Ransomware victims are paying more often and in larger amounts than a year ago, while a growing number of governments are considering or enacting bans on those payments — a combination that puts healthcare organizations, already among the most targeted sectors, in an increasingly difficult position. Research published by Sophos in 2025 found that roughly 47 percent of attacked organizations ultimately paid a ransom, and the median demand continues to rise. For independent practices and health systems operating under HIPAA, the legal and operational stakes on both sides of that decision are sharpening.

The payment calculus is getting harder

The Sophos data reflects a well-documented pattern: attackers have learned to calibrate demands against what victims can realistically pay, and healthcare entities — whose operational continuity is tied directly to patient safety — have historically been seen as higher-probability payers. That perception drives targeting, and targeted attacks on health systems have grown more technically sophisticated, often combining data exfiltration with encryption so that victims face both a ransom demand and a breach-notification obligation regardless of whether they pay.

Paying does not resolve the HIPAA problem. If protected health information was accessed or exfiltrated before encryption, a reportable breach has likely already occurred. Payment may restore system access but does not undo the disclosure, and OCR's breach-notification rules are indifferent to whether a ransom was paid.

Governments are moving to ban payments

The UK is among jurisdictions actively examining mandatory reporting requirements and potential payment prohibitions. Proposed frameworks would require victims to notify authorities before any payment is made and, in some versions, would bar payments to sanctioned threat actors entirely. Australia has already enacted mandatory reporting for ransomware payments above a threshold. In the United States, federal legislation along similar lines has been introduced in multiple congressional sessions, though no payment ban has yet cleared Congress.

The practical effect of a payment ban — even a partial one tied to sanctions compliance — is that organizations lose what many currently treat as a last-resort option. For healthcare providers, that shifts the entire risk calculus toward prevention and recovery capability rather than crisis negotiation. OFAC guidance already prohibits payments to sanctioned entities; organizations that pay without first screening the threat actor against the SDN list face potential civil penalties independent of any new legislation.

What the trend signals for practice-level preparedness

The combination of rising demand amounts, higher payment rates, and tightening legal constraints points toward several operational realities for smaller healthcare organizations:

Where independent practices are most exposed

Smaller practices typically lack dedicated security staff and may not have tested their backups under realistic failure conditions. They are also less likely to have retained outside counsel or a breach-coach relationship before an incident occurs. When a ransomware event hits, those gaps compound: decisions get made under time pressure without the institutional knowledge that larger systems can draw on.

The trajectory of both the threat environment and the regulatory response suggests that gap is becoming more costly. Payment bans, if enacted in the US, would remove an option that some practices currently rely on as a de facto recovery strategy. Building the operational capability to survive without paying — through tested backups, documented response procedures, and pre-established legal relationships — is the only durable answer to a policy environment that may eventually foreclose the payment route entirely.