Officers

    Breach Notification: Know Your Obligations

    HIPAA Requirements. A ransomware attack may constitute a breach under HIPAA if PHI is encrypted or accessed without authorization. A breach risk assessment must evaluate:

    • The nature of the PHI involved
    • Whether the data was actually acquired or viewed
    • The extent of mitigation efforts

    State Laws and Contracts. Even if HIPAA doesn’t require notification, state laws or contractual obligations might. Organizations must:

    • Determine which state laws apply
    • Review BAAs and vendor contracts for reporting requirements
    • Coordinate with legal counsel to ensure timely and accurate notifications

    Post-Incident Legal Considerations

    If PHI is compromised, the incident may be listed on the HHS breach portal, increasing the risk of litigation. Plaintiffs may file class actions based on:

    • Alleged violations of state privacy laws
    • Claims of emotional distress or fear of identity theft

    Best Practices to Minimize Litigation Risk

    • Engage experienced cybersecurity counsel immediately
    • Conduct a thorough forensic investigation
    • Document the investigation, the remediation, and all response efforts
    • Ensure transparency and timeliness in notifications

    From Risk to Readiness

    Cybersecurity is no longer just an IT issue—it’s a patient safety, legal, and reputational imperative. Healthcare organizations must take proactive steps to strengthen their defenses, prepare for the inevitable, and respond with precision when incidents occur.

    At Nixon Peabody, our Healthcare and Cybersecurity & Privacy attorneys collaborate to help HIPAA-regulated entities and healthcare providers develop robust compliance programs, respond to cyber incidents, and navigate the complex regulatory landscape.

    Practices

    HealthcareHealth Information - Privacy, Security & Data SharingHealthcare Regulatory & ComplianceCybersecurity & Privacy

    Industries

    Healthcare

    Key Contacts

    For more information, please contact:

    Valerie Breslin Montague

    Partner

    • Office+1 312.977.4485
    • vbmontague@nixonpeabody.com

    Jason C. Kravitz

    Partner / Leader, Cybersecurity & Privacy

    • Office+1 617.345.1318
    • jkravitz@nixonpeabody.com

    Jenny L. Holmes

    Partner / Deputy Leader, Cybersecurity & Privacy

    • Office+1 585.263.1494
    • jholmes@nixonpeabody.com

    Meredith D. LaMaster

    Associate

    • Office+1 312.977.9257
    • mlamaster@nixonpeabody.com

    Insights And Happenings

    • Alert

      New York State finalizes telemedicine rule for controlled substances

      June 18, 2025
    • Article

      2025 HIPAA enforcement tally rises following three new settlements

      June 12, 2025
    • Article

      Healthcare Cybersecurity Q&A: Ransomware and Data Breaches

      June 3, 2025
    The foregoing has been prepared for the general information of clients and friends of the firm. It is not meant to provide legal advice with respect to any specific matter and should not be acted upon without professional counsel. If you have any questions or require any further information regarding these or other related matters, please contact your regular Nixon Peabody LLP representative. This material may be considered advertising under certain rules of professional conduct.

    Subscribe to stay informed of the latest legal news, alerts, and business trends.Subscribe

    • People
    • Capabilities
    • Insights
    • About
    • Locations
    • Events
    • Careers
    • Alumni
    • Cookie Preferences
    • Privacy Policy
    • Terms of Use
    • Accessibility Statement
    • Statement of Client Rights
    • Purchase Order Terms & Conditions
    • Nixon Peabody International LLC
    • PAL
    © 2025 Nixon Peabody. All rights reserved