Ransomware attacks are generating higher ransom demands and a near-coin-flip compliance rate among victims, according to 2025 research from Sophos cited in a DataBreaches.net analysis published Monday. The finding arrives as regulators in several countries are weighing or enacting bans on ransom payments — a policy shift that would reshape the calculus for every healthcare organization that has historically treated payment as a recovery option.

The payment math that is driving policy

Sophos data shows that roughly 48 percent of ransomware victims ultimately pay. The median demanded amount has climbed year over year, though actual payments often land below the opening demand after negotiation. For healthcare organizations, the stakes are higher than the ransom figure alone: downtime that disrupts clinical operations, potential HIPAA breach notification obligations, and reputational exposure to patients and payers all factor into the decision.

The tension between paying quickly to restore systems and refusing on principle — or because of legal exposure — is not new. What has changed is the regulatory environment around that choice.

Payment bans and what they would mean

The United Kingdom is among the jurisdictions examining or advancing restrictions on ransom payments to cybercriminals. A ban would eliminate payment as a recovery path and force organizations to rely entirely on backup restoration, law enforcement coordination, and incident response capabilities built before an attack occurs.

For US healthcare practices, no federal prohibition currently exists, though the Treasury Department's Office of Foreign Assets Control (OFAC) has long warned that paying groups on sanctions lists can carry civil liability regardless of intent. Any movement toward a statutory ban — whether at federal or state level — would change that risk profile dramatically, converting a bad operational option into a potentially illegal one.

Healthcare administrators should treat a payment ban as a realistic planning scenario now, not a distant hypothetical.

What the pressure on victims reveals about preparation gaps

The high payment rate reflects, in part, the consequences of inadequate backup discipline and slow detection. Organizations that pay are frequently doing so because restoration from clean backups is not viable — either because backups were not maintained, were encrypted alongside production data, or would take longer to restore than the organization can sustain operationally.

Several preparation categories reduce the likelihood of reaching that decision point:

What this signals about the next 12 months

The combination of rising demands, a near-majority payment rate, and emerging payment prohibitions suggests that ransomware defense will face increasing regulatory scrutiny alongside the threat itself. Healthcare organizations that have deferred tabletop exercises, backup architecture reviews, or incident response planning will find the window for low-pressure preparation shrinking.

OCR has consistently cited lack of contingency planning as one of the most common deficiencies identified during breach investigations. If payment bans advance, that deficiency category will carry consequences beyond a HIPAA corrective action plan.