A 2025 Sophos study found that close to half of organizations hit by ransomware ultimately paid the demanded ransom, and median demand figures are rising. That pattern is drawing legislative attention in multiple countries, with some jurisdictions moving toward outright payment prohibitions — a development that would force healthcare organizations to harden their defenses well before an incident occurs rather than treating payment as a backstop option.
The payment calculus is shifting
For years, ransom payment has functioned as an informal insurance mechanism. When backups fail, recovery timelines stretch, and clinical operations stall, finance and operations leaders often calculate that payment is cheaper than prolonged downtime. Sophos data suggests that calculus remains common: roughly one in two victims pays.
The problem is that payment does not reliably restore operations. Decryption tools provided by ransomware groups are frequently slow, incomplete, or damage data in transit. Organizations that pay also tend to be re-targeted at higher rates, because successful extortion marks them as likely payers in criminal forums.
For healthcare specifically, the stakes extend beyond financial loss. Delayed access to patient records, diverted ambulances, and canceled procedures represent patient-safety events, not merely business disruptions.
What payment bans would mean in practice
The UK is among the jurisdictions examining restrictions on ransomware payments. A ban would not eliminate the threat — attackers would continue targeting healthcare systems — but it would remove the financial incentive that currently sustains the ransomware-as-a-service economy. It would also remove the option that many smaller and mid-sized practices currently treat as a last resort.
Under a payment-prohibition regime, organizations that lack tested backups, segmented networks, or offline recovery capability would face only one path: extended outage. For independent practices operating on thin margins and minimal IT staff, that exposure is severe.
Any US policy movement in a similar direction — whether federal legislation or sector-specific HHS guidance — would require healthcare organizations to demonstrate recovery capability rather than rely on payment as an emergency measure. That would shift compliance from a documentation exercise to an operational one.
Where independent practices are most exposed
Independent and small-group practices face a particular set of structural disadvantages in a no-payment environment:
- Backup discipline. Many practices maintain backups but do not test restoration regularly. An untested backup is not a recovery plan; it is an assumption.
- Network segmentation. Flat networks allow ransomware to spread laterally from a single compromised workstation to every system, including EHR servers and billing platforms. Segmentation limits blast radius.
- Incident response planning. Practices without a documented and rehearsed incident response plan typically improvise under pressure, which extends downtime and increases the probability of data exfiltration going undetected.
- Cyber insurance coordination. Many cyber insurance policies include provisions about payment decisions and notification timelines. Practices should confirm what their policies require before an incident, not during one.
What this signals about the next 12 months
The combination of rising demand amounts and growing political pressure against payments suggests the window for treating ransomware payment as an informal recovery option is narrowing. Healthcare organizations that have deferred investment in offline backup infrastructure, endpoint detection, and tested recovery playbooks are accepting a level of operational risk that regulatory and insurance markets are beginning to price more explicitly.
OCR's existing HIPAA Security Rule already requires covered entities to maintain contingency plans, including data backup and disaster recovery procedures. The practical question enforcement has rarely forced is whether those plans actually work. A payment-ban environment would make that question unavoidable.