Nearly half of organizations struck by ransomware paid their attackers in 2025, according to research from cybersecurity group Sophos, even as median ransom demands continued to rise. The finding arrives at a moment when several governments — including the United Kingdom — are actively considering or moving toward formal bans on ransom payments, a policy shift that would force healthcare organizations to confront these incidents with fewer options than they have historically assumed were available.
The payment calculus
The Sophos data reflects a persistent gap between what security practitioners advise and what organizations actually do when systems go dark. For hospitals, clinics, and independent practices, the pressure to pay is acute: clinical workflows depend on access to patient records, scheduling systems, and connected medical devices in ways that a retail or financial-services organization simply does not face. Downtime translates directly into delayed care and, in documented cases, patient harm.
At the same time, paying a ransom does not guarantee restoration. Sophos and other researchers have documented cases in which organizations paid, received a decryption key that worked only partially, and still faced weeks of remediation. Some were hit again by the same or affiliated threat actors within months.
The regulatory pressure building around payments
The UK is the most prominent jurisdiction currently weighing a payment ban, but it is not alone. Several US lawmakers and policy researchers have raised similar proposals at the federal level, arguing that continued payments fund the ransomware ecosystem and keep attack volumes high. For US healthcare organizations, a federal ban would carry particular weight: it would convert a difficult operational decision into a legal compliance question with potential enforcement consequences.
Even absent a formal ban, existing US sanctions frameworks already create liability for payments made to certain designated threat actors. Healthcare organizations that have not reviewed those restrictions with legal counsel may be unaware of exposure they already carry.
What independent practices should check
For smaller and independent healthcare organizations, the policy debate has immediate operational implications regardless of how legislation ultimately resolves.
- Backup architecture. Paying becomes less tempting when verified, air-gapped backups can restore operations in hours rather than weeks. The question is not whether backups exist, but whether they have been tested under realistic failure conditions.
- Incident response planning. Plans written before the payment-ban debate may assume ransom payment as a fallback option. Those plans warrant review now, while there is time to add alternatives rather than during an active incident.
- Legal and sanctions review. Counsel familiar with OFAC sanctions designations should confirm which threat actor affiliations currently trigger payment prohibitions, so the organization is not making that determination at two in the morning during an active attack.
- Cyber insurance alignment. Many policies include ransom payment coverage, but coverage terms vary on whether payments to sanctioned entities are excluded. Policy language and insurer guidance should be reviewed in advance.
What this signals about the next 12 months
If the UK enacts a payment ban, the practical effect on global ransomware economics will take time to measure — and threat actors are likely to redirect pressure rather than simply stop attacking. Healthcare will remain a high-value target precisely because the consequences of extended downtime are severe enough that attackers expect organizations to act quickly. The policy shift does not reduce risk; it redirects the decision tree, removing one exit that many organizations have quietly relied on. The practices best positioned to manage that shift are those that have already made payment an unattractive option through resilient recovery capabilities rather than those treating payment as an available insurance policy.