Ransomware victims are increasingly caught between the operational pressure to restore systems quickly and a policy environment that may soon remove the payment option entirely. Research from Sophos covering 2025 attack data found that roughly 47 percent of targeted organizations ultimately paid a ransom, even as median demand figures continued to climb — a combination that signals the leverage attackers hold over recovery-dependent operations like healthcare delivery.

The payment calculus for healthcare

Healthcare organizations face a version of the pay-or-not dilemma that differs meaningfully from other industries. Clinical operations — scheduling, medication administration, imaging, lab reporting — cannot remain offline for weeks without direct patient-safety consequences. That operational dependency has historically made healthcare one of the more likely verticals to pay.

The Sophos data does not break out healthcare-specific payment rates, but prior research from Coveware and the HHS Office of Information Security has consistently shown healthcare organizations paying at or above cross-industry averages. The median ransom demanded globally has risen year over year; for organizations with limited cyber-insurance coverage or no offline backup architecture, payment can appear to be the only path to a defined recovery timeline.

What complicates that math is outcome uncertainty. Paying does not guarantee decryption, does not prevent secondary extortion, and does not remove stolen data from attacker infrastructure. Organizations that have paid and then experienced a second attack from the same or affiliated threat actors represent a documented pattern in healthcare breach records.

The policy shift toward prohibition

Several jurisdictions are moving toward banning ransom payments outright. The UK is among those considering legislation that would make it illegal for certain organizations — likely including critical infrastructure and healthcare — to transfer funds to ransomware operators. Australia has floated similar proposals following a series of high-profile attacks on its healthcare sector. At the federal level in the United States, no blanket ban is in effect, but OFAC sanctions rules already prohibit payments to designated threat actor groups, and Treasury guidance creates legal exposure when organizations pay without first conducting a sanctions-compliance check.

For US healthcare practices, the practical implication is that the legal environment around payment is layered and evolving. An organization that pays without legal and compliance review risks sanctions violations independent of any HIPAA enforcement action. HHS does not require breach notification to be withheld pending payment, and there is no regulatory safe harbor for paying a ransom to avoid disclosure obligations.

What this signals for incident response planning

The policy direction in allied jurisdictions tends to anticipate US regulatory movement by one to three years. Organizations that have not revisited their incident response plans with payment prohibition as a planning assumption are behind the trend line.

Preparation that reduces dependence on the payment decision includes offline and air-gapped backup architectures tested against realistic recovery time objectives, segmented network design that limits lateral movement before encryption can propagate, and pre-negotiated relationships with legal counsel familiar with OFAC sanctions review — so that the compliance analysis does not begin after encryption has already occurred.

Cyber-insurance carriers are also adjusting. Several major carriers have added sublimits on ransom reimbursement or introduced co-payment requirements, meaning that even organizations with coverage will bear a larger share of the cost than policies written three years ago would have required. Reviewing current policy terms against those changes is a near-term compliance operations task, not a procurement question.

Where independent practices are exposed

Smaller and independent healthcare practices face a structural disadvantage in the payment debate that larger health systems do not: they often lack the legal, forensic, and public-relations infrastructure to assess and execute the sanctions-compliance process quickly under operational pressure. The decision to pay or not pay may effectively be made by default — either because systems are down and the pressure to restore is immediate, or because no one in the organization has the authority or knowledge to make the call in hours rather than days.

Building that decision framework in advance, with defined escalation paths and pre-identified external legal resources, is the preparation gap most commonly identified in post-incident reviews of small-practice ransomware cases. The policy shift underway in other jurisdictions makes that preparation more urgent, not less.