Nearly half of organizations hit by ransomware ended up paying a ransom in 2025, according to research from cybersecurity group Sophos, and the median amount demanded continued to climb. At the same time, several governments — including the United Kingdom — are advancing legislation that would prohibit payment outright, a development that could sharply narrow the options available to healthcare organizations already under pressure to restore clinical operations quickly.

The payment calculus that healthcare faces differently

For most industries, the decision to pay or not pay a ransom is financial and reputational. For healthcare, it carries a third dimension: patient safety. Delayed access to electronic health records, imaging systems, or pharmacy platforms translates directly to clinical risk, which has historically made healthcare operators more likely to pay than counterparts in other sectors.

Sophos data shows the median ransom demand rising even as payment rates remain stubbornly high. That combination suggests threat actors have learned that healthcare and similarly time-sensitive targets will accept higher figures to restore operations — and are pricing accordingly.

What payment bans would change

The UK government's move toward banning ransomware payments represents a significant shift in how regulators are framing the problem. The theory behind a ban is straightforward: if payments dry up, the financial incentive to attack erodes. The practical effect on healthcare organizations, however, is more complicated.

A ban does not eliminate the attack surface or reduce the operational damage of an intrusion. It does, however, remove the fastest path back to system availability that many organizations have historically relied on. Healthcare entities operating in jurisdictions that adopt bans — or those whose parent companies are incorporated in such jurisdictions — would face increased pressure to demonstrate that backup and recovery capabilities are genuinely sufficient to restore systems without a decryption key.

Whether the US follows with federal legislation or sector-specific guidance from HHS remains an open question. HHS has signaled interest in stronger ransomware-response expectations through prior cybersecurity performance goal frameworks, and any international ban that touches US-based healthcare vendors would create de facto compliance pressure regardless of domestic law.

What this signals for independent practices

Independent practices occupy a structurally difficult position in this environment. They typically lack the IT staffing and redundant infrastructure that larger health systems maintain, yet face the same threat actors and, increasingly, the same regulatory expectations.

Several operational questions become more urgent given the trajectory of both ransom demands and potential payment bans:

The underlying message from both the Sophos data and the legislative trend is consistent: organizations that have treated ransom payment as a recovery strategy rather than a last resort are now exposed to a scenario where that option disappears. The practices with the most durable standing are those that have built recovery capability sufficient to operate without it.