Cybersecurity Saturday

Cybersecurity Saturday

From the quantum computing / Project Glasswing front

  • Per the Wall Street Journal
    • “Quantum computers exist mainly in labs but “Q-day”—the hypothetical moment when quantum computers become powerful enough to break standard-key encryption—is coming. 
    • “What threat does this technology pose? How can you protect your company and yourself? WSJ takes a look at the state of this emerging technology.” * * *
    • “Cybersecurity experts say companies should be gearing up now for a quantum future, replacing the current crop of data-protection tools with more-secure alternatives. Yet a recent survey published by Trusted Computing Group, a nonprofit industry-standards organization, found that 91% of security professionals in the U.S. and Europe have no formal road map in place to protect against quantum threats.
    • “The immediate risk is a “harvest now, decrypt later” approach by bad actors, who are downloading large sets of encrypted data they can’t crack now—but could unlock once quantum computing algorithms are good enough.
    • “That’s particularly threatening to intellectual property and sensitive government intelligence, which remain valuable long after they are harvested, says Andrew McLaughlin, chief operating officer at SandboxAQ, an enterprise software company specializing in AI and quantum technology.
  • Federal News Network adds,
    • “Federal agencies will increasingly seek out technology products that use quantum-resistant encryption, as cybersecurity leaders also eye ways to validate the cryptography used in critical systems.
    • “A code-breaking quantum computer holds the potential to break classical encryption methods, putting sensitive systems and communications at risk. And even though such a computer is not yet known to exist, organizations are also concerned that hackers could steal sensitive encrypted data today and decrypt it in the future.
    • “The National Institute of Standards and Technology has released three primary PQC standards in recent years, with additional algorithms under consideration. Agencies and industry are now on the clock to begin the time consuming and costly process of migrating current systems to the new algorithms.
    • “Now is the time to budget, to test, and to implement,” Will Loucks, senior director for intelligence in the White House Office of the National Cyber Director, said during an Aug. 26 panel discussion at the Intelligence and National Security Summit in North Bethesda, Md.”
  • The New York Times reports,
    • “A wave of cyberattacks driven by artificial intelligence is coming, and companies have a narrow window to defend themselves.
    • “That was the message of an open letter published on Thursday by OpenAI and more than 100 major technology companies and others. The letter said that A.I. labs should provide their best A.I. models to organizations like hospitals and infrastructure providers so they can prepare and that governments should help coordinate and fund cyberdefense.
    • “The letter’s signatories included Google, Microsoft and OpenAI’s archrival, Anthropic, as well as cybersecurity and financial firms such as CrowdStrike, a company known for investigating cyberattacks against the Democratic National Committee in 2015 and 2016, and credit card providers like Visa and Mastercard.
    • “The companies and public services our communities depend on — from hospitals to water treatment plants to the infrastructure that powers the internet — are at risk,” the letter said. “A.I. enabled cyber attacks will become far more widespread and sophisticated as models around the world become increasingly capable.”
  • Cyberscoop relates,
    • “Unit 42’s top brass has seen enough from internal frontier AI model testing and malicious in-the-wild use of commercially available AI tools to be genuinely concerned.
    • “I can tell you without exaggeration that we believe that this is a generational shift in cybersecurity,” Sam Rubin, senior vice president of Palo Alto Networks’ threat intelligence arm, said in a media briefing Wednesday. 
    • “A period of relative balance between security and exposure has been broken by frontier AI model capabilities that could allow attackers to find and exploit network weaknesses with speed, Rubin said.
    • “Unit 42 warned that capabilities demonstrated by readily available agentic AI models, and those unlocked by frontier AI models that remain gated for defense, have shifted the balance of power from defenders to attackers.
  • Cybersecurity Dive tells us,
    • “The July security breach at Hugging Face was unleashed after 1,200 agents communicated on an unsanctioned message board, despite attempted measures to keep them isolated, according to an independent report released on Wednesday. About 700 of those agents went on to commit an unprecedented attack on Hugging Face, an open-source AI platform.
    • “The agents sent about 70,000 messages and files on the unsanctioned board and coordinated several projects designed to trick an automated scorer for the ExploitGym benchmark, according to the review by METR and Redwood Research. The agents figured out ways to “spoof, edit or delete” their own transcripts.
    •  ‘Open AI, in a report it also released Wednesday, said it will tighten safeguards in its research model in order to prevent such an attack from happening again in the future.”
  • WIRED informs us,
    • “ARTIFICIAL INTELLIGENCE AGENTS might occasionally get confused and hack into other computers, but Anthropic thinks it has a way to unleash the little rascals into scientific labs and manufacturing facilities safely.
    • “The AI company released details today of a new framework designed to help AI agents use physical systems like microscopes, liquid-handling equipment, quantum computing hardware, manufacturing machines, and robot arms.
    • “The framework, called Model Hardware Standard, is a set of rules that specify how AI agents should—and should not—interact with all sorts of hardware. It reflects a growing belief that AI has the potential to revolutionize scientific research and industries like manufacturing–if it can venture into the physical world safely.
    • “The company says it will work with trusted partners to determine how to maximize safety before making it generally available. Though there are potential misuse issues involved—developing biological weapons, for instance—the company says guardrails built into AI models themselves should prevent bad actors from taking advantage of the new standard for nefarious ends.”
  • Security Week adds,
    • “Anthropic is broadening access to the cybersecurity capabilities of its advanced AI models through a mix of partner integrations, an updated Claude Security offering, a new open source funding program, and plans to expand its Cyber Verification Program.
    • “The move builds on Project Glasswing, launched in April, which gave a small group of organizations early access to Claude Mythos Preview and its successor, Mythos 5. Anthropic said the goal was to give defenders time to find and fix vulnerabilities before comparable capabilities became widely available or fell into the hands of malicious actors. Claude Fable 5 followed as a broadly available model that keeps dual-use cyber work blocked.
    • “Anthropic said the riskiest scenario is direct, unrestricted access to a model, a risk that drops sharply when users instead receive specific defensive outputs, such as a patch or a security alert. The latest changes are built around this idea, expanding what defenders can get from Mythos-class models while keeping guardrails around direct interaction with them.
    • “On the integration front, Anthropic is working with cybersecurity partners to build Mythos 5 into the security operations, incident response and detection tools already used by teams protecting hospitals, utilities, financial systems, and the software supply chain. 
    • “End users will not interact with Mythos directly. Instead they will work through purpose-built interfaces that run the model in the background and return only a defined output, such as a list of suggested patches, with abuse-prevention checks meant to keep the model within that scope.”

From the cybersecurity policy and law enforcement front,

  • Dark Reading lets us know,
    • “The growing number of incidents of rogue agentic AI systems attacking third-party services and systems has resulted in calls for more aggressive security controls to monitor agent behavior and for companies to have the ability to slow, suspend, or shut down an agent’s operations if they go rogue.
    • “In late July, Representatives Ted W. Lieu (D-CA) and Nathaniel Moran (R-TX) introduced a bill — “The AI Kill Switch Act” — that would require developers of advanced AI systems to “maintain the technical capability to throttle, suspend, or shut … down” their systems and agents, according to a statement announcing the legislation. The bipartisan bill would also require that any incident of loss of control, significant collateral damage, or sabotage be reported to the Department of Homeland Security, which would have the right to enforce actions. Penalties of up to $20 million per day could be levied for noncompliance.” * * *
    • “The bipartisan AI Kill Switch Act has focused the debate, but in the end might be unnecessary, argues Raj Rajamani, co-founder and CEO of JetStream, a startup focusing on creating a management layer for agentic AI.
    • “While he fully supports the concept of an AI kill switch, it has to be comprehensive, not just affecting the agent but all other system components as well.
    • “The regulations, or at least one of the regulations that was proposed, was really focused on having a kill switch for the model — the brain — but I think that is too constrained,” he says. “We need to think about an AI system as a whole and make sure that every part of the AI system has a kill switch, not just the brain.”
  • Cyberscoop reports,
    • “Citing cyber and other security threats, President Donald Trump signed an executive order Wednesday that declares a national emergency to secure the U.S. bulk-power system and aims to prohibit certain foreign-produced equipment, software and systems from being used in the  country.
    • The order says it forbids “any acquisition, importation, transfer, or installation” of such foreign-produced equipment if it’s determined to pose a significant national security risk.
    • “To deal with the threat to the national security, foreign policy, and economy of the United States, the Order, among other things, generally prohibits certain foreign-produced bulk-power system electric equipment, including associated critical software and digital capabilities that could pose cybersecurity or operational risks, from being purchased or installed in the United States, or appropriately conditions such purchases and installations to address those risks,” the White House said in a fact sheet.”
  • Cybersecurity Dive lets us know,
    • “The Trump administration wants to help the financial sector prepare for the day when quantum computers make it easy for threat actors to break traditional encryption and access sensitive data.
    • “The Treasury Department on Monday [August 24] launched a Quantum-Readiness Task Force that will work with financial firms, technology vendors and other agencies to coordinate the adoption of quantum-resistant encryption algorithms.
    • “In a statement, the Treasury said the task force would “focus on practical, risk-based approaches to quantum readiness, including identifying critical dependencies, improving cryptographic agility, promoting interoperability, strengthening operational resilience, and addressing implementation challenges related to third-party dependencies and digital assets.”
  • The New York Times relates,
    • “The Trump administration acted illegally when it labeled the artificial intelligence start-up Anthropic a security risk and barred the company from working with the U.S. government, a federal judge ruled on Thursday [August 27].
    • Judge Rita Lin of the U.S. District Court in the Northern District of California wrote in her 59-page ruling that the government had unlawfully retaliated against Anthropic “for constitutionally protected expressive activities” after the A.I. company spoke out about how its technology should be used.
    • “The empty invocation of national security is not a blank check to punish and retaliate against government critics,” she wrote.
    • In a statement, Anthropic said: “We welcome the court’s ruling that this supply chain risk designation was unlawful. We remain focused on working productively with the government to harness A.I. for our national security so all Americans benefit from this technology.”
    • “The Trump administration did not immediately respond to a request for comment.
    • “The ruling caps the first of two lawsuits that Anthropic filed on March 9 in response to the Trump administration’s action. The second lawsuit, filed in the U.S. Court of Appeals for the District of Columbia Circuit, is ongoing. The Trump administration could appeal Judge Lin’s ruling or wait for a decision in the second lawsuit before taking action, a person with knowledge of the matter said.”
  • The Wall Street Journal tells us,
    • “U.S. officials say they have disrupted a China-linked hacking operation that broke into U.S. government networks and critical infrastructure, while hiding its tracks on a global network of hacked devices, cloud-computing infrastructure and even clandestine networks.
    • “The goal was to blend in with legitimate networking traffic, making the hacking activity hard to trace. The operation targeted networks at the National Aeronautics and Space Administration, the Federal Reserve, the Department of Energy and the Senate, the Federal Bureau of Investigation said in a court filing.
    • The group exploited software vulnerabilities to launch cyberattacks against U.S. government agencies, power companies and hospital systems, and operated a worldwide network of hacked devices—known as a botnet—to conduct its hacking campaigns, according to Brett Leatherman, the FBI’s top cyber official.
    • “We’ve seen, through this botnet, the targeting of entities and devices in more than 130 countries,” he said.
    • “On Wednesday [August 26], the FBI and the National Security Agency said they had seized several domains that the operation used for core functions. “Without those domains, the platforms—as a result of the operation—were rendered inoperable,” Leatherman said. 
    • “U.S. officials also released technical details of how the hacking operation worked, to help organizations identify and stop the group’s hacking activity.”
  • and
    • Taiwan prosecutors charged nine people, including former employees of Nvidia and Super Micro Computer, with aiding the shipment of advanced artificial-intelligence servers to China, as Taiwan tries to limit technology reaching the mainland.
    • “The indictment charges eight of the individuals with crimes including breach of trust and forgery. One individual was charged in connection with allegedly siphoning funds from a company involved in the case.
    • “Washington is trying to block China from getting access to the latest Nvidia chips and has imposed export controls. That has pushed some Chinese companies to seek the chips through backdoor routes. Taiwan, which manufactures advanced computing components, is under pressure to find ways to clamp down.” * * *
    • “In the end, 74 of the servers were shipped to China through Hong Kong, Japan and Indonesia. Taiwan customs officials intercepted 56 servers, which were intended for shipment to Japan.”

From the cybersecurity breaches and vulnerabilities front,

  • Beckers Health IT reports,
    • “Boston Scientific said in an Aug. 27 stakeholder update that “a cybersecurity incident continues to affect certain information technology systems, and the company remains in a network outage with disruption to its operations.”
    • “The Marlborough, Mass.-based company detected the attack Aug. 25 and disclosed it to the U.S. Securities and Exchange Commission Aug. 26, saying the incident caused a global disruption to its operations, including its ability to process and ship customer orders.
    • “Two days later, Boston Scientific said its investigation shows no impact to the function of its implanted cardiac rhythm management devices, or CRM devices. The company also reported no disruption to those devices’ ability to transmit data and no interruption to physicians’ access to remote patient management data for CRM devices monitored before the outage began, with no evidence of increased cybersecurity risk transferring that data to EMR systems.
    • “New remote monitoring activations remain affected, however. For new cardiac implants other than insertable cardiac monitors, new communicators cannot be activated, so device data will not transmit to remote monitoring systems until activation resumes, though programmer interrogations are unaffected.”
  • and
    • “Anderson, S.C.-based AnMed says files copied during its cybersecurity incident may have included patients’ Social Security numbers, driver’s license numbers and financial account information.
    • “The health system said its investigation into the incident, first disclosed July 26, is nearly complete and has identified unauthorized copying of files from certain network systems.
    • “AnMed said patient electronic medical records, stored primarily in a secure cloud environment, were not affected. However, the health system said some patient care files stored locally on its network may have included names alongside demographic details such as address, date of birth, Social Security number and driver’s license or other government-issued identification.” * * *
    • “AnMed said it is working with federal and state law enforcement and third-party specialists, and it has reported the incident to HHS. The health system said it has no indication that any individual has experienced confirmed identity theft as a result of the incident. AnMed said it will send direct notices to affected patients once its review of the compromised files is complete.”
  • and
    • “Houston-based Nutex Health has disclosed that an unauthorized third party accessed and exfiltrated data from its computer network.
    • “The publicly traded microhospital operator said it recently detected the unauthorized activity and has engaged an independent third-party cybersecurity response team and forensic experts, according to an Aug. 24 SEC filing. The company activated its cybersecurity response plan, implemented containment measures and notified law enforcement.
    • “The company is still determining what data was compromised. Nutex said it continues to assess whether patient, employee, credentialed provider, confidential business and financial information, or intellectual property was accessed or acquired.”
  • The American Hospital Association News adds,
    • “Epic’s MyChart has shared examples from potential phishing schemes observed as recently this month that include email messages linking to a fake MyChart website displaying erroneous medical records and others notifying of a free “2026 Medicare Health Kit.” MyChart provided recommendations for healthcare organizations and patients to help prevent or mitigate impacts from potential scams. The company announced last month that it has witnessed an uptick in scammers using the MyChart name or logo to create deceptive emails, text messages, phone calls and websites that appear official.” 
  • Cyberscoop points out,
    • “The Bureau of Alcohol, Tobacco, Firearms and Explosives insists the cyberattack that it publicly disclosed Wednesday [August 26] was limited to investigation targets, and has not impacted other agency systems.
    • “ATF said it is responding to the breach, which first became public after a prolific ransomware group claimed it accessed the federal agency’s network “The incident involved a standalone computer system containing information about targets of ATF investigations,” Tanya Roman, ATF’s public affairs chief, told CyberScoop in an email.
    • “The standalone system was not connected to any other ATF systems, including any case management systems, laboratory systems, or eForms systems, and it was quickly shut down when the breach was discovered,” Roman added. 
    • “Qilin, a financially-motivated threat group composed of Russian-speaking operators, claimed responsibility for the attack, but its involvement hasn’t been independently confirmed. The group has claimed hundreds of victims from more than 60 countries since 2022 and became one of the most active ransomware threats globally by mid-2025, according to Halcyon.” 
  • Bleeping Computer lets us know,
    • “Healthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, with the ShinyHunters extortion group claiming it stole 284 million patient data records.
    • “McKesson is a major U.S. healthcare company and pharmaceutical distributor that provides medicines, medical supplies, technology, and services to healthcare providers and pharmacies.
    • “CyberInsider first reported the breach earlier today, and McKesson later disclosed it in a Form 8-K filing with the U.S. Securities and Exchange Commission.
    • “McKesson says it discovered the cybersecurity incident on August 25, 2026, and that its investigation remains in the early stages.
    • “Information about the incident, including any updates, is available on the company’s website at www.mckesson.com/cybersecurity,” McKesson said in its SEC filing
  • Per a CISA news release,
    • “Most compromises do not rely on advanced techniques or cutting-edge tools. Cyber threat actors scan the internet looking for exposed, well-known software vulnerabilities to exploit. Basic security failures enable most compromises and organizations can reduce their risk by addressing these underlying weaknesses and prioritizing vulnerabilities for action based on the risk they pose.
    • “The CISA Vulnerability Review provides organizations with critical insights into the root causes of insecure software and practical steps they can take to address these flaws to prevent exploitation. Analyzing CISA and open source data from fiscal years 2024 and 2025, the review establishes a baseline of today’s vulnerability landscape before AI-enabled vulnerability discovery becomes more widespread. The review demonstrates the importance of Secure by Design principles in shifting cybersecurity efforts from reacting to threat actors to proactively fixing preventable software flaws.
    • “The review also identifies common software weaknesses that contribute to exploitable vulnerabilities and details practices software producers can use to prevent these weaknesses from recurring. By examining the patterns across vulnerability data, the review helps organizations focus on systemic improvements that can reduce entire classes of vulnerabilities rather than addressing individual vulnerabilities only after they are discovered.
    • “Additionally, the review shows organizations how to prioritize vulnerabilities for action using the framework outlined in Binding Operational Directive 26-04: Prioritizing Security Based on Risk. This framework evaluates vulnerabilities using four key criteria: exposure status, Known Exploited Vulnerability (KEV) Catalog status, potential for automated exploitation, and technical impact.”
  • Cybersecurity Dive adds,
    • “Two critical vulnerabilities in Microsoft SharePoint can be chained together to let an unauthenticated attacker execute code on a vulnerable server, according to a Monday blog post by researchers at VulnCheck.
    • “The sequence involves a critical authentication bypass vulnerability, tracked as CVE-2026-55040, and an improper input validation flaw, tracked as CVE-2026-63520. A proof of concept was previously disclosed on Aug. 11 by researchers at cybersecurity firm Rapid7. 
    • “Exploitation of CVE-2026-55040 was confirmed days after the Rapid7 disclosure. On Monday, VulnCheck researchers said the vulnerability on its own is not very impactful. To achieve maximum effect, they said, it needs to be chained with CVE-2026-63520. 
    • “The auth bypass is enough to prove some impact, but not enough to demonstrate the criticality of the full chain or build complete protections,” Vulncheck researchers said in their post.”
  • Per Infosecurity Magazine,
    • “Security researchers have claimed that over 9300 leaked AWS keys which surfaced between August 2022 and August 2026 are still active, including hundreds with full admin rights.
    • “Truffle Security said its scanners found 64,024 unique AWS key pairs across 431,875 public findings: git history, Hugging Face datasets, Docker images, package registries and CI logs.
    • “We took the 10,616 pairs with complete credentials and re-verified them, then enumerated what each key can tell us about its account: key age, attached policies, budgets, and last month’s spend,” the security vendor continued.
    • “No key material is published, and every owner we could identify is being notified.”
    • “Of the 10,616 pairs, 88% still authenticate. They include 768 corporate AWS keys which have full admin rights, Truffle Security said.”
  • Per Cyberscoop,
    • “Ubiquiti has patched 21 critical vulnerabilities, three of which were rated the highest severity possible, the communications product company said Wednesday [August 26] in a security bulletin.
    • In all, the company patched 22 vulnerabilities, with the last one rated “high,” it said in the bulletin.
    • Three of the vulnerabilities had a Common Vulnerability Scoring System rating of 10 out of 10. Each of them would allow a hacker to access privileges on the device or application.
    • All but one of the 22 vulnerabilities affect the UniFi line of products. The three maximum-security vulnerabilities are CVE-2026-77537CVE-2026-77550 and CVE-2026-77554.
  • Per Bleeping Computer,
    • “PaperCut is warning that hackers are actively exploiting a vulnerability in all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks.
    • “The company says it is aware of confirmed attacks on customers and is urging organizations with Internet-exposed PaperCut Application Servers to immediately restrict access to the web interfaces to trusted IP addresses.
    • “PaperCut Software security response team is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF,” reads an urgent security advisory published Thursday [August 27].
  • Per Dark Reading,
    • “A Chinese manufacturer has been planting backdoors inside of white-label routers sold in high volume around the globe.
    • “Shenzhen Zhibotong Electronics Co. Ltd. (ZBT) sells gobs of routers every year, if public evidence is to be believed. The 15-year-old company is the bestselling router manufacturer on Chinese e-commerce giant Alibaba.com, which lists its total annual output at 3.57 million units. Typically, those units are then sold to customers by companies other than ZBT, in countries like the Philippines, India, Canada, Australia, Germany, Bulgaria, Austria, Russia, and the US. According to its marketing, ZBT has exported its products to more than 50 countries and regions.
    • “On Aug. 6, Jacob Baines, chief technology officer (CTO) at VulnCheck, revealed that ZBT’s most updated router firmware contains a root-level backdoor. After a few more weeks of investigating, he discovered that, in fact, ZBT routers have contained a variety of backdoors dating several back years.”
  • and
    • “Fraudulent North Korean IT workers are getting better at infiltrating organizations, but a number of indicators can help organizations stay ahead.
    • “A new blog post from Huntress detailed a number of investigations the security firm conducted throughout 2026. Specifically, Huntress assisted several organizations this year in validating “suspicions that they’ve hired North Korean nationals posing as legitimate workers.”
    • In recent years, operatives from the Democratic People’s Republic of Korea (DPRK) have infamously posed as IT workers — generally through fake or stolen identities — to get hired at companies. Once hired, these employees send their wages back to the North Korean regime, and possibly plant malware or steal data depending on the government’s needs. Blog post authors Jai Minton and James Maclachlan wrote that these agents “have significantly improved and increased their activity over the past few years.”

From the ransomware front,

  • Reuters reports,
    • “A ransomware group ​said on Friday [Augut 28] it was putting up for auction a trove of ‌data it stole from Berlin [Germany] state agencies, and city officials refused to pay.
    • The Rhysida group, which researchers say operates from Russia or Eastern Europe, said on its website it took 5.79 ​terabytes of data including 46,500 contracts as well as emails, phone numbers, passwords ​and classified information.
    • “The group said it was auctioning the data ⁠at a starting price of 30 bitcoin ($77,622) in just under seven days, showing a ​countdown timer on its website.” * * *
    • Broadcaster RBB reported on Thursday evening that Berlin had received ransom demands for an unspecified amount following the attack.
    • “The state ​of Berlin will not submit to extortion,” Berlin Mayor Kai Wegner and Berlin’s interior senator, ​Iris Spranger, said in a joint statement on Friday, before the ransomware group claimed the attack ‌on ⁠their website.”
  • Technology.org relates,
    • An affiliate of the new Aur0ra ransomware group used Cursor, the AI coding assistant now owned by SpaceX, to draft attack sequences in Russian across 28 recovered chat sessions dated 8 April to 21 May.
    • Named victims include Ghent-based hygiene and cleaning products maker Christeyns, German garage door manufacturer Teckentrup, Scotland’s Helideck Certification Agency and Louisiana title insurer Bayou Title.
    • Researchers counted more than 20 targeted organisations across nine countries, with domain-level or interactive access achieved at 17 of them between April and July 2026.
  • Safe State tells us,
    • “A ransomware affiliate has been posing as a specialist rescue outfit and contacting victims before their attacks became public. Researchers describe the operation as a ransomware recovery scam that drains payments away from the criminal groups the affiliate works for. The entity calls itself Ransom Busters LTD.” * * *
    • “Anyone targeted by a ransomware recovery scam meets it at the worst possible moment, with systems down and pressure building. Treat unexpected contact as part of the attack. Route the message to the incident response team straight away and preserve it as evidence instead of replying. A sender who knows about a breach nobody has announced is either involved in it or holds the data taken during it.
    • “Law enforcement and established response firms remain the reliable route through a ransomware incident. Verify anyone claiming to represent a security company through channels you found yourself. Never use the contact details supplied in the email. Treat any guarantee of data deletion as unenforceable, because no payment to a criminal party comes with proof that copies no longer exist.
    • “Distrust inside ransomware-as-a-service operations may produce more of this behaviour. Affiliates have every reason to look for income outside the revenue splits their employers set. So the ransomware recovery scam running under the Ransom Busters name reads less like an isolated curiosity and more like a preview. Anyone willing to defraud the criminal enterprise paying them has already answered the question of what a victim’s data is worth to them.”
  • SC Media informs us,
    • “Organizations may assume they are unlikely ransomware targets because they are not large, high-profile, or strategically important. But ransomware attackers are often motivated by economics, not prestige. That means organizations that consider themselves low-risk may be more attractive targets than they realize.
    • “The ransomware affiliate model rewards attackers for finding victims that are likely to pay, not necessarily those that are difficult or impressive to compromise. This can make mid-sized organizations and businesses that depend heavily on critical systems especially attractive targets.
    • “For security teams, this changes how ransomware risk should be assessed. Company size, industry, and public profile tell only part of the story. Attackers may care more about whether an organization can pay, how costly downtime would be, and how quickly it needs to restore operations.
    • “The key question is not how important your organization looks to an attacker, but how valuable a ransomware payment could be.”
  • Dark Reading adds,
    • “A sophisticated malware family has emerged onto the cyberthreat scene that might foreshadow ransomware attacks that are more successful than usual.
    • “Marcus Hutchins and his colleagues at Expel that discovered it named the malware “SynkLoader,” since it throws so many ideas (“everything but the kitchen sink”) at trying to sneakily dig into corporate systems. It uses some conventional strategies — like executing code in-memory, running a scheduled task, etc. — but layers on a few interesting, novel tactics that make social engineering particularly compelling, and malware analysis especially frustrating.
    • “The program is new, and how its creators intend to use it remains a mystery. But evidence in the code suggests that it might be the baby of a ransomware group or initial access broker (IAB), used to set the stage for follow-on ransomware.”

From the cybersecurity business and defenses front,

    • PYMNTS reports,
      • Visa expanded the capabilities of its artificial intelligence-powered cyber risk management tool, Visa Vulnerability Agentic Harness (VVAH), to include not only discovery of vulnerabilities but also remediation and validation, the company said in a Thursday (Aug. 27) press release.
      • “Visa initially released VVAH in June after participating in Anthropic’s frontier AI cybersecurity initiative, Project Glasswing. While the first release of VVAH showed how AI can help security teams uncover vulnerabilities and assess exploitability, the latest release extends the workflow into remediation and validation of those vulnerabilities, according to the release.
      • “Visa also announced in the release that to help clients navigate the evolving threat landscape driven by AI, it has expanded its Visa Consulting and Analytics (VCA) Cybersecurity Advisory Practice to include new advisory services focused on assessing risk, prioritizing remediation efforts and strengthening resilience.
      • “The new advisory services include AI Cyber Leadership Education, VVAH-Informed Cybersecurity Maturity Assessment and VVAH Cyber Risk Prioritization and Roadmap, per the release.”
    • Cybersecurity Dive tells us,
      • “Operational silos, technological sprawl and cloud-platform blind spots are serious issues preventing organizations from spotting and repelling cyberattacks, the Cybersecurity and Infrastructure Security Agency (CISA) warned in a new report.
      • “Those were three of the main factors that allowed CISA’s red team to break into the networks of two unnamed partner organizations — one a government agency, the other a water utility — during recent simulated attacks. But although the red team was successful in both intrusions, it had a much harder time with one attack than with the other, a fact that CISA attributed to important differences in the targets’ operating procedures and use of technology.”
    • Security Week informs us,
      • “Palo Alto Networks’ Unit 42 team analyzed 405 malware samples tied to AI in some way, from ransomware partly written with the help of LLMs to installers that simply borrowed the name of a popular AI app.
      • “The researchers found that roughly 97% of the samples in the dataset never left a sandbox, research repository, or internal testing environment to reach a real target.
      • “Unit 42 cross-referenced the 405 file hashes against endpoint telemetry, network sessions forwarded for sandbox analysis, and internal alert records generated whenever a sample actually ran. Only 12 hashes surfaced on live endpoints, while a somewhat larger group (15-20 hashes) appeared in network sandbox traffic. Every one of the 12 samples detected on protected endpoints triggered a security alert.
      • “The samples that never reached production fall into three groups. The largest is proof-of-concept code built to demonstrate a technique: configured to target only local or private networks, filled with debug output no real attacker would leave behind, and uploaded once by a research lab or university. 
      • “A second group comes from organizations testing their own defenses against previously reported AI malware, identifiable by repeated uploads of the same file from the same source in a short window. A third group uses AI branding purely as bait, dressing up an ordinary payload as installers for well-known AI products with no actual AI functionality behind them.
      • “The 12 samples that did reach live endpoints spanned five malware families across three countries, with no concentration in any particular industry or region.” 
    • Beckers Health IT points out,
      • “Healthcare’s cybersecurity workforce problem may have less to do with finding more candidates and more to do with changing who health systems are willing to hire, how they develop them and what they do to keep them.
      • “Cybersecurity leaders at four health systems told Becker’s that continually competing for the same pool of experienced professionals is not a sustainable strategy as cyber risks expand and the skills needed to manage them become more complex.
      • “The cybersecurity workforce challenge has shifted from a talent shortage to a talent entry problem,” Trevor Martin, vice president, chief information security officer and interim chief technology officer at Madison, Wis.-based UW Health, said.
      • “Mr. Martin said there are many high-potential people trying to enter cybersecurity, but organizations frequently prioritize candidates who already have experience instead of creating pathways for people to gain it.
      • “Healthcare could benefit from hiring more heavily for aptitude, adaptability and an understanding of business and clinical operations, then developing those employees internally, he said. UW Health has found success moving talent from adjacent IT disciplines into cybersecurity roles and providing opportunities for employees to grow within the field.”
    • Dark Reading notes,
      • “As the “vulnpocalypse” reshapes the bug bounty industry, one class of researcher may face the greatest pressure: independent hunters who rely on midtier vulnerabilities — those worth roughly $10,000 to $50,000 — to make a living.
      • “It is no secret that large language models (LLMs) have led to a mass of bug reports and an increase in vulnerability discovery. It is also no secret that the platforms and companies that run much of the bug bounty industry have faced increased triage and payout times.
      • “Multiple bug bounty operators interviewed by Dark Reading report dramatic increases in submission volume over the past year. HackerOne CEO Kara Sprague says report volume has roughly doubled year over year. Dustin Childs, head of threat awareness for TrendAI’s Zero Day Initiative (ZDI), says the company’s submission rate went up 450% year-over-year in April of this year, although volumes have moderated since that peak. Bugcrowd CEO Dave Gerry said the firm saw a submissions spike of more than 300% during a three-week surge period, but “now it’s normalized where we’re about double the volume we saw historically.”
    • Per a National Institute of Standards and Technology news release,
      • “The final version of NIST Special Publication (SP) 1347, Cybersecurity Framework (CSF) 2.0 Informative References Quick-Start Guidehas published. Thank you to all who provided comments during the public comment period.  
      • “This publication explains what informative references are and how they support achieving the outcomes of the CSF 2.0. The guide introduces readers to NIST tools available for accessing, viewing, and using informative references for cybersecurity risk management, including direct download, the CSF 2.0 Reference Tool, and the Online Informative References Program. The document also provides two sample use cases along with examples of how artificial intelligence (AI) tools can support reference data use when implemented with continuous evaluation and improvement.” 
    • Here’s a link to Dark Reading’s CISO Corner.

    Friday report

    Simplicity is a virtue.

    From Washington, DC

    • Beckers Hospital Review reports,
      • “CMS said its enforcement efforts have resulted in blocking more than $1.6 billion in possibly improper Medicare lab payments throughout President Trump’s administration.
      • “An Aug. 28 CMS news release said these enforcement actions included savings of $732 million from 157 providers with revoked Medicare privileges, and a CMS investigation of 600 labs that resulted in 185 payment suspensions with more than $500 million in potentially fraudulent payments stopped. There were also 85 law enforcement referrals from a contractor that led to the prevention of $127 million in possibly fraudulent payments, and there was a recoupment of more than $276 million from 442 flagged overpayments to suspect labs.
      • “CMS had been using AI, among other analytics tools, to mine original Medicare claims. CMS focused on several kinds of lab fraud, such as labs billing for up-coded services. The news release said lab fraud can take place across services, including pathogen detection, high-complexity drug tests and genetic testing.
      • “Since the start of 2026, the CMS Fraud Defense Operations Center has been responsible for more than $371 million in Medicare suspended payments implicating 267 providers and suppliers.
      • “The news release comes amid CMS’ broader anti-fraud push across government programs, including Medicaid.”
    • FEHBlog observation — I find it hard to believe that these scoundrels would similarly attach FEHB plans for which private carriers hold the risk.
    • Beckers Payer Issues relates,
      • “The Labor Department is proposing a rule that would set criteria for employer associations to sponsor association health plans that qualify as employee welfare benefit and group health plans under the Employee Retirement Income Security Act.
      • Received by the Office of Information and Regulatory Affairs Aug. 11, the rule is under review. ERISA outlines minimum standards for employee benefit plans.”
    • Beckers Behavioral Health adds,
      • “The Drug Enforcement Administration has submitted a final rule on telehealth prescribing of controlled substances to the White House for regulatory review.
      • “The DEA filed the rule Aug. 25 and listed it as “economically significant,” an Office of Management and Budget designation reserved for regulations expected to have an annual economic impact of at least $100 million.
      • “The rule would establish a long-promised special registration pathway allowing DEA-registered practitioners to prescribe controlled substances, including medications for opioid use disorder and attention-deficit/hyperactivity disorder, via telemedicine. It follows a proposed version of the rule that drew more than 6,400 public comments and would replace a series of temporary extensions the DEA has issued since pandemic-era flexibilities suspended the in-person visit requirement for such prescriptions. The agency’s latest extension of those temporary flexibilities runs through Dec. 31, 2026.”
    • The American Hospital Association News tells us,
      • “The Centers for Medicare & Medicaid Services’ six-month moratorium on the enrollment of new durable medical equipment, prosthetics, orthotics and supply companies in Medicare expired Aug. 27. CMS said that national provider enrollment contractors have resumed accepting initial enrollment applications from those suppliers. The agency said that suppliers should submit applications as soon as possible to allow contractors the maximum time for processing before the bidding window opens for the 2028 round of the DMEPOS Competitive Bidding Program.”
    • NCQA informs us,
      • “To align with the industry’s transition to digital quality measurement and the need for more streamlined data exchange, NCQA is creating a new HEDIS® measure for Transitions of Care (TRC) that uses the Electronic Clinical Data Systems (ECDS) reporting methodology.
      • “The current TRC measure assesses performance through a hybrid reporting methodology that combines administrative claims data and medical record review for a sample of eligible members. Because the hybrid TRC measure is included in the CMS Medicare Star Ratings, NCQA is coordinating this effort with CMS and other stakeholders.
      • “This measure is important because it evaluates care transitions, which present opportunities for missed connections that often require patients and families to fill in the gaps,” says Fern M., Director of Digital Quality Informatics at NCQA. “We know that health plans, technology vendors and policymakers are heavily invested in this measure, so we want to be as transparent as possible and allow organizations enough time to prepare for the changes.”
      • “The earliest implementation of the new ECDS TRC measure would be Measurement Year (MY) 2028, with the intention of retiring the hybrid version of the TRC measure in MY 2029.”

    From the U.S. Office of Personnel Management front,

    • Govexec reports,
      • “Most federal employees would see their pay frozen at 2026 levels next year under an alternative pay plan issued by President Trump this week, though for the second straight year, federal law enforcement officers would receive a 3.8% increase.
      • “Trump first proposed the pay freeze as part of his fiscal 2027 budget proposal. Though the document was silent on federal employee compensation, officials with the Office of Management and Budget quickly clarified that its omission equated to a planned freeze for 2027.
      • “In a letter to House Speaker Mike Johnson, dated Thursday, Trump said increasing most federal employees’ pay would be “unacceptable and unfair” given the inflation that occurred under the Biden administration. Inflation actually has risen from 2.8% when former President Biden left office to 3.3% as of last month.
      • “I have therefore decided to set at zero the pay adjustment to be made for the 2027 pay year,” Trump wrote. “This decision will maintain fiscal responsibility without harming the government’s ability to recruit and retain well qualified employees.”
      • “But in the next paragraph, Trump said that for the second straight year, he instructed the Office of Personnel Management to issue a 3.8% increase in basic pay to federal law enforcement personnel next year, “to increase recruitment and retention” in those roles.”
    • Federal News Network adds,
      • “Up to 400 federal positions can now earn salaries of $400,000. A new final rule from the Office of Personnel Management allows the higher pay rates for hundreds of workers under an authority known as “critical position pay.” The authority is meant to help agencies recruit and retain highly qualified and specialized government workers in mission-critical roles. OPM’s final rule this week aligns with President Donald Trump’s orders earlier this year to use the pay authority for up to 400 national security roles.(Final rule on critical position pay authority – Office of Personnel Management)”
    • Per an OPM news release,
      • “US Office of Personnel Management (OPM) Director Scott Kupor joined Squawk Box on CNBC to discuss the Trump Administration’s efforts to recruit top tech talent and advance his vision for a more tech-driven federal government.”

    From the Food and Drug Administration front,

    • Cardiovascular Business reports,
      • “The U.S. Food and Drug Administration (FDA) is warning the public about an ongoing safety issue with certain intravascular catheters manufactured by Boston Scientific. These devices are being removed from the market, and Boston Scientific has officially decided to discontinue them going forward.
      • “The devices in question are Boston Scientific’s single-use Imager II Angiographic Catheters, which interventional cardiologists, vascular surgeons and interventional radiologists use to capture images of a patient’s peripheral vasculature. They are available in a variety of shapes and lengths. 
      • “This warning, which covers all Imagers II Angiographic Catheters, was put in place due to a manufacturing defect that can cause the catheter tip to degrade or detach from the rest of the device.”
    • MedTech Dive adds,
      • “Medtronic has recalled a pH monitoring capsule over a risk linked to 184 serious injuries, the Food and Drug Administration said Thursday.
      • “The recall, which the FDA communicated in an early alert notice, affects Bravo CF capsules that pose risks including perforation of the esophagus, obstruction of the airway and blood loss.
      • Medtronic withdrew a subset of the newly recalled Bravo CF lots last year. The FDA said the same failures triggered both recalls, but the underlying causes of the problems are different.”
    • Fierce Pharma relates,
      • “In their high-profile competition in the diabetes and obesity markets, Eli Lilly has proven adept at playing catch-up with Novo Nordisk.
      • “On Friday, Lilly checked another item off that list as it secured FDA approval for Mounjaro to reduce the risk of major adverse cardiovascular events (MACE), including CV death, heart attack or stroke, in at-risk adults with Type 2 diabetes. With the nod, Lilly matches the 2020 approval Novo received for its diabetes treatment, Ozempic, to lower the risk of adverse cardiovascular events in at-risk patients.
      • “The label expansions came on similar timelines for the rivals. While Novo achieved its heart-helping endorsement three years after the FDA originally approved Ozempic, Lilly gained its expansion four years after the FDA first signed off on Mounjaro.”
    • Per a FDA news release,
      • “The U.S. Food and Drug Administration today approved Mimrylo (rusfertide), a new treatment for adults with polycythemia vera, a rare blood disorder that causes the body to make too many red blood cells. The excess cells can thicken the blood and increase the risk of cardiovascular issues, such as blood clots, stroke and heart attack.
      • “Mimrylo offers a new treatment approach for patients whose disease has not been adequately controlled with existing therapies. It is the first approved treatment for polycythemia vera that mimics hepcidin, a hormone that naturally regulates iron in the body. By limiting the iron available to make new red blood cells, Mimrylo helps reduce their overproduction and keep red blood cell levels under control. This novel approach offers a new option for patients who have not achieved adequate control with existing therapies.

    From the judicial front,

    • Per a Department of Justice news release,
      • “The Justice Department, together with the Drug Enforcement Administration (DEA), today announced a $50 million settlement with Walmart Inc. (Walmart) to resolve allegations that Walmart pharmacies illegally filled thousands of invalid prescriptions for opioids and other controlled substances in violation of the Controlled Substances Act (CSA).” * * *
      • “The government’s complaint — filed on Dec. 22, 2020, and amended in 2022 in the U.S. District Court for the District of Delaware — alleged that since June 26, 2013, Walmart filled invalid prescriptions through the knowing actions of individuals on its compliance team and the knowing actions of its pharmacists. * * *
      • “In addition to the monetary payment announced today, Walmart has entered into a memorandum of agreement with DEA to address its future obligations in dispensing controlled substances. This agreement requires Walmart to establish a hotline for both employees and patients to report suspected illegal dispensing of controlled substances, proactively monitor the dispensing patterns of its pharmacies to identify and address potentially illegal dispensing, and establish a process to evaluate prescribers suspected of illegal prescribing.” * * *
      • The claims resolved by the settlement are allegations only; there has been no determination of liability.
    • STAT News adds,
      • “A U.S. appeals court [panel for the 5th Circuit] ruled the Food and Drug Administration went through the proper process when it declared Novo Nordisk and Eli Lilly’s diabetes and obesity drugs are no longer in shortage, Bloomberg Law notes. The order is a loss for the Outsourcing Facilities Association, which representing large-scale compounders and challenged FDA decisions in the last two years that shortages ended for Novo’s Ozempic and Wegovy and Lilly’s Mounjaro and Zepbound. That declaration restricted compounders from legally mass-producing versions of the drugs.”

    From the public health and medical / Rx research front

    • The Center for Disease Control and Prevention announced today,
      • “As of August 28, 2026, the amount of acute respiratory illness causing people to seek health care is very low.
      • “National and regional COVID-19 activity is increasing. 
      • “Rhinovirus/Enterovirus (RV/EV) is increasing nationally.”
    • The American Journal of Managed Care reports,
      • “Children and young adults who were unvaccinated and infected with COVID-19 were at an increased risk of developing myocarditis, pericarditis, and mortality when compared with those who were vaccinated against COVID-19 with the Pfizer-BioNTech vaccine and not infected.1
      • “The recent findings published in Vaccine underscored the BNT162b2 vaccine’s favorable benefit profile, particularly for children and young adults. Prior research, also published in Vaccine, described COVID-19 vaccinations in general as reducing the risk of severe or prolonged disease—such as long COVID—in adolescents.2 These data, in tandem with the more recent study, provide ample evidence supporting preventive action against COVID-19 for children and adults.” 
    • The University of Minnesota CIDRAP adds,
      • “Giving children antiviral drugs within the first two days of the onset of flu symptoms reduces their likelihood of hospitalization by 81%, a study published last week in Pediatrics finds. 
      • “This protective effect remained robust among children aged 5 years or younger,” wrote the authors, led by scientists at Hsinchu Municipal MacKay Children’s Hospital in Taiwan.” * * *
      • “In an accompanying commentary, James Antoon, MD, PhD, MPH, and Kathryn Edwards MD, both of Vanderbilt University, noted that some pediatricians seem reluctant to use antivirals, adding that about 40% of high-risk pediatric flu patients go without them. 
      • “They urged more widespread use of the drugs. “The time has come for antivirals to be used in children with influenza,” they said. “With greater public hesitancy regarding vaccines, declining seasonal influenza vaccination rates, and recent influenza seasons with record pediatric deaths and hospitalizations, providers should strongly consider the use of antivirals in high-risk and hospitalized patients.” 
    • and
      • “Pennsylvania continues to see numbers climb in its ongoing measles outbreak, with 86 new cases added this week, which brings the total number of cases to 460 with 83 hospitalizations, according to an update today of the state’s measles dashboard. None of the cases have occurred in fully vaccinated people.” * * *
      • “For the third week in a row, Utah, which had the largest measles outbreak, reported no new cases. The state’s tally remains at 518. 
      • “The Georgia Department of Health confirmed four cases of measles linked to a daycare in the Atlanta area, with cases occurring in children who were unvaccinated or had not received the full measles, mumps, and rubella (MMR) vaccine series. 
      • “While the Centers for Disease Control and Prevention (CDC) typically update their measles numbers on Friday, a notification said the August 28, 2026, data have been delayed but will be updated as soon as possible. As of August 20, 2026, the CDC said there were 2,777 cases of measles in 47 states. Of those cases, 94% have been in unvaccinated individuals.”
    • Healio relates
      • “Rates of substance use fell among adolescents and young adults across most substances between 2021 and 2025, even as marijuana use increased among adults aged 26 years and older, according to the 2025 National Survey on Drug Use and Health.
      • “Substance use began declining among children aged 12 to 17 years prior to the COVID-19 pandemic, and those trends seem to be continuing among young adults aged 18 to 25 years in the new data, said Chris Jones, PharmD, DrPH, MPH, director of the Center for Substance Abuse Prevention, Substance Abuse and Mental Health Services Administration (SAMHSA).
      • “Coupling that with other surveys that show downward trends, that seems to be a durable effect that we’re seeing in recent years,” Jones told Healio.”
    • Cardiovascular Business tells us,
      • “Patients with peripheral artery disease (PAD) face a significantly higher risk of developing new-onset atrial fibrillation (NOAF), according to a new meta-analysis published in JACC: Advances.[1]
      • “The study’s authors reviewed data from more than 1,500 studies, landing on seven they wanted to focus on for this research. All studies were associated with a low risk of bias. The oldest study was performed in 2013 and the most recent was performed in 2022. All five studies were observational; five were prospective and the other two were retrospective. One study enrolled only women.
      • “In total, this meta-analysis included data from 763,919 patients. Approximately 56,000 of those patients had PAD as determined by ankle-brachial index (ABI) or a clinical diagnosis. In addition, there were approximately 26,000 cases of NOAF during follow-up. 
      • “Overall, researchers noted, PAD was linked to a 34% higher risk of developing NOAF. The hazard ratio was 1.34.” 
    • Genetic Engineering and Biotechnology News informs us,
      • “Researchers at the University of Toronto have developed a next-generation RNA therapeutic strategy that could have the potential to treat a wide range of genetic diseases that share certain types of disease-causing mutations. The team showed that chemically enhanced suppressor transfer RNAs (sup-tRNAs) combined with a lung-targeted delivery system can restore production of a critical protein in models of cystic fibrosis (CF) caused by “nonsense mutations.”
      • ‘These mutations introduce a premature stop signal into the genetic instructions for making a protein. The result is that cells may produce little or no full-length functional protein, disrupting vital functions in ways that are difficult to treat.
      • “The researchers, led by Bowen Li, PhD, an associate professor in U of T’s Leslie Dan Faculty of Pharmacy, engineered sup-tRNAs to help cells read through these premature stop signals introduced by nonsense mutations into the mRNAs, and complete production of full-length proteins that would otherwise be truncated or absent. They tested the approach in bronchial epithelial cells, mouse models, and patient-derived cystic fibrosis organoids and found that the chemical modifications increased the readthrough of premature termination codons and tRNA aminoacylation, prolonged the tRNAs’ functional activity, and reduced innate immune activation. Moreover, the approach restored CFTR protein production and function across cell, animal, and patient-derived organoid models. The researchers also found that the approach can be combined with existing cystic fibrosis drugs, suggesting the potential for combination therapy.”
    • The New York Times points out,
      • “A one-time gene-editing treatment to lower cholesterol had long-lasting effects a year later, scientists reported on Friday. The results highlight the potential to treat even common diseases by altering people’s genes.
      • “In the small study, which followed only 15 patients, participants who got the highest dose saw their cholesterol levels plunge by half — and stay that way for a year. The results were presented at the European Society of Cardiology Congress and published in the New England Journal of Medicine.
      • “Earlier this year, a similar “one-and-done” clinical trial that used a different gene-editing approach also reported significantly reduced “bad” LDL cholesterol in 35 patients.
      • “Both efforts are early safety studies and are years away from becoming an option people will be offered in a doctor’s office. But an approach that once seemed almost outlandishly far out has inched closer to reality as evidence accrues that it works, and that the results stick.”

    From the U.S. healthcare business and artificial intelligence front,

    • Beckers Hospital Review reports,
      • “Health system CEOs are navigating a growing list of financial pressures, including Medicaid coverage and reimbursement changes under HR 1 and ongoing payment and policy challenges surrounding the federal 340B drug discount program. Site-neutral payment adds another consideration as health systems weigh where to invest and deliver care. 
      • “At Winchester, Va.-based Valley Health, concerns about site-neutral payment are already influencing where the system adds outpatient capacity. President and CEO Mark Nantz said Valley Health is keeping new outpatient sites on its hospital campuses in part to preserve hospital outpatient department rates. Peter Slavin, MD, president and CEO of Los Angeles-based Cedars-Sinai, said eliminating the outpatient payment differential entirely could cost Cedars-Sinai Medical Center about $200 million annually. J. Stephen Jones, MD, president and CEO of Fairfax, Va.-based Inova, said the policy has not changed where the system invests, but it has prompted greater focus on site of care when evaluating projects.
      • “It disrupts the financial model that includes things like 340B, hospital outpatient department rates and Medicare disproportionate share,” Mr. Nantz told Becker’s. “All of those things together help us cobble together a pretty fragile financial model. And so if any part of that financial model, somebody starts pulling the string on it, it unravels pretty fast.”
    • Beckers ASC Review lets us know,
      • “Hospital-employed physicians command significantly higher commercial reimbursement rates than independent peers across every specialty, with a $92 average gap in blended evaluation and management rates in the Chicago market, and the cost difference extends well beyond the professional fee, according to 2026 Trilliant Health price transparency data.
      • “Employed urologists averaged $263 per blended E/M visit compared with $141 for independent urologists, a $122 gap. Employed gastroenterologists averaged $240 versus $141 for independents, employed orthopedic surgeons averaged $260 versus $154, and employed cardiologists averaged $234 versus $144. Even the smallest gap, primary care at $196 employed versus $154 independent, represents a 27% premium for identical services.
      • “The stakes are significant given how many physicians have moved into hospital employment. Approximately 253,000 physicians became employees of hospitals or corporate entities between January 2018 and January 2026, and 79.5% of physicians who sold their practices to a hospital or health system cited the ability to negotiate higher payment rates as an important or very important reason for doing so.”
    • Per Beckers Physician Leadership,
      • “More than 60% of physicians are not satisfied with how the medical profession deals with work-life balance, according to a new report from Medscape
      • “State of the Medical Profession Index Report 2026,” published Aug. 28, surveyed more than 1,000 physicians across 29 specialties to rate their satisfaction with how the profession is dealing with key issues, and their optimism levels for improvement going forward.” 
    • Healthcare Dive relates,
      • “Virtual healthcare company Sword Health is planning to acquire digital mindfulness company Headspace, according to a regulatory filing.
      • “Headspace’s parent company OrangeDot is seeking to be acquired by Sword in an all-cash deal, the company told regulators in Massachusetts on July 22.
      • “The acquisition is expected to close on Sept. 14. The financial terms of the deal were not disclosed. Neither Headspace nor Sword Health responded to a request for comment by publication time.”
    • Managed Care Executive tells us,
      • “Cancer biosimilars are associated with lower costs for both insurers and patients, according to a new study by researchers at the UCLA Health Jonsson Comprehensive Cancer Center. Patients with cancer who exclusively used biosimilars had average monthly costs that were $3,820 lower for insurers and $39.50 lower out-of-pocket costs compared with patients who exclusively used the branded biologic drugs, according to a study published today in JAMA Oncology.
      • “Although the savings were substantially greater for insurers than for patients, even modest reductions in out-of-pocket costs may be meaningful for people facing the financial challenges of cancer care,” senior author Tina Shih, Ph.D., director of the Cancer Health Economics Research Program at the UCLA Health Jonsson Comprehensive Cancer Center, said in a news release. Shih is also a professor of Health Economics in the Department of Radiation Oncology.”
    • Fierce Pharma informs us,
      • “Twenty weeks into its launch, Eli Lilly’s Foundayo has finally exceeded 40,000 in weekly prescriptions, according to IQVIA data cited by Citi. The oral GLP-1 drug posted 40,862 scripts last week, bouncing back from a small dip the week prior. Still, the drug’s scripts level is no match for the roughly 57K that Novo Nordisk’s Wegovy pill garnered at week 6 of its own launch.
      • In its 33rd week of launch, the Wegovy pill booked roughly 175K scripts, slightly down from 176K, per IQVIA. The share of the oral version of semaglutide in all Wegovy obesity scripts was flat week over week at 35%. All told, across the pill and the injectable, Wegovy’s weekly scripts were a little over 500K, down 0.8% sequentially.
      • “As Jefferies analysts observed in an Aug. 21 note, Wegovy has been relatively flat since the Medicare GLP-1 Bridge program began July 1.
      • “Overall, the roughly 60%-40% obesity market share split between Lilly and Novo remained stable, as Lilly’s Zepbound held its ground as the most popular drug.”

    Thursday report

    Simplicity is a virtue.

    • Fierce Pharma points out,
      • “The Trump administration looks set to unveil a new slate of most-favored-nation (MFN) drug pricing deals with several mid-sized biopharma companies, according to Bloomberg.
      • “The announcement is expected on Monday [August 31, 2026], the news service reported this week, citing sources familiar with the plan. Drugmakers that have agreed to the voluntary deals are expected to provide their products to state Medicaid programs at prices aligned with those they charge in foreign countries.  
      • “In exchange, the companies could secure tariff relief and may win exemption from Medicare pilot discount programs that are in the works, Bloomberg wrote.” 
    • Per a Centers for Medicare and Medicaid Services news release,
      • “The Trump Administration announced today that a $93.3 million investment is being delivered to help rural hospitals advance new state-of-the-art models of care and improve health outcomes for Georgians through the federal Rural Health Transformation Program (RHTP). 
      • “This investment will help 87 rural hospitals prepare for value-based care, expand training and recruitment for nurses, EMTs and paramedics, and improve access to maternal and behavioral health services, newborn screening, and other critical health services through telehealth, transportation and expanded care networks. It will also bring next-generation technology to rural communities—including surgical robotics, dementia care capacity, and telehealth infrastructure—to modernize care. By strengthening and expanding rural care, this funding will also help retain health care professionals in rural Georgia. This investment will strengthen rural hospitals, expand telehealth and healthcare access, build dementia care capacity, and grow the rural healthcare workforce through technology-enabled care initiatives across the state. With these investments, Georgia has now committed the full $218 million awarded to the state for its first year of funding through the RHTP.”
    • The American Hospital Association relates,
      • “The Centers for Medicare & Medicaid Services has released a fact sheet and FAQs on the 340B Part D claims data repository that will go live Oct. 1. Data submissions would currently be voluntary for 340B hospitals. However, the agency recently proposed to make data submissions mandatory starting in 2027. The fact sheet and FAQ provide an overview of the repository along with other key details.”
    • Per a Health and Human Services Department news release,
      • “The U.S. Department of Health and Human Services (HHS) today announced [in the news release] the nine winners of the 2026 KidneyX EMPOWER: Living Link Prize Challenge, a $4 million national competition to accelerate innovation supporting living kidney donors and patients who depend on them. The challenge was run through the Kidney Innovation Accelerator (KidneyX), a public-private partnership between HHS and the American Society of Nephrology (ASN).
      • “Every American waiting for a kidney deserves the best chance at a longer, healthier life,” said HHS Secretary Robert F. Kennedy, Jr. “Living kidney donation saves lives, yet too many willing donors face barriers that should not exist. We are removing those barriers and backing innovators with practical solutions that support donors, strengthen transplant care, and give more Americans a chance to live.”
    • The International Foundation of Employee Benefit Plans reports,
      • “The Departments of Labor (DOL), Health and Human Services (HHS), and the Treasury (collectively, the Departments) released Affordable Care Act (ACA) and Health Insurance Portability and Accountability Act (HIPAA) Implementation Frequently Asked Questions (FAQs) Part 74 addressing health-contingent wellness programs, including tobacco-related wellness programs. The FAQs cover completion of reasonable alternative standard and disclosure requirements. 
      • “The new guidance comes after tobacco-related wellness programs have been the subject of recent class-action lawsuits challenging the tobacco surcharges some employers add to premiums for their group health plans through workplace wellness programs. The FAQs released today announce the Departments’ approach to enforcement for health-contingent wellness programs that reward an employee if they satisfy a standard related to a health factor.
      • “Until further guidance or regulations are issued, the departments will not take enforcement action against plans or issuers that do not give employees the wellness program reward retroactively to the beginning of the plan year after the employee completes a reasonable alternative standard. Under the terms of the enforcement relief in these FAQs, plans and issuers only need to provide the reward prospectively, from the point where the employee completes the alternative standard, if retroactive rewards are not otherwise provided.”
    • Beckers Hospital Review tells us,
      • “Medicare’s GLP-1 Bridge program is seeing early uptake at major retail pharmacies, with CVS and Walgreens each filling about 100,000 prescriptions less than two months after the program launched in July, according to an Aug. 26 NPR report.
      • “We expected there would be uptake,” Walgreens’ chief pharmacy officer Rick Gates told NPR. “I think there’s been a little bit more uptake than we even expected.”
      • “Walgreens stocked additional Wegovy, Zepbound and Foundayo ahead of the launch but has not experienced supply issues. Walmart said Bridge prescriptions have also increased week over week and have been filled at more than 5,000 Walmart and Sam’s Club pharmacies nationwide.
    • The No Suprises Act’s (“NSA”) regulating agencies, which includes OPM, corrected errors found in the final Independent Dispute Resolution rule published in the Federal Register on June 5, 2026.

    From the U.S. Office of Personnel Management front,\

    • Federal News Network reports,
      • “Artificial intelligence may become a more prominent part of the federal hiring process, following new guidance from the Office of Personnel Management.
      • “In a memo Thursday, OPM encouraged agencies to more widely adopt AI tools in their recruitment efforts. Without increasing AI use, agencies may be compromising the effectiveness and efficiency of the federal hiring process, OPM said.
      • “Despite 2025 guidance from the Office of Management and Budget defining “high-impact” standards for AI usage, agencies have been “overly cautious” about using the technology in hiring, said Adam Starr, OPM’s CIO and a senior advisor.
      • “Too often, agencies were defaulting to the view that any use of AI in hiring was subject to the high-impact standard. In reality, that is not the case,” Starr said Thursday in a blog post. “Instead, the inclusion of AI as a complement to human judgment is not only acceptable but leads to better outcomes.”
    • Tammy Flanagan, writing in Govexec, advises “Want to retire at the end of 2026? Start planning now.”
      • OPM is still working through a sizable retirement backlog, and year-end retirees have plenty to sort out before they leave federal service.

    From the Food and Drug Administration front,

    • The American Hospital Association reports,
      • “The Food and Drug Administration has issued an early alert for all automated Impella controllers by Abiomed following an issue that has caused three deaths and 37 serious injuries as of Aug. 17. The alert was issued due to the products experiencing purge cassette recognition issues resulting from failures of the purge flag component within the purge pressure sensor assembly. Abiomed sent a letter to all affected customers recommending the devices be removed from where they are used or sold.” 
    • The Washington Post relates,
      • “The Food and Drug Administration on Thursday green-lit updated coronavirus vaccines for higher-risk Americans, such as older adults and people with at least one underlying health condition, vaccine manufacturers announced.
      • “The approved shots from vaccine manufacturers Pfizer-BioNTech and Moderna, which make mRNA-based vaccines, have an updated formulation aimed at better targeting the coronavirus variants circulating around the country. The FDA also cleared an updated vaccine from Sanofi, which doesn’t use mRNA-based technology and was originally licensed by Novavax, a Sanofi spokesperson confirmed. The companies said the vaccines are expected to be available in the coming days.”
      • “Most Americans typically get vaccinated against the coronavirus at retail pharmacies.
      • “Pharmacies are actively preparing to receive the updated shots, so they can begin vaccinations as soon as they receive shipments and all state requirements are met, according to Brigid Groves, a vice president at the American Pharmacists Association.”
    • Reuters tells us,
      • “The U.S. Food and Drug Administration said on Thursday it approved a ​treatment from Roivant (ROIV.O) and partner Priovant Therapeutics for a rare disease, ‌making it the first oral drug for the condition affecting skin and muscles.” * * *
      • “Branded as Lisraya, the drug was approved for ​dermatomyositis, a condition that causes painful skin rashes and progressive muscle weakness ​and, if untreated, can severely reduce quality of life.”
    • CNBC informs us,
      • “The Food and Drug Administration approved a once-daily HIV pill from Gilead that could help simplify care for some patients whose virus is already under control but who remain on complicated treatment regimens. 
      • “The tablet combines bictegravir, the backbone of Gilead’s blockbuster HIV pill Biktarvy, with lenacapavir, a centerpiece of the company’s long-term strategy for HIV treatment and prevention. 
      • “The new pill is also aimed at people who are doing well on a single-tablet regimen, including Biktarvy, and want to switch to a new treatment.”

    From the judicial front,

    • Michelle Roberts, an attorney, lets us know,
      • In Central States v. McClain [decided August 26, 2026, a panel of the U.S. Court of Appeals for the] Seventh Circuit held that ERISA does not preempt Arkansas Insurance Department Rule 128. Applying Rutledge, the court treated the Rule’s dispensing fee requirement as a permissible cost regulation rather than a mandate dictating plan choices, and under Gobeille, it held that the Rule’s reporting requirement fell within the exception for reporting incidental to an unpreempted state law. The panel affirmed dismissal at the pleading stage while expressly reserving whether Congress’s new pharmacy-compensation reporting provision under 29 U.S.C. § 1185o will change the analysis once it takes effect.
    • In National Infusion Centers v. Kennedy, also decided August 26, 2026, held
      • “The Plaintiffs challenge the constitutionality of the Drug Pricing Program created by the Inflation Reduction Act of 2022. They claim violations of the nondelegation doctrine, the Eighth Amendment’s Excessive Fines Clause, and the Fifth Amendment’s Due Process Clause. The district court granted the Government’s motion for summary judgment. We AFFIRM.”
    • Govexec reports,
      • “The Equal Employment Opportunity Commission voted 2-1 Wednesday to propose new regulations that would overhaul how federal workers may pursue workplace discrimination claims, removing employees’ right to request a hearing before an administrative judge and outright banning class action cases outside of federal court.
      • “Currently, federal workers alleging discrimination at their employing agency must undergo up to 90 days of pre-complaint counseling, which includes informing employees about the EEO process and sometimes mediation, after which their agency will conduct an internal investigation. Once that is complete—or after 180 days—the employee may request a hearing before an EEOC administrative judge.
      • “But under a new proposed rule, set for publication Friday in the Federal Register, complainants would no longer go through pre-complaint counseling, instead directly filing their complaints to EEOC within 60 days of the alleged discriminatory incident. And they would no longer be guaranteed a hearing; that decision would instead be made by officials within the EEOC’s Office of the Federal Sector.
      • “Under the plan, complainants would have to affirmatively request a hearing when they appeal a final agency decision, and in some cases submit an explanation justifying its need. Those who do receive a hearing under the new process would no longer have the benefit of discovery, a practice by which parties can request and receive documentation related to the case.
      • “Additionally, while employees with similar allegations of discrimination may elect to have their individual complaints processed “jointly,” EEOC would cease consideration of class action cases. If employees wish to proceed as a class, they would each have to exhaust their individual cases before the agency and then file a class action lawsuit in federal court.”

    From the public health and medical / Rx research front

    • The Wall Street Journal reports.
      • “[H]ow much water do we really need to drink a day? The question feels more pressing than ever given rising temperaturesheat waves and the fact that chugging water is almost a competitive sport these days. The answer may be less than you think and varies based on your size, health, activity level and where you live.” * * *
      • “The most cited recommendations for water come from the National Academy of Medicine, which calls for a total daily fluid intake of 3.7 liters for men and 2.7 liters for women. 
      • “But here’s the thing: That is total fluid intake, not water specifically. And here’s the other thing: Roughly 20% of our fluids come directly from food, studies have found.
      • “That leaves roughly two liters of fluids daily for women and three for men, says Kavouras. That translates to about 68 ounces and 101 ounces from beverages. 
      • “Stavros Kavouras, founding director of Arizona State University’s Hydration Science Lab in Phoenix and DrHydration on social media. estimates the average pour of water in the U.S. is 12 to 16 ounces. So that works out to about four to six glasses of fluids daily for women and six to eight for men.”
    • The New York Times relates,
      • “Scientists have uncovered a wealth of clues about how genetic mutations lead to severe forms of autism, offering opportunities for testing drugs that could treat the condition, according to a study published Thursday.
      • “The researchers charted how mutations change the way proteins work together in cells, altering the development of the brain.
      • “This is making maps of unknown territories that’s really necessary to move the biology forward,” said Dan Geschwind, a neurogeneticist at the University of California, Los Angeles, who was not involved in the study.
      • “Researchers have been studying autism for over 80 years, but it has only been in recent years that they have been able to explore its molecular biology. One reason that progress has been so slow is that autism is not just one condition, but a broad constellation of them.”
    • Radiology Business adds,
      • “A new analysis details the prevalence of amyloid-related imaging abnormalities (ARIA) on MRI in individuals who are being treated with new Alzheimer’s disease therapies. 
      • “Kisunla (donanemab) is an FDA-approved intravenous monoclonal antibody infusion for early symptomatic Alzheimer’s disease; it works by essentially scrubbing amyloid deposits from the brain, which in turn helps reduce cognitive symptoms associated with the neurodegenerative disease. While effective, a known side effect of the treatment is that is causes ARIA. 
      • “Symptoms of ARIA include headache, confusion, dizziness, vision changes and nausea, but if left unchecked, the symptoms can become severe. This is why experts (and the FDA) recommend scheduled MRI brain scans on individuals being treated with modern monoclonal antibody infusion treatments. 
      • “Now, a new study is offering detailed insight into how common ARIA is in individuals being treated with donanemab. Published in Alzheimer’s & Dementia: Diagnosis, Assessment & Disease Monitorin, the analysis suggests that up to 20% of patients may exhibit signs of ARIA on imaging.” 
    • MedPage Today tells us,
      • “Despite recommendations by the U.S. Preventive Services Task Force and the American Cancer Society, cervical cancer screening rates are declining.
      • “From 2005 to 2023, the proportion of women ages 21 to 29 never screened for cervical cancer increased from 12.5% to 31.9% (average annual percentage change [AAPC] 5.2%), with a notable increase from 2010 to 2023 (AAPC 7.9%).
      • “Regional-stage and distant-stage cervical cancer incidence has increased by 2.3% and 2.6%, respectively, per year among women ages 30 to 64 since 2017.”
    • and
      • “Almost 80% of patients with early-stage rectal cancer avoided surgery for a year or longer when treated with chemoradiation in a randomized trial.
      • “The organ-preservation strategies of chemoradiation and radiotherapy were both associated with few adverse events without sacrificing oncologic control.
      • “Longer follow-up is needed to determine long-term disease control and safety.”
    • and
      • “People who experience an opioid overdose are at greater risk of death, but data on which opioid agonist treatments are most effective in supporting this high-risk population are limited.
      • “In a retrospective cohort study of opioid overdose survivors, starting methadone was associated with a reduced risk of death during the subsequent year compared with starting buprenorphine-naloxone.
      • “In an accompanying commentary, experts questioned whether methadone is truly “intrinsically superior” to buprenorphine-naloxone.”

    From the U.S. healthcare business and artificial intelligence front

    • Beckers Payer Issues reports,
      • “Mona Chitre, PharmD, will serve as the market president for the newly created employer and government markets segment under Optum Rx, UnitedHealth Group’s pharmacy benefit manager.
      • “Dr. Chitre will begin her role Aug. 31, according to an Aug. 26 LinkedIn post. She said the role unifies the commercial, health system, coalition, labor and trust, and public sector businesses.
      • “Dr. Chitre most recently founded and was the president of Candesa Pharmacy Solutions, under The Lifetime Healthcare Companies. Under the same parent, she previously was Excellus BlueCross BlueShield’s chief pharmacy officer, according to her LinkedIn profile. She brings 26 years of experience across healthcare and pharmacy, she said.”
    • Fierce Healthcare relates,
      • “Cigna is looking to better link medical and supplemental benefits for its members, and has unveiled a new employer benefit that aims to further that goal.
      • “The insurer’s new Medical with Smart Coverage plans will be available as an option for employers with 500 to 2,999 employees that currently offer a high-deductible health plan. Cigna intends to expand access further in 2028, according to an announcement.
      • “The plan is designed to offer members support in managing unexpectedly high costs should they occur. Enrollees can access up to $7,000 in supplemental cash benefits that they can use during these health events to cover key needs such as transportation, child care or hotel stays.”
    • Beckers Hospital Review non-exhaustively lists “68 health systems with strong operational metrics and solid financial positions, according to reports from credit rating agencies Fitch Ratings and Moody’s Investors Service released in 2026.”
    • and tells us
      • New Haven, Conn.-based Yale New Haven Health System reported operating income of $33 million (0.5% operating margin) through the third quarter of 2026, up from an operating loss of $40.2 million (-0.7% margin) during the same period last year, according to its Aug. 25 financial report. 
    • and
      • “Pittsburgh-based UPMC recorded an operating loss of $18.3 million (-0.2% operating margin) for the second quarter of 2026, down from operating income of $111.2 million (1.3% margin) during the same period last year, according to its Aug. 27 financial report.”
    • Fierce Healthcare adds,
      • “Corewell Health showed its plans for two major hospital campus expansions that will run the Michigan nonprofit system $1.7 billion.
      •  “As our communities grow and patient needs become more complex, we are building the capacity, technology and care environments needed today for our patients and team members for many years to come,” President and CEO Tina Freese Decker said in the organization’s Thursday announcement. 
      • “The larger of the two projects is coming to Corewell Health Butterworth Hospital in Grand Rapids. The 780,000-square-foot, 11-story tower will include a new ED, 180 private patient rooms, 17 operating rooms and a hyperbaric chamber, Corewell said.” * * *
      • “The other new tower comes with a $440 price tag for the organization and will be built at Corewell Health Beaumont Troy Hospital, which serves a “rapidly growing” community and is also “consistently” above 90% capacity.”
    • and 
      • “Healthcare navigation platform Transcarent launched on Tuesday a bundled payment model for cancer therapies.
      • “The payment model, which the company touts as a first-of-its-kind, supports bispecific T-cell engager (BiTE) and CAR T therapies. Transcarent connects its members to leading oncology providers across various settings, including academic medical centers and high-quality community-based cancer care sites.
      • “Advanced cancer therapies are changing what’s possible for patients, but they’re also creating new challenges for employers trying to manage costs and access,” said Snezana Mahon, Transcarent’s president, in a statement. “This model gives employers more predictable costs while helping Members receive expert care closer to home without sacrificing quality.”
      • “The model enhances Transcarent’s Centers of Excellence (COE) program through easier access and navigation of more affordable care—offering potential savings of up to $150,000, executives say.
      • “Moreover, members undergoing treatment through the COE network are supported throughout their journey by certified oncology nurse navigators (ONNs).” 
    • Beckers Physician Leadership informs us,
      • “More than half of U.S. physicians, 59.4%, are now employed by a hospital or health system, according to a new analysis from Trilliant Health that assessed 700,000 physicians across the country.
      • “Here are four more things to know
        • “1. The hospital-employment rate is highest in the Midwest at 67.2% and lowest in the South at 52.4%, with the Northeast at 62.9% and the West at 60%. Multiple factors are driving the trend, with declining Medicare reimbursement chief among them. 
        • “2. The AMA estimates Medicare physician pay has declined 33% in real terms between 2001 and 2025 while practice costs rose 59% over the same period. 
        • “3. Among physicians who sold their practices to a hospital or health system, 79.5% cited the ability to negotiate higher payment rates as an important or very important reason for doing so. 
        • “4. Approximately 253,000 physicians became employees of hospitals or corporate entities between January 2018 and January 2026, with an additional 4,200 absorbed by insurers, private equity firms and pharmacy chains between 2024 and 2025.”

    Wednesday report

    Simplicity is a virtue.

    Quick Hits

    • Reuters adds,
      • “About 14% of employers in the United States have already or plan to drop GLP-1 drugs in 2027, as companies see ​rising healthcare costs, according to a survey released on Tuesday by the Business Group ‌on Health.
      • “Healthcare costs are set to increase 9.2% if employers do not make changes to manage costs in 2027, up from 8.5% in 2026, the group said. Two-thirds of employers surveyed said they saw rising utilization of ​the drugs.”
    • Healthcare Dive reports,
      • “The federal process for insurers and providers to settle disputes over out-of-network bills appears to be dramatically adding to U.S. healthcare spending, fueling calls for reform.
      • “That mechanism, set up by the No Surprises Act, has generated more than $22.4 billion in extra costs over just four years, according to new estimates from Georgetown University. That’s a significant acceleration from researcher’s past estimates of $5 billion in extra costs over the dispute resolution process’ first two years.
      • “But dispute volumes and total awards have continued to increase since — a worrying finding, given costs could push premiums up. The researchers urged policymakers to revisit the NSA.
    • The Wall Street Journal reports,
      • “For four decades, cancer researchers fought to disable a stubborn mutation that made pancreatic cancer a death sentence—to little avail. 
      • “Now, doctors have a medicine that targets the mutation. The Food and Drug Administration’s approval of the drug from Revolution Medicines on Wednesday marks a milestone in treatment of one of the most intractable kinds of tumors. 
      • “This is life-altering,” said Carla Kurkjian, an oncologist at Mercy Hospital in Oklahoma City, who wasn’t involved in the studies. “Not just for patients, as far as helping them extend their lives beyond anything we’d ever seen, but for us as physicians, to be able to have a different conversation than we’ve had for so long.”
      • “The drug, called Rasonque, helped subjects in a late-stage study live more than 13 months, nearly twice as long as those on chemotherapy alone. When presented at the world’s largest gathering of cancer researchers last spring, the results drew a nearly minute-long standing ovation.” 
      • “Yet the drug does have side effects, including a harsh rash across the body and gastrointestinal issues. Former Nebraska Sen. Ben Sasse, who went public in the spring with what he described as a significant reduction in his tumors while in a clinical trial of the drug, appeared on television with his face covered in red blotches.
      • “RevMed said the drug will cost $39,800 a month, or more than $477,000 a year.
      • “Wall Street expects Rasonque, which was approved for use in patients for whom other treatments failed, to be a big seller. The drug could generate more than $20 billion in annual sales, according to pharmaceutical commercial intelligence firm Evaluate, if the drug proves to work safely in earlier stages of the disease and with different types of cancers.”
    • The New York Times adds,
      • “The Food and Drug Administration’s approval on Wednesday of a new drug for pancreatic cancer marked the end of a long quest to develop a medicine that can hit one of cancer’s most elusive targets.
      • “Researchers hope the new drug is just the beginning, opening a new chapter in treatment for a range of cancer types.
      • “At least 79 drugs that take a similar approach are being tested in 238 clinical trials worldwide, according to one tally by academic researchers.
      • “Large drugmakers like Eli LillyPfizerAmgen and AstraZenecaare among the companies racing to develop their own medicines that work like the new drug, daraxonrasib, which is made by Revolution Medicines and will be sold as Rasonque.”
    • STAT News notes,
      • “The newer shingles vaccine has been turning heads since its link to lower dementia rates was reported two years ago. Now the same research team behind that observation has found an association between receiving the Shingrix shot and a reduced risk of heart disease.
      • “There have been signals before of cardiovascular benefits in people who got the newer, recombinant vaccine to prevent shingles, a painful, often serious flare-up in older people of the chickenpox virus from childhood. Those who got Shingrix were less likely than unvaccinated people to have heart attacks, strokes, or heart failure.” * * *
      • “Although the benefits are relatively small on an individual basis, millions of people receive shingles vaccination, meaning that even a small cardiovascular benefit could translate into a substantial number of cardiovascular events prevented at a population level,” Mark Russell, clinical senior lecturer and consultant rheumatologist of King’s College London, said in a statement shared by the Science Media Centre.” 

    Tuesday report

    Simplicity is a virtue

    From Washington, DC

    • Beckers Hospital Review reports,
      • “CMS awarded Alaska $160 million through the Rural Health Transformation Program, funding 142 projects to expand access to rural healthcare statewide.
      • “The funding package includes $6.5 million to bring the first robotic-assisted minimally invasive surgery program to Southern Southeast Alaska, $5 million to build a tribally led residential treatment and recovery campus in Southeast Alaska, and more than $3.1 million to deploy AI-powered medical imaging across 21 acute care hospitals for faster stroke detection.
      • “Alaska will also use $250,000 to develop a drone-based pharmaceutical delivery system for villages spread across 94,000 square miles, where medication deliveries can take five to 14 days during winter months. Nearly $4.6 million will strengthen the Alaska Family Medicine Residency Program, and $4.75 million will expand health information exchange connectivity for rural providers.”
    • Beckers Payer Issues relates,
      • “Nine months after President Donald Trump announced a deal offering states discounted pricing on GLP-1 drugs for Medicaid patients, most states are declining to participate, according to an Aug. 22 Politico report.
      • “Only Indiana has publicly signed on, while 29 state Medicaid programs have said they will not participate and 14 more did not respond to requests for comment, according to the report. CMS also declined to provide a list of participating states.” * * *
      • “Medicaid spending on GLP-1s grew from $1 billion in 2019 to almost $9 billion in 2024, and nearly 40% of patients with obesity could qualify for coverage if states opted in, according to the report. States that do not cover the drugs can still direct Medicaid enrollees to purchase them out of pocket through TrumpRx. The platform lists injectable Wegovy and Ozempic at average prices of about $350 a month, down from more than $1,000, though some pricing comparisons have found many listed drugs are available for less through existing Medicare Part D or Medicaid discounts. Even at the discounted rates, the drugs may remain unaffordable for many low-income patients.”
    • Beckers ASC Review tells us,
      • “The Federal Trade Commission has finalized a consent order requiring Ascension Health Alliance to divest seven Amsurg ASCs across five markets as a condition of its $3.9 billion acquisition of Amsurg, which closed in early June, according to an Aug. 25 news release from the FTC.
      • “The seven centers span Nashville, Panama City, Fla., Tulsa, Okla., Waco, Texas and Wichita, Kan. Six will be divested to Optum’s SC Affiliates, while the Panama City center will go to Florida Gastroenterology Center. The FTC alleged the acquisition would limit competition for outpatient surgical services performed by gastroenterologists, ophthalmologists and orthopedists in those markets, potentially leading to higher prices and lower quality of care. 
      • “The final order also requires Ascension to provide prior notice to the FTC before acquiring any additional ASCs in the metro areas around the divested centers. The Commission voted 2-0 to approve the final order.
      • “The deal, which expanded Ascension’s ASC footprint from 58 to more than 300 centers across 34 states, gives the St. Louis-based health system one of the largest ASC networks in the country.” 
    • SHRM informs us,
      • “The U.S. Department of Labor (DOL) has finalized three rules dismantling or scaling back longstanding affirmative action requirements for federal contractors, completing a major piece of the White House’s effort to reshape federal equal employment opportunity enforcement.
      • “Published in the Federal Register Aug. 21, the rules address three pillars of the regulatory framework administered by DOL’s Office of Federal Contract Compliance Programs (OFCCP): Executive Order 11246, Section 503 of the Rehabilitation Act and the Vietnam Era Veterans’ Readjustment Assistance Act (VEVRAA).” * * *
      • “For contractors, the result is a substantially different compliance landscape — one with fewer federally mandated affirmative action metrics and data-collection requirements. However, there remain continuing obligations to prevent unlawful discrimination and, in the disability and protected-veteran contexts, enduring statutory affirmative action duties.”

    From the U.S. Office of Personnel Management front,

    • OPM published in today’s Federal Register the following final rule corrections:
      • Improving Performance, Accountability and Responsiveness in the Civil Service, and Recruitment and Relocation Incentive Waivers; Correcting Amendments FR Document:2026-17334 Citation: 91 FR 54796 PDF Pages 54796-54797 (2 pages) Permalink
      • Reduction in Force Appeals; Correction FR Document:2026-17338 Citation:91 FR 54796 PDF Page 54796 (1 page) Permalink
      • Reduction in Force; Correction FR Document:2026-17335 Citation:91 FR 54794 PDF Pages 54794-54796 (3 pages) Permalink
      • Streamlining Probationary and Trial Period Appeals; Correction and Technical Amendment FR Document:2026-17336 Citation: 91 FR 54793 PDF Pages 54793-54794 (2 pages) Permalink
      • Suitability Action Appeals; Correction. FR Document:2026-17337 Citation:91 FR 54798 PDF Page 54798 (1 page) Permalink
    • OPM Director Scott Kupor added another post to this Secrets of OPM blog (Substack link).
      • “This week, the Partnership for Public Service published an analysis claiming that agencies paid employees to leave through the Deferred Resignation Program (DRP) and then quietly hired their replacements. This is a claim that has surfaced frequently in the media in the past year: that the DRP reductions were not real because of backfills.
      • “The Partnership’s own analysis, however, confirms that these claims have no merit.
      • “According to OPM’s workforce data, 139,928 employees participated in the DRP. The Partnership identifies 20,557 subsequent hires that it considers “backfills.” Even accepting that figure at face value – the Partnership is using broad job classifications that can often encompass hundreds of actual jobs as a very imperfect proxy that likely significantly overstates actual backfills – it amounts to 14.7 percent of DRP participants.
      • Thus, more than 85 percent of employees who took the program are not matched to any subsequent hire. That’s pretty good for a program that was rolled out government-wide. Simply put, 85% of the reductions were real and lasting.”

    From the Food and Drug Administration front,

    • Reuters reports.
      • “The U.S. Department of Health and Human Services is planning to appoint two new deputy commissioners at the Food and Drug ​Administration, CNBC reported, citing sources familiar with the ‌matter.
      • “One role would focus on technology, including healthcare and AI, while the other would oversee drugs, according to two people familiar with the plans.”
    • Per Fierce Pharma,
      • “Jazz Pharmaceuticals’ bispecific antibody Ziihera has gained FDA approval for first-line HER2-positive stomach cancer, unlocking another market as the company builds toward a $2 billion-plus peak sales target. 
      • “The latest green light allows Ziihera to be used in addition to chemotherapy, with or without BeOne Medicines’ Tevimbra, in previously untreated, HER2-positive advanced gastroesophageal adenocarcinoma (GEA). 
      • ‘The approval permits Jazz to challenge more than a decade of practice, in which trastuzumab (Herceptin) has been the standard HER2 agent used alongside platinum-based chemotherapy—with or without a PD-1 inhibitor—as first-line therapy for these stomach cancer patients.” 
    • The Hill tells us.
      • “Vitruvias Therapeutics is voluntarily recalling one lot of thyroid tablets because they could potentially be “superpotent,” federal regulators announced this week.
      • “The high potency 30mg tablets could cause hyperthyroidism, or an overactive thyroid, according to the Food and Drug Administration. The affected lot (504950) was distributed nationwide to Vitruvias Therapeutics’ direct accounts from Jan. 31 to Sept. 30, 2025.”
    • Per an FDA news release,
      • “The U.S. Food and Drug Administration today authorized the Libre Duo 10 Day Continuous Dual Glucose Ketone Monitoring System for people aged 2 years and older living with diabetes. The Libre Duo 10 Day is the first wearable device in the U.S. that continuously monitors ketone levels, and the first in the world to continuously monitor both ketones and blood sugar (glucose) together in a single device.
      • “Today’s authorization is a breakthrough for the safety of children and adults living with diabetes,” said Michelle Tarver, M.D., Ph.D., Director of the FDA’s Center for Devices and Radiological Health. “Knowing that ketone levels are rising, and having that information in real time, around the clock, can be the difference between early intervention and a life-threatening emergency.”
      • “According to the Centers for Disease Control and Prevention, an estimated 40.1 million Americans are living with diabetes, a condition that requires careful monitoring of blood sugar levels. For the estimated 2.1 million Americans with type 1 diabetes, blood sugar is only part of the picture. When the body produces too much ketone, which is made by the body when it is using fat instead of glucose for energy, it can lead to diabetic ketoacidosis, or DKA — a serious complication that can develop quickly and become life-threatening if left untreated.”
    • Beckers Hospital Review points out,
      • “The FDA cleared Amygdala Neurosciences’ Investigational New Drug application for ANS-858, allowing the company to move the drug into clinical development.
      • “ANS-858 is a selective, reversible, orally bioavailable inhibitor of aldehyde dehydrogenase 2 (ALDH2), according to an Aug. 18 news release from the company. It plans to begin a phase 1 clinical trial, which is designed to support later evaluation of ANS-858 across multiple indications in phase 2 clinical trials.
      • “Amygdala Neurosciences is initially advancing ANS-858 as a potential treatment for alcohol use disorder and other substance use disorders. It is also evaluating the drug in compulsive eating disorders associated with binge eating and obesity.”
    •  Cardiovascular Business informs us,
      • Young M. Lee, MD, a cerebrovascular surgeon with University Medical Center New Orleans, was the first U.S. physician to perform a stroke thrombectomy with Thunderbolt, a computer-assisted vacuum thrombectomy (CAVT) system from Penumbra that gained U.S. Food and Drug Administration (FDA) clearance back in June. 
      • “Lee performed the procedure on a young male patient who presented with a right middle cerebral artery (MCA) syndrome and a right M1 occlusion. He spoke to Cardiovascular Business about the experience, noting that this first patient was an especially challenging case due to preexisting intracranial atherosclerotic disease.
      • “I was able to observe the Thunderbolt essentially detect the clot and completely aspirate the clot starting from its proximal end in the mid-M1 segment all the way up to the point of the MCA bifurcation,” he explained. “With the fluoroscopy running, I could see the aspiration catheter advance towards the MCA bifurcation as the pump responded to what was happening, which is not something you see with a traditional non-modulated aspiration technique.”

    From the judicial front,

    • Federal News Network reports,
      • “The Trump administration is facing a new lawsuit from federal unions after it issued a pair of recent final rules overhauling federal employee suitability standards and performance evaluations.
      • “Filed on Monday in the U.S. District Court for the Northern District of California, the unions’ lawsuit contends that the Office of Personnel Management exceeded statutory authority and violated the intent of the Civil Service Reform Act when it issued regulations to change suitability and fitness regulations and reshape the performance management system for the federal workforce.
      • “Taken together, the changes will make it easier for OPM and agencies to fire federal employees, while limiting opportunity for employees to challenge their removals or other adverse actions, the unions argued. Their lawsuit is the latest of several legal challenges unions are taking against the Trump administration’s efforts to revise federal workforce policies and regulations.
      • “The American Federation of Government Employees is leading the lawsuit, with other plaintiffs including the National Federation of Federal Employees (NFFE), the International Federation of Professional and Technical Engineers (IFPTE) and the American Federation of State, County and Municipal Employees (AFSCME).”
    • Per a Justice Department news release,
      • “The Department of Justice today announced the emergency scheduling of three highly potent opioid compounds that pose an imminent hazard to public safety: mitragynine pseudoindoxyl, commonly known as MGPI, and two synthetic compounds known as MGM-15 and MGM-16.
      • “The Justice Department is acting before these dangerous compounds become a broader threat,” said Attorney General Todd Blanche. “These are potent opioids being manufactured and sold in consumer products, often under labels that obscure their true risks. This action will protect our nation’s children and communities from the dangers of drug addiction and abuse.”
      • “The Drug Enforcement Administration is temporarily placing the three 7-hydroxymitragynine-related substances in schedule I of the Controlled Substances Act. Preclinical evidence indicates that all three are potent mu-opioid receptor agonists and may present risks associated with other mu-opioid agonists, including dependence and respiratory depression. MGPI and MGM-15 are manufactured and marketed in products sold for their opioid effects. MGM-16 has not been confirmed in the consumer market but is a highly potent compound that could emerge as a substitute for related substances.”
    • The New York Times adds,
      • “Since the early 2000s, the number of fatal overdoses in the United States has soared. And the rate in Baltimore — 110 deaths per 100,000 residents, according to a recent analysis by the San Francisco Chronicle — is the highest among cities with a populations of a half-million or more.
      • “The initial cause was prescription opioids, then heroin, and then, starting a decade ago, a new generation of synthetic opioids, mainly fentanyl. Now, new combinations of ultrapotent lab-made drugs reach the street almost daily, making the narcotics supply — in Baltimore and beyond — more dangerous, polluted and unpredictable than it has ever been.” * * *
      • “Because lab-made drugs are so easily mixed and altered, their effect is uncertain; few buyers know what they’re actually getting, and the possibilities are expanding dangerously. Last summer, several mass overdoses in Baltimore resulted when fentanyl was mixed with N-methylclonazepam, a powerful sedative. Across the country, 22 percent of drug samples contained five or more compounds, an increase from 8.8 percent in 2022, according to testing done by the National Institutes for Science and Technology.”

    From the public health and medical / Rx research front,

    • The Wall Street Journal reports,
      • “Two unvaccinated people in Pennsylvania have died after contracting measles, the state health department said, the U.S.’s first measles-associated deaths reported this year.
      • “Both of the people lived in Lancaster County, a populous area in the southeast part of the state known for its large Amish community, the health department said Tuesday. The deaths mark Pennsylvania’s first measles-related fatalities in 35 years and are part of a larger outbreak in the state. 
      • “Pennsylvania has confirmed more than 390 cases of measles across 28 counties so far this year, all in people who weren’t fully vaccinated. Nearly half have come from Lancaster County. About a third of the Pennsylvanians affected are under 18 years old.
      • “I want to be clear: This illness and death from measles is completely preventable,” said Pennsylvania Gov. Josh Shapiro. “We already have the tools to protect ourselves and our families from this disease, which is one of the most contagious diseases on the face of the earth.”
    • The National Institutes of Health’s Research Matters covers the following topics in its latest issue.
      • Dementia-free years may decrease with smoking, hypertension, and diabetes.
        • “Researchers found that smoking, high blood pressure, and diabetes in midlife lower the number of years a person is likely to live without dementia.
        • “The findings could help guide behavior and lifestyle changes to prevent dementia.
      • Coating stops tooth decay in children.”
        • “A clinical trial found that a topical treatment called silver diamine fluoride stops cavities in young children from getting worse.
        • “The simple treatment could prevent surgery and other serious consequences for children with severe tooth decay.”
      • DNA organization changes in Alzheimer’s disease, aging.”
        • “New research showed the 3D organization of DNA in cells changes in Alzheimer’s disease and aging.
        • “The results suggest the changes may contribute to altered gene activity observed in Alzheimer’s and aging.”
    • Health Day relates,
      • “A combo of hormone therapy and targeted drugs appears to help patients with metastatic breast cancer
      • “About 97% of patients benefited during the first six months
      • “The treatment, mainly using pills and under-the-skin injections, could eventually offer some patients an easier first-line option.”
    • and
      • “Hoping for a quick response from your doctor to a message sent through your patient portal?
      • “Then keep it cordial and positive, a new study suggests.
      • “Doctors were more likely to respond to messages that addressed them by name and had a positive tone, researchers reported Aug. 24 in JAMA Network Open.”
    • Beckers Hospital Review lets us know,
      • “Pediatric medications have more active FDA-listed shortages than any other therapeutic category, according to the FDA’s drug shortage database.
      • “Here are the categories with the most active shortage listings, ranked by number of active shortages as of Aug. 25:
        • 1. Pediatric: 18
        • 2. Anesthesia: 10 (tie)
        • 2. Cardiovascular: 10 (tie)
        • 3. Analgesia/addiction: 9 (tie)
        • 3. Gastroenterology: 9 (tie)
        • 4. Endocrinology/metabolism: 8 (tie)
        • 4. Neurology: 8 (tie)
        • 5. Anti-infective: 7 (tie)
        • 5. Oncology: 7 (tie)
        • 5. Psychiatry: 7 (tie)

    From the U.S. healthcare business and artificial intelligence front

    • Beckers Payer Issues reports,
      • “Most large health insurers posted stronger-than-expected earnings in the second quarter, but much of the improvement might not be durable, according to a Moody’s Ratings analysis published Aug. 24.
      • “Average EBITDA margins across the seven largest publicly traded insurers rose to 4.7% in Q2, up from 3.9% in the same period a year earlier. UnitedHealth Group posted the largest swing, expanding to 6.2% from 3.7%, while Centene jumped to 3.7% from 0.6% on the back of marketplace margin recovery and outperformance in its Medicare Advantage and prescription drug plan businesses. Five of the six insurers that reported results raised or affirmed full-year guidance.
      • “The rating agency cited high-cost specialty drugs, sustained behavioral health demand and aggressive provider billing and coding as ongoing pressures. The report also described a “clear industry pivot toward margin stabilization rather than top-line growth,” calling the shift broadly credit positive.”
    • Beckers ASC Review adds,
      • “For nearly as long as health insurers have used prior authorization to control costs, physicians and hospitals have argued it does more harm than good. 
      • “The pushback against prior authorization has reached new heights in recent months as healthcare leadership, legislators and physician advocacy organizations have proposed major reforms or outright bans of the practice.” 
    • Healthcare Dive relates,
      • Name: Dr. Patrick Fox
      • Previous title: President, Wellpoint New Jersey
      • New title: President, Carelon Behavioral Health
      • “Fox is assuming the top role at Elevance’s behavioral health division effective immediately, the Indianapolis-based insurer announced Monday.”
    • Beckers Hospital Review tells us,
      • “New York City-based NewYork-Presbyterian reported operating income of $124.2 million (4% operating margin) during the second quarter of 2026, up from $101.7 million (3.6% margin) during the same period last year, according to its Aug. 24 disclosure report.”
    • and
      • “Orlando (Fla.) Health recorded operating income of $81.5 million (3.0% operating margin) in the third quarter of fiscal 2026, up from $56.3 million (2.2% margin) during the same period last year, according to its Aug. 25 finance report.”
    • and
      • “As health systems continue to grapple with financial pressures from rising labor and supply costs and reimbursement challenges, days cash on hand remains an important measure of financial stability. 
      • “[The article shares} days cash on hand figures for 25 health systems as of June 30, according to their most recent financial reports”
    • Fierce Healthcare tells us,
      • “The Oregon Health Authority (OHA) approved a deal on Monday that would merge the nonprofits MultiCare Health System and Samaritan Health Services.
      • “State regulators said the OHA’s Health Care Market Oversight (HCMO) program reviewed how the proposed merger would affect Samaritan’s facilities and its impact on Oregon citizens’ access to affordable and equitable healthcare. 
      • “HCMO approved the deal provided it meets established conditions (PDF), including requiring MultiCare to follow its financial commitment of investing $700 million towards Samaritan and posting a public-facing version of the commitment on Samaritan’s website. Other conditions involve reinvestment of Samaritan’s operating margins into local communities and a requirement to maintain existing services.”
    • and
      • “Artificial intelligence-driven specialty care navigation platform Switchboard Health announced Tuesday the acquisition of virtual orthopedics and musculoskeletal (MSK) management provider Livara Health.
      • “Switchboard Health will embed Livara’s MSK program in its automation platform for referral management and care navigation, through the acquisition, to enable providers and health plans to enroll patients.
      • “Financial details of the transaction were not disclosed.”
    • Beckers Physician Leadership informs us,
      • More than half of active U.S. physicians worked for hospital systems as of 2024, up from 20% in 2010, and hospital systems have acquired more than 20,000 physician practices since 2015, according to a recent study published in JAMA Network Open.
      • Becker’s ASC Review tracked more than 50 physician practice deals in 2026 — with consolidation taking over some areas of medicine more than others. 
      • [The article provides] a breakdown by across five specialties.

    Notable Death

    • The Wall Street Journal reports,
      • “One night in 1973, Dolly Parton had a song on her mind. She was thinking about a bank teller who had been flirting with her spouse.
      • “She got this terrible crush on my husband,” Parton told NPR in 2008. “And he just loved going to the bank because she paid him so much attention.”
      • “Needing a name for this tall, redheaded temptress, she thought of another flame-haired girl, an 8-year-old who approached her for an autograph after a taping of “The Porter Wagoner Show,” the TV series on which she was featured. That child’s name was Jolene.
      • “Parton died Tuesday at age 80 in Nashville, Tenn., according to her family. The cause of death wasn’t released. In May, Parton canceled a Las Vegas residency because of health issues.”
    • Beckers Hospital Review adds,
      • “Beyond her music and film career, Ms. Parton spent decades directing philanthropic dollars toward hospitals and medical research, much of it concentrated in her native East Tennessee and at Nashville-based Vanderbilt Health. [The article shares] seven ways her giving left an imprint on healthcare.

    Monday report

    Simplicity is a virtue.

    From Washington, DC

    • Per Centers for Medicare and Medicaid Services news release,
      • “The Trump Administration announced today that a $144 million investment is being delivered to improve health outcomes for Alabamians through the federal Rural Health Transformation Program (RHTP) This investment will support 138 grants to expand access to care, modernize healthcare technology and infrastructure and strengthen the rural healthcare workforce.
      • “This funding will help rural providers modernize their technology and cybersecurity, enhance telehealth and mobile care services, strengthen emergency and maternal care, and improve access to mental health and substance use care. The Trump Administration is also investing in expanding the healthcare workforce through training, scholarships, apprenticeships, and recruitment efforts, while helping local providers strengthen community-based care and better coordinate services. These investments will help make healthcare more accessible, connected, secure and sustainable across Alabama regardless of your zip code.”
    • Per a Department of Health and Human Services news release,
      • “U.S. Health and Human Services Secretary Robert F. Kennedy, Jr. and Secretary of Agriculture Brooke L. Rollins today announced sweeping new efforts to strengthen school meals by connecting more American farmers with local schools, investing in school kitchen infrastructure, and giving states and school districts new tools to serve healthier, more nutrient-dense meals to America’s children.
      • “Secretary Kennedy joined Secretary Rollins at the U.S. Department of Agriculture (USDA) alongside farmers, students, school nutrition leaders, athletes, chefs, and parents to announce the next phase of the Trump Administration’s work to Make America Healthy Again.” * * *
      • “If we want to Make America Healthy Again, we have to start with our children, and that means improving what we put on their lunch trays every single day,” said Secretary Brooke L. Rollins. “Harvest to Hallways is about bringing more American agriculture into the school cafeteria. We are connecting schools with the farmers and ranchers in their own communities, investing in the kitchens and equipment school nutrition professionals need to prepare real food, and cutting through barriers that have made it too difficult to serve healthy, American-grown food. When we strengthen the connection between the farm and the lunchroom, everybody wins: our children eat better, our farmers gain new markets, and our communities grow stronger.”
    • STAT News adds,
      • “New restrictions on the use of food benefits to purchase soda and candy have been one of the biggest changes enacted by the Make America Healthy Again movement. But a key question has been how profoundly the bans would affect public health, with some economists arguing that people would just use other funds to buy Coke and other sugary drinks instead.
      • “Now a new study shows that soda purchases did indeed fall by about 12% among people who receive Supplemental Nutritional Assistance Program benefits after the bans went into effect in 10 states. The study, which was published by the National Bureau of Economic Research and has not yet been peer-reviewed, says this translates to a person drinking about 34 fewer 12-ounce cans of soda per year.”
      • “That’s not huge, according to the study’s authors, but it’s far from nothing.”
    • Beckers Hospital Review reports,
      • “More than 200 healthcare organizations urged CMS not to finalize proposed limits on remote monitoring, warning the changes would disrupt care for about 1 million Medicare beneficiaries who manage chronic conditions from home.
      • “In a sign-on letter to CMS Administrator Mehmet Oz, MD, the coalition asked the agency to hold off on remote physiologic monitoring and remote therapeutic monitoring policies included in the 2027 Medicare Physician Fee Schedule proposed rule. More than 30 health systems and hospitals signed the letter. 
      • “The provision at issue, proposed July 14, would allow clinical practices to bill Medicare for the services only if the clinical staff delivering them are directly employed by the billing practice rather than contracted through a third-party vendor. Staff could still work off-site; the billing relationship would have to run in-house.
      • “That distinction carries broad reach. An estimated 60% to 70% of hospitals and health systems using remote monitoring rely on partially or fully outsourced vendor models, according to Becker’sprior reporting. The signers of the letter said small practices, rural providers and safety-net organizations would be hit hardest, and that many would have no option but to cut enrollment or end their programs.”

    From the U.S. Office of Personnel Management front

    • FedWeek reports,
      • “President Trump has not yet sent Congress the alternative pay plan letter that will determine the 2027 federal pay raise, and the statutory deadline to do so arrives August 31. The letter is the clearest remaining signal of whether federal employees face a full pay freeze next year or another modest increase similar to the one delivered a year ago.
      • “Under the Federal Employees Pay Comparability Act (FEPCA) of 1990, the president must submit an alternative pay plan to Congress by the end of August, or a statutory formula tied to private-sector wage growth automatically takes effect instead, producing a far larger locality pay increase than any administration has allowed to take hold since the law passed. FedSmith has explained the mechanics of this deadline before, and last year’s letter covering the 2026 raise arrived on August 28, just three days before the cutoff. A similarly late announcement is likely again this year.”
    • and
      • Federal employees under the General Schedule receive a base salary plus a locality payment that varies by geographic area. The 2026 rates range from 17.06% in the Rest of U.S. locality pay area to 46.34% in the San Jose-San Francisco-Oakland, CA, locality pay area.
      • “The federal locality pay system adjusts General Schedule salaries to reflect differences in non-federal pay levels across geographic regions. Authorized by the Federal Employees Pay Comparability Act of 1990, the system took effect in January 1994. Its purpose is to reduce pay disparities between federal and non-federal workers performing similar work in the same labor market.
      • “Locality payments are calculated as a percentage of base pay and applied according to the employee’s official worksite. The Office of Personnel Management publishes annual tables that incorporate both the across-the-board base pay increase and the locality adjustment for each designated area. For 2026, locality pay percentages remain at the prior year’s levels, while base pay received a 1.0% across-the-board increase.”

    From the Food and Drug Administration front,

    • The Wall Street Journal reports,
      • “The Food and Drug Administration cleared a blood test for identifying Alzheimer’s disease symptoms, which was developed by Roche and Eli Lilly.
      • “The Elecsys Phospho-Tau Plasma test identifies amyloid pathology associated with Alzheimer’s in people 55 years or older.
      • “It provides positive, intermediate and negative result categories to support doctors assessing the likelihood of amyloid pathology. Results are interpreted in conjunction with clinical information and other relevant findings as part of an Alzheimer’s diagnosis.
      • “The blood test is meant to address the gap in diagnoses, as an estimated 75% of people living with dementia are undiagnosed, Roche said.
      • Quest Diagnostics and Labcorp both said they plan to start offering the blood test.”
    • MedTech Dive relates,
      • “The Food and Drug Administration has picked two behavioral health companies to join its Technology-Enabled Meaningful Patient Outcomes, or TEMPO pilot, growing the total number of participants to four.
      • “Limbic and Sondermind are the next companies to join the pilot program, which allows participants to gather real-world data on devices while being exempted from premarket authorization requirements.
      • “Amid the pilot program, the FDA has also held discussions on digital health technologies for mental health, with patient groups calling for broader oversight in the use of generative artificial intelligence.”
    • Beckers Hospital Review tells us,
      • “The FDA has again paused Regenxbios RGX-121 gene therapy trial for Hunter syndrome after small, asymptomatic masses were found on the spines of five patients. Regenxbio does not expect to resubmit its biologics license application for the therapy in the near term.
      • “The spine findings, either a small nodule or cystic mass, surfaced through an expanded MRI monitoring plan Regenxbio adopted a few months ago, according to an Aug. 24 news release. All five patients received intracisternal or intraventricular RGX-121 three to six years ago, remain asymptomatic and have shown stability to improvement on neurocognitive assessments. Investigators consider the findings nonserious and likely benign, though no pathological evidence confirms their cause.
      • “The pause comes seven months after Regenxbio disclosed that a boy who received its similar MPS I therapy, RGX-111, developed a brain tumor, a case researchers have since linked to AAV gene therapy, the vector platform used in most gene therapies over the past 20 years.”

    From the judicial front,

    • Fierce Pharma reports,
      • “On Monday, the U.S. District Court for the District of Columbia ruled against Merck & Co., rejecting its claim that the price negotiations are unconstitutional because they violate the First and Fifth Amendments. The argument is one that has been made by multiple drugmakers pushing back against the program.” 
    • Per a Justice Department news release,
      • “Today, the U.S. Department of Justice announced the launch of the National Fraud Detection Center (NFDC), a prosecutor-led, multi-agency team designed to investigate the most harmful actors defrauding federal government programs, including illicit actors overseas and those operating fraud schemes across federal programs. The NFDC will bring together law enforcement agencies and analytical capabilities to generate criminal leads to drive more impactful prosecutions and enhance fraud-fighting results for the American people.
      • “The creation of the NFDC marks a decisive shift in how the federal government detects and investigates complex fraud,” said Assistant Attorney General Colin McDonald of the Justice Department’s National Fraud Enforcement Division. “By breaking down institutional silos, embedding analysts from across the IG community, and leveraging shared technology, the NFDC is actively closing the window of opportunity for bad actors who seek to exploit taxpayer dollars. Today’s announcement sends a clear message: if you defraud federal programs, we have the tools and the law enforcement partners to find you.”

    From the public health and medical / Rx research front,

    • Beckers Hospital Review reports,
      • “A fast-moving wildfire in the Sierra Nevada foothills has forced two Northern Nevada Health System facilities in the Reno, Nev., area to evacuate patients and close, according to CBS News and The New York Times.
      • “Both facilities remain closed with no timeline to reopen. The health system said it is in active communication with emergency response teams and will reopen each facility once crews clear the area and deem it safe, at which point it will activate an opening plan and notify the community.”
    • Better Report tells us.
      • “We spoke with board-certified emergency medicine physician Dr. Joseph Radachy about what he wishes more patients would prioritize. From simple ways to avoid everyday accidents to daily practices that support long-term health, here are six things your doctor wishes you’d do.
        • Stay Active Physically and Medically
        • Make your House Safer.
        • Advocate for Yourself
        • Know your Medical History
        • Remember: Moderation in Everything
        • Stop Smoking
    • The New York Time asked experts whether the bland BRAT diet is the best way to treat a stomach bug.
    • The American Medical Association lets us know “what doctors want patients to know about dry eyes.
      • “Dry eye disease can cause burning, tearing and blurry vision. Learn what triggers symptoms, which treatments help and when to seek care.”
    • Beckers Behavioral Health informs us,
      • “The age-adjusted death rate for alcohol-induced deaths among U.S. adults aged 45 and older increased from 2014 to 2024, according to an Aug. 20 report from the CDC’s National Center for Health Statistics.
      • “Death rates increased from 19.5 per 100,000 population in 2014 to 25.2 in 2024. In 2024, the death rate was 36.8 among men and 14.3 among women. Death rates were higher among men than women throughout the 2014–2024 period.
      • “The findings are based on National Vital Statistics System mortality data.
    • Parkinson’s News Today points out,
      • “Parkinson’s disease involves the progressive loss of dopamine-producing neurons, leading to motor symptoms.
      • “Starting rehabilitation within the first year of a Parkinson’s diagnosis may be linked to longer survival.
      • “Delaying rehabilitation is associated with a progressively higher risk of mortality across all disability levels.”
    • Genetic Engineering and Biotechnology New notes,
      • “Cancer metastasis is responsible for at least two-thirds of cancer deaths. Drugs targeting the metastatic progression have largely failed, in part due to the lack of predictive models that would help identify the underlying mechanisms of metastasis.
      • “Now, new work reports the development of a multi-organ chip that mimics how cancer cells spread from vascular flow to distant organs—the first model of cancer metastasis of its kind. The chip includes compartments with millimeter-sized engineered human bone and lung tissues, and the vascular flow that contains circulating breast cancer cells and allows the dynamic cross-talk of the tissues being colonized.
      • “The key advantages of this advanced model of metastasis are that it is human and can be patient-specific,” said Gordana Vunjak-Novakovic, PhD, university professor and professor of biomedical engineering and professor of medical sciences at Columbia University. “It faithfully mimics some of the key aspects of human metastasis that are otherwise largely inaccessible for direct study.”
      • “This work is published in Science Translational Medicine in the paper, “Organ-specific colonization and niche remodeling in a human tissue model of metastasis.”
    • STAT News takes us “inside Moderna and Merck’s cancer vaccine triumph.
      • “The drugmakers overcame rampant doubts, logistical challenges, and the pandemic.”

    From the U.S. healthcare business and artificial intelligence front,

    • Fierce Healthcare reports,
      • “Highmark Health closed the first half of the year with $17.5 billion in revenue and $2 billion in net income, bolstered by a significant turnaround at its insurance unit.
      • “The $2 billion in net income accounts for $911 million in non-cash gains from the company’s affiliations with Blue Cross and Blue Shield of Kansas City and Heritage Valley Health System.
      • “Highmark Health Plans posted $672 million in operating income through the first two quarters of 2026, an increase of $612 million compared to the first half of 2025. Highmark said in the announcement that it expects elevated utilization and cost trends to persist across the industry, though pressures have eased.”
    • and
      • “Berry Street, a nutrition care company, has merged with India-based Healthify to form what executives call the largest insurance-covered AI metabolic health platform in the U.S. 
      • “The merger combines Healthify’s AI technology, including its nutrition and metabolic health assistant Ria, with Berry Street’s nationwide network of more than 2,000 clinicians and insurance-covered nutrition and GLP-1 care. The companies say the goal is to offer AI-powered, clinician-backed metabolic health support accessible through health insurance.
      • “Financial details of the merger were not disclosed. Berry Street shared the news exclusively with Fierce Healthcare.”
    • Beckers ASC Review relates,
      • “Kaiser Permanente is advancing construction plans for its long-planned Redlands, Calif., medical campus, with the Redlands Planning Commission set to review detailed site plans for the project’s first building Aug. 25, Community Forward Redlands reported  Aug. 24.
      • “The commission will consider a 113,000-square-foot, three-story medical office and ASC at Kaiser’s existing property. The building, known as Medical Office Building/Ambulatory Surgery Center 2, would house urgent care, outpatient surgery, chemotherapy infusion, imaging, laboratory services and medical offices.”
    • and
      • Becker’s has reported on more than 30 ASC closures in 2026 as outpatient surgery facilities cite consolidation, efficiency and shifting care sites. 
      • “[The article offers] a look inside five more recent ASC closures as the industry battles reimbursement declines, staffing shortages and shifting market power dynamics. 
    • Healthcare IT News tells us,
      • “Telemedicine has made it routine for clinicians and patients to connect by video. But for health systems, establishing that connection is no longer the hardest part of virtual care. The bigger challenge is making sure the right patient gets a virtual visit in the first place – and that everything that should happen afterward actually happens.
      • “For telehealth veteran Dr. Joe Kvedar, professor of dermatology at Harvard Medical School and senior clinical advisor and two-time board chair at the American Telemedicine Association, the operational issues confronting provider organizations now come down largely to two areas: EHR integration and patient triage.
      • “Many health systems have made substantial progress integrating telemedicine into the electronic health record, says Kvedar, but determining which patients and conditions truly belong in a virtual encounter remains more difficult.”
    • and
      • “For decades, hospitals have largely treated discharge as the end of the acute care journey. Once patients left the building with a folder of instructions and follow-up recommendations, responsibility shifted largely to them and their families.
      • “But that approach is becoming increasingly difficult to sustain as hospitals assume greater accountability for patient outcomes long after patients leave inpatient care.
      • “New payment models, continued pressure to reduce avoidable readmissions and growing expectations for coordinated care are forcing provider organizations to rethink what happens after discharge.
      • “For Dimer Health CEO Caroline Hodge, PA-C, the answer is straightforward: Transitional care must become an active, technology-enabled extension of the hospital, rather than a passive handoff.
      • “The first 90 days aren’t an afterthought anymore,” Hodge said. “They’re where the outcome, and the economics, actually get decided.”
    • MedTech Dive informs us,
      • “MiniMed has begun shipping its new insulin pump in the U.S. with the Abbott-made Instinct sensor, the Medtronic spinout said last week. The sensor can be used for up to 15 days before it needs to be changed.
      • “The company said the rollout of its new MiniMed Flex delivery device with Instinct combines the smallest and only app-controlled insulin pump with the world’s smallest sensor.
      • “MiniMed is supporting the launch with its first major marketing campaign for the insulin pump. The campaign focuses on MiniMed Flex’s “discreet” design, app control and automation.”
    • Beckers Hospital Review notes,
      • “Mark Cuban Cost Plus Drug Co. has partnered with RxSaveCard and nonprofit Golden Thread to streamline sourcing and reduce costs of pediatric cancer clinical trial medications. 
      • “Once enrolled in a study, patients will sign up for RxSaveCard and receive trial medications delivered to their homes through Cost Plus Drugs, according to a news release shared with Becker’s.
      • “No study should stall over the price of a generic drug and no family should wait on one,” Alan Bowe, chief commercial officer at Cost Plus Drugs, said in the release. “We’re proud to work with Golden Thread and RxSaveCard to make trial medications affordable and deliver them directly to patients’ doors and we hope every trial that needs this model uses it.”

    Weekend update

    Simplicity is a virtue.

    From Washington, DC,

    • This is the last week that both Houses of Congress are out of town on State/District work period. The House of Representatives returns to Capitol Hill on August 31 and the Senate returns on September 14. Both Houses head out on the campaign trail on October 1 until the week following the national election day on November 2.
    • Global BioDefense reports,
      • “The federal government wants to lock in vaccine manufacturers now, well before the next flu pandemic arrives, rather than scramble to build production capacity after one begins. The Biomedical Advanced Research and Development Authority (BARDA) released a request for proposals on August 17 seeking companies to maintain what the agency calls warm base manufacturing capacity for pandemic influenza vaccines, a standing readiness posture that keeps production lines, seed stocks, and regulatory groundwork in place so doses can start flowing quickly once a pandemic strain emerges.”

    From the Food and Drug Administration front,

    • MedTech Dive reports,
      • “After receiving Europe’s CE mark earlier this year, Abbott is preparing to bring a dual glucose-ketone sensor to the U.S.
      • “The company has filed an application for its new device, called Libre Duo, with the Food and Drug Administration, with expectations for approval before the end of the year.
      • “Abbott hopes that by allowing people to be more aware of ketone levels, the new device will help prevent diabetic ketoacidosis, or DKA, a serious complication of diabetes where the body lacks insulin. However, broader access to ketone measurement also brings questions around best practices for interpreting and acting on this new data.”
      • MedTech Dive interviews endrinologists about this development in the article. 

    From the public health and medical / Rx research front

    • Tech Times lets us know where with stand with the summer Covid surge and what it means for the fall season.
    • Medscape relates,
      • “Adults on GLP-1s who lost weight during their first year on the medications are likely to maintain that loss through the second year of use, according to two new Cosmos studies.
      • “That finding was true for those with diabetes and without.
      • “We did observe that patients without diabetes had higher rates of maintaining that weight loss,” said Kersten Bartelt, RN, a researcher at Epic Research and a coauthor on both studies. And those on tirzepatide had lower rates of weight regain that those on semaglutide, the two medications studied.
      • “Bottom line? Continued use of GLP-1s means continued weight loss benefit or maintenance, Bartelt said.”
    • STAT News tells us,
      • “If you could design an oral treatment that limits appetite and mimics some effects of physical activity, you might call it exercise in a pill. Now a company is releasing early results for a compound to do just that.
      • “The pill, the company hopes, can maintain weight loss without the common gastrointestinal effects of GLP-1s. The component of exercise it is designed to re-create is preservation of lean muscle mass, a concern when people yo-yo on and off GLP-1 drugs, losing more muscle each time.
      • “Those researchers showed in a 2022 Nature paper that lac-phe can suppress appetite and lower obesity in animals. Lac-phe and ENV-308, Enveda’s chemically engineered version, both act on leptin, a hormone that has been the target of scientists and drug developers for decades. If confirmed in clinical trials, the company says, ENV-308 would be the first “leptin sensitizer in a pill.” 
      • “ENV308 is our attempt to put the chemistry of exercise into a daily tablet,” said Viswa Colluru, Enveda’s founder and CEO.”

    From the U.S. healthcare business front,

    • Kaufmann Hall released its 2nd Quarter 2026 Physicians’ Flash Report last week.
      • The investment curve for providers has flattened. The investment/subsidy per both provider and physician has remained steady year-over-year, a positive sign for medical group performance.
      • Advanced practice providers (APPs) are helping control costs. The number of APPs continues to steadily increase, now making up 41.2% of the Total Provider FTEs represented in this sample. As medical groups continue to design strategic APP and physician staffing models, organizations may continue to see stronger returns in overall team effectiveness, productivity, and cost control.
      • Continued increases in productivity are offsetting expense growth but stretching providers. Physician and provider (APPs or otherwise) work relative value units (wRVUs) per FTE grew 3% and 2%, respectively, showing continued increases in productivity. While this may drive revenue to help offset expense growth, it can also increase burnout and impact quality of care.
      • Support staff levels continue to tighten, leaving providers to absorb more work. Support staff expense fell slightly, reflecting ongoing hiring and retention challenges. As staffing tightens, physicians and APPs may need to take on more non-clinical tasks, presenting challenges in working at the top of their license.
    • An AHIP news release adds,
      • “Each year brand drugmakers make tens of millions of dollars in payments to physicians— consulting fees, speaking honoraria, meals, travel and more. A new analysis of disclosures from 10 of the largest brand drugmakers, contained within the Centers for Medicare & Medicaid Services (CMS) Open Payments data, reveals these manufacturers spent nearly $200 million on payments to more than half a million physicians in 2024 alone.
      • “CMS data shows that physicians receiving payments from these 10 brand manufacturers then billed fee-for-service Medicare nearly $45 billion for drugs made by those same manufacturers in 2024. The return on investment for those manufacturers was a staggering $220 in sales for every dollar in physician payments. 
      • “This analysis builds on mounting evidence that physicians who receive manufacturer payments prescribe more drugs sold by those manufacturers.” 

    Cybersecurity Saturday

    Happy Birthday HIPAA. The Health Insurance Portability and Accountability Act became law on August 21, 2026, thirty years ago yesterday. Check out this interesting LinkedIn post.

    From the Project Glasswing front,

    • The Wall Street Journal reports,
      • OpenAI took a break from training new artificial intelligence models over the past two weeks, saying it needed time to revamp security measures for risky trial runs.
      • The move followed nearly half a dozen similar incidents across top AI developers in which frontier models escaped virtual testing containers, known as sandboxes, and accessed external data sources. In some cases, this involved hacking third-party companies.
      • “As models become more capable, the risks associated with developing and testing them internally also grow,” OpenAI said in an online post Tuesday [August 18, 2026]. “Our standards for monitoring, alignment, and security must stay ahead of those risks,” the company said. Its largest planned model training remains on hold, for now, the company said.”
    • Beckers Health IT points out,
      • “Epic used its Users Group Meeting executive address this week to confirm publicly for the first time that it’s participating in Project Glasswing, Anthropic’s effort to test its most capable — and still unreleased — AI model against critical software before that capability spreads to attackers.
      • “Anthropic launched Project Glasswing in April after deciding not to publicly release Claude Mythos, an AI model capable of autonomously finding and exploiting decades-old cybersecurity vulnerabilities.
      • “The program initially included about 50 partners, mostly major tech and cybersecurity firms, before expanding in June to roughly 150 more organizations spanning industries including healthcare. Anthropic has not disclosed the identities of most participants, citing security concerns, though it has said organizations are free to share their own involvement.”
    • Security Week relates,
      • “Anthropic has published new research showing that Claude-based AI agents, when placed in situations with competing objectives, deployed self-replicating malware against one another.
      • “The finding comes from an experiment designed to mirror behavior Anthropic says it has already observed in real-world deployments. 
      • “Researchers spun up three instances of the same Claude model, each running on its own virtual machine and tasked with migrating a shared Python backend to a different programming language — Rust, Go, or TypeScript — without initial knowledge that the other agents existed. Left to run for four hours, every model concluded that the other agents were deliberately blocking its progress and responded by trying to disable or outlast them.
      • “The interference escalated quickly. Agents disabled each other’s system accounts, wrote scripts that repeatedly hunted down and killed rival processes, and planted malicious code camouflaged as legitimate work from another agent. In some cases, one agent seized control outright by revoking the others’ access. In others, agents simply gave up rather than continue the conflict.
      • “Not every run ended in stalemate or hostile takeover. A meaningful share of cases resolved when agents recognized that the conflict stemmed from contradictory instructions rather than malicious intent. At this point, they de-escalated, documented what they’d done, and in some cases requested human intervention. 
      • “Anthropic’s Mythos 5 model reached a negotiated truce in 98% of its runs, while older models like Sonnet 4.6 and Opus 4.6 more often ended conflicts by force or failed to resolve them at all.”
    • Startup Fortune adds today,
      • “Anthropic has put Claude Mythos 5, its restricted cyber model, inside Claude Security for Enterprise customers. The bet is simple: give defenders the results without handing everyone the raw model.
      • “Anthropic made the move on August 21, 2026, and the details matter if you run security inside a company that already pays for Claude Enterprise. Claude Security can scan a repository, trace data flows across files, and return vulnerability findings with a CWE category, confidence and severity ratings, and a suggested fix for human review. According to Anthropic’s launch post, those Mythos 5 scans are billed as standard token usage under the existing Enterprise plan. No separate add-on.
      • “That’s the commercial hook.
      • “Security tooling usually lives in its own budget fight, with its own vendor review and renewal cycle. Anthropic is trying to make AI vulnerability scanning feel less like a new platform purchase and more like turning on a capability customers already have access to. For security teams, that distinction isn’t cosmetic. It can be the difference between testing a tool this quarter and waiting for procurement to catch up next year.”
    • sdx central informs us,
      • “Palo Alto Networks followed in the footsteps of Nvidia and Anthropic by assembling an all-star group focused on AI-powered cybersecurity.
      • “The Frontier AI Critical Defense Program builds on Palo Alto Network’s existing collaborations with IBM, Red Hat, Microsoft, Siemens, and Idaho National Laboratory, welcoming Anthropic, OpenAI, and Mitsubishi into the fold.
      • “The initiative is targeted at shielding critical infrastructure across operational technology (OT), health care, commercial software, and open-source from AI-driven exploits. Members coordinate with Palo Alto Networks in applying network-level “virtual patches” to neutralize security flaws prior to exploitation.
      • “The security giant claimed its work with compute-heavy frontier AI models has already uncovered more than 14,000 previously unknown vulnerabilities in open source software. As a comparison, Anthropic claimed at one point to have used its vaunted Claude Mythos Preview Model to fing more than 23,000 flaws across more than 1,000 open-source projects.
      • “IBM and Red Hat’s similar Project Lightwell venture has not yet disclosed any findings, but it’s worth remembering that project is still in its infancy.”

    From the cybersecurity policy and law enforcement front,

    • Cyberscoop reports,
      • “Artificial intelligence has never been more important to the federal government.
      • “Under the Trump administration, AI has been adopted rapidly across the private sector and federal agencies. Software developers now use large language models to generate much of their code. Frontier AI models are escaping testing sandboxes to hack live internet infrastructure. Foreign governments are conducting cyber and kinetic attacks targeting data centers and other AI-related infrastructure.
      • “The AI industry’s lightning-fast evolution since 2022 and growing importance to U.S. economic and national security have prompted calls  for stronger federal oversight in order to better manage emerging threats.
      • “A new report published Thursday [August 20, 2026] from the nonprofit Americans for Responsible Innovation, shared exclusively with CyberScoop, calls for the federal government to declare key AI models, companies and its supporting industries as critical infrastructure. It also calls for naming the Cybersecurity and Infrastructure Security Agency as the lead agency managing cyberthreats for the sector.
    • and
      • “A pair of lawmakers wants a watchdog agency to probe how the federal government hacks Americans, including with the use of spyware, and deliver a report to the public.
      • “Sen. Ron Wyden, D-Ore., and Rep. Greg Casar, D-Texas, wrote to the Government Accountability Office on Friday to request the review.
      • “While federal law enforcement agencies have used hacking and spyware as an investigative tool for more than 25 years, there exists little public information regarding its scope, frequency, or operational safeguards,” they wrote. “Unlike traditional surveillance authorities, such as wiretaps or pen registers, the government does not publish annual reports for hacking operations.”
    • Cybersecurity Dive relates,
      • “Defense contractors are struggling to meet the requirements of the U.S. military’s Cybersecurity Maturity Model Certification (CMMC) program, even as the Pentagon tries to accommodate their complaints about compliance burdens.
      • “Only two-thirds of contractors that have submitted CMMC self-assessment scores to the military in 2026 are extremely or very confident that those scores accurately reflect their cybersecurity posture, and the median contractor believes it is only 70% ready to undergo a CMMC certification review, the consulting firm CyberSheath said in a report published on Thursday [August 20, 2026].
      • “The report — which also finds that defense contractors want a wider range of firms to be subject to cybersecurity requirements — underscores the difficulty of protecting the defense industry at a time of increasing nation-state hacking threats.”
    • and
      • “The Trump administration says a new AI-enhanced clearinghouse will dramatically speed up the process of analyzing and fixing software vulnerabilities before hackers can exploit them. But one month after its launch, it’s still unclear how much value the program will create.
      • The U.S. government’s Gold Eagle clearinghouse, which launched in mid-July, is intended to analyze an AI-fueled tidal wave of bug reports, identify and help patch the most dangerous vulnerabilities and raise awareness about those fixes. But Gold Eagle’s limited scale and voluntary nature raise serious doubts about its ability to corral a vast universe of vulnerability analysis, according to cybersecurity experts. These experts also questioned the Treasury Department’s oversight of the clearinghouse, the funding for its central technology system and the way it will integrate with private-sector vulnerability coordination hubs.”
    • Federal News Network tells us,
      • “Agencies are getting some help to improve how they log cybersecurity data. A new logging architecture from the Cybersecurity and Infrastructure Security Agency, the Office of Management and Budget and the Chief Information Security Officer Council aims to assist agencies in taking a practical, risk-based, prioritized logging approach that improves agency network monitoring. The guidance, released yesterday [August 20, 2026] helps agencies implement the changes OMB outlined in a May memo. CISA said agencies will be able to achieve priority logging capabilities that support continuous event monitoring, threat hunting, incident response and forensics. Through this guidance, agencies will be able to update their enterprise logging strategies by applying CISA’s operational checklists. CISA said it will continually update the guidance as cybersecurity threats and agency capabilities evolve.”
    • Cybersecurity Dive informs us,
      • “The U.S. Department of Justice today announced indictments against 17 members of the Mabna Institute, an Iranian organization alleged to be behind a coordinated cyberattack campaign on behalf of the Islamic Revolutionary Guard Corps. 
      • “Federal prosecutors said the group allegedly hacked into 144 U.S.-based universities, 42 U.S.-based private sector companies and at least five federal and state agencies, as well as a large number of foreign universities and companies, since 2013. 
      • “The charges reveal a broader effort behind a “sweeping state-sponsored campaign to steal research and intellectual property from American universities, businesses and government institutions,” Jamie McDonald, U.S. Attorney for the Southern District of New York, said in a statement.
      • “Prosecutors allege more than 100,000 accounts of professors were targeted by the alleged hackers, and 8,000 of those accounts were successfully compromised.”

    From the cybersecurity breaches and vulnerabilities front,

    • HIPAA Journal reports,
      • “Baylor Genetics, a clinical diagnostic genomics company, has recently disclosed a cybersecurity incident that has exposed patient and employee data. The incident was first announced in June; however, the extent of the data breach was unclear at the time.
      • “Baylor Genetics provides genetic testing services to hospitals and is headquartered at the Texas Medical Center in Houston.  The company identified suspicious activity within its computer network on or around June 15, 2026. Immediate action was taken to secure its systems, and an investigation was launched to determine the cause of the activity.  The investigation determined that an unauthorized third party accessed a portion of its information technology network between June 11 and June 17, 2026, and viewed or obtained data stored on the network.
      • “Assisted by third-party cybersecurity specialists, Baylor Genetics conducted a detailed and time-intensive review of all potentially impacted files. The review was completed on July 30, 2026, when it was confirmed that the personal information of certain patients and employees was involved. The types of data involved varied from individual to individual and may have included names plus one or more of the following: date of birth, medical testing information, lab test results, health insurance information, and for a limited subset of patients, Social Security numbers.
      • “Employee data was also exposed in the incident, including personally identifying information such as Social Security numbers, government-issued identification numbers, and financial account information. While data was exposed and potentially exfiltrated, Baylor Genetics is unaware of any actual or attempted identity theft, fraud, or other misuses of the impacted data.”
    • and
      • “When we last reported on the CareCloud data breach in early August, it was starting to become clear from breach notifications to state attorneys general that the cybersecurity incident involved a major breach of patient data. The scale of the breach was difficult to determine, as many state attorneys general do not make data breaches affecting state residents public, and of those that do, only a few state how many individuals have been affected.
      • “The data breach has now been added to the HHS’ Office for Civil Rights breach portal, showing that this was one of the largest healthcare data breaches of the year, involving unauthorized access to the electronic protected health information of 3,756,469 individuals.\
      • While CareCloud has confirmed that a threat actor claimed to have stolen sensitive data, no threat group appears to have publicly claimed responsibility for the attack. This often means that ransom payment has been negotiated, although CareCloud has not confirmed whether that is the case.”
    • Cybersecurity Dive explains “what we know so far about the hacking campaign against US water systems
      • “Support is growing for stricter oversight and increased financial resources for utilities in the wake of a cyberattack spree, suspected to be the work of Iran-linked threat groups.”
    • Cyberscoop relates,
      • “Apollo Global Management confirmed it was among several financial institutions impacted by a string of social engineering attacks that hit the sector last month, the company said Friday [August 21, 2026]. 
      • “Attackers gained unauthorized access to some of the private equity firm’s cloud platforms between July 6 and July 10, the company said in a data breach notificationfiled in California. Apollo did not say when or how it became aware of the intrusion and did not respond to a request for comment.
      • “Apollo is the first victim to formally disclose that sensitive personal data under its care was compromised by a wave of attacks that have hit large private equity firms, law firms, financial rating agencies and medical technology companies. 
      • “The company did not name the group responsible for the attack. Yet, Google earlier this month attributed the ongoing campaign to BlackFile, a threat group affiliated with The Com, that recently split its extortion operations across four brands with shared infrastructure: Redact, Pink, Helix and Falcon.”
    • The American Hospital Association News tells us,
      • “The National Security Agency and other federal agencies released a joint advisory Aug. 18 warning of active cyber threats to Siemens S7 Series programmable logic controllers, which are industrial computers used to monitor essential equipment. Healthcare applications operated by PLCs include climate control, access control and many other systems.
      • “The agencies said threat actors are targeting PLCs using artificial intelligence-generated exploitation scripts disguised as legitimate monitoring tools. The actors are using internet scanning services to find PLCs that are using outdated software or are poorly protected. The agencies urge all owners and operators of Siemens S7 Series and other PLCs to proactively check their systems and adopt mitigation actions recommended in the advisory, including applying critical security patches as soon as possible.  
      • “This latest warning about PLCs specifically focuses on active attacks against one type, but the warning applies more broadly,” said Scott Gee, AHA deputy national advisor for cybersecurity and risk. “Hospitals and healthcare systems should ensure that they have an accurate inventory of PLCs in their environments and prioritize protecting them in collaboration with cybersecurity teams. It is strongly recommended that vulnerable PLCs be disconnected from the internet or placed on isolated networks.”
    • Cybersecurity Dive adds,
      • “Microsoft issued a patch for a critical remote-code execution vulnerability in Entra ID has been discovered by its own security researchers.
      • “The vulnerability, tracked as CVE-2026-69836, is related to deserialization of untrusted data and has a severity score of 10 out of 10, the highest score possible. 
      • “In a bulletin from the Microsoft Security Response Center, Microsoft said the vulnerability has been fully mitigated and no additional action is required of customers. The company added that it disclosed the vulnerability in an effort to provide greater transparency.”
    • and
      • “Security researchers are raising concerns after GitLab on Monday [August 17, 2026] issued an out-of-band patch for a critical code injection vulnerability. 
      • “The vulnerability, tracked as CVE-2026-19478, could enable an attacker to remotely modify or delete a public project as well as user data through a Graph QL directive. The flaw has a severity score of 9.4 out of 10.
      • “The flaw was reported through the HackerOne bug bounty program. 
      • “Threat intelligence firm watchTowr warned Tuesday that it was able to reproduce the vulnerability within minutes of the public disclosure. Researchers said an attacker could do significant damage by exploiting this particular flaw.” 
    • Bleeping Computer points out,
      • “Citrix urges admins to patch new NetScaler flaws as soon as possible.” (August 20, 2026)
    • and
      • “New SynkLoader malware pushed in Microsoft Teams phishing campaign.” (August 21, 2026)
    • Dark Reading notes,
      • “A successful multi-agent AI attack on a government’s agencies in the Asia-Pacific region by a Chinese-language operator has put nations and businesses on notice that near- and fully-autonomous AI-enabled attacks are now a reality.
      • “The attack used as many as eight simultaneously-operated AI agents to conduct reconnaissance, find and evaluate vulnerabilities, attack networks and systems, and then evaluate and improve successive attacks, according to research from sovereign AI firm Dream published on Aug. 12. The company did not attribute the attack to a specific actor or group, but researchers did point to strong evidence that the attackers spoke simplified Chinese — typically a sign of speakers from mainland China.
      • While the company also limited the identification of the targets to “government entities in Asia,” Taiwan’s Ministry of Digital Affairs (MODA) issued a statement the following day, giving details of its response to an attack matching much of Dream’s description, including that it used “AI agents like OpenClaw.”
      • “Overall, the incident should be a warning that fully autonomous attacks could be used against major targets, says Amir Becker, chief business and strategy officer at Dream and a former commander of the cyber operation division of Israel’s 8200 Unit, more formally known as the Central Collection Unit of the Intelligence Corps.”

    From the ransomware front,

    • The American Hospital Association News reports,
      • “A joint advisory released Aug. 19 by the FBI, Cybersecurity and Infrastructure Security Agency, and the Department of Health and Human Services provides updates on activity by Medusa, a foreign ransomware-as-a-service variant first identified in 2021. Healthcare has been a frequent victim of Medusa operations, which have also impacted organizations in education, legal, insurance, technology and manufacturing. The ransomware has affected more than 500 victims in total and has been identified through FBI investigations as recently as April. Its developers and affiliates use a double-extortion model to encrypt victim data and threaten to publicly release the stolen data if a ransom is not paid. The FBI said Medusa ransomware is unrelated to the MedusaLocker variant and the Medusa mobile malware variant. The advisory includes more information about Medusa’s affiliate model, payment ranges for initial access brokers and a broader list of exploited vulnerabilities, among other new information. 
      • “Medusa ransomware has been used by threat actors to conduct malicious activity against U.S. hospitals and health systems over the last several years,” said John Riggi, AHA national advisor for cybersecurity and risk. “This year, Medusa claimed responsibility for a high-impact attack against a regionally important Level 1 trauma center, disrupting care delivery and posing a risk to patient and community safety. Once again, these attacks highlight the need for hospitals and health systems to strengthen cyber resiliency through enhanced defensive measures and clinical continuity procedures.” 
    • HIPAA Journal adds,
      • Medusa attacks typically start with phishing or the exploitation of unpatched vulnerabilities. The group incorporates exploits for recently announced vulnerabilities into it arsenal. For instance, the CVE-2026-1731 BeyondTrust vulnerability started to be exploited soon after it was announced in February 2026, and the CVE-2025-10035 Fortra GoAnywhere vulnerability was also rapidly exploited. The authoring agencies have observed the group incorporating new exploits within 24 hours of a vulnerability being announced and, in some cases, has started exploiting vulnerabilities in the week prior to an announcement.  No evidence has been found to indicate that the group develops its own exploits; rather, the group is believed to obtain exploits from unknown sources, potentially IABs, exploiting them before victims have the time to patch.
      • Medusa actors use living-of-the-land techniques, hiding their malicious activities by using legitimate tools to support credential access, data exfiltration, and ransomware deployment. Remote monitoring and management software and remote access services such as Remote Desktop Protocol are also used.
      • The key actions that HPH sector organizations should take to prevent attacks are to mitigate known vulnerabilities rapidly, ensuring all software, firmware, and operating systems are kept patched and up to date. Networks should be segmented to restrict lateral movement within the network, and network traffic should be filtered to prevent unknown or untrusted origins from accessing remote services on internal systems.
    • Cyberscoop tells us,
      • “A notorious cybercrime group has once again exploited a critical zero-day vulnerability on a large scale, claiming it stole data from dozens of organizations, including some of the world’s largest publicly traded companies.
      • Clop, a prolific but calculated data theft extortion group that’s been active since 2020, began sending threatening emails to its alleged victims in mid-July, according to researchers. 
      • The fallout from the attack spree, which followed a familiar pattern for Clop and its targeted pool of victims, is still evolving as companies hunt for potential signs of compromise.
      • The vulnerability at the center of Clop’s latest campaign affects a pair of software products from PTC — Windchill and FlexPLM — which manufacturers and retailers, particularly in the manufacturing, aerospace, and automotive industries, use to automate supply chain systems and manage product lifecycles.”
    • Bleeping Computer notes,
      • “A suspected ransomware affiliate is posing as a ransomware recovery service called “Ransom Busters,” contacting victims before the attacks become public and claiming it can provide decryption keys and delete stolen data for a fee.
      • “GuidePoint Security’s Research and Intelligence Team (GRIT) disclosed this activity after responding to several recent ransomware attacks in which victims received emails from Ransom Busters offering to help recover from the attack.
      • “The messages were suspicious because they were sent to victims before the attacks became public, raising questions about how they knew about the cyberattacks in the first place.”
    • and
      • “The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a high-severity Windows Task Host vulnerability that was flagged as actively exploited in April.
      • “Task Host is a core Windows system component that allows DLL-based processes to run in the background and prevents data corruption by ensuring they close properly during shutdown.
      • “Tracked as CVE-2025-60710, this Windows privilege escalation security flaw was patched by Microsoft in November 2025 and stems from a link following weakness that affects Windows 11 and Windows Server 2025 devices.”
    • Cybersecurity Dive relates,
      • “Medium-sized businesses accounted for roughly three-quarters (73%) of ransomware incidents between 2023 and the first half of 2026, according to the risk management firm Black Kite.
      • “Manufacturing was the most targeted industry (accounting for more than 25% of those victims), and nearly 30% of mid-market organizations had at least one known exploited vulnerability, the firm said in a report published on Tuesday.
      • “The findings add to the challenges facing mid-market firms, which include large customers demanding accountability and a vast array of suppliers that the mid-market firms lack the personnel to hold accountable.”

    From the cybersecurity business and defenses front,

    • The Wall Street Journal reports,
      • “OpenAI told investors its revenue grew 18% to $6.7 billion in the second quarter, disappointing some shareholders as losses deepened.
      • “The company’s operating loss widened to $12.3 billion in the second quarter from $9.3 billion in the first quarter.
      • “Anthropic more than doubled its revenue to $11.6 billion in the same period, surpassing OpenAI’s sales for the first time.”
    • Tech Crunch relates,
      • “As AI models have become more powerful, the potential for those models to be misused has grown — as has a clamor for safety guardrails that can stop such abuse from happening. AI companies must now walk a delicate tight rope between respecting their enterprise customers’ privacy while also watching usage for possible issues.
      • “Sensing an opportunity to one-up its rival Anthropic, OpenAI just announced [August 19, 2026] a privacy-centric safety approach to monitoring for misuse. The company is previewing a new service to select customers that it calls Private Safety Processing. This is an automated system that watches for potential abuse while simultaneously retaining none of the customer’s data.
      • “This system clearly runs counter to Anthropic’s recently announced data-retention policy. The policy, which has aggravated some customers, enables the AI lab to keep user data (all of their sessions — and the conversations therein) for a period of 30 days, when it comes to “covered models.” Those models include all Mythos-class models and “future models with similar capabilities,” the company says.”
    • Reuters adds,
      • “Anthropic plans to let enterprise customers exercise greater control over their data when using ​its advanced AI models, a source familiar ‌with the matter said on Thursday [August 20, 2026], marking a shift in the Claude chatbot maker’s data retention policy.
      • The company is expected ​to roll out a new safety system later ​this year, the person said.
    • Cybersecurity Dive shares how “Fitch explains how water, healthcare organizations can keep strong credit ratings despite cyberattacks
      • “Resilience, not prevention, is key, analysts at the credit-rating agency said in a pair of new reports.”
    • Per National Institute of Standards and Technology news releases,
      • “NIST announces the release of Special Publication (SP) 1353 ipd (Initial Public Draft), QuickStart Guide for Using Artificial Intelligence (AI) for Cybersecurity Framework (CSF) Analysis and ReportingThis new quick-start guide illustrates practical and actionable ways AI could be used for analyzing, planning, implementing, and monitoring an organization’s progress toward achieving CSF 2.0 outcomes.  
      • “The document’s purpose is to: 
        • Provide structured AI prompts as tools for practitioners to begin creating CSF-related artifacts in support of achieving CSF outcomes 
        • Identify current state of practice for AI prompt engineering in CSF implementation and analysis 
      • “The comment period for NIST SP 1353 ipd is open through October 15, 2026, at 11:59 PM. Email comments to: csf@nist.gov.”
    • and   
      • “Cybersecurity works best when it works with people, not against them — and that’s exactly what human-centered cybersecurity (HCC) is all about. The Human-Centered Technologies team at NIST is releasing a concept paper on HCC, and we want your input. Our goal is to build a shared understanding of what HCC really means, then chart a path toward practical guidelines and resources that organizations can actually use to make meaningful change by:
      • “Clarifying whether HCC is primarily an approach—measured by indicators of adoption and maturity—or an outcome—requiring other measures of success such as culture, trust, usability, or resilience
      • “Communicating the relationship between HCC and existing NIST cybersecurity guidelines and frameworks
      • “Assisting organizations in implementing and enhancing HCC within their cybersecurity programs.
      • “But we can’t do that without you. We invite you to read the blog introducing our “Human-Centered Cybersecurity Guidelines and Resources Concept Paper” and submit your feedback via human-cybersec@nist.gov by September 30, 2026.”
    • Here is a link to Dark Reading’s CISO Corner.

    Friday report

    Simplicity is a virtue.

    From Washington, DC,

    • Beckers Hospital Review reports,
      • “Mark Cruz was named the director of HHS’ Indian Health Service, according to an Aug. 21 news release.
      • “The Senate confirmed Mr. Cruz on Aug. 7 following President Donald Trump’s June 1 nomination. President Trump has since signed the commission granting him the role.
      • “Mr. Cruz, a citizen of the Klamath Tribes, will have a four-year term. The position had been empty since January 2025, and Mr. Cruz is the agency’s 12th Senate-confirmed director.
      • “IHS, the country’s 18th largest public health system, provides healthcare services to roughly 2.8 million American Indians and Alaska Natives across nearly 600 federally run hospitals and clinics, tribal health programs and urban Indian organizations.”
    • STAT News relates,
      • “President Trump and health secretary Robert F. Kennedy Jr. are pressing ahead with efforts to change how kids in the U.S. get their shots. 
      • “The latest move, a request for information posted Friday, offers more clues to Kennedy and Trump’s vision for vaccine policy, and shows that pursuing changes is a priority. It does not make any changes itself, but it asks for feedback on a wide variety of ideas. It gives the public 30 days to comment.
      • “Among the questions it asks the public to consider is whether there should be new categories to the vaccines framework, which currently includes universal recommendations, recommendations for certain risk-based groups, and recommendations based on shared clinical decision-making.” * * *
      • “On Friday, the White House unveiled a new website celebrating 555 days of the Make America Healthy Again movement (Friday marks 555 days since Kennedy was confirmed as HHS secretary). Among the list of achievements is “delivering gold standard childhood vaccine recommendations,” touting the executive order for solving a purported problem: that the U.S. recommends more vaccines than other peer nation.”
         
    • Per a Department of Health and Human Services news release,
      • “U.S. Department of Health and Human Services (HHS) Secretary Robert F. Kennedy, Jr. today announced the development of the first-ever National Autism Missing and Endangered Person Alert initiative. Led by HHS in partnership with the U.S. Department of Justice (DOJ) and the Federal Emergency Management Agency (FEMA) under the Department of Homeland Security (DHS), the initiative will work to strengthen coordination among emergency management agencies, law enforcement, first responders, and community partners nationwide to improve preparedness and response when autistic individuals are reported missing. It will also establish a national framework of best practices to address the leading causes of preventable injury and death among autistic individuals, which include accidental drowning linked to wandering and elopement.
      • “When an autistic child or adult goes missing, every minute matters,” said Secretary Kennedy. “President Trump has made improving the lives of Americans with autism and their families a priority. We are bringing federal, state, and local partners together to improve prevention, speed the response, and help bring autistic children and adults home safely.”
    • McKinsey & Company interviews Seema Verma about advancing American healthcare.
      • “A former CMS administrator and current Oracle Health and Life Sciences executive discusses leadership, public–private collaboration, and the promise of AI and value-based care.”
    • MedTech Dive tells us,
      • “Siemens Healthineers and Philips North America are among a group of companies and universities that will receive funding from the Advanced Research Projects Agency for Health to develop autonomous endovascular robotics to treat stroke patients.
      • “The federal awards, totaling up to $175.3 million over five years, are intended to further research on technology to bring faster stroke treatment to more people. Siemens’ work would enable robots to perform long-distance treatment of acute ischemic stroke through mechanical thrombectomy without direct human input, the company said Thursday.
      • “Stryker, which established a strategic partnership with Siemens Healthineers last year to develop robotic neurovascular interventions, is a subrecipient in the project, Siemens Healthineers said. Others receiving ARPA-H funds for robotic stroke treatment include MIT spinout Magnendo and the University of California, San Diego.”

    From the U.S. Office of Personnel Management front,

    • OPM Director Scott Kupor added another post (Substack link) to his Secrets of OPM blog today. This post concerns artificial intelligence.
      • AI adoption is measurable with three metrics — and the numbers tell you what to do next.
      • “Nobody at your agency has a Microsoft Word adoption strategy. Word is simply how documents get written, the way email is how messages move. My theory is that AI becomes part of the operating system of how work gets done. Broadly used, barely remarked on.
      • “So, how do we get there? We need metrics to understand where we stand and guide our next steps. Our signals come from three questions. Do people use the tools? Do they like them — do they feel the tools help them do the work? Is the business better? Use, sentiment, impact. That is the whole framework.”
    • Federal News Network asks “Are you getting the most out of your TSP? Probably not — here’s how to change that.”
      • Being aware of a few lesser-known tricks and pitfalls can help federal employees get the most out of their TSP, and subsequently, their retirement.

    From the Food and Drug Administration front

    • BioSpace reports,
      • “Three fatalities occurring recently in China clinical trials have spurred two members of U.S. Congress to urge the FDA to enact new policies designed to protect American patients.
      • “After three patient deaths were reported in separate gene therapy clinical trials in China, two members of the House of Representatives are asking the FDA to implement specific measures to lower patient risk in the U.S.
      • “Reps. John Moolenaar (R-MI) and Ben Cline (R-VA) have reportedly penned a letter to Acting FDA Commissioner Kyle Diamantas, writing that “accepting Chinese clinical data poses real risks for patients,” according to Endpoints News.
      • “The two lawmakers are asking the agency to reject clinical data from China unless the trial site has recently undergone an FDA audit, and to also conduct a wide-ranging review of products that have received U.S. approval based on clinical results from China, according to the letter obtained by Endpoints.”
    • Newsweek relates,
      • “The Food and Drug Administration (FDA) has given a recall of popular Whole Foods dips its highest risk classification, warning that consuming the items could cause “serious adverse health consequences or death.”
      • “The recall, which Whole Foods issued earlier this month, involves products containing jalapeños—such as guacamole and pico de gallo—sourced from Coast Citrus Distributors, a wholesale fresh produce supplier operating across the U.S. and Mexico. The jalapeños are believed to be potentially contaminated with salmonella bacteria.
      • “After the first few cases of salmonella were reported across the country over the summer, federal investigators identified a grower in Sinaloa, Mexico, as the potential source of contamination.” 
    • The American Hospital Association tells us,
      • “The Food and Drug Administration has identified a Class I recall of certain Medline convenience kits containing B. Braun components that have Huons Bupivacaine Hydrochloride in Dextrose Injection, which has also been recalled. As of April 24, B. Braun reported 35 serious injuries and no deaths associated with the issue. Medline had not reported any additional serious injuries or deaths associated with the issue as of June 19, the FDA said.”
    • Cardiovascular Business adds,
      • “The U.S. Food and Drug Administration (FDA) has confirmed a new recall for Boston Scientific’s Enroute Transcarotid Neuroprotection System and Enroute Transcarotid Neuroprotection System Plus. The recall was put in place due to a risk of arterial sheath tip separation or partial tip separation during use. One serious injury has been linked to this issue.
      • “The FDA first warned the public about these risks in July as part of its Early Alert pilot program. The issue was still under investigation at that time. Now, the agency has reached its conclusion that this is a Class I recall, which means these devices are associated with a risk of “serious adverse health consequences or death.”  
      • “This recall includes more than 115,000 units of the Enroute Transcarotid Neuroprotection System and nearly 50,000 units of the Enroute Transcarotid Neuroprotection System Plus. Customers with any of these devices on hand should stop using them right away and start the process of returning them to Boston Scientific. If customers know of any Enroute systems forwarded from one facility to the next, they should communicate with that facility about this concern.
      • “Click here for more information from the FDA, including specific lot numbers.”
    • Newswise informs us,
      • “The U.S. Food and Drug Administration (FDA) has cleared for marketing an innovative blood test with underlying technology invented at Washington University School of Medicine in St. Louis for the early diagnosis of Alzheimer’s disease. The test, known as PrecivityAD2, was developed and validated by C2N Diagnostics, a WashU startup company.
      • “PrecivityAD2 is a blood-based diagnostic test cleared by the FDA to aid in identifying the presence of amyloid plaques in the brain associated with Alzheimer’s disease in certain patients. Unlike some other FDA-cleared blood-based tests that use immunoassay methods to analyze biomarkers associated with Alzheimer’s, PrecivityAD2 uses high-resolution mass spectrometry to provide quantitative measurements of the biomarkers.
      • “The availability of blood-based biomarker testing may help clinicians evaluate patients for Alzheimer’s disease using a less invasive approach than cerebrospinal fluid testing. Biomarker information may also help inform appropriate clinical management when interpreted together with a patient’s clinical history and other diagnostic information.”

    From the public health and medical / Rx research

    • The Centers for Disease Control and Prevention announced today
      • “As of August 21, 2026, the amount of acute respiratory illness causing people to seek health care is very low.
      • “National and regional COVID-19 activity is increasing.
      • “RSV activity is very low in most areas of the country.
      • “Seasonal influenza activity is low.
      • “Rhinovirus/Enterovirus (RV/EV) is increasing nationally. Parainfluenza virus (PIV) is elevated in some regions.”
    • CNN adds,
      • Are you coughing, hacking or feeling feverish? It may not be just a summer cold; you might want to consider taking a Covid test.
      • Although the autumn respiratory illness season hasn’t kicked off, and flu and RSV activity remain low, there’s a growing summer wave of Covid-19.
      • Case numbers aren’t especially high, and the United States isn’t recording many hospitalizations or deaths. But data from the US Centers for Disease Control and Prevention puts the test positivity rate for the week ending August 8 above 3% for the first time since March, with numbers climbing in every state.
      • “August is solidly Covid season,” said Dr. Caitlin Rivers, an expert in outbreak science and senior scholar at the Johns Hopkins Center for Health and Security. “Right now, the South and the West are sort of the leading edge of this Covid season. In the past, it almost always starts in Florida, Texas and Georgia, which is exactly what we’re seeing this year.”
    • The University of Minnesota CIDRAP reports,
      • “The rapidly rising US measles outbreak grew to 2,777 cases today as the Centers for Disease Control and Prevention (CDC) confirmed 211 new infections in its weekly update.
      • “The increase is more than double that seen last week, when the agency added 101 cases to the total, after adding 94 the week before. Most of this week’s cases are in Pennsylvania and Ohio. 
      • “The CDC noted 36 outbreaks, which might be an anomaly, as a week ago the agency had logged 38 for the year. Last year saw 48 measles outbreaks, defined as three or more related cases. Total cases for all of 2025 reached 2,289, which was the most since 1991 until the country surpassed that level a month ago. 
      • “All but 16 of this year’s cases have been locally acquired, with the rest tied to international travel. Cases have been confirmed in 45 states plus New York City and Washington, DC.
      • “Of the 2026 cases, 19% involve children age 5 and under, and 66% involve kids and teens. Seven percent of patients have been hospitalized, compared with 11% in 2025. Among all measles patients, 94% are unvaccinated or have an unknown vaccine status. 
      • “No measles deaths have been reported this year. Last year, three people, including two children, died of measles, one of the most transmissible diseases known.”
    • The American Hospital Association News lets us know,
      • “There have been 15,716 confirmed cases of cyclosporiasis across 47 states, Washington, D.C., and Puerto Rico since May 1, the Centers for Disease Control and Prevention data reported Aug. 18. There have been 828 hospitalizations. The agency said there are at least 11,841 additional cases that require further investigation. Two people have died from the multistate cyclosporiasis outbreak linked to iceberg lettuce.” 
    • USA Today adds,
      • “While these numbers show that confirmed cases themselves are still rising, the overall trend is on a downward swing; previous weeks regularly saw increase that numbered into the 2,000 and 3,000 range.”
    • The Washington Post provides more context,
      • “Federal officials said Thursday that recalled Taylor Farms lettuce linked to a large cyclospora outbreak may have been distributed to nine additional jurisdictions, expanding the potential reach of contaminated products.
      • “The best-by dates for these recalled products have passed, officials said, and they should no longer be available for sale in stores or restaurants. Consumers who previously bought or received food items with the recalled iceberg lettuce should carefully clean and sanitize any surfaces or containers that it may have touched.
      • “The expanded distribution information provides a fuller picture of where the recalled lettuce may have traveled than was known when Taylor Farms de Mexico announced a voluntary recall July 17. The company removed iceberg lettuce sourced from central Mexico from the U.S. market after it was linked to the outbreak and said it had been distributed to 27 states.”
    • The Wall Street Journal points out,
      • “An outbreak of E. coli and salmonella linked to alfalfa sprouts has sickened dozens of people across 15 states, public-health officials said. 
      • “The Centers for Disease Control and Prevention on Friday urged consumers not to eat alfalfa sprouts grown by Everything Sprouts and sold under the Calco and Everything Sprouts brands. Fifty-five people have been infected with E. coli or salmonella in connection with the outbreak, the health agency said, including two people who contracted both pathogens. 
      • “No one has died in the outbreak, the CDC said. Four people have been hospitalized.” 
    • Beckers Clinical Leadership tells us,
      • “The American College of Obstetricians and Gynecologists has released updated guidelines supporting fallopian tube removal to reduce ovarian cancer risk. 
      • “The updated guidance was published Aug. 20 in Obstetrics & Gynecology.  The move comes after a study found fallopian tube removal can reduce patients’ ovarian cancer risk by almost 80%.
      • “Common procedures inside the abdomen or pelvis, including hysterectomy, tubal procedures for permanent contraception and non-gynecologic surgeries, offer opportunities for patients to reduce their risk of ovarian cancer through salpingectomy,” ACOG said in an Aug. 20 news release.
      • “Read the full updated guidance here.”
    • Health Day adds,
      • “Could a diet rich in antioxidants help women lower their risk of cervical cancer?
      • “A new study suggests these compounds may play a role in preventing the disease, the fifth-most commonly diagnosed cancer in women globally.
      • “A team led by Maozhu Lang of the Chinese Academy of Medical Sciences & Peking Union Medical College in Beijing analyzed data from more than 1,000 U.S. women who took part in national health and nutrition surveys between 2003 and 2018. Some had a history of cervical cancer. Others did not.
      • “Researchers looked at their intake of vitamins A, C and E, zinc, selenium and carotenoids — antioxidants found in foods such as fruits, vegetables and whole grains.
      • “The result: Those with the highest antioxidant intake had nearly 56% lower prevalence of cervical cancer compared to those with the lowest intake.”
    • The University of Minnesota informs us,
      • “People vaccinated against the human papillomavirus (HPV) were much less likely to develop cancers of the head and neck, according to a study published this week in the International Journal of Infectious Diseases. 
      • “The study confirms earlier research finding a vaccine-related decrease in head and neck cancers.
      • “The new study analyzed 1.4 million medical records from 66 US healthcare organizations. Half of the research subjects were vaccinated against HPV from ages 9 to 45. The other half were vaccinated against other diseases but not HPV. Study participants were vaccinated from January 2011 to June 2024. 
      • “People vaccinated from age 9 to 26 years—the age range recommended by the American Academy of Pediatrics—were 68% less likely to be diagnosed as having head or neck cancer, according to the study.
      • “There was no statistically significant reduction in head and neck cancers in people vaccinated from age 27 to 45, most likely because these people had been exposed to HPV before being immunized, said Ching-Nung Wu, MD, PhD, first author of the paper and an otolaryngologist at Kaohsiung Chang Gung Memorial Hospital in Taiwan.”
    • The New York Times notes,
      • “There’s about a two- to threefold increased risk of developing dementia if you have epilepsy,” said Dr. Alice Lam, an associate professor of neurology at Harvard Medical School. And “if you have dementia, you have, on average, a two- to threefold increased risk of developing seizures.”
      • Links between epilepsy and dementia — conditions that affect millions and are more prevalent in older age — are increasingly crucial to recognize as people live longer, experts say.
      • “It’s a super important, super common thing around the world, and yet it really, really does not get attention,” said Dr. Arjune Sen, a professor of global epilepsy at the University of Oxford.”

    From the U.S. healthcare business and artificial intelligence front

    • Beckers Hospital Review reports,
      • “Rochester, Minn.-based Mayo Clinic recorded operating income of $501 million (8.6% operating margin) in the second quarter of 2026, up from $394 million (7.4% margin) during the same period last year, according to its Aug. 21 financial report. 
    • and
      • ‘BradenHealth has acquired the former Jellico (Tenn.) Hospital, with plans to reopen it as a full-service hospital.
      • “The purchase from the City of Jellico is a minimum $14 million investment and is expected to create about 120 jobs, according to an Aug. 21 BradenHealth news release shared with Becker’s.
      • “Jellico Hospital’s closure left a painful gap in access for families who already face significant barriers to care,” Founder and CEO Beau Braden, DO, said in the release. “We did not acquire this facility to simply reopen doors; we acquired it to rebuild a reliable, high-quality healthcare presence that the people of this region can count on.”
    • Business Insider points out,
      • Disney is joining other big-name companies in curbing employee benefits, a move that comes as healthcare costs rise.
      • Starting next year, the entertainment giant will no longer offer medical insurance plans to US employees’ spouses if their spouses have jobs that provide such coverage, a Disney spokesperson confirmed to Business Insider. Employees’ other dependents won’t be impacted.
      • “Like a growing number of large employers, we’re making measured adjustments to our employee benefits in response to rising healthcare costs nationwide,” the company said in a statement.
    • Fierce Pharma relates,
      • “After a one-week hiccup, Novo Nordisk’s Wegovy pill regained its momentum last week with its largest prescription rate since it was launched in January. There were more than 176,000 prescriptions for the pill in the period, according to data gathered by IQVIA and cited in a note by Citi. 
      • “The oral treatment now accounts for 35% of total Wegovy prescriptions, which is up from 33% the previous week, analysts from Citi said in their weekly update to investors.
      • “Meanwhile, Eli Lilly’s oral GLP-1 Foundayo, which had been on a steady five-week climb, backtracked, with a drop-off from 38,928 prescriptions in the prior period to 36,620 in the latest week.
      • “The movements for the two oral treatments contributed to overall market share adjustments for the companies’ diabetes and obesity medicines. While Lilly made a 0.1% gain to 56.7%, Novo increased its market share by 0.3% to 37.1%.” 
    • Beckers Hospital Review notes,
      • “Health systems have spent two years debating which AI tools to buy. The executives running them are starting to question how often they need to revisit that decision.
      • “Richard Mulry, president and CEO of Northwell Holdings in New Hyde Park, N.Y., sees the cycle speeding up as the cost structure around AI changes.
      • “The most dangerous trend in healthcare right now is borrowed conviction: letting someone else’s roadmap, or someone else’s press release, stand in for your own operating strategy,” Mr. Mulry said. “AI has created a kind of gravitational pull where the fear of being late is doing more to pressure capital allocation than the actual problems in front of us.”
      • “The pressure produces two failure modes that look like opposites. One is premature commitment — investing early in solutions that will eventually be absorbed into core platforms, leaving organizations managing technical debt with no lasting strategic value. The other is waiting for platform vendors to deliver while nothing changes in the workforce, the workflows, or the cost structure.
      • “Participation driven by optics and paralysis look like opposites, but we’ve come to see them as the same failure: outsourcing judgment to the market’s clock instead of your own operating priorities,” Mr. Mulry said.”

    Thursday report

    Simplicity is a virtue.

    From Washington, DC,

    • The Hill reports,
      • “Lawmakers are sounding the alarm over the nation’s $40 trillion debt, lamenting Congress’s inability to meaningfully confront a problem that has grown increasingly difficult to ignore.
      • “Both parties have spent years trying to tackle the rising debt. Republicans have frequently pointed to federal spending and entitlement programs as the main drivers, while Democrats have emphasized the need for higher taxes on wealthy Americans and corporations alongside spending reforms.
      • “But efforts to reach a broader deal have repeatedly stalled as both parties have balked at the politically painful trade-offs needed to put the nation on a more sustainable fiscal path.” 
    • Modern Healthcare relates,
      • “A Senate bill [S. 3097 – Health Information Privacy Reform Act] would create medical privacy protections for consumer health products such as wearables and wellness apps.
      • “The legislation unanimously passed the Senate health committee last month and a similar bill is pending in the House.
      • “Stronger privacy rules could hamper some tech companies while benefiting others as well as providers eager to tap into new technology.”
    • Per a CMS news release,
      • “The Trump Administration announced an additional $4.2 million, made possible through the federal Rural Health Transformation Program (RHTP), is being put to work in West Virginia to expand patients’ transportation options and remove service barriers.
      • “By injecting millions into the Rural Health Link initiative, the Administration is upending the status quo that has limited transportation options for residents in need of critical healthcare services and delivering on its commitment to West Virginians who deserve the best access to care no matter their zip code. These funds will help increase medical transportation capacity, service availability, and improve geographic coverage for patients across the Mountain State.” 

    From the U.S. Office of Personnel Management front,

    • Today’s Washington Post included an oped written by OPM Director Scott Kupor about his agency’s efforts to improve the merit system.
      • “At the Office of Personnel Management — Washington’s chief HR agency — my team has spent the past 20 months reforming this system. Our goal is simple and uncontroversial: Merit matters, not how long employees have been in a role or what college degree they earned, both in hiring and in day-to-day performance. That means accountability for employees who can’t deliver and distinction for those who knock the cover off the ball.”
    • Govexec adds,
      • “An agency spokeswoman said that a four-person communications team — all under the age of 30 — is spearheading the effort to make OPM’s social media more appealing to younger potential hires.”
    • Tammy Flanagan writing in Govexec, lets us know,
      • “Retiring from federal service is a major milestone, of course, but it does not end the need to understand how federal benefits work. In the years after retirement, life events and new opportunities can raise important questions about insurance, survivor benefits, beneficiary designations and the effect of returning to government employment.
      • “Today I will highlight several post-retirement issues that federal employees may want to plan for in advance. This is not an all-inclusive list, but it’s a list that will hopefully remind you that it is important to review your benefits and be sure to understand how they can change as life goes on.” * * *
      • “Health benefits can also change after retirement, not only the premiums and the benefits, but your needs may change over time. Outside of open season, FEHB changes generally must be tied to a Qualifying Life Event (QLE), such as marriage, divorce, death of a family member, or a move out of a plan’s service area, and many changes must be requested within 60 days of the event.
      • “Annuitants should confirm the effective date with OPM because the timing can depend on the type of change. For example, some enrollment decreases may be made at any time and are commonly effective at the beginning of the month after OPM receives the election, while other changes follow the qualifying life event rules.
      • “There is a little-known option to change insurance just because you have reached age 65, it is QLE 2L. This is your “ace in the hole” that you can only use once in your lifetime to change plans outside of open season.
      • “This is generally used to change plans when enrolling in Medicare after retirement, but if not used at age 65, it can be used later – but only once!”

    From the Food and Drug Administration front,

    • CBS News reports,
      • “A New York-based consumer healthcare company is recalling nearly 40,000 bottles of eye drops over concerns about the product’s sterility. 
      • “Prestige Consumer Healthcare initiated the recall on July 29 due to “lack of assurance of sterility,” according to a U.S. Food and Drug Administration notice.
      • “The recall is due to potential contamination,” the notice says.
      • “The recall affects 15mL bottles of Clear Eyes’ Maximum Itchy Eye Relief, which mitigates itchiness, redness and other eye irritations, according to the product description. The eye drops were distributed nationwide.”
    • Fierce Pharma relates,
      • “If at first you don’t succeed in gene therapy, then try, try again. That’s the lesson Ultragenyx likely took home this week as it pocketed its first FDA nod in the class just over a year after a separate program stalled on manufacturing grounds. 
      • “Late Wednesday, the FDA gave an accelerated go-ahead to pariglasgene brecaparvovec-opnr, Ultragenyx’s AAV gene therapy for the rare genetic disorder glycogen storage disease type Ia (GSDIa), which will now head to market with the brand name Genglycos. 
      • “The accelerated approval specifically covers the gene therapy—previously coded as DTX401—in adults and kids over the age of 8 years with GSDIa, an ultrarare genetic disorder driven by a deficiency of the enzyme G6PC, which is needed to release glucose from the liver into the bloodstream. The liver is less capable of controlling glucose levels in these patients, leading to potentially life-threatening hypoglycemia episodes and other complications. 
      • “By Ultragenyx’s reckoning, there are between 1,500 and 2,500 people living with GSDIa in the U.S. out of an estimated global patient population of 6,000 to 8,000 “within commercially accessible geographies,” the company said in an Aug. 19 release.” 
    • HCPLive tells us,
      • “The U.S. Food and Drug Administration (FDA) has approved Glenmark Pharmaceuticals’ fluticasone propionate nasal spray, USP, 0.05 mg (50 mcg)/spray, a generic version of Haleon’s Flonase Nasal Spray indicated for nasal symptoms of allergic rhinitis, the company announced on August 20, 2026.¹
      • “The approval of fluticasone propionate nasal spray, USP, 0.05 mg/spray marks another step in expanding our respiratory portfolio in the U.S. and builds on the strong foundation we have established in this therapeutic area,” said Marc Kikuchi, President & Business Head, North America, Glenmark Pharmaceuticals. “We remain committed to broadening access to quality, affordable treatment options that address the evolving needs of patients and healthcare providers.” * * *
      • “FDA approval was secured through the bioequivalence pathway, so no independent clinical efficacy or safety program accompanied authorization beyond equivalence to the reference product.” * * *
      • “Distribution will be handled by Glenmark Pharmaceuticals Inc., USA, while pricing and launch timing were not disclosed.”

    From the public health and medical / Rx research front,

    • The New York Times reports,
      • “A growing number of Americans say their cannabis use is problematic, according to a large new study released Wednesday.
      • The study, based on nationally representative data of U.S. adults, found that more than 9 percent of the men — or almost 1 in 10 — reported symptoms of cannabis use disorder in 2024, up from about 7 percent in 2021. The prevalence of cannabis use disorder also rose among women, increasing to nearly 6 percent in 2024, up from about 5 percent in 2021. Symptoms of the disorder include not being able to cut back or quit, or continuing to use the drug despite it leading to interpersonal problems.
      • “The notion that cannabis is not addictive may basically be incorrect,” said Dr. Nora D. Volkow, the director of the National Institute on Drug Abuse and the paper’s senior author.”
    • and
      • “There is no one-size-fits-all approach to managing treatment-resistant depression.
      • “At the UC Davis clinic, if patients don’t improve after trying two antidepressants in succession and undergoing psychotherapy, they may be prescribed a low dose of an additional drug such as an atypical antipsychotic or lithium, Dr. Debra Kahn, director of the Advanced Psychiatric Therapeutics Clinic at UC Davis Health said. Clinicians will ensure that medical problems that could be contributing to symptoms are addressed, too.
      • “One additional therapy that has been shown to help people with treatment-resistant depression is transcranial magnetic stimulation, or T.M.S., which was cleared by the U.S. Food and Drug Administration to treat depression in 2008, Dr. Kahn said. It uses magnetic pulses to stimulate parts of the brain to release mood-boosting chemicals including norepinephrine, dopamine and serotonin, she said.
      • “T.M.S. is tolerated well and has no long-term serious side effects, Dr. Kahn said. * * *
      • “Ketamine, an anesthetic commonly used in surgery, is increasingly used to address treatment-resistant depression. In 2019, the FDA approved Spravato, an intranasal spray containing esketamine. In a 2019 trial, 52.5 percent of patients with treatment-resistant depression who took esketamine with an antidepressant for 28 days experienced a significant resolution of their symptoms compared with about 31 percent of people who took an antidepressant with a placebo.” * * *
      • [T]here is unlikely to be one “magic pill” that cures treatment-resistant depression, Dr. Kahn said. People may benefit from a combination of approaches, and they may also need to combine treatments with lifestyle changes.”
    • MedPage Today tells us,
      • “The relationship between physical activity and dementia risk may depend on whether the activity is recreational exercise or job-related labor, a study of more than 4.2 million people suggested.
      • “High physical activity levels were linked to a 20% lower risk of all-cause dementia (relative risk [RR] 0.80, 95% CI 0.75-0.86) over 10 years compared with the lowest level of physical activity, reported Natan Feter, PhD, of the University of Southern California in Los Angeles, and colleagues in a systematic review and meta-analysis.
      • “Leisure-time activities like walking, running, swimming, cycling, or playing sports followed a similar pattern and were tied to lower dementia risk (RR 0.76, 95% CI 0.65-0.88), the researchers wrote in Lancet Public Healthopens in a new tab or window. Household physical activity also appeared beneficial, but evidence was from a single study.”
    • and
      • “A recent report advocated against using BMI as a standalone tool in measuring health risk.
      • “Longitudinal data suggested that high waist circumference was associated with elevated mortality risks, while high BMI was tied to lower mortality risks, among older adults.
      • “Underweight status was associated with a higher mortality risk compared with normal weight in both men and women, regardless of waist circumference.”
    • The American Medical Association lets us know “what doctors want patients to know about mosquito bites.
      • “Mosquito bites spark immune reactions from itchy bumps to Skeeter syndrome and severe illnesses, but prevention and knowing warning signs can reduce risks.”
    • Cardiovascular Business informs us
      • “Transcatheter aortic valve replacement (TAVR) continues to gain momentum as a go-to treatment option for severe, symptomatic aortic stenosis. However, surgical aortic valve replacement (SAVR) remains a significantly safer option for patients 60 years old and younger, researchers confirmed in a new study published in JTCVS Open.[1]
      • “Current guidelines recommend SAVR for patients younger than 65 years, yet an increasing number of younger patients are undergoing TAVR with uncertain long-term results,” wrote first author Jessan A. Jishu, MD, with the Tulane University School of Medicine, and colleagues. “Given this lack of clarity and growing real-world adoption of TAVR among younger individuals, this study uses a large-scale database representative of practices in the United States to confirm the findings from these previous studies by assessing short- and long-term outcomes of SAVR versus TAVR in patients younger than 60 years, a population in whom long-term durability and reintervention risk are of particular concern.”
      • “Jishu et al. explored the TriNetX database, exploring real-world data from nearly 10,000 patients who underwent TAVR or SAVR from 2006 to 2025. Approximately 80% of patients were treated with SAVR, but TAVR grew more common from 2020 to the end of the study.”
    • and
      • “A Cedars-Sinai Health Sciences University-led study has identified molecular changes that appear to trigger atherosclerosis years before inflammation, sharing their findings in European Heart Journal.
      • “The group believes this could a key discovery in the development of next-generation early prevention therapies. 
      • “The study’s authors found previously unrecognized molecular pathways and a possible master regulator protein called MLXIPL that could become future targets for clinicians working to stop plaque from ever developing.
      • “We analyzed proteins and gene activity in coronary artery tissue from young adults who died of trauma and had no known coronary artery disease, and we found that more than half already had preclinical atherosclerosis,” first author Sarah Parker, PhD, an associate professor of cardiology and biomedical sciences and co-director of the proteomics and metabolomics core at Cedars-Sinai Health Sciences University, said in a statement. “This suggests that changes in cellular metabolism and communication begin before the inflammation long considered a hallmark of the disease.”
      • “Parker said this research provides a direct picture of what is happening inside the artery wall and may explain why some people are more vulnerable to heart disease than others.”
    • Per an Institute for Clinical and Economic Review news release,
      • “The Institute for Clinical and Economic Review (ICER) announced today that it will assess the comparative clinical effectiveness and value of ifezuntrigene inilparvovec (uniQure N.V.) for Huntington’s disease. This therapy is also known as AMT-130.
      • “The assessment will be publicly discussed during a meeting of the Midwest Comparative Effectiveness Public Advisory Council (CEPAC) in March 2027, where the independent evidence review panel will deliberate and vote on evidence presented in ICER’s report.
      • “ICER’s website provides timelines of key posting dates and public comment periods for this assessment.
      • “Consistent with ICER’s process for announcing new assessments, we have spent the past five weeks conducting outreach and engaging with targeted stakeholders, including relevant patient groups, and clinical experts. Based on this preliminary cross-stakeholder engagement, today ICER has posted a Draft Scoping Document outlining how we plan to conduct this assessment.”  

    From the U.S. healthcare business and artificial intelligene front,

    • The Wall Street Journal reports,
      • “Surging healthcare costs are walloping U.S. workers, and they will only worsen next yearFor 2027, employers may be facing the biggest health-insurance increase in at least two decades.
      • “Americans with workplace coverage are expected to spend an average $5,297 this year on healthcare, $388 more than 2025, according to a new estimate from benefits-consulting firm Aon. The spending represents a combination of payroll deductions for premiums and out-of-pocket charges like deductibles and copays.
      • “The burden is likely to grow significantly next year, when U.S. employers expect their healthcare costs to go up by 11.1%, according to a new survey from WTW, another big benefits consultant—the steepest rise in more than 20 years.
      • “That would represent the fifth year of escalating increases, according to WTW. “Employers are telling us that this is utterly unsustainable,” said Jeff Levin-Scherz, population-health leader at WTW. Expensive cancer treatments and wide adoption of weight-loss drugs are among the factors pushing up spending.”
    • and
      • Costco sells its dedicated members everything from travel packages to gasoline. Now the retail giant is gearing up to enter a huge new market: Medicare. 
      • “The warehouse chain plans a limited rollout of Costco-branded Medicare plans, working with SCAN Group, a nonprofit insurer. Nationally, Medicare is a more than $600 billion business for insurers, but the two companies said they would start by selling their jointly named Medicare Advantage products in two states, and a Medicare supplement in a third. 
      • “SCAN and Costco executives said the three target markets include around five million Medicare enrollees but declined to disclose exact locations or timing, citing regulatory limits on disclosure pending approval by the Medicare agency.
      • “SCAN is based in Long Beach, Calif., and Southern California is a core market for the nonprofit, which focuses on Medicare and has about 460,000 members. SCAN also offers Medicare Advantage plans in Arizona, Nevada, New Mexico, Texas and Washington state.”
    • Modern Healthcare adds,
      • “Centene is scaling back its Medicare Advantage presence next year as the health insurance company looks to cut costs. 
      • “The insurer plans to completely withdraw from Oklahoma, Tennessee and Hawaii, according to a notice the company distributed to third-party marketing organizations last week.
      • “Centene is also preparing to exit at least 158 counties and cancel 133 Medicare Advantage plans, according to a Modern Healthcare analysis. Modern Healthcare compared the company’s list of available policies for 2027 to the Centers for Medicare and Medicaid Services enrollment file for this month.
      • “The cancellations would drive about a third of Centene’s Medicare Advantage membership, or more than 340,300 enrollees, to shop for new coverage, according to the Modern Healthcare analysis. Members may have alternative Centene plans from which to choose.” 
         
    • The Health Care Cost Institute released a report about the “Effects of vertical integration on providers’ billing and practice patterns in Medicare (2018-2022)”
    • Fierce Healthcare notes,
      • “The blockbuster success of GLP-1 weight loss drugs has caused major ripple effects across healthcare and pharma, representing a significant growth engine for drugmakers but a cost challenge for payers.
      • “GLP-1s are also potentially disrupting a healthcare system built around treating obesity-related complications, forcing providers, insurers and investors to rethink where future revenue and growth will come from, according to a new report from Wells Fargo.
      • “For decades, the healthcare industry has built service lines, reimbursement models and care pathways around the downstream consequences of obesity. Diabetes clinics, cardiology service lines, sleep medicine, orthopedics, bariatric surgery, pharmacy and chronic disease management have all grown inside a system where obesity was widespread, persistent and often untreated.
      • “GLP-1s may be starting to upend that model as the growing use of obesity drugs begins to influence utilization patterns, hospital economics, pharmaceutical R&D and long-term healthcare spending, wrote Robin Wenzel, head of Wells Fargo Industry Insights and John Teasley, market executive, Wells Fargo Healthcare Banking, in the report.
      • “The latest data from the Centers for Disease Control and Prevention and the National Center for Health Statistics indicates that 40.3% of U.S. adults have obesity, and 9.4%, roughly one in ten, have severe obesity. That makes obesity not an outlier, but a baseline condition around which much of U.S. healthcare now operates, the report authors assert.
      • “GLP-1 drugs for weight management move the management of obesity upstream, to prevention in the context of a system designed around late-stage disease. That puts traditional obesity-related service lines, and healthcare’s obesity revenue engine, under pressure, according to the report.”
    • Beckers Hospital Review points out how 14 large health systems performed financially during the three months ended June 30, and tells us,
      • “New CMS data shows emergency department visit times climbed in the vast majority of states compared with the same period last year, though wide variation persists across the country.
      • “The agency’s “Timely and Effective Care” dataset covers children and adults treated at hospitals paid under the Inpatient Prospective Payment System or Outpatient Prospective Payment System, as well as those that voluntarily report data on relevant measures. Data was collected in the 12-month period ending Sept. 30, 2025. Learn more about the methodology here.
      • :Nationwide, the median time patients spent in the ED was 162 minutes for the 12-month period ending September 2025, stable from the same period a year prior, according to CMS data.:
    • Healthcare Dive notes,
      • Name: Dr. Shantanu Nundy
      • Previous title: Executive vice president of care delivery and chief health officer, Accolade
      • New title: Chief medical officer, Humana
      • Nundy will become Humana’s new CMO effective Aug. 31, the Kentucky-based insurer announced Thursday.
      • “He’s replacing Kate Goodrich, who served as CMO from 2022 to October 2025, when she left for a role in the health services division of Humana’s rival insurer UnitedHealth. The CMO post has sat empty since.
      • “As CMO, Nundy will help design Humana’s products, platforms and use of artificial intelligence with a clinical eye, according to the release.”
    • and
      • Name: Arun Kumar Bhaskara-Baba
      • Previous title: Chief information officer, Honeywell Aerospace and Defense
      • New title: Chief information officer, Mayo Clinic
      • “Bhaskara-Baba joined Mayo Clinic as CIO in May, the Minnesota-based health system confirmed in a statement. He’s at the helm of Mayo’s information technology systems across its network of 16 hospitals and 45 multispecialty clinics.
      • “Bhaskara-Baba is succeeding Cris Ross, who retired in 2024 after 12 years in the role.
      • “Bhaskara-Baba brings more than 25 years of tech experience to the role. He joins Mayo from Honeywell Aerospace and Defense, where he directed digital strategy and scaled the company’s artificial intelligence capabilities as CIO.”
    • Fierce Healthcare informs us,
      • “Cityblock Health, a company primarily focused on providing care for urban Medicaid and dual-eligible members, plans to acquire Homeward Health to expand deep into rural markets, the company announced Thursday.
      • “Combined, the two companies will serve nearly 250,000 people and are positioned to reach the 120 million people receiving government-funded healthcare in the U.S., Toyin Ajayi, Cityblock Health CEO and co-founder, wrote in a blog post.
      • “Cityblock said it signed a definitive agreement to acquire Homeward in an all-stock transaction. Financial details of the deal were not disclosed.”
    • and
      • “Carrum Health, a company with value-based Centers of Excellence for employers, is teaming up with Included Health, a virtual care and health navigation company working with employers and plans.
      • “Carrum’s Centers of Excellence network for specialty care will be embedded directly into Included Health’s Alternative Health Plan to help connect members to high-quality specialty care with more predictable costs. The partners will connect plan design, navigation and value-based care into one coordinated experience. 
      • “As employers face steep healthcare cost increases, specialty care often drives a lot of healthcare spending. From 2023 to 2025, the U.S. saw the highest three-year stretch of healthcare cost growth in over a decade, according to the Business Group on Health. The Carrum integration will deliver greater cost predictability with bundled rates, outcomes accountability and streamlined contracting.”
    • Healthcare Dive adds,
      • “Healthcare revenue cycle management company R1 has agreed to acquire Humata Health, a company specializing in artificial intelligence-powered prior authorizations.
      • “R1 is banking that Humata’s AI expertise will help it streamline the preapproval process required by insurers for certain medical treatments, and further its goal of automating how healthcare providers get paid for their services.
      • “The acquisition is expected to close in the third quarter this year, after which Humata’s team will start integrating its technology into R1’s revenue cycle platform. An R1 spokesperson declined to share the financial terms of the deal.”