Nearly half of organizations hit by ransomware paid a ransom in 2025, according to research from cybersecurity group Sophos, and the median amount demanded has continued to climb. The finding arrives as governments in the UK and other jurisdictions are debating — or actively advancing — legislation that would prohibit ransom payments outright, a shift that would fundamentally alter how healthcare organizations respond to an attack.

The payment calculus is getting harder

For years, the decision to pay or refuse a ransom has been treated as a situational judgment call: weigh recovery costs against ransom amount, factor in data exposure risk, consult legal counsel, and decide. That framework is eroding on two fronts.

On one side, ransomware operators have grown more sophisticated in their pricing strategies, setting demands that are calibrated to what victims can realistically pay rather than arbitrary figures. The result is that even organizations with cyber-insurance coverage are finding that policies do not fully absorb the financial impact.

On the other side, the emerging legislative push toward payment bans removes the option entirely, regardless of circumstance. A practice facing encrypted patient records and a non-functional EHR would have no legal path to paying for a decryption key — making pre-incident resilience the only viable strategy.

What payment ban legislation would mean for healthcare

Healthcare is a frequent ransomware target precisely because downtime is a patient-safety issue, not merely an operational inconvenience. That reality has historically made payment a tempting short-term solution: restore systems, resume care, deal with the regulatory fallout later.

A payment ban changes that math in several ways:

The US has not enacted a federal payment ban, but the legislative conversation in allied jurisdictions tends to inform domestic policy over a two-to-four year horizon. Several states have also floated restrictions on ransomware payments by government entities, and that framing sometimes extends to heavily regulated private sectors.

Where independent practices are most exposed

Independent and small-group practices occupy a particularly difficult position in this environment. They lack the incident-response infrastructure of large health systems, often carry lower cyber-insurance limits, and may have backup configurations that have not been validated under realistic failure conditions.

The Sophos data suggests that the organizations most likely to pay are those with the least recovery capacity — which describes a large share of independent healthcare providers. A payment ban would hit those organizations hardest, because the decision to pay is often driven by an absence of alternatives rather than a preference.

Practices should treat the current regulatory discussion as an operational signal: the window to build genuine recovery capability — verified backups, tested restoration procedures, documented downtime workflows — is open now. If payment prohibitions reach the US, organizations that waited will face a crisis without any financial shortcut available.

What this signals about the next 12 months

The global direction of travel on ransomware payments is toward restriction, not tolerance. Even without a US federal ban, the reputational and regulatory environment around paying ransoms is shifting. HHS guidance already discourages payments and notes that paying does not guarantee recovery or eliminate breach-notification obligations.

Practices that have deferred investments in air-gapped or immutable backup systems, incident response planning, and tabletop exercises should treat the current period as the last comfortable window before the policy environment hardens. The Sophos research confirms that attackers are not reducing pressure; the question is whether defenders are building the capacity to refuse.