Nearly half of organizations struck by ransomware paid their attackers in 2025, according to research from cybersecurity group Sophos, even as median ransom demands continued to rise. The finding arrives at a moment when several governments — including the United Kingdom — are actively considering or moving toward formal bans on ransom payments, a policy shift that would force healthcare organizations to confront these incidents with fewer options than they have historically assumed were available.

The payment calculus

The Sophos data reflects a persistent gap between what security practitioners advise and what organizations actually do when systems go dark. For hospitals, clinics, and independent practices, the pressure to pay is acute: clinical workflows depend on access to patient records, scheduling systems, and connected medical devices in ways that a retail or financial-services organization simply does not face. Downtime translates directly into delayed care and, in documented cases, patient harm.

At the same time, paying a ransom does not guarantee restoration. Sophos and other researchers have documented cases in which organizations paid, received a decryption key that worked only partially, and still faced weeks of remediation. Some were hit again by the same or affiliated threat actors within months.

The regulatory pressure building around payments

The UK is the most prominent jurisdiction currently weighing a payment ban, but it is not alone. Several US lawmakers and policy researchers have raised similar proposals at the federal level, arguing that continued payments fund the ransomware ecosystem and keep attack volumes high. For US healthcare organizations, a federal ban would carry particular weight: it would convert a difficult operational decision into a legal compliance question with potential enforcement consequences.

Even absent a formal ban, existing US sanctions frameworks already create liability for payments made to certain designated threat actors. Healthcare organizations that have not reviewed those restrictions with legal counsel may be unaware of exposure they already carry.

What independent practices should check

For smaller and independent healthcare organizations, the policy debate has immediate operational implications regardless of how legislation ultimately resolves.

What this signals about the next 12 months

If the UK enacts a payment ban, the practical effect on global ransomware economics will take time to measure — and threat actors are likely to redirect pressure rather than simply stop attacking. Healthcare will remain a high-value target precisely because the consequences of extended downtime are severe enough that attackers expect organizations to act quickly. The policy shift does not reduce risk; it redirects the decision tree, removing one exit that many organizations have quietly relied on. The practices best positioned to manage that shift are those that have already made payment an unattractive option through resilient recovery capabilities rather than those treating payment as an available insurance policy.