Ransomware attacks continue to extract payments from roughly half of all victim organizations, according to 2025 research from Sophos, even as the median ransom demanded keeps rising. The dual pressure — escalating financial demands on one side and emerging legal restrictions on the other — is sharpening the dilemma for healthcare operators, who remain among the most frequently targeted sectors and face the added weight of patient safety consequences when systems go dark.
The payment calculus is shifting
For years, the decision to pay or refuse a ransom turned on a narrow set of operational factors: how quickly could systems be restored from backups, how sensitive was the exfiltrated data, and what was the reputational cost of disclosure. That calculus is changing as several governments move toward prohibiting ransom payments entirely.
The United Kingdom is among the jurisdictions examining payment restrictions, according to the DataBreaches.net report. A ban would not eliminate the extortion attempt, but it would remove the legal option to settle — forcing organizations to invest more heavily in resilience before an incident rather than treating payment as a fallback. For US-based healthcare practices that operate internationally or work with UK-affiliated vendors, those policy shifts signal a direction that domestic regulators may eventually follow.
Median ransom demands have climbed even as payment rates hold near 50 percent, suggesting attackers have concluded that higher asks do not substantially reduce the likelihood of collection. That dynamic rewards groups that can identify high-value, time-pressured targets — a description that fits hospitals, specialty clinics, and any practice where downtime translates directly into patient harm.
Why healthcare faces asymmetric pressure
Most industries weigh ransom payment as a purely financial decision. Healthcare organizations carry an additional variable: the clinical consequence of extended downtime. When imaging systems, EHR platforms, or pharmacy dispensing infrastructure become inaccessible, patient care degrades in ways that create liability beyond the breach itself. That pressure compresses the decision window and can push organizations toward payment even when their security teams advise against it.
HHS has not issued explicit guidance prohibiting ransom payments, and OFAC's existing sanctions framework — which bars payments to designated foreign entities — already creates legal exposure for organizations that pay without first screening the recipient. Practices that have not built OFAC screening into their incident-response plans carry a compliance gap that could convert a bad situation into a worse one.
What independent practices should examine before the next incident
The Sophos data and the emerging legislative discussion point to several planning gaps that independent practices are most likely to have left unaddressed:
- Tested backup and recovery procedures. Paying a ransom is most tempting when the alternative — restoring from backup — is untested, slow, or incomplete. Practices that regularly test full-system restores have a credible non-payment option.
- Incident-response retainer arrangements. Negotiating with an attacker under pressure, without prior legal and forensic support in place, consistently produces worse outcomes. Pre-arranged retainers reduce the time lost in the early hours.
- OFAC and sanctions screening in the IR plan. Any organization that might consider payment needs a documented step for checking whether the threat actor falls under US Treasury designations before funds move.
- Cyber insurance policy review. Some carriers now exclude ransomware payments to sanctioned entities or require pre-authorization before a payment decision is made. Policy language should be reviewed annually, not at the moment of crisis.
What this signals about the next 12 months
Payment bans, if enacted broadly, will not stop ransomware groups — they will redirect pressure toward forcing victims to restore systems faster or face regulatory action for paying illegally. That outcome effectively mandates the kind of operational resilience that voluntary frameworks like the HHS cybersecurity performance goals have encouraged but not required. Practices that treat those goals as aspirational rather than operational will find themselves in an increasingly difficult position if legislative trends in allied countries reach US federal rulemaking.
The near-term signal for compliance officers is straightforward: the option to pay quietly and move on is narrowing, legally and reputationally. Incident-response planning built around payment as a recovery strategy needs to be revisited now, before an attack forces the decision.