Ransomware attackers are extracting payments from a larger share of victims while demanding higher sums, according to 2025 research from Sophos cited in a DataBreaches.net report. Nearly half of organizations struck by ransomware ultimately paid — a figure that signals the continued effectiveness of extortion as a business model — and policymakers in at least one major jurisdiction are now weighing whether to remove that option entirely.

The payment calculus

Organizations facing ransomware attacks weigh operational downtime, data exposure risk, and recovery costs against the attacker's demand. When those calculations tip toward payment, they often do so because backup systems are either unavailable, incomplete, or have themselves been encrypted.

The Sophos data show median demand amounts rising alongside payment rates, a combination that rewards attackers for persistence and escalation. Security economists have long argued that aggregate payment behavior shapes future attack volume: higher and more frequent payments increase expected returns, drawing more threat actors into ransomware operations and funding more capable ones.

For healthcare organizations specifically, the calculus carries extra weight. Clinical downtime is not an abstraction — delayed care, diverted ambulances, and inaccessible medication records create direct patient safety pressure that general-industry statistics do not capture. That pressure shortens the window available to assess alternatives before a payment decision is forced.

The regulatory turn

The UK is among jurisdictions examining a ban on ransomware payments as a policy lever. The theory is straightforward: eliminate the revenue stream and attenuate attacker incentives. The practical objection is equally direct — organizations under attack may face immediate harm that a legal prohibition does not resolve, and bans risk pushing payment decisions into less transparent channels rather than eliminating them.

In the United States, no federal prohibition exists, but the Treasury Department's Office of Foreign Assets Control has long warned that payments to sanctioned entities may carry civil liability regardless of the circumstances. HHS has not treated ransom payment itself as a HIPAA violation, though the underlying breach of protected health information triggers standard notification and investigation obligations.

Any movement toward payment prohibitions in allied jurisdictions will generate pressure on US regulators and congressional committees to respond — particularly given the volume of cross-border managed service and cloud infrastructure that links US healthcare providers to international threat actors and foreign-based criminal groups.

What this means for independent practices

Independent practices and small health systems are disproportionately exposed because they typically carry less redundancy than large integrated networks. Several structural questions are worth examining now, before an incident:

What the next 12 months may bring

If payment ban legislation advances in the UK and gains traction in the EU, US healthcare vendors with international operations or data-sharing agreements may face compliance conflicts — situations where a ban in one jurisdiction intersects with continuity obligations in another. Federal agencies including HHS and Treasury are likely to issue updated guidance on the intersection of sanctions compliance and healthcare continuity as the policy debate matures.

Domestically, the combination of rising demand amounts and high payment rates will continue to attract congressional attention. Healthcare has been the most-breached major sector for more than a decade, and the industry's demonstrated willingness to pay — driven by patient safety pressure — makes it a focal point in any legislative effort to reshape ransomware economics.