Nearly half of organizations hit by ransomware end up paying to recover their data or restore operations, according to 2025 research from Sophos, and the median amount demanded continues to rise. The trend is drawing legislative attention in several countries, including the United Kingdom, where policymakers are debating whether to prohibit ransom payments entirely — a move that would force victim organizations to find other paths to recovery regardless of the operational cost.
The payment calculus healthcare operators face
For hospitals, clinics, and independent practices, the decision to pay or not is rarely simple accounting. Downtime that prevents access to electronic health records, laboratory results, or prescription systems translates directly into care disruption and patient safety exposure. Organizations weighing a payment are simultaneously managing regulatory obligations under HIPAA, potential breach-notification timelines, and the practical question of whether decryption keys, when supplied, actually work.
Sophos data from prior years has consistently shown that paying does not reliably accelerate recovery. Organizations that paid still faced lengthy restoration periods, in part because decryption is only one step in rebuilding systems that may be partially corrupted or backdoored. The rising median demand suggests attackers have absorbed that lesson and are pricing accordingly.
What payment bans would mean in practice
The UK debate reflects a broader policy argument: that ransom payments sustain the criminal ecosystem by guaranteeing revenue. Jurisdictions that ban payments would effectively remove the financial option, pushing organizations toward backup restoration, manual operations, or negotiated law-enforcement intervention.
For US healthcare entities, no federal ban is currently in place, though Treasury's Office of Foreign Assets Control has long prohibited payments to sanctioned entities — a category that includes several prolific ransomware groups. A full payment prohibition at the federal or state level would change the calculus significantly, because it would shift the entire burden of recovery planning onto operational resilience rather than financial fallback.
- Backup integrity becomes the primary control. If payment is unavailable or prohibited, the speed and completeness of recovery depends entirely on whether offline or immutable backups exist and have been tested against realistic restore scenarios.
- Incident response retainers take on new weight. Pre-negotiated access to forensic and recovery expertise shortens the window between attack detection and the start of restoration, which matters more when payment is not an option.
- Cyber insurance terms are shifting. Several carriers have added policy language that limits coverage for ransom payments to sanctioned groups or conditions reimbursement on proof that payment alternatives were exhausted first.
What this signals for independent practices
Smaller healthcare practices often operate with thinner IT resources than health systems and are proportionally more exposed to extended downtime. The Sophos data, combined with the legislative direction visible in the UK, suggests that regulators and insurers in the US may move in a similar direction over the next several years.
Practices that have not recently tested their backup restoration procedures — not just confirmed that backups exist, but run a timed, documented test of restoring clinical systems from those backups — are carrying more risk than the current threat environment warrants. The same applies to incident response planning: a written plan that has never been exercised provides limited operational value when systems go down at 2 a.m. on a weekend.
The broader pattern from the Sophos research is that ransomware operators have refined their targeting and pricing. Healthcare remains a preferred sector because downtime carries patient safety stakes that accelerate the payment decision. Understanding that dynamic — and building recovery capability that does not depend on paying — is increasingly the expected standard, not an optional enhancement.