Roughly half of organizations struck by ransomware paid their attackers in 2025, according to research from cybersecurity group Sophos, even as median demand amounts continued to rise. The finding lands at an awkward moment: several governments, including the United Kingdom, are moving toward outright bans on ransom payments, a policy shift that would remove the payment option entirely and force victims to rely solely on recovery capabilities. For healthcare organizations — which remain among the most frequently targeted sectors and face the steepest operational pressure to restore systems quickly — the policy debate has direct practical consequences.
Why healthcare is caught in the middle
Hospitals and medical practices face a calculation that differs from most other industries. Downtime is not merely a financial inconvenience; delayed access to patient records, medication administration systems, and diagnostic equipment can become a patient-safety event. That pressure has historically made healthcare a preferred target precisely because attackers believe organizations will pay rather than endure extended outages.
The Sophos data suggests that belief is still largely correct. When nearly half of all victims pay, attackers have little incentive to reduce demand amounts or shift focus elsewhere. Rising median demands reflect that math directly.
The payment-ban argument and its complications
Proponents of payment bans argue that prohibiting ransom transfers would dry up the economic model underpinning ransomware operations. If no victim can legally pay, the reasoning goes, attack volume should eventually fall. The UK's proposed approach follows similar policy discussions in Australia and, in more limited form, in US federal guidance discouraging payments to sanctioned entities.
The counterargument is stark for healthcare. A ban does not restore encrypted systems — it only removes one recovery pathway. Organizations that have not invested in offline backups, tested restoration procedures, and documented manual downtime workflows would face the full cost of an attack with no payment option available. Critics of payment bans point out that the burden falls heaviest on under-resourced organizations that already lag on preventive controls, a category that describes a significant share of independent practices and rural hospitals.
Regulators and policymakers have not resolved this tension. HHS has not issued formal guidance on payment bans as of mid-2026, though the agency's broader ransomware guidance consistently emphasizes that payment does not guarantee data recovery and does not fulfill HIPAA breach notification obligations.
What the policy shift signals for incident response planning
Whether or not a payment ban reaches US law, the direction of travel in peer jurisdictions suggests that planning around the payment option as a backstop is increasingly risky. Practices and health systems that have treated ransom payment as an implicit last resort need to stress-test what full recovery without payment actually looks like.
Several planning disciplines become more critical under that scenario:
- Backup architecture and testing. Offline or immutable backups that are tested for restoration speed and completeness, not merely existence, are the core of any payment-independent recovery plan.
- Downtime procedures. Documented, practiced manual workflows for medication administration, patient intake, and care coordination reduce the operational pressure that drives hasty payment decisions.
- Cyber insurance clarity. Many policies contain language about insurer approval before payment and about coverage limits tied to payment decisions. Coverage terms should be reviewed before an incident, not during one.
- Breach notification readiness. Paying a ransom does not eliminate HIPAA breach notification obligations if protected health information was accessed or exfiltrated. Organizations sometimes conflate payment with resolution; regulators do not.
The broader trend suggests that the window for treating ransom payment as a viable contingency is narrowing, regardless of how specific legislative efforts resolve. Healthcare organizations that build recovery plans assuming payment is unavailable will be better positioned under any regulatory outcome.