Ransomware remains one of the most disruptive threats facing healthcare organizations, and the calculus around whether to pay attackers is becoming more complicated. Research published by Sophos in 2025 found that close to half of all ransomware victims ultimately pay a ransom, even as median demand amounts continue to climb — a dynamic that carries outsized implications for hospitals, physician groups, and health systems that hold sensitive patient data and cannot afford extended system outages.

The payment math is changing

Sophos data shows the median ransom demand has risen year over year, compressing the decision window for organizations that are already managing patient care under degraded conditions. Two forces are pulling in opposite directions: paying quickly may restore operations faster, but it funds attacker infrastructure, offers no guarantee of decryption or data deletion, and — increasingly — may expose the paying organization to legal liability.

Payment also does not reliably end exposure. Threat actors have returned to victims who paid, and data stolen before encryption is frequently published or sold regardless of whether a ransom is settled. For healthcare entities subject to HIPAA, a payment-and-recovery path does not eliminate the breach notification obligation triggered when protected health information is exfiltrated.

Governments are moving toward bans

The UK is among jurisdictions actively examining legislation that would prohibit ransom payments outright, at least for critical infrastructure sectors, which typically include healthcare. Similar discussions are advancing in Australia and parts of the European Union. The United States has not enacted a federal payment ban, but the Office of Foreign Assets Control has for years maintained that payments to sanctioned groups can violate Treasury regulations — creating a de facto legal risk even without explicit prohibition.

A payment ban would force organizations to rely entirely on backup and recovery capabilities, making the quality of those systems the central variable in ransomware resilience. For independent practices that have historically treated backup as a low-priority infrastructure item, a ban would remove the option that many currently treat as a fallback.

Where this leaves healthcare compliance officers

The Sophos findings arrive as OCR continues to signal heightened enforcement attention around ransomware preparedness under the HIPAA Security Rule. The 2024 proposed updates to that rule, if finalized, would require covered entities to document and test incident response and recovery plans with greater specificity than current guidance demands.

Several practical questions now sit at the center of incident response planning for healthcare organizations:

What the next 12 months may signal

If one or more major jurisdictions enact a payment ban, the practical effect on healthcare organizations will depend on whether healthcare is carved in or carved out of any critical-infrastructure exemption. Advocates for a ban argue it eliminates the financial incentive that sustains ransomware-as-a-service ecosystems. Opponents note that for hospitals and clinics, a prolonged outage carries patient safety consequences that differ categorically from those faced by other industries.

Either outcome reinforces the same operational conclusion: organizations that have invested in tested, isolated recovery capabilities hold materially better options than those that have not. The payment question becomes significantly less consequential when recovery does not depend on the attacker's cooperation.