Nearly half of organizations hit by ransomware end up paying the demanded ransom, according to 2025 research from Sophos, and the median demand amount continues to rise. That finding arrives as a growing number of governments consider or enact outright bans on ransom payments — a policy shift that would force healthcare organizations to absorb the full operational and financial cost of an attack rather than negotiate an exit.
The payment calculus
For healthcare targets, the decision to pay or not rarely comes down to money alone. Downtime in a clinical environment carries patient-safety consequences that have no direct equivalent in retail or financial services. When electronic health records, imaging systems, or pharmacy dispensing software go dark, administrators face pressure that has nothing to do with the ransom figure on the screen.
Sophos data shows the median ransom demand has grown year-over-year, and healthcare has consistently ranked among the sectors with the highest average recovery costs — driven not just by any potential payment but by the labor, hardware, and third-party forensics required to restore operations afterward. Organizations that do pay often discover that decryption tools supplied by attackers are slow or incomplete, meaning downtime extends regardless.
What payment bans would change
The UK is among the jurisdictions examining legislation that would prohibit ransom payments, at least for critical infrastructure operators. Similar proposals have circulated in Australia and, at the state level, in the United States. The intent is to reduce the financial return that funds continued criminal operations, but critics argue the policy shifts all residual cost onto victims without addressing the underlying vulnerabilities that made an attack possible.
For US healthcare practices, a federal or state payment ban would carry specific compliance dimensions. Paying a ransom to a sanctioned entity already violates Treasury Department rules regardless of any cybercrime-specific legislation, and OCR has made clear that a ransomware incident is presumed to constitute a HIPAA breach unless the covered entity can demonstrate otherwise. A formal payment prohibition would add a third regulatory layer to an event that already triggers breach notification, potential OCR investigation, and state attorney general scrutiny.
Where this lands for independent practices
Smaller and independent practices tend to have thinner margins, fewer redundant systems, and less experienced incident-response capability than health systems. That combination makes them statistically more likely to pay — and more likely to suffer extended downtime even after paying. Several points deserve attention now, before an incident occurs:
- Offline backups tested for restoration — backup systems that are connected to the same network as production systems are routinely encrypted alongside primary data; air-gapped or immutable backups remain the most reliable recovery path.
- Incident response plans that specify a payment decision process — waiting until an attack is underway to determine who has authority to authorize payment, which legal counsel to engage, and which law enforcement contacts to notify adds days to an already compressed timeline.
- Cyber insurance policy language — many policies have shifted to exclude or cap ransom reimbursements; coverage terms should be reviewed annually and well before a claim is needed.
- OFAC screening obligations — any payment decision must include a check of Treasury's Specially Designated Nationals list; paying a sanctioned group can result in civil penalties even when the payment was made under duress.
What the next 12 months may bring
The policy environment is moving faster than the threat environment is improving. If a major jurisdiction enacts a payment ban that applies to healthcare, affected organizations will need documentation showing they had functioning alternatives to payment — meaning recovery capabilities, tested backups, and response plans. The shift also increases pressure on federal regulators to clarify how the HIPAA Security Rule's contingency planning requirements map to current ransomware scenarios, a question OCR has addressed in guidance but not in updated rule text.
Practices that treat ransomware preparedness as a periodic checklist item rather than an operational discipline are exposed on two fronts: the attack itself, and the regulatory scrutiny that follows it.