Nearly half of organizations hit by ransomware ultimately pay the attacker, according to 2025 research from Sophos, and the median ransom demand continues to climb. For healthcare entities — which hold data valuable enough to command premium ransom demands and face regulatory penalties for system downtime — the decision to pay or refuse is growing more complicated as governments in multiple jurisdictions move toward outright payment bans.
The payment calculus
Sophos data places the payment rate at roughly 49 percent of ransomware victims globally. That figure has remained stubbornly elevated despite years of law-enforcement guidance urging organizations not to pay. The persistence of payments reflects a practical reality: when clinical systems are offline, patient care is directly affected, and the cost of prolonged downtime often exceeds the ransom amount itself.
Healthcare organizations face a compounding problem. Beyond the ransom, a successful attack typically triggers breach-notification obligations under HIPAA, state law, and — for entities with international patients or partners — foreign data-protection regimes. The financial exposure from those parallel obligations can rival or exceed the extortion payment, making the arithmetic genuinely difficult.
What regulatory bans would change
The United Kingdom is among the jurisdictions examining legislation that would prohibit ransom payments outright, according to the reporting. If enacted, such a ban would not only affect UK-based organizations but could create compliance friction for US healthcare groups with UK operations, UK-based vendors, or cross-border patient data flows.
A payment ban shifts the pressure entirely onto preparedness. Organizations that cannot pay must recover through their own means — backups, redundant systems, and tested incident-response plans. For independent practices that have deferred infrastructure investment, that is a significantly harder position than it sounds. An unrecoverable backup or an untested restoration procedure, discovered mid-incident, eliminates the option that a ban would mandate as the only path forward.
Where this lands for independent practices
Two near-term questions are worth working through before an incident occurs:
- Payment authorization. Who in the organization is authorized to approve a ransom payment, and has legal counsel been identified in advance? Absent a clear chain of authority, decisions get made under pressure without adequate review.
- Backup integrity. Offline or immutable backups — copies that ransomware cannot reach and encrypt — are the functional substitute for paying. Practices that cannot confirm their backup sets are recent, complete, and tested are, in effect, dependent on the payment option.
- Cyber insurance terms. Many policies contain ransomware-specific sublimits or conditions. Whether a policy covers the ransom itself, the forensics costs, the notification vendor, and the regulatory-response costs varies significantly by contract language.
- Regulatory trajectory. US federal agencies have not proposed a payment ban, but the Office of Foreign Assets Control already prohibits payments to sanctioned threat actors. Any practice that experiences an incident should assume OFAC screening of the attacker is a required step before any payment decision.
What the next 12 months may signal
The combination of rising demand amounts and legislative interest in payment prohibition is likely to define ransomware policy debate through at least mid-decade. For healthcare organizations, the practical implication is that the window in which paying is both legal and insurable may narrow. Practices that treat incident response planning as a future project rather than a current operating requirement are betting on a stable regulatory environment — a bet that looks less reasonable each quarter.