Ransomware attacks against organizations across all sectors continued at elevated volume through 2025, and a core operational question — whether to pay — is becoming harder to answer as both ransom demands and legislative pressure rise simultaneously. Research from cybersecurity group Sophos found that nearly half of companies hit by ransomware ended up paying, while the median amount demanded has increased year over year. For healthcare, where system downtime translates directly into patient safety risk, the pay-or-refuse calculation carries stakes that most other industries do not face.

The payment math is shifting

Sophos's 2025 data placed the median ransomware demand at a level that has continued to climb from prior years, even as recovery-without-payment costs have also risen sharply. The practical effect is that neither path — paying or rebuilding — is cheap, and the gap between them is narrowing.

Healthcare organizations have historically been disproportionate targets because their tolerance for downtime is low and their data is high-value on criminal markets. That dynamic has not changed. What has changed is that external pressure from regulators and legislators is beginning to constrain the payment option in ways that were not present three years ago.

Government bans are moving from proposal to policy

Several jurisdictions are now treating ransomware payments as a policy problem rather than a purely operational one. The United Kingdom has advanced proposals to ban payments to hackers outright in certain contexts, joining a broader international conversation about whether payment prohibitions deter attacks or simply displace harm onto victims who cannot recover independently.

In the United States, no federal payment ban is currently in effect, but the discussion is live. State-level proposals and federal agency guidance have both signaled that payment bans are under active consideration. For healthcare compliance officers, the uncertainty itself is a planning problem: contracts, cyber insurance policies, and incident response procedures written today may operate in a materially different legal environment within 24 months.

Healthcare-specific considerations add further complexity. Payments to threat actors who appear on Office of Foreign Assets Control sanctions lists are already prohibited under existing US law regardless of sector, meaning a decision to pay always requires legal review before any transfer occurs.

What the pressure means for independent practices

Independent practices and smaller health systems are in a structurally difficult position. They are frequent targets — partly because their security programs tend to be less mature than large health systems — but they also have fewer resources to absorb either a large ransom payment or an extended recovery. Payment bans, if enacted, would remove an option that smaller organizations disproportionately rely on when backups are inadequate or recovery timelines are unacceptable.

The practical implication is that prevention and recovery capability — not payment strategy — need to be the primary investment:

What the next 12 months are likely to bring

Legislative momentum toward payment restrictions is real but uneven. A blanket US federal ban is not imminent, but sector-specific guidance — including potential HHS guidance directed at healthcare — is plausible given that healthcare remains one of the most attacked industries and one where payment has been widely used as a coping mechanism.

The Sophos data also illustrates a structural problem with the payment equilibrium: when victims pay, they fund the next attack cycle. Policymakers arguing for bans frame the issue in exactly those terms. Healthcare organizations that have not yet stress-tested their ability to recover without paying should treat the current window as an opportunity to close that gap before the option is removed by statute.