Roughly half of organizations struck by ransomware pay their attackers, according to 2025 research from Sophos, and the median ransom demand continues to climb. The finding arrives as regulators in the United Kingdom and several other jurisdictions are actively considering or advancing bans on ransom payments — a policy shift that would force healthcare organizations to treat operational resilience, not payment, as the only viable recovery path.
The payment calculus is shifting
For years, the decision to pay or refuse a ransom has been treated as a private business calculation: weigh recovery costs against the ransom, factor in reputational exposure, and decide. That framing is losing ground. Payment bans would convert what is currently an ethical and financial question into a legal one, eliminating optionality for covered entities and their business associates regardless of the operational pressure they face.
Healthcare targets are disproportionately affected by that pressure. Hospitals and physician groups cannot defer clinical operations the way a retailer might hold a store dark for a weekend. The combination of high payment rates and rising demand amounts shows that attackers understand this and price accordingly.
What a payment ban actually changes
A jurisdiction that prohibits ransom payments does not make ransomware attacks less frequent. It does, however, change the downstream accountability picture significantly:
- Backup and recovery investment becomes non-discretionary. If payment is illegal, offline or air-gapped backup infrastructure shifts from a best practice to a survival requirement. Practices without tested, segmented backups would face extended downtime with no legal exit.
- Cyber insurance terms are likely to move. Insurers in payment-ban jurisdictions cannot write coverage that reimburses a prohibited transaction. Policy language, sublimits, and incident-response obligations will need to be renegotiated, and premiums may reflect the added underwriting exposure.
- Negotiation services become a compliance risk. Third-party incident-response firms that typically manage ransom negotiations on behalf of clients would need to restructure their service offerings in any jurisdiction where payment is banned, and healthcare organizations that engage them would bear their own liability exposure.
Where the regulatory picture stands for US healthcare
No federal payment ban is currently in force in the United States, though Treasury's Office of Foreign Assets Control has long warned that payments to sanctioned threat actors may violate sanctions law regardless of the underlying attack. CISA and HHS have issued joint guidance encouraging healthcare organizations to refuse payment and invest in resilience, but guidance is not prohibition.
State-level proposals have surfaced periodically, and the international momentum — particularly if the UK enacts legislation — tends to accelerate domestic policy conversations. Healthcare compliance officers should treat the current period as a preparation window rather than a signal that the status quo is stable.
What independent practices should check now
The Sophos data and the emerging regulatory discussion point toward the same set of operational gaps that make payment feel necessary in the first place. Practices that want to reduce their exposure to that pressure should audit three areas before a regulatory mandate forces the issue:
- Recovery time objectives. How long would it take to restore clinical systems from backup without paying? If that answer is unknown or exceeds a day or two, backup architecture needs attention.
- Segmentation. Ransomware that can reach backup systems from the same network segment it encrypted eliminates the backup option entirely. Logical and physical separation of backup environments is the control that makes non-payment survivable.
- Incident response planning. A documented, tested response plan — including who has authority to make payment decisions and under what legal review — reduces the chaos that drives organizations toward rapid payment. Practices that have never tabletop-tested a ransomware scenario are planning to improvise under the worst possible conditions.
The policy environment around ransomware payments is not settled, but the direction of travel is visible. Healthcare organizations that build recovery capacity now are better positioned regardless of which legal regime they eventually operate under.