The share of ransomware victims that pay their attackers has held near half, even as median ransom demands continue to rise, according to 2025 research from cybersecurity group Sophos. The pattern is drawing regulatory attention: several governments are actively considering or have moved toward banning ransom payments, a development that would force healthcare organizations — some of the most frequent ransomware targets — to rethink their incident-response strategies before an attack occurs rather than during one.

The payment calculus is getting harder

Sophos data places the ransom-payment rate at roughly 49 percent across surveyed organizations. For healthcare entities, the pressure to pay is often acute: clinical systems downtime translates directly into patient care disruption, and the cost of extended outages can exceed the ransom itself. That arithmetic has historically made payment feel like the faster, cheaper path back to operations.

The problem is that payment does not reliably resolve the underlying exposure. Victims who pay frequently receive decryption tools that restore systems only partially, and a meaningful share face follow-on extortion or re-attack from the same or affiliated threat actors. The short-term calculus that makes payment attractive does not account for those downstream costs.

Governments are starting to close off the payment option

The United Kingdom is among the jurisdictions examining mandatory payment prohibitions. A ban would represent a structural shift: organizations could no longer treat ransom payment as a contingency option embedded in their incident-response plan. For healthcare entities that currently rely on the payment path as a backstop, the policy change would require developing alternative recovery capabilities — tested, documented, and resourced in advance.

In the US, no federal ban is in place, but Treasury's Office of Foreign Assets Control has long maintained that payments to sanctioned entities carry civil liability regardless of whether the payer was aware of the sanctions nexus. That exposure already complicates the payment decision for any covered entity or business associate attempting to verify counterparty identity under duress.

What this means for independent practices

Independent and small group practices tend to hold thinner operational reserves than health systems, making downtime tolerance lower and the temptation to pay proportionally higher. Several structural preparations reduce that pressure before an incident occurs:

What the next 12 months may look like

If payment-ban legislation advances in major English-speaking markets, US regulators and Congress are likely to face renewed pressure to follow. Healthcare-sector trade associations have historically lobbied against payment bans on patient-safety grounds — the argument being that withholding the payment option during an acute care disruption could harm patients. That debate will intensify as more jurisdictions act.

For compliance officers at independent practices, the period before any potential US legislative action is the relevant planning window. Organizations that treat backup integrity, recovery-time documentation, and incident-response rehearsal as deferred projects are making a bet that their own attack will not occur before they get around to it — a bet the Sophos data suggests is getting worse by the year.