A 2025 Sophos study found that close to half of organizations hit by ransomware ultimately paid the demanded ransom, and median demand figures are rising. That pattern is drawing legislative attention in multiple countries, with some jurisdictions moving toward outright payment prohibitions — a development that would force healthcare organizations to harden their defenses well before an incident occurs rather than treating payment as a backstop option.

The payment calculus is shifting

For years, ransom payment has functioned as an informal insurance mechanism. When backups fail, recovery timelines stretch, and clinical operations stall, finance and operations leaders often calculate that payment is cheaper than prolonged downtime. Sophos data suggests that calculus remains common: roughly one in two victims pays.

The problem is that payment does not reliably restore operations. Decryption tools provided by ransomware groups are frequently slow, incomplete, or damage data in transit. Organizations that pay also tend to be re-targeted at higher rates, because successful extortion marks them as likely payers in criminal forums.

For healthcare specifically, the stakes extend beyond financial loss. Delayed access to patient records, diverted ambulances, and canceled procedures represent patient-safety events, not merely business disruptions.

What payment bans would mean in practice

The UK is among the jurisdictions examining restrictions on ransomware payments. A ban would not eliminate the threat — attackers would continue targeting healthcare systems — but it would remove the financial incentive that currently sustains the ransomware-as-a-service economy. It would also remove the option that many smaller and mid-sized practices currently treat as a last resort.

Under a payment-prohibition regime, organizations that lack tested backups, segmented networks, or offline recovery capability would face only one path: extended outage. For independent practices operating on thin margins and minimal IT staff, that exposure is severe.

Any US policy movement in a similar direction — whether federal legislation or sector-specific HHS guidance — would require healthcare organizations to demonstrate recovery capability rather than rely on payment as an emergency measure. That would shift compliance from a documentation exercise to an operational one.

Where independent practices are most exposed

Independent and small-group practices face a particular set of structural disadvantages in a no-payment environment:

What this signals about the next 12 months

The combination of rising demand amounts and growing political pressure against payments suggests the window for treating ransomware payment as an informal recovery option is narrowing. Healthcare organizations that have deferred investment in offline backup infrastructure, endpoint detection, and tested recovery playbooks are accepting a level of operational risk that regulatory and insurance markets are beginning to price more explicitly.

OCR's existing HIPAA Security Rule already requires covered entities to maintain contingency plans, including data backup and disaster recovery procedures. The practical question enforcement has rarely forced is whether those plans actually work. A payment-ban environment would make that question unavoidable.