Ransomware victims face an increasingly constrained set of options as median ransom demands rise and a growing number of governments consider or enact outright payment bans. Research published by Sophos in 2025 found that roughly 47 percent of organizations struck by ransomware ultimately paid the attacker — a figure that carries particular weight for healthcare, where system downtime carries direct patient safety consequences and compliance obligations run parallel to recovery timelines.

The payment calculus is shifting

For years the debate over ransom payment hinged on a straightforward cost comparison: pay the attacker or absorb the cost of rebuilding from backups. That calculation has become harder to make cleanly.

Median demand amounts have risen, meaning the payment option is more expensive even before factoring in the reputational and regulatory exposure that follows a confirmed breach. At the same time, backup integrity and recovery speed remain inconsistent across the sector. Healthcare organizations that discover their most recent restorable backup is weeks old often face operational pressure that nudges leadership toward payment regardless of stated policy.

A second complication is attribution. Law enforcement agencies in multiple countries have warned that paying certain threat actors may implicate organizations under sanctions rules. In healthcare, the Office of Foreign Assets Control (OFAC) obligations layer on top of HIPAA breach notification requirements, creating a dual-track legal exposure that most small and mid-size practices are not equipped to assess in real time.

Governments are moving toward prohibition

The UK is among the jurisdictions examining whether to ban ransomware payments entirely. The argument for prohibition rests on deterrence theory: cutting off the revenue stream should, over time, reduce the frequency of attacks. Critics counter that prohibition without guaranteed recovery alternatives simply shifts the harm onto victims rather than attackers.

For US healthcare organizations, no federal payment ban is currently in force, but the direction of regulatory travel is relevant for a few reasons. First, US policymakers watch UK and EU regulatory moves closely, and HHS rulemaking in adjacent areas has historically mirrored international trends with a lag of one to three years. Second, any future prohibition would interact directly with HIPAA breach notification timelines — organizations that could not pay would need to assume data exfiltration and begin the 60-day notification clock immediately, rather than waiting to assess what the attacker actually accessed.

Third, several state attorneys general have begun scrutinizing breach response decisions, including payment choices, as part of broader consumer protection investigations. That scrutiny is likely to intensify if payment bans make the act of paying a ransomware attacker a per se legal violation.

What independent practices should examine now

The Sophos data and the regulatory movement together point toward three operational gaps that independent practices should assess before an incident, not during one.

The broader shift in the ransomware ecosystem — higher demands, more aggressive data exfiltration as a secondary lever, and governments retreating from tacit tolerance of payments — means that organizations relying on payment as an implicit fallback are operating on an assumption that is losing its practical basis.