4 ms·
Demanding a ransom is criminal. Paying a ransom should be a business decision. There are already many business constructs such as key man insurance, cybercrime
by vivegi 3y ago
Demanding a ransom is criminal.
Paying a ransom should be a business decision. There are already many business constructs such as key man insurance, cybercrime insurance etc., that are b2b contractual agreements to protect against such losses. How does one reconcile the existence of such agreements while (potentially) outlawing this?
It is horrifying to be on the receiving end of a business' data security and confidentiality mess.
IANAL, but the patient should have sued under PHI disclosure by the covered entity to an unauthorized party without patient consent. This in addition to the federal HIPAA violations and state civil penalties and other legal remedies the patient is entitled to. [1]
[1]: https://www.hipaajournal.com/what-is-the-maximum-penalty-for-violating-hipaa/ https://www.hipaajournal.com/what-is-the-maximum-penalty-for...
- lostlogin 3y agoSo once you have paid the hackers, what’s to stop them doing it again, or demanding a second ransom?
- vivegi 3y agoSo, you would prohibit constructs like key person insurance [1] or cyber insurance [2] that have clauses for settling ransom payment claims for kidnaps or extortion after a data breach? These already exist. [1]: https://www.travelers.co.uk/iw-documents/uk/documents/kidnap-and-ransom-coverage-examples-0814.pdf https://www.travelers.co.uk/iw-documents/uk/documents/kidnap... [2]: https://www.thehartford.com/cyber-insurance https://www.thehartford.com/cyber-insurance