Ransomware victims are increasingly caught between rising financial pressure and shifting legal ground. Research published in 2025 by cybersecurity group Sophos found that roughly half of organizations hit by ransomware ultimately paid their attackers, even as median demand amounts continued to climb. Governments in the UK and other jurisdictions are now moving to ban payments outright, a regulatory posture that would force a fundamental rethink of incident response planning — particularly for healthcare entities that cannot afford extended system outages.
The payment calculus is getting harder to solve
The Sophos figures reflect a market dynamic that compliance officers in healthcare know well: when clinical operations depend on systems being restored within hours, the abstract argument against paying becomes very concrete very fast. Downtime at a hospital or specialty practice is not merely a business disruption — it affects patient scheduling, medication management, and in acute settings, direct care delivery.
At the same time, payment does not guarantee recovery. Threat actors have delivered corrupted or incomplete decryption keys, and paying one group does not prevent a second actor from deploying a separate payload if the original intrusion vector was not closed. The median ransom figure rising alongside the payment rate suggests attackers are calibrating demands to what the market will bear, not to what victims can comfortably absorb.
Government intervention is reshaping the decision tree
The UK's reported move toward prohibiting ransom payments is the most visible example of a broader regulatory pattern. Australia has signaled similar intent. In the United States, no federal payment ban is currently in force, but the Office of Foreign Assets Control has long warned that payments routed to sanctioned entities — including several ransomware groups — can carry civil liability regardless of intent. That risk layer already complicates the pay-or-not analysis for any US-based healthcare organization.
A formal payment ban, if it reaches the US, would shift incident response doctrine significantly. Organizations could no longer treat payment as a recovery backstop and would need to demonstrate — to regulators, insurers, and patients — that backup and restoration capabilities are sufficient to make payment unnecessary. OCR's existing HIPAA Security Rule requirements around contingency planning and data backup already point in that direction, but enforcement attention on those controls has been uneven.
What independent practices should check now
Independent practices tend to have less redundancy than large health systems, making the stakes of a ransomware event proportionally higher. Several structural gaps show up repeatedly in post-incident reviews:
- Backup integrity testing. Backups that are never restored in a test environment are of unknown value when a real event occurs. Scheduled restoration drills, documented and dated, are the baseline standard.
- Network segmentation. Flat networks allow ransomware to move laterally from an infected workstation to the systems where patient records and billing data reside. Logical separation of clinical, administrative, and backup infrastructure limits blast radius.
- Incident response planning with legal counsel. The payment decision should not be made in the middle of an event. Pre-event planning that includes legal review of OFAC obligations, cyber insurance coverage terms, and breach notification timelines removes improvisation from a moment when clear thinking is hardest.
- Cyber insurance review. Some policies have begun excluding coverage for ransom payments to sanctioned groups. Practices should review their current policy language for exclusions and sublimits that may not have been present when coverage was first purchased.
What this signals about the next 12 months
If the UK ban advances and other jurisdictions follow, US pressure for similar legislation will grow — and the healthcare sector will be central to that debate because of its demonstrated vulnerability. Regulators will likely cite the sector's payment rate as evidence that voluntary market discipline has failed. That sets up a scenario in which compliance with a payment prohibition becomes a new HIPAA-adjacent obligation, layered on top of existing Security Rule requirements, rather than a separate policy conversation.
For practices not already conducting annual security risk analyses with specific attention to ransomware scenarios, the gap between current practice and where regulatory expectations are heading is widening.