Ransomware attacks against healthcare and other sectors are producing a widening policy fault line: pay the ransom and restore operations quickly, or refuse and absorb prolonged downtime while governments in several countries debate making payment illegal. Research published in 2025 by Sophos found that roughly 45 percent of ransomware victims ultimately transfer funds to attackers, even as median ransom demands continue to rise. For independent healthcare practices, where clinical continuity is directly tied to system availability, the calculus is particularly fraught.
The payment debate hardens
The core tension is not new, but legislative momentum is. The United Kingdom has moved toward restricting ransom payments, joining a handful of jurisdictions that view payment prohibitions as the most effective lever for reducing attacker revenue and, by extension, the volume of attacks. The argument from policymakers is straightforward: as long as payments flow, ransomware remains a profitable business model.
Opponents of payment bans argue that prohibitions shift the burden entirely onto victims, many of whom lack the technical depth or backup infrastructure to restore operations without a decryption key. Healthcare organizations are frequently cited in that argument because extended downtime translates directly into patient care risk, not merely financial loss.
What the numbers show about victim behavior
The Sophos findings illustrate why bans are difficult to enforce in practice. When nearly half of all victims pay, attackers have statistical reason to keep launching campaigns. The median demanded amount has risen in parallel, suggesting that payment compliance is emboldening groups to set higher initial figures. Healthcare has consistently appeared among the most targeted sectors in annual ransomware reports, in part because the combination of sensitive data and operational urgency creates pressure to resolve incidents quickly.
Payment does not guarantee recovery. Decryption tools delivered after ransom transfer are frequently slow, incomplete, or accompanied by secondary extortion demands threatening to publish stolen data. Independent practices that pay may still face weeks of partial outage and a separate negotiation over publication of patient records.
Where the regulatory exposure sits
US regulators have not moved to ban ransomware payments, but the compliance landscape around incidents is already complex. HHS requires breach notification when protected health information is accessed or exfiltrated, and OCR has made clear that a ransom payment does not eliminate that obligation. Paying attackers who appear on Treasury Department sanctions lists can create separate legal exposure under OFAC rules, a risk that intensified after several ransomware groups were designated in prior years.
Practices facing an active incident should treat legal counsel and breach counsel as immediate resources, not post-incident ones. The decision to pay or not intersects breach notification timelines, potential sanctions screening, and cyber insurance policy conditions — all of which require review before funds transfer.
What independent practices should check now
The article's broader signal is that the operating environment for ransomware response is changing at the policy level, even if US law has not yet caught up. Practices can take concrete steps now that reduce dependence on a payment decision later:
- Offline and tested backups. Backups that are network-connected at the time of an attack are routinely encrypted along with primary systems. Air-gapped or immutable backup configurations, tested regularly through restoration drills, are the primary alternative to payment.
- Incident response documentation. A written response plan that identifies legal counsel, cyber insurer contacts, and a designated decision-maker speeds the initial hours of an incident, when the pressure to pay is highest.
- Sanctions screening awareness. Staff with authority over financial decisions during an incident should understand that paying a designated entity carries legal risk independent of the ransom itself.
- Tabletop exercises that include the payment question. Practices that have not rehearsed the pay-or-not decision are more likely to make it under maximum duress, with incomplete information.
The policy environment will continue to shift. Practices that build recovery capability independent of attacker cooperation are better positioned regardless of which direction legislation moves.