"Change Healthcare, a major U.S. healthcare claims processor, paid multiple ransoms"
It should be illegal for a company to pay a ransom as it just incentivizes more attacks on other companies. Companies should also be required to report to the FBI if they are being extorted over a certain dollar amount so that the government can track this activity. Companies paying millions of dollars to a contractor to "solve" the problem (by paying the ransom) must also be banned. If the company doesn't comply with these laws, then the people (CEO, officers, IT, accountant, etc.) responsible at the company should be subject to jail. Fines are not sufficient since it just the companies money that is being lost.
Once companies are no longer able to pay the ransoms the incentive will go away and this will stop.