Paying a ransomware demand does not buy an exit. Survey data published by Proofpoint and reported by DataBreaches.net shows that 22 percent of UK organizations that paid a ransom were subsequently extorted a second time by the same actors. The figures come from a broader dataset in which 58 percent of affected UK organizations paid at least one demand — meaning a meaningful fraction of those who complied were immediately repositioned as repeat targets. The pattern carries direct relevance for US healthcare, where ransom payments have become a visible and contested response strategy following a series of large-scale attacks on health systems and clearinghouses.

Why payment invites a second demand

The structural logic is straightforward: an organization that pays a ransom has demonstrated both the willingness and the financial means to do so. Ransomware crews, many of which operate as affiliate networks with detailed victim tracking, treat a completed payment as a data point about that organization's decision-making threshold. The victim's internal systems may still carry the access credentials or unpatched vulnerabilities that enabled the original intrusion, giving threat actors a ready path back in — or leverage to threaten a secondary data leak even without re-entering the network.

Healthcare organizations are particularly exposed to this dynamic. The sensitivity of protected health information creates compounding extortion pressure: beyond recovering encrypted systems, covered entities face the risk that stolen records will be published, sold, or used to file fraudulent HIPAA complaints unless further payment is made. That threat can persist long after decryption keys are delivered and systems are restored.

What the data changes about the payment calculus

Healthcare compliance officers and practice administrators who treat ransom payment as a risk-transfer mechanism — a way to move an incident from active crisis to closed file — should recalibrate against these numbers. A 22 percent re-extortion rate means roughly one in five paying victims reenter the incident cycle. Costs associated with a second demand, a second negotiation, and potential regulatory disclosure of a second event can exceed the original payment and response costs combined.

Authorities in the US and UK have consistently advised against paying ransoms for reasons that include this re-victimization risk. The HHS Office for Civil Rights has not prohibited payment, but its breach notification requirements apply regardless of whether a ransom is paid — meaning payment does not reduce regulatory exposure and may signal to threat actors that the organization treats compliance obligations as manageable costs.

Where this lands for independent practices

For independent and smaller healthcare practices, the operational takeaway centers on incident response planning done before an attack arrives, not during one.

The Proofpoint data is drawn from UK organizations, but the ransomware affiliate groups responsible for the majority of healthcare attacks operate across geographies without meaningful distinction. Any practice that has paid a ransom or experienced a network intrusion without full forensic remediation should treat re-extortion as a live risk, not a theoretical one.