Nearly half of organizations hit by ransomware end up paying their attackers to recover data or restore systems, according to 2025 research from Sophos — and the median ransom demand is climbing. That calculus is growing more complicated as governments in multiple jurisdictions consider or enact outright bans on ransom payments, a development with direct implications for healthcare entities that have historically been among the most frequent targets and the most likely to pay.

The structural problem

Healthcare organizations face a combination of factors that make them disproportionately vulnerable to extortion pressure. Clinical operations depend on continuous system availability in ways that most other industries do not, and the sensitivity of protected health information creates a second layer of leverage: attackers can threaten to publish patient records even after a decryption key is provided. That dual-threat model — encrypt and exfiltrate — has become standard practice among major ransomware groups and makes the payment decision substantially harder than it was five years ago.

The Sophos research, drawn from a global sample, does not break out healthcare-specific payment rates, but prior reporting from HHS and independent security researchers has consistently shown the sector paying at above-average rates. The combination of operational urgency and data sensitivity explains much of that gap.

What payment bans would change

The UK is among jurisdictions examining mandatory payment prohibitions. Under a ban, organizations that pay ransom — whether directly or through cyber-insurance intermediaries — would face legal consequences, removing payment as a recoverable option regardless of operational pressure. Proponents argue that cutting off the revenue stream is the only reliable way to reduce attack frequency; critics note that bans shift the cost of non-payment entirely onto victims who may lack the recovery resources to absorb it.

For US healthcare organizations, no federal payment ban is currently in force, though the Office of Foreign Assets Control already prohibits payments to sanctioned entities, a category that includes several active ransomware groups. Any expansion of that framework — or state-level action — would require covered entities and their insurers to revisit incident-response plans that currently treat payment as a contingency option.

Where this lands for independent practices

Smaller and independent practices are particularly exposed. They typically carry thinner IT and security staffs, rely more heavily on a single EHR or billing platform, and have less negotiating leverage with cyber-insurers than large health systems. If payment bans expand, practices without tested offline backup and recovery procedures would have no fallback short of extended downtime.

The practical implications for compliance and operations teams include:

What this signals about the next 12 months

The policy direction in multiple countries is toward restricting or eliminating payment as an option. Even if the US does not enact a federal ban in the near term, the trajectory creates pressure on insurers, state regulators, and HHS to revisit existing guidance. Healthcare organizations that treat payment as an implicit backstop to inadequate backup and recovery investment are operating on an assumption that may not hold through the next budget cycle.