Ransomware attacks against organizations across all sectors continued at elevated volume through 2025, and a core operational question — whether to pay — is becoming harder to answer as both ransom demands and legislative pressure rise simultaneously. Research from cybersecurity group Sophos found that nearly half of companies hit by ransomware ended up paying, while the median amount demanded has increased year over year. For healthcare, where system downtime translates directly into patient safety risk, the pay-or-refuse calculation carries stakes that most other industries do not face.
The payment math is shifting
Sophos's 2025 data placed the median ransomware demand at a level that has continued to climb from prior years, even as recovery-without-payment costs have also risen sharply. The practical effect is that neither path — paying or rebuilding — is cheap, and the gap between them is narrowing.
Healthcare organizations have historically been disproportionate targets because their tolerance for downtime is low and their data is high-value on criminal markets. That dynamic has not changed. What has changed is that external pressure from regulators and legislators is beginning to constrain the payment option in ways that were not present three years ago.
Government bans are moving from proposal to policy
Several jurisdictions are now treating ransomware payments as a policy problem rather than a purely operational one. The United Kingdom has advanced proposals to ban payments to hackers outright in certain contexts, joining a broader international conversation about whether payment prohibitions deter attacks or simply displace harm onto victims who cannot recover independently.
In the United States, no federal payment ban is currently in effect, but the discussion is live. State-level proposals and federal agency guidance have both signaled that payment bans are under active consideration. For healthcare compliance officers, the uncertainty itself is a planning problem: contracts, cyber insurance policies, and incident response procedures written today may operate in a materially different legal environment within 24 months.
Healthcare-specific considerations add further complexity. Payments to threat actors who appear on Office of Foreign Assets Control sanctions lists are already prohibited under existing US law regardless of sector, meaning a decision to pay always requires legal review before any transfer occurs.
What the pressure means for independent practices
Independent practices and smaller health systems are in a structurally difficult position. They are frequent targets — partly because their security programs tend to be less mature than large health systems — but they also have fewer resources to absorb either a large ransom payment or an extended recovery. Payment bans, if enacted, would remove an option that smaller organizations disproportionately rely on when backups are inadequate or recovery timelines are unacceptable.
The practical implication is that prevention and recovery capability — not payment strategy — need to be the primary investment:
- Offline and tested backups. Backups that are network-connected can be encrypted alongside primary systems. Regularly tested, air-gapped or immutable backups remain the single most consequential mitigation against ransomware extortion.
- Incident response planning that does not assume payment is available. Organizations whose incident response plan routes to "pay the ransom" as a primary recovery path are exposed if legislation changes or if payment is legally blocked.
- Cyber insurance policy review. Many policies include sub-limits, exclusions, or conditions around ransomware payments. With the legal landscape shifting, policy language written for an earlier environment may not perform as expected.
- Legal and OFAC review protocols. Any scenario in which payment is under consideration requires legal counsel to confirm that the recipient is not a sanctioned entity. This step cannot be deferred to after a payment decision is made.
What the next 12 months are likely to bring
Legislative momentum toward payment restrictions is real but uneven. A blanket US federal ban is not imminent, but sector-specific guidance — including potential HHS guidance directed at healthcare — is plausible given that healthcare remains one of the most attacked industries and one where payment has been widely used as a coping mechanism.
The Sophos data also illustrates a structural problem with the payment equilibrium: when victims pay, they fund the next attack cycle. Policymakers arguing for bans frame the issue in exactly those terms. Healthcare organizations that have not yet stress-tested their ability to recover without paying should treat the current window as an opportunity to close that gap before the option is removed by statute.