Ransomware victims are paying at rates that remain stubbornly high even as governments in several countries move to make those payments illegal. Research published by Sophos in 2025 found that nearly half of organizations hit by ransomware ultimately paid a ransom to recover data or restore systems, and the median demand continues to rise. For healthcare — a sector that faces outsized pressure to restore operations quickly because patient safety hangs on system availability — that statistic carries particular weight.
The payment calculus
The decision whether to pay is rarely straightforward. Organizations weigh the cost of the ransom itself against the cost of extended downtime, data reconstruction, regulatory penalties, and reputational harm. In healthcare, downtime translates directly into deferred care, diverted ambulances, and manual workarounds that introduce clinical risk.
Several factors complicate the math further:
- No recovery guarantee. Paying a ransom does not guarantee that decryption keys will work or that stolen data will not be published anyway. A meaningful share of paying organizations report they still could not restore all affected systems from attacker-provided tools.
- Rising demands. Median ransom demands have climbed year over year, meaning organizations that absorbed a payment once face higher exposure if they are hit again — and repeat targeting of known payers is documented.
- Sanctions exposure. US Treasury's Office of Foreign Assets Control has previously warned that payments to sanctioned groups may themselves violate federal law, adding legal risk on top of financial risk.
Governments are tightening the rules
The UK is among the jurisdictions actively exploring or advancing bans on ransom payments, at least for public-sector entities and critical infrastructure. The logic is straightforward: payments fund further attacks. If enough high-value targets stop paying, the economic model for ransomware groups weakens.
For US healthcare organizations, no federal payment ban is currently in force, but the regulatory direction is worth tracking. HHS has signaled repeatedly that it views inadequate security controls — rather than payment decisions — as the primary compliance failure in ransomware incidents. The revised HIPAA Security Rule proposed in early 2025 would, if finalized, require more prescriptive technical controls including network segmentation, encryption at rest, and regular tested recovery procedures. Those controls are precisely the ones that reduce the pressure to pay in the first place.
What the payment rate reveals about preparedness
A near-50 percent payment rate across industries suggests that a large share of organizations still lack the recovery infrastructure to avoid paying. In practical terms, that means offline or immutable backup systems that can restore operations within a clinically acceptable timeframe, incident response plans that have been tested against realistic scenarios, and business continuity arrangements that do not depend on a single point of failure.
Healthcare practices that have not tested a full restoration from backup under time pressure may be surprised by how long the process takes. The decision to pay or not is almost always made under extreme time pressure and incomplete information. Organizations that have already answered the operational questions — can systems be restored, how long will it take, what is the patient safety threshold — are better positioned to hold the line when that decision arrives.
What the next 12 months may bring
If payment bans spread or are extended to private-sector critical infrastructure, healthcare organizations will need documented evidence that they evaluated all recovery options before any payment decision. That shifts compliance exposure: it is no longer enough to say paying was the fastest path back to operations. Regulators and, potentially, law enforcement will want to see that alternative recovery paths were genuinely available and genuinely tried.
The current environment rewards investment in tested, isolated recovery capability more than almost any other single control. Organizations that treat backup and recovery as a checkbox item rather than a practiced discipline are the ones most likely to face a payment decision with no good options on either side.