Ransomware remains one of the most disruptive threats facing healthcare operations, and new data from cybersecurity group Sophos shows that roughly half of targeted organizations ultimately pay a ransom — even as median demand amounts continue to rise. The findings arrive as several governments, including the United Kingdom, are actively considering or moving toward outright bans on ransom payments, a policy shift that would force healthcare organizations to revisit the assumptions that often drive their incident-response calculus.

The payment decision under pressure

The Sophos research, drawn from 2025 survey data, places the payment rate at just under 50 percent globally. That figure reflects a persistent dynamic: when systems go down, clinical operations can stall, and the perceived speed of a paid recovery often outweighs the financial cost in the moment. In healthcare, where downtime carries patient-safety implications, that pressure is especially acute.

At the same time, paying does not guarantee a clean outcome. Encrypted data restored through attacker-supplied decryption tools frequently requires additional remediation, and a portion of victims who pay still face data publication by threat actors. The median ransom amount is increasing year over year, meaning the cost-benefit analysis that once made payment seem pragmatic is shifting.

What a payment ban would mean for healthcare

The UK is among the jurisdictions examining legislation that would prohibit ransomware payments. Similar proposals have circulated at the state and federal level in the United States. A ban would close the financial circuit that sustains ransomware-as-a-service operations, but it also removes an option that some covered entities and business associates currently treat as a continuity tool.

For independent practices and small health systems, the practical implications are significant:

Where independent practices should focus preparation

The trajectory of the ransomware landscape — higher demands, more frequent attacks, and probable payment restrictions — points toward several operational priorities that do not depend on a payment option being available.

Offline or immutable backup systems that cannot be encrypted by an attacker who has reached the primary network are the most direct control. Equally important is the ability to actually execute a restoration under incident conditions, which requires documented procedures and periodic drills rather than assumed capability.

Incident response plans should be reviewed against a scenario in which payment is not an available option, testing whether clinical operations can continue in a degraded state and how long the organization can sustain manual workflows. Many practices have not stress-tested that question explicitly.

Segmenting clinical networks — keeping patient-record systems, medical devices, and administrative systems on separated network zones — limits how far an attacker can move after initial access, reducing the scope of an encryption event and potentially keeping some systems operational during a response.

The Sophos data and the legislative direction in multiple jurisdictions signal that the decision to pay or not will increasingly be made by regulators rather than by individual organizations. Practices that build recovery capability now will have more options regardless of which direction policy moves.