Ransomware attacks continued to accelerate through 2025, and the economic calculus for victims is growing harder to resolve. Research from cybersecurity group Sophos found that roughly half of targeted organizations ultimately paid a ransom — even as median demand figures kept rising — while a parallel policy debate in several countries is moving toward outright bans on ransom payments. For healthcare organizations, which remain among the most frequently targeted sectors, these two trends are converging at an uncomfortable point.
The payment dilemma in practice
The Sophos data reinforces what incident responders have described for years: paying and refusing each carry serious operational costs, and neither guarantees a clean outcome.
Organizations that pay frequently find that decryption tools delivered by threat actors are slow, incomplete, or introduce additional risk. Those that refuse face extended downtime that, in healthcare settings, translates directly into delayed care, diverted ambulances, and rescheduled procedures — harms that carry both clinical and liability weight.
The rising median demand figure matters for smaller practices specifically. Amounts that large health systems can absorb through cyber insurance or reserves may be existential for an independent clinic or specialty group, pushing them toward payment even when law enforcement guidance and data recovery prospects argue against it.
What payment bans would change
The UK is among the jurisdictions examining a prohibition on ransom payments, with Australia and several US state legislatures also debating similar measures. A ban would shift the decision from an operational judgment call to a legal constraint — and would likely force a corresponding shift in how healthcare organizations plan for and respond to incidents before an attack occurs.
If payment is removed as an option, the pressure falls entirely on resilience: whether backup infrastructure is current enough, isolated enough, and tested enough to restore operations without a decryption key. Incident response plans written with payment as a fallback option are not equivalent to plans written without it.
Healthcare organizations operating under HIPAA already carry an affirmative obligation to maintain data availability as part of the Security Rule's contingency planning requirements. A payment ban would effectively raise the enforcement floor on those requirements without changing the regulatory text.
Where this lands for independent practices
Several operational questions follow from the current environment, regardless of whether payment prohibitions pass:
- Backup architecture. Immutable, air-gapped backups that are tested on a defined schedule are the single control most consistently cited by recovery teams as the difference between a days-long and a months-long restoration. Backups that are reachable from a compromised network segment are not effective backups.
- Cyber insurance alignment. Some insurers have begun excluding or limiting ransomware payment coverage, or conditioning it on documented pre-incident controls. Practices should confirm what their current policy covers and what documentation it requires before a claim is filed.
- Incident response planning. Plans should be reviewed specifically for whether they assume payment remains available. Tabletop exercises that test a no-payment recovery scenario will surface gaps that standard drills miss.
- Vendor dependency mapping. Many healthcare ransomware incidents propagate through a managed service provider or software vendor. Understanding which critical systems depend on external parties — and what those parties' own recovery capabilities are — affects how realistic any recovery timeline estimate is.
What this signals about the next 12 months
The policy debate over payment bans is unlikely to resolve quickly, but it is already influencing how regulators and insurers frame their expectations. OCR's ongoing emphasis on Security Rule compliance — particularly contingency planning — maps directly onto the controls that determine whether a practice can survive a ransomware event without paying. Enforcement activity following incidents has historically looked at whether organizations had documented, tested plans.
Practices that treat ransomware preparedness as a distinct planning exercise, separate from general cybersecurity checklists, are better positioned regardless of how the legal landscape shifts. The direction of travel in both policy and adversary capability argues against deferring that work.