Ransomware victims are increasingly caught between operational collapse and the risk of funding criminal networks, with fresh data showing that payment remains a common outcome despite years of guidance to the contrary. Research published by cybersecurity group Sophos in 2025 found that close to half of organizations struck by ransomware ended up paying to recover their data or restore systems — and the median ransom demand has continued to climb. For healthcare organizations, which hold sensitive patient data and operate systems where downtime carries clinical risk, the calculus is especially difficult.
The payment dilemma in healthcare context
Healthcare has long been among the industries most frequently targeted by ransomware operators, in part because the combination of time pressure and data sensitivity makes payment feel unavoidable. When clinical workflows depend on electronic health records, imaging systems, or connected medical devices, even hours of disruption can affect patient care. That operational reality gives attackers pricing leverage that most other sectors do not face in the same form.
The Sophos figures do not isolate healthcare, but the general trend — rising demand amounts alongside a near-coin-flip payment rate — reflects dynamics that healthcare security teams recognize. Organizations that lack tested backup environments or incident response plans frequently discover during an attack that recovery-without-payment is a theoretical option, not a practical one.
Regulatory pressure on the payment question
Several governments are moving to reduce ransom payments by making them legally impermissible. The UK has advanced legislative proposals that would ban payments by public-sector bodies and certain critical infrastructure operators, a category that includes hospitals and health systems in the British model. The approach is designed to reduce the financial incentive for attackers, though critics argue that banning payments without first raising resilience leaves victims with no viable path when backups fail.
In the United States, no federal ban on ransom payments currently exists, though the Treasury Department's Office of Foreign Assets Control (OFAC) has long required that organizations confirm a potential payee is not a sanctioned entity before transferring funds. Payments to sanctioned groups — which include several prolific ransomware gangs — can generate civil liability regardless of intent. HHS has not issued binding guidance directing covered entities to refuse payment, but its ransomware guidance consistently frames pre-incident resilience, not post-incident payment, as the appropriate response framework.
What the trend signals for practice-level planning
The policy debate tends to center on large hospital systems, but independent practices face the same structural exposure with fewer resources to absorb a prolonged outage. Several patterns from recent incidents apply broadly:
- Backup integrity is the deciding variable. Organizations that paid were disproportionately those whose backups were incomplete, unverified, or compromised in the same attack that encrypted production systems. Offline or air-gapped backup copies, tested regularly through actual restoration exercises, are the factor that most consistently allows recovery without payment.
- Incident response plans need to address the payment decision explicitly. Waiting until an attack is underway to determine who has authority to approve a payment, which legal counsel to contact, or how to handle OFAC screening creates delays that cost money and extend downtime.
- Cyber insurance terms are shifting. Insurers have become more specific about requiring documented controls — endpoint detection, privileged access management, segmentation — as conditions of coverage. Practices should review current policy language before an incident, not after.
- Payment does not guarantee recovery. A portion of organizations that pay do not receive working decryption tools or receive them only after extended negotiation. The Sophos data does not suggest payment is a reliable resolution mechanism; it reflects desperation as much as strategy.
What the next 12 months may look like
If UK legislation passes in its current form, it will set a precedent other governments are likely to examine. A formal ban on healthcare-sector payments in the US would represent a significant shift, creating legal exposure for covered entities that choose to pay while simultaneously requiring HHS and CISA to support faster recovery alternatives. Whether that pressure accelerates investment in healthcare resilience infrastructure — or simply transfers costs from ransom payments to regulatory penalties — remains an open question. In the meantime, the Sophos figures suggest the current equilibrium heavily favors attackers.