Roughly half of organizations hit by ransomware end up paying their attackers, according to 2025 research from Sophos, and the median ransom demanded continues to climb. The data arrives as a growing number of governments — including the United Kingdom — are actively weighing legislation that would make those payments illegal. For healthcare organizations, which remain the most frequently targeted sector and carry the highest average breach costs of any industry, the policy debate has direct operational consequences.
The payment calculus is shifting
Sophos found that payment rates have held stubbornly near 50 percent even as security investment has increased across most industries. The persistence of that figure suggests that many organizations still see payment as the faster or cheaper path to recovery compared with restoring from backups — a calculation that becomes especially fraught in clinical environments where system downtime affects patient care.
Healthcare entities face a compounding pressure: the data encrypted or exfiltrated often includes protected health information, meaning a ransomware event can simultaneously trigger HIPAA breach-notification obligations and a ransom demand. Organizations that pay do not automatically escape notification requirements; OCR has consistently held that payment does not constitute evidence that data was not accessed or acquired.
The regulatory environment is moving toward prohibition
The UK's proposed payment ban represents the most prominent example of a hardening policy line, but it is not isolated. Australia introduced mandatory reporting requirements for ransomware payments in 2024, and several US lawmakers have floated similar federal restrictions. No federal US ban is currently in effect, but state-level conversations are advancing, and federal cyber agencies have repeatedly discouraged payment on the grounds that it funds further attacks without guaranteeing data recovery.
For US healthcare organizations, the absence of a federal prohibition does not settle the question. OFAC sanctions rules already make payments to designated threat actors potentially unlawful regardless of the victim's industry. Healthcare compliance officers should confirm that their incident-response plans account for a sanctions screening step before any payment decision is made — a requirement that is often missing from templated response playbooks.
What a payment ban would mean for healthcare recovery planning
If payment prohibitions expand to the United States, healthcare organizations that currently treat ransom payment as an implicit fallback option would need to rebuild their recovery assumptions entirely around backup integrity and restoration speed. Sophos and other researchers have documented that many organizations pay precisely because their backups are incomplete, untested, or themselves encrypted during the attack.
Several areas of recovery readiness deserve attention:
- Backup isolation. Backups stored on network segments reachable from production systems are routinely targeted before encryption begins. Offline or immutable copies are the functional alternative.
- Restoration testing cadence. A backup that has never been tested for full-system restoration is not a reliable recovery asset. Testing frequency should match the pace at which clinical systems change.
- Downtime procedures. Healthcare entities are required under the HIPAA Security Rule to maintain documented contingency plans, including emergency-mode operation procedures. Many organizations have these on paper but have not rehearsed them against a realistic extended-outage scenario.
- Legal review of payment authority. Decision-making chains for ransom payment — including who can authorize, what legal review is required, and what sanctions screening must occur — should be documented before an incident, not improvised during one.
What the next 12 months likely bring
The combination of rising median demands, near-50-percent payment rates, and accelerating international prohibition efforts suggests the current equilibrium will not hold. Healthcare organizations that treat payment as a viable backstop are exposed to a policy environment that may remove that option on short notice. The more durable approach is investing in recovery capability — backup integrity, tested restoration, and practiced downtime operations — sufficient to make payment unnecessary, regardless of what any given jurisdiction ultimately decides.