Ransomware victims are caught between rising demands and the prospect of legal prohibition on paying them. Sophos research from 2025 found that roughly 46 percent of targeted organizations ultimately paid a ransom — and median demand amounts are climbing. For healthcare, where operational downtime can directly affect patient safety, that pressure is more acute than in most industries.
The payment calculus is getting harder
Organizations that pay are betting that restoring encrypted systems quickly costs less than the operational and reputational damage of a prolonged outage. That math has historically favored payment in healthcare settings, where a locked EHR or imaging system is not merely a business inconvenience but a clinical one.
The Sophos data suggests the bet does not always pay off. Paying does not guarantee full data recovery, and it demonstrably funds further criminal infrastructure. A growing body of incident-response reporting shows that organizations which pay once become statistically more likely to be targeted again — attackers share intelligence on which sectors reliably produce revenue.
Governments are moving to close the payment option
The UK is among jurisdictions actively considering or advancing legislation that would ban ransom payments, or at minimum require mandatory disclosure before any payment is made. The logic is that payment bans starve the ransomware economy. The practical concern is that organizations facing a genuine crisis — a hospital diverting ambulances, a clinic unable to access medication records — may have no viable alternative if restoration from backup is slow or incomplete.
Several US legislators and state attorneys general have floated similar proposals in recent cycles. No federal payment ban is currently law in the United States, but mandatory reporting requirements under the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) are moving toward implementation, and healthcare is explicitly named as critical infrastructure. Incident reporting timelines under CIRCIA, combined with existing HIPAA breach notification obligations, mean the window for making a quiet payment decision is already narrowing.
What the payment debate signals for preparedness
Whether or not a jurisdiction bans payments, the policy direction is clear: regulators are betting that organizations with genuinely resilient backup and recovery capabilities will not need to pay. That premise puts the burden back on the organization.
Independent practices and small health systems are the segment least likely to have tested their recovery time objectives against a realistic ransomware scenario. The gap between having a backup and being able to restore clinical operations from that backup within 24 to 72 hours is where most organizations discover they are less prepared than they believed.
- Offline or immutable backup copies are the operational requirement regulators and incident responders consistently point to — backups connected to the same network segment as production systems are routinely encrypted alongside the primary data.
- Documented recovery procedures that have been rehearsed, not just written, determine whether staff can actually execute restoration under pressure.
- Cyber incident response retainers arranged before an event, not during one, affect both speed of response and negotiating position if payment becomes unavoidable.
Where policy is likely to land next
The UK's proposed payment restrictions are being watched closely by US federal health agencies. If a major jurisdiction demonstrates that a payment ban does not produce a wave of catastrophic healthcare outages — because operators have improved their resilience in anticipation — American regulators will have political cover to advance similar measures.
Healthcare organizations should treat the next 12 to 24 months as a window to close the gap between current recovery capabilities and the standard that a payment-ban environment would demand. Waiting until legislation is enacted leaves almost no runway for the infrastructure and process changes required.