Ransomware attackers are extracting payments from a larger share of victims even as governments in multiple jurisdictions move to prohibit those payments entirely, according to 2025 research from Sophos cited by DataBreaches.net. For healthcare organizations — which remain among the most frequently targeted sectors and face the steepest operational consequences from system downtime — the trend puts compliance officers and practice administrators in a genuinely difficult position.

The payment calculus is shifting

Sophos data puts the share of ransomware victims that ultimately pay a ransom at close to half, and median demand figures have continued to climb. The decision to pay has never been straightforward, but the variables are multiplying. Encrypted or exfiltrated patient records create pressure to restore access quickly; extended EHR or clinical-system downtime directly affects care delivery in ways that a retail or financial-services outage does not.

At the same time, payment does not guarantee recovery. Decryptors provided by threat actors routinely fail to restore all affected systems, and paying establishes an organization as a compliant target for repeat attacks. Research across multiple data sets shows that a significant portion of organizations that pay are hit again within twelve months.

The regulatory response: payment bans

The UK is among the jurisdictions moving toward a formal prohibition on ransomware payments by certain categories of organizations. The policy logic is straightforward: if payments stop flowing, the financial model that sustains ransomware operations degrades. Critics argue that banning payments without providing organizations a credible path to rapid recovery simply transfers the cost of the attack from the threat actor's wallet to the victim's operations.

For US healthcare organizations, no federal payment ban is currently in force, but the Office of Foreign Assets Control (OFAC) already prohibits payments to sanctioned threat actor groups — a list that has expanded as law enforcement attributes more attacks to state-linked actors. Healthcare organizations that pay a ransom without first screening the recipient against OFAC's sanctions list face potential civil liability regardless of whether the payment itself restored their systems.

What this signals for independent practices

The gap between large health systems and independent practices is particularly acute here. Large systems typically carry cyber-insurance policies with incident-response retainers, legal counsel experienced in ransomware negotiations, and dedicated IT staff who can assess decryptor reliability before a payment decision is made. Independent practices rarely have any of those resources on standby.

Several preparation disciplines directly affect how a practice fares when an attack occurs:

What the next 12 months may bring

If payment-ban legislation advances in the UK and similar proposals gain traction in other jurisdictions, US policymakers will face renewed pressure to follow. HHS has signaled interest in stronger cybersecurity requirements for covered entities and business associates through its proposed updates to the HIPAA Security Rule; mandatory minimum controls — rather than payment restrictions — appear to be the near-term federal approach. But the international trajectory is worth watching: US-headquartered health systems with offshore operations or vendors operating in multiple markets may find themselves subject to conflicting legal obligations if a ban takes effect abroad while US law remains permissive.

For now, the most durable protection remains the same one it has been: making the cost of an attack high enough — through rapid detection, effective isolation, and tested recovery capability — that a payment decision never has to be made at all.