Ransomware victims are paying more often and in larger amounts, even as governments in multiple countries consider banning the payments entirely. Research from cybersecurity firm Sophos published in 2025 found that roughly 49 percent of targeted organizations ultimately paid their attackers, while median ransom demands continued to climb. The tension between immediate operational recovery and the long-term consequences of funding criminal networks is sharpening — and healthcare organizations, which face acute pressure to restore clinical systems quickly, sit at the center of that tension.
The payment calculus
The decision to pay or refuse a ransom has never been straightforward, but the variables have grown more complex. Organizations that pay do not guarantee data recovery: Sophos data indicates that a significant share of victims who paid still experienced data loss or extended downtime. Meanwhile, attackers have refined double-extortion tactics — encrypting systems and separately threatening to publish sensitive data — which removes the clean resolution that a decryption key once implied.
For healthcare entities, the stakes extend beyond financial loss. Prolonged system outages delay care, divert patients, and in documented cases have been associated with adverse clinical outcomes. That operational reality creates pressure to restore systems fast, often making the payment option feel like the only lever available when backups are absent, untested, or themselves encrypted.
Government intervention shifts the landscape
The UK is among the jurisdictions actively examining a legislative ban on ransomware payments, a policy approach that has gained traction in several other countries. Proponents argue that removing the economic incentive is the only structural way to reduce attack volume; opponents counter that banning payment without guaranteeing recovery capacity effectively leaves victims — including hospitals — with no recourse.
For US healthcare organizations, no federal ban is currently in effect, but the regulatory environment is moving. HHS has signaled increased scrutiny of cyber incident response, and the proposed updates to the HIPAA Security Rule would require documented, tested contingency plans specifically designed to maintain clinical operations during a ransomware event. Whether or not a payment ban reaches the US, regulators are signaling that paying an attacker will not shield a covered entity from enforcement if its baseline controls were inadequate before the attack.
What independent practices should check
The Sophos data and the emerging legislative debate point to several concrete preparation gaps that small and mid-sized healthcare organizations should audit now.
- Backup integrity and isolation. Backups that are network-connected at the time of an attack are frequently encrypted alongside production systems. Offline or immutable backup copies, tested regularly for restoration speed, remain the single most reliable alternative to paying.
- Incident response planning. A written plan that has never been rehearsed offers limited operational value under attack conditions. Tabletop exercises that simulate a system-down scenario — including who authorizes a ransom decision — reduce the time-pressure that drives hasty payment choices.
- Cyber insurance policy terms. Many policies contain clauses that affect coverage when a payment is made, when law enforcement is not notified promptly, or when the attacker appears on a sanctions list. Reviewing policy language before an incident is the only way to understand what coverage will actually apply.
- Legal and regulatory notification timelines. A ransomware event that affects the availability of protected health information is a reportable breach under HIPAA in most circumstances. The 60-day notification clock begins at discovery, not at resolution, and paying a ransom does not reset or suspend it.
What this signals about the next 12 months
The combination of rising demand amounts, higher payment rates, and active legislative debate in allied jurisdictions suggests that the rules governing ransomware response are entering a period of change. US policymakers have watched UK and Australian proposals closely, and pressure on Congress to address payment policy has grown since the high-profile disruptions to hospital networks in 2023 and 2024. Healthcare organizations that treat their current response plans as settled should expect that the compliance and legal framework around ransomware will look materially different by mid-2027 — and that plans built on the assumption that payment is always an available option may need to be revised.