Nearly half of organizations hit by ransomware paid their attackers in 2025, according to research from cybersecurity firm Sophos, and the median amount demanded continues to rise. At the same time, governments in multiple jurisdictions — including the United Kingdom — are moving to ban ransom payments entirely, a shift that would force healthcare entities to absorb operational disruption rather than buy their way out of it. The collision of rising extortion pressure and tightening legal constraints is creating a decision calculus that independent practices are poorly positioned to handle without preparation.
The payment pressure is getting worse
Sophos data shows that roughly 49 percent of ransomware victims submitted to payment demands in 2025. In healthcare, where clinical continuity is directly tied to system availability, the pull toward payment has historically been stronger than in other sectors. Hospitals and practices have cited patient safety as a rationale for paying quickly, and threat actors have exploited that leverage deliberately — timing attacks to maximize disruption and accelerate the decision.
The rising median demand compounds the problem. Organizations that might have absorbed a smaller payment in prior years now face demands that can exceed their cyber insurance policy limits, force liquidity decisions, or trigger board-level involvement that smaller practices simply lack the governance structure to manage under time pressure.
Payment bans are reshaping the legal environment
The UK's proposed prohibition on ransom payments is the most prominent current example of a government attempting to remove payment as a viable option. The theory is straightforward: if attackers cannot collect, the economic model breaks down. The practical effect for healthcare operators is that paying could itself become a legal violation, not merely a reputational or ethical problem.
The United States has not enacted a blanket federal payment ban, but the Office of Foreign Assets Control has long prohibited payments to sanctioned entities, and Treasury has issued guidance making clear that paying a sanctioned group — even unknowingly — can result in enforcement action. Any expansion of that framework, or adoption of UK-style prohibitions at the state level, would close off an option that many smaller healthcare organizations currently treat as a fallback.
What this means for independent practices
The combination of rising demands and narrowing legal permission to pay places new weight on pre-incident preparation. For a small or mid-size practice, the relevant questions are concrete:
- Offline backup integrity. Whether a practice can restore from a clean backup without paying depends entirely on whether those backups exist, are tested regularly, and are isolated from the production environment that attackers encrypt.
- Incident response agreements. A practice that has never contracted with a forensic response firm will spend the first critical hours searching for one. Pre-arranged agreements reduce that delay.
- Insurance policy terms. Many cyber policies have added sub-limits or exclusions for ransom payments, or condition coverage on demonstrating pre-incident controls. Practices should review current policy language before an event, not after.
- Legal counsel familiar with OFAC. If a payment is being considered, legal review of whether the attacker has been sanctioned is not optional under current Treasury guidance.
What the next 12 months may look like
The regulatory direction is clear even if the pace is uncertain: payment is becoming a less available and more legally fraught option. Threat actors are aware of this dynamic and are expected to increase pressure tactics — publishing stolen data, contacting patients directly, or threatening regulatory self-reporting — to preserve their leverage as the payment channel tightens. Healthcare organizations that have not built operational resilience into their incident response plans are the most exposed to that pressure, because they have the fewest alternatives when systems go down.