Ransomware victims paid up in nearly half of all attacks last year, according to 2025 research from Sophos, and the median amount demanded continues to climb. The finding arrives as governments in the United Kingdom and several other jurisdictions are actively considering — or moving toward — outright bans on ransom payments, a policy shift that would fundamentally alter how healthcare organizations plan for and respond to encryption attacks.
The payment calculus is getting harder
For years, paying a ransom has occupied a gray zone: condemned in principle, practiced in reality. The Sophos figures reinforce how durable that gap is. When systems are locked and patient data is at risk, the operational pressure to pay is significant, particularly for smaller facilities with limited backup infrastructure or no tested recovery plan.
The calculation is further complicated by the fact that payment does not guarantee recovery. Threat actors sometimes deliver broken decryptors, retain copies of exfiltrated data regardless, or return months later with a second extortion demand. Healthcare organizations that paid once have ended up paying again — or disclosing a breach anyway when stolen records surfaced on leak sites.
Legislation could change the math entirely
The UK's proposed payment ban represents the most consequential policy development in the ransomware space in years. If enacted, it would make paying a ransom legally prohibited rather than merely discouraged — removing the option that roughly half of current victims are taking. Australia and Singapore have discussed similar restrictions. In the United States, no federal ban has passed, but the conversation is moving; bills have been introduced, and HHS has separately signaled interest in tying ransom-payment disclosure to breach-reporting timelines.
For US healthcare practices, the near-term relevance is indirect but real. Vendors, clearinghouses, and business associates that operate internationally would be subject to the laws of each jurisdiction in which they operate. A payment ban affecting a US healthcare organization's UK-based billing partner, for example, could ripple into domestic incident response plans in ways that current contracts and business associate agreements do not anticipate.
What independent practices should examine now
The Sophos data and the legislative trend together point toward the same operational gap: organizations that have not pressure-tested their recovery capabilities before an attack are the ones most likely to face an impossible choice when one arrives. Several areas warrant attention.
- Backup architecture and isolation. Encrypted or offline backup copies that are logically separated from production systems remain the most reliable path to recovery without payment. Many practices have backups in name only — copies that are reachable by the same credentials an attacker already controls.
- Incident response planning that assumes no payment. Tabletop exercises and response plans built around the assumption that payment is available as a fallback produce different decisions than plans built around the assumption that payment is prohibited or impractical. Running both scenarios produces a more honest assessment of actual recovery time.
- Contract and BAA review for international counterparties. If any third-party vendor or associate operates under UK, Australian, or Singaporean law, existing agreements should be reviewed for clauses that address payment prohibition scenarios and notification obligations when a counterparty is the victim.
- Ransom-payment disclosure obligations. HHS has not finalized a specific ransom-payment reporting requirement, but OCR has made clear that ransom payments connected to a breach of protected health information are reportable events. Organizations should not treat payment and breach reporting as separate decisions.
What this signals about the next 12 months
The ransomware economics described in the Sophos research — higher demands, durable payment rates — suggest threat actors have not been deterred by existing enforcement or disclosure requirements. Legislative payment bans, if they spread to additional jurisdictions or reach the US federal level, would represent a structural intervention rather than an incremental one. Healthcare organizations that wait for regulatory certainty before hardening their recovery capabilities are accepting a period of elevated exposure during which their incident response options may narrow considerably.