Roughly half of organizations hit by ransomware end up paying the ransom, according to 2025 research from cybersecurity group Sophos — and the median amount demanded continues to rise. That dynamic is now drawing a regulatory response: governments in the UK and other jurisdictions are examining or moving toward outright payment bans, a policy shift that would fundamentally alter the calculus for healthcare organizations that have historically treated payment as a last-resort recovery option.

The payment dilemma as it stands

For healthcare organizations — where system downtime translates directly into delayed care, diverted patients, and disrupted medication management — the pressure to pay is structural rather than financial. When clinical workflows depend on locked systems, administrative leadership faces a recovery timeline measured in weeks if they decline, often against a ransom demand that can be resolved in days.

Sophos data shows that payment rates have remained stubbornly high despite years of law-enforcement guidance discouraging the practice. The median demand itself has increased, meaning that even organizations that budget for worst-case scenarios may find prior estimates obsolete. For independent and community hospitals with thin operating margins, the gap between "what we prepared for" and "what attackers are asking" is widening.

What payment bans would mean for covered entities

A prohibition on ransom payments — whether enacted by a national government or, eventually, a US federal or state body — would remove the payment option entirely, making pre-incident preparation the only viable strategy. Healthcare covered entities and their business associates would face a binary outcome: either systems are recoverable from their own backups and continuity plans, or operations remain offline until manual workarounds or vendor-assisted restoration can take hold.

The UK's evolving policy discussion is particularly relevant for US-based health systems that operate international entities, share vendors with UK-based partners, or use technology platforms with UK regulatory exposure. A payment ban applied to a parent organization or shared IT vendor could cascade to US affiliates even before any American legislation moves.

Where this lands for independent practices

Three areas warrant immediate attention for compliance officers and practice administrators:

What this signals for the next 12 months

Payment bans, if adopted broadly, will not reduce the frequency of ransomware attacks against healthcare targets — threat actors will continue targeting the sector because of the data value and operational urgency. What bans do is eliminate the shortcut that has allowed underprepared organizations to buy their way back to operation. The policy pressure is therefore also a compliance pressure: regulators signaling that payment is impermissible are, implicitly, signaling that resilience is mandatory.

OCR's HIPAA Security Rule updates finalized earlier in 2025 already reflect a harder line on technical safeguard specificity, including requirements around data backup and contingency planning. The international policy trajectory on payment bans suggests that American rulemaking may eventually follow. Practices that treat resilience investment as optional are making a bet that the regulatory environment will stay static — a bet that current evidence does not support.