Ransomware attacks continue to extract payments from roughly half of all victim organizations, according to 2025 research from Sophos, even as the median ransom demanded keeps rising. The dual pressure — escalating financial demands on one side and emerging legal restrictions on the other — is sharpening the dilemma for healthcare operators, who remain among the most frequently targeted sectors and face the added weight of patient safety consequences when systems go dark.

The payment calculus is shifting

For years, the decision to pay or refuse a ransom turned on a narrow set of operational factors: how quickly could systems be restored from backups, how sensitive was the exfiltrated data, and what was the reputational cost of disclosure. That calculus is changing as several governments move toward prohibiting ransom payments entirely.

The United Kingdom is among the jurisdictions examining payment restrictions, according to the DataBreaches.net report. A ban would not eliminate the extortion attempt, but it would remove the legal option to settle — forcing organizations to invest more heavily in resilience before an incident rather than treating payment as a fallback. For US-based healthcare practices that operate internationally or work with UK-affiliated vendors, those policy shifts signal a direction that domestic regulators may eventually follow.

Median ransom demands have climbed even as payment rates hold near 50 percent, suggesting attackers have concluded that higher asks do not substantially reduce the likelihood of collection. That dynamic rewards groups that can identify high-value, time-pressured targets — a description that fits hospitals, specialty clinics, and any practice where downtime translates directly into patient harm.

Why healthcare faces asymmetric pressure

Most industries weigh ransom payment as a purely financial decision. Healthcare organizations carry an additional variable: the clinical consequence of extended downtime. When imaging systems, EHR platforms, or pharmacy dispensing infrastructure become inaccessible, patient care degrades in ways that create liability beyond the breach itself. That pressure compresses the decision window and can push organizations toward payment even when their security teams advise against it.

HHS has not issued explicit guidance prohibiting ransom payments, and OFAC's existing sanctions framework — which bars payments to designated foreign entities — already creates legal exposure for organizations that pay without first screening the recipient. Practices that have not built OFAC screening into their incident-response plans carry a compliance gap that could convert a bad situation into a worse one.

What independent practices should examine before the next incident

The Sophos data and the emerging legislative discussion point to several planning gaps that independent practices are most likely to have left unaddressed:

What this signals about the next 12 months

Payment bans, if enacted broadly, will not stop ransomware groups — they will redirect pressure toward forcing victims to restore systems faster or face regulatory action for paying illegally. That outcome effectively mandates the kind of operational resilience that voluntary frameworks like the HHS cybersecurity performance goals have encouraged but not required. Practices that treat those goals as aspirational rather than operational will find themselves in an increasingly difficult position if legislative trends in allied countries reach US federal rulemaking.

The near-term signal for compliance officers is straightforward: the option to pay quietly and move on is narrowing, legally and reputationally. Incident-response planning built around payment as a recovery strategy needs to be revisited now, before an attack forces the decision.