Ransomware victims are paying at near-record rates, and regulators in multiple countries are moving to make payment illegal — a combination that is forcing healthcare administrators and compliance officers to think seriously about what happens when the ransom option disappears. Research published by Sophos in 2025 found that roughly half of organizations struck by ransomware ended up paying, while the median demand figure continued rising. For healthcare — a sector that has faced some of the largest and most disruptive attacks in recent memory — both trends carry direct operational and legal implications.

The payment calculus is shifting

For years, paying a ransom occupied a legal gray zone in most jurisdictions. That is changing. The UK is among the governments actively examining prohibitions on ransom payments, and the policy conversation has accelerated in the US as well. A ban would not eliminate the financial damage of an attack — it would redirect it entirely toward recovery costs, regulatory penalties, and the business disruption that persists while encrypted systems are rebuilt.

Healthcare organizations that have historically viewed payment as a faster path back to clinical operations would face a harder set of choices under a ban. Restoration from backups, manual workarounds, and patient-diversion protocols — measures that many practices have underfunded — would become the only available options.

Why healthcare is structurally exposed

Several features of clinical environments make ransomware containment harder than in other industries:

What a payment-ban environment demands

If payment prohibition becomes law — in the US or in jurisdictions where US-based vendors operate — the practical burden shifts entirely to pre-incident controls. Organizations that cannot restore encrypted systems within days face prolonged outages with no legal exit. That changes the cost-benefit analysis for investments that are currently easy to defer.

The controls that determine recovery speed are not exotic. Tested offline or immutable backups, documented restoration procedures with realistic time estimates, network segmentation that limits blast radius, and tabletop exercises that stress-test manual workflows are the categories that determine whether a practice survives a ransomware event without paying. The Sophos data and the emerging regulatory direction both point toward the same conclusion: organizations that treat those controls as optional are making a bet that is becoming increasingly expensive to lose.

What the next 12 months may bring

The policy window on payment bans is open. Legislative proposals and regulatory consultations are active in multiple jurisdictions, and a significant attack on critical healthcare infrastructure could accelerate the timeline. For independent practices, the relevant preparation is not waiting to see whether a ban passes — it is auditing recovery capability now, before the legal landscape changes and before the next incident.

Practices should specifically examine whether backup systems are genuinely isolated from production environments, how long a full restoration has actually taken in testing, and whether clinical staff have practiced operating under downtime procedures long enough to sustain care for 72 hours or more without electronic systems. Those are the questions a payment ban makes unavoidable. Asking them before the ban arrives is cheaper than asking them during an active incident.