Nearly half of organizations hit by ransomware ultimately pay the attacker, according to 2025 research from Sophos, and the median ransom demand continues to climb. For healthcare entities — which hold data valuable enough to command premium ransom demands and face regulatory penalties for system downtime — the decision to pay or refuse is growing more complicated as governments in multiple jurisdictions move toward outright payment bans.

The payment calculus

Sophos data places the payment rate at roughly 49 percent of ransomware victims globally. That figure has remained stubbornly elevated despite years of law-enforcement guidance urging organizations not to pay. The persistence of payments reflects a practical reality: when clinical systems are offline, patient care is directly affected, and the cost of prolonged downtime often exceeds the ransom amount itself.

Healthcare organizations face a compounding problem. Beyond the ransom, a successful attack typically triggers breach-notification obligations under HIPAA, state law, and — for entities with international patients or partners — foreign data-protection regimes. The financial exposure from those parallel obligations can rival or exceed the extortion payment, making the arithmetic genuinely difficult.

What regulatory bans would change

The United Kingdom is among the jurisdictions examining legislation that would prohibit ransom payments outright, according to the reporting. If enacted, such a ban would not only affect UK-based organizations but could create compliance friction for US healthcare groups with UK operations, UK-based vendors, or cross-border patient data flows.

A payment ban shifts the pressure entirely onto preparedness. Organizations that cannot pay must recover through their own means — backups, redundant systems, and tested incident-response plans. For independent practices that have deferred infrastructure investment, that is a significantly harder position than it sounds. An unrecoverable backup or an untested restoration procedure, discovered mid-incident, eliminates the option that a ban would mandate as the only path forward.

Where this lands for independent practices

Two near-term questions are worth working through before an incident occurs:

What the next 12 months may signal

The combination of rising demand amounts and legislative interest in payment prohibition is likely to define ransomware policy debate through at least mid-decade. For healthcare organizations, the practical implication is that the window in which paying is both legal and insurable may narrow. Practices that treat incident response planning as a future project rather than a current operating requirement are betting on a stable regulatory environment — a bet that looks less reasonable each quarter.