Ransomware victims face an increasingly constrained set of options as median ransom demands rise and a growing number of governments consider or enact outright payment bans. Research published by Sophos in 2025 found that roughly 47 percent of organizations struck by ransomware ultimately paid the attacker — a figure that carries particular weight for healthcare, where system downtime carries direct patient safety consequences and compliance obligations run parallel to recovery timelines.
The payment calculus is shifting
For years the debate over ransom payment hinged on a straightforward cost comparison: pay the attacker or absorb the cost of rebuilding from backups. That calculation has become harder to make cleanly.
Median demand amounts have risen, meaning the payment option is more expensive even before factoring in the reputational and regulatory exposure that follows a confirmed breach. At the same time, backup integrity and recovery speed remain inconsistent across the sector. Healthcare organizations that discover their most recent restorable backup is weeks old often face operational pressure that nudges leadership toward payment regardless of stated policy.
A second complication is attribution. Law enforcement agencies in multiple countries have warned that paying certain threat actors may implicate organizations under sanctions rules. In healthcare, the Office of Foreign Assets Control (OFAC) obligations layer on top of HIPAA breach notification requirements, creating a dual-track legal exposure that most small and mid-size practices are not equipped to assess in real time.
Governments are moving toward prohibition
The UK is among the jurisdictions examining whether to ban ransomware payments entirely. The argument for prohibition rests on deterrence theory: cutting off the revenue stream should, over time, reduce the frequency of attacks. Critics counter that prohibition without guaranteed recovery alternatives simply shifts the harm onto victims rather than attackers.
For US healthcare organizations, no federal payment ban is currently in force, but the direction of regulatory travel is relevant for a few reasons. First, US policymakers watch UK and EU regulatory moves closely, and HHS rulemaking in adjacent areas has historically mirrored international trends with a lag of one to three years. Second, any future prohibition would interact directly with HIPAA breach notification timelines — organizations that could not pay would need to assume data exfiltration and begin the 60-day notification clock immediately, rather than waiting to assess what the attacker actually accessed.
Third, several state attorneys general have begun scrutinizing breach response decisions, including payment choices, as part of broader consumer protection investigations. That scrutiny is likely to intensify if payment bans make the act of paying a ransomware attacker a per se legal violation.
What independent practices should examine now
The Sophos data and the regulatory movement together point toward three operational gaps that independent practices should assess before an incident, not during one.
-
Backup architecture and restoration speed. The primary reason organizations pay is that restoring from backup takes longer than the operational crisis can tolerate. Practices should know, in writing, how long a full restoration of core clinical systems takes and whether that figure has been tested recently against current data volumes.
-
Incident response decision authority. Payment decisions made under pressure are rarely made by the right people with the right information. A documented escalation policy — specifying who has authority to authorize payment, who must be consulted (legal counsel, cyber insurer, law enforcement), and in what sequence — reduces the chance that a panicked decision creates additional regulatory exposure.
-
Cyber insurance policy language. Many policies that covered ransom payments in 2022 have been rewritten to exclude certain threat actors, require pre-authorization of payments, or cap the covered amount below current median demand levels. Practices should review current policy terms against the rising demand environment rather than assuming prior coverage limits remain adequate.
The broader shift in the ransomware ecosystem — higher demands, more aggressive data exfiltration as a secondary lever, and governments retreating from tacit tolerance of payments — means that organizations relying on payment as an implicit fallback are operating on an assumption that is losing its practical basis.