Ransomware victims are paying at rates that remain stubbornly high even as governments in several countries move to make those payments illegal. Research published by Sophos in 2025 found that nearly half of organizations hit by ransomware ultimately paid a ransom to recover data or restore systems, and the median demand continues to rise. For healthcare — a sector that faces outsized pressure to restore operations quickly because patient safety hangs on system availability — that statistic carries particular weight.

The payment calculus

The decision whether to pay is rarely straightforward. Organizations weigh the cost of the ransom itself against the cost of extended downtime, data reconstruction, regulatory penalties, and reputational harm. In healthcare, downtime translates directly into deferred care, diverted ambulances, and manual workarounds that introduce clinical risk.

Several factors complicate the math further:

Governments are tightening the rules

The UK is among the jurisdictions actively exploring or advancing bans on ransom payments, at least for public-sector entities and critical infrastructure. The logic is straightforward: payments fund further attacks. If enough high-value targets stop paying, the economic model for ransomware groups weakens.

For US healthcare organizations, no federal payment ban is currently in force, but the regulatory direction is worth tracking. HHS has signaled repeatedly that it views inadequate security controls — rather than payment decisions — as the primary compliance failure in ransomware incidents. The revised HIPAA Security Rule proposed in early 2025 would, if finalized, require more prescriptive technical controls including network segmentation, encryption at rest, and regular tested recovery procedures. Those controls are precisely the ones that reduce the pressure to pay in the first place.

What the payment rate reveals about preparedness

A near-50 percent payment rate across industries suggests that a large share of organizations still lack the recovery infrastructure to avoid paying. In practical terms, that means offline or immutable backup systems that can restore operations within a clinically acceptable timeframe, incident response plans that have been tested against realistic scenarios, and business continuity arrangements that do not depend on a single point of failure.

Healthcare practices that have not tested a full restoration from backup under time pressure may be surprised by how long the process takes. The decision to pay or not is almost always made under extreme time pressure and incomplete information. Organizations that have already answered the operational questions — can systems be restored, how long will it take, what is the patient safety threshold — are better positioned to hold the line when that decision arrives.

What the next 12 months may bring

If payment bans spread or are extended to private-sector critical infrastructure, healthcare organizations will need documented evidence that they evaluated all recovery options before any payment decision. That shifts compliance exposure: it is no longer enough to say paying was the fastest path back to operations. Regulators and, potentially, law enforcement will want to see that alternative recovery paths were genuinely available and genuinely tried.

The current environment rewards investment in tested, isolated recovery capability more than almost any other single control. Organizations that treat backup and recovery as a checkbox item rather than a practiced discipline are the ones most likely to face a payment decision with no good options on either side.