Roughly half of organizations struck by ransomware pay their attackers, according to 2025 research from Sophos, and the median ransom demand continues to climb. The finding arrives as regulators in the United Kingdom and several other jurisdictions are actively considering or advancing bans on ransom payments — a policy shift that would force healthcare organizations to treat operational resilience, not payment, as the only viable recovery path.

The payment calculus is shifting

For years, the decision to pay or refuse a ransom has been treated as a private business calculation: weigh recovery costs against the ransom, factor in reputational exposure, and decide. That framing is losing ground. Payment bans would convert what is currently an ethical and financial question into a legal one, eliminating optionality for covered entities and their business associates regardless of the operational pressure they face.

Healthcare targets are disproportionately affected by that pressure. Hospitals and physician groups cannot defer clinical operations the way a retailer might hold a store dark for a weekend. The combination of high payment rates and rising demand amounts shows that attackers understand this and price accordingly.

What a payment ban actually changes

A jurisdiction that prohibits ransom payments does not make ransomware attacks less frequent. It does, however, change the downstream accountability picture significantly:

Where the regulatory picture stands for US healthcare

No federal payment ban is currently in force in the United States, though Treasury's Office of Foreign Assets Control has long warned that payments to sanctioned threat actors may violate sanctions law regardless of the underlying attack. CISA and HHS have issued joint guidance encouraging healthcare organizations to refuse payment and invest in resilience, but guidance is not prohibition.

State-level proposals have surfaced periodically, and the international momentum — particularly if the UK enacts legislation — tends to accelerate domestic policy conversations. Healthcare compliance officers should treat the current period as a preparation window rather than a signal that the status quo is stable.

What independent practices should check now

The Sophos data and the emerging regulatory discussion point toward the same set of operational gaps that make payment feel necessary in the first place. Practices that want to reduce their exposure to that pressure should audit three areas before a regulatory mandate forces the issue:

The policy environment around ransomware payments is not settled, but the direction of travel is visible. Healthcare organizations that build recovery capacity now are better positioned regardless of which legal regime they eventually operate under.