Nearly half of organizations hit by ransomware paid their attackers in 2025, according to research from Sophos, even as median ransom demands continued to rise. The data arrives as governments in the UK and several other jurisdictions are drafting or advancing legislation that would ban payments outright — a development that would force healthcare organizations, already among the most targeted sectors, to abandon what has functioned as a last-resort option when backups fail or operational pressure mounts.
Why payment rates stay high
The persistence of near-50% payment rates reflects the limited options available to organizations when attacks succeed. When clinical systems are encrypted or patient data is exfiltrated and threatened for publication, practice administrators face pressure from multiple directions simultaneously: operational downtime, patient care continuity, breach notification deadlines, and the economics of recovery.
Ransom payment has, in practice, served as a form of incident-cost calculus rather than a capitulation. When the cost of rebuilding systems from backup — accounting for labor, downtime, and data loss — exceeds the ransom demand, finance and operations leadership often concludes that payment is the rational choice. The Sophos figures suggest that calculus still resolves in favor of payment for a significant share of victims.
The rising median demand complicates that math. As threat actors have shifted toward targeting larger organizations and have refined their negotiation tactics, the floor on demanded amounts has climbed, narrowing the gap between "pay and recover quickly" and "rebuild and recover slowly."
What payment bans would change
Legislation prohibiting ransom payments, which the UK government has been examining alongside mandatory incident reporting requirements, would fundamentally alter the decision framework. Under a ban, payment would not simply be inadvisable — it would expose an organization to civil or criminal liability. Healthcare entities operating under such regimes would have no legal path to the fastest available recovery mechanism.
The practical consequence is that organizations that have depended on payment as a backstop would need to demonstrate that their technical recovery capabilities can function without it. That means tested, offline, or immutable backup systems capable of restoring clinical operations within a time frame acceptable for patient care continuity — not merely backup systems that exist on paper.
A secondary effect of bans, which proponents acknowledge, is that they are intended to collapse the economic incentive for ransomware operations. If a large enough share of potential victims cannot legally pay, the model becomes less profitable. Critics counter that bans shift leverage entirely to attackers who can threaten data publication even when systems are restored, making double-extortion a more dominant tactic.
Where this lands for independent practices
Independent healthcare practices occupy a structurally disadvantaged position in this environment. They are frequently targeted because their security investments are lighter than those of health systems, their recovery capabilities are less mature, and their tolerance for downtime is low — a single-provider clinic that cannot access scheduling or prescribing systems faces an immediate patient-care problem.
Several areas warrant attention from practice administrators and compliance officers:
- Backup architecture. Backups stored on systems accessible from the same network segment as clinical workstations are routinely encrypted in ransomware attacks. Segmented, offline, or immutable backup copies are the technical standard that makes payment-free recovery plausible.
- Tested recovery procedures. A backup that has never been restored from is an untested assumption. Tabletop exercises and periodic full-restore drills reveal whether documented recovery times are achievable.
- Incident reporting obligations. HIPAA breach notification timelines run regardless of whether an organization is negotiating with an attacker or rebuilding from backup. Payment does not pause the 60-day notification clock, and mandatory reporting requirements in proposed legislation would add parallel obligations.
- Cyber insurance terms. A growing number of insurers have introduced policy language that limits or excludes coverage for payments made to sanctioned entities, or that conditions coverage on documented pre-incident controls. Policy terms should be reviewed against current technical practices, not assumed to reflect them.
What this signals about the next 12 months
If payment-ban legislation advances in the UK and is taken up by US legislators — a pattern that has recurred with data protection concepts originating in European regulatory frameworks — the compliance question for US healthcare organizations would shift from "should we pay" to "can we recover without paying." That is a more demanding standard than most independent practices currently meet. Organizations that treat ransomware response as primarily a negotiation problem rather than a recovery-capability problem are likely to find that framing increasingly untenable.