FEHBlog

Thursday Report

From Washington, DC,

  • According to the House of Representatives and Senate press galleries, each body will assemble before noon to adjourn the 118th Congress sine die and at noon will convene for the start of the 119th Congress.
  • Govexec tells us,
    • “Current federal employees, retirees and others impacted by widespread breach of personal data maintained by the Office of Personnel Management took advantage of only a small portion of the money made available in a settlement agreement following the 2015 hack. 
    • “Plaintiffs in the class action lawsuit reached a settlement in 2022 with the government that made $63 million available for those who could demonstrate financial hardship as a result of the breach. A federal judge closed out the case last month after OPM and the Treasury Department doled out just $4.8 million to just more than 5,000 individuals. The remaining $58.2 million is set to go back to the Treasury on Thursday, according to court documents last month.” 

From the public health and medical research front,

  • The Washington Post reports, “More children are getting kidney stones. Experts think it’s their diet.”
    • Some research suggests that genetic predisposition may play a role, but experts say the increase more likely reflects dietary habits and lifestyle.
    • “A North Carolina doctor detected a potential culprit: salt-laden diets. Sodium intake has increased significantly among children in the past few decades.
    • “There is so much added salt to the American diet today, and when the kidney is excreting the sodium, it pulls calcium with it and increases the risk of calcium-based stones,” John S. Wiener, a pediatric urologist at Duke Health, said.”
  • The American Medical Association discusses “Raw milk: Questions patients may have and how to answer.” Econtalk host Russ Roberts chats with Brown University economist Emily Oster about raw milk and similar public health issues in his latest podcast.
  • HealthDay lets us know,
    •  “Alzheimer’s disease experts have updated their diagnosis guidelines for the first time in more than 20 years, laying out how family doctors and brain specialists can best detect dementia.
    • “The guidelines call for the use of three general criteria to assess a person’s brain health, according to a report published Dec. 23, 2024, in the journal Alzheimer’s & Dementia:
      • “The patient’s overall level of cognitive impairment
      • “Specific symptoms they’re suffering, which can involve memory, reasoning, language or mood
      • “Brain diseases most likely to be causing these symptoms
    • “These three areas of diagnosis were intentionally left broad, so that new tests can be incorporated into the guidelines as researchers learn more about dementia and Alzheimer’s, Dr. Alireza Atri, a lecturer on neurology at Harvard Medical School, said in a news release from the Alzheimer’s Association.”
  • Per National Institutes of Health news releases,
    • “Based on new brain mapping research funded by the National Institutes of Health (NIH), scientists have discovered that not all cell types in the brain age in the same way. They found that some cells, such as a small group of hormone-controlling cells, may undergo more age-related changes in genetic activity than others. The results, published in Nature, support the idea that some cells are more sensitive to the aging process and aging brain disorders than others.
    • “Aging is the most important risk factor for Alzheimer’s disease and many other devastating brain disorders. These results provide a highly detailed map for which brain cells may be most affected by aging,” said Richard J. Hodes, M.D., director of NIH’s National Institute on Aging. “This new map may fundamentally alter the way scientists think about how aging affects the brain and also provide a guide for developing new treatments for aging-related brain diseases.”
    • “Scientists used advanced genetic analysis tools to study individual cells in the brains of 2-month-old “young” and 18-month-old “aged” mice. For each age, researchers analyzed the genetic activity of a variety of cell types located in 16 different broad regions — constituting 35% of the total volume of a mouse brain.”
  • and
    • ‘In a small clinical trial, a CAR T-cell therapy—a type of immunotherapy that uses a patient’s own immune cells to fight cancer—shrank tumors in several children and young adults with diffuse midline gliomas. This fast-growing form of brain and spinal cord cancer typically causes death within a year of diagnosis.
    • “In the trial, several participants were still alive 2 years or more after receiving the treatment.” * * *
    • “This study breaks new ground,” said study co-investigator Crystal L. Mackall, M.D., of Stanford Medicine. “It demonstrates that CAR T cells can have real, meaningful benefit for solid cancers, something that many people have not believed [was possible].”  
    • “In the trial, 9 of 11 patients who received the GD2 CAR T-cell therapy had neurological improvement. Of those, 7 had tumor shrinkage and in some cases the effects were quite dramatic. As patients’ tumors shrank, their symptoms improved and many regained physical functions they had lost from the disease, such as hearing, walking, and taste sensation. 
    • “Participants lived a median of nearly 2 years after treatment, with two patients still alive past the study’s 2.5-year follow-up period. One of these patients had a complete disappearance of his tumor and remains cancer free 4 years after his diagnosis. 
    • “It’s really remarkable,” said Rosandra N. Kaplan, M.D., of NCI’s Center for Cancer Research, who is also running a GD2 CAR T-cell therapy clinical trial but was not involved in this study. “This is a tumor for which nothing has ever worked. I think this is the start of a revolution in understanding how to treat these patients.”   
  • The Hill reported yesterday
    • “Broccoli sold at Walmart stores in 20 states has been recalled.
    • “Braga Fresh last week issued a voluntary and precautionary advisory for 12-ounce bags of Marketside Broccoli Florets that may be contaminated with Listeria monocytogenes.” * * *
    • “According to the U.S. Food and Drug Administration (FDA), which posted the advisory Tuesday, the pathogen can cause “serious and sometimes fatal infections” in young children, elderly people and others with weakened immune systems.” * * *
    • “It was distributed to stores in Alaska, Arkansas, Arizona, California, Colorado, Idaho, Illinois, Indiana, Kentucky, Louisiana, Michigan, Montana, Nevada, Ohio, Oklahoma, Oregon, Texas, Utah, Washington and Wyoming.
    • “No illnesses have yet been reported in connection with the product, the advisory said.”

From the U.S. healthcare business front,

  • Modern Healthcare reports,
    • “Sanford Health closed its merger with Marshfield Clinic Health System on Wednesday.
    • “The combined system, led by Sanford President and CEO Bill Gassen, has more than $10 billion in revenue and operates 56 hospitals across seven states, in addition to two health plans with roughly 425,000 members. It has almost 56,000 employees, including about 13,000 employees from Marshfield, according to a Thursday news release.
  • and
    • “CareSource has completed its acquisition of Common Ground Healthcare Cooperative, the nonprofit health insurers announced in a news release Thursday.
    • “Privately held CareSource, which has 2 million Medicare, Medicaid and health insurance exchange members, gains 54,000 marketplace customers in Wisconsin through the deal. Common Ground CEO Cathy Mahaffey remains as chief executive of Common Ground Healthcare Cooperative and was named CareSource market president for the Badger State.”
    • “Common Ground had been one of three remaining member-owned cooperative health insurers supported with funding from the Affordable Care Act of 2010.” * * *\
    • “Of the 23 co-ops that debuted on the exchanges in 2013, only Community Health Options in Maine and Mountain Health CO-OP in Idaho, Montana and Wyoming are still in operation.”
  • Beckers Hospital Review lists “the hospitals patients are most likely to recommend in every state using Hospital Consumer Assessment of Healthcare Providers and Systems data from CMS.”
  • Beckers Payer Issues identifies the fifteen insurers exiting Medicare Advantage markets in 2025.
  • BioPharma Dive points out “ten clinical trials to watch in the first half of 2025. Expected readouts in diabetes, cancer and depression headline a series of study results that could help the biotechnology sector regain its footing after a shaky year.”
  • Forbes reports,
    • “The anti-obesity drug Zepbound made by Eli Lilly & Co. could be one of the biggest cost drivers for health insurers, employers and government health programs that cover it this year.
    • “Already, GLP-1 weight loss prescriptions Wegovy, Rybelsus and Saxenda—along with Ozempic—are the “single biggest driver” of employer health costs, adding 1% to the total premium expense for 2025, data released last fall from the benefits consultancy Aon said.
    • ‘These GLP-1 drugs are adding to general healthcare inflation that is projected to increase employer-sponsored health insurance coverage by 9%, eclipsing $16,000 per employee in 2025. The spike in premiums, which is higher than the 6.4% increase employers faced in 2024 and in 2023, comes before any “cost savings strategies” are implemented, Aon said.
    • “But a new report from GlobalData indicates Zepbound is poised to overtake other GLP-1 drugs.
    • “Zepbound’s superior efficacy and strategic market expansion suggest that the drug will dominate the obesity market, surpassing Novo Nordisk’s Wegovy (semaglutide),” GlobalData said in a report the market research firm released Tuesday.”
  • Per BioPharma Dive,
    • “Neumora Therapeutics, a well-funded biotechnology company, lost more than 80% of its value Thursday because its most advanced drug failed a major test.
    • “After seeing positive signs in a smaller study in 2023, Neumora pushed the drug into a trio of late-stage clinical trials to evaluate it as a treatment for the most common type of depression. The company just released data from the first of those trials, which found the drug no better than a placebo at alleviating depression.
  • and
    • “Pfizer won’t move forward with asking regulators to approve a gene therapy for hemophilia A and instead will hand back rights to development partner Sangamo Therapeutics in a blow to the California-based biotechnology company. In a Dec. 30 statement, Sangamo CEO Sandy Macrae said his company was “surprised and extremely disappointed” by Pfizer’s decision, which comes some five months after the treatment met its goal in a Phase 3 study of people with the inherited bleeding disorder. Sangamo plans to search for an “optimal path” forward, which could include partnering with another company. Pfizer has steadily retreated from gene therapy, although it sells a hemophilia B gene therapy called Beqvez that it obtained from Spark Therapeutics.”
  • and
    • “After many years of effort, Novartis has obtained positive results from a Phase 3 study for a form of its spinal muscular atrophy gene therapy Zolgensma that’s delivered via spinal injection rather than intravenous infusion. Data from the study, called Steer, showed treatment improved motor abilities in people with the neuromuscular disease who were two years of age or older and could still sit but had never walked independently. U.S. regulators suspended testing of the intrathecal formulation in late 2019 over safety concerns, but in August 2021 permitted Novartis to begin the Steer study. Novartis plans to share the new data with health authorities to support approval of the gene therapy in a broader range of people with spinal muscular atrophy.”

Happy New Year!

Photo by Natalie Kinnear on Unsplash

Happy New Year, FEHBlog readers, and greetings to the Postal Service Health Benefits Program which launched today.

The New York Times offers “10 Ways to Keep Your Mind Healthy in 2025” and “12 Ways to Get Fitter in 2025.”

The Wall Street Journal advises “Want to Lose Weight This Year? Start With What You Drink. Sugary drinks are sneakier than equally high-calorie foods—and even diet soda can affect your metabolism.” Stick with water.

From the public health and medical research front,

  • Per an NIH news release,
    • “Since 1996, HPAI H5N1 influenza viruses have circulated in at least 23 countries. In late 2021, HPAI H5N1 spread from Europe to North America causing sporadic infections among wild birds and poultry farms. In 2022, the virus spread to South America where it devastated birds and marine mammals. In March 2024, USDA scientists identified HPAI H5N1 in U.S. dairy cows, and it subsequently reached herds in 16 states. The virus has been detected in dairy herds in three states over the past 30 days, according to USDA/APHIS. In 2024, the virus has caused 66 confirmed and 7 probable cases of influenza in people in the U.S. and one case in Canada. These human cases have been caused by either the H5N1 type circulating in birds (D1.1) or the type circulating in dairy cows (B3.13).
    • “Against this backdrop, Drs. Marrazzo and Ison say there are four keys to controlling the current outbreak. The first imperative is timely, effective collaborations among investigators in human and veterinary medicine, public health, health care, and occupational workers, such as dairy and poultry workers.
    • “This involves cultivating trust not only between numerous entities, but with people seeking care for symptoms of concern, including conjunctivitis, the authors write. Fortunately, so far most U.S. cases of HPAI H5N1 have been mild and resolved on their own without the need for treatment.
    • “Their second key is a focus on the Canadian HPAI H5N1 patient, who developed respiratory failure and required life-saving medical intervention and treatment before recovering. The authors write that mutations found in the virus in this patient highlight an urgent need for vigilant disease surveillance to identify and assess viral changes to evaluate the risk for person-to-person transmission. Effective surveillance, they say, requires that complete genomic sequencing data from animals and people are made rapidly and readily available.
    • Without information pertaining to where and when isolates were collected, the data cannot be linked phylogenetically to other reported sequences, limiting insight into how the virus is spreading, they write. These data would also provide opportunity for early detection of mutations that might portend avidity for human respiratory epithelium, which may require as little as one mutation in the virus.
    • “Third, researchers must continue to develop and test medical countermeasures—such as vaccines and therapies that eliminate or alleviate disease—against H5N1 and other influenza viruses. Fortunately, current vaccine candidates neutralize the circulating strains, which so far are susceptible to antivirals that could mitigate transmission and severity of illness, they write.
    • “Lastly, Drs. Marrazzo and Ison encourage people to take precautions to prevent exposure to the virus and minimize the risk of infection. For example, people who work with poultry and cows should use personal protective equipment and educate themselves about occupational risks when working with birds and mammals, as CDC and USDA have repeatedly recommended.
    • “Ideally, following these four steps will help scientists and public health officials investigating HPAI H5N1 to answer the many remaining questions more quickly about how the virus is spreading, evolving, and affecting people, other mammals, and birds.”
  • MedPage Today adds,
    • “A 13-year-old Canadian girl recovered after being hospitalized in critical condition with H5N1 avian influenza, researchers reported.
    • “The girl was hospitalized on Nov. 7 and transferred to BC Children’s Hospital the next day, where she was intubated and put on extracorporeal membrane oxygenation (ECMO) and treated with three different antivirals, David Goldfarb, MD, of BC Children’s Hospital in Vancouver, and colleagues reported in the New England Journal of Medicine (NEJM).”
  • Precision Vaccinations lets us know,
    • “A recent study found that 73% of adult Portuguese patients with urinary tract infections (UTIs) reported a reduction in symptom severity or duration of illness after treatment with Uromune™ (MV140). This inactivated oral spray serves as a novel sublingual mucosal-based bacterial vaccine.
    • “This prospective observational study, which involved 125 patients with complicated and uncomplicated recurrent UTIs, was published in the journal MDPI Vaccines (12(12), 1426) on December 18, 2024. In addition to the primary outcome of symptom reduction, the study assessed overall patient satisfaction, adverse events, and the effectiveness of Uromune in subgroups with specific UTI risk factors.
    • “During the 12 months following the start of treatment, 38% of patients were free of UTIs. Meanwhile, 34% reported experiencing one or two episodes, while the remaining 28% had three or more recurrent UTIs.”
  • Beckers Hospital Review informs us,
    • “The FDA approved a subcutaneous injection version of Bristol Myers Squibb nivolumab and hyaluronidase-nvhy for the treatment of several cancers including melanoma, non-small cell lung cancer and renal cell carcinoma. 
    • “The approval covers both monotherapy and combination therapy options, including use of chemotherapy and combination therapy options including use with chemotherapy or cabozantinib, according to a Dec. 27 news release from the agency. “
  • Here’s a link to the December NIH Office of Reseach on Women’s Health Pulse newsletter.
  • Per Medscape,
    • “Researchers are gaining new insight into the relationship between the human cytomegalovirus (HCMV), a common herpes virus found in the gut, and the immune response associated with CD83 antibody in some individuals with Alzheimer’s disease (AD).
    • ‘Using tissue samples from deceased donors with AD, the study showed CD83-positive (CD83+) microglia in the superior frontal gyrus (SFG) are significantly associated with elevated immunoglobulin gamma 4 (IgG4) and HCMV in the transverse colon (TC), increased anti-HCMV IgG4 in the cerebrospinal fluid (CSF), and both HCMV and IgG4 in the SFG and vagus nerve.
    • Our results indicate a complex, cross-tissue interaction between HCMV and the host adaptive immune response associated with CD83+ microglia in persons with AD,” the investigators including Benjamin P. Readhead, MBBS, research associate professor, ASU-Banner Neurodegenerative Disease Research Center, Arizona State University, Tempe, Arizona, noted.
    • “The results suggest antiviral therapy in patients with biomarker evidence of HCMV, IgG4, or CD83+ microglia might ward off dementia.
    • “We’re preparing to conduct a clinical trial to evaluate whether careful use of existing antivirals might be clinically helpful in preventing or slowing progression of CD83+ associated Alzheimer’s disease,” Readhead told Medscape Medical News.”

From the U.S. healthcare business front,

  • STAT News asked “Four digital health unicorns on what they expect in 2025.” For example,
    • “Sean Duffy, the CEO of Omada Health, jokes that 2024 was “the year of Gs” when GLP-1s and GPT were all anybody talked about. While the description could have just as easily applied to 2023, Omada’s most important move this year was all about GLP-1s: a deal with Cigna subsidiary Evernorth to offer its digital behavior change program as a key piece of EncircleRx, which helps employers manage the growing boom in interest for the weight loss drugs. In October, Cigna reported that it had 8 million covered lives in the program. 
    • “Looking ahead to 2025, Duffy said that by the end of the year, Omada hopes to have data that show the company’s lifestyle programs have a meaningful impact on the success of GLP-1s.
    • “Glen Tullman, the CEO of Transcarent, is elated that next year Apple, a company that’s legendarily fastidious about design, will be one of the first users of Transcarent’s new WayFinding tech. The AI chat interface answers questions about care and benefits and represents a sophisticated real-world example of patient-facing generative AI. 
    • “Transcarent already has plans to launch the tool to 1 million people, and Tullman said that ambitiously, he’d like to roll it out to 5 million members by the end of 2025. Tullman thinks of Transcarent as a more sophisticated health care benefit for self-insured employers. Over the last few years, he said the company has poured over $100 million into developing AI for its app that serves as the focal point for the company’s services including virtual care, pharmacy benefits, as well as specialized services for mental health, cancer, surgery and more.” 
    • “Maven Clinic has grown to be a vanguard in the women’s health space by taking a broad approach to fertility benefits, which includes access to additional family planning resources, menopause care, and support for men.
    • “CEO and founder Kate Ryder says in 2024, she’s proud the company launched a comprehensive fertility benefit offering that integrates care coordination, coaching, virtual care, and financial support. One stat the company often cites is that 30% of members in its fertility program conceive without IVF — which Ryder points out can save tens of thousands of dollars per family. * * *
    • “Looking ahead, Ryder said she believes the company can lean on artificial intelligence to create a more personalized experience for members.  “We know what great personalization looks like in other areas of consumer tech, but we haven’t seen that in health care yet,” she said.”
  • The Healthcare Management Financial Association tells us,
    • “Accelerating hospital-focused expenditures helped spur a 2023 increase in national health spending, according to newly released actuarial data.
    • ‘Spending on hospital services surged by 10.4% for the year, up from a 3.2% increase in 2022 and 3.4% for the three-year period spanning 2020-22. The 2023 increase was the biggest seen since a 10.8% jump in 1990.
    • “Partially as a result, total healthcare spending (including clinical research and public health activities) jumped by 7.5% to reach $4.9 trillion, or 17.6% of GDP. In 2022, spending had risen by 4.6% and amounted to 17.4% of GDP. The 2023 share of GDP still was lower than in the peak pandemic years of 2020-21 and roughly the same as it was in 2019.
    • “The spending increase dropped from 7.5% to 4.4% when accounting for healthcare price inflation, up from 1.4% using that adjustment in 2022. Spending per capita reached $14,570.”
  • Modern Healthcare reports,
    • “Elevance Health completed its acquisition of Indiana University Health Plans, according to a Tuesday news release from the insurance company’s subsidiary Anthem Blue Cross and Blue Shield.
    • “IU Health Plans — which will operate under Anthem Blue Cross and Blue Shield in Indiana — offers Medicare Advantage plans in 36 Indiana counties, with 19,000 members. It also offers fully insured commercial plans to employers, covering approximately 9,600 members.”
  • Per MedPage Today, “IV fluid shortage [created by Hurricane Helene is] likely to extend Into early 2025. Major supplier damaged by Hurricane Helene continues to bring production lines back online.”
  • Beckers Hospital Review reports,
    • “Several major pharmaceutical companies, including Pfizer, Bristol Myers Squibb and Sanofi, are set to raise prices on more than 250 branded medications in the U.S. starting Jan. 1, 2025, according to a Reuter’s exclusive report. 
    • “Data analyzed by healthcare research firm 3 Axis Advisors showed the price increases will affect a range of drugs, including Pfizer’s COVID-19 treatment Paxlovid, Bristol Myer Squibb’s cancer therapies and vaccines from Sanofi. 
    • “Most of the price hikes are below 10%, with the median increase across affected drugs at 4.5%. This aligns with the median price increase for 2024, as drugmakers have scaled back large price hikes over the years following public scrutiny. 
    • “The price adjustments apply to list prices, which do not include rebates or discounts negotiated with pharmacy benefit managers.”

Monday report

Thanks to Justin Casey for sharing their work on Unsplash.

From Washington, DC

  • Per a press release,
    • “OPM joins the nation in mourning the passing of President Jimmy Carter. President Carter showed that public service isn’t just a line of work – it is life’s calling. From a young naval officer to a political leader, to leading as a humanitarian building homes and curing diseases, President Carter answered the call to public service. He set an example for every American to give back to their communities. He will truly be missed.” 
  • The Washington Post reports,
    • Memorial services for former president Jimmy Carter are expected to span several days and include public events in Atlanta and Washington.
    • Carter’s state funeral will be held Jan. 9 at 10 a.m. inside Washington National Cathedral after a procession from Georgia and a ceremony in which his body will lie in state in the U.S. Capitol, according to a news release from the Joint Task Force-National Capital Region.
    • “The 39th president will then be buried in a private ceremony in his hometown, Plains, Georgia.”
  • Govexec adds,
    • “President Biden issued an executive order on Monday to close federal agencies and offices next month in recognition of former President Jimmy Carter, who died Sunday at 100 in his home in Plains, Georgia.”
    • In accompanying guidance, Office of Personnel Management acting Director Rob Shriver said all federal employees would be excused from duty Jan. 9 “except those who, in the judgment of the head of the agency, cannot be excused for reasons of national security, defense, or other essential public business.” 
    • The day off applies to federal employees nationwide and will be treated like a holiday for purposes of pay and leave, the memorandum said.  

From the public health and medical research front,

  • The Wall Street Journal reports,
    • “When President Jimmy Carter was diagnosed in 2015 with cancer in his liver and brain, he said that he would like to see the last Guinea worm die before he did.
    • “That just about came true.
    • “There were 3.5 million cases of the parasitic worm disease in 1986, when the 39th U.S. president took up the cause of eradicating it. In 2023, there were 14 human cases, and 11 from January through early December 2024, according to a provisional count.
    • “We’re not there yet, but thanks to him we’re very close,” said Dr. Donald R. Hopkins, former vice president of health programs and now special adviser on Guinea worm eradication to the Carter Center, the human-rights nonprofit the former president founded in 1982 with his wife, Rosalynn Carter.”
  • The Washington Post reports,
    • “Cases of the illness known as norovirus — which induces miserable bouts of vomiting and diarrhea — are surging across the United States, according to the Centers for Disease Control and Prevention. Ninety-one outbreaks of the gastrointestinal bug were reported the week of Dec. 5, the latest period for which data is available. That’s 22 more outbreaks than in the last week of November.
    • “While sometimes referred to as the stomach flu, the disease is not caused by the influenza virus, which results in respiratory illness.
    • “There are about 2,500 reported outbreaks each year in the United States, happening most frequently between November and April. When new strains of norovirus emerge, case counts usually rise, according to disease trackers.
    • “This year, the number of reported norovirus outbreaks have exceeded the numbers that we’ve seen recently and in the years before the pandemic,” according to the CDC.”
    • The article delves into signs and symptoms, treatment options, etc.
  • The American Medical Association tells us what doctors wish their patients knew about depression.
  • Neurology Advisor adds, “One in 6 women experienced symptoms of postpartum depression 2 months after cesarean delivery, according to study findings published in the American Journal of Obstetrics and Gynecology.
  • The Wall Street Journal tells us about a 24 year old man who is trying to “outrun” schizophrenia.
    • “For the past four years, Kevin has been part of a living experiment. Shortly after he began hallucinating, during his junior year at Syracuse University, his doctors recommended him for an intensive, government-funded program called OnTrackNY. It provided him with therapy, family counseling, vocational and educational assistance, medication management and a 24-hour hotline.
    • “Such programs — there are around 350 in the United States — challenge the old idea that psychotic disorders are degenerative, a long slide to permanent disability. They operate on the notion of a golden hour. By wrapping a young person in social supports early on, the theory goes, it may be possible to prevent the disorder from advancing.” * * *
    • “But now, after four years, his time in the program was up. An estimated 100,000 people experience a first episode of psychosis every year, roughly four times the number of spots available in early intervention programs. So in December, it would all go away: the team of five providers and the hotline and the therapist who reminded him of his mother.
    • “What would happen to him without their support? Even as enthusiasm for early intervention builds, long-term studies are casting doubt on whether its benefits last after discharge. For Kevin, leaving the program meant a sudden blast of autonomy and a million questions about what his future, with schizophrenia, would look like.
    • “The training wheels are coming off,” he said.”
  • Per MedPage Today,
    • “There was “low but improving uptake” of reporting about the diversity of participants in summary documents for FDA-cleared pulse oximeters after voluntary guidance was issued in 2013, an analysis of public FDA records found.” * * *
    • “The most important finding is that although there were more mentions of skin color descriptors in performance testing after the FDA’s guidance, a majority of the public clearance documents for pulse oximeters did not include any mention of testing in diverse individuals,” Ferryman told MedPage Today in an email.
    • “Clinicians who work in hospital settings often do not get to choose which pulse oximeter device they use with their patients,” Ferryman said. “Because this research is based on the public record, it suggests that even if clinicians wanted to do their own research on the performance of pulse oximeters across diverse populations, the majority of FDA-cleared device records do not include any information about testing in different skin tones.”
    • Pulse oximeter readings in patients with darker skin tones tend to overestimate oxygen saturation, a long-standing issue described in multiple studies and discussed by an FDA advisory committee. * * *
    • “Newer FDA guidance on pulse oximeter testing that’s under development may correct some of these problems, but no single change in guidance “is likely to be sufficient to fully correct the problems of development, marketing, and dissemination of fully equitable pulse oximeters,” the [researchers] wrote.”
  • Per National Institutes of Health press releases,
    • A study of nearly 10,000 adolescents funded by the National Institutes of Health (NIH has identified distinct differences in the brain structures of those who used substances before age 15 compared to those who did not. Many of these structural brain differences appeared to exist in childhood before any substance use, suggesting they may play a role in the risk of substance use initiation later in life, in tandem with genetic, environmental, and other neurological factors.
    • “This adds to some emerging evidence that an individual’s brain structure, alongside their unique genetics, environmental exposures, and interactions among these factors, may impact their level of risk and resilience for substance use and addiction,” said Nora Volkow M.D., director of NIDA. “Understanding the complex interplay between the factors that contribute and that protect against drug use is crucial for informing effective prevention interventions and providing support for those who may be most vulnerable.”
    • “Among the 3,460 adolescents who initiated substances before age 15, most (90.2%) reported trying alcohol, with considerable overlap with nicotine and/or cannabis use; 61.5% and 52.4% of kids initiating nicotine and cannabis, respectively, also reported initiating alcohol. Substance initiation was associated with a variety of brain-wide (global) as well as more regional structural differences primarily involving the cortex, some of which were substance-specific. While these data could someday help inform clinical prevention strategies, the researchers emphasize that brain structure alone cannot predict substance use during adolescence, and that these data should not be used as a diagnostic tool.”
  • and
    • “Among people with dialysis-dependent kidney failure, a form of psychological therapy called pain coping skills training reduced how much pain got in the way of their daily lives, also known as pain interference. The clinical trial, funded by the National Institutes of Health (NIH), found that training people on how to manage pain reduced the extent to which pain affected their work and social activities, mood, and relationships. The pain coping skills training, which was adapted for people undergoing long-term dialysis, also improved other effects of pain, including the intensity of pain, depression, anxiety, and quality of life. Pain coping skills training is an approach widely used for chronic pain, but it had not previously been tested for people treated with dialysis.
    • “Very few interventions have been shown to improve the quality of life for people with end-stage kidney disease being treated with dialysis,” said Dr. Paul Kimmel, program director at NIH’s National Institute of Diabetes and Digestive and Kidney Diseases (NIDDK), which led the study. “For example, opioids, which have been a main treatment for pain in this population, have side effects that can be more pronounced in the presence of kidney failure, making pain management challenging.” * * *
    • “The study results indicate that pain coping skills training may be an appealing alternative or complement to pain medications. Although the effect of the pain coping skills training on the overall cohort was modest, its high acceptability, tolerability, and safety and its observed benefits to pain, anxiety, depression, and quality of life support further research on developing nonpharmacologic, non-invasive strategies for managing pain in dialysis populations.
    • “Future work will focus on how to prolong the favorable effects of pain coping skills training and how to broadly implement this intervention in clinical practice,” said lead author Dr. Laura M. Dember, nephrologist and clinical investigator at the University of Pennsylvania Perelman School of Medicine, Philadelphia. “Based on the successful results of this study, our hope is that this intervention can be made available broadly to patients receiving dialysis.”
  • The Wall Street Journal offers a quiz about the FDA’s latest guidance on whether a particular food is healthy. For what it’s worth, the FEHBlog scored 100.

From the U.S. healthcare business front,

  • Fierce Pharma offers a “2025 forecast: After Novo, Lilly expansion sprees, ‘positive signals’ emerge around future supply of GLP-1 drugs.”
  • The Washington Post informs us,
    • “They don’t get fruitcakes or Christmas cards from grateful patients, but for decades robots have been helping doctors perform gallbladder removals, hysterectomies, hernia repairs, prostate surgeries and more. While patients lie unconscious on the operating table, robotic arms and grippers work on their bodies at certain stages in these procedures ― all guided by doctors using joystick-like controllers, a process that minimizes human hand tremor.
    • “Now, a team of Johns Hopkins University and Stanford University researchers has reported a significant advance, training robots with videos to perform surgical tasks with the skill of human doctors.
    • “The robots learned to manipulate needles, tie knots and suture wounds on their own. Moreover, the trained robots went beyond mere imitation, correcting their own slip-ups without being told ― for example, picking up a dropped needle. Scientists have already begun the next stage of work: combining all of the different skills in full surgeries performed on animal cadavers.
    • “A new generation of more autonomous robots holds the potential to help address a serious shortage of surgeons in the United States, the researchers said.
  • Check this out!
    • “As 2025 nears, healthcare is undergoing unprecedented transformation, particularly with headlines about artificial intelligence (AI) technologies shifting away from grandiose promises as the dust starts to settle around the potential of Generative AI (GenAI). These innovations and others aim to reshape how healthcare is delivered. 
    • “To shed light on anticipated trends, challenges and opportunities in healthcare technology in 2025, leading experts from Wolters Kluwer Health offer their outlook on 2025 across a variety of topics. Diffusing the hype, the predictions offer an eye-opening look at what’s ahead and lead us toward a smarter, more resilient future in healthcare technology.” 

Weekend update

From Washington, DC

  • On December 23, 2024, President Biden signed a raft load of Congressionally approved bills into law.
  • The 119th Congress convenes on Friday January 3, 2025. Here are links to the 2025 House of Representatives calendar and the 2025 Senate calendar.
  • Per Govexec,
    • Jimmy Carter, the 39th president of the United States and arguably the most dedicated to reforming the operations of the government, died on Dec. 29 at his home in Plains, Georgia. He was 100.

From the public health and medical research front,

  • Pew Research tells us,
    • “The number of Americans ages 100 and older is projected to more than quadruple over the next three decades, from an estimated 101,000 in 2024 to about 422,000 in 2054, according to projections from the U.S. Census Bureau. Centenarians currently make up just 0.03% of the overall U.S. population, and they are expected to reach 0.1% in 2054.
    • The number of centenarians in the United States has steadily ticked up since 1950, when the Census Bureau estimates there were just 2,300 Americans ages 100 and older. (The Census Bureau uses calculated estimates for years prior to the 1990 census because it has identified large errors in the census counts of centenarians for those years.)
    • “In the last three decades alone, the U.S. centenarian population has nearly tripled. The 1990 census counted around 37,000 centenarians in the country.”
  • The Wall Street Journal reports,
    • “The rich get richer—and older. People with high salaries and net worth tend to live longer lives, research shows.
    • “Once Americans make it to their late 50s, the wealthiest 10% live to a median age of around 86 years, roughly 14 years longer than the least wealthy 10%, according to a study published earlier this year in JAMA Internal Medicine.
    • “People with more money can afford healthier food, more healthcare and homes in safer, less-polluted neighborhoods, says Kathryn Himmelstein, a co-author of the study and a medical director at the Boston Public Health Commission.
    • “Though you can’t add more months or years to your online shopping cart yet, health and aging researchers say there are ways to spend money to improve your chances of living longer. They suggest favoring purchases that help you track your health, stay active and reduce stress.”
  • Medscape points out,
    • A booster dose of recombinant pertussis vaccines provides sustained immunity in adolescents and young adults even after 5 years, with pertussis toxin (PT)–neutralizing antibody levels remaining 2.5- to 3-fold higher than pre-vaccination levels. 
  • Per MedPage Today,
    • study presented at the American Society of Hematology (ASH) annual meeting revealed that multiple myeloma patients with higher socioeconomic deprivation, as measured by the Area Deprivation Index (ADI), experienced poorer outcomes, emphasizing the need for targeted interventions.

From the U.S. healthcare business front,

  • The Wall Street Journal lets us know,
    • “Since the assassination of his top lieutenant Brian Thompson on Dec. 4, Andrew Witty has been keeping long difficult hours at the Minnesota headquarters of the giant company he runs, UnitedHealth Group.
    • “Witty has been telling company executives during meetings and rank-and-file employees in videos that the work they do is important, lifesaving and deeply appreciated following the killing of Thompson, who had run the company’s health-insurance division.
    • ‘More quietly, Witty is telling executives that the company is expecting to hit financial records by the end of the year. 
    • “It is up to Witty, a knighted former pharmaceutical chief who went on to a rare second act running the even larger and more powerful healthcare conglomerate that is UnitedHealth, to steer through one of the worst corporate crises imaginable: the targeted killing of one of its own executives.
    • “Witty must ease the concerns of his company’s anxious 440,000 employees following Thompson’s assassination, and keep its complex business humming, while also responding to a wave of outrage over health-insurance practices since the killing in Midtown Manhattan.”
  • Per Beckers Payer Issues,
    • “UnitedHealth Group and home health company Amedisys have agreed to extend the deadline for a planned $3.3 billion merger due to a legal challenge by the Department of Justice.
    • “In a Dec. 26 regulatory filing, the two companies waived their right to terminate the agreement if it does not occur before an agreed-upon date: either 10 business days after a final court ruling that blocks the merger or December 31, 2025. They also made adjustments to the terms, including a potential penalty fee of up to $325 million if regulatory conditions aren’t met.
    • “UnitedHealth’s Optum first announced its plans to merge with Amedisys in June 2023. The Baton Rouge, La.-based company was founded in 1982 and provides home health, hospice and high-acuity care services across more than 500 care centers in 37 states and the District of Columbia.
    • “In November, the Justice Department sued to block the deal in a Maryland federal court, citing concerns of lessened competition in the home health market because the two companies are “direct competitors.” The lawsuit claims the purchase could increase home healthcare prices across 23 states and in Washington, DC. The Attorneys General of Maryland, Illinois, New Jersey, and New York have also joined the complaint.
    • “The proposed merger has been under an antitrust review by the DOJ since August 2023. In March 2024, Oregon regulators opened their own review after a preliminary report found the deal could hurt competition in the state’s home health markets.”

Cybersecurity Saturday

From the cybersecurity retrospection and predictions front as we approach New Year’s Day,

  • CSO lists the “top 7 zero-day exploitation trends of 2024,” and “IT leaders’ top 9 takeaways from 2024.”
  • Dark Reading points out “Emerging Threats & Vulnerabilities to Prepare for in 2025. From zero-day exploits to 5G network vulnerabilities, these are the threats that are expected to persist over the next 12 months.”
  • Federal News Network offers a “2024 review: ‘Typhoons’ bookend [the Change Healthcare breach in a] busy year in cyber. From Volt Typhoon to Salt Typhoon, major cyber incidents in 2024 shined a spotlight on how agencies are managing cyber threats to critical infrastructure.”
  • Healthcare Dive recounts “seven of the biggest healthcare cyberattack and breach stories of 2024 Cyberattacks targeting the healthcare industry continued to rise this year. Here are some of the largest incidents, from Change Healthcare to Ascension.”

From the cybersecurity policy front,

  • Yesterday the Health and Human Services Department’s Office for Civil Rights announced its proposed amendments to the HIPAA Security Rule which is intended to protect electronic personal health information. The public comment deadline is March 7, 2025, sixty days from January 6, 2025, the date that proposed rule will be published in the Federal Register.
  • Here is a link to the OCR’s fact sheet for the proposed rule. The HIPAA Security Rule dates back to 2003, and its hallmark was flexibility in implementation. To that end, the HIPAA Security rule set forth required standards and addressable standards. Because a lot has changed since 2003, I expected standard changes, but I did not expect OCR to do away with the required / addressable standard distinction in favor of exceptions. Like many other regulations issued by the current administration, the proposed amendments are loaded with new paperwork and oversight requirements. Hopefully the next administration will pull back the proposed rule so that the changes focus on requiring tools that are known to work, e.g., multi factor authentication, encryption, adequate backups.
  • Cybersecurity Dive lets us know,
    • “Lax security controls played a significant role in allowing a China-government sponsored threat group to gain broad and full access to U.S. telecom networks, a senior White House official said Friday.
    • “From what we’re seeing regarding the level of cybersecurity implemented across the telecom sectors, those networks are not as defensible as they need to be to defend against a well-resourced, capable, offensive cyber actor like China,” Anne Neuberger, deputy national security advisor for cyber and emerging technology, said during a Friday media briefing.
    • “Neuberger’s remarks came as the White House confirmed a ninth telecom company was among those compromised by Salt Typhoon’s widespread intrusion of U.S. telecom networks. The unnamed company recently determined it was impacted after reviewing threat hunting and hardening guidance provided by the U.S. government, Neuberger said.
    • “Earlier this month, U.S. officials said at least 8 U.S. telecom providers or infrastructure companies were compromised in a campaign that went undetected for months and has been underway for up to two years.”
  • Per Federal News Network,
    • “The DoD’s big cybersecurity program advanced earlier this month. It’s a big rule to carry out if it becomes effective. For what the rule means and what comes next in the Cybersecurity Maturity Model Certification Program, Deltek cybersecurity researcher Michael Greenman joined the Federal Drive with Tom Temin for details.”
    • The article offers a transcript of this interview

From the cybersecurity breaches, ransomware, and vulnerabilities front,

  • The Cybersecurity and Infrastructure Security Agency (CISA) added one known exploited vulnerability to its catalog this week.
  • Here is a link to a Security Affairs explanation of the vulnerability.
  • Bleeping Computer pointed out on December 24,
    • The Clop ransomware gang started to extort victims of its Cleo data theft attacks and announced on its dark web portal that 66 companies have 48 hours to respond to the demands.
    • The cybercriminals announced that they are contacting those companies directly to provide links to a secure chat channel for conducting ransom payment negotiations. They also provided email addresses where victims can reach out themselves.
    • In the notification on their leak site, Clop lists 66 partial names of companies that did not engage the hackers for negotiations. If these companies continue to ignore, Clop threatens to disclose their full name in 48 hours.
    • The hackers note that the list represents only victims that have been contacted but did not respond to the message, suggesting that the list of affected companies may be larger.
    • “The Cleo data theft attack represents another major success for Clop, who leveraged leveraging a zero-day vulnerability in Cleo LexiCom, VLTransfer, and Harmony products to steal data from the networks of breached companies.” * * *
    • “The zero-day flaw exploited this time is now tracked as CVE-2024-50623 and it allows a remote attacker to perform unrestricted file uploads and downloads, leading to remote code execution.
    • “A fix is available for Cleo Harmony, VLTrader, and LexiCom version 5.8.0.21 and the vendor warned in a private advisory that hackers were exploiting it to open reverse shells on compromised networks.”
  • and
    • “The North Korean hacker group ‘TraderTraitor’ stole $308 million worth of cryptocurrency in the attack on the Japanese exchange DMM Bitcoin in May.
    • “In a short post, the FBI attributed the attack to the state-affiliated threat actor TraderTraitor, also tracked as Jade Sleet, UNC4899, and Slow Pisces.
    • “The crypto heist occurred in May 2024 and forced the platform to restrict account registration, cryptocurrency withdrawals, and trading until the completion of the investigations.”

From the cybersecurity defenses front,

  • Netxgov/FCW alerts us that “Government and private sector organizations have begun to recognize that physical and virtual assets must be protected from cyber threats in the same way as IT.”
  • Dark Reading discusses “Defining & Defying Cybersecurity Staff Burnout. Sometimes it feels like burnout is an inevitable part of working in cybersecurity. But a little bit of knowledge can help you and your staff stay healthy.”
  • Here is a link to Dark Reading’s CISO Corner, which was updated this week.

Friday Report

Hanukkah greeting template. Nine candles and wishing. Hand drawn sketch illustration. White, yellow and blue colors

From Washington, DC,

  • The Washington Examiner reports,
    • Debate within the intelligence community over the origins of COVID-19 ran much deeper than previously known, particularly within the Pentagon’s Defense Intelligence Agency. 
    • Three scientists at the National Center for Medical Intelligence, a branch of the Defense Intelligence Agency, conducted a scientific investigation in the summer of 2021, concluding that COVID-19 was likely manipulated in a biolaboratory. But the information was suppressed by the Pentagon and not included in White House briefings on the virus, according to a new report from the Wall Street Journal.”  * * *
    • “The National Center for Medical Intelligence examines global health threats, including infectious diseases and bioweapons, to determine what threats could endanger troops. The agency received a significant boost in funding in the immediate aftermath of the 9/11 attacks on the World Trade Center as the threat of biowarfare increased in the 21st century. 
    • “Three scientists at the medical intelligence center determined through genetic testing that a segment of the novel bat coronavirus, known as the spike protein, had been manipulated to infect human cells. They argued these changes indicated that Chinese scientists at the Wuhan Institute of Virology were engaging in gain-of-function experiments to see if they could make the virus more dangerous for humans.” * * *
    • “Sen. Rand Paul (R-KY) has promised to pick up where the House investigation left off and said he plans to use his new chairmanship of the Senate Homeland Security and Governmental Affairs Committee to delve deeper into what happened at the Wuhan Institute of Virology and what occurred behind closed doors within federal public health agencies.”
  • NCQA shares its insights about a December 9, 2024, White House listening session concerning the ongoing opioid crisis.
  • Federal News Network lets us know,
    • “With an incoming presidential administration and a new Congress both starting up at the beginning of 2025, there are many unknowns about what’s to come for the federal workforce.
    • “But at least one thing is for certain — telework for the federal workforce will remain a high-priority topic for agencies, employees, lawmakers, unions and many others.
    • “Already, key Republicans in Congress are looking ahead to further investigations into telework options for federal employees. House Oversight and Accountability Committee Chairman James Comer (R-Ky.) announced plans to hold a hearing on federal telework once the 119th Congress begins.”

From the public health and medical research front,

  • The Centers for Disease Control and Prevention announced today,
    • “Due to the holidays, a short summary of this week’s respiratory virus illness findings is presented here, and updated data are provided in subsequent pages. No additional data summaries will be provided this week. Regular updates will resume on Friday, January 3, 2025.
    • “COVID-19, seasonal influenza, and RSV activity continue to increase across the country.
    • ‘COVID-19
      • “COVID-19 activity is increasing in most areas of the country, with high COVID-19 wastewater levels and increasing emergency department visits and laboratory percent positivity. Based on CDC modeled estimates of epidemic growth, we predict COVID-19 illness will continue to increase in the coming weeks as it usually does in the winter.
      • “There is still time to benefit from getting your recommended immunizations to reduce your risk of illness this season, especially severe illness and hospitalization.
      • “CDC expects the 2024-2025 COVID-19 vaccine to work well for currently circulating variants. There are many effective tools to prevent spreading COVID-19 or becoming seriously ill.
    • “Influenza
    • “RSV
      • “RSV activity is high and continues to increase in most areas of the country, particularly in young children. Emergency department visits and hospitalizations are increasing in children and hospitalizations are increasing among older adults in some areas.
    • “Vaccination
      • “Vaccination coverage with influenza and COVID-19 vaccines are low among U.S. adults and children. COVID-19 vaccine coverage in older adults has increased compared with the 2023-2024 season. Vaccination coverage with RSV vaccines remains low among U.S. adults. Many children and adults lack protection from respiratory virus infections provided by vaccines.”
  • The University of Minnesota CIDRAP adds,
    • “The genetic analysis of the H5N1 avian flu virus in specimens from the nation’s first severely ill hospitalized patient in Louisiana reveals mutations that may enable upper-airway infection and greater transmission, concludes a technical summary from the Centers for Disease Control and Prevention (CDC).
    • ‘But the authors of the report, released late yesterday afternoon, say the risk of an influenza pandemic amid the ongoing outbreak remains low.
    • “In related news, Los Angeles County and Stanislaus County this week announced their first human H5N1 cases in two dairy workers. Both workers had mild symptoms and are recovering after receiving antiviral drugs. No related cases have been identified. 
    • “California, which has reported a total of 37 cases, recently announced a public health emergency for H5N1 to free up more resources with the virus now spreading to dairy farms beyond the Central Valley and further south.
    • “The US total for human cases is now at 65.”
  • The Washington Post reports,
    • “Whooping cough continues to surge in the United States, with reported cases soaring to more than 32,000 this year — nearly five times the 6,500 cases recorded during the same period last year — marking the highest levels in a decade.
    • “Health experts cite as main culprits for the increase waning vaccination rates and a loss of broad immunity tracing to coronavirus lockdown protocols.
    • “The disease, caused by the bacterium Bordetella pertussis, is highly transmissible from person to person through the air. Because of their immature immune systems, infants younger than 1 year old are at highest risk of contracting whooping cough — also known as pertussis — and are at most significant risk of severe illness.
    • “Vaccination rates with the DTaP shot — which protects against diphtheria, tetanus and pertussis — declined from March through September 2020 at the height of the coronavirus pandemic. But because people were following pandemic protocols such as masking and social distancing, cases did not soar. Some children who missed getting their shots during that period may never have received them, experts have said.”
  • The Wall Street Journal informs us about “What Your ‘Face Age’ Can Tell Doctors About Your Health Scans of face photos are estimating people’s ‘biological age’ and even predicting how long they’ll live.”
    • “The FaceAge test is an artificial intelligence model trained on tens of thousands of photos from patients and public-image databases to look for signs of aging in the face. [Dr. Raymond] Mak and his team ran a study that found that the algorithm did a better job than doctors at predicting how long cancer patients would live. 
    • “Their hope is that one day, the tool could be a standard part of assessing health. Already, separate versions of face-age tests exist online where anybody can upload a selfie and get an estimate of their biological age
    • “Your face reflects the wear and tear of your lifetime,” says Mak, a radiation oncologist at Brigham and Women’s Hospital, who co-led the study alongside other Mass General Brigham researchers. “We viewed this as a way to quantify a doctor’s clinical intuition.”
  • Per STAT News,
    • “Blood stem cell transplants have been central players in treating blood cancers for decades. These procedures can improve patients’ chances of survival and can even offer the opportunity for a cure in some cases.
    • “But over the last decade, physicians say they’ve started doing transplants for fewer cancer types, particularly lymphomas, and are instead reaching first for newer immune or targeted therapies that are safer and often more effective.
    • “That’s progress that experts hope will continue. “I know from my days as a transplanter, there was nothing better than when a patient didn’t have to be transplanted,” said Andy Kolb, the president and CEO of the Leukemia and Lymphoma Society. “Because it’s toxic.”
  • Per HealthDay,
    • “When supplies of certain generic, platinum-based cancer chemotherapies dwindled in 2023, oncologists feared it might lead to under-treatment and many more cancer deaths.
    • “Fortunately, that did not turn out to be the case, a new study published recently in the Journal of the National Cancer Institute shows.
    • “When we looked at the data on prescribing practices over the shortage period, compared to the previous year, we found that although reporting of the shortages was widespread, it didn’t affect as many patients as we had feared,” said lead study author Dr. Jacob Reibel. He’s a third-year fellow in hematology-oncology at Penn Medicine’s Abramson Cancer Center in Philadelphia.”

From the U.S. healthcare business front,

  • Modern Healthcare reports,
    • “National health expenditures in 2025 are forecast to rise 2.2% over 2024 levelsaccording to the Centers for Medicare and Medicaid Office of the Actuary. But some analysts say the predictions should be taken with a measure of skepticism.
    • “The predictions, released annually from CMS actuaries, project changes to healthcare spending by governments, businesses and households several years into the future. The report’s methodology acknowledges limitations, including relying on law and government policy in force at the time the projections were made.
    • “The office, which is independent from CMS leadership, predicts personal healthcare spending — which includes provider and retail revenue from medical goods and services — will increase 2.3% in 2025.
    • “Kevin Holoran, a senior director with data and analytics firm Fitch Group, said the projected 1.7% increase in spending on hospital care “feels a little low.” In December, Fitch Ratings released a 2025 outlook for nonprofit hospitals and health systems suggesting the sector would benefit from boosted cash flows and improved equity market returns.
    • “The Office of the Actuary predicted a 4.5% increase in prescription drug spending. Fitch Senior Director Mark Pascaris — who, along with Holoran, is a lead nonprofit hospital analyst at the firm — said those projections are consistent with growth in the sector, which Fitch expects to continue in 2025. Actuaries’ predicted 3.7% boost in home healthcare spending also makes sense, Pascaris said.
    • “The personal healthcare spending category additionally includes dental services; nursing home and continual care facilities; durable and non-durable medical products; other health, residential and personal care; and “other” professional services not included in the other subcategories.”
  • and
    • “Per diem nursing is replacing travel nursing as the preferred solution to providers’ staffing issues.” * * *
    • “Many employers, including Franklin, Tennessee-based Community Health Systems and Dallas-based Tenet Healthcare have said they’ve lowered their contract labor costs. And a June survey from employment firm Incredible Health found 67% of health executives did not increase travel nurse positions in 2024. The survey also found nurse interest in travel work dropped by 22% in 2024.
    • “Per diem nurses typically operate “on-demand,” picking up shifts for permanent staff who call out, are on a short leave or when a hospital needs extra help when a patient population is high. They are usually local residents and do not require long-term contracts, compared with travel nurses who often require relocation assistance and guaranteed pay regardless of whether a facility needs extra nurses.”
  • The Healthcare Cost Institute updated its assessment of no value care in the employer sponsored and traditional Medicare health insurance markets.
    • “In this brief, we calculated the prevalence and spending among a subset of “no value care” services between 2018 and 2022 among the employer-sponsored insurance and Traditional Medicare populations.
    • “Vitamin D Screening in administrative claims accounted for nearly $708 million in ESI and $312 million in Traditional Medicare spending in 2022. In that year, we estimate that 23% of all Vitamin D Screenings had no evidence of clinical benefit in administrative claims data among those with Employer Sponsored Insurance, much higher than the estimated 4% no value tests among those with Traditional Medicare. The prevalence of arthroscopic knee surgeries for osteoarthritis amounted to $389 million in ESI and $30 million Traditional Medicare spending in 2022.
    • “Our analysis focused just on these three services and, accordingly, does not speak to the prevalence of “no value care” in the employer-sponsored insurance and Traditional Medicare population broadly. Due to absence of clinical and health care operation data elements, we are not able to identify and measure most “no value care” or related challenges, such as medical mistakes, preventable infections, lack of care coordination, and lack of access to care.”
  • Beckers Payer Issues explains why Premera Blue Cross wants its employees to get creative with artificial intelligence.
  • Beckers Hospital Review shares what’s on pharmacy leaders’ radar screens for 2025 and its updated list of 2024 hospital closures which merited a Beckers report.

Slow News Day

On Sunday, December 22, the FEHBlog announced his plan to take off December 23 through December 25. However, due to a flood of news on Monday, he issued a FEHBlog extra. In retrospect he should have taken off December 24 through December 26, Boxing Day. Due to Monday’s Extra and it being a very slow news day, the FEHBlog is continuing its hiatus until tomorrow.

FEHBlog Extra

From Washington, DC,

  • Federal News Network reports,
    • “President-elect Donald Trump has announced plans to nominate a new leader for the Office of Personnel Management.
    • “On Sunday evening, Trump’s team shared in a press email that Scott Kupor, currently a managing partner at venture capital firm Andreessen Horowitz, is the planned pick for OPM director in Trump’s second term.
    • “Scott will bring much needed reform to our federal workforce,” Trump said in a statement on Sunday.
    • “Prior to his current role at Andreessen Horowitz, Kupor served as chairman of the National Venture Capital Association from 2014 to 2018, according to his LinkedIn profile. Kupor has also worked as vice president and general manager of technology company Hewlett-Packard (HP) and held various other executive management roles in the private sector. * * *
    • “Kupor graduated Phi Beta Kappa from Stanford University with a bachelor’s degree in public policy with honors and distinction. He also holds a law degree with distinction from Stanford University and is a member of the State Bar of California.”
  • and
    • “President Joe Biden has finalized a 2% federal pay raise for the General Schedule, but the increases federal employees across the country will see when they open their first paycheck of 2025 will look a little different.
    • “That’s because the 2% federal pay raise is an average — it will vary slightly depending on where federal employees work and their locality pay area.
    • “Biden’s 2% raise includes a 1.7% across-the-board boost that most civilian employees on the General Schedule will get, as well as an average of a 0.3% locality pay adjustment. The 0.3% portion of the raise accounts for the variations in next year’s federal pay raise. Starting in January, some feds’ raises will be slightly above the 2% average raise, while others will see slightly less than the average.
    • “For 2025, the spread of raises ranges from a high of 2.35% in the San Francisco-San Jose-Oakland locality pay area, and a low of 1.88% in the Cleveland locality pay area, according to the General Schedule pay tables the Office of Personnel Management published Monday afternoon. Federal employees working in the national capital region will get a 2.22% raise next year.”
  • Bloomberg reports,
    • “The Biden administration on Monday withdrew a proposed rule that, if finalized, would have expanded access to birth control coverage offered under the Affordable Care Act.
    • “The ACA guarantees coverage of women’s preventive services, like birth control and contraceptive counseling, at no cost for women enrolled in group health plans or individual health insurance coverage. In 2018, new regulations expanded exemptions for religious beliefs and moral convictions that allow private health plans and insurers to deny coverage of contraceptive services.
    • “The [February 2, 2023] proposal—from the departments of Health and Human Services (RIN: 0938-AU94), Labor (RIN: 1210-AC13), and Treasury (RIN: 1545-BQ35)—would have removed the moral exemption waiver, but retained the current religious exemption, the Centers for Medicare & Medicaid Services said previously.”

In judicial news,

  • Reuters lets us know,
    • “A federal judge in Texas ruled that Democratic President Joe Biden’s administration likely exceeded its authority by issuing a rule strengthening privacy protections for women seeking abortions and for patients who receive gender transition treatments.
    • “U.S. District Judge Matthew Kacsmaryk in Amarillo on Sunday [December 22] agreed to block the U.S. Department of Health and Human Services from enforcing the rule against a Texas doctor who through lawyers at a conservative Christian legal group challenged the regulation as unlawful.
    • “The ruling by Kacsmaryk, who was appointed by Republican President-elect Donald Trump in his first term, issued the preliminary injunction a day before a Monday deadline for the doctor, Carmen Purl and her business to comply with the rule.”
    • FEHBlog observation: As noted in the article, the preliminary injunction applies only to the plaintiff.

In Food and Drug Administration news,

  • Per an FDA press release,
    • “Today [December 23], the U.S. Food and Drug Administration approved the first generic referencing Victoza (liraglutide injection) 18 milligram/3 milliliter, a glucagon-like peptide-1 (GLP-1) receptor agonist indicated to improve glycemic control in adults and pediatric patients aged 10 years and older with type 2 diabetes as an adjunct to diet and exercise.
    • “The FDA approved the first generic in this class of medications last month with the approval of a generic referencing Byetta (exenatide).
    • “Liraglutide injection and certain other GLP-1 medications are currently in shortage. The FDA prioritizes assessment of generic drug applications for drugs in shortage to help improve patient access to these medications.
    • “The FDA supports development of complex generic drugs, such as GLP-1s, by funding research and informing industry through guidance as part of our ongoing efforts to increase access to needed medications,” said Iilun Murphy, M.D., director of the Office of Generic Drugs in the FDA’s Center for Drug Evaluation and Research. “Generic drugs provide additional treatment options which are generally more affordable for patients. Today’s approval underscores the FDA’s continued commitment to advancing patient access to safe, effective and high-quality generic drug products.”
  • STAT News reports,
    • “The FDA just approved Alyftrek, a once-daily medicine for a small slice of cystic fibrosis patients that carry certain mutations, including F508del. It’s a triple combination CFTR modulator that works across 31 other mutations, and outperformed Trikafta — another popular Vertex drug for cystic fibrosis — in its ability to reduce sweat chloride levels. This is the company’s fifth CFTR modulator to win U.S. approval.
    • “Vertex said that the drug offers simpler dosing for existing patients taking its drugs — but will be beneficial for an additional 150 U.S. patients with the disease, whose mutations are now treatable.”
  • Per Fierce Pharma,
    • “Undeterred by last year’s rejection and the recent approval of a close rival from Pfizer, Novo Nordisk has pushed its once-daily hemophilia injection across the regulatory finish line days before we hit 2025. 
    • “Late last week, Novo revealed that the FDA approved its tissue factor pathway inhibitor (TFPI) antagonist concizumab as a once-a-day treatment to prevent or curb the frequency of bleeding episodes in patients ages 12 and older who have hemophilia A or B with inhibitors.
    • “The prophylactic, which comes in prefilled, premixed pens for subcutaneous injection, will be marketed under the commercial title Alhemo, Novo said in a release.”

From the public health and medical research front,

  • Beckers Clinical Leadership offer five updates on the respiratory illness surge and six developments on bird flu as we head into the new year.
  • The American Medical Association fills us in on what doctors wish their patients knew about pneumonia.
  • Consumer Reports, writing in the Washington Post, relates “Things to do, and not to do, when you have a cut. Don’t “air it out.” Put down the hydrogen peroxide. Don’t bother with the antibiotic ointment. But do wash it and cover it.”

From the U.S. healthcare business front

  • Per Fierce Healthcare,
    • “Despite significant headwinds coming to bear over the past several years, healthcare executives are expecting a favorable 2025, according to a new survey from Deloitte.
    • “Deloitte’s Center for Health Solutions polled 80 C-level leaders at healthcare organizations, including 40 from health systems and 40 from health plans. Close to 60% said they believe the outlook for the coming year is favorable, increasing from 52% in last year’s survey.
    • “A majority (69%) said they believe revenues will grow in 2025, and 71% said they expect greater profitability.
    • “Two major themes emerged from executives in both sectors, according to Deloitte: growth and consumer affordability. In addition, insurance executives said they were gearing up for a year of regulatory change and new technological advancements, while health system leaders said they expect continued workforce challenges and enhancements to core business technologies.
  • Bloomberg reports,
    • “Republicans have a new chance to expand health savings accounts offered by employer plans when Congress reconvenes in 2025, revisiting a divisive policy that some Democrats support even as others denounce it as a tax break for the wealthy.
    • “Health savings accounts let high-deductible health plan enrollees use tax-free dollars on certain medical expenses. The money rolls over annually and can be invested tax-free for higher returns. Twenty-two percent of employers surveyed by the Kaiser Family Foundation offered HSA-eligible plans in 2024.
    • “Advocates see the tax-advantaged accounts as a vehicle to increase both health care access and conscious spending for high-deductible plan members, who pay more out-of-pocket before insurance kicks in. Lawmakers from both parties have proposed bills to allow patients to use HSAs for everything from gym memberships and menstrual products to funeral expenses and veterinary bills.” * * *
    • “Labeling HSAs as tools for the wealthy is a “mischaracterization,” said Johns Hopkins University accounting and health policy professor Ge Bai, pointing to data that show the majority of HSA holders live in zip codes where the median income is below $100,000. Loosening requirements around the accounts could be particularly useful for gig workers who lack insurance, she said.”
  • Beckers Hospital Review shares Mark Cuban’s plans for the new year.

Weekend Update

Jingle bells! The FEHBlog will be on a holiday break until next Thursday December 26.

From Washington, DC

  • The President signed into law yesterday the skinny continuing resolution (H.R. 10545) funding the federal government through March 14, 2025, and creating funding for disaster relief and farmers. No shutdown. No PBM “reform.”
  • Healthcare Finance adds,
    • “Acute hospital-care-at-home and telehealth temporary waivers were continued but were not given the long-term extensions that were included in a Dec. 18 bipartisan resolution. Both received short-term extensions until March 31.
    • “The original bill extended telehealth for two years and acute hospital care at home by five years.
    • “Stripped out of the bill is a provision to prevent the Medicare pay cut to physicians. This means physicians get a 2.8% Medicare payment cut on January 1, 2025. 
    • Also excluded from the CR is a provision extending the ability of high deductible health plans to cover telemedicine services before the deductible beyond December 31, 2024.
  • The Senate also passed the Social Security Fairness Act on Saturday which benefits federal, state, and local government employees who receive Social Security retirement income. That bill now goes to the President for his signature. 
  • The 118th Congress has completed its work. The 119th Congress will be gaveled in on January 3, 2024.

In Food and Drug Administration News,

  • The New York Times shares the story of a woman “fighting to avoid her mother’s fate [early onset dementia], for her daughters’ sake. A mutant gene is coming to steal Linde Jacobs’s mind. Can she find a way to stop it?” Fascinating.
  • Per FDA press releases,
    • “The U.S. Food and Drug Administration approved Symvess [December 20], the first acellular tissue engineered vessel indicated for use in adults as a vascular conduit for extremity arterial injury when urgent revascularization (restoration of blood flow) is needed to avoid imminent limb loss, and autologous vein graft is not feasible.
    • “Vascular trauma occurs when a blood vessel is injured such as a rupture of an artery in the extremities, which can lead to serious, life-threatening complications such as hemorrhage or blood clotting. When damage to an artery in the extremity occurs, urgent surgical repair is needed to restore normal blood flow. The current standard of care for patients with extremity vascular injuries can include procedures such as autologous vein grafting (surgical repair using the patient’s own blood vessels) or implantation of a synthetic graft. These treatments are not suitable or available for every patient.
    • “Today’s approval provides an important additional treatment option for individuals with vascular trauma, produced using advanced tissue engineering technology,” said Peter Marks, M.D., Ph.D., director of the FDA’s Center for Biologics Evaluation and Research (CBER). “The FDA remains committed to facilitating the development of innovative products that offer potentially life-saving benefits for patients with severe injuries.” 
  • and
    • “Today, the U.S. Food and Drug Administration approved Ryoncil (remestemcel-L-rknd), an allogeneic (donor) bone marrow-derived mesenchymal stromal cell (MSC) therapy indicated for the treatment of steroid-refractory acute graft-versus-host disease (SR-aGVHD) in pediatric patients 2 months of age and older.
    • “Ryoncil is the first FDA-approved MSC therapy. It contains MSCs, which are a type of cell that can have various roles in the body and can differentiate into multiple other types of cells. These MSCs are isolated from the bone marrow of healthy adult human donors. 
    • “Today’s decision marks an important milestone in the use of innovative cell-based therapies to treat life-threatening diseases with devastating impacts on patients, including children,” said Peter Marks, M.D., Ph.D., director of the FDA’s Center for Biologics Evaluation and Research (CBER). “This first mesenchymal stromal cell therapy approval demonstrates the FDA’s commitment to supporting the development of safe and effective products that could improve the quality of life for patients with symptoms that are unresponsive to other therapies.”

From the public health and medical research front,

  • Fortune Well tells us,
    • “A drug already FDA-approved for people with a rare form of breast cancer has now been shown to improve patients’ long-term survival, new clinical trial data suggest.
    • Lynparza (olaparib), a product of Fortune 500 pharmaceutical firm Merck and Fortune 500 Europe company AstraZeneca, exhibited clinically meaningful improvements in overall survival, among other promising findings, in people with germline BRCA-mutated (gBRCAm), HER2-negative high-risk early breast cancer. About 87.5% of patients treated with the drug were alive after six years, compared to 83.2% who received a placebo. Long-term results of the OlympiA phase 3 trial were presented Dec. 11 at the San Antonio Breast Cancer Symposium.
    • “The durable long-term efficacy seen in the OlympiA study reinforces Lynparza as an important treatment option for those living with this truly challenging, very aggressive form of breast cancer,” Dr. Eliav Barr, senior vice president, head of global clinical development, and chief medical officer of Merck Research Laboratories, said in a news release about the findings.”
  • A mother, writes in the Washington Post, about having a stroke soon after giving birth. According to the article, “postpartum strokes happen more often than you’d think.”
  • The Wall Street Journal lets us know,
    • Dabbing has emerged in recent years as a popular way to consume marijuana, especially among youths. But it is dangerous. Like other new forms of marijuana use that have proliferated in recent years, dabbing involves highly potent concentrates of cannabis.
    • Health authorities are sounding the alarm, warning that dabbing could addict users and is sending teenagers to emergency rooms with seizures, cyclical vomiting or psychosis. Some users and doctors call a cannabis overdose, with the accompanying sweaty nausea and disorientation, a “green out,” a term believed to be a play on “black out.” 
    • “People are consuming extremely high doses of THC,” the psychoactive component of cannabis, said Dr. Nora Volkow, director of the National Institute on Drug Abuse. “People can become psychotic.”
  • and
    • California OnTrack uses a skills-based therapy program called coordinated specialty care, which is offered through at least 381 programs in all 50 states. The program substantially reduces symptoms of psychosis, as well as hospitalizations and homelessness compared with traditional treatment, according to published studies.
    • “The premise of the treatment is simple: Teach people with psychosis to live with their imagined voices, hallucinations and false memories. With practice, such symptoms can be managed or ignored. The techniques taught in the program, in conjunction with medication, diminish symptoms over time and keep new ones at bay.
    • “People who enroll in the treatment within two years of their first psychotic episode fare the best, studies found. People with longer-term psychosis also improved but to a lesser degree.
    • “It’s not like a switch where all the symptoms subside. It’s like a dimmer switch,” said Carlos Larrauri, who completed a similar treatment in Florida after being diagnosed with schizophrenia in 2011 at age 24. He has since finished law school, trained as a nurse practitioner, married and now works as a lawyer.
    • “For more than a decade, the federal government and the American Psychiatric Association have identified coordinated specialty care as the gold standard to treat early psychosis. Yet few people know about it, and fewer still have a chance to benefit from it. Three of the largest private insurers only recently began covering the treatment, which has largely been limited to Medicaid patients. California OnTrack is one of the few providers in the U.S. that has secured coverage from private insurance.” 

Cybersecurity Saturday

From the cybersecurity policy and law enforcement front,

  • The Wall Street Journal reports,
    • “Congress might pull in opposite directions on cybersecurity in its new two-year term, while President-elect Donald Trump’s position on key cyber topics remains a wild card.
    • “The agenda is packed: Corporate executives want regulatory harmonization, policymakers realize that key critical infrastructure sectors like healthcare need more support and oversight, and artificial intelligence continues to intrigue lawmakers.
    • “Despite partisan tensions over everything from taxes to immigration, cybersecurity is likely to remain an issue that brings Democrats and Republicans together on national security grounds. Still, Republicans are expected to go after regulation they see as burdensome, in particular the Securities and Exchange Commission’s incident-reporting rule.
    • “It’s important now more than ever that policymakers ensure advancing common-sense and bipartisan cybersecurity policy is a top priority for the 119th Congress,” said John Miller, senior vice president of policy, trust, data and technology at the Information Technology Industry Council, a trade group.”
  • NextGov/FCW discusses the Defense Department related cybersecurity and other provisions found in the Fiscal Year 2025 National Defense Authorization Act which Congress passed this week.
  • Security Affairs lets us know,
    • “According to the WSJ, the U.S. government is considering banning TP-Link routers starting in 2025.
    • “TP-Link holds 65% of the U.S. market and is the top choice on Amazon, powering internet communications for the Defense Department.
    • “In August, two U.S. lawmakers urged the Biden administration to investigate TP-Link over concerns its devices could be used in cyberattacks.
    • The Commerce, Defense and Justice departments have opened separate probes into the company, with authorities targeting a ban on the sale of TP-Link routers in the U.S. as early as next year, the report said.” reported Reuters. “An office of the Commerce Department has even subpoenaed the company while the Defense Department launched its investigation into Chinese-manufactured routers earlier this year, the newspaper reported, citing people familiar with the matter.” * * *
    • “[A] spokesperson for TP-Link’s U.S. subsidiary told the WSJ that the company welcomes any opportunities to engage with the U.S. government to demonstrate that its security practices align with industry standards and to show its ongoing commitment to the U.S. market, consumers, and addressing national security risks.”
  • The Office of Management and Budget’s Office of Information and Regulatory Affairs concluded its review of the HHS’s Office for Civil Rights proposed amendments to the HIPAA Security Rule on December 18.
  • The next step is publication of the proposed rule in the Federal Register.
  • Last Monday, the Cybersecurity and Infrastructure Security Agency released its “2024 Year in Review Highlights CISA’s Achievements in Reducing Risk and Building Resilience in Cybersecurity and Critical Infrastructure Security.”
  • Cyberscoop adds,
    • “Federal civilian agencies have a new list of cyber-related requirements to address after the Cybersecurity and Infrastructure Security Agency on Tuesday issued guidance regarding the implementation of secure practices for cloud services.
    • “CISA’s Binding Operational Directive (BOD) 25-01 instructs agencies to identify all of its cloud instances and implement assessment tools, while also making sure that their cloud environments are aligned with the cyber agency’s Secure Cloud Business Applications (SCuBA) configuration baselines.
    • “CISA Director Jen Easterly said in a statement that the actions laid out in the directive are “an important step” toward reducing risk across the federal civilian enterprise, though threats loom in “every sector.”
    • “Malicious threat actors are increasingly targeting cloud environments and evolving their tactics to gain initial cloud access,” Easterly said. “We urge all organizations to adopt this guidance. When it comes to reducing cyber risk and ensuring resilience, we all have a role to play.”
  • and
    • “The Cybersecurity and Infrastructure Security Agency unveiled a detailed set of guidelines Wednesday to safeguard the mobile communications of high-value government targets in the wake of the ongoing Salt Typhoon telecom breach.
    • The guide aims to help both political and federal leadership harden their communications and avoid any data interception by the Chinese-linked espionage group. As of earlier this month, government agencies were still grappling with the attack’s full scope, federal officials told reporters. Among the targets were officials from both presidential campaigns, including the phone of President-elect Donald Trump.
    • “The advisory details several key practices intended to mitigate risks associated with cyber threats and raise awareness on techniques that can thwart any type of malicious actor.
    • “I want to be clear that there’s no single solution that will eliminate all risks, but implementing these best practices will significantly enhance the protection of your communication,” said Jeff Greene, CISA’s executive assistant director for cybersecurity. “We urge everyone, but in particular those highly targeted individuals, to review our guidance and apply those that suit their needs.”
    • “Even with the guidance’s focus on high-value targets, the advice is good for anyone that wants to take actions to secure their mobile devices. One of the primary recommendations includes the exclusive use of end-to-end encrypted messaging applications for secure communication. CISA suggests adopting apps like Signal, which provide robust encryption for both Android and iPhone platforms, preventing unauthorized interception of messages.”
  • The American Hospital Association News tells us,
    • The Cybersecurity and Infrastructure Security Agency is seeking comments on its draft National Cyber Incident Response Plan Update. The plan describes how the federal government, private sector, and state, local, tribal and territorial government entities will coordinate to manage, respond to and mitigate the consequences of high-profile cyberattacks. The update addresses changes in the cyberthreat and operations landscape by incorporating feedback and lessons learned from stakeholders in previous incidents. Comments are being accepted in the Federal Register until Jan. 15.
  • Per a Justice Department press release,
    • “A superseding criminal complaint filed in the District of New Jersey was unsealed today charging a dual Russian and Israeli national for being a developer of the LockBit ransomware group.
    • “In August, Rostislav Panev, 51, a dual Russian and Israeli national, was arrested in Israel pursuant to a U.S. provisional arrest request with a view towards extradition to the United States. Panev is currently in custody in Israel pending extradition on the charges in the superseding complaint.
    • “The Justice Department’s work going after the world’s most dangerous ransomware schemes includes not only dismantling networks, but also finding and bringing to justice the individuals responsible for building and running them,” said Attorney General Merrick B. Garland. “Three of the individuals who we allege are responsible for LockBit’s cyberattacks against thousands of victims are now in custody, and we will continue to work alongside our partners to hold accountable all those who lead and enable ransomware attacks.”

From the cyber vulnerabilities and breaches front,

  • SC Media relates,
    • “A Chinese-backed malware operation is building a botnet out of smart cameras and video boxes.
    • “The FBI said [on December 16] that a group identified as HiatusRAT has been seeding internet-of-things (IoT) devices with malware that allows for remote access and control. Targets include smart cameras and DVR boxes.
    • “In addition to gathering video footage or traffic data from the compromised hardware, attackers can use the edge-facing devices as a foothold to gain access into other hardware on the network and perform further attacks and data exfiltration.
    • “In this case, the FBI believes that the attackers are trying to compromise U.S. government agencies and the private contractors that work with them. It is believed that the threat actors are working on behalf of the Chinese government to infiltrate networks and gather data that would benefit Beijing.”
  • The American Hospital Association adds,
    • “This recent campaign appears to have targeted vulnerable Chinese-branded webcams and DVRs for specific, published vulnerabilities and default passwords set by the vendor,” said Scott Gee, AHA deputy national advisor for cybersecurity and risk. “These devices are often used in security video monitoring systems. Several of these vulnerabilities impacting older, end-of-life devices have not been patched by the manufacturer and the FBI recommends replacing them with updated devices. The critical takeaway from this bulletin is that patch management programs must cover not only traditional computer systems, but also Internet of Things devices on your network.” 
  • On December 17, HHS’s Health Sector Cybersecurity Coordination Center issued an analyst note about credential harvesting.
  • Bleeping Computer lets us know,
    • “A new Microsoft 365 phishing-as-a-service platform called “FlowerStorm” is growing in popularity, filling the void left behind by the sudden shutdown of the Rockstar2FA cybercrime service.
    • “First documented by Trustwave in late November 2024, Rockstar2FA operated as a PhaaS platform facilitating large-scale adversary-in-the-middle (AiTM) attacks targeting Microsoft 365 credentials.
    • “The service offered advanced evasion mechanisms, a user-friendly panel, and numerous phishing options, selling cybercriminals access for $200/two weeks.
    • According to Sophos researchers Sean Gallagher and Mark Parsons, Rockstar2FA suffered from a partial infrastructure collapse on November 11, 2024, making many of the service’s pages unreachable.
    • Sophos says this does not appear to be the result of law enforcement action against the cybercrime platform but rather a technical failure.
    • A few weeks later, FlowerStorm, which first appeared online in June 2024, started quickly gaining traction.
  • CISA added eight known exploited vulnerabilities to its catalog this week.
  • Cybersecurity Dive adds,
    • “Attackers are actively exploiting a critical vulnerability in Apache Struts 2 just days after it was originally disclosed and patched, researchers warn.  
    • “The vulnerability, listed as CVE-2024-53677, involves a flaw in file upload logic, according to a bulletin from Apache. The vulnerability has a CVSS score of 9.5 out of 10, indicating the risk is considered critical.  
    • “An attacker can manipulate file upload parameters to enable path traversal. Apache urged users to upgrade to Struts 6.4.0 or greater and use the Action File Upload Interceptor. Security researchers warn the vulnerability can allow an attacker to conduct malicious actions.”\
  • and
    • “Researchers have now traced exploitation of a critical vulnerability in Cleo file transfer software back to October, Mandiant Consulting CTO Charles Carmakal said in a LinkedIn post Wednesday. Mandiant’s discovery puts active exploitation at least a month earlier than previously observed by other researchers.
    • “Mandiant identifies the cluster actively exploiting the two vulnerabilities, CVE-2024-50623 and CVE-2024-55956, as UNC5936. Researchers say the cluster has overlaps with FIN11, also known as Clop, which claimed responsibility for the attacks earlier this month. 
    • “There is currently no evidence of mass data theft, which was observed in prior campaigns by the threat group, Carmakal said. However, malicious backdoors including Beacon and Goldtomb have been deployed on exploited systems.”
  • and
    • “An attacker gained access to a limited number of BeyondTrust customers’ instances of Remote Support SaaS, an access-management tool, the company said in a Dec. 8 blog post, which was updated Wednesday. The attacker compromised a Remote Support SaaS API key and reset passwords of multiple accounts.
    • “The cybersecurity vendor initially detected anomalous activity on one customer instance of Remote Support SaaS on Dec. 2, according to the updated blog. Three days later, the company determined multiple customers were impacted, suspended those instances and revoked the compromised API key.
    • “Our initial investigation has found that no BeyondTrust products outside of Remote Support SaaS are impacted,” the company said in the blog post.”

From the ransomware front,

  • Cybersecurity Dive points out,
    • “Data from nearly 5.6 million people was exposed due to a ransomware attack on nonprofit health system Ascension this spring, according to a report to federal regulators.
    • “The attack compromised personal information from some current and former Ascension patients, senior living residents and employees, the system said on Thursday [December 19]. Personal details, medical information, payment information, insurance details and government ID numbers, including Social Security numbers, could have been exposed.
    • “The breach is the third largest reported to the HHS’ Office for Civil Rights’ healthcare data breach portal this year, trailing only incidents at Change Healthcare and Kaiser Foundation Health Plan.” * * *
    • “In June, Ascension reported that cybercriminals gained access to its systems after a worker accidentally downloaded a malicious file, and that personally identifiable and protected health information may have been exposed.
    • “Now, the health system has completed its review of what data may have been compromised. Ascension is mailing letters to affected people, which should be delivered over the next two to three weeks, the health system said in an update Thursday [December 19].
    • “Though patient data was involved, Ascension said it found no evidence that data was stolen from EHR and other clinical systems, where full patient records are stored.” 
  • Statescoop lets us know,
    • Hackers are threatening as early as this week to release the personal information of potentially hundreds of thousands of Rhode Islanders connected with RIBridge, the state’s health and social services system that suffered a cyberattack on Dec. 5, Gov. Dan McKee and state officials told media over the weekend.
    • Brian Tardiff, Rhode Island’s chief digital officer, said that the cybercriminals behind the attack threatened to release the data they claim to have obtained in the Dec. 5 cyberattack unless they receive a ransom payment. Tardiff did not specify the ransom deadline, amount of money demanded or if the hackers identified themselves.
    • “Any individual who has received or applied for state health coverage or health and human services programs or benefits could be impacted by this breach,” according to an update posted to the state’s website Friday after the cyberattack was detected.
    • The state’s benefits programs that may be impacted by the breach include Medicaid, Supplemental Nutrition Assistance Program, Temporary Assistance for Needy Families,  Child Care Assistance Program, health coverage purchased through HealthSource RI, Rhode Island Works, Long-Term Services and Supports, General Public Assistance and Program At HOME Cost Share.
  • Per TechTarget,
    • “Despite being taken down and humiliated by the National Crime Agency (NCA) coordinated Operation Cronos in February 2024, an unknown individual(s) associated with, or claiming to represent, the LockBit ransomware gang has broken cover to announce the impending release of a new locker malware, LockBit 4.0.
    • “In screengrabs taken from the dark web that have been widely circulated on social media in the past day, the supposed cybercriminal invited interested parties to “sign up and start your pen tester billionaire journey in 5 minutes with us”, promising them access to supercars and women. At the time of writing, none of the links in the post direct anywhere, while a countdown timer points to a ‘launch’ date of 3 February 2025.
    • “Robert Fitzsimons, lead threat intelligence engineer at Searchlight Cyber, said it was hard to say at this stage what LockBit 4.0 entailed – whether the gang was launching a new leak site, its old one having been seized, or whether it has made changes to its ransomware.
    • “It is worth noting that LockBit has already been through many iterations, its current branding is LockBit 3.0. It’s therefore not surprising that LockBit is updating once again and – given the brand damage inflicted by the law enforcement action Operation Cronos earlier this year – there is clearly a motivation for LockBit to shake things up and re-establish its credentials, keeping in mind that the LockBit 3.0 site was hijacked and defaced by law enforcement,” said Fitzsimons.”

From the cybersecurity defenses front,

  • Dark Reading discusses
    • “Managing Threats When Most of the Security Team Is Out of the Office. During holidays and slow weeks, teams thin out and attackers move in. Here are strategies to bridge gaps, stay vigilant, and keep systems secure during those lulls”
  • and
    • “To Defeat Cybercriminals, Understand How They Think. Getting inside the mind of a threat actor can help security pros understand how they operate and what they’re looking for — in essence, what makes a soft target.”
  • Here is a link to Dark Reading’s CISO Corner.
  • The Cyberscoop article on CISA’s mobile communications protection guide adds
    • “The guidelines advocate for the use of Fast Identity Online (FIDO) phishing-resistant authentication as a superior alternative to traditional multifactor authentication (MFA) methods. FIDO authentication, especially through hardware-based security keys such as Yubico or Google Titan, is recommended for enhancing the security of high-targeted accounts.
    • The guidance also emphasizes moving away from Short Message Service (SMS) messages as a form of MFA, advising that SMS-based authentication is not encrypted and can be easily intercepted by those with access to telecommunications infrastructure.
    • “Additional recommendations include the use of a password manager, regular software updates for both operating systems and applications to patch vulnerabilities and setting telecommunications account PINs to prevent SIM-swapping attacks — a common technique used by hackers to hijack phone numbers and intercept sensitive communications.
    • “Specific guidelines tailored for Apple iPhone and Android users were also included. iPhone users are advised to enable “Lockdown Mode” to restrict app access and deploy Apple iCloud Private Relay for secure internet browsing. Meanwhile, Android users are encouraged to choose devices with strong security records and long-term update commitments, and to ensure the use of encrypted Rich Communication Services (RCS) for messaging.”