Nearly half of ransomware victims pay their attackers, according to 2025 research from cybersecurity group Sophos, and the median amount demanded continues to climb. At the same time, regulators in the UK and several other jurisdictions are moving to prohibit ransom payments entirely — a policy shift that would remove the option many organizations currently treat as a last resort. For healthcare entities, which hold high-value patient data and often face acute operational pressure to restore systems quickly, the convergence of rising costs and potential payment bans demands a clear-eyed review of existing incident response plans.

The payment calculus is shifting

Sophos's research places the payment rate at roughly 49 percent across industries. Healthcare has historically skewed higher, in part because downtime that affects clinical systems carries direct patient-safety consequences that most sectors do not face. That operational urgency gives attackers leverage when setting demand amounts, and it helps explain why healthcare organizations have been disproportionately targeted in recent ransomware campaigns.

The rising median demand reflects a broader maturation of the ransomware-as-a-service economy. Affiliate groups that carry out attacks now negotiate with greater sophistication, often conducting pre-attack reconnaissance to estimate what a target organization can afford to pay before setting an opening figure.

Jurisdictions are moving toward payment prohibition

The UK is among the governments examining legislation that would ban ransom payments to known threat actors. Similar discussions are underway in Australia and have been aired in US congressional hearings, though no federal prohibition has passed as of this writing. Some proposals include mandatory disclosure of any payment, intended both to dry up attacker revenue and to give regulators better data on the scope of the problem.

For covered entities and business associates operating under HIPAA, a federal payment ban would layer new legal exposure on top of existing breach-notification obligations. Organizations that currently factor payment as a contingency option in their incident response plans may find that option foreclosed — potentially without adequate lead time to develop alternatives.

What independent practices should examine now

The policy momentum toward payment prohibition, combined with rising demand amounts, makes pre-incident preparation more consequential than it has been in prior years. Several areas warrant close attention:

What the next 12 months are likely to bring

Legislative action in the UK will be watched closely by US policymakers as a proof-of-concept. If a ban is enacted and demonstrably reduces attack frequency or payment rates, pressure on Congress to act will intensify. HHS and OCR have separately signaled interest in tightening encryption and backup requirements under a revised HIPAA Security Rule — a parallel track that pushes in the same direction as payment bans by incentivizing investment in resilience over reliance on ransom as a recovery mechanism.

Healthcare organizations that treat backup integrity, incident response planning, and insurance review as ongoing operational disciplines rather than one-time compliance tasks will be better positioned regardless of which legislative path payment-ban proposals ultimately take.