Ransomware victims are caught between operational desperation and hardening government policy. Research published by Sophos in 2025 found that close to half of all organizations hit by ransomware ultimately pay the demanded ransom, and median demand figures continue to climb. At the same time, jurisdictions in the UK and elsewhere are moving to prohibit payments outright — a collision course that healthcare organizations, among the most targeted sectors, will need to anticipate now rather than after an incident.
Why healthcare sits at the center of this problem
Hospitals, physician groups, and health systems face a different calculus than most industries when ransomware encrypts critical systems. Disruption to clinical workflows — scheduling, medication administration, imaging access, laboratory results — creates patient safety pressure that purely financial calculations cannot capture. That urgency is precisely what threat actors rely on to extract payment.
Healthcare has consistently ranked among the top targets in annual ransomware reporting, and attackers have refined their approach accordingly. Double-extortion tactics, in which data is exfiltrated before encryption so attackers can threaten publication regardless of whether systems are restored, have become standard practice. Paying a ransom no longer guarantees data will not be published or sold.
The policy landscape is shifting fast
Several governments are now treating ransomware payments as a demand-side driver of the broader ecosystem — the logic being that each payment funds the next attack. The UK has signaled interest in mandatory reporting of attacks combined with restrictions on payment, and similar discussions are active in Australia and parts of the European Union.
In the United States, no federal payment ban exists as of mid-2026, but the policy conversation is live. The Treasury Department's Office of Foreign Assets Control already prohibits payments to sanctioned threat actors, and violations carry significant civil penalties regardless of whether an organization knew its attacker was on the sanctions list. Healthcare organizations that pay without first conducting a sanctions check face compounding legal exposure on top of the incident itself.
The practical effect for compliance officers: the decision to pay or not is no longer a binary financial question. It carries regulatory, legal, and reputational dimensions that should be worked out in incident response planning, not improvised under operational duress.
What this signals about the next 12 months
If the UK or another major jurisdiction moves from discussion to enacted law, the precedent will accelerate similar proposals in the US Congress. Healthcare organizations with operations or vendors in multiple countries will face the additional complexity of conflicting legal obligations — paying may be prohibited in one jurisdiction and operationally unavoidable in another.
Independent practices are particularly exposed. Large health systems typically carry cyber insurance with pre-negotiated incident response retainers and legal counsel on call. Smaller organizations often discover, mid-incident, that their coverage terms exclude certain payment scenarios or that their policy has sublimits that fall well short of the actual demand.
Several preparation steps follow directly from the current environment:
- Offline, tested backups. The primary mechanism for avoiding payment pressure is the ability to restore systems from clean backups that ransomware cannot reach. Backup integrity should be verified through periodic restoration drills, not assumed.
- Sanctions screening protocol. Any payment scenario should include an immediate check against the OFAC Specially Designated Nationals list before funds transfer. This step should be documented in incident response plans now.
- Insurance policy review. Coverage terms should be reviewed to confirm what ransomware payment scenarios are covered, what sublimits apply, and whether the insurer requires prior authorization before payment.
- Legal counsel on retainer. The legal exposure associated with a ransomware payment decision — OFAC, state attorney general notification, HIPAA breach assessment — requires counsel familiar with healthcare regulatory obligations, not general corporate attorneys.
The Sophos data and the emerging payment-ban movement together suggest that the window for planning this response is narrowing. Organizations that treat ransomware response as a purely technical recovery problem are likely to discover the legal and financial dimensions at the worst possible moment.