Nearly half of organizations hit by ransomware attacks paid the demanded ransom in 2025, according to research published by cybersecurity group Sophos, and the median ransom demand continued to climb. At the same time, regulators in multiple countries are moving to make those payments illegal — a convergence that puts healthcare organizations, which remain among the most targeted sectors, in an increasingly difficult position when an attack occurs.
The payment calculus is shifting
For years, the decision to pay or not pay after a ransomware attack has been treated primarily as a financial and operational question: weigh the cost of downtime against the cost of the demand, factor in the probability that the attacker delivers a working decryption key, and choose accordingly. That framing is becoming obsolete.
Sophos data puts the payment rate at close to 47 percent globally. The median demand amount has risen year over year. But the more significant change is external: governments are beginning to treat ransom payments as a structural problem, not an individual business decision, on the grounds that each payment funds the next attack.
The UK is among the jurisdictions examining payment prohibitions or mandatory reporting requirements tied to payments. Proposals vary in scope — some would ban payments outright by organizations receiving public funds, others would require government notification before any payment is made — but the direction of travel is consistent.
What this means for healthcare specifically
Healthcare organizations operate under constraints that make the payment question especially fraught. Clinical systems disruption is not an abstract cost; delayed care carries direct patient safety consequences. That operational pressure has historically made healthcare a preferred target precisely because the urgency to restore systems is higher than in most other sectors.
A payment ban, or a mandatory pre-payment notification requirement, changes the incident timeline. An organization that previously could resolve an attack quietly and quickly would instead face a regulatory checkpoint — potentially including OCR notification obligations that already exist under HIPAA, layered on top of any new payment-reporting requirement.
Independent practices are particularly exposed here. Large health systems typically retain outside counsel and incident response firms on retainer. Smaller organizations often make real-time decisions about payment without legal or regulatory guidance, under system outage conditions, with limited awareness of what their obligations are in the moment.
Where incident response planning needs to catch up
The Sophos findings and the emerging legislative environment together identify a gap in how many organizations approach ransomware preparation. Most tabletop exercises focus on technical recovery: restoring from backup, isolating affected systems, rebuilding network segments. Fewer exercises walk through the legal and regulatory decision tree that now accompanies those technical steps.
- Payment legality review. Before an attack, legal counsel should document which jurisdictions' rules apply to the organization, including any rules that may apply to business associates or parent entities in other countries.
- Notification sequencing. HIPAA breach notification timelines do not pause during a ransomware event. Incident response plans should map OCR notification obligations against the operational response timeline, not treat them as a post-recovery task.
- Backup integrity verification. The viability of a no-payment decision depends almost entirely on whether tested, air-gapped or immutable backups exist and can be restored within a clinically acceptable timeframe. Organizations that cannot answer that question before an attack will be making the payment decision under the worst possible conditions.
- Cyber insurance alignment. Many policies have begun to restrict or exclude ransom payment coverage in anticipation of regulatory changes. Coverage terms should be reviewed annually, not at renewal only.
What the next 12 months look like
Legislative activity in the UK and other jurisdictions tends to accelerate US regulatory thinking, particularly at the HHS and CISA level, where cross-border threat intelligence is shared routinely. A formal US payment-reporting mandate — which CISA has already piloted in a more limited form through its cyber incident reporting framework — is a plausible near-term development, independent of whether an outright ban advances.
For compliance officers at independent practices, the practical implication is that ransomware response can no longer be treated as an IT-only problem resolved before anyone calls a lawyer. The decision tree now includes regulatory, legal, and potentially criminal dimensions that require documented procedures developed before the event, not improvised during it.