Ransomware attacks continue to extract payments from roughly half of all victim organizations, according to 2025 research from Sophos cited in a Financial Times analysis, while the median ransom demand keeps climbing. At the same time, several governments are weighing or advancing legislation that would prohibit payments entirely — a shift that would force healthcare organizations to confront a threat they have long managed, in part, by treating payment as a last-resort option.

The payment calculus healthcare has relied on

For years, many healthcare organizations have quietly treated ransom payment as a contingency within their incident response planning. When clinical operations halt, patient safety considerations accelerate the pressure to restore systems quickly, and paying — however reluctantly — can appear faster than restoring from backup. The Sophos figures suggest this calculation remains common across industries: approximately 48 percent of victim organizations paid in the period studied, and median demand amounts continued to rise year over year.

Healthcare sits at a particular disadvantage in this dynamic. Disrupted access to electronic health records, pharmacy systems, and diagnostic equipment creates patient-facing harm that most other industries do not face. That operational urgency has made the sector a preferred target for ransomware groups, which understand that the cost of downtime is measurably higher for a hospital or clinic than for a manufacturer or retailer.

What payment bans would change

The UK has proposed legislation that would ban ransom payments by public-sector bodies and critical national infrastructure operators — a category that would include NHS trusts and likely extend pressure to private healthcare providers as well. Australia has considered similar measures. In the United States, no federal payment ban is currently law, but the debate is active, and several policy proposals have circulated in Congress and at CISA.

A payment ban would not eliminate ransomware attacks. It would, however, remove the financial option that roughly half of victims currently exercise and shift the entire weight of recovery onto preparedness: backup integrity, system redundancy, incident response capability, and negotiation-free restoration timelines. For independent practices and smaller health systems that have not invested heavily in offline backup architecture or tested recovery procedures, that shift would arrive as a significant gap.

Where this lands for independent practices

The policy trajectory — even if a US ban is years away — gives healthcare compliance and operations leaders a planning signal now. Organizations that treat payment as an implicit fallback should treat that fallback as increasingly unreliable, for regulatory and practical reasons alike.

Several concrete areas deserve attention:

What this signals about the next 12 months

The gap between ransomware group sophistication and healthcare sector preparedness has not closed. Research consistently shows that healthcare remains among the top targeted verticals, that dwell times before encryption are often long enough to compromise backup systems, and that recovery costs — including downtime, remediation, and regulatory response — typically exceed the ransom itself even when payment is made.

A legislative ban on payments, wherever it first takes effect, would validate what incident response specialists have argued for years: payment does not guarantee decryption, does not prevent re-attack, and funds further adversary development. The policy debate is catching up to that operational reality. Healthcare organizations that begin building payment-independent recovery capability now will be better positioned regardless of how the legislative outcome unfolds.