Ransomware victims paid up in nearly half of all attacks last year, according to 2025 research from Sophos, and the median amount demanded continues to climb. The finding arrives as governments in the United Kingdom and several other jurisdictions are actively considering — or moving toward — outright bans on ransom payments, a policy shift that would fundamentally alter how healthcare organizations plan for and respond to encryption attacks.

The payment calculus is getting harder

For years, paying a ransom has occupied a gray zone: condemned in principle, practiced in reality. The Sophos figures reinforce how durable that gap is. When systems are locked and patient data is at risk, the operational pressure to pay is significant, particularly for smaller facilities with limited backup infrastructure or no tested recovery plan.

The calculation is further complicated by the fact that payment does not guarantee recovery. Threat actors sometimes deliver broken decryptors, retain copies of exfiltrated data regardless, or return months later with a second extortion demand. Healthcare organizations that paid once have ended up paying again — or disclosing a breach anyway when stolen records surfaced on leak sites.

Legislation could change the math entirely

The UK's proposed payment ban represents the most consequential policy development in the ransomware space in years. If enacted, it would make paying a ransom legally prohibited rather than merely discouraged — removing the option that roughly half of current victims are taking. Australia and Singapore have discussed similar restrictions. In the United States, no federal ban has passed, but the conversation is moving; bills have been introduced, and HHS has separately signaled interest in tying ransom-payment disclosure to breach-reporting timelines.

For US healthcare practices, the near-term relevance is indirect but real. Vendors, clearinghouses, and business associates that operate internationally would be subject to the laws of each jurisdiction in which they operate. A payment ban affecting a US healthcare organization's UK-based billing partner, for example, could ripple into domestic incident response plans in ways that current contracts and business associate agreements do not anticipate.

What independent practices should examine now

The Sophos data and the legislative trend together point toward the same operational gap: organizations that have not pressure-tested their recovery capabilities before an attack are the ones most likely to face an impossible choice when one arrives. Several areas warrant attention.

What this signals about the next 12 months

The ransomware economics described in the Sophos research — higher demands, durable payment rates — suggest threat actors have not been deterred by existing enforcement or disclosure requirements. Legislative payment bans, if they spread to additional jurisdictions or reach the US federal level, would represent a structural intervention rather than an incremental one. Healthcare organizations that wait for regulatory certainty before hardening their recovery capabilities are accepting a period of elevated exposure during which their incident response options may narrow considerably.