Nearly half of organizations hit by ransomware paid the demanded ransom in 2025, according to research published by Sophos, and the median amount demanded continued to climb year over year. At the same time, a growing number of governments — including the United Kingdom — are actively exploring or moving toward banning ransom payments altogether, a regulatory shift that would fundamentally change how organizations, including healthcare providers, respond to an attack.
The payment calculus
The Sophos findings illustrate the bind that ransomware victims face. Paying offers a chance at faster data or system recovery, but it funds criminal operations, rarely guarantees complete restoration, and — increasingly — may expose an organization to legal liability if the recipient turns out to be a sanctioned entity.
For healthcare organizations specifically, the stakes are compounded. Encrypted systems can delay care delivery, trigger HIPAA breach notification obligations, and invite OCR investigation regardless of whether a ransom is paid. The calculation that a payment might be cheaper than prolonged downtime has historically driven many smaller practices toward compliance — a pattern that adversaries have learned to exploit by targeting organizations with thin IT staff and older infrastructure.
What a payment ban would mean in practice
A prohibition on ransom payments would shift the entire incident response framework. Organizations that currently treat payment as a fallback option would need functioning offline backups, tested recovery procedures, and contractual clarity with third-party vendors before an attack occurs — not after.
The UK is among the jurisdictions examining payment bans most seriously. If such rules take effect abroad and US regulators follow, healthcare entities without mature backup and recovery programs would face the worst outcomes: extended downtime with no legal path to a quick resolution. HHS has not announced a similar rulemaking, but the international policy direction is one compliance officers should be tracking now, given that federal ransomware guidance has grown steadily more prescriptive since 2021.
Where this lands for independent practices
Smaller and independent healthcare practices are disproportionately represented in ransomware victim data. They tend to carry cyber insurance with coverage limits that have tightened as insurers have hardened underwriting standards, and they often lack the internal expertise to assess whether paying would even produce a usable decryption key.
Several areas warrant attention before an incident occurs:
- Backup architecture. Air-gapped or immutable backup copies, tested on a regular schedule, are the primary alternative to paying. A backup that has never been tested for restoration is not a reliable backup.
- Incident response planning. A written plan that accounts for ransom demand scenarios — including legal review of any payment under OFAC sanctions rules — reduces decision-making time when systems are already down.
- Vendor contracts. Business associate agreements should address ransomware notification timelines and vendor recovery obligations explicitly, since a supply-chain attack on a billing or EHR vendor can trigger the same operational crisis as a direct attack.
- Cyber insurance review. Policies vary significantly in what qualifies as a covered loss and whether a ransom payment is reimbursable; those terms deserve annual scrutiny as the threat environment shifts.
What this signals about the next 12 months
The combination of rising demand amounts, persistent payment rates, and emerging legislative pressure suggests the ransomware threat to healthcare will not ease in the near term. If payment bans spread from European jurisdictions to US federal or state law, organizations that have not built recovery capabilities independent of paying will face far harder choices than they do today. The time to close those gaps is before a demand arrives.