The share of ransomware victims that pay their attackers has held near half, even as median ransom demands continue to rise, according to 2025 research from cybersecurity group Sophos. The pattern is drawing regulatory attention: several governments are actively considering or have moved toward banning ransom payments, a development that would force healthcare organizations — some of the most frequent ransomware targets — to rethink their incident-response strategies before an attack occurs rather than during one.
The payment calculus is getting harder
Sophos data places the ransom-payment rate at roughly 49 percent across surveyed organizations. For healthcare entities, the pressure to pay is often acute: clinical systems downtime translates directly into patient care disruption, and the cost of extended outages can exceed the ransom itself. That arithmetic has historically made payment feel like the faster, cheaper path back to operations.
The problem is that payment does not reliably resolve the underlying exposure. Victims who pay frequently receive decryption tools that restore systems only partially, and a meaningful share face follow-on extortion or re-attack from the same or affiliated threat actors. The short-term calculus that makes payment attractive does not account for those downstream costs.
Governments are starting to close off the payment option
The United Kingdom is among the jurisdictions examining mandatory payment prohibitions. A ban would represent a structural shift: organizations could no longer treat ransom payment as a contingency option embedded in their incident-response plan. For healthcare entities that currently rely on the payment path as a backstop, the policy change would require developing alternative recovery capabilities — tested, documented, and resourced in advance.
In the US, no federal ban is in place, but Treasury's Office of Foreign Assets Control has long maintained that payments to sanctioned entities carry civil liability regardless of whether the payer was aware of the sanctions nexus. That exposure already complicates the payment decision for any covered entity or business associate attempting to verify counterparty identity under duress.
What this means for independent practices
Independent and small group practices tend to hold thinner operational reserves than health systems, making downtime tolerance lower and the temptation to pay proportionally higher. Several structural preparations reduce that pressure before an incident occurs:
- Offline and tested backups. Backups stored in network-accessible locations are regularly encrypted alongside production systems. Air-gapped or immutable backup copies, tested through periodic restoration drills, are the primary alternative to paying for decryption keys.
- Documented recovery time objectives. Practices that have never estimated how long specific systems take to restore from backup have no basis for comparing that timeline against a ransom demand. The estimate should be done in advance and reflected in the incident-response plan.
- Incident-response plan with legal and law-enforcement steps. Any payment decision involves legal counsel review of sanctions exposure, FBI or CISA notification, and HHS breach-notification timelines running simultaneously. Practices that map those steps before an attack is underway move faster and with fewer errors when one occurs.
- Cyber insurance policy review. Some insurers are beginning to restrict coverage for ransom payments made to sanctioned entities or to exclude payments following certain policy conditions. Practices should verify current policy terms rather than assume payment would be reimbursed.
What the next 12 months may look like
If payment-ban legislation advances in major English-speaking markets, US regulators and Congress are likely to face renewed pressure to follow. Healthcare-sector trade associations have historically lobbied against payment bans on patient-safety grounds — the argument being that withholding the payment option during an acute care disruption could harm patients. That debate will intensify as more jurisdictions act.
For compliance officers at independent practices, the period before any potential US legislative action is the relevant planning window. Organizations that treat backup integrity, recovery-time documentation, and incident-response rehearsal as deferred projects are making a bet that their own attack will not occur before they get around to it — a bet the Sophos data suggests is getting worse by the year.