Ransomware attacks continue to extract payments from nearly half of all victims, according to 2025 research from cybersecurity group Sophos, and the median ransom demanded keeps rising. At the same time, a growing number of governments are weighing or enacting outright prohibitions on paying threat actors — a policy shift that would fundamentally alter the calculus for healthcare organizations, which remain among the most targeted sectors and among the most likely to pay in order to restore clinical operations quickly.

The payment dilemma

The decision to pay a ransom has never been straightforward, but the pressure points have sharpened. For healthcare organizations, the calculus is complicated by patient safety: delayed access to electronic health records, laboratory systems, or imaging platforms can translate directly into care disruptions. That operational urgency has historically made the sector a preferred target, and it has made administrators more willing to authorize payments than their counterparts in other industries.

Sophos data shows median demanded amounts trending upward even as law enforcement agencies warn that paying does not guarantee data recovery or prevent the stolen data from being published. A significant share of organizations that paid still saw their exfiltrated information appear on leak sites.

What a payment ban would mean

The UK is among the jurisdictions actively considering legislation that would prohibit ransom payments, joining a small set of governments that have moved from discouraging payments to banning them outright. For US-based healthcare organizations, the direct legal impact of a UK ban would be limited — unless they have UK operations or contract with UK-based suppliers. The broader significance is normative: if major economies criminalize payment, US federal and state policymakers face renewed pressure to follow, and cyber insurance carriers operating across those jurisdictions may restructure coverage terms globally.

Healthcare compliance officers should monitor whether HHS or Treasury's Office of Foreign Assets Control issues updated guidance tying ransom payment prohibitions to existing sanctions frameworks. OFAC has previously warned that payments to sanctioned entities — which include several active ransomware groups — can trigger civil liability regardless of intent.

Where this lands for independent practices

For smaller and independent healthcare organizations, the practical takeaway is that relying on payment as a recovery path carries more risk than it did two years ago, on multiple dimensions: rising demand amounts, uncertain data recovery, potential regulatory exposure, and a shifting insurance landscape.

The durable alternative is making payment a genuinely unattractive last resort by investing in the controls that reduce both the likelihood of a successful attack and the recovery time if one occurs:

The Sophos findings and the emerging legislative trend both point toward the same conclusion: the window in which payment felt like a reliable, low-consequence option is closing. Healthcare organizations that have not revisited their recovery capabilities recently are operating on assumptions that may no longer hold.