Paying a ransomware demand does not end the threat — it may accelerate the next one. Survey data published this week shows that nearly a quarter of organizations that paid a ransom were subsequently extorted a second time, a pattern that regulators and law enforcement have warned about for years but that now has concrete figures attached to it. For healthcare practices, where the pressure to restore system access quickly is acute and the sensitivity of patient data creates additional leverage, the finding carries direct operational weight.
The numbers behind the pattern
Proofpoint's survey data, covering affected organizations in the United Kingdom, found that 58 percent of organizations hit by ransomware paid the initial demand. Of those that paid, 22 percent were approached for a second payment. The mechanism is straightforward: threat actors who receive payment confirm that the target is both willing and able to pay, and they retain copies of exfiltrated data regardless of whether they provide a working decryptor.
Healthcare organizations are structurally attractive for repeat extortion. Encrypted clinical systems create immediate patient-safety pressure, compressed negotiating timelines, and a lower threshold for paying than most other sectors. Attackers know this, and the extortion sequence — initial encryption demand, followed by a separate threat to publish or sell patient records — has become a documented double-extortion template used against hospitals, physician groups, and specialty practices.
Why payment accelerates future targeting
When a ransom is paid, several things happen simultaneously. The victimized organization is logged as a confirmed payer in whatever communication infrastructure the threat group uses to coordinate. That record persists beyond the immediate incident, and it circulates among affiliated actors, particularly in ransomware-as-a-service models where initial access brokers and encryption operators are separate parties.
Threat actors who retain a copy of exfiltrated data before providing a decryptor also hold an ongoing instrument of leverage. Months after the original incident closes internally, the same data can resurface as the basis for a new payment demand — either from the original group or from a secondary actor who purchased the data. Healthcare records, which carry individually identifiable information subject to HIPAA notification requirements, give attackers a credible threat: publish or sell the data unless paid again.
What this means for incident response planning
The survey data reinforces a position that HHS and law enforcement have held consistently: payment should not be treated as a resolution strategy. For independent practices and small health systems, the practical implication is that incident response planning needs to treat a ransomware event as a multi-phase threat, not a one-time crisis.
Several planning elements become more important given the repeat-extortion pattern:
- Offline, verified backups. Restoring systems from clean backups removes the operational pressure that makes payment feel necessary. Backups that are network-accessible or unverified can be encrypted alongside production systems.
- Data inventory and exfiltration detection. If a practice cannot determine what data was taken, it cannot assess whether a second extortion threat is credible or bluffing. Network logging and data-loss-detection controls support that determination.
- Legal and regulatory coordination before an incident. HIPAA breach notification timelines run from the point of discovery. Engaging legal counsel and understanding notification obligations in advance reduces the chance that payment pressure overrides compliance obligations.
- Cyber insurance review. Some policies restrict or exclude coverage for repeat events or payments made without insurer approval. Practices should confirm what their policy requires before an incident, not during one.
What the next 12 months are likely to show
The ransomware-as-a-service ecosystem has continued to professionalize, and the double-extortion model is now the default rather than an exception. Healthcare remains the most frequently targeted sector in published breach data, and the combination of operational urgency, sensitive data, and historically underfunded security programs keeps it at the top of target lists.
Regulatory pressure is also increasing. OCR's proposed updates to the HIPAA Security Rule place explicit emphasis on incident response planning, backup integrity, and access controls — requirements that map directly to the controls that reduce both the likelihood of a successful ransomware deployment and the leverage available for repeat extortion. Practices that treat security investment as a one-time checklist rather than an ongoing operational discipline will remain the path of least resistance for threat actors looking for a second payment.