People should not pay the ransom, it would only incentive such types of attacks to happen again. If they follow basic guidelines of how to use the computer, they should have everything backup'ed somewhere where malwares can't reach.
Also there is no guarantee that they will in fact have their archives back, some ransomwares don't decrypt them even if the ransom is paid
I presume that if it's a hospital that ransom is a necessary expense to save lives and access patient data. On principle it makes sense but it is not the best choice in practice for some situations.
http://www.telegraph.co.uk/news/2017/05/12/nhs-hit-major-cyber-attack-hackers-demanding-ransom/Operations and appointments were cancelled and ambulances diverted as up to 40 hospital trusts became infected by a “ransomware” attack demanding payment to regain access to vital medical records.
Doctors warned that the infiltration – the largest cyber attack in NHS history – could cost lives.
In the UK the only affected organisation appeared to be the NHS.
Patients awaiting heart surgery were among those who had operations cancelled, with doctors telling how staff were frantically ordering computers to be shut down. New parents were left stuck on wards with their newborns as administrative systems failed.
Doctors at dozens of trusts resorted to pen and paper, with no access to medical records that could alert them to medical histories or allergies. Handwritten signs in the entrance of the Royal London’s A&E read: “The emergency department has no IT facilities, there are significant delays occurring.”
NHS trusts are supposed to regularly back up their files.
But yesterday doctors and nurses were left treating patients without any access to their medical histories, with lost access to X-rays, blood tests and details such as allergies to medication.
It raises the possibility that recent changes to medical records – such as a cancer diagnosis, or the results of a blood test – could be lost, if hackers delete the files.
---
So when it comes to a few hundred dollars or a persons life the ransom will be paid even if their is a risk of no decryption.