Nearly half of organizations hit by ransomware end up paying their attackers, according to 2025 research from cybersecurity group Sophos — and the median ransom demand continues to climb. For healthcare organizations, which remain among the most targeted sectors, the decision to pay or refuse has never carried higher financial and regulatory stakes, particularly as governments move to remove payment as a legal option entirely.
The payment calculus is shifting
The Sophos figures reflect a persistent pattern: organizations often conclude that paying is cheaper than the alternative. Downtime costs, patient care disruption, recovery labor, and reputational damage can dwarf the ransom itself — a calculation that has historically made healthcare providers especially vulnerable to the pressure to pay quickly.
What the aggregate data also shows is that payment does not reliably resolve the crisis. Threat actors increasingly exfiltrate data before encrypting systems, meaning a paid ransom releases locked systems but does nothing to prevent a subsequent extortion demand or a data sale on criminal markets. Healthcare records command a premium on those markets precisely because they combine clinical, financial, and identity information in a single record.
Regulators are moving to close the payment option
In the UK, proposed legislation would ban ransomware payments by organizations in critical sectors — a category that includes healthcare — and require victims to report attacks to government authorities before any payment decision is made. Several other jurisdictions are examining similar frameworks.
For US healthcare organizations, no federal payment ban is currently in force, but the regulatory environment around incident disclosure is tightening. HHS guidance and pending updates to the HIPAA Security Rule both push toward faster breach notification and more detailed documentation of the decisions made during an incident. If payment bans eventually reach the US — either federally or through state-level action — organizations that have never practiced a no-pay scenario will face a sharp transition.
What the payment debate reveals about preparation gaps
The high payment rate is itself a signal about the state of recovery readiness across the industry. Organizations that maintain tested, isolated backups and documented recovery procedures have a credible path to restoration without paying. Those that do not face a binary choice between extended downtime and writing a check to an adversary.
The structural gap the Sophos data exposes is not primarily a technical one. It is an operational one: many organizations have never stress-tested whether their backup systems actually restore at the speed clinical operations require. Tabletop exercises that walk through a full encryption scenario — including the moment when leadership asks how long recovery will take without paying — remain infrequent in smaller and mid-sized practices.
What this signals about the next 12 months
Pressure from multiple directions is converging. Ransom demands are rising. Payment prohibition legislation is advancing in at least one major jurisdiction. US regulators are demanding more disclosure detail and tighter timelines. And threat actors are refining double-extortion techniques that make payment an unreliable remedy even when organizations choose it.
Independent practices and smaller health systems that have deferred investment in recovery infrastructure face the greatest exposure as this environment hardens. The decision about whether to pay, if ransomware strikes, will be made under time pressure and clinical duress — conditions that favor attackers unless the organization has already resolved the question through planning and tested procedures before an incident occurs.