Nearly half of organizations hit by ransomware paid the demanded ransom in 2025, according to research published by Sophos, and the median amount demanded continued to climb year over year. At the same time, a growing number of governments — including the United Kingdom — are actively exploring or moving toward banning ransom payments altogether, a regulatory shift that would fundamentally change how organizations, including healthcare providers, respond to an attack.

The payment calculus

The Sophos findings illustrate the bind that ransomware victims face. Paying offers a chance at faster data or system recovery, but it funds criminal operations, rarely guarantees complete restoration, and — increasingly — may expose an organization to legal liability if the recipient turns out to be a sanctioned entity.

For healthcare organizations specifically, the stakes are compounded. Encrypted systems can delay care delivery, trigger HIPAA breach notification obligations, and invite OCR investigation regardless of whether a ransom is paid. The calculation that a payment might be cheaper than prolonged downtime has historically driven many smaller practices toward compliance — a pattern that adversaries have learned to exploit by targeting organizations with thin IT staff and older infrastructure.

What a payment ban would mean in practice

A prohibition on ransom payments would shift the entire incident response framework. Organizations that currently treat payment as a fallback option would need functioning offline backups, tested recovery procedures, and contractual clarity with third-party vendors before an attack occurs — not after.

The UK is among the jurisdictions examining payment bans most seriously. If such rules take effect abroad and US regulators follow, healthcare entities without mature backup and recovery programs would face the worst outcomes: extended downtime with no legal path to a quick resolution. HHS has not announced a similar rulemaking, but the international policy direction is one compliance officers should be tracking now, given that federal ransomware guidance has grown steadily more prescriptive since 2021.

Where this lands for independent practices

Smaller and independent healthcare practices are disproportionately represented in ransomware victim data. They tend to carry cyber insurance with coverage limits that have tightened as insurers have hardened underwriting standards, and they often lack the internal expertise to assess whether paying would even produce a usable decryption key.

Several areas warrant attention before an incident occurs:

What this signals about the next 12 months

The combination of rising demand amounts, persistent payment rates, and emerging legislative pressure suggests the ransomware threat to healthcare will not ease in the near term. If payment bans spread from European jurisdictions to US federal or state law, organizations that have not built recovery capabilities independent of paying will face far harder choices than they do today. The time to close those gaps is before a demand arrives.