Nearly half of organizations hit by ransomware end up paying to recover their data or restore operations, according to 2025 research from Sophos, and the median amount demanded continues to rise. The trend is drawing legislative attention in several countries, including the United Kingdom, where policymakers are debating whether to prohibit ransom payments entirely — a move that would force victim organizations to find other paths to recovery regardless of the operational cost.

The payment calculus healthcare operators face

For hospitals, clinics, and independent practices, the decision to pay or not is rarely simple accounting. Downtime that prevents access to electronic health records, laboratory results, or prescription systems translates directly into care disruption and patient safety exposure. Organizations weighing a payment are simultaneously managing regulatory obligations under HIPAA, potential breach-notification timelines, and the practical question of whether decryption keys, when supplied, actually work.

Sophos data from prior years has consistently shown that paying does not reliably accelerate recovery. Organizations that paid still faced lengthy restoration periods, in part because decryption is only one step in rebuilding systems that may be partially corrupted or backdoored. The rising median demand suggests attackers have absorbed that lesson and are pricing accordingly.

What payment bans would mean in practice

The UK debate reflects a broader policy argument: that ransom payments sustain the criminal ecosystem by guaranteeing revenue. Jurisdictions that ban payments would effectively remove the financial option, pushing organizations toward backup restoration, manual operations, or negotiated law-enforcement intervention.

For US healthcare entities, no federal ban is currently in place, though Treasury's Office of Foreign Assets Control has long prohibited payments to sanctioned entities — a category that includes several prolific ransomware groups. A full payment prohibition at the federal or state level would change the calculus significantly, because it would shift the entire burden of recovery planning onto operational resilience rather than financial fallback.

What this signals for independent practices

Smaller healthcare practices often operate with thinner IT resources than health systems and are proportionally more exposed to extended downtime. The Sophos data, combined with the legislative direction visible in the UK, suggests that regulators and insurers in the US may move in a similar direction over the next several years.

Practices that have not recently tested their backup restoration procedures — not just confirmed that backups exist, but run a timed, documented test of restoring clinical systems from those backups — are carrying more risk than the current threat environment warrants. The same applies to incident response planning: a written plan that has never been exercised provides limited operational value when systems go down at 2 a.m. on a weekend.

The broader pattern from the Sophos research is that ransomware operators have refined their targeting and pricing. Healthcare remains a preferred sector because downtime carries patient safety stakes that accelerate the payment decision. Understanding that dynamic — and building recovery capability that does not depend on paying — is increasingly the expected standard, not an optional enhancement.