Ransomware victims are still paying — often — and the median demand is climbing. Research published by Sophos in 2025 found that nearly half of organizations hit by ransomware paid their attackers, a figure that holds even as law enforcement agencies have repeatedly warned that payment does not guarantee data recovery and may invite repeat attacks. Healthcare organizations, which routinely top sector-by-sector breach tallies, face the same calculus under sharper pressure: prolonged system outages can directly affect patient care.
The payment debate shifts to legislatures
Several jurisdictions are moving from guidance to prohibition. The United Kingdom is among governments examining mandatory reporting requirements and potential payment bans aimed at cutting off the ransomware revenue stream at its source. Proponents argue that if institutions cannot legally pay, attackers lose the financial incentive to target them. Critics counter that banning payment without providing organizations a credible alternative — faster system restoration, better backups, law enforcement intervention — simply converts a financial harm into an operational one.
For U.S. healthcare entities, no federal ban is currently in effect, but the policy momentum is visible. Several bills introduced in Congress in recent years would require reporting ransomware payments to federal agencies, and HHS has signaled in its cybersecurity performance goals that payment decisions should be documented as part of incident response planning.
Why healthcare feels the pressure differently
Hospitals and medical practices cannot absorb extended downtime the way a retail or financial services firm might. Encrypted scheduling systems, inaccessible electronic health records, and disabled pharmacy interfaces translate into diverted ambulances, postponed surgeries, and medication errors. That operational dependency gives ransomware groups a structural advantage when negotiating with healthcare targets, and it is one reason median ransom amounts in the sector have trended above cross-industry averages.
The Sophos data also suggests that paying does not reliably shorten recovery time. Organizations that paid still spent weeks restoring systems, in many cases because attackers provided incomplete or malfunctioning decryption tools. That finding weakens one of the central arguments for payment — speed — and gives compliance officers cleaner ground to build the internal case for prioritizing resilience investments over ransom reserves.
What this signals for incident response planning
The combination of rising demands, potential payment restrictions, and unreliable decryption outcomes points toward a single planning priority: making payment a last resort rather than a default. For independent practices, that means stress-testing three specific capabilities before an incident occurs.
- Offline, tested backups. Backups that are network-connected at the time of an attack are routinely encrypted alongside production systems. Air-gapped or immutable backup architectures eliminate that exposure, but only if restoration procedures are tested regularly against realistic recovery-time targets.
- Documented decision authority. When systems go down, practices need a pre-authorized chain of command for the payment decision — including legal counsel, cyber insurance carriers, and a designated incident coordinator — so that pressure and time constraints do not force an improvised choice.
- Regulatory reporting timelines. HIPAA's breach notification rule requires covered entities to notify HHS and affected individuals within specified windows. If payment-reporting mandates pass at the federal level, those deadlines will compound. Incident response plans written now should build in parallel reporting tracks rather than sequential ones.
The broader policy shift toward payment restrictions may take years to resolve legislatively. The operational problem — ransomware groups that have refined their targeting and pricing models against healthcare — is already here.