Roughly half of organizations hit by ransomware end up paying the ransom, according to 2025 research from cybersecurity group Sophos — and the median amount demanded continues to rise. That dynamic is now drawing a regulatory response: governments in the UK and other jurisdictions are examining or moving toward outright payment bans, a policy shift that would fundamentally alter the calculus for healthcare organizations that have historically treated payment as a last-resort recovery option.
The payment dilemma as it stands
For healthcare organizations — where system downtime translates directly into delayed care, diverted patients, and disrupted medication management — the pressure to pay is structural rather than financial. When clinical workflows depend on locked systems, administrative leadership faces a recovery timeline measured in weeks if they decline, often against a ransom demand that can be resolved in days.
Sophos data shows that payment rates have remained stubbornly high despite years of law-enforcement guidance discouraging the practice. The median demand itself has increased, meaning that even organizations that budget for worst-case scenarios may find prior estimates obsolete. For independent and community hospitals with thin operating margins, the gap between "what we prepared for" and "what attackers are asking" is widening.
What payment bans would mean for covered entities
A prohibition on ransom payments — whether enacted by a national government or, eventually, a US federal or state body — would remove the payment option entirely, making pre-incident preparation the only viable strategy. Healthcare covered entities and their business associates would face a binary outcome: either systems are recoverable from their own backups and continuity plans, or operations remain offline until manual workarounds or vendor-assisted restoration can take hold.
The UK's evolving policy discussion is particularly relevant for US-based health systems that operate international entities, share vendors with UK-based partners, or use technology platforms with UK regulatory exposure. A payment ban applied to a parent organization or shared IT vendor could cascade to US affiliates even before any American legislation moves.
Where this lands for independent practices
Three areas warrant immediate attention for compliance officers and practice administrators:
- Backup integrity and isolation. Offline or immutable backup systems that attackers cannot reach through the same network they encrypted are the foundation of any no-payment recovery plan. Periodic restoration tests — not just backup confirmation — determine whether those systems will actually function when needed.
- Downtime procedures. Paper-based and manual clinical workflows need to be documented, trained, and periodically exercised. Ransomware events that stretch past 72 hours expose practices that have never rehearsed operating without EHR access.
- Incident response planning that accounts for regulatory exposure. OCR breach notification timelines do not pause during a ransomware event. Practices need legal counsel and a notification workflow that can run in parallel with technical recovery, regardless of whether a payment decision is on the table.
What this signals for the next 12 months
Payment bans, if adopted broadly, will not reduce the frequency of ransomware attacks against healthcare targets — threat actors will continue targeting the sector because of the data value and operational urgency. What bans do is eliminate the shortcut that has allowed underprepared organizations to buy their way back to operation. The policy pressure is therefore also a compliance pressure: regulators signaling that payment is impermissible are, implicitly, signaling that resilience is mandatory.
OCR's HIPAA Security Rule updates finalized earlier in 2025 already reflect a harder line on technical safeguard specificity, including requirements around data backup and contingency planning. The international policy trajectory on payment bans suggests that American rulemaking may eventually follow. Practices that treat resilience investment as optional are making a bet that the regulatory environment will stay static — a bet that current evidence does not support.