Columbus Day Holiday Report

Columbus Day Holiday Report

Supplementing yesterday’s Weekend Update

From Washington, DC,

  • The AP reports,
    • “President Donald Trump said Saturday that he has directed the Defense Department to use “all available funds” to ensure U.S. troops are paid Wednesday despite the government shutdown, a short-term fix that will not apply to the hundreds of thousands of federal workers who have been furloughed.
    • “Trump said in a social media post that he was acting because “our Brave Troops will miss the paychecks they are rightfully due on October 15th.”
    • ‘The Republican president’s directive removes one of the pressure points that could have forced Congress into action, likely ensuring that the shutdown — now in its 11th day and counting — extends into a third week and possibly beyond. But no similar action seems forthcoming for federal employees also working without pay while thousands are now being laid off during the lapse in government operations.”
  • Federal News Network tells us,
    • “The number of federal employees filing retirement claims in September was the lowest all year. Just over 6,300 employees submitted their retirement paperwork to the Office of Personnel Management. At the same time, OPM also processed the fewest number of current claims in September, just over 7,900. Despite the lower number of claims, OPM said it took six days longer, on average, in September than in August to process claims. The current retirement claims backlog is at 23,500, which dropped for the fourth straight month.”
  • The Washington Post interviews OPM Director Scott Kupor and others about the coming surge of retirement applications.
  • Per Beckers Payer Issues,
    • “The No Surprises Act is succeeding in protecting patients from unexpected medical bills, but insurers and provider groups remain divided on what is driving rising costs tied to the Independent Dispute Resolution process and how regulators should respond.
    • “Since the arbitration system launched in 2022, providers have won the vast majority of disputes. In 2024, they prevailed in about 85% of cases, with median payment determinations reaching 459% of the qualifying payment amount in the fourth quarter. The process has also generated at least $5 billion in costs, much of it from administrative fees and higher payments.
    • “As those costs have climbed, payers have said that the system is inflating prices across the healthcare system, while providers say it is correcting years of underpayment.
    • “The concern now is that the law hasn’t met its second objective, to contain costs,” Jennifer Jones, senior director of legislative and regulatory policy at the Blue Cross Blue Shield Association, told Becker’s. “That’s primarily because of the challenges we’re seeing with the independent dispute resolution process.”
  • The FEHBlog agrees with Ms. Jones.

From the public health and medical / Rx research front,

  • MedPage Today informs us,
    • “Among older adults who received at least one dose of the recombinant shingles vaccine, vaccine effectiveness against any herpes zoster-related outcome was 56.1%.
    • “Getting a second dose yielded a relative vaccine effectiveness of 67.9% against any herpes zoster outcome.
    • “The findings emphasize the importance of completing the full vaccination series.”
  • The Washington Post reports,
    • “The tendency to use cannabis is associated with genes linked to impulsive behavior, obesity, schizophrenia and bipolar disorder, among other traits, according to a study released Monday by researchers at the University of California at San Diego.
    • “The research, published in the journal Molecular Psychiatry, explored the genetic traits of casual and frequent cannabis users in hopes of eventually identifying medications and other therapies to treat or prevent problematic marijuana use.
    • “The study adds to a growing body of genetics research into cannabis use as policymakers and researchers weigh how to balance the benefits and consequences of the drug’s growing popularity.”

From the U.S. healthcare business front,

  • Beckers Hospital Review relates,
    • “Many nonprofit hospitals and health systems have made steady progress on financial turnarounds since the end of the COVID-19 pandemic — though others continue to struggle — but new and persistent challenges threaten to derail those efforts.
    • “Operating margins have inched upward across the sector, yet most remain far below the pre-pandemic “magic number” of 3%. The latest data from Strata Decision Technology shows that health system margins improved slightly to 1% in August, up from 0.9% in July, but remain relatively unchanged for the year. 
    • “While operating revenue has generally increased, it continues to be offset by rising costs — particularly in non-labor categories (such as supply and drug costs), which rose 5.7% year over year compared to a 4.6% rise in labor expenses.
    • “These pressures could intensify in the months ahead.” 
  • Beckers Payer Issues adds,
    • “When a critical patient’s prognosis is unclear, often because they are unable to wean from the ventilator, care teams begin to discuss palliative care, advance care planning, and even hospice.  Making decisions about long-term care goals can be challenging for patients and their families as they navigate the complexities of their conditions. Discussions often take place over many days while patients and families evaluate the options.  Including long-term-acute care hospital (LTACH) referral in these discussions benefits the patient for three reasons [explained in the article].

Weekend update

From Washington, DC

  • As the FEHBlog noted on Friday, the Senate will be in session this week, but not the House of Representatives. There is only one Senate committee meeting scheduled for this week. The Senate press gallery adds,
    • “The Senate stands adjourned until 3:00 p.m. on Tuesday, October 14th. At that time, following any Leader remarks, the Senate will be in a period of Morning Business.
    • “At approximately 5:30 p.m., the Senate will vote on cloture on the motion to proceed to H.R.5371; House passed Continuing Resolution.
    • “Further votes are possible.”
  • The Wall Street Journal reports,
    • “The Trump administration is attempting to retain some CDC staffers after initially notifying them of layoffs on Friday.
    • “The National Public Health Coalition estimated 1,300 CDC workers were laid off, with about 700 rehired on Saturday.
    • “The White House initiated mass layoffs across the government last week.”
  • STAT News tells us,
    • “Centers for Disease Control and Prevention staff behind the agency’s flagship publication had suffered deep cuts as part of the firings the Health and Human Services Department has blamed on the government shutdown, according to five people familiar with the situation. But as of Saturday evening, the terminations appeared to have been rescinded.
    • “An HHS official, speaking on condition of anonymity, said workers who produce Morbidity and Mortality Weekly Report may have mistakenly received reduction-in-force notices because of coding errors in their job classifications.”

From the public health and medical / Rx research front,

  • The New York Times identifies the cost common signs of a heart attack and explains that those signs aren’t all sudden or intense according to experts.
    • “I had a relative who experienced chest pain one afternoon. He brushed it off and said that he’d sleep on it and that if he still felt lousy, he’d go to the hospital the next day.
    • “He died of a heart attack that night.
    • “Dr. Donald Lloyd-Jones, a professor of cardiology at Boston University Chobanian & Avedisian School of Medicine, told me he understood why someone would hesitate to go to the emergency room.
    • “It’s “a very human thing” to assume you’re overreacting, he said. “You don’t want to cry wolf.”
    • “But acting quickly when you have symptoms of a heart attack is critical. They happen when blood flow to your heart is cut off or reduced. Without blood flow, the affected heart muscle will begin to die. And any delay in getting care can cause irreversible damage, said Dr. Seth Martin, a cardiologist at Johns Hopkins Medicine.”
  • MedPage informs us,
    • “Cardiovascular (CV) disease is the primary cause of maternal morbidity and mortality, but study did not find statistically significant links between adolescent heart health with later pregnancy outcomes.
    • “Participants with optimal CV health in both adolescence and young adulthood had the lowest incidence of gestational diabetes and hypertension and hypertensive disorders of pregnancy.
    • “Expert says study could still offer insight into how heart health trajectories impact pregnancy.
  • Per Medscape Today,
    • “The GLP-1 receptor agonist tirzepatide confers the same benefit in women as it does in men with obesity-related heart failure with preserved ejection fraction (HFpEF), according to a new analysis from the SUMMIT trial.
    • “Results from the randomized study also showed that women with obesity-related HFpEF had higher risk factors for worse outcomes than men with HFpEF, including greater adiposity, more severe symptoms, and poorer exercise capacity. The same trial found that women also had reduced risk with lower left ventricular mass and paracardiac fat deposition than men.
    • “We know that there are important sex differences in the heart and the vasculature in patients with HFpEF,” investigator Barry Borlaug, MD, a cardiologist at Mayo Clinic in Rochester, Minnesota, said during a late-breaking clinical research session at the Heart Failure Society of America (HFSA) 2025 Annual Scientific Meeting.”
  • BioPharma Dive points out,
    • “Each year, a small number of babies are born mostly, if not fully, deaf because one of their genes isn’t working.
    • “The gene normally makes a protein that the hairs in our inner ears need to relay sound signals to the brain. Without that protein, people with this rare form of hearing loss often rely on cochlear implants for their entire lives.
    • “But in the near future, genetic medicine may offer another option. On Sunday, fresh results from a small clinical trial showed that, among a dozen children given a gene therapy from Regeneron Pharmaceuticals, most are now hearing well enough to not need help from implants.
    • ‘Encouraged by those results, Regeneron plans to submit an approval filing to the Food and Drug Administration by the end of the year.”

From the U.S. healthcare business front,

  • HR Dive reports,
    • “The majority (77%) of employees surveyed by Voya Financial said they plan to spend more time re-assessing their benefit elections during open enrollment this year — up from 69% last year.
    • “Likewise, 63% of Americans surveyed told the firm they “strongly agree” or “agree” that their financial stability has a direct impact on their mental health — up from 57% over the past two years.
    • “Voya researchers noted that workers may benefit from more education about retirement in particular, with only about half of workers feeling “very” or “somewhat” prepared for retirement.”
  • The Wall Street Journal relates,
    • “Some 25% of U.S. employers with 200 or more employees offered menopause-related benefits in 2025, an increase of 10 percentage points from 2023.
    • ‘The annual cost of missed work due to menopause-related symptoms in the U.S. is estimated at $1.8 billion.
    • “Rhode Island became the first state to mandate reasonable workplace accommodations for employees experiencing menopause-related symptoms.”
  • Medical Economics lets us know where physician pay satisfaction is highest in the U.S.
  • Per Fierce Healhcare,
    • “Between 2012 and 2023, registered nurses’ inflation-adjusted wages grew at a slower rate than other support and billed-for healthcare occupations, a review of Bureau of Labor Statistics data on millions of workers found.
    • “The “fairly flat” 0.51% annual growth for RNs, the nation’s largest clinical workforce, across all employment settings came amid the industry’s broad demand for these types of admissions, researchers wrote in the study published this week.
    • “At the same time, the increases were greater for lower-paid support positions like licensed practical nurses (LPNs; 0.79% growth per year) and nurse assistants (NAs; 1.41% growth per year).
    • “That trend may suggest healthcare employers looking to check spending are prioritizing lower-paid roles, they wrote. By 2023, average annual wages for RNs were $94,480, compared to $60,790 for LPNs and $39,610 for NAs.
    • “Although hiring NAs and LPNs instead of RNs could cut costs initially, this could translate to worsening patient outcomes and higher overall expenses for health care organizations, as these workers may lack the training or scope of practice to manage more complex care needs,” researchers from the University of Michigan, Yale University and Johns Hopkins University wrote in Health Affairs.”
  • Modern Healthcare reports,
    • Humana is taking another step to limit its exposure to the volatile Medicare market.
    • “The health insurance company will remove all of its Medicare Part D prescription drug plans from enrollment portals for brokers and other third-party marketers on Nov. 9, it announced Friday.
    • “As we approach this year’s annual enrollment period, we are notifying you that Humana has made the difficult decision to not use agents to sell our prescription drug plans,” Humana wrote in a notice emailed to marketers. The Medicare annual enrollment period begins next Wednesday and runs until Dec. 7.”
  • and
    • “Hackensack Meridian Health is ramping up its Amazon One Medical partnership to expand primary care as part of its outpatient push. 
    • “The Edison, New Jersey-based health system is set to open its third One Medical facility in the second quarter of next year, Hackensack CEO Bob Garrett said. Hackensack initially aimed to open 20 clinics over 10 years but plans to move faster and expand that target given the partnership’s success, he said.
    • Amazon in 2023 acquired virtual and brick-and-mortar primary care service provider One Medical for $3.9 billion. Amazon has since partnered with health systems across the country to grow the subscription-based model for commercially insured patients, helping boost systems’ specialty care referrals.”

Cybersecurity Saturday

From the cybersecurity policy and law enforcement front.

  • Cyberscoop tells us,
    • “A top Senate Democrat introduced legislation Thursday to extend and rename an expired information-sharing law, and make it retroactive to cover the lapse that began Oct. 1.
    • “Michigan Sen. Gary Peters, the ranking member of the Homeland Security and Governmental Affairs Committee, introduced the Protecting America from Cyber Threats (PACT) Act, to replace the expired Cybersecurity and Information Sharing Act of 2015 (CISA 2015) that has provided liability protections for organizations that share cyber threat data with each other and the federal government. Industry groups and cyber professionals have called those protections vital, sometimes describing the 2015 law as the most successful cyber legislation ever passed.
    • “The 2015 law shares an acronym with the Cybersecurity and Infrastructure Security Agency, which some Republicans — including the chairman of Peters’ panel, Rand Paul of Kentucky — have accused of engaging in social media censorship. As CISA 2015 has lapsed and Peters has tried to renew it, “some people think that’s a reauthorization of the agency,” Peters told reporters Thursday in explaining the new bill name.” * * *
    • “Michael Daniel, leader of the Cyber Threat Alliance made up of cybersecurity companies, told CyberScoop that his organization hasn’t been affected by the lapse yet, but that’s partially because it’s an organization that was set up with the long term in mind, with a formalized structure that included information-sharing requirements for members.
    • “The lapse might also not immediately affect other organizations, he said, comparing it to the risks of the government shutdown underway.
    • “An hour-long lapse doesn’t really do very much, but the longer it goes on, the more you have time for organizations to say, ‘Well, maybe we need to reconsider what we’re doing, maybe we need to think about it differently,’” Daniel said. “The longer it goes on, you start having questions about, ‘Maybe this thing won’t get reauthorized down the road.’ And once you start questioning the long-term prospects, that’s when people start making changes in their behavior.”
  • The American Hospital Association News (“AHA”) informs us,
    • “The Health Sector Coordinating Council Oct. 7 released its Sector Mapping and Risk Toolkit, created to help health care providers and other organizations visualize key services that support essential health care workflows and determine which of them present critical risk of cyberattack disruption capable of impacting care delivery, operations and liquidity. The toolkit consists of 17 health care workflow maps and usage guidelines and encourages organizations to prioritize their risks, mitigate them where possible and develop recovery and continuity plans that cannot be controlled or mitigated.
    • “The SMART initiative was created in April 2024 as a response to the cyberattack on Change Healthcare two months earlier. The AHA contributed the development of this project, which has helped identify these systemically important, mission-critical services for health care.”
  • AHA President and CEO Rick Pollack writes in the AHA News about his thoughts on this Cybersecurity Awareness Month.
    • “This week, the FBI issued an urgent warning to all users — including hospitals — of a critical security soft spot within Oracle’s E-Business Suite, stating “This is ‘stop-what-you’re-doing and patch immediately vulnerability.’”
    • “The vulnerability has allowed cyber bad actors to carry out data theft ransomware attacks. Oracle is offering a patch to address the security problem.
    • “This latest threat reminds us that cybercrime is ever-present, and health care has been the No. 1 target for years. Hospitals and health systems are committed to taking every possible precaution to protect system operability and patients’ personal data, and the good news is their defenses block most attacks.
    • “But no individual hospital can defend against all of these very sophisticated criminal and nation-state sponsored attacks. That’s why we need a whole-of-government approach to preventing and mitigating cyberattacks, including the federal government going after the bad guys as it has effectively done in counterterrorism.
    • “As we observe Cybersecurity Awareness Month this October, we must remain aware that the scope, frequency and sophistication of cyber incursions into health care have increased steadily. The evolving tactics used by bad actors to steal information, encrypt systems, delay and disrupt patient care, and shut down vital systems continue to put patient care and safety at risk.”
  • Dark Reading adds,
    • “Last night [October 9, 2025], the FBI, in coordination with law enforcement in France, seized the latest version of the BreachForums’ underground forum domain, which was converted earlier this month into an extortion site used by Scattered Lapsus$ Hunters, the gang behind the recent high-profile spate of Salesforce data heists.
    • Scattered Lapsus$ Hunters is an apparent combination of the Scattered Spider, Lapsus$, and ShinyHunters cybercriminal groups that first emerged this past summer. It has been busy compromising Salesforce data and claims that Salesforce victims have up until midnight Eastern Time today, Oct. 10, to meet its ransom demands before it will start publishing the stolen records. 
    • “Despite the BreachForums site being taken down, the group’s Tor Dark Web site is still accessible, and will be used to leak the data, the threat actors claimed.
    • “Aside from Salesforce data, Scattered Lapsus$ Hunters claims to have 1 billion records and 39 victim organizations listed on the site with sample data, such as Chanel, Disney and Hulu, Marriot, Google, Toyota, FedEx, and many more.
    • “For its part, Salesforce has issued its own statement, acknowledging the extortion attempts and reiterating that there is no indication that the Salesforce platform itself had been compromised.”

From the cybersecurity vulnerabilities and breaches front,

  • Cyberscoop reports,
    • “A brute-force attack exposed firewall configuration files of every SonicWall customer who used the company’s cloud backup service, the besieged vendor said Wednesday.
    • “An investigation aided by Mandiant confirmed the totality of compromise that occurred when unidentified attackers hit a customer-facing system of SonicWall controls. The company previously said less than 5% of its firewall install base stored backup firewall configuration files in the cloud-based service.
    • “SonicWall did not answer questions about the extent to which the investigation revealed a more widespread impact for its customers, or if its assessment of that 5% figure remained accurate. The company initially revised its disclosure to clarify the scope of exposure was less than 5% of firewalls as of Sept. 17 but has since removed that detail from the blog post. 
    • “The investigation confirmed that an unauthorized party accessed firewall configuration backup files for all customers who have used SonicWall’s cloud backup service,” the company said in a statement.” * * *
    • “Fourteen defects affecting the vendor’s products have been added to the Cybersecurity and Infrastructure Security Agency’s known exploited vulnerabilities (KEV) catalog since late 2021. Nine of those defects are known to be used in ransomware campaigns, according to CISA, including a wave of about 40 Akira ransomware attacks between mid-July and early August.
    • “While those attacks were linked to exploited vulnerabilities in SonicWall devices, the latest attack marked a direct hit on SonicWall’s internal infrastructure and practices.”
  • Security Week tells us,
    • Law firm Williams & Connolly said state-sponsored hackers breached some of its systems and gained access to attorney email accounts.
    • “The prominent Washington, DC-based law firm is known for representing political figures and government officials, including Barack Obama and the Clintons, as well as major companies such as Intel, Samsung, Google, Disney, and Bank of America. 
    • “According to a statement issued by the company, an investigation conducted with the assistance of CrowdStrike showed that the hackers exploited an unspecified zero-day vulnerability to gain access to a “small number” of attorneys’ email accounts. 
    • “The probe showed that the attack was likely the work of a state-sponsored hacker group known to have recently targeted law firms and other companies. 
    • “Williams & Connolly said there was no evidence that confidential client data was stolen or that other parts of its IT system had been compromised. 
    • “While the company’s statement does not mention China, The New York Times learned that Chinese hackers targeted Williams & Connolly, along with other law firms.”
  • The Cybersecurity and Infrastructure Security Agency (CISA) added nine known exploited vulnerabilities to its catalog this week.
  • Per Bleeping Computer,
    • “Threat actors are exploiting a zero-day vulnerability (CVE-2025-11371) in Gladinet CentreStack and Triofox products, which allows a local attacker to access system files without authentication.
    • “At least three companies have been targeted so far. Although a patch is not yet available, customers can apply mitigations.
    • “CentreStack and Triofox are Gladinet’s business solutions for file sharing and remote access that allow using a company’s own storage as a cloud. According to the vendor, CentreStack “is used by thousands of businesses from over 49 countries.”
  • Cardiovascular Business relates,
    • “The U.S. Food and Drug Administration (FDA) has announced another new recall for Johnson & Johnson MedTech’s Automated Impella Controller (AIC) due to a significant cybersecurity risk. 
    • “If the identified cybersecurity vulnerabilities are exploited, it may affect the essential performance of the AIC,” according to the FDA’s advisory.
    • “At this time, no cyberattacks have been tied to this specific issue. This is the fourth time in three months the FDA has shared serious safety concerns related to these devices, which serve as the primary user control interface for Impella catheters.” 
  • Per Cybersecurity Dive,
    • “AI isn’t yet transforming how hackers launch phishing attacks, although it is helping them clean up their lures, the security firm Intel 471 said in a report published on Wednesday.
    • “Several factors have combined to keep AI in an evolutionary rather than revolutionary role, the report found.
    • “Still, business and government leaders need to pay attention to several increasingly common AI-assisted attack strategies.”

From the ransomware front,

  • Sophos shares its 2025 report on the state of ransomware in healthcare.
    • “Sophos’ latest annual study explores the real-world ransomware experiences of 292 healthcare providers hit by ransomware in the past year. The report examines how the causes and consequences of these attacks have evolved over time. This year’s edition also sheds new light on previously unexplored areas, including the organizational factors that left providers exposed and the human toll ransomware takes on retail IT and cybersecurity teams.”
  • TRM Labs point out “Nine Emerging Groups Shaping the Ransomware Landscape.”
    • “Artificial intelligence (AI) has lowered the barrier to entry for cybercriminals, allowing ransomware threat actors to automate coding, generate polymorphic malware — which alters its code with each infection to evade detection — and create more convincing social engineering lures. As a result, new groups are emerging rapidly, and established groups are scaling their operations. 
    • “In this post, we take a closer look at nine emerging ransomware groups and examine how their off-chain and on-chain tactics are reshaping the ecosystem.”
  • The Hacker News relates,
    • “Three prominent ransomware groups DragonForceLockBit, and Qilin have announced a new strategic ransomware alliance, once underscoring continued shifts in the cyber threat landscape.
    • “The coalition is seen as an attempt on the part of the financially motivated threat actors to conduct more effective ransomware attacks, ReliaQuest said in a report shared with The Hacker News.
    • “Announced shortly after LockBit’s return, the collaboration is expected to facilitate the sharing of techniques, resources, and infrastructure, strengthening each group’s operational capabilities,” the company noted in its ransomware report for Q3 2025.
    • “This alliance could help restore LockBit’s reputation among affiliates following last year’s takedown, potentially triggering a surge in attacks on critical infrastructure and expanding the threat to sectors previously considered low risk.”
  • Per Cyberscoop,
    • “Microsoft Threat Intelligence said a cybercriminal group it tracks as Storm-1175 has exploited a maximum-severity vulnerability in GoAnywhere MFT to initiate multi-stage attacks including ransomware. Researchers observed the malicious activity Sept. 11, Microsoft said in a blog post Monday.
    • “Microsoft’s research adds another substantive chunk of evidence to a growing collection of intelligence confirming the defect in Fortra’s file-transfer service was exploited as a zero-day before the company disclosed and patched CVE-2025-10035 on Sept. 18.
    • ‘Despite this mounting pile of evidence, Fortra has yet to confirm the vulnerability is under active exploitation. The company has not answered questions or provided additional information since it updated its security advisory Sept. 18 to include indicators of compromise. 
    • “Storm-1175, a financially motivated cybercrime group known for exploiting public vulnerabilities to gain access and deploy Medusa ransomware, exploited CVE-2025-10035 to achieve remote code execution, according to Microsoft.”
  • Per Dark Reading,
    • “A China-based threat group known as Storm-2603 has added a new weapon to its hacking arsenal.
    • “Cisco Talos researchers observed Storm-2603 abusing Velociraptor, an open-source digital forensics and incident response (DFIR) tool, in a recent ransomware attack. The open-source project, which was acquired by Rapid7 in 2021, was designed by security researcher Michael Cohen to assist incident response teams with endpoint monitoring and investigations. However, it seems attackers have turned the tables on defenders and are now leveraging Velociraptor to conceal their malicious activity.”
    • “Storm-2603 initially burst on to the threat landscape in July as one of several threat groups exploiting a set of SharePoint vulnerabilities in an attack chain known as “ToolShell.” There, the threat actors gained access to SharePoint servers, moved laterally in the victims’ networks, and deployed Warlock ransomware. In a blog post published Thursday, Cisco Talos researchers said they responded to a different incident in August, in which threat actors dropped three different types of ransomware on the victim’s VMware ESXi servers — Warlock, LockBit, and Babuk — and caused severe disruption to the organization.
    • “In addition to the ransomware trio, Cisco Talos found Storm-2603 actors had also deployed Velociraptor to aid their attack. It was a shift in strategy; the researchers noted that the tool had not been definitively tied to ransomware attacks prior to August.”
  • and
    • “Chaos ransomware has gotten a significant facelift with an “aggressive” new variant that adds destructive tactics and clipboard hijacking for cryptocurrency theft, as well as other capabilities to bolster its operations for speed and effectiveness.
    • “Researchers from FortiGuard Labs have identified a new version of Chaos ransomware written in C++, the first not written in .NET, they revealed in a report published Wednesday. This evolution also introduces a host of new features that make the ransomware harder to disrupt once it’s in execution, as well as more destructive than previous versions.
    • “This evolution underscores Chaos’s shift toward more aggressive methods, amplifying both its operational impact and the financial risk it poses to victims,” FortiGuard researcher Yen-Ting Lee wrote in the report.”

From the cybersecurity defenses front,

  • Cybersecurity Dive reports,
    • “Managing cyber risk has become a point of emphasis in the insurance and asset management sector, with companies boosting annual expenditures and increasing oversight at the board level, according to a report released Wednesday by Moody’s.
    • “Almost seven of every 10 companies have a chief information security officer overseeing corporate cyber risk, while another 10% of companies have a chief information officer overseeing cybersecurity. 
    • “More than 95% of organizations have their CISOs provide briefings directly to the chief executive officer at least on a semiannual basis. This compared with 88% using that practice in 2023.
    • “In addition, seven of 10 companies have their CISO brief the corporate board of directors, at least on a semiannual basis. This compares with 54% in 2023. Four of every 10 companies link CEO compensation to the company’s cybersecurity performance, a sharp increase from just 24% in 2023.” 
  • The Wall Street Journal adds,
    • “Security chiefs are emerging as sought-after advisers as companies plunge headlong into artificial intelligence.
    • “Although the rising threat of cyberattacks has elevated the role of chief information security officers in recent years, some say they are appearing more frequently before their boards and senior executives to help unpack the risks associated with AI.
    • “Often jokingly referred to as the “Department of No” inside companies, security staff are now being actively consulted on AI implementations. This includes explaining risks to management and collaborating with other parts of the business that haven’t typically worked closely with cybersecurity.
    • “Security was always thought of as the boat anchor; what I want is to be the boat motor,” said Pablo De La Rosa, vice president of information security at electric vehicle infrastructure specialist Vontier.”
  • Dark Reading discusses the cyber-risks associated with AI note takers. “Transcription applications are joining your online meetings. Here’s how to create policies for ensuring compliance and security of your information.”
  • Security Week notes,
    • “Google has several projects focusing on the use of AI for the discovery of vulnerabilities in software. The tech giant recently reported that its Big Sleep agent discovered a critical SQLite vulnerability and thwarted efforts to exploit it in the wild.
    • “Its latest product is CodeMender, an AI agent that not only finds security holes but also patches them. The company argues that such tools are needed because as AI gets better at discovering flaws, it will be difficult for humans to keep up with patching.” 
  • Here is a link to Dark Reading’s CISO Corner.

Friday report

From Washington DC,

  • Here is a link to today’s Secrets of OPM blog post by OPM Director Scott Kupor.
  • Here are links to Fedweek and Fedsmith articles about OPM’s 2026 government contribution announcement made yesterday.
  • Yesterday, the FEHBlog posted the Internal Revenues Service’s 2026 inflation adjusted amounts.
    • The Wall Street Journal discusses how the adjustments impact federal income taxation.
    • Newfront discusses how the adjustments impact employee benefits.
  • Healthcare Dive notes,
    • “Average Medicare Advantage star ratings for 2026 are essentially flat after a few consecutive years of declines — a good sign for the industry, which had braced itself for lower quality scores.
    • “Still, there was variation in major insurers’ results. The percentage of members in plans rated 4 stars or above, an important cutoff for payers, stayed stable for UnitedHealthcare, dropped for Humana and Aetna, and improved for Elevance and Centene — the five largest publicly traded payers in the privatized Medicare program.
    • “Perhaps the biggest loser is Clover Health. The insurer’s largest contract covering almost all of its MA members dropped below 4 stars — a slip that could cost Clover tens of millions of dollars in earnings, analysts estimate.”
  • The American Hospital Association News tells us,
    • “The federal government shutdown is expected to continue into next week as the Senate adjourned Oct. 9 after failing to pass spending legislation; senators plan to return Oct. 14. Meanwhile, the House currently has no plans to return to session next week. The Senate Oct. 9 failed to adopt the House-passed continuing resolution to fund the government following a seventh vote on the bill. Senate Republicans and Democrats have yet to begin formal negotiations toward a deal.”
  • Federal News Network points out,
    • “Hundreds of thousands of federal employees are set to receive reduced paychecks, now on day 10 of the partial government shutdown.
    • “While most civilian federal employees are expected to get their paychecks sometime in the next couple days, they’ll only take home the pay they earned up until the shutdown began. Regardless of whether they are excepted or furloughed, federal employees will not be paid for any days worked between Oct. 1 and Oct. 4 — the final few days of the most recent two-week pay period.
    • “With the partial paychecks, many federal employees will lose out on hundreds of dollars. The exact timing of when employees receive their paychecks depends on their agency, but many began going out Friday.
    • “It’s also the last paycheck excepted and furloughed employees will receive until the government shutdown ends. The first fully missed paycheck, if the shutdown continues, will be for the pay period of Oct. 5 through Oct. 18. Only federal employees who are considered “exempt” from the shutdown will continue to be paid as usual.”
  • Roll Call reports,
    • ​”The Trump administration made good on its threat to begin mass firings of federal civilian employees Friday while exploring creative avenues to make sure military personnel don’t miss their paychecks slotted to go out next week.
    • “With no end in sight to the partial government shutdown that began 10 days ago, White House budget director Russ Vought announced on X that he has begun executing mass layoffs across federal agencies.
    • “An Office of Management and Budget official said the layoffs are “substantial,” without elaborating. Details began trickling out ahead of a court-ordered deadline by close of business Friday, however, hitting numerous agencies including Treasury, EPA, Homeland Security, Education, and Housing and Urban Development, among others.
    • “Speaker Mike Johnson, R-La., meanwhile, officially canceled votes in the House next week, meaning there is virtually no chance that Congress could pass a stand-alone bill to provide pay to some 2 million troops whose next paycheck is due Oct. 15.
    • “But in keeping with President Donald Trump’s pledges to “take care of” the military while punishing “Democrat agencies,” his administration is looking at how to make sure the troops are kept whole financially. A senior White House official said the administration is “exploring every legal maneuver and option at our disposal to get our troops paid during the Democrat Shutdown.” 
  • STAT News informs us,
    • “The Senate on Thursday passed legislation that would restrict U.S. pharmaceutical and biotechnology companies from doing business with certain Chinese companies, potentially giving the president another way to pressure the industry into doing what he wants. 
    • “The BIOSECURE Act, which was passed as an amendment to the National Defense Authorization Act, has been a long time coming. A more aggressive version of the bill was introduced in the Senate in December 2023. The House proposed similar legislation the next month.
    • “BIOSECURE is not over the finish line yet, but it’s significant that the Senate included it in the National Defense Authorization Act, because the defense budget bill has passed every year for decades. The House passed its version of the defense bill earlier in the year without the BIOSECURE Act, so the two chambers would need to agree to include BIOSECURE in the final version of the defense budget bill when reconciling differences between their versions of it.”
  • The AHA News adds,
    • “The AHA discussed ways hospitals and health systems are leveraging artificial intelligence for care delivery in a statement submitted to the Senate Committee on Health, Education, Labor and Pensions for a hearing held Oct. 9 titled, “AI’s Potential to Support Patients, Workers, Children, and Families.” The AHA highlighted examples of AI applications in hospitals, such as diagnostic imaging, ambient listening tools and scheduling for patients and staff.
    • “Hospitals recognize that AI tools hold tremendous promise to alleviate administrative burden and enhance clinical care,” the AHA wrote. “Among other benefits, these innovations can improve workflow, enhance the overall patient experience by reducing wait times and support timely medical interventions.”
    • “The AHA also discussed potential risks of AI in health care, such as commercial insurers using it to determine disposition of claims and prior authorizations, which has exacerbated inappropriate denials. The AHA advocated for the use of clinicians to independently review care recommendations.”
  • The University of Minnesota’s CIDRAP relates,
    • “A federal vaccine advisory group has established a panel to review the safety and efficacy of the childhood immunization schedule, according to a document posted yesterday on the Centers for Disease Control and Prevention (CDC) website.
    • “The Childhood and Adolescent Immunization Schedule Workgroup (WG), established within the CDC’s Advisory Committee on Immunization Practices (ACIP), will review data and “clinical and scientific knowledge” and present its findings to help ACIP members make policy recommendations. 
    • “As part of ACIP’s core mission to develop recommendations on the use of vaccines in the civilian population of the United States, the committee is standing up a WG focused on assessing the safety and effectiveness of the childhood and adolescent schedule,” the document states.
    • “Among the topics the group will review are the timing and order of different childhood vaccines, administering different vaccines at the same time, the safety of certain vaccine ingredients, and the different childhood vaccine schedules used in other countries.”

From the Food and Drug Administration front,

  • Cardiovascular Business informs us,
    • “The U.S. Food and Drug Administration (FDA) has approved another new treatment option for heart-failure related edema. 
    • “Just weeks after its approval of bumetanide nasal spray for the treating edema associated with congestive heart failure, kidney disease and liver disease, the agency has given the greenlight to Lasix ONYU, a new drug-device combination from SQ Innovation, for adult patients with chronic heart failure. 
    • “Lasix ONYU provides patients with injections of a high-concentration formulation of furosemide. The injections are delivered with a small two-in-one device. While the base of the device is reusable, only to be replaced after 48 treatments, the other part of the device is used once and then discarded. According to SQ Innovation, this new-look design helps ensure the delivery device can be manufactured at a low enough price point so the treatment remains affordable.
    • “In one recent analysis published in European Heart Journal – Cardiovascular Pharmacotherapy, researchers found that the Lasix ONYU technology was linked to a bioavailability similar to receiving furosemide through an IV. Treatment was also confirmed to be “feasible and well tolerated.”

From the. public health and medical / Rx research front,

  • The Centers for Disease Control and Prevention is not updating its respiratory illnesses data channel during the shutdown.
  • Dr. Tom Friden, a former CDC Director, writes in the Wall Street Journal about the simple steps that can prevent dementia.
    • “When it comes to healthy aging, personal responsibility matters. But American healthcare also suffers from systemic failures. Despite spending more than $4 trillion annually, we get the most important things, such as blood pressure control, right at most half the time. Our system doesn’t incentivize doctors to deliver the preventive care that matters most. For instance, they are paid little or nothing for making an effort to control a patient’s blood pressure.
    • “The tools for a healthy, dementia-free future exist: blood pressure control, appropriate statin and other therapy, smoking prevention and cessation support, and comprehensive primary care focused on prevention. We need a healthcare system that delivers them reliably, for all our sakes.”
  • Per Health Day,
    • “Heart-related health problems might affect as many as 1 in 7 pregnancies, even among women without any prior heart disease, a new study says.
    • “Researchers found a steady increase in heart-related health problems among more than 56,000 pregnancies between 2001 and 2019 in New England.
    • “Heart attack, stroke, heart failure, blood clots, high blood pressure and heart-related maternal death affected about 15% of pregnancies during that time, researchers reported Oct. 6 in the journal Circulation.
    • “Our findings showcase an alarming trend of rising real-world burden of pregnancy-related cardiovascular complications and highlights pregnancy from preconception to the postpartum period as a crucial window of opportunity to implement primary prevention strategies and optimize cardiovascular health,” concluded a team led by Dr. Emily Lau, a cardiologist at Massachusetts General Hospital in Boston.”
  • Per MedPage Today,
    • “New-onset atrial fibrillation (Afib or AF) was surprisingly common after coronary artery bypass grafting (CABG), but its burden quickly diminished to near zero after 30 days, according to long-term continuous ECG monitoring data.
    • “With a monitor implanted during surgery, patients at two German centers showed a 48% incidence of new-onset Afib in the first year after CABG, with a median Afib burden of 0.07% (or 370 minutes).
    • “It turned out that on days 1-7, the median Afib burden was 3.65% (368 minutes), dropping quickly thereafter to 0.04% (13 minutes) on days 8-30 and 0% (0 minutes) on days 31-365, according to researchers led by Florian Herrmann, MD, of LMU University Hospital in Munich, Germany.
    • “Although the incidence of new-onset AF after CABG in this study was higher than previously reported, the AF burden in these patients was very low, especially after 30 days,” the authors reported in JAMA.
    • “This low burden calls into question whether long-term oral anticoagulation is necessary in patients with new-onset AF after CABG. The very low burden provides a likely explanation for why observational studies have failed to demonstrate reduced stroke rates with oral anticoagulation in this patient group,” Herrmann’s group suggested.”
  • Per the American Journal of Managed Care,
    • “A smartphone app significantly reduced depressive symptoms and improved self-esteem and quality of life in individuals with intellectual disabilities.
    • “The study addressed a research gap, highlighting the app’s potential as an accessible mental health intervention for an underserved population.
    • “Limitations include self-reported data, potential bias, and lack of long-term follow-up, affecting the generalizability of results.
    • “Future research should explore optimal app use, caregiver involvement, and accessibility barriers to enhance mental health support for individuals with IDs.”

From the U.S. healthcare business front,

  • The Wall Street Journal reports,
    • AstraZeneca is the latest major drugmaker to agree to a deal with the Trump administration on lowering the prices of its drugs, some of which will be available for purchase through a government website next year, President Trump said Friday. 
    • “The agreement, which entails offering “most-favored nation” drug pricing, follows Pfizer’s deal to reduce prices for its drugs sold in the Medicaid program and through a new direct-purchasing service to be branded TrumpRx.
    • “AstraZeneca will similarly offer all prescription drugs on the government website, TrumpRx, which the administration said it will launch in 2026, said Mehmet Oz, administrator for the Centers for Medicare & Medicaid Services.
    • “In addition to the lower drug prices for people on Medicaid, all new AstraZeneca drugs introduced to the market will be launched at most-favored nation pricing, which is tied to comparable prices in other wealthy nations.” 
  • Reuters adds,
    • “Retail pharmacies and prescription drug savings site GoodRx (GDRX.O)
      are talking with the Trump administration about joining its TrumpRx website, they told Reuters, suggesting an expansion beyond the early description of it as a link to pharmaceutical companies’ direct discounts.” * * *
    • “The National Community Pharmacists Association and the National Association of Chain Drug Stores, which represent companies like Walgreens and Costco (COST.O), said they were also talking with administration officials.”
  • The Wall Street Journal also lets us know,
    • Johnson & Johnson JNJ is in talks to buy Protagonist Therapeutics in a deal that would solidify the companies’ existing partnership, according to people familiar with the matter.
    • “A deal is not guaranteed and the exact details being discussed couldn’t be learned, the people said. 
    • “Protagonist had a market value of over $4 billion as of Thursday’s close. Including a typical premium, a deal would likely value the company well above that. 
    • “”J&J is already working with Protagonist to develop an oral treatment for immune diseases including plaque psoriasis and ulcerative colitis and has the exclusive rights to commercialize the product. It already owns close to 4% of Protagonist’s shares, according to FactSet.
    • “By acquiring Protagonist, the healthcare conglomerate would also gain access to the drug rusfertide, from Protagonist and partner Takeda Pharmaceutical4502 -2.63%decrease; red down pointing triangle. Rusfertide has shown promise in late-stage testing in treating a rare blood cancer called polycythemia vera. 
    • “Both assets would complement J&J’s portfolio of immune and cancer drugs.” 
  • Per BioPharma Dive,
    • “Bristol Myers Squibb is joining big pharma’s rush into “in vivo” cell therapies, paying $1.5 billion to acquire Orbital Therapeutics for a technology designed to rewire the immune systems of people with inflammatory conditions.
    • “The deal announced Friday gives Bristol Myers ownership of a company that’s been working on ways to genetically modify immune cells inside the body. Orbital’s lead program, OTX-201, does so by sending into cells “circular” RNA instructions training them to seek out cells with a particular protein flag. OTX-201, which is envisioned as an autoimmune disease treatment, could begin human testing next year.
    • “The acquisition expands Bristol Myers’ presence in cell therapies. The company is already one of the field’s leaders, with multiple marketed medicines for blood cancers. But, like its peers, Bristol views autoimmune disorders as a way to potentially broaden use of the complex treatments.”
  • Per MedTech Dive,
    • “Zimmer Biomet has launched two orthopedic devices with Paragon 28, the foot and ankle specialist it bought for $1.1 billion early this year. 
    • “The new products, which Zimmer reported Wednesday, add treatments for a type of shinbone break and hindfoot injuries to the company’s portfolio.
    • “Introducing the devices continues Zimmer’s efforts to maintain Paragon’s double-digit growth and expand its sports medicine, extremities and trauma (SET) business.”
  • The Employee Benefits Research Institute released its 2025 Employer Mental Health Survey.
  • Fierce Healthcare adds,
    • “Most employers offer coverage for mental health services, but where they fall short is in tracking whether those benefits are working, according to a new survey.
    • “The report, conducted by the Employee Benefit Research Institute (EBRI), found that 97% of employers offer mental health coverage and 67% offer coverage for substance abuse treatment. However, only 22% said they actively monitor whether employees are using the benefits.
    • “In addition, there is a significant opportunity for employers to do more in tracking network adequacy, the study found. Forty-seven percent of those surveyed said they receive details from vendors or collect data on provider-to-enrollee ratios, while 44% said they track employees’ distance to providers and 48% said they monitor wait times.
    • “Fewer than one-third (31%) said they collect data on out-of-network care use, which is a major barrier to behavioral health access, per the report.”
  • KFF-Peterson Health System Tracker studies “how much do people with employer plans spend out-of-pocket on cost-sharing?”
    • “By cost-sharing type, average spending on deductibles and coinsurance has increased, while copayments have remained flat relative to inflation since 2013. However, since 2021, inflation (16%) and spending on deductibles (13%) have grown at similar rates. Deductibles rose rapidly before 2019, however starting in about 2019 employers have held deductibles constant.
    • “In 2023, 66% of people with employer coverage spent at least $100 on out-of-pocket health care expenses. Among them, 39.7% spent between $100 and $999 on average, while 26% spent $1,000 or more. Over time, the share of enrollees facing over $1,000 in annual out-of-pocket costs has steadily increased.  Conversely, 18% of people with employer coverage incurred no out-of-pocket costs, and 15.4% spent less than $100 in 2023.
    • “Regarding total health spending, 56% of people with employer coverage spent $1,000 or more, including 41% who spent between $1,000 and $9,999 and 15% who spent $10,000 or more. Meanwhile, 12% of enrollees used no health care billed to their health plan in the year, which further highlights the uneven distribution of health care costs across the insured population under employer plans.”
  • Per an Institute for Clinical and Economic Review news release,
    • “The Health Economics Methods Advisory (HEMA) yesterday released its first ever Draft Report focused on the assessment of the benefits of treatment that are appropriate to consider in economic evaluation for health technology assessment (HTA) decision-making.
    • “HEMA has been convened by the leaders of three global HTA organizations to independently assess new methods and processes. The three institutions include ICER, England’s National Institute for Health and Care Excellence (NICE), and Canada’s Drug Agency (CDA-AMC).
    • “This draft report will be open for public comment until October 30, 2025, providing a unique opportunity for all stakeholders to engage in the report development process.
    • “If you are interested in submitting a public comment on the Draft Report, visit https://hemamethods.org/our-research/.”

Thursday Report — 2026 Government Contributions Announced

From Washington, DC,

  • Federal News Network informs us,
    • “Federal employees and annuitants are heading for yet another year of large increases to their health insurance premiums, in both the Federal Employees Health Benefits (FEHB) program and the Postal Service Health Benefits (PSHB) program.
    • “The Office of Personnel Management announced Thursday that FEHB participants will pay an average of 12.3% more toward their insurance premiums starting in January 2026 — or in dollars, an average of $26.40 more per pay period.
    • “The upcoming 12.3% premium spike follows multiple large premium increases over the last few years for FEHB enrollees. Federal employees saw an average of a 13.5% increase for the 2025 plan year — the largest year-over-year increase in well over a decade. Feds also saw a 7.7% jump in 2024, and an 8.7% increase in 2023.
    • “The PSHB program, which is open to more than 2 million USPS employees, annuitants and family members, is also set for a large premium increase for 2026. Enrollees in PSHB will be paying 11.3% more, on average, toward their 2026 premiums. In dollars, that’s about $21.51 more per pay period.” * * *
    • “When accounting for the government’s share of FEHB costs, which is increasing by about 9.2%, premiums will rise by 10.2% overall. PSHB premiums are increasing by 9% overall, when including the government’s portion of the cost, which is going up by 8%.”
  • Per an OPM news release,
    • “Today, the Office of Personnel Management (OPM) announced the 2025 Federal Benefits Open Season will be held from November 10 through December 8, 2025, and the 2026 plans and premiums for Federal Employees Health Benefits (FEHB) Program, Postal Service Health Benefits (PSHB) Program, and Federal Employees Dental and Vision Insurance Program (FEDVIP) are now available for review
    • “This is the opportunity for eligible federal and postal employees and annuitants to enroll or make changes to their health, dental, and vision coverage for the upcoming year.
    • “During Open Season, we want to give enrollees the opportunity to review their coverage, compare coverage options, and make the choice that is right for them,” Associate Director for Healthcare and Insurance Shane Stevens said. “I strongly encourage all employees to reassess their current coverage and choose the plans that best meet their family’s needs.” * * *
    • “Read Associate Director Stevens’ blog post about this year’s Open Season here. Read how to prepare for Open Season here.”
  • Here is a link to Govexec’s article about the OPM announcement.
  • Modern Healthcare reports,
    • “Medicare Advantage insurers suffered another disappointing year under the Star Ratings quality measurement program. 
    • “The average Medicare Advantage star rating for 2026 is essentially flat at 3.66, compared with 3.65 for 2025, according to data the Centers for Medicare and Medicaid Services released Thursday.
    • “Just over four in 10 Medicare Advantage contracts — which are bundles of plans — earned at least four of five stars, the threshold to qualify for the maximum 5% bonus payment, the same as this year. Eighteen contracts, or 3.5%, won five stars, up from seven for 2025. The annual enrollment period begins next Wednesday and ends Dec. 7.”
  • The Wall Street Journal reports.
    • “Republican and Democratic senators are trading ideas on healthcare funding to forge a path out of the government shutdown, as tensions rose on Capitol Hill ahead of what is set to be a painful week for government workers and military servicemembers.
    • “Informal discussions have centered on extending enhanced Affordable Care Act subsidies temporarily, but with new guardrails meant to cut back on aid for higher-income families. One cutoff point that has been discussed among Democrats: limiting the subsidies to households at or below $200,000 of income, rather than leaving the benefit uncapped.
    • “Sen. Angus King (I., Maine), who caucuses with the Democrats, has dubbed his approach the “two and two”—a two-year extension of the subsidy capped at $200,000 of income. Sen. Mark Kelly (D., Ariz.) said that a cap would be hard to implement this year, but that discussions were occurring about reducing the subsidy for next year by limiting the benefit to people making above a certain percentage of the federal poverty line, with some members aiming for a cap at $200,000 of household income.” * * *
    • “The government shutdown started Oct. 1, and many federal workers and troops are set to miss their first full paychecks next week.”
  • and
    • “The Trump administration said it isn’t planning to impose tariffs on generic drugs from foreign countries, after months of wrangling over whether to impose levies on the vast majority of drugs that are dispensed in the U.S.
    • “The administration has been weighing duties on a range of pharmaceutical products and ingredients, using a tariff investigation under Section 232 of the Trade Expansion Act of 1962, which covers threats to national security. President Trump last month posted online that he would impose 100% tariffs on name-brand drugs on Oct. 1 but didn’t mention generics. Trump ultimately delayed imposing tariffs, as officials said they would allow for more negotiations with drug companies.
    • “The administration is not actively discussing imposing Section 232 tariffs against generic pharmaceuticals,” White House spokesman Kush Desai said in a statement. A spokesman for the Commerce Department, which is handling the tariff investigation, similarly said that the 232 investigation wouldn’t result in tariffs on generics.
    • “The move, which isn’t final and could change in the coming weeks, comes after months of debate within the administration over how to bring manufacturing of generic drugs back to the U.S. and what role tariffs should play in that effort.”
  • The Internal Revenue Service helpfully posted a revenue procedure that “sets forth inflation-adjusted items for 2026 for various Code provisions as in effect on October 9, 2025.”
  • Beckers Clinical Leadership informs us,
    • “The federal government has directed the United Network for Organ Sharing to pause some of its oversight work amid the government shutdown.
    • “As the primary contractor for the Organ Procurement and Transplantation Network, UNOS manages the nation’s donation and transplant system, facilitating matches and monitoring patient outcomes.
    • “While critical services — including operation of the organ matching system and responding to serious patient safety risks — will continue, the OPTN has been ordered to pause much of its routine oversight responsibilities. As a result, many committee meetings have been canceled, a UNOS spokesperson told Becker’s. One specific area of work being paused is the monitoring of reports for policy implementation on heart and lung transplants. 
  • MedCity News discusses the application of the White House’s artificial intelligence action plan to healthcare.
    • “Healthcare and life sciences are about to face unprecedented AI-driven regulatory changes that will reshape everything from research and development to drug approval submissions. Here are 10 steps healthcare and life sciences organizations should take to strategically prepare.”
  • Bloomberg Law relates,
    • “The US Centers for Disease Control and Prevention will reschedule a late October meeting of an influential vaccine panel that’s been weighing changes to long-standing advice around childhood shots.
    • “The Advisory Committee of Immunization Practices, or ACIP, will no longer meet on Oct. 22 and 23, according to the panel’s website. No indication was given of when a future meeting will take place or why it was moved. 
    • “A US Department of Health and Human Services spokesperson said the meeting details would be posted online once they are finalized. ACIP typically only meets three times a year, though the upcoming October meeting was set to be its fourth gathering in 2025.”

From the Food and Drug Administration front,

  • Per Fierce Pharma,
    • “In 2022, Regeneron paid Sanofi $900 million to gain full rights to its partnered cancer drug Libtayo. Three years later, the pricey bet on the injected PD-1 inhibitor appears to be paying off.
    • “Thursday, the FDA approved Libtayo as the first immunotherapy for adjuvant treatment of cutaneous squamous cell carcinoma (CSCC). The nod applies to patients who are at a high risk of recurrence after surgery and radiation.”
    • “The green light comes seven years after Libtayo became the first drug to reach the market in CSCC, as it was endorsed for patients with metastatic CSCC or those with locally advanced CSCC who are not candidates for surgery or curative radiation.”
  • Per Cardiovascular Business,
    • “San Francisco-based Bunkerhill Health has received U.S. Food and Drug Administration (FDA) clearance for its new advanced artificial intelligence (AI) algorithm designed to detect and evaluate mitral annular calcification (MAC) on routine, non-gated CT scans.
    • “According to Bunkerhill Health, the AI model—known as Bunkerhill MAC—is the first AI model cleared by the FDA to identify signs of MAC, a known cardiovascular disease risk factor. It was developed and tested using data from more than 25 academic medical centers.
    • “MAC may be missed on imaging, but it carries prognostic value for cardiovascular risk and procedural outcomes,” Alexander Sandhu, MD, MS, assistant professor in the division of cardiology at Stanford University School of Medicine, said in a statement. Stanford is one of the schools that provided data for the development of Bunkerhill MAC. “A tool that can automatically identify and quantify MAC on routine chest CT scans gives us a way to capture this information consistently and at scale, which could help guide decision-making and research across cardiology and structural heart care.”

From the public health and medical / Rx research front,

  • Politico reports,
    • “The CDC and its independent panel of vaccine advisers have quietly opened the door to wider access to Covid-19 vaccination during pregnancy, softening an earlier decision by Health Secretary Robert F. Kennedy Jr. to stop recommending that pregnant women get the shots.
    • “The CDC’s Advisory Committee on Immunization Practices voted in September to advise that adults get the Covid-19 shot through shared clinical decision-making between patients and providers. It did not specifically vote on whether the shot should be administered during pregnancy, yet the vote appears to encompass pregnant women, according to an update this month on the CDC website that reflects the new guidance.
    • “The new guidance for adults means that pharmacies can administer the vaccine to pregnant women and almost all insurers must cover the shots with no cost sharing — expanding access.”
  • Cardiovascular Business tells us,
    • Transcatheter aortic valve replacement (TAVR) is being used to treat a rising number of patients with severe aortic stenosis. However, according to a new commentary published in the Journal of the American College of Cardiology (JACC), this trend may have gone too far.[1] The authors fear that too many low-risk patients are undergoing TAVR when they should be considered for surgical aortic valve replacement (SAVR) instead.[1] 
    • “With some U.S. states documenting that nearly 50% of patients requiring aortic valve replacement aged <65 years receive TAVR rather than guideline-directed SAVR, a significant public health concern may be looming,” wrote first author J. Hunter Mehaffey, MD, MSc, a cardiac surgeon with West Virginia University (WVU), and colleagues. “While we await long-term data from trials, there are growing questions surrounding valve durability and reintervention rates, particularly in younger and lower-risk populations. These concerns include the potential deleterious effects of accelerated structural valve deterioration, and the commensurate rise in the need for premature surgical TAVR explantation.”
    • “Mehaffey et al. emphasized that the risks associated with SAVR are typically procedural. With TAVR, however, some risks persist for up to two years after treatment. In addition, the group added, many patients who care teams treat on a daily basis were excluded from the initial studies used to track the safety and effectiveness of TAVR in low-risk patients. This creates uncertainty about whether or not a patient with a bicuspid aortic valve, for example, should be treated with TAVR over SAVR.”
  • Healthcare Dive adds,
    • “Hospitals charged Medicare more than $1.9 billion over three years for more than 200,000 unnecessary, “low-value” back surgeries for older adults, according to a new analysis of claims data from the Lown Institute.
    • “That amounts to one unnecessary back procedure every eight minutes, according to the report, which analyzed the rates of spinal fusions and vertebroplasties — or surgeries that inject medical-grade cement into broken spinal bones to relieve pain.
    • “Back surgeries have come under scrutiny due to the high risk of complications — including including infection, blood clots and strokes — which can occur in up to 18% of patients, according to the report. “Reducing unnecessary procedures, particularly invasive ones that carry grave risks, is a moral imperative,” Dr. Vikas Saini, president of Lown, said in a statement.”
  • The New York Times relates,
    • “Surgeons in China have for the first time transplanted a section of liver extracted from a genetically modified pig into a human cancer patient, they reported on Thursday.
    • “The surgeons, who described the procedure in a paper in The Journal of Hepatology, grafted the portion of pig liver onto the left lobe of a 71-year-old patient’s liver after removing the larger right lobe, where a tumor the size of a grapefruit had grown. The lobe with the porcine transplant functioned, producing bile and synthesizing blood clotting factors, the surgeons reported. The patient’s body did not reject the organ graft, which enabled the remaining left lobe of the patient’s own liver to regenerate and grow, the scientists said.
    • “The porcine liver lobe was removed 38 days after the transplant, when complications developed, the surgeons wrote in the report. The patient, who had advanced disease, died a little over five and a half months later. He would not have been eligible to receive a human donor organ in China because he had advanced cancer and hepatitis B-related cirrhosis, the authors wrote.”
  • NBC News lets us know,
    • “Just as a single night of insomnia may leave you feeling groggy and cranky, solid slumber can help you feel rested and ready to take on the day. How well you sleep over time, however, can influence deeper aspects of your health and well-being, new research shows.
    • “Five distinct sleep patterns are tied to your health, lifestyle and cognition and even how different regions of your brain connect to one another, according to a study published Tuesday in the journal PLOS Biology
    • “Specifically, those “sleep-biopsychosocial profiles” encompass biological, psychological and socioenvironmental factors — such as having a safe, comfortable place to sleep — that contribute to your sleep hygiene.”
  • Per Health Day,
    • “A rare but dangerous form of breast cancer is on the rise in the United States, a new report says.
    • “Lobular breast cancer rates are rising three times as fast as all other breast cancers combined, 2.8% per year versus 0.8% per year, researchers reported Oct. 7 in the journal Cancer.
    • “Although lobular breast cancer accounts for a little over 10% of all breast cancers, the sheer number of new diagnoses each year makes this disease important to understand,” said lead researcher Angela Giaquinto, an associate scientist for cancer surveillance research at the American Cancer Society (ACS).
    • “Also, survival rates beyond seven years are significantly lower for (lobular breast cancer) than the most common type of breast cancer, highlighting the pressing need for prevention and early detection strategies targeting this subtype to be brought to the forefront,” Giaquinto added in a news release.
    • “Lobular breast cancer develops in the milk-producing glands of the breast, which are called lobules, researchers said in background notes.”
  • and
    • “Concussions and traumatic brain injuries (TBI) have been considered a potential cause of ALS, also known as Lou Gehrig’s disease.
    • “But a new study argues the association might be the other way around, with concussions providing an early warning sign among folks already in the early stages of ALS (amyotrophic lateral sclerosis).
    • “The loss of muscle control that comes with early ALS might increase people’s risk for a concussion-causing fall or accident; researchers write in JAMA Network Open.
    • “If that’s so, then “TBI in some individuals perhaps (reflects) a consequence of early, subclinical ALS,” concluded the research team led by Dr. William Stewart, a neuropathologist at Queen Elizabeth University Hospital in Glasgow, U.K.”
  • The FEHBlog recalls reading that Lou Gehrig suffered a lot of concussions as a baseball player in the days before batting helmets.

From the U.S. healthcare business front,

  • Fierce Pharma relates,
    • “AstraZeneca has broken ground on a $4.5 billion manufacturing facility near Charlottesville, Virginia, confirming a report about its location six weeks ago when state lawmakers approved an economic development package for the project.
    • “The company has added an additional $500 million to its original planned investment in the site, which will manufacture active pharmaceutical ingredient (API) for the production of weight management, metabolic and cardiovascular treatments, along with drugs from AZ’s growing antibody-drug conjugate (ADC) portfolio.
    • “AZ plans to create 600 full-time roles at the site, plus an additional 3,000 jobs during construction of the facility, according to an Oct. 9 press release.  The company expects the plant to come online in the next four to five years.”
  • Bloomberg points out,
    • UnitedHealth Group Inc. plans to acquire a 45-doctor medical practice in Massachusetts in a sign that its Optum division will keep adding doctors despite turmoil in the business.
    • “The company’s Atrius Health affiliate has agreed to buy a Boston-area primary care group called Acton Medical Associates, PC, according to a notice posted by a Massachusetts regulator.
    • “The deal shows UnitedHealth continues to expand its reach in primary care and physician groups even as that part of its business has struggled. Physician groups are part of its sprawling Optum Health business, where executives said earnings were $6.6 billion below expectations in a July call with analysts.”
  • BioPharma Dive notes,
    • “Novo Nordisk will spend billions of dollars to grow its foothold in treating a common liver condition, agreeing on Thursday to buy Akero Therapeutics for a drug that’s currently in late-stage testing. 
    • “Novo will pay $54 per share, or about $4.7 billion upfront, for California-based Akero and its lead drug, known as efruxifermin. Akero stockholders could see another $6 per share in payouts via a so-called contingent value right if efruxifermin is approved by U.S. regulators.
    • “In buying Akero, Novo is adding to a recent upswing in dealmaking involving drugs for the liver disease known as metabolic dysfunction-associated steatohepatitis, or MASH. GSK bought one prospect from privately held Boston Pharmaceuticals in May, and Roche acquired another through a deal for 89bio last month. All three deals were centered around medicines that mimic the activity of a metabolism-balancing hormone called FGF21.” 
  • Per STAT News,
    • “With a flurry of startup activity, tech to monitor the symptoms of Parkinson’s disease is gaining traction in care.
    • “On Thursday, Kneu Health, a startup spun out of Oxford University research labs, announced $5.6 million in funding for its smartphone app-based platform that measures movement, speech, and cognitive changes in people with Parkinson’s over time. In addition to working with the U.K. National Health Service, Kneu is being trialed by Cedars-Sinai, which is an investor, and Mass General Brigham. It has raised $11.2 million to date.
    • “Over the summer, San Francisco-based Rune Labs quietly raised $11 million from its existing investors with plans to add more funding. The company has raised $57 million total to support its Parkinson’s technology, which uses an Apple Watch to track symptoms and boasts a growing partnership with Kaiser Permanente. Last week, wearable device and algorithm developer Empatica announced it had acquired PKG Health, another maker of Parkinson’s tracking tech that’s been used to care for 35,000 people. Empatica’s largest business is supporting pharma companies.”
  • Per Fierce Healthcare,
    • “Similar to Medicare, commercial insurers are seeing substantially higher prices when care is delivered in a hospital outpatient department as opposed to an ambulatory surgical center, according to a multi-payer analysis published this week.
    • “However, just how much those prices increase varies substantially between individual commercial payers, suggesting there’s more room for insurers to push down spending via selective provider contracting, Brown University researchers wrote in their Health Affairs study.
    • “The researchers said their analysis is unique in focusing on site-based payment differentials across multiple payers in the commercial insurance market, which have largely been overshadowed by investigations and debate over site-neutral payment policies for Medicare.
    • “Although insurers can, and do, pursue strategies to limit payment differentials across settings, large payment differentials remain common and costly,” they wrote in the journal.”
  • and
    • “When the government entered a partial shutdown Oct. 1, hospitals across the country faced a major task: discharging, relocating or shifting care programs for the thousands of patients in hospital at home programs. 
    • “With Congress at a standoff over healthcare cuts and Affordable Care Act premium tax subsidies, the body failed to reauthorize the Centers for Medicare & Medicaid Services’ (CMS’) pandemic-era Acute Hospital Care at Home program, along with Medicare telehealth services.
    • “The CMS directed the 419 participating AHCaH hospitals to discharge or relocate Medicare hospital at home patients if Congress did not extend the waiver. Health systems received the notice about 60 days in advance of the Sept. 30 deadline, and they received periodic reminders as the shutdown drew near. 
    • “In the days before the shutdown, hospitals ramped down admissions to hospital at home programs . Since the lapse of the waiver, home hospital providers have entered a complex maze of regulations and decisions.”
  • The Wall Street Journal reports,
    • “Drug Rehabs Lure in Patients for Insurance Money—Then Leave Them on the Street.”
    • “Operators promise high-end treatment, help addicts sign up for insurance then pile on charges for little in return, say former patients and insurers.:”
  • The FEHBlog observes that’s a big bowl of wrong.

Midweek report

From Washington, DC,

  • Roll Call reports.
    • “As the government shutdown entered its second week, Democratic lawmakers insisted the tide is shifting toward a deal as some hard-line Republicans express support for extending health insurance subsidies, despite blanket opposition from Republican leadership to any agreement in advance of reopening the government. 
    • “Ending the standoff appears unlikely in the short term — votes aimed at doing so Wednesday yielded similar results as before, with the GOP’s continuing resolution going down for a sixth time, 54-45. The same three Democratic caucus members — Catherine Cortez Masto of Nevada, Angus King of Maine and John Fetterman of Pennsylvania — voted in favor. The Democrats’ continuing resolution was also blocked.
    • “As for the parameters of a potential deal, House Minority Leader Hakeem Jeffries, D-N.Y., once again ruled out a one-year extension of the subsidies. Democrats have called for a permanent extension of the premium tax credits but asked by reporters if a two-year extension was possible, Jeffries didn’t rule it out.”
  • The Wall Street Journal explains who currently gets subsidies in return for receiving coverage under the Affordable Care Act.
  • Because the 2019 shutdown ended due to an air traffic controller walkout, Govexec observes,
    • “The Federal Aviation Administration reported no travel delays due to staffing levels at U.S. air traffic control facilities Wednesday, following a day of some delays related to above-average absences at a handful of facilities.
    • “An FAA operational plan posted about noon Eastern Time on Wednesday, the eighth day of the federal government shutdown, showed no facilities impacted by “staffing triggers.” A day earlier, the same memo showed staffing levels affected operations at major hub airports in Phoenix and Denver, as well as a smaller airport in Burbank, California.
    • “Air traffic controllers are essential to the functioning of the nation’s air transportation system and must continue to work during a shutdown, though they are not paid while it is ongoing.
    • “The group has not yet missed a paycheck during the current lapse in federal funding. The first impact most federal employees will see on their pay will be Friday, when electronic funding transfers are made for the pay period from Sept. 24 to Oct. 7. 
    • “Because Congress has not appropriated money beyond Sept. 30, they would only receive a partial paycheck. Future paychecks would not be allocated until the government reopens.”
  • Per Fierce Healthcare,
    • “The top senator on healthcare policy is taking a hard look at the American Medical Association’s “anti-patient and anti-doctor” handling of the healthcare system’s near-ubiquitous billing and claims processing codes.
    • “Bill Cassidy, M.D., R-Louisiana, who chairs the Senate Health, Education, Labor and Pensions (HELP) Committee, chastised the nation’s leading physician association for “abusing” the Current Procedural Terminology (CPT) coding system and said he will be “actively reviewing” the issue.
    • “In a letter sent Monday but made public Wednesday, he accused the AMA of “charging exorbitant fees to anyone using the CPT code set, including doctors, hospitals, health plans and health IT vendors. These fees inevitably are passed on by CPT users to patients in the form of higher healthcare costs.”
    • “The letter includes requests for the AMA to detail how it incorporates provider feedback into its process for finalizing codes, and for specific details on revenues and spending related to CPT codes.”
  • The Wall Street Journal relates,
    • “The country’s top drugmakers are set to meet in early December at the Four Seasons hotel in Georgetown with Donald Trump Jr. and senior Trump administration officials that regulate the pharmaceutical industry.
    • “The host: BlinkRx, an online prescription drug delivery company that this year installed Trump Jr. as a board member. The summit will conclude with a dinner at the Executive Branch, the exclusive new club founded by Trump Jr. and his close friends, according to people with knowledge of the event and a copy of the invitation viewed by The Wall Street Journal. 
    • “BlinkRx stands to benefit from a shake-up of how patients buy drugs after President Trump urged pharmaceutical companies to sell their medicines directly to consumers. BlinkRx helps drugmakers do exactly that with a service that promises to set up direct-to-patient sales programs in as little as three weeks. TrumpRx, a new government website set to launch in early 2026, would funnel patients to direct-sale sites.”
  • Healthcare Dive informs us,
    • “The top lobby for pharmacy benefit managers has named Adam Kautzner, the head of major PBM Express Scripts, as chair of its board.
    • “As board chair, Kautzner will oversee the Pharmaceutical Care Management Association’s strategy, including defense of the drug middlemen amid growing scrutiny of their role in rising drug costs. 
    • “The PCMA has also created a new council to represent its mid-market clients, a segment of its membership that’s been growing, the lobby said Tuesday. The council will be represented by a new seat on the PCMA’s board to be held by Jeff Park, president of drug pricing platform Waltz Health.”

From the Food and Drug Administration front,

  • Fierce Pharma points out,
    • “More than 10 years after bringing one of the first idiopathic pulmonary fibrosis (IPF) drugs to market, Boehringer Ingelheim is freshening up its leadership in the rare lung disease space with a newly approved treatment option.
    • “Jascayd’s Oct. 7 FDA approval makes it the first new therapy for IPF in more than a decade, following in the footsteps of the company’s own Ofev and Roche’s Esbriet, which won their respective FDA nods back in 2014. Together, those two medicines make up the current therapeutic market for IPF in the U.S. 
    • “With a tolerability edge over the older treatments and proven benefits in lung function, Boehringer’s new option could “shape the future of IPF treatment,” Martin Beck, head of the company’s inflammation disease area, told Fierce Pharma in an interview.”
  • BioPharma Dive adds,
    • “Lexeo Therapeutics on Tuesday said the Food and Drug Administration appears willing to review, and potentially approve, its experimental rare disease gene therapy more quickly than previously anticipated.
    • “According to the company, the agency has “indicated openness” to an accelerated approval filing for its treatment — a gene therapy called LX2006 for the neurodegenerative condition Friedreich’s ataxia — that’s based on pooled data from ongoing studies as well as results from a planned pivotal trial.”

From the judicial front,

  • Reuters reports,
    • “A federal appeals court on Monday rejected Novo Nordisk’s (NOVOb.CO) challenge to the U.S. government’s program that gives its Medicare health insurance plan the power to negotiate lower drug prices, the latest in a barrage of lawsuits brought by drugmakers to fail.
    • “The Philadelphia-based 3rd U.S. Circuit Court of Appeals affirmed a lower court’s ruling dismissing the Danish drugmaker’s challenge to the program and the Centers for Medicare and Medicaid Services’ selection of six of its insulin products for price negotiations.
    • “A unanimous three-judge panel rejected Novo’s constitutional challenges to the program, which was part of Democratic former President Joe Biden’s Inflation Reduction Act, and said the law specifically bars courts from reviewing the drugs selected.
    • “A Novo Nordisk spokesperson said the company was assessing its options to appeal the ruling.”

From the public health and medical / Rx research front,

  • The University of Minnesota’s CIDRAP informs us,
    • “Today the Centers for Disease Control and Prevention (CDC) updated its measles data for the country, showing a total of 1,563 cases in 2025, an increase in 19 cases since last week. This is the most cases seen in the United States since 2000, the year measles was officially declared eliminated. 
    • “Twenty-seven percent of cases have been in children under the age of 5, and 92% of patients are unvaccinated or have an unknown vaccination status. CDC officials have confirmed 44 outbreaks, which account for 87% of confirmed infections.”
  • and
    • “An international team of researchers today reported promising results from a phase 1 trial of a novel vaccine designed to protect against typhoid fever and non-typhoidal Salmonella infections.
    • “The team, led by investigators from the University of Maryland (UM) School of Medicine, reported that the trivalent (three-strain) Salmonella conjugate vaccine (TSVC) produced a strong immune response, and was safe and well-tolerated, in a small group of healthy US adults. The findings from the trial were published today in Nature Medicine.
    • “The investigators say the findings are encouraging and provide a strong foundation for evaluating the vaccine in children. Typhoid fever and invasive non-typhoidal Salmonella (iNTS), which causes severe bloodstream infections, are leading causes of illness and death in children in Africa.
    • “A single vaccine that protects against both could be a game-changer for global pediatric health,” UM School of Medicine Dean Mark Gladwin, MD, said in a university press release.”
  • MedPage Today notes,
    • “Receipt of the 2024-2025 COVID-19 vaccine was associated with decreased risks of severe outcomes, according to an observational cohort study of U.S. veterans.
    • “Looking at COVID-associated outcomes in nearly 300,000 veterans at 6 months, the estimated vaccine effectiveness was 29.3% against emergency department visits, 39.2% against hospitalizations, and 64% against deaths, reported Ziyad Al-Aly, MD, of the VA St. Louis Health Care System, and colleagues.
    • “Overall, vaccine effectiveness for a composite of the three outcomes was 28.3%, with a risk difference per 10,000 people of 18.2 (95% CI 10.7-27.5), they noted in the New England Journal of Medicine.
    • “The severity of SARS-CoV-2 infections has waned since 2020, and uncertainty about the value of annual COVID shots helped drive down adult vaccination rates to 21% during the 2024-2025 season.”
    • “The severity of SARS-CoV-2 infections has waned since 2020, and uncertainty about the value of annual COVID shots helped drive down adult vaccination rates to 21% during the 2024-2025 season.”
  • The Washington Post lets us know how to stop the No. 1 killer of Americans long before any symptoms. Cardiovascular disease experts propose a new approach to treating heart disease, focusing on atherosclerosis prevention and early detection.
    • To improve your heart health, consider following the American Heart Association’s checklist, said Neha Pagidipati, a cardiovascular disease prevention expert with the American College of Cardiology.
    • The AHA’s “Life’s Essential 8” include:
      • Eating better. Recommendations include whole foods, lots of fruits and vegetables, lean protein, nuts, seeds, and using olive or canola oil for cooking.
      • Staying active.
      • Quitting tobacco and vaping.
      • Getting healthy sleep. For most adults, this is seven to nine hours of sleep each night.
      • Managing weight.
      • Controlling cholesterol. LDL, or “bad” cholesterol, should be 100 milligrams per deciliter or lower, Nissen said.
      • Managing blood sugar. If you have diabetes, pay attention to your hemoglobin A1C levels, which should be below 5.7 percent.
      • Managing blood pressure. For most people, blood pressure should be below 120/80, Nissen said.
  • Medscape adds,
    • “Many people with obesity have chronic pain due to joint stress and inflammation. Speaking to these patients about modifiable lifestyle factors — like diet and exercise — can help improve their pain severity and quality of life.
    • “In a new study published in the European Journal of Nutrition, patients with overweight or obesity who followed a 3-month weight-loss dietary intervention cut chronic musculoskeletal pain scores in half — independent of adiposity changes.”
  • NBC News reports,
    • “Short bursts of purposeful activity — such as walking around the block or lifting small weights — may be the best way to get in the habit of exercising. Bite-sized bits of exercise also improve heart and muscle fitness, a study published Tuesday in BMJ Sports Medicine found.
    • “Less than half of adults in the United States get enough aerobic activity and less than a quarter get the recommended amount of both aerobic and muscle-strengthening exercise
    • “When people are asked why they don’t exercise, the answers are almost always the same, no time and no motivation,” Miguel Ángel Rodríguez, a doctoral student in clinical research at the University of Oviedo in Spain, who led the study, said in an email.”
  • Per Health Day,
    • Memantine improves social impairments in youth with autism spectrum disorder (ASD), according to a study published online Oct. 1 in JAMA Network Open.
    • “Gagan Joshi, M.D., from Massachusetts General Hospital in Boston, and colleagues examined the safety and efficacy of memantine for treating social impairments in youths with ASD in a 12-week placebo-controlled randomized clinical trial. The study population included 42 youths aged 8 to 17 years with ASD without intellectual disability who initiated treatment. The intention-to-treat efficacy analysis included 35 youths (16 treated with memantine and 19 with placebo).”
  • and
    • “More women are choosing to freeze their eggs, but fewer are returning to use them, according to a study published online Aug. 29 in the American Journal of Obstetrics & Gynecology.
    • “Mabel B. Lee, M.D., from the University of California, Los Angeles, and colleagues assessed national trends in planned oocyte cryopreservation, subsequent oocyte utilization, and outcomes of oocyte warming cycles. The analysis included data from the Society for Assisted Reproductive Technology Clinic Outcome Reporting System (2014 to 2021).”

From the U.S. healthcare business front,

  • Modern Healthcare reports,
    • “Medical practice network OneOncology has acquired GenesisCare USA of Florida and is relaunching the practice as SunState Medical Specialists.
    • “The deal adds more than 100 physicians, including urologists, oncologists and surgeons, at 104 clinics throughout Florida to OneOncology’s portfolio, according to a Wednesday news release.
    • “GenesisCare USA of Florida was part of GenesisCare, an Australia-based cancer treatment provider that filed for Chapter 11 bankruptcy protection in 2023. The company, which was backed by private equity firm KKR and China Resources Capital, entered the U.S. in 2020 when it acquired 21st Century Oncology.
    • “As part of bankruptcy proceedings, GenesisCare sought to restructure with about $1.7 billion in debt and separate U.S. operations from those in Australia and Europe. It emerged from the bankruptcy process in 2024 and trimmed its U.S. footprint to Florida and North Carolina markets. 
    • “OneOncology, which is majority owned by TPG Capital, said the latest Florida deal builds on the company’s previous investments in urology. It plans to invest in upgraded technology at SunState Medical and expand access to clinical services such as advanced radiation therapies and interventional radiology, according to the release.”
  • BioPharma Dive tells us,
    • “Having closed a nine-figure fundraising round, a newly launched biotechnology company hopes to rewire the immune system with drugs aimed at a special kind of nerve cell.
    • “Nilo Therapeutics debuted Wednesday, equipped with $101 million from a Series A financing that was co-led by the venture capital firms DCVC Bio, Lux Capital and The Column Group. Alexandria Venture Investments and the Gates Foundation also contributed to the round.
    • “The fresh money, according to Nilo, will go toward growing the biotech’s research and development team, advancing its preclinical drug programs, and establishing laboratories in New York City. Nilo formed through a collaboration between The Column Group and three Ivy League scientists — Charles Zuker, of Columbia University; Ruslan Medzhitov, of Yale University; and Stephen Liberles, of Harvard University.”
  • Per Fierce Healthcare
    • “As pharma giant Eli Lilly builds out its direct-to-consumer care site, LillyDirect, the company has tapped virtual primary care company HealthTap to join its small lineup of independent care providers.
    • “Consumers who come to LillyDirect in search of specific treatments or Lilly-manufactured medications, such as GLP-1s, can find educational materials on common health conditions and access recommendations for in-person or virtual care. 
    • “LillyDirect has been building out its network of independent care providers for a slew of healthcare conditions and specialities, including diabetes, obesity, cancer, dermatology, autoimmune, sleep apnea and migraine.
    • “HealthTap will be listed as a provider for treating type 1 and type 2 diabetes on the LillyDirect site.”
  • and
    • Allara Health, a virtual women’s health provider, has expanded to all 50 states. 
    • “The provider, specializing in women’s hormonal, metabolic and reproductive health, was in 30 states at the start of the year. Alongside news of the expansion, Allara has also published clinical outcomes data that demonstrate improvements in patient health in a health impact report.
    • “The retrospective analysis included nearly 1,500 patients who either had a PCOS diagnosis or were being seen for other hormonal or metabolic care. It found that in the first nine months of care, patients with a body mass index (BMI) in the obese range (equal to or greater than 30) achieved a 5% mean BMI reduction. A 5% weight reduction is considered clinically significant, the report said.
    • “The analysis also found that after 10 months, two-thirds of prediabetic patients had normalized their A1C levels, and 77% of diabetics reduced their A1C levels out of the diabetic range. Patients with a high level of insulin resistance saw a 12% reduction in those levels.” 
  • and
    • “Amazon Pharmacy is rolling out kiosks stocked with prescription medications to help patients get their meds immediately after appointments. 
    • “The kiosks will launch across One Medical locations in Los Angeles starting December 2025. Expansion to additional One Medical offices is expected soon after. The kiosks will contain commonly prescribed meds like antibiotics, inhalers and blood pressure medications. Controlled substances and medications requiring refrigeration are not available.” 

Tuesday report

From Washington, DC,

  • Federal News Network tells us,
    • “The guarantee of back pay for furloughed federal employees is now in limbo, as the White House weighs a different interpretation of the 2019 law that ensures federal employees get compensated following a government shutdown.
    • “A new draft legal opinion from the Office of Management and Budget, as first reported by Axios, argues that whatever funding legislation Congress ultimately passes to end the current shutdown must explicitly include appropriations to provide back pay for furloughed federal employees. And if it’s not expressly written in the spending legislation, the OMB memo argues that furloughed workers cannot receive any retroactive compensation.
    • “A copy of the OMB document, which a senior White House official shared with Federal News Network, appears to contradict OMB’s previous interpretation of the Government Employee Fair Treatment Act, or GEFTA, which President Donald Trump signed into law in 2019 during the last government shutdown. Both OMB and the Office of Personnel Management previously affirmed that under GEFTA, excepted and furloughed employees would be given back pay as soon as possible, once any current or future shutdown ends.”
  • In the FEHBlog’s opinion, this draft OMB opinion is a lead balloon.
  • Healthcare Dive shares six takeaways from CMS Administrator Mehmet Oz’s appearance on Monday before a Washington D.C. think tank audience.
  • Modern Healthcare reports,
    • “Federal regulators say they have made inroads into speeding up the process to resolve out-of-network billing disputes. It’s not enough for frustrated providers and health insurance companies.
    • “The No Surprises Act’s Independent Dispute Resolution, or IDR, process has been a punching bag for both camps since it launched in 2022, and a backlog of cases had piled up by the beginning of this year.
    • “But the share of IDR cases unsettled after 30 business days fell from 69% in January to 34% in July, the most recent month for which data are available, according to the Health and Human Services, Labor and Treasury departments. Likewise, 96.5% of disputes submitted since 2022 are either resolved or are less than 30 business days old, the departments wrote in a notice published Sept. 19.
    • “The departments’ efforts have delivered remarkable improvements in the throughput of cases compared to prior years,” the notice says. “IDR entities are now resolving disputes faster than they are submitted.”
  • STAT News informs us,
    • “The agreement between Pfizer and the Trump administration to lower drug prices has sent other companies scrambling to make a deal.
    • “Several major pharmaceutical firms that received letters from President Trump demanding lower prices have been hustling to show progress, with some hoping to announce a deal with the White House as soon as this week, according to five Washington representatives and lobbyists for the companies, granted anonymity to speak about private deliberations.”
    • “They have to now,” said one lobbyist of their clients’ thinking, noting the “anger”with Pfizer for effectively adding to their pressure to come to an agreement with the administration.
    • “The people cautioned that negotiations remain unfinished and several variables, including the government shutdown, could delay any announcements.
    • “The growing chatter around potential announcements signals the Trump administration’s pressure campaign may be paying off. But whether the deals will actually accomplish the administration’s objective — lowering prescription drug prices — remains unknown.”
  • Fierce Healthcare points out,
    • “The current state of the Medicare Part D market is a mixed bag, with premiums declining but many payers scaling back options, according to a new analysis from KFF.
    • “The report noted that the Centers for Medicare & Medicaid Services put an emphasis on “stability” in Part D when it announced premium estimates in late September, but KFF found that the total number of stand-alone Part D plans available will decrease in 2026, marking the third straight year of shrinking plan options.
    • “Some payers are trimming down their offerings, per the report. For example, Centene is ending three drug plans offered through WellCare and Health Care Service Corporation is discontinuing one of Cigna’s three Part D plans and pulling back from certain regions.
    • “Other insurers, such as Elevance Health, are exiting the stand-alone Part D plan market entirely.
    • “For 2026, beneficiaries in each state will be able to select from between eight and 12 stand-alone Part D plans, in addition to Medicare Advantage prescription drug coverage. Across the 34 Part D plan markets, a total of 360 plans will be made available by 17 parent organizations—a decrease of 22% from 2025.”
  • “As many major insurers scale back on Medicare Advantage,” Beckers Payer Issues takes a “look at the insurers that are fully backing out.”
  • NextGov/FCW explains how OPM Director Scott Kupor plans “to attract tech talent [to federal government employment] after months of workforce cuts.”
  • Per HR Dive,
    • “The U.S. Senate confirmed Brittany Panuccio, an assistant U.S. attorney for the Justice Department in Florida, as a commissioner for the U.S. Equal Employment Opportunity Commission in a 51-47 vote Tuesday. Panuccio’s confirmation was part of an en bloc vote on several nominations.
    • “Panuccio fills the seat vacated in December by Keith Sonderling, who was named deputy labor secretary in March, and gives Republicans a majority. Her term expires July 1, 2029. 
    • “Panuccio’s confirmation restores a quorum to EEOC, which has operated with only two commissioners since January, when President Donald Trump fired Democratic commissioners Charlotte Burrows and Jocelyn Samuels before the expiration of their terms.”

From the Food and Drug Administration front,

  • Healio adds,
    • “The FDA approved Zoryve cream 0.05% for the treatment of children aged 2 to 5 years with mild to moderate atopic dermatitis, according to a press release. 
    • “Currently, there are approximately 1.8 million children aged 2 to 5 years being treated with a topical therapy for AD. Zoryve (roflumilast, Arcutis) cream 0.05% is a once-daily, next-generation phosphodiesterase-4 inhibitor that offers a nonsteroidal option for children and their caregivers.
    • “It is essential to have safe and effective treatments for children, who are often diagnosed with atopic dermatitis at a young age and can live with the condition across their lifetime,” Lawrence F. Eichenfield, MD, chief of pediatric and adolescent dermatology at Rady Children’s Hospital-San Diego and vice chair of the department of dermatology at University of California San Diego, said in the release. “Young children often experience widespread disease, affecting large portions of their skin. Although topical steroids have been the standard treatment for years, they are not appropriate for long-term use.”

From the public health and medical / Rx research front,

  • The Wall Street Journal reassuringly explains how to get a Covid booster vaccination under the CDC’s newly approved guidelines.
  • MedPage Today reports
    • “To prevent measles outbreaks, public health systems and clinicians should look below the 35,000-foot view of state- and county-level vaccination rates against measles, mumps, and rubella (MMR) and instead aim their focus on at-risk school districts and schools, according to a statewide analysis of Texas counties.”
  • and
    • “The pre-cooked pasta Listeria recall broadened to include pasta salads and prepared dishes at Kroger, Trader Joe’s, and more grocery stores.
    • “Some Hello Fresh meals may contain Listeria-tainted spinach, USDA’s Food Safety and Inspection Service warned.
    • Chicken corn dog products from Foster Poultry Farms also were recalled after wood was found in the batter causing at least five injuries. (NBC News)”
  • Per Healio,
    • “Changing trajectories of heart health markers during young adulthood were associated with potentially increased risk for cardiovascular disease later in life, researchers reported.
    • “In addition, individuals who maintained higher levels of CV health through young adulthood had lower risk for incident CVD vs. those whose CV health was maintained at lower levels or declined, according to data published in JAMA Network Open.”
  • and
    • “Acupuncture needling greatly improved pain-related disability in older adults with low chronic back pain compared with usual care, a randomized controlled trial demonstrated.
    • “Acupuncture may be an effective and safe pain management tool for many older adult patients,” Lynn L. DeBar, PhD, MPH, a researcher at Kaiser Permanente Center for Health Research, told Healio. “While it is unlikely to take away all the pain, this study suggests that it can decrease pain-related disability substantively.”
  • The New York Times considers that “He was expected to get Alzheimer’s 25 years ago. Why hasn’t he? Scientists are searching for the secret in [76-year-old] Doug Whitney’s biology that has protected him from dementia, hoping it could lead to ways to treat or prevent Alzheimer’s for many other people.”
  • Per Health Day,
    • “Preschoolers who regularly overeat are likely swallowing their emotions as well, a new study says.
    • “Girls who overeat as preschoolers are more likely to develop anxiety, impulsivity and hyperactivity when they grow into teenagers, researchers reported in the journal BMC Pediatrics.
    • “The results indicate that children’s eating patterns could be early signs of mental health challenges, researchers said.
    • “Occasional overeating is normal, but if a child frequently overeats, it can be a sign of emotional struggles,” senior researcher Linda Booij, a professor of psychiatry at McGill University in Quebec, Canada, said in a news release.”
  • Per Genetic Engineering and Biotechnology News,
    • “A research team co-led by scientists at Institute for Bioengineering of Catalonia (IBEC) and West China Hospital Sichuan University (WCHSU), working with partners in the U.K., has developed a nanoparticle technology that studies showed can reverse Alzheimer’s disease (AD) in mice. Unlike other types of nanomedicine that rely on nanoparticles as carriers for therapeutic molecules, this approach employs nanoparticles that are bioactive in their own right, and which the team refers to as “supramolecular drugs.”
    • “Instead of targeting neurons directly, the therapy restores proper function of the blood-brain barrier (BBB), the vascular gatekeeper that regulates the brain’s environment. The BBB is a cellular and physiological barrier that separates the brain from the blood flow to protect it from external dangers such as pathogens or toxins. Through their newly reported research the investigators demonstrated that targeting a specific mechanism enables undesirable “waste proteins” produced in the brain to pass through this barrier and be eliminated in the circulation. In Alzheimer’s disease, the main waste protein is amyloid-β (Aβ), the accumulation of which impairs normal neuronal function.
    • “By repairing this critical interface, the researchers observed a significant reduction in brain amyloid-β (Aβ) levels and a reversal of Alzheimer’s pathology in the animal models, with cognitive benefits lasting up to six months following treatment.
    • “Study lead Giuseppe Battaglia, PhD, ICREA research professor at IBEC, principal investigator of the Molecular Bionics Group, and colleagues reported on their findings in Signal Transduction and Targeted Therapy, in a paper titled “Rapid amyloid-β clearance and cognitive recovery through multivalent modulation of blood–brain barrier transport,” in which they stated, “This innovative therapeutic paradigm offers a promising pathway for developing effective clinical interventions, addressing vascular contributions to AD, and ultimately enhancing patient outcomes…The therapeutic trilogy achieved—amyloid clearance, barrier restoration, and sustained cognitive recovery—establishes a blueprint for precision neurovascular medicine.”

From the U.S. healthcare business front,

  • Fierce Healthcare reports,
    • “It was a repeat performance for all 10 children’s hospitals named as the nation’s best in this year’s iteration of U.S. News & World Report’s ranking.
    • “The highly watched list, now in its 19th year, reviewed outcomes, practices and surveyed opinions for 198 children’s hospitals.
    • “Of these, 86 hospitals were named in some respect, whether that be a top-10 ranking for 10 different pediatric specialties and/or as one of 50 unranked facilities named as a high performer on pediatric and adolescent behavioral health.
    • “Among these, 10 children’s hospitals were named to the list’s honor roll for scoring well across multiple specialties. That unranked collection is identical to last year’s honorees.
      • “Boston Children’s Hospital
      • “Children’s Hospital Colorado, Aurora
      • “Children’s Hospital Los Angeles
      • “Children’s Hospital of Philadelphia
      • “Children’s National Hospital, Washington, D.C.
      • “Cincinnati Children’s
      • “Nationwide Children’s Hospital, Columbus, Ohio
      • “Rady Children’s Hospital, San Diego
      • “Seattle Children’s Hospital
      • “Texas Children’s Hospital, Houston”
  • and
    • “Providers are betting on artificial intelligence to ease the pain point of prior authorization, a new survey shows.
    • “Cohere Health, which provides clinical intelligence to insurers and risk-bearing providers, polled 200 clinicians and office administrators and found that 99% of clinicians report confidence in using AI to back prior authorization. Most (96%) office administrators said the same.
    • “Two-thirds of those surveyed said a completely digital prior authorization process would significantly improve their workflows. Across the board, the respondents said the process should have real-time tracking baked into the experience, allowing them to track the status of key requests.
    • “Providers are speaking loud and clear: they want and deserve a prior authorization process that is smarter, simpler and more transparent,” said Brian Covino, M.D., chief medical officer of Cohere Health, in an announcement.”
  • Healthcare Dive relates,
    • “Saint Peter’s Healthcare System and Atlantic Health abandoned plans to merge on Monday, citing impacts of the “rapidly evolving healthcare landscape nationally.”
    • “The New Jersey-based health systems first announced plans to combine in January last year and signed a definitive agreement to merge in June 2024. 
    • “The systems shared scant details about why the deal fell apart. However, in a joint statement issued Monday both Atlantic President and CEO Saad Ehtisham and Saint Peter’s President and CEO Leslie Hirsch called the deal’s end disappointing.”
  • STAT News informs us,
    • “Just a decade ago, a doctor with multiple medical licenses was an anomaly. Sometimes physicians would apply for credentials from a few states if they lived near a border and wanted the flexibility to practice on either side, since a doctor needs to be licensed where their patient is physically located. In-demand specialists might get a few more if they wanted to see patients virtually. But in the years since Covid began driving patients online, the number of physicians seeking multi-state licensure has ballooned to support the growing field of telehealth.
    • “Within that group, a STAT analysis of physician licenses shows that a small but powerful cohort of physicians is accumulating licenses in all 50 states, plus the nation’s capital and its territories. These physicians don’t max out on licenses just to practice across state lines. Often, they own the medical groups that are affiliated with nationwide telehealth companies. A doctor’s full roster of medical licenses can be leveraged for online businesses that provide specialty care, build patient funnels for pharma companies seeking to sell drugs directly to consumers, prescribe compounded meds — or sometimes, all of the above. 
    • “In 2016, just nine physicians in the U.S. held active licenses in all 50 states, according to data from the Federation of State Medical Boards. By 2024, 172 doctors had filled out their bingo card, and another 356 doctors had acquired at least 45 licenses — significantly outpacing the profession’s overall growth.”
  • As we approach Open Season, the American Diabetes Association offers “Health Insurance Aid for Diabetes. Access to medical care is key to managing your diabetes. Get more information on resources available to people living with diabetes.”

Monday report

From Washington, DC,

  • The Wall Street Journal reports,
    • “President Trump signaled a willingness to strike a deal on funding healthcare subsidies demanded by Democrats, as the government shutdown entered its second week. 
    • “We have a negotiation going on right now with the Democrats that could lead to very good things,” Trump told reporters in the Oval Office on Monday. 
    • “Senate Minority Leader Chuck Schumer (D., N.Y.) said formal talks hadn’t commenced. “Trump’s claim isn’t true. But if he’s finally ready to work with Democrats, we’ll be at the table,” he said in a statement.” * * *
    • “After Trump’s comments on Monday, Sen. Markwayne Mullin (R., Okla.) said he had spoken with Democrats and the president in an informal way about healthcare, but funding the government must come first. “Once they reopen the government, we’ll be happy to talk about the way we make healthcare better for the American people,” he said.” * * *
    • “At a press conference late Monday, House Minority Leader Hakeem Jeffries (D., N.Y.) said he hadn’t heard from Trump, but it was “an interesting statement that the president has made.” He said that he would be willing to talk with Trump or White House officials at any time.” 
       
  • The American Hospital Association News tells us,
    • “The Centers for Disease Control and Prevention will update its immunization schedules for the COVID-19 and chickenpox vaccines to adopt recent recommendations by the Advisory Committee on Immunization Practices. Patients are now advised to consult their health care provider if they want to receive a COVID-19 vaccine, which would be covered by health insurance like other routine vaccines. In addition, it is now recommended that children through age 3 receive a standalone chickenpox vaccine rather than the combined measles, mumps, rubella and varicella vaccine.”
  • The Washington Post adds,
    • “What does it mean to consult a clinician [/ their health care provider?
    • “The CDC website lists health care providers who can be involved in discussing vaccines with patients. They include anyone else who provides or administers vaccines, including primary care physicians, specialists, pharmacists, physician assistants, nurse practitioners and registered nurses.
    • “That means a person doesn’t necessarily need to make a doctor’s appointment to get a vaccine.
    • “Pharmacists are trained to discuss pros and cons of all medications with patients, including coronavirus vaccines.”
  • Per Health Day,
    • “The U.S. Food and Drug Administration is considering changes to a 20-year-old warning on menopause hormone therapy
    • “Experts say the warning has discouraged safe use of treatment for hot flashes, poor sleep and other symptoms
    • “Research suggests hormone therapy can be safer and more effective when started earlier in menopause.”
  • Bloomberg Law points out,
    • “A new regulatory pilot project from the US Centers for Medicare and Medicaid Services is under review at the White House budget office, suggesting that the Trump administration is seeking to take regulatory action against drugmakers even as it strikes deals with individual companies.
    • “There are no details about the policy CMS plans to test, titled the “Guarding US Medicare Against Rising Drug Costs” pilot, including what drugs or companies could be impacted. Regulatory pilot projects help the government determine if a new regulation will save money, allowing it to experiment with rules before implementing them widely.
    • “The proposed regulation is the agency’s second recent move toward new rules on drug prices; another posted on Sept. 25.”
  • Healthcare Dive informs us,
    • “Arbitration of surprise billing disputes between insurers and providers will continue despite the government shutdown, the CMS said on Friday.
    • “Parties that disagree over how much an out-of-network claim should be reimbursed can still submit disputes via the federal independent dispute resolution portal, and arbiters will continue to process disputes, according to the agency.
    • “However, a prolonged shutdown could throw a wrench in other processes that underlie the implementation of the No Surprises Act, which was passed in 2020 to protect consumers from unexpected out-of-network bills. Since congressional appropriations lapsed last week, Congress has made no progress on a deal to reopen the government.”
  • The Healthcare Financial Management Association lets us know that “No Surprises Act arbitration has been a bonanza for a few provider groups. For-profit provider companies have fared well in the NSA’s independent dispute resolution portal even as the process remains a frequent subject of litigation.”
    • “In a span of 2.5 years through 2024, providers reaped more than $2.2 billion from the No Surprises Act’s arbitration process, relative to the applicable in-network payment rates for the disputed care episodes.
    • “The awards received through the NSA’s independent dispute resolution (IDR) process largely arise from “disputes that are primarily initiated and won by private-equity-backed providers,” said Kennah Watts, research fellow at the Center on Health Insurance Reforms at Georgetown University.
    • “Driven by that handful of groups, the volume of IDR disputes “continues to surpass agency estimates by millions,” Watts said during a webinar presented by Health Affairs.”
    • “Although the involvement of private equity (PE) frequently raises questions in healthcare, some smaller providers might struggle to effectively engage with the IDR process if not for that support, panelists noted during a discussion as part of the webinar.”
  • Per Govexec,
    • “Dr. Kevin Rhodes has received Senate confirmation to lead the White House’s Office of Federal Procurement Policy, a move that designates him as the first permanent leader of that component in six years.
    • “Senate lawmakers approved the nomination of Rhodes on Thursday, five months after the White House announced him as President Trump’s choice for the role.
    • “Rhodes has been acting as a senior adviser to OFPP’s parent agency, the Office of Management and Budget, since February with the responsibility of leading the Trump administration’s push to restructure federal procurement.
    • “All but one section of the Federal Acquisition Regulation has been overhauled since then. OFPP and the FAR Council have collaborated on the effort and gradually rolled out the changes.”

From the public health and medical / Rx research front,

  • The Wall Street Journal reports,
    • “Immunologists Mary E. Brunkow, Fred Ramsdell and Shimon Sakaguchi were awarded the Nobel Prize in Physiology or Medicine for uncovering a process that prevents the immune system from attacking our own tissues, called peripheral immune tolerance. The work unlocked a new field of research and potential therapies.
    • “The trio identified a core feature of how the immune system functions and keeps itself in-check: regulatory T-cells. They prevent other immune cells from harming our own bodies and developing autoimmune conditions including Type 1 diabetes and rheumatoid arthritis. Based on this fundamental knowledge, clinical trials are ongoing to test therapies for autoimmune diseases, cancer and post-organ transplantation.
    • “Their discoveries have been decisive for our understanding of how the immune system functions and why we do not all develop serious autoimmune diseases,” said Olle Kämpe, chair of the Nobel Committee on Monday.
    • “Brunkow is now based at the Institute for Systems Biology in Seattle, Ramsdell at the San Francisco and Seattle-based Sonoma Biotherapeutics, while Sakaguchi is a distinguished professor at Japan’s Osaka University. The group will share the 11 million Swedish kronor, or roughly $1.1 million, prize.”
  • Heath Day reports,
    • “An alarming trend is emerging on America’s roads.
    • “More drivers killed in crashes are testing positive for THC, the active ingredient in marijuana.
    • Researchers in Ohio reviewed autopsy records from 246 drivers killed in crashes between 2019 and 2024.
    • “They found that 41.9% had THC in their system — at levels far above what most states consider impairment.
    • “The average blood level was 30.7 nanograms per milliliter. By comparison, many states set legal limits between just 2 and 5.
    • “The researchers say that means the drivers likely used marijuana close to the time of the crash. The study also found the high rate of THC positivity stayed consistent over six years and didn’t change when recreational pot became legal in Ohio in 2023.
    • “The lead author says from a public health standpoint, there hasn’t been enough attention on the dangers of legalization.”
  • and
    • “When someone has whooping cough, the sound can be unmistakable: A deep, gasping “whoop” as they struggle to catch their breath between fits of coughing. 
    • “Now, this once-rare illness, also known as pertussis, is making a comeback across the United States.
    • “Cases have now surpassed pre-pandemic levels, and while the disease can be exhausting for adults, experts warn it can be life-threatening for newborns and infants, especially those under two months old.
    • “Most babies in this age group who contract pertussis are hospitalized, according to a report published Oct. 3 in the journal Pediatrics.”
    • “Pertussis symptoms are different in infants,” said lead author Dr. Caitlin Li, an infectious diseases specialist at Ann & Robert H. Lurie Children’s Hospital of Chicago and assistant professor of pediatrics at Northwestern University Feinberg School of Medicine. “The characteristic whooping cough may be absent, but apnea, or breathing interruption, is common.” * * *
    • “Given that infants are at high risk for complications, pertussis vaccination of mothers during pregnancy is critical, as it protects newborns against this potentially fatal illness,” Li explained in a news release. “Widespread vaccination is also an important tool to protect everyone.”
  • The American Cancer Society lets health plans know “how to address cancer care gaps to improve cost and clinical outcomes at every step.”
  • Genetic Engineering and Biotechnology News discusses the largest genetic map of human metabolism ever created.
    • “The contribution of genetics to the variability in people’s metabolism has remained largely unknown. This is, in part, because genetic studies of human metabolism have been limited in scale and allelic breadth. Now, the largest genetic map of human metabolism has been created, revealing new insights on the role of metabolites in health and disease and creating a blueprint for further research.
    • “This work is published in Nature Genetics in the paper, “A genetic map of human metabolism across the allele frequency spectrum.
  • Per Healio,
    • “Adults with obesity who reported more intense tastes while receiving semaglutide or tirzepatide had a higher likelihood for increased satiety and decreased appetite and food cravings, according to a presenter.
    • “In a cross-sectional study presented at the European Association for the Study of Diabetes annual meeting and published in Diabetes, Obesity and Metabolism, researchers surveyed adults with obesity who were using semaglutide (Ozempic/Wegovy, Novo Nordisk) or tirzepatide (Mounjaro, Eli Lilly) and asked about changes in their appetite, satiety and sensory perception after starting an incretin-based therapy. Researchers found some adults reported increased intensity of sweet and salty tastes, and increased intensity of both types of tastes were tied with greater odds for increased satiety. However, change in taste did not affect weight-related outcomes.
    • “This means that taste perception changes may serve as markers of appetite response rather than predictors of treatment success,” Othmar Moser, PhD, professor in the division of endocrinology and diabetology in the department of internal medicine at Medical University of Graz in Austria and in the division of exercise physiology and metabolism at the Institute for Sports Science at University of Bayreuth in Germany, told Healio. “The findings highlight the nuanced ways incretin therapies act beyond pure metabolic regulation.”
  • BioPharma Dive relates,
    • “An experimental weight loss drug from Skye Bioscience failed a mid-stage clinical trial, wiping out most of the San Diego biotechnology company’s market value.
    • “Skye said Monday its therapy, an obesity medicine targeting a kind of cannabinoid receptor, didn’t significantly lower weight loss compared to a placebo after 26 weeks of treatment. Patients who received Skye’s drug, nimacimab, achieved only 1.5% weight loss, compared to less than 0.3% for placebo recipients. In a statement, Skye blamed the findings on the dose it chose for the study, arguing an analysis found that a 200 milligram weekly injection is “suboptimal as a monotherapy.”
    • “Nimacimab fared better when paired with semaglutide, the active ingredient in Novo Nordisk’s Wegovy, and tested against semaglutide alone. In that study cohort, patients on the combination lost just over 13% of their body weight, compared to more than 10% for those only on semaglutide. Skye said the findings support the potential for future studies evaluating combinations of nimacimab and other so-called incretin-based therapies widely used for weight loss.”

From the U.S. healthcare business front,

  • Modern Healthcare reports,
    • “Physician pay is increasing, largely through sign-on bonuses, but higher salaries alone often aren’t enough to retain physicians or attract top-tier talent.
    • “Advanced technology, paid time off and compensation for on-call requirements are just a few of the demands incoming physicians have for potential employers, according to respondents to Modern Healthcare’s 2025 Physician Compensation Survey. This year’s results reflect data from nine staffing and consulting firms, indicating that the trend of rising physician compensation isn’t likely to slow down anytime soon.
    • “If you’re employing physicians or any staff, you’re probably going to have to pay higher wages, particularly now,” said Chad Stutelberg, a managing director at consulting firm Gallagher. “The physicians have more leverage.”
  • Beckers Hospital Review notes,
    • “Rite Aid has closed its final 89 stores, bringing an end to operations after decades as one of the largest pharmacy chains in the U.S.
    • “All Rite Aid stores have now closed. We thank our loyal customers for their many years of support,” the company said on its website.
    • “The company filed for Chapter 11 bankruptcy protection in October 2023 and shuttered 154 stores. It filed again in May after failing to recover. 
    • “The pharmacy chain once operated more than 5,000 stores at its peak and employed about 45,000 people in 2023, including 6,100 pharmacists.”
  • The Washington Post reports,
    • “Popular weight-loss drugs Ozempic and Wegovy are now being sold at below sticker prices at Costco pharmacies across the United States, as rising obesity levels boost demand for the drugs and cheaper copycat versions.
    • “Novo Nordisk’s U.S. president, David Moore, told NBC News that the drugmaker’s push into Costco is a way to “offer the real, authentic Wegovy and Ozempic where patients seek care.”
    • “It comes as the Danish pharmaceutical giant seeks to head off competition from rival manufacturers, after sales of copycat drugs from compound pharmacies soared amid national shortages.
    • “The drugs, which mimic a natural hormone to curb hunger and make people feel full for longer, will be available on prescription to Costco members for an out-of-pocket price of $499 a month.
    • “The current list price of Ozempic is nearly $1,000 per injectable pen while Wegovy is around $1,350.”
  • Beckers Payer Issues tells us nine things to know about confusion among older adults before Medicare open enrollment.
  • Per Fierce Healthcare,
    • “Online therapy provider Talkspace acquired Wisdo Health to integrate peer support and coaching into its mental health services.
    • Wisdo is an artificial-intelligence-powered coaching and peer-to-peer support platform that gives users 24/7 access to trained peers, moderated communities and group coaching to help combat social isolation and loneliness.
    • “The acquisition will enhance Talkspace’s service line, offering lower-acuity options and complementing existing therapy and psychiatry services. 
    • “Financial terms of the acquisition were not disclosed.”
  • and
    • “Health data company CertifyOS has unveiled its new Provider Hub platform, technology that allows insurers greater insight into key data across their provider network.
    • “Through Provider Hub, payers can tap into unified and real-time provider data that are critical to operations. The company said in an announcement that these data have traditionally been managed in siloed systems, spreadsheets and outdated tools that hinder effective use.
    • “When payers lack access to complete or usable provider data, it can have a negative impact on a slew of key business functions, Certify said, including compliance with key regulations, member experience and claims processing. 
    • “The Provider Hub takes in and cleanses, normalizes and validates key provider data from multiple sources, including credentialing, directories, claims and other internal systems. The platform leans on artificial intelligence to support this effort, according to the announcement.”
  • Per Beckers Health IT,
    • “AI-powered customer engagement company Qualtrics has agreed to acquire healthcare market research firm Press Ganey for $6.75 billion, the Financial Times reported Oct. 6.
    • “Press Ganey, currently owned by investor Ares Management and private equity firm Leonard Green & Partners, conducts surveys on behalf of over 41,000 health systems and other healthcare organizations.
    • “The deal would give Qualtrics, which deploys AI for such uses as ordering food online and rescheduling hotel stays and flights, a foothold in healthcare alongside other tech players including Oracle and Palantir, the Times reported.”

Weekend Update

  • Roll Call reported on October 3, 2025,
    • “Senators left town Friday afternoon for the weekend after another set of unsuccessful votes to reopen the government, but a renewed flurry of bipartisan discussions on the floor provided at least a faint glimmer of hope that agreement could be reached.
    • “Republicans involved in the talks said there’s a deal to be had on a stopgap funding bill with a sidecar commitment on two fronts.
    • “One is to take up legislation dealing with expiring health insurance subsidies by Nov. 1, when open enrollment begins. The other is to pass regular, bipartisan full-year appropriations bills that would make it harder for President Donald Trump and White House budget director Russ Vought to arbitrarily cut programs they don’t like.”
  • Govexec adds,
    • “Even as the shutdown drags into its second week, federal workers will not experience any immediate delays to their pay. The next official pay date, in which most feds would be missing parts of their normal paychecks, is not until mid-October, though the exact timing will depend on which federal entity disburses their salaries. Paychecks otherwise set to hit accounts at the end of the month would be delayed in their entirety, if the shutdown continues until that point.”
  • The House of Representatives announced on October 2, 2025, that “Pursuant to clause 13 of Rule I, the Chair announced the Speaker’s designation of the period from Tuesday, October 7, 2025, through Monday, October 13, 2025, as a “district work period.” October 13 is a federal holiday.
  • The U.S. Supreme Court begins its October 2025 term today.
  • NPR Shots lets us know that as of October 2, 2025, the acting CDC Director has not adopted the September 18-19 Covid-19 vaccine recommendations of the Advisory Committee on Immunization Practices.
    • “The [final actions] are necessary for the federal Vaccines for Children Program to start shipping the vaccines to doctors, health departments and others. About half of U.S. kids are eligible for shots through the program.” * * *
    • “The CDC’s delay has also forced adults seeking vaccination to continue navigating an often confusing and frustrating patchwork of state rules that have, in many places, made it difficult if not impossible for them to get vaccinated too. Even though many states have taken steps to make it easier for people to get the vaccines, some still require prescriptions, and some pharmacists are still turning away people who can’t document they meet new eligibility requirements.”
  • Per Fierce Pharma,
    • “After reacquiring the rights to its non-vaccine flu preventative last year, Cidara Therapeutics has secured federal support to develop and produce the candidate, dubbed CD388, in the U.S.
    • “The Department of Health and Human Services’ (HHS’) Biomedical Advanced Research and Development Authority (BARDA) has graced Cidara and its flu asset with an award worth up to $339 million, Cidara said Thursday. The deal includes confirmed funding of $58 million over two years, which will be used to stand up domestic manufacturing for CD388 in the U.S. and help Cidara establish its “initial commercial supply chain,” the company explained in an Oct. 2 press release.
    • “That initial tranche of cash will also fuel a clinical trial comparing a higher-concentration formulation and different presentations of CD388, help the company further characterize the asset’s activity against pandemic flu strains in nonclinical models and kick off development of trial protocols for expanded populations, Cidara said.”
  • and
    • “Friday, the regulator unveiled a new pilot prioritization program that aims to speed up approval review times for generic drug makers that test and manufacture their products in the U.S.
    • “Specifically, generics companies that file abbreviated new drug applications that meet the “FDA’s domestic production and bioequivalence testing requirements—including the use of “exclusively domestic sources for API”—will become eligible for priority review, the agency explained in an Oct. 3 release.
    • “The pilot program aligns with the onshoring ethos that has defined many of the administration’s pharma-related policy maneuvers this year.”
  • HR Dive tells us that last week the Labor Department clarified overtime pay requirements in new opinion letters. The second batch of wage-and-hour letters released during the second Trump administration addressed a joint employer scenario as well as firefighter emergency pay.”

From the public health and medical / Rx research front,

  • The New York Times explains why brittle bones aren’t just a woman’s problem. More men are now living long enough to develop osteoporosis. But few are aware of the risk, and fewer still are screened and treated.
  • Per Medscape,
    • “Oral semaglutide showed similar reductions in cardiovascular events in patients with type 2 diabetes (T2D) and cardiovascular or chronic kidney disease with and without peripheral artery disease (PAD), according to a new SOUL trial subanalysis. Overall, however, patients without PAD experienced the most benefit.
    • “Major adverse limb events (MALE), including both acute limb ischemia and chronic limb ischemia, were also lower in patients treated with oral semaglutide than placebo, regardless of whether patients had PAD or not.
    • “PAD is common and significantly increases risk of cardiovascular and limb events, yet [it] is an under-recognized comorbidity in patients with type 2 diabetes,” said Matthew Cavender, MD, interventional cardiologist at the University of North Carolina at Chapel Hill, who presented the data at the European Association for the Study of Diabetes (EASD) 2025 Annual Meeting.
    • “Therapeutic options that reduce cardiovascular and limb events are limited, and there’s an urgent need for novel strategies to improve outcomes in this vulnerable population,” he said.”
  • and
    • “In the prevention of kidney disease in patients with type 2 diabetes (T2D) and mildly reduced kidney function, SGLT2 inhibitors (SGLT2i) showed a stronger benefit than GLP-1 receptor agonists (RA) and other diabetes drugs, however, an SGLT2i/GLP-1 combination showed greater efficacy than either therapy alone, results of a new study showed.
    • “Importantly, the utilization of a clinical risk score could further improve the treatment efficacy by assigning patients to the most appropriate therapy, the study authors noted.
    • “Our take-home message is that SGLT2 inhibitors give better kidney protection than GLP-1 receptor agonists, regardless of the individual, and clinical risk scores could help identify high-risk individuals who might benefit from SGLT2/GLP-1 combination treatment,” first author Thijs Jansz, MD, University of Exeter, Exeter, England, told Medscape Medical News.
    • “The study was presented at the European Association for the Study of Diabetes (EASD) 2025 Annual Meeting.”
  • and
    • “At the 28th World Congress of the International Federation for the Surgery of Obesity and Metabolic Disorders (IFSO 2025), Marianela Aguirre Ackermann, MD, presented that limited awareness, stigma, and time constraints during consultations prevent internists from discussing metabolic and bariatric surgery with patients, leaving the vast majority of individuals with obesity without appropriate care.
    • “Aguirre Ackermann is a specialist in diabetes and internal medicine at the Endocrinology, Obesity, and Nutrition Center (Centro CIEN) in Buenos Aires, Argentina.
    • “Speaking with Medscape’s Spanish edition, Aguirre Ackerman highlighted TheLancet Commission’s framework, which distinguishes “preclinical” from “clinical” obesity, as a tool to bridge the gap between consultation and surgery.
    • “It provides a clear definition and emphasizes the health impact of excess weight,” she stated.
    • “A cultural shift is needed; we need to look at the patient differently. In other words, the patient is no longer a scale, no longer an excess of kilograms, but rather an excess of adiposity that can cause disease,” she said.”

From the U.S. healthcare business front,

  • The New York Times points out how private equity oversees the ethics of drug research. Many drug trials are vetted by companies with ties to the drugmakers, raising concerns about conflicts of interest and patient safety.
  • Medscape discusses the potential role of oral GLP-1 drugs in weight management.
    • Only a fraction of the people who could benefit from taking obesity medications are currently doing so. A wider array of affordable, effective treatment options could help more people. Could oral GLP-1s be one of them? Yes, experts say, but there are some caveats [, which are discussed in the article].
  • Per MedTech Dive,
    • “Boston Scientific aims to become the market leader in the electrophysiology category as the device maker looks to pulsed field ablation to drive growth. 
    • “Our new vision is not just to be a leader in pulsed field ablation, but to be a leader in overall electrophysiology,” Nick Spadea-Anello, Boston Scientific’s global president of electrophysiology, said at a Tuesday investor meeting.”
  • and
    • “Boston Scientific is working on a new version of its Watchman device, company leaders said at a Tuesday investor presentation. 
    • “Angelo De Rosa, global president of Boston Scientific’s Watchman business, said the company is working on a version of Watchman that “will provide an answer, stability and unprecedented adaptability to each possible anatomy.”
    • “The company plans to begin enrollment next year for an upcoming U.S. investigational device exemption study and hopes to launch the device in the second half of 2027 or early 2028.”  

Cybersecurity Saturday

From the cybersecurity policy front,

  • Federal News Network reports,
    • “The Cybersecurity and Infrastructure Security Agency typically marks October’s awareness month with a range of public engagements and outreach campaigns. But under the ongoing government shutdown, CISA has furloughed nearly two-thirds of its staff and curtailed most public communication.
    • “CISA is not actively managing its website under the shutdown. But the agency did establish a landing webpage for cybersecurity awareness month prior to the shutdown, detailing the campaign’s theme and linking to a toolkit.
    • “CISA Director of Public Affairs Marci McCarthy said, “CISA remains fully committed to safeguarding the nation’s critical infrastructure,” as part of a statement.” * * *
    • “Chris Cummiskey, a former state chief information officer and former chief management officer at DHS, said CISA typically retains enough employees to staff the agency’s watch floor, maintain technology that monitors federal networks for cyber threats, and collaborate with cyber defenders at other federal organizations, like U.S. Cyber Command.
    • “But if a major cyber incident were to occur, CISA may not have enough staff immediately on hand to manage the event.
    • “A key concern is, do you need to start recalling people?” Cummiskey said. “You probably wouldn’t have the onsite capacity to cover a major exploit without the additional help.”
    • “In addition to the shutdown, key privacy and liability protections under the Cybersecurity Information Sharing Act of 2015 expired on Sept. 30. Those protections had been pivotal to encouraging the private companies to share cyber threat data with each other and with government agencies, including CISA.
    • “Cyber experts say companies may be more hesitant to share information about new cyber threats and vulnerabilities without the statute’s protections.”
  • Cybersecurity Dive adds,
    • “Michael Daniel, president of the Cyber Threat Alliance, an information-sharing group, predicted that some companies will “suspend some sharing activities with the government,” but he added that a lot will depend on “each company’s risk tolerance.”
    • “I think some collaboration will continue,” he said, “but likely at reduced levels and requiring more human oversight.”
    • “Ari Schwartz, managing director of cybersecurity services at the law firm Venable, said, “There will just be many more lawyers involved, and it will all go slower, particularly new sharing agreements.” Venable has advised clients on what to consider when establishing such agreements.
    • “As for companies sharing information with each other, that likely will continue for now because of a lack of near-term concern about antitrust investigations, Daniel said. But companies’ attitudes could change if the program isn’t reauthorized.”
  • The National Institute of Standards announced on September 29, 2025,
    • “As part of ongoing efforts to strengthen the protections for securing controlled unclassified information (CUI) in nonfederal systems [which includes FEHB and PSHB claims data], NIST has released the following drafts for comment:
    • SP 800-172r3 (Revision 3) fpd (final public draft)Enhanced Security Requirements for Protecting Controlled Unclassified Information, provides new enhanced security requirements that support cyber resiliency objectives, focus on protecting CUI, and are consistent with the source controls in SP 800-53r5.
    • SP 800-172Ar3 ipd (initial public draft)Assessing Enhanced Security Requirements for Controlled Unclassified Information, provides a set of assessment procedures for the enhanced security requirements. These procedures are based on the source assessment procedures in SP 800-53Ar5.” * * *
    • “A public comment period will be open from September 29 through November 14, 2025. Reviewers should submit comments on all or parts of the drafts to 800-171comments@list.nist.gov.”
  • Cybersecurity Dive tells us,
    • “Barely any U.S. defense contractors say they’re fully prepared to comply with the Department of Defense’s new cybersecurity assessment program.
    • “Only 1% of companies say they’re completely ready to be assessed through the Cybersecurity Maturity Model Certification (CMMC) program, which takes effect on Nov. 10, according to a report that the managed security provider CyberSheath published on Wednesday.
    • “The percentage of respondents expressing confidence in their readiness has dropped over the past two years.”

From the cybersecurity vulnerabilities and breaches front,

  • NextGov/FCW reports on September 29, 2025,
    • “A “widespread cybersecurity incident” at the Federal Emergency Management Agency allowed hackers to make off with employee data from both the disaster management office and U.S. Customs and Border Protection, according to a screenshot of an incident overview presentation obtained by Nextgov/FCW.
    • “The hack is also suspected to have later triggered the dismissal of two dozen Federal Emergency Management Agency technology employees announced late last month, according to internal meeting notes and a person familiar with the matter.
    • “The initial compromise began June 22, when hackers accessed Citrix virtual desktop infrastructure inside FEMA using compromised login credentials. Data was exfiltrated from Region 6 servers, the image says. That FEMA region services Arkansas, Louisiana, New Mexico, Oklahoma and Texas, as well as nearly 70 tribal nations.” * * *
    • “DHS security operations staff were notified of the breach on July 7, the screenshot adds. On July 14, the unnamed threat actor used an account with high-level access and attempted to install virtual networking software that could allow them to extract information. Initial remediation steps were taken on July 16. 
    • “On Sept. 5, additional remediation actions were taken, including changing FEMA Zscaler policies and blocking certain websites, the screenshot says. Those actions were previously reported by Nextgov/FCW.”
  • Following up on last Saturday’s post about the Cisco KVEs, Cybersecurity Dive lets us know,
    • “Nearly 50,000 Cisco firewall devices with recently disclosed vulnerabilities are connected to the internet, according to new data.
    • Statistics from the Shadowserver Foundation illustrate the extent of the world’s exposure to the three flaws in Cisco’s Adaptive Security Appliance devices and Firepower Threat Defense devices, which earned a rare emergency patching directive from the Cybersecurity and Infrastructure Security Agency (CISA) after the Sept. 25 disclosure.
    • “The United States has by far the most devices that have not been patched to block exploitation of the flaws, with Shadowserver tallying more than 19,000 vulnerable U.S. devices. The U.K. ranks second, with more than 2,700 vulnerable devices, followed by Japan, Germany and Russia. Other European countries have fewer than 1,000 vulnerable devices each.
    • “Shadowserver’s records will reveal how quickly different countries are reducing their exposure as the organization continues collecting data in the coming days and weeks.
    • “A sophisticated threat actor has been using two of the new Cisco flaws, CVE-2025-20362 and CVE-2025-20333, in a stealthy cyberattack campaign that has breached multiple federal agencies and other organizations worldwide. Both vulnerabilities involve improper validation of HTTPS requests, which could allow Cisco firewalls to accept malicious requests that bypass authentication. CVE-2025-20362 could allow hackers to access restricted VPN-related URLs, while CVE-2025-20333 could let intruders run arbitrary code as root.”
  • Cyberscoop points out,
    • “Red Hat on Thursday [October, 2, 2025] confirmed an attacker gained access to and stole data from a GitLab instance used by its consulting team, exposing some customer data. The open-source software company, a subsidiary of IBM, said the breach is contained and an investigation into the attack is underway. 
    • “Upon detection, we promptly launched a thorough investigation, removed the unauthorized party’s access, isolated the instance, and contacted the appropriate authorities,” Red Hat said in a security update. “Our investigation, which is ongoing, found that an unauthorized third party had accessed and copied some data from this instance.”
    • “Red Hat said the compromised GitLab instance contained work related to consulting engagements with some customers, including project specifications, example code snippets and internal communications about the consulting services. 
    • “This GitLab instance typically does not house sensitive personal data,” Red Hat said. “While our analysis remains ongoing, we have not identified sensitive personal data within the impacted data at this time.”
  • Dark Reading informs us,
    • “The month-long outage for luxury car maker Jaguar Land Rover appears to be at an end, with the company working through a “controlled, phased restart” of its manufacturing operations this week, following a massive cyberattack that forced the company to shut down its systems.
    • “JLR said on Sept. 2 that it had “proactively” shut down operations following a cyber incident, initially stating that customer data did not seem to be stolen, but revising that statement a week later. JLR, a subsidiary of Tata Motors, likely suffered $50 million to $70 million in lost revenue per week, with the total cost of the incident estimated at a staggering $1.7 billion to $2.4 billion.
    • “The attack, and its vast impact, should be a warning for companies, says Chris Gibson, executive director of the Forum of Incident Response and Security Teams (FIRST).
    • “The outage “highlights that even large corporations with substantial resources can be completely disrupted and that critical industries may be more vulnerable than previously thought,” he says. “This was far beyond data theft; it was a complete operational outage.”
  • Security Week adds,
    • “Japanese brewing giant Asahi Group Holdings on Monday [September 29, 2025] announced that its operations in the country have been disrupted by a cyberattack.
    • “The incident, the company said, resulted in system failures that affected orders and shipments at all its subsidiaries in the country, as well as call center operations, customer service desks included.
    • “Reuters reported that production at some of Asahi’s 30 domestic factories has been suspended due to the cyberattack.
    • “At this time, there has been no confirmed leakage of personal information or customer data to external parties,” the company said in a Monday notice.
    • “Asahi said it is investigating the attack and working on restoring the affected systems but could not provide an estimated timeline for recovery.
    • “The system failure is limited to our operations within Japan,” it said.
    • “The company has not disclosed the nature of the cyberattack it fell victim to, but the system-wide outage could indicate that file-encrypting ransomware might have been used.”

From the ransomware front,

  • Cybersecurity Dive reports,
    • “Corporate executives are being targeted in an email-based extortion campaign by a threat actor claiming affiliation with the notorious Clop ransomware gang, according to security researchers from Google Threat Intelligence Group and Kroll. 
    • “The hacker claims to have data stolen from breached Oracle E-Business Suite applications and has been demanding payment from various corporate executives, according to a LinkedIn post from Austin Larsen, principal threat analyst at GTIG.
    • “While researchers have not been able to substantiate the claims of a data breach, they have confirmed important links to a financially motivated threat group tracked under the name FIN11, which has prior associations with Clop.” 
  • Cyberscoop provides us with “the email Clop attackers sent to Oracle customers. The emails, which are littered with broken English, aim to instill fear, apply pressure, threaten public exposure and seek negotiation for a ransom payment.”
  • Dark Reading adds,
    • After announcing its farewell last month, the cyber extortion group known as Scattered Lapsus$ Hunters returned on Friday with a website featuring stolen Salesforce data and a list of dozens of alleged victims.
    • Scattered Lapsus$ Hunters is an apparent combination of the Scattered Spider, Lapsus$, and ShinyHunters cybercriminal groups, which first emerged over the summer in a public Telegram channel. However, just a few weeks later, the collective published a goodbye letter on Telegram and the Dark Web marketplace BreachForums, saying the three groups, as well as other threat actors, had “decided to go dark.”
    • “But Scattered Lapsus$ Hunters burst back into the limelight this week with a Dark Web leak site devoted to the recent spate of Salesforce data thefts; one of the two distinct campaigns targeting Salesforce environments recently has been attributed to a threat group tracked by Google as UNC6040, which has claimed to be ShinyHunters in its extortion attempts.
    • “According to Google, UNC6040 actors used vishing calls to convince IT support personnel at targeted organizations to grant them access to or credentials for the organizations’ Salesforce environments. Mandiant researchers this week said the threat actors have impersonated third-party vendors in the vishing calls and had also targeted users in victim organizations with elevated access to other SaaS applications.’
  • The American Hospital Association points out,
    • “A Health-ISAC (Information Sharing and Analysis Center) bulletin released Oct. 1 warns of a recently released LockBit 5.0 ransomware variant that poses a threat to health care and other sectors. LockBit 5.0 is the latest version of the ransomware-as-a-service group that has previously attacked hospitals and other organizations in the U.S. and abroad. The notice said the new variant directly targets virtual environments and has improved and enhanced technical capabilities, evasion techniques and affiliate engagement. The variant is known to target Windows, Linux and VMware ESXi software. Health-ISAC said the new variant’s technical capabilities make it faster, more flexible for affiliates and harder for security to detect and analyze. LockBit was disrupted by authorities last year before resurfacing last month.
    • “This is a very technical bulletin, but it’s important to note that it addresses a new version of a well-known ransomware,” said Scott Gee, AHA deputy national advisor for cybersecurity and risk. “Hospitals should ensure that they have defensive measures in place and that those measures are tuned and working properly.”
  • HackRead reports on September 29,
    • “The Medusa ransomware group is claiming responsibility for a ransomware attack on Comcast Corporation, a global media and technology company best known for its broadband, television, and film businesses.
    • “According to the group’s dark web leak site, they exfiltrated 834.4 gigabytes of data and are demanding $1.2 million for interested buyers to download it. The same sum has been set as ransom for Comcast if the company wants the data deleted rather than leaked or sold.
    • “To back its claims, Medusa has posted around 20 screenshots allegedly showing internal Comcast files. The group also shared a massive file listing of 167,121 entries, suggesting access to actuarial reports, product management data, insurance modelling scripts, and claim analytics.” * * *
    • “Medusa ransomware is known for publishing file listings and partial screenshots as proof of compromise while holding back the bulk of the data to increase ransom pressure. In this case, the nature of the files points toward actuarial and financial datasets, some of which appear to involve insurance calculations, customer data processing, and claim management systems.”
  • HelpNetSecurity provides us background about and advice on how to avoid Akira ransomware.
  • Wired notes that “Google has launched a new AI-based protection in Drive for desktop that can shut down a [ransomware] attack before it spreads—but its benefits have their limits.”

From the cybersecurity defenses front,

  • Per ISACA,
    • “Cybersecurity professionals from around the world recently weighed in on some of the key findings from ISACA’s latest State of Cybersecurity survey report. Aparna Achanta, security leader, IBM (US); Simon Backwell, head of information security, Benefex (UK); Donavan Cheah, senior cybersecurity consultant, Thales (Singapore); Jenai Marinkovic, vCISO/CTO, Tiro Security, and CEO & chairman of the board, GRCIE (US); Kannammal Gopalakrishnan, cybersecurity and GRC professional (India), and Carlos Portuguez, Sr. Director BISO, Concentrix (Costa Rica)—all of whom are also members of ISACA’s Emerging Trends Working Group—reflect on how these stats show up for them in the profession.”
  • and
    • “Phishing has escalated beyond masquerading techniques. Traditional attacks depended on typos, being in a rush and not so well-disguised social engineering. But hackers today use generative AI, such as WormGPT or FraudGPT, and even deepfakes, to create perfect messages with contextual background that can effortlessly be mixed with everyday corporate messages. Cofense has noted that it receives an AI-enhanced malicious email every 42 seconds, with that pace expected to accelerate in the months to come. This hypergrowth is an indication that phishing is not an outlying issue anymore but a mainstream cyber-crime, now with AI-driven precision. 
    • “The next pivot is neuro-phishing, which can tie in the details of biometric and psycho-physiological indicators, like the EEG, micro-hesitation spikes, blink frequency, and the focus of the eyes, to see the response of the user in real-time and work a different approach. Previous and extensive studies have already established the reliability of finding recognition and stress using the EEG, when users are stimulated with phishing. This is not passive baiting anymore, but a dynamic, cognitive feedback loop, which transforms human users into interactive targets.”
    • The article offers advice on creating resilience against neuro-phishing.
  • Dark Reading adds,
    • “Email security has long dominated the enterprise security conversation — and rightfully so. It remains a key vector for phishing, credential theft, and social engineering. But in 2025, the threat landscape has shifted. Quietly yet decisively, attackers increasingly are bypassing the inbox and expanding their reach across multiple channels. 
    • “Recent data from TechMagic shows that 41% of phishing incidents now employ multichannel tactics, including SMS (smishing), voice calls (vishing), and QR codes (quishing). The trend is clear: While email still matters, adversaries are shifting to mobile-first platforms like text, iMessage, WhatsApp, and social direct messages. These attacks are harder to spot, more difficult to control, and more likely to succeed, because they target the most vulnerable point in the chain: the human behind the screen.
    • “To address this growing threat to mobile platforms, new security approaches are emerging that leverage AI-driven defenses to identify and prevent social engineering attacks in real-time. By training large language models (LLMs) to understand the content and intent behind messages, these systems can flag suspicious activity and enforce protective measures before users fall victim. Whether it’s a text message posing as IT support or impersonating a vendor, these next-generation solutions focus on stopping threats at the human layer — not just at the device.”
  • Infosecurity Magazine explains how “AI-Generated Code Used in Phishing Campaign Blocked by Microsoft.”
  • Per CISO Online,
    • “A surge in vulnerabilities and exploits leaving overloaded security teams with little recourse but to embrace risk-based approaches to patching what they can.
    • “Enterprise attack surfaces continue to expand rapidly, with more than 20,000 new vulnerabilities disclosed in the first half of 2025, straining already hard-pressed security teams.
    • “Nearly 35% (6,992) of these vulnerabilities have publicly available exploit code, according to the Global Threat Intelligence Index study by threat intel firm Flashpoint.
    • “The volume of disclosed vulnerabilities has more than tripled while the amount of exploit code has more than doubled since the end of February 2025 alone.
    • “These increases make it no longer feasible for most organizations to triage, remediate, or mitigate every vulnerability, Flashpoint argues, suggesting enterprises need to apply a risk-based patching framework. But some experts quizzed by CSO went further — arguing a complete operational overhaul of vulnerability management practices is needed.
    • The article delves into that approach.
  • Per the National Institute of Standards,
    • “The NIST National Cybersecurity Center of Excellence (NCCoE) has finalized a guide, NIST Special Publication (SP) 1334, Reducing the Cybersecurity Risks of Portable Storage Media in Operational Technology (OT) Environments, to help organizations protect their industrial control systems from cybersecurity threats when using removable media devices.
    • “Portable storage media devices, like USB flash drives, are commonly used to transfer data between computers. However, using them in OT environments and industrial control systems, such as those used in power plants or manufacturing facilities, can pose a cybersecurity risk. If a USB device is infected with malware, it can spread to the industrial control system and cause problems, such as disrupting operations or compromising safety.
    • “This NCCoE resource suggests implementing physical and technical controls to limit access to these devices and ensure they are used securely.”
  • Here is a link to Dark Readings’ CISO Corner.