Ransomware attacks continue to extract payments from organizations at a rate that should alarm healthcare compliance officers: nearly half of companies hit by ransomware in 2025 paid the demanded ransom, according to research from cybersecurity group Sophos, while median demand figures trended upward. At the same time, a growing number of governments are moving to ban such payments outright — a policy shift that would force healthcare entities to absorb operational disruptions rather than buy their way out.

The payment calculus is shifting

For years, the decision to pay a ransom has been framed as a business continuity calculation: weigh the ransom against the cost of extended downtime, recovery, and regulatory exposure. That math has become less stable on every dimension.

Median ransom demands have risen, meaning the financial shock of paying is larger than it was even two years ago. At the same time, security researchers and law enforcement agencies have consistently documented that payment does not guarantee data recovery or prevent a second attack — and in healthcare, where patient records and clinical systems are involved, the downstream regulatory consequences of a breach do not disappear because a ransom was paid.

The Department of Health and Human Services and the Office for Civil Rights treat ransomware incidents as presumptive HIPAA breaches. Payment transfers funds to threat actors but does not resolve the covered entity's notification obligations or protect it from an OCR investigation.

Payment bans are becoming a policy lever

The United Kingdom has moved toward restricting ransom payments in critical sectors, and similar conversations are advancing in other jurisdictions. The underlying theory is that payment bans reduce the financial incentive for ransomware operators — if major markets stop paying, the economics of the attack model weaken.

For US healthcare organizations, no federal payment ban currently exists, but the direction of international policy matters for several reasons. US-based health systems with international operations or vendor relationships may face legal exposure in jurisdictions that prohibit payment. And domestic proposals for payment restrictions surface periodically in congressional discussions, making the regulatory environment less predictable than it appeared three years ago.

Healthcare attorneys and compliance teams should be tracking these developments now, before a payment decision needs to be made under operational pressure.

What independent practices should check

Healthcare practices of any size can find themselves in a ransomware scenario, and the decision framework needs to exist before an attack, not during one.

What this signals for the next 12 months

The Sophos findings, combined with the movement toward payment restrictions in allied countries, suggest that the ransomware threat environment for healthcare will become simultaneously more expensive and more legally constrained. Threat actors who perceive shrinking payment rates typically respond by intensifying pressure tactics — publishing stolen data, contacting patients directly, or accelerating the speed of encryption to reduce recovery options.

Healthcare organizations that treat ransomware preparedness as a once-a-year tabletop exercise rather than an ongoing operational discipline will find the gap between their capabilities and attacker sophistication widening. The policy trend toward payment bans makes that gap more consequential, not less, because it removes the option that many organizations have treated as a fallback.