Ransomware victims are paying attackers at a rate approaching one in two incidents, according to 2025 research from Sophos, and the median ransom demand has continued to climb. At the same time, governments in the UK and several other jurisdictions are weighing or have already advanced legislation that would ban payments to cybercriminal groups outright — a shift that would remove the option most organizations have quietly relied on to restore operations quickly. For healthcare organizations, which remain among the most targeted sectors globally, the policy trajectory and the payment economics are converging in ways that demand preparation now rather than later.
The payment calculus is changing
The Sophos data, which covered incidents across industries, found that nearly half of attacked organizations ultimately transferred funds to threat actors. The figure is notable because it reflects outcomes after many organizations have weighed legal counsel, insurance coverage, and operational downtime costs — and still chose to pay. The median demand amount rising in parallel suggests attackers are recalibrating ransom levels based on observed willingness to pay, creating a feedback loop that pressures future victims.
For healthcare specifically, the calculation carries additional weight. Disrupted clinical systems translate directly into patient care delays, and the pressure to restore access to electronic health records, pharmacy systems, or imaging platforms within hours — not weeks — can make payment feel like the only viable path. That perception is exactly what ransomware groups exploit.
Payment bans would rewrite the incident-response equation
The UK government has signaled intent to restrict ransom payments, and similar legislative conversations are active in other jurisdictions. A payment ban does not eliminate ransomware attacks; it removes the fastest fallback option available to victims who have not invested in recovery infrastructure. For organizations operating under US regulatory frameworks, no federal ban is currently in place, but state-level proposals have surfaced, and the policy momentum is worth monitoring.
If payment becomes legally prohibited — or if cyber-liability insurers narrow coverage for ransom disbursements, which several carriers have already begun doing — organizations without tested backup and recovery capabilities face a substantially harder incident response. The practical implication is that restoration timelines measured in days rather than hours depend on whether offline backups exist, whether recovery procedures have been drilled, and whether critical systems can be isolated and rebuilt without the attacker's decryption key.
What independent practices should examine before an incident
Healthcare practices that have not recently tested their ransomware response face a widening gap between assumption and reality. Several areas deserve attention:
- Backup integrity and isolation. Backups stored on network-connected systems are routinely encrypted alongside primary data in modern ransomware attacks. Verified, offline or immutable copies are the difference between a recovery and a ransom negotiation.
- Recovery time estimates. Knowing a backup exists is different from knowing how long full restoration takes. Practices that have not timed a recovery exercise do not know their actual downtime exposure.
- Insurance policy language. Cyber-liability policies vary significantly on whether ransom payments are covered, under what conditions, and whether coverage changes if a payment ban applies in the relevant jurisdiction. Policy review before an event is not optional.
- Incident-response contacts. Decisions about payment, law enforcement notification, and regulatory reporting under HIPAA's breach notification rule must be made under time pressure. Identifying legal counsel, a forensic response firm, and an insurance contact in advance reduces errors during an active incident.
- Regulatory notification timelines. HIPAA requires covered entities to notify HHS and affected individuals following a breach involving protected health information. A ransomware event that encrypts PHI is presumed a breach under HHS guidance unless a specific exception applies. Practices should confirm they understand the 60-day notification clock and the conditions that trigger it.
What the next 12 months may look like
The combination of rising demand amounts, near-50% payment rates, and advancing payment-ban legislation points toward a period of structural change in how ransomware incidents resolve. Attackers are likely to respond to any payment restrictions by intensifying data-exfiltration tactics — threatening to publish stolen patient records rather than simply withholding decryption keys — because extortion over sensitive data remains actionable even when payment for decryption is legally blocked.
Healthcare organizations that treat ransomware preparedness as a one-time checklist exercise rather than an ongoing operational discipline will find themselves at greater risk as both attacker tactics and the legal environment shift. The Sophos research and the legislative activity together signal that the window for proactive preparation is narrowing.