Ransomware attacks continue to extract payments from nearly half of all victims, according to 2025 research from cybersecurity group Sophos, and the median ransom demanded keeps rising. At the same time, a growing number of governments are weighing or enacting outright prohibitions on paying threat actors — a policy shift that would fundamentally alter the calculus for healthcare organizations, which remain among the most targeted sectors and among the most likely to pay in order to restore clinical operations quickly.
The payment dilemma
The decision to pay a ransom has never been straightforward, but the pressure points have sharpened. For healthcare organizations, the calculus is complicated by patient safety: delayed access to electronic health records, laboratory systems, or imaging platforms can translate directly into care disruptions. That operational urgency has historically made the sector a preferred target, and it has made administrators more willing to authorize payments than their counterparts in other industries.
Sophos data shows median demanded amounts trending upward even as law enforcement agencies warn that paying does not guarantee data recovery or prevent the stolen data from being published. A significant share of organizations that paid still saw their exfiltrated information appear on leak sites.
What a payment ban would mean
The UK is among the jurisdictions actively considering legislation that would prohibit ransom payments, joining a small set of governments that have moved from discouraging payments to banning them outright. For US-based healthcare organizations, the direct legal impact of a UK ban would be limited — unless they have UK operations or contract with UK-based suppliers. The broader significance is normative: if major economies criminalize payment, US federal and state policymakers face renewed pressure to follow, and cyber insurance carriers operating across those jurisdictions may restructure coverage terms globally.
Healthcare compliance officers should monitor whether HHS or Treasury's Office of Foreign Assets Control issues updated guidance tying ransom payment prohibitions to existing sanctions frameworks. OFAC has previously warned that payments to sanctioned entities — which include several active ransomware groups — can trigger civil liability regardless of intent.
Where this lands for independent practices
For smaller and independent healthcare organizations, the practical takeaway is that relying on payment as a recovery path carries more risk than it did two years ago, on multiple dimensions: rising demand amounts, uncertain data recovery, potential regulatory exposure, and a shifting insurance landscape.
The durable alternative is making payment a genuinely unattractive last resort by investing in the controls that reduce both the likelihood of a successful attack and the recovery time if one occurs:
- Offline and tested backups. Immutable, air-gapped backup systems that are tested on a regular schedule remain the single most consequential control for reducing ransomware leverage. If systems can be restored from clean backups within an acceptable window, the ransom demand loses its force.
- Network segmentation. Limiting lateral movement between clinical, administrative, and billing systems can contain an intrusion before it reaches the point of full encryption.
- Incident response planning. A documented, rehearsed response plan — including pre-established relationships with forensic counsel and breach notification specialists — compresses recovery time and reduces the pressure to pay quickly.
- Tabletop exercises. Simulated ransomware scenarios, run at least annually, expose gaps in decision-making chains before a real event forces rushed choices.
The Sophos findings and the emerging legislative trend both point toward the same conclusion: the window in which payment felt like a reliable, low-consequence option is closing. Healthcare organizations that have not revisited their recovery capabilities recently are operating on assumptions that may no longer hold.