Ransomware attacks continue to extract payments from organizations at a rate that should alarm healthcare compliance officers: nearly half of companies hit by ransomware in 2025 paid the demanded ransom, according to research from cybersecurity group Sophos, while median demand figures trended upward. At the same time, a growing number of governments are moving to ban such payments outright — a policy shift that would force healthcare entities to absorb operational disruptions rather than buy their way out.
The payment calculus is shifting
For years, the decision to pay a ransom has been framed as a business continuity calculation: weigh the ransom against the cost of extended downtime, recovery, and regulatory exposure. That math has become less stable on every dimension.
Median ransom demands have risen, meaning the financial shock of paying is larger than it was even two years ago. At the same time, security researchers and law enforcement agencies have consistently documented that payment does not guarantee data recovery or prevent a second attack — and in healthcare, where patient records and clinical systems are involved, the downstream regulatory consequences of a breach do not disappear because a ransom was paid.
The Department of Health and Human Services and the Office for Civil Rights treat ransomware incidents as presumptive HIPAA breaches. Payment transfers funds to threat actors but does not resolve the covered entity's notification obligations or protect it from an OCR investigation.
Payment bans are becoming a policy lever
The United Kingdom has moved toward restricting ransom payments in critical sectors, and similar conversations are advancing in other jurisdictions. The underlying theory is that payment bans reduce the financial incentive for ransomware operators — if major markets stop paying, the economics of the attack model weaken.
For US healthcare organizations, no federal payment ban currently exists, but the direction of international policy matters for several reasons. US-based health systems with international operations or vendor relationships may face legal exposure in jurisdictions that prohibit payment. And domestic proposals for payment restrictions surface periodically in congressional discussions, making the regulatory environment less predictable than it appeared three years ago.
Healthcare attorneys and compliance teams should be tracking these developments now, before a payment decision needs to be made under operational pressure.
What independent practices should check
Healthcare practices of any size can find themselves in a ransomware scenario, and the decision framework needs to exist before an attack, not during one.
- Incident response planning. A documented response plan that includes a legal escalation path, a designated decision-maker for ransom questions, and pre-established contact with law enforcement — specifically the FBI's Internet Crime Complaint Center — significantly shortens the time-to-decision under pressure.
- Backup integrity. The practical alternative to payment is restoration from backup. Practices that cannot reliably restore clinical systems from an isolated, tested backup have fewer real options and face greater pressure to pay. Backup architecture and recovery time objectives should be verified on a scheduled basis, not assumed.
- Cyber insurance review. Many cyber insurance policies include coverage for ransom payments, but policy language varies considerably on conditions, sublimits, and exclusions for state-sponsored actors. A policy review before an incident is the only way to understand actual coverage.
- Breach notification readiness. Because OCR treats ransomware as a presumptive breach, notification timelines begin at the point of discovery. Practices should confirm they understand the 60-day clock and have a notification workflow ready to activate.
What this signals for the next 12 months
The Sophos findings, combined with the movement toward payment restrictions in allied countries, suggest that the ransomware threat environment for healthcare will become simultaneously more expensive and more legally constrained. Threat actors who perceive shrinking payment rates typically respond by intensifying pressure tactics — publishing stolen data, contacting patients directly, or accelerating the speed of encryption to reduce recovery options.
Healthcare organizations that treat ransomware preparedness as a once-a-year tabletop exercise rather than an ongoing operational discipline will find the gap between their capabilities and attacker sophistication widening. The policy trend toward payment bans makes that gap more consequential, not less, because it removes the option that many organizations have treated as a fallback.