Ransomware attacks continued to accelerate through 2025, and the economic calculus for victims is growing harder to resolve. Research from cybersecurity group Sophos found that roughly half of targeted organizations ultimately paid a ransom — even as median demand figures kept rising — while a parallel policy debate in several countries is moving toward outright bans on ransom payments. For healthcare organizations, which remain among the most frequently targeted sectors, these two trends are converging at an uncomfortable point.

The payment dilemma in practice

The Sophos data reinforces what incident responders have described for years: paying and refusing each carry serious operational costs, and neither guarantees a clean outcome.

Organizations that pay frequently find that decryption tools delivered by threat actors are slow, incomplete, or introduce additional risk. Those that refuse face extended downtime that, in healthcare settings, translates directly into delayed care, diverted ambulances, and rescheduled procedures — harms that carry both clinical and liability weight.

The rising median demand figure matters for smaller practices specifically. Amounts that large health systems can absorb through cyber insurance or reserves may be existential for an independent clinic or specialty group, pushing them toward payment even when law enforcement guidance and data recovery prospects argue against it.

What payment bans would change

The UK is among the jurisdictions examining a prohibition on ransom payments, with Australia and several US state legislatures also debating similar measures. A ban would shift the decision from an operational judgment call to a legal constraint — and would likely force a corresponding shift in how healthcare organizations plan for and respond to incidents before an attack occurs.

If payment is removed as an option, the pressure falls entirely on resilience: whether backup infrastructure is current enough, isolated enough, and tested enough to restore operations without a decryption key. Incident response plans written with payment as a fallback option are not equivalent to plans written without it.

Healthcare organizations operating under HIPAA already carry an affirmative obligation to maintain data availability as part of the Security Rule's contingency planning requirements. A payment ban would effectively raise the enforcement floor on those requirements without changing the regulatory text.

Where this lands for independent practices

Several operational questions follow from the current environment, regardless of whether payment prohibitions pass:

What this signals about the next 12 months

The policy debate over payment bans is unlikely to resolve quickly, but it is already influencing how regulators and insurers frame their expectations. OCR's ongoing emphasis on Security Rule compliance — particularly contingency planning — maps directly onto the controls that determine whether a practice can survive a ransomware event without paying. Enforcement activity following incidents has historically looked at whether organizations had documented, tested plans.

Practices that treat ransomware preparedness as a distinct planning exercise, separate from general cybersecurity checklists, are better positioned regardless of how the legal landscape shifts. The direction of travel in both policy and adversary capability argues against deferring that work.