Nearly half of organizations hit by ransomware end up paying their attackers to recover data or restore systems, according to 2025 research from Sophos — and the median ransom demand is climbing. That calculus is growing more complicated as governments in multiple jurisdictions consider or enact outright bans on ransom payments, a development with direct implications for healthcare entities that have historically been among the most frequent targets and the most likely to pay.
The structural problem
Healthcare organizations face a combination of factors that make them disproportionately vulnerable to extortion pressure. Clinical operations depend on continuous system availability in ways that most other industries do not, and the sensitivity of protected health information creates a second layer of leverage: attackers can threaten to publish patient records even after a decryption key is provided. That dual-threat model — encrypt and exfiltrate — has become standard practice among major ransomware groups and makes the payment decision substantially harder than it was five years ago.
The Sophos research, drawn from a global sample, does not break out healthcare-specific payment rates, but prior reporting from HHS and independent security researchers has consistently shown the sector paying at above-average rates. The combination of operational urgency and data sensitivity explains much of that gap.
What payment bans would change
The UK is among jurisdictions examining mandatory payment prohibitions. Under a ban, organizations that pay ransom — whether directly or through cyber-insurance intermediaries — would face legal consequences, removing payment as a recoverable option regardless of operational pressure. Proponents argue that cutting off the revenue stream is the only reliable way to reduce attack frequency; critics note that bans shift the cost of non-payment entirely onto victims who may lack the recovery resources to absorb it.
For US healthcare organizations, no federal payment ban is currently in force, though the Office of Foreign Assets Control already prohibits payments to sanctioned entities, a category that includes several active ransomware groups. Any expansion of that framework — or state-level action — would require covered entities and their insurers to revisit incident-response plans that currently treat payment as a contingency option.
Where this lands for independent practices
Smaller and independent practices are particularly exposed. They typically carry thinner IT and security staffs, rely more heavily on a single EHR or billing platform, and have less negotiating leverage with cyber-insurers than large health systems. If payment bans expand, practices without tested offline backup and recovery procedures would have no fallback short of extended downtime.
The practical implications for compliance and operations teams include:
- Backup architecture. Air-gapped or immutable backup systems — where production environments cannot overwrite or delete backup copies — are the primary technical defense against being forced into a payment decision. Frequency and tested restore times matter as much as storage capacity.
- Incident-response planning. Plans written when payment was a legal and insurable option may need to be revised now, before any ban takes effect. That includes downtime procedures, patient diversion protocols, and vendor notification chains.
- Insurance policy review. Many cyber-insurance policies currently cover ransom payments. Carriers are already tightening terms; any regulatory ban would likely accelerate exclusions and may affect how policies define a covered loss.
- Sanctions compliance. Regardless of broader ban legislation, paying a sanctioned entity remains a federal violation. Incident-response procedures should include a step to screen any extortion demand against current OFAC designations before any payment decision is considered.
What this signals about the next 12 months
The policy direction in multiple countries is toward restricting or eliminating payment as an option. Even if the US does not enact a federal ban in the near term, the trajectory creates pressure on insurers, state regulators, and HHS to revisit existing guidance. Healthcare organizations that treat payment as an implicit backstop to inadequate backup and recovery investment are operating on an assumption that may not hold through the next budget cycle.