Ransomware victims are paying more and more often, according to 2025 Sophos research cited by DataBreaches.net, with nearly half of targeted organizations ultimately transferring funds to attackers and median ransom demands continuing to climb. For healthcare organizations — which remain among the most frequently targeted sectors and face particular pressure to restore clinical systems quickly — the calculus around payment is becoming harder to resolve, especially as regulators in multiple jurisdictions move toward outright payment bans.
The payment dilemma in practice
The Sophos figures capture a dynamic that compliance officers in healthcare know well: when patient-facing systems go down, the operational cost of prolonged downtime can feel more concrete than the abstract risk of rewarding criminal actors. That pressure has historically made healthcare one of the sectors most likely to pay.
Paying does not reliably solve the problem. Research consistently shows that organizations that transfer ransom funds frequently face delayed decryption, incomplete data recovery, and — in a significant share of cases — repeat targeting. The ransom payment itself also does not extinguish notification obligations under HIPAA or state breach laws, meaning covered entities that pay are still required to investigate, assess, and report.
The regulatory pressure building against payment
Several jurisdictions are now examining or advancing legislation that would prohibit ransom payments outright. In the UK, the discussion has moved toward formal policy consideration. In the United States, similar proposals have circulated at the federal level, and a handful of states have explored restrictions on public-entity payments. For healthcare organizations operating across state lines or with international data flows, the legal landscape around what is even permissible is no longer static.
HHS guidance has not yet prohibited payment, but the agency has signaled that strong preventive controls — not post-incident negotiation — are the expected standard. OCR enforcement patterns show that organizations with documented, tested incident-response plans and verified backup integrity face meaningfully different post-breach scrutiny than those that cannot demonstrate preparedness.
What the trend signals for independent practices
- Backup architecture is now a regulatory artifact. The ability to demonstrate that isolated, tested backups exist — and that recovery time objectives were validated before an incident — bears directly on both the payment decision and on how OCR evaluates an organization's good-faith efforts.
- Cyber insurance terms are tightening. Carriers are increasingly requiring documented evidence of multi-factor authentication, endpoint detection controls, and staff phishing-awareness training as conditions of coverage. Practices that cannot show these controls at the time of a claim may find payment or recovery costs uninsured.
- Incident-response planning needs a payment-decision protocol. Organizations that have not pre-established an internal authorization chain for the ransom-payment question — including legal counsel, leadership, and law enforcement notification — are making that decision under maximum duress with minimum information.
- Law enforcement notification affects options. Reporting to the FBI before or immediately after a ransomware event can surface intelligence about the specific threat actor, including whether decryptors are already available through prior law enforcement action, which can change the payment calculus entirely.
Where this lands for compliance planning
The structural reality the Sophos data illustrates is that payment has become the de facto response for a large share of organizations, not because it is the advised path but because prevention and recovery infrastructure was not in place when the incident hit. For covered entities, HIPAA's Security Rule already requires documented contingency planning, backup and recovery procedures, and regular testing — controls that, if genuinely operational, reduce the conditions that make payment feel inevitable.
The approaching possibility of legal payment prohibitions adds a new dimension: organizations that have not built genuine recovery capability may find themselves both unable to pay and unable to restore operations from backups they never properly maintained. The policy debate is accelerating faster than many compliance calendars anticipate.