Nearly half of organizations hit by ransomware ended up paying a ransom in 2025, according to research from cybersecurity group Sophos, and the median amount demanded continued to climb. At the same time, several governments — including the United Kingdom — are advancing legislation that would prohibit payment outright, a development that could sharply narrow the options available to healthcare organizations already under pressure to restore clinical operations quickly.
The payment calculus that healthcare faces differently
For most industries, the decision to pay or not pay a ransom is financial and reputational. For healthcare, it carries a third dimension: patient safety. Delayed access to electronic health records, imaging systems, or pharmacy platforms translates directly to clinical risk, which has historically made healthcare operators more likely to pay than counterparts in other sectors.
Sophos data shows the median ransom demand rising even as payment rates remain stubbornly high. That combination suggests threat actors have learned that healthcare and similarly time-sensitive targets will accept higher figures to restore operations — and are pricing accordingly.
What payment bans would change
The UK government's move toward banning ransomware payments represents a significant shift in how regulators are framing the problem. The theory behind a ban is straightforward: if payments dry up, the financial incentive to attack erodes. The practical effect on healthcare organizations, however, is more complicated.
A ban does not eliminate the attack surface or reduce the operational damage of an intrusion. It does, however, remove the fastest path back to system availability that many organizations have historically relied on. Healthcare entities operating in jurisdictions that adopt bans — or those whose parent companies are incorporated in such jurisdictions — would face increased pressure to demonstrate that backup and recovery capabilities are genuinely sufficient to restore systems without a decryption key.
Whether the US follows with federal legislation or sector-specific guidance from HHS remains an open question. HHS has signaled interest in stronger ransomware-response expectations through prior cybersecurity performance goal frameworks, and any international ban that touches US-based healthcare vendors would create de facto compliance pressure regardless of domestic law.
What this signals for independent practices
Independent practices occupy a structurally difficult position in this environment. They typically lack the IT staffing and redundant infrastructure that larger health systems maintain, yet face the same threat actors and, increasingly, the same regulatory expectations.
Several operational questions become more urgent given the trajectory of both ransom demands and potential payment bans:
- Tested recovery capability. Offline or air-gapped backup systems are only as useful as the last verified restoration test. Practices that cannot demonstrate a recent, successful recovery exercise from backup alone face the greatest exposure if payment becomes legally prohibited.
- Incident response planning. A documented, rehearsed response plan that accounts for extended system unavailability — not just the hours needed to negotiate a ransom — is the relevant preparation frame now.
- Cyber insurance alignment. Many cyber insurance policies have historically covered ransom payments. Insurers are actively revising terms in response to rising demands and regulatory uncertainty; practices should review current policy language to understand what coverage would remain if payment were legally barred.
- Vendor dependency mapping. Third-party clinical and billing systems present recovery dependencies that a practice may not control. Understanding which vendors have their own ransomware-response obligations, and what service-level commitments they carry, is a prerequisite for realistic continuity planning.
The underlying message from both the Sophos data and the legislative trend is consistent: organizations that have treated ransom payment as a recovery strategy rather than a last resort are now exposed to a scenario where that option disappears. The practices with the most durable standing are those that have built recovery capability sufficient to operate without it.