Cybersecurity Saturday

Cybersecurity Saturday

From the frontier AI front,

  • The Wall Street Journal reports,
    • Google’s Gemini model accessed the internet and hacked other companies during a test of its cybersecurity capabilities, the first known example of the company’s artificial-intelligence systems autonomously committing such an act. 
    • “The hacks, which the company confirmed on Friday [September 18], occurred in May as part of a test run by the company Irregular, which was also involved in similar incidents disclosed by OpenAI, Anthropic and Meta
    • “In one of the cases, the model guessed passwords until it gained access to a protected system. In the other two cases, the model found credentials in a public repository that allowed it to then access protected systems. In each case, the model ended the intrusion after determining it had accessed a real company’s systems, Google said.
    • “Irregular notified Google about the hacks at the end of July, Google and Irregular said, in the wake of the discovery that OpenAI’s agents had hacked the AI software company Hugging Face. Google didn’t disclose the hacks until The Wall Street Journal reached out with inquiries this week.” * * *
    • “Worries about the cybersecurity capabilities of new models have increased since the July discovery of the Hugging Face hack. In that case, up to 1,200 agents coordinated on a secret message board inside OpenAI to try to cheat on an evaluation, a report by the third-party testing company METR revealed in August. 
    • “Last week, those concerns spilled into the mainstream after the dramatic quitting of Jacob Coxon, a former OpenAI researcher who had gone to Anthropic earlier this year. Over the weekend, leaders from Anthropic, OpenAI, Google and SpaceX all agreed on the need to slow down the rate of AI progress, although none of the companies have outlined exactly how that would happen.”
  • and
    • “The WSJ Technology Council Summit kicked off Monday afternoon [September 14] in New York City with an informal poll of the audience during a town hall conversation. In a show of hands, only a few people said they feared that AI could kill us all in the next decade, while about half of attendees indicated that they were in support of slowing down AI development at the frontier and prioritizing safety guardrails.
    • “But that slowdown didn’t apply to the deployment of AI within their organizations, where not all models are at the cutting edge and even the most advanced of them tend to be relatively well understood and tested by experience.
      “It’s in our hands and it’s up to us to apply [AI] for good, and I think it can do a lot of good for society,” said Vishal Talwar, president, FedEx Dataworks, and chief digital and information officer, FedEx.
      “Much of ensuing town hall discussion focused on the myriad ways in which companies were operationalizing AI.”
  • Cyberscoop adds,
    • “The AI hacking apocalypse is not inevitable.
      • “While large language models present real risks to society, experts say they can be tested and largely controlled using well-worn cybersecurity and policy choices.”
      • “Juan Andres Guerrero-Saade, a fellow for AI and security research at SentinelOne and an adjunct professor at Johns Hopkins University, said the hacks are worth taking seriously, but at a time when businesses and open-source maintainers should be focused on further hardening their systems and policymakers should be discussing new solutions, “what we see is cybersecurity being used essentially as an excuse for these AI doomer arguments.” * * *
      • “Guerrero-Saade is among a growing chorus of cybersecurity professionals who say that while AI systems pose real, unique threats to our systems, the apocalypse is far from inevitable. Most of the public concerns around the incidents, let alone worries about killer AIs attacking critical infrastructure, assuming control of the internet and wiping out humanity, are either technically impossible or can largely be controlled through established cybersecurity principles.
      • “There is this “narrative or magical thinking of ‘Well, AI is going to be able to hack everything, and therefore it can control everything, and therefore it’s going to kill us all,’” he told CyberScoop. “And you [think] these just don’t add up. They’re not very well-reasoned arguments.”
      • “This fatalistic narrative tied to AI’s eventual dominance doesn’t hold up under scrutiny, according to experts CyberScoop spoke with. In recent conversations, cybersecurity and national security professionals raised questions about both the technical solutions OpenAI and Anthropic use to contain their models, as well as the glaring absence of federal oversight from federal regulators or truly independent third-party review.”

From the cybersecurity policy and law enforcement front.

  • Per a Senate Finance Committee news release,
    • “U.S. Sens. Mark R. Warner (D-VA) and Ron Wyden (D-OR) today reintroduced the Health Infrastructure Security and Accountability Act, legislation to improve cybersecurity in our health care system amid a growing wave of cyberattacks that are compromising Americans’ sensitive information and disrupting access to critical care across the country.” * * *
    • “Specifically, the Health Infrastructure Security and Accountability Act would require the Department of Health and Human Services (HHS) to establish, enforce, and regularly update strong minimum cybersecurity standards for health care providers, health plans, clearinghouses, and business associates, with heightened standards for systemically important entities and entities critical to national security.
    • “The legislation would also require covered entities to develop continuity plans describing how it would resolve a tech failure or intrusion, conduct annual cybersecurity tests, and undergo independent security audits, while increasing fines for failure to meet security requirements and strengthening HHS oversight through annual cybersecurity audits. Additionally, this legislation would provide $1.3 billion to help hospitals strengthen their cybersecurity, including $800 million for hospitals in rural and underserved urban communities.
    • “Full text of the bill can be found here. A summary of the bill can be found here.”
  • Cybersecurity Dive reports,
    • “The Cybersecurity and Infrastructure Security Agency (CISA) will stop publishing weekly roundups of newly disclosed software vulnerabilities at the end of September, the agency announced on Thursday.
    • “CISA is ending its Vulnerability Bulletin “as part of its shift from severity‑based vulnerability management to a modern, risk‑based approach,” the agency said in a statement.
    • The weekly bulletins, published since early 2004, listed vulnerabilities published during the reporting period along with their CVEs, severity scores and brief descriptions.” * * *
    • “CISA said in its Thursday statement that sunsetting the bulletin aligns with the prioritization directive it issued in July, “which directs federal agencies to prioritize vulnerabilities based on real‑world risk factors, including evidence of exploitation and exposure, rather than severity scores alone.”
    • “As it discourages organizations from relying solely on Common Vulnerability Scoring System (CVSS) scores to decide which vulnerabilities to fix, CISA has also been highlighting the Stakeholder-Specific Vulnerability Categorization (SSVC) system as a more nuanced approach to vulnerability analysis.
    • “Chris Butera, CISA’s acting executive assistant director for cybersecurity, said on Wednesday at Google’s Cyber Defense Summit that the agency has been discussing SSVC with companies that sell vulnerability management software. “They’re building some of this prioritization into their vulnerability tooling,” Butera said.”
  • and
    • “The Cybersecurity and Infrastructure Security Agency (CISA) wants to hire critical infrastructure experts with broad, rather than specialized, knowledge as it tries to help defend the infrastructure community with limited resources.
    • “I need to be able to hire people that are highly adaptive, because I think the threat is continuing to evolve so much, and the exposure that we have within these critical infrastructure sectors is evolving so much,” acting CISA Director Nick Andersen told reporters after speaking at Google’s Cyber Defense Summit here on Wednesday [September 16]. “I need people that can pivot from day to day to be able to help meet all of these stakeholders where they are.”
    • “Andersen’s comments come as CISA prepares to onboard roughly 250 new employees as part of a hiring sprint meant to fill critical vacanciescreated by the Trump administration’s sweeping downsizing of the agency over the past two years. As ransomware gangs and nation-state hacker groups increasingly menace infrastructure operators, in some cases aided by destabilizing advances in AI, CISA’s supporters say its mission — and its partnerships — have become more important than ever.”
  • Per a Department of Health and Human Services news release,
    • “The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) today [September announced a settlement with Ambry Genetics Corporation (Ambry) concerning potential violations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Security Rule. Ambry, headquartered in Aliso Viejo, California, is a covered entity that provides genetic testing and clinical genomics services.
    • “In January of 2020, Ambry discovered that an employee’s email account was compromised by a phishing attack. The protected health information (PHI) of 225,370 individuals was potentially exfiltrated by the threat actor. Affected PHI included names, addresses, dates of birth, some Social Security numbers or driver’s license numbers, financial information, diagnoses and conditions, lab results, medications, and treatment information.” * * *
    • “The settlement resolves an investigation that OCR initiated after Ambry filed a breach report in March 2020 about the phishing incident that occurred in January 2020.  OCR found that Ambry had potentially violated provisions of the Security Rule, including:
      • “Failing to conduct an accurate and thorough risk analysis of the potential risks and vulnerabilities to the electronic protected health information (ePHI) held by Ambry;
      • “Failing to implement procedures for terminating access to ePHI when the employment of or other arrangement with a workforce member ends or access is no longer appropriate; and
      • “Failing to assign a unique name and/or number for identifying and tracking user identity in electronic systems containing ePHI.” * * *
  • “The resolution agreement and corrective action plan may be found at https://www.hhs.gov/sites/default/files/ocr-ra-cap-ambry-genetics-corporation.pdf [PDF, 51.88 MB].”
  • Cyberscoop adds,
    • “Another core member of the hacker subset of The Com involved in a spree of extortion attacks from at least 2021 to 2023 pleaded guilty to federal charges, according to court records released Tuesday.
    • “Ahmed Hossam Eldin Elbadawy, a 24-year-old from Texas, pleaded guilty exactly one year ago to wire fraud conspiracy and aggravated identity theft. His guilty plea wasn’t shared publicly until prosecutors filed an order of forfeiture this week seeking proceeds from Elbadawy’s criminal activities. 
    • “Elbadawy and his co-conspirators — Noah Michael Urban, a Florida man sentenced to 10 years in prison last year, and Tyler Robert Buchanan, a Scottish man who pleaded guilty to multiple cybercrimes in April and awaits sentencing — were part of an aggressive subset of The Com coined Scattered Spider.”
  • and
    • “Authorities seized the primary domain and other websites linked to NightmareStresser, one of the longest-running and most popular distributed denial-of-service operations used by cybercriminals globally, the Justice Department said Tuesday. 
    • “Cybercriminals of various motivations used the DDoS-for-hire service to launch hundreds of thousands of DDoS attacks or attempted attacks since at least 2022, officials said. 
    • “The takedown, part of an ongoing globally coordinated effort dubbed “Operation PowerOFF,” marks law enforcement’s continued targeting of IP stressers or DDoS booters that inundate websites, servers and networks with junk traffic, rendering legitimate sites inaccessible. The seizures were executed by the FBI Anchorage field office and the Royal Canadian Mounted Police.”

From the cybersecurity vulnerabilities and breaches front

  • HIPAA Journal notes,
    • “A hacking group has claimed responsibility for an August 2026 cyberattack on Cedar County Memorial Hospital in Missouri. Hacking-related data breaches have been reported by Next Level Medical in Texas and Grafton City Hospital in West Virginia.”
  • MSSP Alert adds,
    • “Artificial intelligence is fundamentally altering the economics of cybercrime, making attacks faster and less expensive to execute, as first reported by Channel Insider. Ransomware victims saw a 45% increase in the first half of 2026, while the average underground price for initial access dropped by 69%, from $1,427 to $439. This shift indicates that AI is enabling threat actors to target more organizations with greater speed and scale, even if individual attacks are not necessarily more successful.”
  • Cyberscoop reports,
    • “Researchers said they used Anthropic’s Claude and OpenAI’s Codex to identify a damaging flaw embedded in a popular software decoding tool that could leave major internet platforms, enterprise services, and web frameworks vulnerable to data theft and remote access.
    • “The vulnerability, nicknamed HEIF Heist, refers to the malware’s ability to trigger memory corruption errors in affected software, allowing the attacker to pilfer sensitive data from its victims. In a report published Thursday, the researchers laid out the potential damage an attacker could cause, including gaining access to internal OpenAI repositories, leaking user files, access tokens, and other sensitive data for online services like Amazon Web Services, and gaining remote code execution privileges across a range of online services, including Meta’s core product suite, GitHub Enterprise servers and open-source internet forum Discourse.”
  • and
    • “North Korean hackers are infiltrating tens of thousands of job seekers’ computer networks by posing as prospective employers, such as artificial intelligence firms, to steal sensitive information and millions of dollars worth of cryptocurrency, U.S. and allied governments warned Friday.
    • The security agencies behind the alert, attributed the group, known as WaterPlum or Contagious Interview, as operating under the 313 General Bureau of the Munitions Industry Department subordinate to the Central Committee of the Workers Party of Korea. The efforts dovetail with those of North Korean IT workers.
    • “WaterPlum actors pose as prospective employers to target software developers and IT professionals worldwide under the pretext of attractive job opportunities,” the agencies wrote. “They often impersonate legitimate Artificial Intelligence (AI), cryptocurrency, or Non-Fungible Token (NFT) companies and have also used recruiting services.”
    • Additionally, “Some WaterPlum actors also operate as North Korean IT workers performing web system design and development tasks on corporate web systems for clients,” read the alert from agencies in Japan, Australia and Germany, alongside the FBI and the Department of Defense’s Cyber Crime Center.”
  • Help Net Security tells us,
    • “A fake ChatGPT billing email is steering users to a copy of the OpenAI login page that keeps whatever username and password they type. Josh Varden of Cofense’s Phishing Defense Center traced the email’s payment button through a Google redirect to the attacker’s page.
    • “The lure targets ChatGPT users on work and personal accounts alike, and it copies the kind of bill a subscriber already expects. Credentials entered on the fake page go to the attacker, and the victim is sent on to an error page.” * * *
    • “Cofense listed three indicators: the Google redirect link and two paths on the same nxcli[.]io host, login.php and key.php. Mail teams can search their logs for all three. If you use ChatGPT, the check that matters takes two seconds: read the address bar and confirm it says auth.openai.com before you type a password.”

From the ransomware front,

  • Industrial Cyber informs us,
    • “New data from Comparitech disclosed a record 997 ransomware attacks worldwide in August 2026, averaging 32 attacks per day and representing a 23% increase from 809 attacks in July. The total surpassed the previous monthly record of 988 attacks recorded in February 2025. Businesses accounted for 861 attacks, up 24% from July, while ransomware incidents targeting healthcare providers rose 30% to 69. Utility companies recorded the sharpest sector increase, with attacks doubling from five in July to 10 in August. 
    • “Ransomware surge was led by Qilin and The Gentlemen, which together accounted for more than 26% of August’s attacks, with Qilin claiming 157 incidents and The Gentlemen 107. Qilin’s attack claims increased 22% during the month, while The Gentlemen’s declined 21%; Qilin also had 12 confirmed attacks, compared with eight for The Gentlemen.” * * *
    • “Attacks on healthcare providers increased by 30% from July 2026 to August 2026, rising from 53 to 69. Eight attacks were confirmed in August. Three of the confirmed attacks took place in the U.S. Nutex Health Inc. noted unauthorized activity on its systems in a SEC filing on Aug. 24, 2026, and The Gentlemen claimed the attack. Cedar County Memorial Hospital experienced disruption to its IT networks on the afternoon of Aug. 14, 2026, with operations returning to normal on the morning of Aug. 28. Wallstreet claimed the attack. At Windrose Health Network, hackers exploited a vulnerability in the network’s remote-management tool in early August, resulting in a data breach. Storm claimed the attack.” 
  • Beckers Health IT reports,
    • “Jackson-based University of Mississippi Medical Center did not pay a ransom in connection with the cyberattack that disrupted its systems in February, according to officials.
    • “UMMC Vice Chancellor of Health Affairs LouAnn Woodward, MD, told SuperTalk Mississippi the state did not compensate hackers following the Feb. 19 attack. State Sen. Nicole Akins Boyd, who chairs the Universities and Colleges Committee, corroborated Dr. Woodward’s account.
    • “The statements come after State Auditor Shad White said his office would investigate the incident and notify the public if the government had paid a ransom.
    • “The cyberattack knocked out UMMC’s phones, website, records database and IT systems, forcing partner clinics to close for nine days and staff to record patient information by hand. The medical center returned to full operations Feb. 27.”
  • Cybersecurity Dive relates,
    • “Security researchers warn that a newly discovered ransomware variant called Settra has targeted virtual private network environments or compromised credentials for initial access before deploying remote monitoring and management tools to gain persistent access in targeted environments. 
    • “Researchers from Huntress observed two specific attacks in recent months, including a July incident at a consumer services and retail organization and a September incident at a manufacturing firm, according to a blog post published Thursday [September 17].
    • “The attackers could be described as capable rather than sophisticated,” said Lindsey O’Donnell-Welch, principal technical community engagement writer at Huntress. “They used effective, established ransomware tradecraft: MeshAgent for persistence, a vulnerable driver to potentially impair defenses, log clearing and recovery tampering.”
    • “Researchers from MoxFive said Settra used compromised VPN credentials to gain initial access and posted numerous victim organizations on its shaming site. The group claims to target organizations with exploitable weaknesses, such as unpatched systems or weak access management, according to a blog post from MoxFive.”
  • Bleeping Computer lets us know,
    • “The ShinyHunters extortion gang breached the Clop (aka Cl0p) ransomware operation’s data leak site, defacing the Tor site and allegedly stealing server data and the private keys for its onion service.
    • “The attack began Friday night [September 18] when ShinyHunters exploited what they claim is an unauthenticated file upload vulnerability in Grav CMS, which they used to upload a small text file to Clop’s site.
    • “The small text file contained a message from the threat actors to the Clop ransomware gang, warning not to threaten them and including a link to ShinyHunter’s own data leak site.”
  • InfoSecurity Mag tells us,
    • “It is a scenario that every CISO hopes they never face: the network encrypted by ransomware attack and cybercriminals who claim to have stolen sensitive data which they will leak if they don’t receive a ransom payment.
    • “Unfortunately for Zach Lewis, CISO at the University of Health Science and Pharmacy (UHSP) in St. Louis, this was the reality he faced when the organization was hit by a LockBit ransomware attack in summer 2023. The University recovered without paying the ransom, but it was a challenging time for all involved.
    • “In a conversation with Infosecurity, Lewis opened up about how it felt to be the victim of a ransomware attack and the toll it took on his team, as well as how the organization recovered from the incident and the lessons other cybersecurity leaders can learn from this experience.”

From the cybersecurity business and defenses front

  • The Wall Street Journal reports,
    • “Companies are facing a new era in cyberattacks driven by AI. But according to one cybersecurity CEO, having the right technology for defense isn’t necessarily the problem. It’s the humans who need to step up—particularly CEOs.
    • “What we’ve seen practically from working with some of the largest organizations in the world is that the technology is already there,” Galina Antova, CEO of the AI-driven security platform Kai, said at the Leadership Institute’s WSJ Technology Council Summit this week. “We could implement so many improvements,” using autonomous AI, she added.
    • “But what it really comes down to is having “the right incentive for the leaders to pursue that,” and “are they enabling their security organization to really move at machine speed?” 
    • “Companies need courage and leadership, she told enterprise tech bureau chief Steve Rosenbush, in a discussion that included Oege de Moor, founder and CEO of cybersecurity firm XBOW. 
    • Some additional insights from their conversation:
      • “Companies may need to redesign their security workflows. Attackers are “already moving at machine speed,” and they’re encountering a patchwork of protections, Antova reported. She has found that many Fortune 500 companies use some 80 to 120 security tools “that are organized in a very fragmented way,” she said. That means that when a company has an exposure, it can take time—days, weeks, or months—to find and close it. By contrast, she said, an end-to-end autonomous defense system that’s supervised by humans can reduce that time to minutes.” * * *
      • “[B]oth CEOs noted that the gap between frontier and open models was shrinking—and Antova added that with the right cybersecurity expertise and a surgical approach to deployment, the cost of AI-enabled security no longer needs to be prohibitive.”
  • Cybersecurity Dive adds,
    • “Artificial intelligence is now the leading driver behind new investment into cybersecurity budgets, according to a report released Tuesday from IANS and Artico Search.  
    • “About seven of every 10 chief information security officers surveyed said AI was their top priority for new cybersecurity spending. Two specific areas for AI-related spending shown in the report include automating security operations and enhancing identity and access management. 
    • “Overall security spending rose 5% in the current survey, which is barely ahead of the 4% spending increase in the year-ago report. AI spending priorities come at a time of relatively modest growth in overall security spending.”
  • Per CISA news releases,
    • “The Cybersecurity and Infrastructure Security Agency (CISA) hosted Cyber Storm X this week, a four-day national cybersecurity exercise designed to test and ultimately strengthen the nation’s resilience. This year’s exercise included 2,000 participants from across the public and private sectors and marks the tenth exercise in the 20-year history of Cyber Storm. The biennial exercise brings together the people who manage the services our nation relies on, including water, energy, and other vital sectors. During the exercise, participants practice how they would respond to a major cyber incident affecting critical infrastructure.
    • “Cyber Storm helps critical infrastructure owners and operators understand how we would manage a large-scale cyber incident,” said Acting CISA Director Nick Andersen.  “Exercises strengthen our national resilience by making sure our plans, policies, and partnerships are ready when we need them.  As a nation, we need the ability to respond swiftly and effectively to critical threats. That’s exactly what Cyber Storm does and why it’s a vital exercise for our nation’s security.”
    • “This year’s exercise focused on a scenario involving a nation-state adversary targeting the transportation systems sector, including rail and ports, along with the water and wastewater systems sector. The exercise allowed participants to test response plans, practice coordination, and strengthen information sharing in a safe environment. Cyber Storm X included over two hundred organizations across all levels of government and the private sector.
    • “CISA will now collaborate with participating organizations to identify lessons learned from the exercise. We will use these findings in a public after-action report that captures observations, analyses, and recommendations. CISA is committed to providing access to a wide range of cybersecurity tools and training opportunities, with exercises being a critical part of that toolkit to enhance our nation’s cyber preparedness.
    • “For more information, please visit Cyber Storm X: National Cyber Exercise.”
  • and
    • “Today [September 16], the Cybersecurity and Infrastructure Security Agency (CISA) released guidance that helps critical infrastructure owners and operators implement realistic decoy systems and information assets to quickly detect and disrupt malicious activity occurring in their networks, which will ultimately improve their cyber defenses. Using Cyber Decoys to Strengthen Detection and Response is the first guide from CISA that offers a detailed explanation of the defensive cyber decoy process.
    • “Many organizations struggle to detect adversaries who use legitimate credentials, native tools, and living off the land techniques to conduct discovery, move laterally, and access data. In this guide, CISA encourages critical infrastructure organizations to incorporate cyber decoy capabilities alongside existing Zero Trust models. Cyber decoy strategies operate on the expectation that malicious actors may eventually gain some level of access. By placing decoys within internal networks and systems, especially in high-value areas, organizations can enable defenders to:
      • “Detect adversaries operating within the environment early in the intrusion lifecycle;
      • “Gather and analyze information taken from intrusions and attempted intrusions;
      • “Allocate defensive resources more effectively based on observed adversary behaviors;
      • “Reduce mean time to detection (MTTD) by generating high-fidelity alerts.” * * *
    • “To effectively use this guide, cyber defenders should have a basic understanding of the MITRE ATT&CK ® Matrix and common enterprise security controls and tools. The guide provides a practical approach to designing and implementing decoy strategies by leveraging the MITRE ATT&CK® knowledge base and the MITRE Engage™ framework.
    • “For more information, please visit Cybersecurity Best Practices.”
  • and
    • “The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology (NIST) today [September 15] released Interagency Report (IR) 8587, Protecting Tokens and Assertions from Forgery, Theft, and Misuse: Implementation Recommendations for Agencies and Cloud Service Providers (CSPs). The report guides federal agencies and CSPs in defending the identity tokens and assertions that underpin modern single sign-on (SSO), federation, and application programming interface (API)-based access, systems adversaries increasingly target to move laterally through enterprise networks and reach sensitive data.
    • “The final report incorporates key feedback from nearly 250 public comments on token validation, secrets management, and detection at scale. The report also reflects input from CISA’s long-term, strategic collaboration with industry CSPs and interagency partners through the Joint Cyber Defense Collaborative. CISA and NIST engagements with this group included a technical exchange in June 2025 with over 50 industry experts to identify approaches to harden identity infrastructure and a webinar in January 2026 to review the draft report. Dozens of individual meetings with CSPs were also held to discuss feedback that included Google, HashiCorp, an IBM Company, IBM, Microsoft Corporation, Okta Inc., the OpenID Foundation, Oracle America, Inc., Amazon Web Services, and Wiz.” * * *
    • “The recommendations in the final report apply across commercial and government-operated cloud services and support implementation of Executive Order 14306 on secure software development practices.
    • “CISA urges federal agencies, CSPs and cloud consumers to review and implement IR 8587 to improve the security of their cloud systems. 
    • “For more information on this effort, read NIST’s News Release.
  • Tech Target offers a tip about “how to verify the value of AI-powered business analytics.”
    • Executives can separate AI analytics capabilities from marketing hype by taking steps to confirm the platform improves decision-making and gives results that hold up.
  • Here is a link to Dark Reading’s CISO Corner.

Thursday report

Happy Constitution Day!

From Washington, D.C.,

  • The American Hospital Association News reports,
    • “A Capitol Hill briefing Sept. 17 in Washington, D.C., hosted by 11 national healthcare organizations, including the AHA, highlighted the growing epidemic of workplace violence and its effects on staff well-being and patient safety. At the briefing, titled Protecting Those Who Care: Addressing Violence Against Healthcare Workers, Hill staff heard panelists’ personal experiences with physical and verbal attacks on the job and how hospitals are working to reduce the incidence of violence. The panelists were: Elizabeth Wells, M.D., executive vice president, chief clinical officer, and physician-in-chief, Children’s National Hospital; Jonathan Ripp, M.D., chief wellness officer and dean for well-being, Icahn School of Medicine at Mount Sinai; Tiffany Covarrubias-Lyttle, RN, associate professor of nursing, University of Lynchburg; and, Sheila Roth, Ph.D., professor emeritus, Carlow University. Reps. John Joyce, R-Pa., and Joe Courtney, D-Conn., also made brief remarks during the event.
    • “In a joint statement, the AHA and other participating organizations said, “Workplace violence, including physical assaults, threats, intimidation, and harassment, erodes the safety and dignity of healthcare workers, directly contributes to staff burnout and turnover, and staffing shortages, and compromises the quality of care and patient safety. This violence undermines providers’ ability to ensure safe, healing environments for all.”
    • “The AHA’s Hospitals Against Violence initiative includes resources and best practices for hospitals to use and share to address workplace and community violence.” 
  • Beckers Clinical Leadership relates,
    • “HHS Secretary Robert F. Kennedy Jr. appointed eight new members to the U.S. Preventive Services Task Force, bringing the influential preventive care panel to 16 members.
    • “Mr. Kennedy made the appointments Sept. 17 through the Agency for Healthcare Research and Quality. The eight join eight members currently serving on the volunteer panel of prevention and evidence-based medicine experts.
    • “The task force carries outsized weight for health system and payer leaders: preventive services that the panel grades “A” or “B” must be covered by most private insurers without cost-sharing under the ACA. Its composition effectively shapes which screenings and preventive services patients can get at no cost.” * * *
    • “Seth Corey, MD, a pediatric hematologist-oncologist at Cleveland Clinic, will chair the task force. The other seven appointees are:
      • “Patrick Hunter, MD, a pediatrician at Pensacola (Fla.) Pediatrics and member of the Florida State Board of Medicine
      • “Ronald Karlsberg, MD, a clinical professor of medicine at Los Angeles-based Cedars-Sinai Medical Center’s Smidt Heart Institute
      • “Venkatesh Murthy, MD, PhD, professor of preventive cardiology at the University of Michigan in Ann Arbor
      • “Stephen Parente, PhD, a health finance professor at the University of Minnesota’s Carlson School of Management in Minneapolis
      • “Goldie Stands-Over-Bull, MD, lead family medicine physician at Texas Native Health in Dallas
      • “Louis Wilson, MD, a gastroenterologist and managing partner at Wichita Falls (Texas) Gastroenterology Associates
      • “Dennis Wulfeck, MD, a diagnostic radiologist and president of the practice board at Radiology Partners’ MBB Radiology in Jacksonville, Fla.” 
  • U.S. News and World Report tells us,
    • “The U.S. Senate ⁠health ⁠committee will hold a confirmation ⁠hearing next week for Dr. Heidi Overton, President Donald Trump’s pick to ​lead the embattled Food and Drug Administration, the panel said on Thursday.
    • “The hearing will take place ‌on September 24, the Senate Health, ‌Education, Labor, and Pensions Committee said in a statement. Trump nominated Overton, a White ⁠House policy aide, ⁠in August, turning to an “America First” ally to steady an agency ​shaken by staff losses, low morale and fights over vaccines, the abortion pill and drug approvals.
  • Per Department of Health and Human Services news releases,
    • “The Advanced Research Projects Agency for Health (ARPA-H), an agency within the U.S. Department of Health and Human Services (HHS), today launched the new Systems for Phenotypic Evaluation, Clinical Trajectories, Response, and Agency (SPECTRA) program, a major research effort to transform how autism is understood, diagnosed, and supported across the lifespan. SPECTRA will bring together biological, clinical, behavioral, and real-world data with advanced computational tools to enable earlier and more accurate diagnosis, identify factors that shape individual health and developmental trajectories, and develop more precise approaches to care tailored to each person’s needs.
    • “Autism is not one-size-fits-all, and our science and care cannot be either,” said HHS Secretary Robert F. Kennedy, Jr. “Millions of American families are impacted by autism, and they need better answers about why it presents so differently from one person to another and which approaches can best meet each person’s needs. SPECTRA will harness the best of American science and innovation to deliver those answers — and turn them into better outcomes for people with autism and their families.” * * *
    • “Learn more about SPECTRA on its program page, including information about the solicitation.”
  • and
    • “The U.S. Department of Health and Human Services (HHS) today issued a Request for Information (RFI) calling on Americans, scientists, physicians, industry, and public health experts to submit evidence and information on the potential health effects of electromagnetic fields (EMFs), radiofrequency (RF) radiation, and wireless radiation exposure.
    • “The RFI will help HHS evaluate the state of the science, compare U.S. and international safety standards and regulatory approaches, identify critical research gaps, and develop practical, evidence-based recommendations for policymakers, families, schools, communities, and public health professionals.
    • “Wireless technologies are part of daily life, and our science must keep pace,” said HHS Secretary Robert F. Kennedy, Jr. “The MAHA Strategy directed HHS to examine electromagnetic radiation and health research, and we are acting on that directive. I encourage scientists, physicians, industry, public health experts, workers, parents, and citizens to bring us the best available evidence so we can identify the gaps and focus federal research where it is needed most.” * * *
    • “More information about the RFI can be found at the Federal Register [PDF].”
  • The International Foundation of Employee Benefit Plans helpfully shares information about “Red Flags for Mental Health Parity Compliance Problems.”

From the U.S. Office of Personnel Management front,

  • FedSmith reports,
    • “Federal retirees and Social Security recipients are only one inflation report away from knowing their 2027 cost-of-living adjustment (COLA). The Bureau of Labor Statistics (BLS) will release the September inflation report on October 14. That report will provide all three CPI-W figures needed to calculate the 2027 COLA.”
    • “The latest estimate from The Senior Citizens League (TSCL) puts the 2027 Social Security COLA at 3.5%. The organization lowered its estimate from 3.6% after the latest inflation report.
    • “Because Social Security and Civil Service Retirement System (CSRS) benefits use the same underlying inflation measure, that estimate also indicates the COLA CSRS retirees may receive. For most Federal Employees Retirement System (FERS) retirees eligible for a COLA, however, a 3.5% increase in the CPI-W would result in a 2.5% FERS COLA because FERS uses a different formula.”
  • Serving those We Serve tells us what federal and Postal employees should know about the redesigned Social Security Statement.
  • Tammy Flanagan, writing in Govexec, lets us know how to navigate the Pay.gov maxe for federal retirement deposits.
    • “Don’t let missing service credits or opaque OPM billing notices shrink your monthly annuity. Here is what you need to know before clicking submit.”
  • MeritTalk informs us,
    • “The Office of Personnel Management (OPM) used governmentwide OneGov deals to give every employee access to six artificial intelligence (AI) platforms, and more than 70% of its workforce actively uses at least one, according to OPM CIO Adam Starr.
    • “Speaking Tuesday at the GovExec Government & AI Summit in Washington, D.C., Starr said OPM has leaned heavily on the General Services Administration’s (GSA) OneGov agreements to rapidly expand employee access to AI.
    • “The OneGov deals were key to our ability to innovate at OPM with AI,” Starr said. “We basically bought all of the AI offerings at $1, and so we gave every employee six AI tools, and we encourage them to use it.”
    • “Those tools include Google’s Gemini, Microsoft Copilot, xAI’s Grok, OpenAI’s ChatGPT, Anthropic’s Claude, and Perplexity AI, Starr said.
    • “The strategy is intentionally multi-model. Starr said he wants employees to have access to several platforms because AI models are evolving quickly and vendors are regularly “leapfrogging each other.”

From the Food and Drug Administration front,

  • Per an FDA news release,
    • “The U.S. Food and Drug Administration today approved Fayuvi (rebisufligene etisparvovec-hopf), the first treatment for pediatric patients with mucopolysaccharidosis type IIIA (MPS IIIA), also known as Sanfilippo syndrome type A., MPS IIIA is a rare inherited disease that progressively damages the brain and nervous system, causing children to lose cognitive, language and other developmental abilities over time. Until today, treatment was limited to managing symptoms; there was no FDA-approved therapy designed to change the underlying course of the disease.
    • “The Trump Administration is committed to bringing safe and effective treatments to patients with the most urgent and unmet needs. The approval of Fayuvi marks a historic moment for children and families living with MPS IIIA, which is a disease that has, until now, offered no approved treatment to alter its devastating course,” said Acting FDA Commissioner Kyle Diamantas, J.D. “Gene therapy holds tremendous promise for rare diseases like Sanfilippo syndrome type A, and this milestone reflects the FDA’s commitment to action.”  
    • “Fayuvi is a one-time, intravenous (given directly into a vein) gene therapy that uses a modified, non-infectious virus called an adeno-associated virus serotype 9 (AAV9) to deliver a working copy of the SGSH gene into the patient’s cells. This enables the body’s cells to produce sulfamidase — the enzyme that is missing or deficient in MPS IIIA — allowing heparan sulfate to be properly broken down in lysosomes and reducing its harmful buildup throughout the body and brain.”
  • Targeted Oncology reports,
    • “FDA 510(k) clearance covers robotic colonoscopy for screening, surveillance, diagnostic evaluation, and advanced therapy including EMR and ESD across the full colon. 
    • “Triton 1 targets limitations of manual scope manipulation by adding robotic control intended to enhance stability, maneuverability, and procedural efficiency during flexible endoscopy. 
    • “CARE I (NCT06935734) reported 100% cecal intubation and no adverse events, meeting primary safety/efficacy end points in a first-in-human cohort. 
    • “Detection performance in CARE I included ADR 54.2% and polyp detection rate 67.5%, exceeding a cited 35% ADR industry threshold. 
    • “Endoscopist ergonomics improved, with a 67% lower perceived procedural workload versus manual colonoscopy on NASA-TLX, suggesting reduced physical and cognitive operator burden.”
  • MedTech Dive adds,
    • “Medtronic has received Food and Drug Administration clearance for a vessel-sealing technology used with its Hugo soft tissue robotic surgery system.
    • “The clearance, which Medtronic disclosed Wednesday, brings LigaSure technology, used in more than 45 million procedures worldwide, to the company’s robotic-assisted surgery platform.
    • “Targeting markets dominated by Intuitive, Medtronic has identified an opportunity to win share by pairing its platform with energy instruments that physicians use in non-robotic surgeries.”
  • MedPage Today informs us,
    • “Unapproved use of deoxycholic acid injection (Kybella) outside of the submental fat region may carry a risk of neuromuscular and other potentially serious adverse events, according to an FDA labeling update.
    • “A review of the FDA Adverse Event Reporting System (FAERS) revealed 129 cases of adverse events associated with use of deoxycholic acid in unapproved areas since the product was approved in 2015, the agency stated in a safety communication. The reports included some serious adverse events, such as blurred or reduced vision with periorbital use of deoxycholic acid injection and muscle or nerve injury, including facial paresis and paresthesia.
    • In announcing deoxycholic acid injection’s approval, the FDA emphasized, “It is important to remember that Kybella is only approved for the treatment of fat occurring below the chin, and it is not known if Kybella is safe or effective for treatment outside of this area.”

From the judicial front,

  • Bloomberg Law reports,
    • “An out-of-network healthcare provider can’t sue Cigna Health and Life Insurance Co. to recover more than $3 million it won against the plan through the No Surprises Act’s independent dispute resolution process, a federal appeals court said Thursday.
    • “The text and structure of the federal law, which created a process for resolving disputes between health plans and out-of-network providers, make clear that it doesn’t provide a private right of action to enforce arbitration awards obtained through that process, Judge Michael H. Park said. The US Court of Appeals for the Second Circuit thus affirmed the dismissal of East Coast Advanced Plastic Surgery LLC’s suit against Cigna.
    • “Although the NSA gives providers a right to payment from health plans for certain services, it delegates enforcement authority to multiple federal agencies and to states,” Park said for the unanimous panel. “This statutory scheme reflects Congress’s intent that the NSA, including payment of IDR awards, be enforced through administrative action rather than private litigation.”
  • Beckers ASC Review relates,
    • “San Tan Valley, Ariz.-based Rita Ntusa Anagho has been sentenced to 14 years in federal prison for orchestrating a $69 million Medicaid fraud scheme through her addiction treatment clinic, according to a Sept. 17 news release from the Department of Justice.
    • “Ms. Anagho, 54, a licensed nurse practitioner, owned and operated Tusa Integrated Clinic, which fraudulently billed Arizona’s Medicaid agency more than $69 million between about May 2022 and March 2023; the agency paid roughly $54.9 million on the false claims, according to court documents. 
    • “Ms. Anagho and her co-conspirators allegedly targeted patients covered under Arizona Medicaid’s American Indian Health Care Program, which reimburses at higher rates than other Medicaid plans, paid illegal kickbacks to sober home owners for patient referrals, and falsified treatment records to conceal the scheme.”

From the public health and medical / Rx research front,

  • Beckers Clinical Leadership reports,
    • “The U.S. cancer death rate declined 35% between 2015 and 2024, averting more than 4.8 million deaths, according to the American Association for Cancer Research’s 16th annual Cancer Progress Report, published Sept. 16.
    • Here are [three] things [the article has eight] healthcare leaders need to know from the report:
    • Death rates fell an average of 4.2% per year for lung cancer, 1.3% for colorectal cancer and 1.2% for female breast cancer between 2015 and 2024.
    • An estimated 2.1 million new cancer cases will be diagnosed in 2026.
    • By 2050, the number of annual cancer diagnoses is projected to rise to 2.5 million.
    • More than 18.6 million people with a history of cancer were living in the U.S. as of Jan. 1, 2025.
    • AACR researchers expect 22 million people to be living with cancer or a history of cancer by 2035.
    • “Read the full report here.”
  • Healio points out,
    • “Around 2.71 billion people worldwide were exposed to secondhand smoke in 2023.
    • “An expert encouraged clinicians to screen women, children and patients with cardiac issues for exposure.” * * *
    • “Despite the findings, Flor and colleagues highlighted progress from tobacco-reducing policies in the Americas, as “of the 79 countries attaining the highest level of achievement in smoke-free protections globally, 24 are in the Americas, approximately 70% of the countries in that region.”
  • STAT News adds,
    • “For years, researchers have known that, among people diagnosed with lung cancer, the prevalence of nonsmokers has been increasing. But they have been trying to determine what factors — whether genetic, environmental, or something else — might put these “never-smokers” at heightened risk. 
    • “Now, researchers have identified a very rare genetic variant that is associated with 25-fold higher odds of lung cancer, they reported in the journal Science on Thursday. In the U.S., the variant is far more common among people in Southern Appalachia than in other regions. 
    • Experts said that the variant likely only plays a role in a small portion of never-smoker lung cancer cases. But the research provides further evidence that these types of tumors can be tied to distinct risk factors, which may in turn require thinking differently about screening programs and treatment strategies. More broadly, the new study highlights the types of narrow but crucial discoveries that can be made by turning to large datasets replete with health information from millions of people. In this case, the investigators relied on genetic data from 23andMe.” * * *
    • “The variant in question — known as T790M — is a version of a gene called EGFR, which typically helps regulate how cells grow and divide. Select EGFR mutations can crop up over a person’s life and are among the most important drivers of lung cancer, and in turn are targeted by some cancer drugs.”
  • The Washington Post calls attention to “5 movements physical therapists say every adult over 50 should do daily.”
    • These simple moves can help you maintain mobility and independence as you age.”
  • Beckers Behavioral Health informs us,
    • “A 13-item Mental Wellness Tool detected common or severe mental disorders, substance use disorders and suicide risk among patients receiving psychiatric emergency department care at a New York City hospital, according to a Sept. 17 Medscape report.
    • “Existing mental health screening tools typically assess for one disorder, and screening for a range of psychiatric conditions can take well over 45 minutes and require several assessment tools. The mwTool-13 is designed to screen for multiple conditions in a single assessment.
    • “The mwTool-13 can be administered in 2 to 10 minutes, according to a Sept. 3 study published in Psychiatric Services.”
  • The Wall Street Journal shares readers views on patient portals.
  • Health Day tells us,
    • “Nearly two-thirds of suspected poisonings in young children probably do not need the emergency department and can be handled by a call to the local poison control center, according to a study published in the August issue of Clinical Toxicology.
    • “Liam P. McLoughlin, M.D., from Rutgers New Jersey Medical School in Newark, and colleagues investigated the medical necessity of pediatric emergency department presentations for poison cases where a poison control center was not contacted prior to presenting at the emergency department. The analysis included toxicologist reviews of summaries from 348 poison control center cases, originating from a health care facility, involving patients aged younger than 6 years.” * * *
    • “A big takeaway from the paper is that more needs to be done to make sure parents, schools, and communities know the poison center is a resource they can turn to when a poisoning is suspected,” McLoughlin said in a statement. “The poison center is available 24/7, 365, and is staffed by amazing people who can provide life-saving information by phone at no cost.”
  • and
    • “Exercise is already recommended to help people with cancer manage fatigue and improve quality of life. Now, there is evidence the benefits may go further.
    • “A new study finds structured exercise may help people with cancer live longer and have more time free of disease.
    • Chih-Chen Tzang of the National Taiwan University and colleagues analyzed 21 clinical trials involving more than 8,400 cancer patients.
    • “Some followed supervised exercise programs that included aerobic exercise, strength training or both. Others did not.
    • “Over an average follow-up of about five years, those who exercised were 23% less likely to die and 17% less likely to have their cancer return before death.
    • “The benefits were strongest among people with early-stage cancer, those who did aerobic exercise — alone or with strength training — and those who completed at least 70% of their exercise program.”
  • Per Genetic Engineering and Biotechnology News,
    • “The genome editing toolbox provides unprecedented opportunities to engineer the human genome. However, genome editing for therapeutic benefit continues to have its limitations. Most current methods rely on untargeted gene delivery or short DNA edits that need to be individualized to each patient.
    • “Now, a new paper describes a novel genome engineering method, prime assembly, that allows long DNA fragments to be integrated into precise and programmable target positions within living cells. This approach, which leverages CRISPR-targeted dual flap synthesis, may allow for the development of universal gene therapies.
    • “This work is published in Nature in the paper, “Targeted genomic integration and rearrangement using prime assembly.”
  • Per Fierce Pharma,
    • “Roche’s T-cell engager portfolio has notched another milestone, as a phase 3 trial of the company’s Lunsumio met its primary endpoint in earlier-line follicular lymphoma.
    • “Without sharing any specific data, Roche and its subsidiary Genentech said Lunsumio’s combination with lenalidomide (Revlimid) demonstrated a statistically and clinically meaningful improvement in progression-free survival against rituximab (Rituxan) plus lenalidomide, known as R2, in the phase 3 Celestimo study. 
    • “The trial enrolled follicular lymphoma (FL) patients who have received at least one prior line of treatment, and it serves as the confirmatory study required to convert Lunsumio’s existing accelerated approval as a monotherapy in third-line FL into a full approval, while also potentially moving the drug earlier into the second-line setting.”

From the U.S. healthcare business and artificial intelligence front,

  • Beckers Payer Issues reports,
    • “The National Committee for Quality Assurance has named the highest quality and most effective health plans of 2026 based on clinical quality, patient experience and health plan accreditation status.
    • “The ratings were released Sept. 16 and are based on 2025 data from commercial, Medicare, Medicaid and ACA plans that reported HEDIS and CAHPS results to the NCQA, which cover approximately 236 million people. Some MA plan data is from 2024 because of reporting schedules, and NCQA Accreditation status was also factored in. Plans were rated on a zero- to five-star scale, with five being the highest rating. In total, 956 plans received a rating.
    • “Commercial plans that received a five-star rating:
      • BCBS Massachusetts
      • Capital District Physicians’ Health Plan (New York)
      • Capital District Physicians’ Healthcare Network (New York)
      • Harvard Pilgrim Health Care (Massachusetts, Maine)
      • Independent Health (New York)
      • Kaiser Mid-Atlantic (Washington, D.C.; Maryland; Virginia)
      • Kaiser Northern California
      • UPMC Benefit Management Services
      • UPMC Health Plan
  • and
    • “When Providence announced it was shutting down its health plan earlier this year after a $102 million loss in 2025, it joined a growing list of health systems stepping back from the insurance business. Carle Health’s Health Alliance, Michigan Medicine’s U-M Health Plan and others have wound down or are exiting, citing volatility in Medicare Advantage and government payer markets that have made provider-sponsored plans increasingly difficult to sustain.
    • “Terry Gilliland, MD, president and CEO of Danville, Pa.-based Geisinger, is watching the same environment unfold and coming to the opposite conclusion.
    • “Rather than say, this is hard and dump the plan, we’ve made the necessary changes including leadership top to bottom to grow profitably,” Dr. Gilliland said.”
  • and
    • “CVS Health’s Aetna is expanding prior authorization bundles for cancer, available to some Medicaid members as of Sept. 1.
    • “The update impacts Medicaid members with providers in Oklahoma, Illinois, Maryland, New Jersey, Virginia, Florida, Kentucky and West Virginia who use the Eviti portal for prior authorizations. Aetna anticipates broadening eligibility to Medicare and commercial members in the first half of 2027.
    • “According to a Sept. 17 news release, Aetna observed providers submitting four different prior authorizations, on average, for its members needing cancer treatments. These bundles allow a single prior authorization request that could encapsulate medical oncology and radiation oncology services with high-tech imaging needs. The expansion builds upon an early rollout of the bundles. 
    • “By approving a broader set of treatments and related services upfront, we’re removing barriers that can delay care,” Aetna COO and Medicaid President Katerina Guerraz said.”
  • Beckers Hospital Review relates,
    • “St. Louis-based Ascension has reached an agreement to transfer full ownership of its co-owned Arizona managed care health plan, Mercy Care, to CVS Health subsidiary Aetna, a spokesperson for Ascension confirmed with Becker’s
    • “Ascension co-owns the plan with San Francisco-based CommonSpirit’s Dignity Health, the spokesperson confirmed. The agreement is subject to regulatory reviews and approvals.
    • “Mercy Care has long served vulnerable populations, families and individuals across Arizona through Arizona Health Care Cost Containment System Medicaid programs and Medicare Duals Special Needs Plans,” the spokesperson said. “Aetna has successfully managed Mercy Care’s day-to-day operations and administrative services for over 20 years.”
  • and
    • “HCA Healthcare CFO Mike Marks said payers have outpaced hospitals on AI-driven claims processing, adding another layer to the friction hospitals face on denials, underpayments and prior authorization.
    • “I know there’s a lot of talk about AI in the hospital revenue cycle, we’re behind the payers, in my view,” Mr. Marks said Sept. 15 at the Jefferies Healthcare Services and Technology Conference in Nashville, Tenn., where the 190-hospital system is also headquartered.
    • “Payers, he said, have real incentives driving their AI investments, including medical loss ratios and patient populations to manage.
    • “They’ve been working really hard on their version of AI in their claims shop,” he said.”
  • and
    • “Nashville, Tenn.-based HCA Healthcare is seeing softer elective surgery volumes as patients lose coverage through the health insurance exchanges, with broader affordability pressures potentially contributing to the slowdown, CFO Mike Marks said Sept. 15 at the Jefferies Healthcare Services and Technology Conference.
    • “The 189-hospital, for-profit system continues to see strong overall demand for healthcare services, but the movement of patients from exchange coverage to uninsured status is weighing on elective procedures.
    • “On the inpatient side of elective, and frankly, on the outpatient surgery side as well, the biggest issue is HICS,” Mr. Marks said, referring to health insurance exchange coverage. “This movement out of HICS to uninsured — as people in our communities have lost coverage on the exchange [and] become uninsured — they generally lose access to elective care. That is the primary driver of the slowdown in our elective surgery volumes is exchanges.”
  • Beckers ASC Review tells us,
    • “Brentwood, Tenn.-based Surgery Partners has completed the sale of its ownership interests in its Idaho Falls, Idaho, facilities to Intermountain Health for $797 million in gross proceeds, according to a Sept. 17 news release.
    • “The deal includes Mountain View Hospital and Idaho Falls Community Hospital, values the combined facilities at about $1.15 billion, and delivered Surgery Partners $587 million in net cash proceeds at closing, subject to customary post-closing adjustments. Physician ownership of Mountain View Hospital will remain unchanged under Intermountain’s leadership, and the proceeds will primarily go toward paying down debt, which is expected to improve the company’s balance sheet leverage by about 30 basis points from 4.4x at the end of the second quarter.
    • “Excluding the Idaho Falls facilities, Surgery Partners expects a 50% reduction in its Medicaid payor mix, to under 2% of revenue, along with the elimination of its neonatology, obstetrics, inpatient pediatrics and retail and compounding pharmacy service lines.”
  • Fierce Healthcare informs us,
    • “Big box retailer Walmart is launching a six-month pilot program that places pharmacists in a new “Health Ambassador” role at five rural stores to help customers navigate health and wellness resources.
    • “Walmart’s Health Ambassador Associate will be able to aid patients in understanding their health goals and help connect them to relevant services and resources.
    • “The Health Ambassador role will be piloted at locations serving rural and underserved communities across the U.S., including in Lexington, Tenn.; Caro, Mich.; Franklin, Va.; Fort Scott, Kan.; and Searcy, Ark.
    • “The pilot will initially focus on three healthcare areas: diabetes, weight management and maternal health. Health Ambassadors can also aid customers in nutrition, movement, sleep and stress management through the program’s in-person conversations and tailored coaching.”
  • and
    • “Humana researchers found that cancer patients who received specialty pharmacy care coordination services had fewer hospitalizations and emergency department visits, along with lower medical costs.
    • “The study, conducted by Humana Pharmacy Analytics and Consulting, analyzed health outcomes for people with cancer who are Humana Medicare Advantage members with Part D prescription plan coverage and who received medication adherence care coordination guidance, as compared to those who opted out of coordination. 
    • “Humana’s CenterWell Specialty Pharmacy Oncology Center of Excellence (COE) provided the care coordination services over the course of one year. That COE program provides specialized, personalized clinical care and mail-order delivery for patients managing complex cancer diagnoses and therapies. Within CenterWell, Humana’s health care services organization, CenterWell Pharmacy serves many Humana members as a mail-order pharmacy and also serves patients who are not enrolled in a Humana plan.”
  • and
    • “Blue Shield of California announced Thursday that it plans to expand its Virtual Blue program, doubling program enrollment for members.
    • “Beginning in January 2027, the benefit will be included in fully insured preferred provider organization (PPO) plans for employers with 101 to 3,000 employees, as well as for certain individual and family plans, the insurer said.
    • “The expansion will allow an additional 200,000 mid-size employer PPO members and 60,000 individual and family plan members to utilize the program, increasing its total enrollment to more than 410,000 participants, executives say.
    • The virtual-first program, first launched in 2023 in collaboration with Accolade and TeleMed2U, has more than 150,000 members as of April. The program gives members access to a range of virtual health services at no additional cost, along with care from providers in Blue Shield’s PPO network.
  • Per BioPharma Dive,
    • “Novo is investing in oral biologics, signing a deal with fellow Danish company Orbis Medicines to discover multiple “macrocycles” that have the “potential to replace injectable medicines,” Orbis said Thursday.
    • “Orbis could receive as much as $1.4 billion in up front and downstream payouts, as well as sales royalties, in the deal. The companies didn’t specify the number of drugs on which they would collaborate, nor specific diseases, only mentioning that they’ll pursue unnamed cardiometabolic targets.
    • “The use of macrocycles is one way Novo could overcome some of the limitations of standard oral peptide medicines, such as poor digestive absorption. The highest dose of Novo’s Wegovy pill contains 20 times the highest injectable dose because most of the drug’s active ingredient is chewed up before reaching the bloodstream.”
  • and
    • “North Immunology, in the early stages of developing a potential competitor for the widely popular inflammatory disease drug Dupixent, plans to go public next year via a reverse merger with Aethlon Medical.
    • “After the merger, the companies expect North Immunology investors to own 95.25% of the new entity, with the rest going to Aethlon shareholders. Those who own Aethlon stock immediately prior to the merger will also get a contingent value right entitling them to potential proceeds from Aethlon’s legacy Hemopurifier business. 
    • “The new company will operate as North Immunology and trade on the Nasdaq under the ticker symbol “NRTX,” Aethlon said Thursday. North Immunology’s executives will lead the combined entity, and its directors will populate the board, along with some new independent directors. The companies expect the transaction to close in the first quarter of 2027.”
  • Healthcare Dive points out,
    • “Healthcare organizations are rapidly adopting agentic artificial intelligence, but governance frameworks for managing the technology are not evolving at the same pace, according to a new survey from digital identity security firm Imprivata.
    • “More than 85% of leaders responsible for AI strategy at healthcare organizations say they’re confident they have visibility into AI agent activity and are able to fully control and govern an autonomous agent’s actions.
    • “However, 72% of respondents admit AI tools are deployed without IT approval at least occasionally within their organizations, highlighting a disconnect between confidence and reality.”

Midweek report

Simplicity is a virtue.

From Washington, D.C.,

  • STAT News reports,
    • “Normally, discussions about how congressional advisers study Medicare spending are quite dry. Not so at the House Ways and Means Committee on Wednesday.
    • “In a party line vote, committee Republicans pushed forward a bill that seeks to change how the Medicare Payment Advisory Commission studies Medicare Advantage spending. In particular, this bill would direct the nonpartisan agency to study the topic of overpayments to Medicare Advantage plans in a manner that’s more favorable to insurers.” * * *
    • “It’s a bit of a change in tune for some Republicans, especially those who are doctors, who had become frustrated with Medicare Advantage insurers that deny care to patients. 
    • “However, Rep. Greg Murphy (R-N.C.), who is among those doctors who have criticized certain industry practices, said he had no problem supporting the bill. 
    • “Asking for more information so that we can make real choices and reform the Medicare Advantage system, I am absolutely for,” he said.”
  • and
    • “Democrats are vowing to aggressively pursue oversight if they win control of either the House or Senate in November’s midterm elections. Health care issues, including President Trump’s drug pricing deals, are potential targets. 
    • “It’s common for parties to turn to oversight when they take control of a congressional chamber. Lawmakers can use oversight to tell a story about the other side. It also avoids intraparty divisions by focusing attention on what the other party has done. And if Democrats want to keep the focus on Trump, even though he can’t run again, oversight is a good way to do that.”
  • MedPage Today adds,
    • Nicole Saphier, MD, President Donald Trump’s third surgeon general nominee, was grilled at her confirmation hearing Wednesday about her stance on childhood vaccines, voicing support for immunization as she seeks to serve in an administration that has moved to make sweeping changes to vaccine guidance.
    • Saphier, a radiologist and former Fox News Channel contributor, faced tough questioning about her views on the safety of childhood vaccines by Sen. Bill Cassidy, MD (R-La.), who pressed her to declare whether she believed there was a link between vaccines and autism — which widespread scientific consensus has concluded doesn’t exist, yet which the Trump administration has repeatedly pushed to revisit.
    • “I do not believe childhood vaccines cause autism,” Saphier said. She also said “the MMR [measles, mumps, and rubella] vaccine is our greatest tool for combating measles,” in response to a question by Cassidy over whether parents should give children that shot, and which the president recently ordered be spaced out.
  • Healthcare Dive relates,
    • “Health plans are generally performing better on quality and performance ratings, though nonprofit insurers continue to surge past their for-profit peers.
    • “The National Committee for Quality Assurance released its 2026 ratings on Tuesday, which score commercial, Medicare and Medicaid plans across a range of measures of clinical quality, patient experience and health outcomes. Eighteen plans nabbed the standards organization’s highest 5-star rating, up from 11 last year. All of them are nonprofits.
    • “Of the major publicly traded carriers, CVS had the highest scores, averaging at about 4 stars, according to a Healthcare Dive analysis of the data. Meanwhile, plans’ average rating ticked up slightly, from 3.483 last year to 3.493 in 2026 thanks to improvements in commercial and Medicaid plans, though Medicare insurers’ average rating slipped.”
  • Healthcare Finance News tells us
    • “The American Hospital Association and American Medical Association are urging the Centers for Medicare & Medicaid Services to reconsider proposed reductions to Medicare physician payments for 2027, warning that the cuts could threaten patient access and the financial stability of physician practices.
    • “Comments on the proposed rule, which was released in July, were due Monday.
    • “The AMA voiced its concerns earlier this month about a CMS plan to cut physician pay when doctors provide a separately identifiable office or outpatient evaluation and management (E/M) visit on the same day as most procedures are performed. 
    • “The agency scrapped this same plan eight years ago, the AMA said, after physicians and other stakeholders raised serious concerns. 
    • “But CMS is pitching a similar idea in its 2027 Medicare physician payment schedule proposed rule,” the AMA said. “If finalized, most changes, including this one, would be scheduled to take effect Jan. 1.”
    • “The AMA called for annual physician payment updates tied to medical inflation, arguing that the lack of consistent inflationary adjustments has contributed to the erosion of physician practice sustainability.”
  • The American Hospital Association News tells us,
    • “The Workgroup for Electronic Data Interchange has launched its fall 2026 survey to assess industry readiness for the Centers for Medicare & Medicaid Services’ interoperability and prior authorization final rule. Survey responses are anonymous, and all results are aggregated. The survey will close on Oct. 9. WEDI plans to use the results to make recommendations to CMS, inform stakeholders and assist WEDI in its development of industry guidance and education.” 

From the U.S. Office of Personnel Management front,

  • Govexec reports,
    • “Senate Democrats again urged the Trump administration Wednesday to abandon its plans to collect detailed health information from federal workers, retirees and their families, saying recent tweaks to “de-identify” records are insufficient to protect employees’ privacy.
    • “Last December, the Office of Personnel Management published an information collection request in the Federal Register that would require insurers who participate in the Federal Employees Health Benefits and Postal Service Health Benefits programs to provide monthly reports with identifiable health data on their enrollees.
    • “Following pushback from federal employee groups and medical ethicists, OPM in June revised its proposal, purporting to take steps to mask employees and retirees’ identities in the data collection. But organizations that represent federal workers and retirees warned that the agency still hadn’t done enough to protect patients’ privacy.
    • “In a letter to OPM Director Scott Kupor, a group of six Senate Democrats, led by Sens. Adam Schiff, D-Calif., and Mark Warner, D-Va., who previously requested the proposal’s withdrawal, wrote that the proposed pseudonymization of records does not their “fundamental” concerns with the plan, particularly the agency’s insistence that it may re-identify insurance claimants in the future.”
  • FedWeek relates,
    • “OPM has provided some additional information on agency responsibilities to conduct the annual survey of federal employees—which it plans to shift to them from itself under a pending rules proposal—although still not setting a schedule for conducting this year’s version.
    • “A September 17 Federal Register notice states that the survey traditionally called the Federal Employee Viewpoint Survey will be renamed as the Annual Employee Survey, and reaffirms the intention in the earlier rules proposal to reduce the number of core questions from 16 to 10.
    • “That is to include dropping longstanding questions asking employees about their overall level of satisfaction with their job; with the recognition they receive for doing good work; with their organization overall; with the information they receive about what is going on in it; with their level of involvement with decisions that affect their work; and whether they would recommend their organization as a good place to work.
    • “OPM traditionally used those satisfaction-related questions in creating an index that was widely—although not officially—seen as a proxy for morale.”

From the U.S. Food and Drug Administration front,

  • Good Housekeeping reports,
    • “FDA issued a Class II recall on September 11 for six hand soap products from Intercon Chemical Co. distributed across 15 states. The original recall happened on June 29 due to potential bacterial contamination.
    • “Two soap variants contained harmful bacteria including Pseudomonas aeruginosa and Serratia marcescens, which can cause serious infections like pneumonia, UTIs, and blood infections, especially in immunocompromised individuals.
    • “Consumers should identify recalled products by UPC codes and lot numbers listed for Intercon, Clearly Better, Summit, Vestis, and Laura Lynn brands, then stop use immediately and seek medical attention if symptoms develop.”
  • Radiology Business relates,
    • “The U.S. Food and Drug Administration has approved a new generic radiopharmaceutical alternative from drugmaker Curium, aimed at competing with another treatment on the market. 
    • “Bexlutry (lutetium Lu 177 dotatate) is a radioligand therapy designed to deliver targeted radiation for treating a group of rare cancers originating in the digestive track and pancreas. Boston-based Curium scored the approval through the FDA’s 505(b)(2) pathway, supported by published evidence and targeted bridging data. 
    • “This demonstrated that Bexlutry achieved a similar biological and chemical profile to the previously approved Lutathera, manufactured by rival firm Novartis. 
    • “Today’s FDA approval brings us a step closer to advancing our ambition of aiming to improve the lives of up to 80% of patients with cancer,” Mike Patterson, Curium’s CEO of North America, said in a statement Sept. 14. “Our priority now is a high-quality launch supported by our end-to-end nuclear medicine infrastructure, designed to help ensure consistent delivery, predictable scheduling support for sites of care, and a dependable experience for patients receiving radioligand therapy.”

No Surprises Act News

  • Politico reports,
    • “A Senate committee held stakeholder roundtables on Tuesday to discuss reforms to the 2020 No Surprises Act, which set up how doctors and insurers are paid for unexpected medical bills, Simon reports.
    • “The act, originally co-sponsored by Health, Education, Labor and Pensions Chair Bill Cassidy, shielded patients from unexpected out-of-network emergency care bills. But it has come under fire for creating a case backlog in a system that critics argue can pay disproportionately in favor of doctors.
    • “Employers, physicians, insurers and unions — groups typically at odds — held a cordial, constructive talk about possible solutions, according to four people familiar with the meetings who were granted anonymity to speak candidly. Committee staff also met separately with the arbitrators responsible for overseeing and resolving payment disputes.
    • “Over three hours, the stakeholder group didn’t settle on any policy changes, but they agreed on the need to eliminate the dispute backlog by filtering out ineligible claims and encouraging faster payouts. The group emphasized the importance of benchmark rates for medical services, known as qualified payment amounts, when determining payouts and that only emergency care bills should be eligible for arbitration.
    • “It is early, and the devil will be in the details, so to speak, as conversations continue, but overall a positive vibe,” said one of the four people familiar with the discussion. Another of the four, who was a provider attendee, said, “It was pointed but respectful.” * * *
    • What’s next: The Senate HELP Committee will hold a roundtable with members next week to talk through legislative solutions.”

From the judicial front,

  • Healthcare Dive reports,
    • “A group of independent pharmacies in Arkansas are suing Express Scripts, one of the largest pharmaceutical middlemen in the U.S., for allegedly underpaying for tens of thousands of prescriptions.
    • The lawsuit filed Tuesday, which seeks hundreds of millions of dollars in damages, is the first filed under a state law passed last year giving Arkansas pharmacies the ability to go after PBMs for reimbursing them below the acquisition cost of drugs, according to lawyers for the plaintiffs.
    • “We’re committed to reimbursing pharmacies at competitive rates and will defend ourselves against these allegations,” an Express Scripts spokesperson said.

From the public health and medical / Rx research front,

  • The New York Times offers advice on whether you are eating enough fiber in your diet.
    • “With so much attention on protein lately, you’d be forgiven for forgetting about fiber.
    • “But if you’re like most adults in the United States, you’re probably falling short of the recommended minimum of 21 to 38 grams per day, depending on your age and sex. The average U.S. woman consumes about 15 grams of fiber daily, and men consume about 18 grams per day.
    • “Closing that gap may be one of the best strategies for improving your health. Fiber nourishes gut microbes, lowers blood pressure and cholesterol, improves digestion and reduces the risks of heart disease, Type 2 diabetes and certain cancers.
    • “It can seem like a big challenge to eat enough fiber, but nutrition experts say it doesn’t have to be. You just have to know where to look.”
  • Cardiovascular Business adds,
    • “Eating four to six servings of whole-grain foods per day is associated with multiple cardiovascular benefits, according to a new meta-analysis published in European Heart Journal
    • “The authors focused on data from more than 6,500 adults from the United States, Europe, Asia, Canada, Australia or Brazil who participated in one of 87 different clinical trials. Overall, eating 48 grams of whole-grain food—oats, brown rice or quinoa, for example—each day was associated with improvements in body weight, waist circumference, total cholesterol, blood pressure, LDL cholesterol, glucose and interleukin-6 levels. These are all known risk factors of cardiovascular disease.
    • “This is the largest and most comprehensive meta-analysis of randomized controlled trials on whole grain intake and cardiovascular risk factors,” senior author Helda Tutunchi, PhD, a nutrition specialist with Tabriz University of Medical Sciences in Iran, explained in a statement. “Unlike previous reviews, we looked specifically at how much whole grain people need to eat to get the greatest benefits. We also evaluated the certainty of the evidence and found high-certainty evidence for improvements in several outcomes, including body weight, waist circumference and total cholesterol.”
    • “Tutunchi added the impact of eating more whole-grain foods appears to be through “several modest improvements acting together” as opposed to “one large effect on a single risk factor.”
  • Health Day relates,
    • “Women’s risk of having a harmless tumor caught and treated as a result of breast cancer screening is much lower than once thought, a new evidence review has concluded.
    • “Overdiagnosis — the detection of breast cancers that never would have harmed a woman’s health during her life — occurs in fewer than 5% of cancer screenings, researchers reported Sept. 14 in the Journal of the National Cancer Institute.
    • “That’s far lower than previous estimates, which held that as many as 30% to 50% of breast cancer detected through screening might represent overdiagnosis, researchers said.
    • “These earlier studies were inaccurate because they tracked breast cancer screenings for a limited period of time, the research team argued.”
  • and
    • “ADHD is linked to a nearly 50% increase in GI problems, a new evidence review says.
    • The association was even stronger for specific GI problems, including an almost doubled risk of constipation, a 58% increase in irritable bowel syndrome and more than four times higher odds of losing bowel control, researchers reported Sept. 10 in the Journal of Attention Disorders.
    • “Almost every gut symptom we looked at: constipation, IBS, even indigestion, appeared to be associated with ADHD,” said lead researcher Sarah Blake, a medical student at the University of Warwick Medical School in the U.K.
    • “These symptoms can have a real impact on daily life, but they could easily be overlooked if the focus is on ADHD itself,” she added in a news release.
    • “There are several potential explanations for these links, including ADHD-related eating patterns, side effects from medication and even ties between ADHD and gut bacteria, researchers said.”
  • Genetic Engineering and Biotechnology News tells us,
    • “Scientists studying Alzheimer’s disease have long focused on genes, proteins, and cells, but one class of molecules has remained largely outside the playbook: microproteins. These small proteins, produced from small open reading frames (ORFs) and typically measuring 150 amino acids or fewer, have been difficult to detect and study. Yet growing evidence suggests they may have important roles in health and disease.
    • “Now, researchers at the Salk Institute have created what they describe as the first microprotein atlas of the human frontal cortex with and without Alzheimer’s disease. The study, “A microprotein atlas of the human frontal cortex in Alzheimer’s disease,” was published in Nature Aging. The resource integrates transcriptomics, mass spectrometry, and deep-learning-predicted spectra across postmortem brain samples to identify microproteins that have been overlooked in standard protein catalogs.
    • “We still do not fully understand the molecular mechanisms of healthy aging, and that is especially true for microproteins, which have been inadvertently overlooked for decades,” said senior and co-corresponding author Alan Saghatelian, PhD, professor and the Dr. Frederik Paulsen Chair at Salk, in a press release. “Our atlas allows scientists to systemically investigate microproteins in aging and neurodegeneration, which should bring us closer to understanding and tackling diseases like Alzheimer’s or Parkinson’s.”
  • Per an Institute for Clinical and Economic Review (ICER) news release,
    • “The Institute for Clinical and Economic Review (ICER) today posted its revised Evidence Report assessing the comparative clinical effectiveness and value of tavapadon (AbbVie Inc.) for Parkinson’s Disease.
    • Downloads: Evidence Report | Voting Questions | Public Comments | Response to Public Comments
    • “Parkinson’s disease is a chronic and progressive neurological condition largely characterized by the loss of motor skills and physical function,” said ICER’s Chief Scientific Officer and Director of Health Technology Assessment Methods and Engagement, Dan Ollendorf, PhD, MPH. “There are currently no disease-modifying treatments, so symptom management is paramount. While tavapadon provides some relief from key symptoms, benefits were similar to those of older, generic drugs, and discontinuation from tavapadon due to adverse events was relatively high. The combination of modest benefit and uncertainties around discontinuation raise important questions about tavapadon’s long-term value.”
    • Register here to watch the live webcast of the October 1st ICER public meeting.

From the U.S. healthcare business and artificial intelligence front,

  • Beckers Hospital Review reports,
    • St. Louis-based Ascension narrowed its operating loss by $371 million in fiscal 2026, as stronger revenue, higher patient volumes and operational improvements moved the health system closer to breakeven, according to financial documents published Sept. 16.
  • and
    • “Fitch revised Chicago-based CommonSpirit Health’s rating outlook to negative from stable on Sept. 16, while affirming the health system’s “A-” rating. 
    • “The revision follows CommonSpirit’s financial results through the quarter ended March 31, which fell short of management’s internal margin targets, Fitch said in a Sept. 16 report. Fitch pointed to an uneven path to sustained profitability as the system executes several overlapping initiatives at once, including an Epic EHR rolloutinsourcing revenue cycle operations and its multiphase Project Impact plan, which targets an 8% EBITDA margin by fiscal 2029.” 
  • Beckers Behavioral Health relates,
    • U.S. News & World Report named 50 hospitals to its 2026-2027 Best Children’s Hospitals Pediatric & Adolescent Behavioral Health list.
    • U.S. News evaluated 91 hospitals for their care of children and teens with mental and behavioral health conditions, including autism, anxiety, depression, eating disorders, ADHD, bipolar disorder, schizophrenia, language and learning disorders, and substance abuse and addiction.
    • “Programs and care in areas such as medication screening and safety, speed and efficiency of the emergency department, and management of side effects were among the factors used to rank hospitals.”
  • Beckers Payer Issues tells us,
    • “SCAN Health Plan has emerged as a major Medicare Advantage partner for retailers, with Walmart now partaking in a co-branded plan.
    • “The health insurer and retailer are launching the plan in two states, according to a Sept. 16 SCAN news release. More than 2 million enrollees are expected to have access.
    • “The MA offering could tie in pharmacy and vision services, food, and over-the-counter benefits, pending regulatory approval. The news release also said Walmart will leverage Everyday Health Signals, its AI-driven platform for tailored nutrition and wellness, in the collaboration.
    • “What makes this collaboration unique is Walmart’s role in customers’ everyday lives. Because customers regularly turn to Walmart for groceries and other everyday essentials, we have an opportunity for those who choose to participate, to use insights from their shopping experiences to make nutrition guidance more relevant and actionable,” said Pravene Nath, MD, group director for consumer health and data solutions at Walmart U.S.” * * *
    • “In August, SCAN announced plans to roll out insurance products with Costco, as well.” 
  • Beckers Physician Leadership shares the new math of physician independence.
    • “Independent physicians have spent more than a decade watching the share of their peers who own their own practices shrink
    • “New data exists that tells the story of what it now costs to stay independent, how much deal-making and closure activity is still working against that choice, and where regulators and a new wave of physician-owned infrastructure are starting to push back.
    • “Taken together, the figures describe less a single trend than a recalculated equation — one where the cost of going it alone, the cost of selling and a growing set of options in between are all moving at once.”
  • MedCity News informs us,
    • “Thatch, a health benefits platform, announced on Tuesday that it raised $108 million in funding, reaching a $1 billion valuation.
    • Thatch helps employers offer Individual Coverage Health Reimbursement Arrangements (ICHRAs) — which recently rebranded as CHOICE Arrangements — in which employers can provide their employees tax-free money so they can purchase their own individual health insurance plans. Employees can also use the funds for certain healthcare expenses, including GLP-1s and therapy. More than 5,000 employers use the company, including Jersey Mike’s and Smoothie King. 
    • “The Series C funding round was from The General Partnership, Index Ventures, General Catalyst and Andreessen Horowitz. ADP Ventures, Paychex, Eli Lilly and Company, Scale Venture Partners, QuantumLight, SemperVirens, Quiet Capital and Avid Ventures also participated. In total, Thatch has raised $192.5 million in equity funding.”
  • Fierce Healthcare adds,
    • “Ayble Health secured a $16 million oversubscribed series A funding round to accelerate its expansion into artificial intelligence-driven precision digestive and autoimmune healthcare.
    • “Neon led the funding round, with participation from Unum Ventures, Upfront Ventures, M13, Cleveland Clinic Ventures, DigiTx, Accomplice and several individual investors. 
    • “I’ve been tracking the GI space closely for years, and what Ayble has built is different,” said Kimmy Scotti, Neon founding and managing partner, in a statement. “Having invested early in top digital health companies, I’ve seen what it takes to build a category-defining company in healthcare. Ayble has spent years building the clinical evidence before they scaled the business. That earns trust from the full ecosystem: health systems, payers, and most importantly, patients, and it’s what makes a durable market leader.”
  • BioPharma Dive points out,
    • “Novartis will pay $125 million up front for rights to a delivery platform designed to get drugs into the brain.
    • “Sironax, a Boston-area biotechnology company, said Tuesday that Novartis has exercised an option to acquire full ownership of that startup’s brain delivery platform. Sironax’s technology is meant to overcome a major challenge in neurological drug development: delivering therapeutics across the “blood-brain barrier.”
    • “Sironax will receive the nine-figure payout following the close of the transaction and will continue to retain rights to develop, manufacture, and commercialize certain assets with the platform. The company currently has three programs in early-stage trials that it plans to move forward using the purchase proceeds.”
  • Cardiovascular Business notes,
    • “Jaguar LAA, a new California-based medtech startup, has purchased key assets related to performing left atrial appendage (LAA) closure procedures from Johnson & Johnson. 
    • “Johnson & Johnson has owned these assets since it acquired the medtech company Laminar for $400 million back in 2023. Now, some original Laminar employees have partnered with investment firm Santé Ventures to buy back the assets and push forward as Jaguar LAA, a brand new company.
    • “The financial terms of this acquisition have not yet been made public.” 
  • The Wall Street Journal lets us know,
    • Novo Nordisk NOVO.B, the Danish drugmaker behind blockbuster diabetes and weight-loss drugs Ozempic and Wegovy, is partnering with Anthropic to use artificial intelligence for drug research.
    • “Novo said Wednesday it would use Anthropic’s science-specific platform, known as Claude Science, to help speed up the discovery and development of new medicines and strengthen the pharmaceutical company’s software development.
    • “The partnership is the latest by a slate of major drugmakers, including Eli Lilly, Merck and Roche, that are placing big bets that AI can help them discover and produce medicines more quickly. 
    • “AI can help us increase productivity in R&D and compress the path from research to marketed product. But beyond this, AI tools can also offer completely new scientific opportunities and aid reasoning and understanding of human biology and drug mechanics,” Novo Chief Executive Mike Doustdar said.”

Tuesday report

Simplicity is a virtue.

From Washington, DC,

  • The American Hospital Association News reports,
    • “The House Energy and Commerce Subcommittee on Health held a hearing Sept. 15 to discuss more than a dozen legislative proposals regarding Medicare provider payment and healthcare cybersecurity. The AHA provided comments to the subcommittee on bills designed to improve long-term physician payments, including proposals to increase the budget neutrality threshold in the Medicare physician fee schedule and a bill to replace the Merit-based Incentive Payment System with the Data-driven Performance Payment System. The AHA also commented on bills to provide grants for the adoption of cybersecurity best practices, direct the Department of Health and Human Services to create a strategy for rural hospital cybersecurity staff training, and improve obstetric emergency preparedness in rural healthcare settings.” 
       
  • MedPage Today relates,
    • “Chris Klomp, President Donald Trump’s nominee for deputy HHS secretary, declared his support for the measles, mumps, and rubella (MMR) vaccine at a Senate Finance Committee confirmation hearing Tuesday, but that wasn’t good enough for one of the Democratic senators on the committee.
    • “Klomp, who currently serves as HHS chief counselor, told Sen. Ron Wyden (D-Ore.), the committee’s ranking member, that “Unquestionably, the MMR vaccine is the single most effective public health tool that we have against measles. It’s 97% effective after two doses [in] preventing transmission, and this is the single best thing that we can do to eradicate” the disease, Klomp said.
    • Chris Klomp, President Donald Trump’s nominee for deputy HHS secretary, declared his support for the measles, mumps, and rubella (MMR) vaccine at a Senate Finance Committee confirmation hearingopens in a new tab or windowTuesday, but that wasn’t good enough for one of the Democratic senators on the committee.
    • Klomp, who currently serves as HHS chief counselor, told Sen. Ron Wyden (D-Ore.), the committee’s ranking member, that “Unquestionably, the MMR vaccine is the single most effective public health tool that we have against measles. It’s 97% effective after two doses [in] preventing transmission, and this is the single best thing that we can do to eradicate” the disease, Klomp said.
    • “Committee chairman Sen. Mike Crapo (R-Idaho) took the opposite view. “You have met all of the requirements and standards of this committee in vetting a nominee, and you are completely and well qualified to be deputy secretary at the Department of Health and Human Services,” he told Klomp.” 
  • The Wall Street Journal adds,
    • Pennsylvania health officials announced Tuesday a fourth measles-associated death, the latest fatality in the commonwealth where recently reported deaths from the vaccine-preventable disease have inflamed politics at the local and national level.
    • “The death follows those of two infants in the state’s Lancaster County in mid-August amid a growing measles outbreak. The state health department’s classification of those deaths spurred a highly politicized debate over vaccinations and sparring between the state’s Democratic governor and the nation’s health secretary.
    • “Over the weekend, a coroner in Pennsylvania’s Jefferson County said a 40-year-old woman there died from complications from measles. The Mifflin County Coroner’s Office on Tuesday said an 18-year-old resident died due to a rare neurological complication from measles. The state health department said it worked with local coroners’ offices to determine both individuals tested positive for measles and the deaths didn’t result from an unrelated cause.
    • “That’s four total measles-associated deaths in our Commonwealth and the first Pennsylvania has seen in 35 years,” Pennsylvania Gov. Josh Shapirosaid in a post on social media Tuesday. “These are tragedies, and four families are grieving.”
  • Per a U.S. Census Bureau news release,
    • “The U.S. Census Bureau today announced that real median household income was $87,460 in 2025, the highest on record dating back to 1967.
    • “The official poverty rate fell 0.5 percentage points to 10.2% in 2025. The following 2025 findings were not statistically different from 2024: the Supplemental Poverty Measure (SPM) rate in 2025 was 13.1% and in 2025, 26.7 million people (7.9%) were uninsured for the entire year, according to the 2026 Current Population Survey Annual Social and Economic Supplement (CPS ASEC).
    • ‘These findings come from three Census Bureau reports, “Income in the United States: 2025,” “Poverty in the United States: 2025” and “Health Insurance Coverage in the United States: 2025.”
  • Beckers Hospital Review tells us,
    • CMS will add four condition tracks to its Advancing Chronic Care with Effective, Scalable Solutions (ACCESS) model starting in spring 2027, the agency said in a Sept. 15 news release.  
    • Four things to know: 
      • “The expansion adds heart failure, chronic obstructive pulmonary disease, substance use disorders and tobacco cessation to the model. CMS will also expand support for chronic musculoskeletal pain, extending coverage for certain conditions beyond the model’s initial 12-month care period.
      • “The model already covers hypertension, diabetes, chronic musculoskeletal pain and depression. CMS says 3 out of 4 Medicare beneficiaries qualify for at least one track.
      • “The ACCESS model ties Medicare payments to measurable improvements in patient health rather than paying solely for individual services. Participating organizations can offer virtual care, health coaching, remote monitoring, and connected devices and wearables between regular doctor visits.
      • “There are currently 160 organizations participating in the ACCESS model, and CMS said Medicare will continue to add to the list throughout the model’s 10-year run. The model supports those with traditional Medicare. Medicare Advantage enrollees are not eligible, but CMS said MA plans may offer similar programs.”

From the U.S. Office of Personnel Management front,

  • OPM included the following additions in today’s Federal Register.
    • Rules
      • Reduction in Force; Correction
      • Shared Certificates and Pooled Hiring Actions
    • Proposed Rules
      • Promoting Employee Accountability
  • Federal News Network reports,
    • “The fewest number of federal employees submitted their retirement papers in August as compared to the rest of 2026. The Office of Personnel Managements says it received only 7,618 retirement claims last month. This is down from more than 10,000 claims OPM received in July. Additionally, OPM’s backlog of retirement claims is at the lowest of the year at just over 15,400. The average number of days to process a claim for August also dropped considerably: to 70 days for a digital claim, down from 98 days the month before, and to 79 days for all claims, down from 109 days in July. (Federal retirement claims down, as the backlog hit lows for 2026 – OPM)”
  • Kevin Moss, writing in Federal News Network, discusses
    • “Healthcare affordability series part 8: Enrollment flexibility for two-person families can lead to premium savings.”
      • “Most of the time, self-plus-one is cheaper, but there are plans where you’ll save more enrolling as self & family.”
  • Govexec relates,
    • “More ‘Big Balls’-type young feds are what the OPM chief wants 
      • “In an interview on Monday, Scott Kupor also discussed implementing skills-based hiring, which had been a priority of the Biden administration as well.”

From the U.S. Food and Drug Administration front,

  • STAT News relates,
    • “The Food and Drug Administration is opening applications for a pilot program designed to shorten the amount of time it takes for drugmakers to begin testing their products in humans, the agency announced Tuesday. 
    • “The pilot was first announced in June as part of Operation TrialBlazer, the Department of Health and Human Services initiative that pledged to shorten the FDA’s drug approval timelines and help the U.S. compete with the rapidly accelerating biotechnology industries in countries like China and Australia.
    • “Too often, the U.S. pathway can be measured in years, while other countries’ pathways are measured in months,” the department wrote in the TrialBlazer roadmap.”
  • and
    • “Vera Therapeutics said Tuesday that its recently approved drug Trutakna stabilized kidney function and reduced the risk of kidney-related death and other complications in patients with a chronic autoimmune kidney disease, according to final, two-year results from a Phase 3 clinical trial. 
    • “In July, the Food and Drug Administration granted accelerated approval to Trutakna for the treatment of IgA nephropathy, or IgAN, a disease caused by the buildup of immune antibodies in the kidneys. The condition leads to progressive loss of kidney function and potentially organ failure requiring dialysis.
    • “With the final data from the study in hand, Vera said it will seek full approval of the drug from the FDA during the fourth quarter.”
  • Cardiovascular Business tells us,
    • “XCath Robotics has received the FDA’s breakthrough device designation for its Iris surgical robotic system that performs remote robotic-assisted mechanical thrombectomy in acute ischemic stroke patients.
    • “This represents a significant step forward for the Houston-based medtech company. The FDA’s breakthrough devices drogram helps support the development of medical devices that have the potential to provide more effective treatment for patients with life-threatening or irreversibly debilitating conditions. This provides XCath Robotics with more opportunities to interact with FDA experts and receive support as the company works toward U.S. regulatory approval for the Iris system.
    • “Back in March, the Iris system was used to complete the world’s first telerobotic stroke thrombectomy. Neurosurgeon Vitor Mendes Pereira, MD, chair of advanced neurovascular interventions at the University of Toronto, used the system to perform the historic procedure in Santiago, Panama, while the patient was 120 miles away in Panama City.”

No Surprises Act News

  • The FEHBlog did receive his CMS invitation to join its Independent Dispute Resolution Gateway this morning, and the FEHBlog promptly took CMS up on its offer. The process went smoothly.
  • The Paragon Institute September 15, 2026, Newletter’s kicks off with an article about “Fixing the No Surprises Act’s Broken Arbitration System.”
    • “Congress already required much of this transparency through the NSA’s Advanced Explanation of Benefits provisions, but those requirements have yet to be fully implemented. The administration should finish that work. Once patients have meaningful advance information about networks and prices, there is no justification for a federal arbitration system setting payments for elective care.
    • “For emergency services, a different approach is needed, and Congress has two reasonable options. It could eliminate federal IDR entirely while maintaining the prohibition on balance billing, leaving insurers and providers to settle payment disputes through private arbitration, litigation, or state law.
    • “Alternatively, Congress could retain IDR solely for emergency services but impose meaningful guardrails. Awards should have a reasonable upper limit so arbitration does not continue producing payments wildly disconnected from market prices. Congress should also reform how arbitrators are paid, and if an upper limit is implemented, insurers should face penalties when they fail to pay awards on time.
    • “The administration can make additional improvements now: require arbitrators to explain their decisions, audit firms with unusually high provider win rates or awards, strengthen eligibility reviews, improve arbitrator training, prohibit conflicts of interest and forum shopping, and restore a meaningful filing fee.
    • “The No Surprises Act solved a real problem by protecting patients from bills they could neither anticipate nor avoid. Those protections should remain. But protecting patients from surprise bills does not require a federal arbitration system that rewards providers for staying out of network and raises health care costs for everyone.”

From the fraud, waste, and abuse front,

  • Healthcare Dive reports,
    • “The federal government is once again targeting fraud in durable medical equipment suppliers, publishing a report Monday through the HHS’ Office of the Inspector General that urges regulators to crack down on suspect billing in Medicare Advantage.
    • “The OIG found that, in addition to other issues, MA organizations don’t screen for fraudulent medical equipment suppliers as often when they’re out of network, compared to in-network suppliers.
    • “MA organizations should tighten the screening process for suppliers and the CMS should use its fraud prevention tool more regularly, the OIG said.”

From the public health and medical / Rx research front,

  • The American Hospital Association News reports,
    • “In recognition of Suicide Prevention Month, Susan Szulewski, M.D., president and chief operating officer, McLean Hospital and vice president, Mass General Brigham Behavioral and Mental Health, wrote on the importance of healthcare organizations working to reduce the stigma surrounding suicide and create a supportive environment with timely access to care and a clear path forward. READ MORE
  • Per a CDC news release,
    • “Today, the Centers for Disease Control and Prevention and the Ad Council are launching a new round of public service announcements (PSAs) encouraging people to understand their risk of prediabetes and take action to prevent or delay type 2 diabetes.
    • “Now in its 10th year, the national “Do I Have Prediabetes?” campaign encourages viewers to take a 1-minute prediabetes risk test on DoIHavePrediabetes.org. This year’s “Undo It” PSAs spotlight that while there are many scenarios in life we can’t undo, prediabetes is something that can be reversed. 
    • “Prediabetes is a serious health condition that increases the risk of type 2 diabetes, heart attack and stroke. Because prediabetes often has no symptoms, many people do not know they have it. Research shows that early diagnosis can inspire individuals to adopt healthier habits, including eating better, being active and managing weight, that can reverse prediabetes and delay or prevent type 2 diabetes.
    • ‘If someone receives a high score on the risk test, that person is encouraged to speak to a doctor to confirm a diagnosis of prediabetes with a blood test, then enroll in the National Diabetes Prevention Program.” 
  • Healio tells us,
    • “Development of alcohol use disorder, depression or stress after a traumatic event was a strong predictor of major adverse cardiac and cerebrovascular events for both men and women, researchers reported.
    • “Evaluation of psychiatric predictors of major adverse events may be an important step in the prediction of CV risk after a traumatic event, according to data published in the Journal of the American Heart Association.
    • “Experiencing traumatic events can have long-lasting consequences for mental health that can take many forms, but research to date had yet to comprehensively consider these. Indeed, nearly all work on trauma and CVD had focused on PTSD and other stress-related disorders — the quintessential trauma-related mental health disorders — but depression, anxiety and substance use disorders are also common following trauma and are relevant to cardiovascular disease risk,” Jennifer A. Sumner, PhD, associate professor of psychology at the University of California, Los Angeles, told Healio. “We wanted to comprehensively investigate different posttraumatic mental health conditions as possible predictors of CVD onset. Also, given sex differences in both posttraumatic psychopathology and CVD, we examined whether links between various psychiatric disorders following trauma and CVD might differ for men vs. women.”
  • Health Day informs us
    • “New research suggests that the blood pressure and heart rate guidelines doctors use to guide emergency treatment in children are misleading in cases of traumatic injury. 
    • “These thresholds for “hemodynamic instability” — the inability of the circulatory system to get blood to organs — may be different for children with traumatic injuries versus healthy children, researchers wrote Sept. 9 in the Journal of the American College of Surgeons.
    • “Recognizing hemodynamic instability is fundamental in trauma care because these vital signs tell us when a child may be at increased risk of death or complications and when we may need to intervene,” explained study senior author Dr. Zain Hashmi. He’s an assistant professor of trauma and acute care surgery at the University of Alabama at Birmingham.
    • “Blood pressure and heart rate guidelines are often used by doctors to decide when to start resuscitation treatments, including blood transfusions, Hashmi said in a news release. However, the values used in children were not developed specifically for trauma patients and may not accurately reflect when the risk of death begins to rise in injured children, he added.” 
  • Medscape points out,
    • “A new international consensus statement providing evidence-based guidance on smoking cessation for people with type 2 diabetes (T2D) has been issued by a multidisciplinary international panel called the DiaSmokeFree Working Group. 
    • “The central message “is that smoking cessation needs to be treated as an integral part of diabetes management rather than as generic lifestyle advice,” statement co-author Riccardo Polosa, MD, PhD, professor of internal medicine at the University of Catania in Catania, Italy, told Medscape Medical News.
    • “There is evidence that this is under-prioritized in diabetes care,” he added. “Clinicians understandably focus on glucose, blood pressure, lipids, and medications, while smoking may receive only brief and mostly ineffective advice.”
  • Today’s issue of NIH’s Research Matters covers the following topics:
    • Depression may stall development of new neurons 
      • “Researchers found that a part of the brain important for memory struggles to make new neurons in people with depression.
      • “The study sheds light on how the brain is altered in depression and suggests new treatment targets.”
    • GLP-1 drug slows aging in mice 
      • A GLP-1 drug extended lifespan and prevented age-related decline in older female mice.
      • Understanding how calorie restriction and GLP-1 drugs slow aging could lead to new ways to treat age-related diseases.
    • Antibodies may prevent tick-related syndrome 
      • “Researchers identified rare antibodies that may help combat alpha-gal syndrome, a condition that causes allergic reactions to red meat and dairy products.
      • “With further development, the finding could lead to treatments for this tick-related allergic condition.”

From the U.S. healthcare business and artificial intelligence front,

  • Beckers Payer Issues reports,
    • “Aetna’s two-year financial turnaround has taken hold following a leadership overhaul, thousands of ongoing cost management initiatives and a margin recovery plan expected to complete by 2027.
    • “Once you get the fundamentals in place, you start getting credibility, not only with investors, but internally with our employees, and then, in particular, with our members,” Aetna President Steve Nelson said Sept. 9 at the Wells Fargo Healthcare Conference. “We can be a little more disruptive and innovative. Aetna has a legacy of being innovative in terms of product and clinical programs, and we are getting back to that.”
    • “The insurer has spent the past two years in recovery mode after a period of financial turmoil driven by Medicare Advantage cost pressures, previously unfavorable star ratings and major losses in the ACA business, which it exited for 2026. Mr. Nelson, who also serves as executive vice president at CVS Health, was tapped to lead the insurer in late 2024.”
  • and 
    • “Health Care Service Corp. has completed the rebranding of its Medicare supplement and supplemental health and life products under the HealthSpring name.
    • “The move finishes a transition that began last year, when HCSC shifted the Medicare Advantage and Part D business it acquired from Cigna for $3.3 billion to the HealthSpring brand. 
    • “HealthSpring has more than 3 million members. HCSC said it is the second-largest Medicare supplement carrier by policyholders, with plans available in 48 states and Washington, D.C. Its supplemental health and life products, which include hospital indemnity and dental, vision and hearing benefits, are offered in 49 markets and D.C.”
  • and
    • “The Blue Cross Blue Shield Association has tapped Daniel Serrano to serve as CFO.
    • “The president and CEO of the BCBS Association, Kim Keck, announced the update Sept. 14 on LinkedIn
    • “With critical capabilities for this moment, including a practitioner’s orientation to data-driven financial management and a strong track record of aligning financial performance with operational outcomes, Dan is a great fit for our organization,” she said.”
  • Fierce Healthcare adds,
    • “Member trust in insurers is on the decline among Gen Z and Millennials, down 10.5% between 2023 and 2026, new research from Accenture found.
    • “This trust gap, according to analysts, could cost $3 billion in future member lifetime value for the largest commercial payers over the next decade. 
    • “When members don’t trust their health plan, they don’t just disengage; they route around it,” said Bracken Flynn, Accenture’s Health industry principal director, in a statement. “Our data shows that younger consumers aren’t asking for less from their insurer. They want more. They’re looking for a partner that helps them navigate care, understand costs, and make confident decisions. The insurers that earn that trust now will define what health coverage means for the next generation.”
    • “During a Sept. 14 AHIP webinar, Flynn said the report—which polled 1,200 consumers—found members trust insurers when they believe the health plan will help them make good healthcare decisions and navigate them to the best care.
    • “That’s across clinical and administrative touchpoints,” Flynn said. “And so it’s a partnership. In practice, it’s a partnership.”
    • “The lack of trust in insurers is causing younger members to turn to artificial intelligence tools, with 62% of respondents saying they have used AI to help choose a health plan.”
  • The American Hospital Association News relates,
    • “A new report from Kaufman Hall prepared for the AHA highlights new insights and data on hospital mergers and acquisitions. An AHA blog accompanying the report is also available.
    • “The report discusses how hospital merger reviews should look beyond the potential impact on commercial insurance prices and consider what proposed transactions mean for all patients, particularly the nearly 60% of hospital patient days attributable to Medicare, Medicaid and Medicare Advantage beneficiaries whose payment rates are largely set by government programs. Drawing on analyses of challenged and canceled transactions, the report also finds that hospitals seeking partners often serve more vulnerable communities and face greater financial pressures, and that when proposed deals do not move forward, struggling hospitals can experience significant financial deterioration that threatens services, workforce stability and access to care.
    • “These findings suggest that a more comprehensive analysis of hospital M&A transactions, one that considers impacts on all patients served, broadens the focus to impacts beyond pricing, and considers the consequences if an M&A transaction is not permitted to proceed, would ensure not only competitive but also healthy hospital markets that can continue to provide the fullest possible range of services,” the report says.”
  • AHIP relates,
    • “New data highlighted by Washington Post Intelligence show hospital system consolidation continues to accelerate, with 40 new mergers and acquisitions announced already in the first half of 2026 — nearly as many as throughout all of 2025. 
    • “Clear evidence demonstrates that anticompetitive hospital consolidation leads to higher healthcare costs for patients, families and employers. Hospital spending already makes up the largest share (40%) of insurance premiums, accounting for over $1.6 trillion in spending nationwide.”
  • Beckers Hospital Review adds,
    • “Salt Lake City-based Intermountain Health has acquired the nine-story, 235,000 square-foot Fairbourne Building in West Valley City, Utah, and plans to convert it into a medical campus.”
  • and
    • “The nonprofit parent organization of OpenAI — the Open AI Foundation — has given $40 million to Chapel Hill, N.C.-based UNC Lineberger Comprehensive Cancer Center to generate data that can be used to develop more precise, personalized cancer vaccines. 
    • “UNC Lineberger researchers, led by immunologist Benjamin Vincent, MD, and computational biologist Alex Rubinsteyn, PhD, will gather deidentified tumor tissue and immune cell data that will train AI models to identify cancer cell targets for vaccines, according to a Sept. 15 news release from the cancer center. 
    • “Researchers will also conduct clinical trials to compare multiple vaccine formulations for triple-negative breast cancer, the release said.”
  • Cardiovascular Business points out,
    • U.S. News & Report has published its annual ranking of the top children’s hospitals in the United States, once again producing a separate list for the best hospitals for cardiology and heart surgery. This represents the 20th year that U.S. News.& World Report has compiled these rankings.
    • “For two decades, U.S. News has helped guide families to top-tier pediatric care,” Ben Harder, chief of health analysis and managing editor at U.S. News, said in a statement. “Finding the right medical team for a rare diagnosis or complex surgery can be overwhelming, and U.S. News’ annual evaluation of the Best Children’s Hospitals provides a clear starting point for parents and referring pediatricians alike.”
    • “Nearly 200 U.S. facilities were eligible for these rankings. Each one is either a freestanding children’s hospital or a large multidisciplinary pediatric department working within a major medical center.
    • “This latest ranking of the Best Children’s Hospitals for Cardiology and Heart Surgery includes some familiar names at the top. For instance, Texas Children’s Hospital in Houston is No. 1, just like it was in 201920202021202220232024 and 2025
    • “Meanwhile, Children’s Hospital Colorado and Duke Children’s Hospital and Health Center are No. 2 and No. 3, respectively. That is where each one landed in the previous year’s ranking as well. 
    • “Going a bit deeper, Children’s Hospital of Philadelphia came in at No. 4, and Children’s Health Dallas came in at No. 5.” 
  • MedCity News lets us know,
    • “Virtual solutions for chronic kidney disease (CKD) management don’t slow disease progression, nor do they reduce total healthcare spending, according to a new analysis by the Peterson Health Technology Institute (PHTI).
    • PHTI is an independent evaluator of digital health solutions. For the analysis, PHTI reviewed more than 5,400 articles and other evidence. The solutions evaluated in the report include DaVita IKC, Evergreen Nephrology, Healthmap Solutions, Interwell Health, Kidneylink, Monogram Health, Somatus and Strive Health. These companies take on financial responsibility for the total cost of care for patients with stage 3–5 CKD, and typically work with Medicare Advantage plans and Medicare’s Kidney Care Choices model.
    • “The assessment focuses on managing chronic kidney disease before patients progress to end-stage kidney disease, including the need for dialysis or a kidney transplant.”
  • Managed Healthcare Executive tells us,
    • “GLP-1s now dominate market momentum, with obesity products surging from near-zero in 2022 to $55B annually and diabetes GLP-1s sustaining double-digit year-over-year growth. 
    • “Independent pharmacies are reassessing dispensing economics, with refusal rates declining to 35% for weight-loss GLP-1s and 8% for diabetes GLP-1s. 
    • “Distribution remains retail-heavy (~80%), but mail fulfillment is increasing, reaching 12.9% of GLP-1 prescriptions as direct-to-consumer channels expand. 
    • “Diabetes category mix is shifting away from insulin, whose sales share has dropped to 9.8% and prescription share to 16%, reflecting GLP-1 substitution dynamics. 
    • “Medicare Part D Bridge uptake appears immediate, with 9,000 paid claims in three days, alongside a large pipeline exploring neuropsychiatric, SUD, cancer-risk, women’s health, and systemic inflammation indications.”
  • The Wall Street Journal informs us,
    • “Legend Names Novartis Executive as CEO
      • “Ingrid Zhang takes the helm of the cancer therapy company, filling a post vacant since its previous CEO abruptly resigned in July.”
  • Per Beckers Health IT,
    • “Oracle has expanded its fiscal 2026 restructuring plan by approximately $700 million, bringing expected costs to roughly $2.8 billion as the company pursues strategic initiatives and operational efficiencies that include adopting and integrating AI across certain functions.
    • “The Sept. 11 Securities and Exchange Commission filing does not specify what actions the additional $700 million will cover or how many employees could be affected. Oracle said restructuring expenses under the broader plan include employee severance, contract termination and other exit costs.
    • “As of Aug. 31, prior to the additional $700 million, Oracle estimated total restructuring costs of up to $2.1 billion.
    • ‘The disclosure comes as Oracle employees across social media reported a recent round of layoffs, including at Oracle Health. Business Insider first reported the layoffs Sept. 14, citing three people affected and an email notification.”
  • and
    • “Mayo Clinic and Thermo Fisher Scientific have launched Precure, a joint venture designed to detect biological signs of disease before patients develop symptoms, according to a news release shared with Becker’s.
    • “Rochester, Minn.-based Mayo Clinic, will serve as majority owner of the entity and Thermo Fisher joins as a minority partner. Precure will build one of the world’s largest human multi-omics datasets — integrating proteomic and genomic data with longitudinal clinical information drawn from 1 million biospecimens collected over several years, according to the release.
    • “At Mayo Clinic, we are committed to transforming patient care through innovation,” said Gianrico Farrugia, MD, president and CEO of Mayo Clinic. “By harnessing the full potential of multi-omics data, Precure, LLC aims to help us better understand disease before symptoms appear.”
    • “Thermo Fisher will contribute its Olink Explore HT proteomics platform and Orbitrap mass spectrometry technology to the effort. Marc Casper, Thermo Fisher Scientific’s chairman and CEO, said the venture has “the potential to create a step change in how we generate and apply multi-omics data to improve human health.”
    • “Target disease areas include cancer, cardiometabolic conditions, neurological disorders and immune-mediated disease — conditions where biological changes often precede clinical diagnosis by years. Advanced AI and large-scale data analytics will be used to identify patterns across the datasets and translate them into actionable insights.”
  • Per Beckers Clinical Leadership,
    • “The nonprofit parent organization of OpenAI — the Open AI Foundation — has given $40 million to Chapel Hill, N.C.-based UNC Lineberger Comprehensive Cancer Center to generate data that can be used to develop more precise, personalized cancer vaccines. 
    • “UNC Lineberger researchers, led by immunologist Benjamin Vincent, MD, and computational biologist Alex Rubinsteyn, PhD, will gather deidentified tumor tissue and immune cell data that will train AI models to identify cancer cell targets for vaccines, according to a Sept. 15 news release from the cancer center. 
    • “Researchers will also conduct clinical trials to compare multiple vaccine formulations for triple-negative breast cancer, the release said. 
    • “These efforts aim to create a public, multimodal dataset to “help reach a future where cancer patients can get rapid personalized cancer vaccines when they are diagnosed,” the OpenAI Foundation said in a Sept. 15 news release. 
    • “UNC Lineberger’s $40 million grant is part of a $125 million funding program, called Public Data for Health, established by the foundation.”
  • and
    • “Ambient artificial intelligence handed many physicians their evenings back. For nurses, the same promise is proving harder to keep, and the reason is buried in the flow sheet.
    • “Physician ambient scribes listen to a visit and draft a narrative note when it ends. Nursing documentation does not work like that. It lives in structured flow sheets, entered field by field across a shift, every time a nurse assesses, medicates or turns a patient.
    • “Nursing documentation occurs throughout the entire shift. It’s every time we interact with a patient,” said Stephanie Clements, BSN, RN, senior vice president and chief nurse executive at Chesterfield, Mo.-based Mercy. “It’s very different than summarizing care at the end of a period.” 
    • “That difference is why early attempts to copy the physician model — record the encounter, generate the note — have not mapped cleanly onto the bedside, and why some nurses have found the tools slower, not faster, at first.
    • “Yet the systems furthest along say the payoff is real when the technology is built for nurses from the get-go.” 

Notable Deaths

  • The New York Times reports
    • “Harold P. Freeman, an influential oncology surgeon whose knowledge of the devastating effects of breast cancer on poor Black women inspired him to create a landmark program at Harlem Hospital Center, helping patients navigate the health care bureaucracy, died on Aug. 11 in Atlanta. He was 93.
    • “His death, at a hospital, was confirmed by his son Neale.
    • “Dr. Freeman’s patient navigation program became a model for hospitals around the world, helping to eliminate barriers to early cancer detection. The program’s success influenced the passage of the federal Patient Navigator Outreach and Chronic Disease Prevention Act of 2005, which provided $25 million for similar programs across the United States. In 2024, Medicare began providing providers with reimbursement for some navigation services for cancer, heart failure, H.I.V./AIDS and other high-risk conditions.
    • “There are no navigation events or meetings that don’t acknowledge Dr. Freeman’s role in patient navigation,” Dr. Shanthi Sivendran, the interim chief patient officer of the American Cancer Society, said in an interview. “There wasn’t a patient navigation concept before him.”
  • and
    • “The milk truck would pull up to the house, and out would come the groceries — not just milk, but also eggs, cheese, juice, cereal and baby formula. It might have stopped at a rich family’s house, or a poor one. No one could tell the difference, which was precisely the point.
    • “Vermont’s supplemental food program for low-income women, infants and children, the first in the nation to be implemented statewide, began in 1974. It was the brainchild in part of Dr. Anthony Robbins, then one of the country’s youngest state health commissioners, at 33; he had secured a federal grant to made the program possible.
    • “Not only did the program provide much-needed supplies, but it also shielded families from the stigma of receiving public assistance.
    • “The milk truck was stopping at practically every house — high income, low income, whatever,” Donna Bister, a former director of the program, known widely as WIC, said in an interview. The program is now available in all 50 states.” * * *
    • “Dr. Robbins died on July 5 at his home in Rockport, Mass. He was 85. His death, which was not widely reported at the time, was caused by complications of long Covid, heart disease and Parkinson’s disease, his wife, Phyllis Freeman, said.
    • “He was considered to be on the cutting edge of health care,” Madeleine Kunin, a former governor of Vermont, said in an interview. “He was a bright light.”
  • RIP Doctors.

Cybersecurity Saturday

From the frontier AI / Project Glasswing front

  • Daniel Borish writes in LinkedIn,
    • Anthropic released its fourth threat intelligence report on September 10, 2026, covering activity its Threat Intelligence team disrupted between December 2025 and August 2026. The report documents cases across seven categories of harm: cyber operations, surveillance, influence operations, conventional weapons development, biological misuse, scams and fraud, and illicit distillation. The company assigns each disrupted actor an internal designator, a Generative Threat Group (GTG) number, and publishes case studies detailing how each group used Claude models, along with indicators of compromise for other defenders to act on.
    • “The report’s central claim is not that AI created new categories of attack. Credential theft, phishing, SQL injection, and unpatched edge devices remain the entry points they have always been. What changed is who can run these attacks at what speed. Anthropic’s investigators found a suspected Russian state espionage unit, a network of financially motivated ShinyHunters affiliates, Chinese university students moonlighting in exploit research, and a lone French hacktivist all using functionally similar AI-orchestrated methodologies to run multi-victim campaigns that would previously have required coordinated teams.”
  • The Wall Street Journal reports,
    • “Artificial intelligence agents being tested by OpenAI launched a cyberattack against a popular software service two months before they hacked the AI software company Hugging Face, a new signal of the potential for advanced AI tools to slip out of human control.
    • “The attack overwhelmed maintainers of an online service for coders, called RubyGems, and forced them to shut down new account registrations as they dealt with the chaos it had caused, operators of the service said.
    • “A coalition of AI researchers said it had unearthed evidence that OpenAI agents were behind the May attack and shared its findings with The Wall Street Journal and OpenAI. The AI developer on Friday confirmed that its agents had been involved in an incident involving RubyGems.
    • “Based on our review, our agents used the RubyGems platform to access the internet to carry out benign tasks and retrieve public information. We’ll continue to investigate as part of our broader review of agent activity during training and evaluation,” an OpenAI spokeswoman said in a statement.”
  • and
    • “An Anthropic researcher is quitting the artificial-intelligence industry over fears that the lab and its competitors are racing to build systems they won’t be able to control, a sign of mounting safety concerns within top AI companies.
    • “Jacob Coxon, a researcher who specializes in training new AI models by having them consume vast amounts of data, said Tuesday that he is leaving the company because he doesn’t want to participate in an industrywide rush to build AI systems that can improve themselves, worried such systems could spiral out of control and destroy humanity.
    • “The 27-year old Brit, who previously studied mathematics, said many of his industry colleagues now use phrases like “crunchtime” and “endgame” to describe the trajectory toward self-improving models.” * * *
    • “Anthropic didn’t immediately comment on the departure. Chief Executive Dario Amodei and other company leaders have repeatedly warned about the risks of rogue AI models, and urged the industry to slow development
    • “After Coxon announced his departure, a top scientist at the company, Evan Hubinger, wrote on X that he thought Coxon was correct about the risks of AI development.
    • “We really do earnestly believe AI could kill all humans! I personally think it is >10% within the next decade,” Hubinger wrote. “I believe Anthropic is trying its best, but we do not yet have a plan to solve alignment for superintelligence and are not clearly on track to.” Others also amplified the view.”
  • Per Axios: “Nvidia CEO Jensen Huang: AI fears designed to generate cybersecurity business.”
  • BigGo Finance lets us know,
    • “A bipartisan group of US senators is negotiating legislation that would create a legal duty of care for frontier AI developers, requiring them to prevent catastrophic risks and giving the federal government authority to block unsafe model releases. The proposal, led by John Thune, Ted Cruz and Amy Klobuchar, would apply to advanced models from companies such as OpenAI, Anthropic and Google, with national laboratory experts potentially conducting hands-on testing for nuclear, biological and cyber threats. Companies could appeal government blocking decisions in federal court. The measure would also preempt state AI safety laws. With the House in session only one week before the November 3 midterms, passage remains uncertain despite growing pressure on Congress to address frontier AI risks.”
  • Axios adds,
    • “A letter is circulating among House members urging Speaker Mike Johnson (R-La.) to bring back the House “immediately” and keep it in session until Congress passes AI safeguards, Axios has learned.”
  • The Wall Street Journal notes,
    • “President Trump, who has taken a light touch overseeing the sector, previously said he is in favor of kill switches and other steps to keep AI safe but has warned burdensome regulation could cost the U.S. in the tech race.”
  • and
    • “The leaders of three of the biggest AI companies agreed [September 12] that they needed to slow development of the technology before their advances create a menace that can’t be controlled.
    • “It was a rare display of unity by Elon MuskSam Altman and Dario Amodei, who have been spending tens of billions of dollars to develop evermore powerful artificial intelligence models. Altman even suggested that his company, OpenAI, may need to delay its much-anticipated IPO to focus on safety.”

From the cybersecurity policy and law enforcement front,

  • Per GovCIO Media,
    • “Federal agencies are looking to deepen their partnership with the private sector to protect critical infrastructure, with joint efforts to identify vulnerabilities, deploy technology and scale solutions.
    • “National Cyber Director Sean Cairncross said Thursday [September 10] at the Billington Cybersecurity Summit in Washington that government and industry need to work “hand in glove” rather than rely on compliance checklists as technology increasingly shapes both critical infrastructure and the threats against it.
    • “We’re in a moment technologically where security and innovation have melded, and in order to move forward, protect critical infrastructure, make sure the systems that our citizens rely on for daily life are protected and secure, we need a relationship that is hand in glove, and that means we cannot be dictating a compliance checklist to industry,” said Cairncross.”
  • Federal News Network reports,
    • “The FBI released its first agency-wide, unclassified cyber strategy on Wednesday, with the goal of unifying efforts across the bureau’s 56 field offices to counter both nation-state threats and cyber criminals.
    • “The 17-page strategy details a four-pillar approach to countering cyber threats across the bureau. Brett Leatherman, assistant director of the FBI’s Cyber Division, said previous cyber strategies for the bureau have either been classified or focused on specific threats, like countering China.
    • “This is a comprehensive strategy that directs our teams, our field offices, our global presence, and how we are to align all our efforts to counter this work,” Leatherman told reporters after speaking at the Billington Cybersecurity Summit in Washington on Wednesday morning [September 9].”
  • and
    • “The CIA is pushing to bring more scientific and technical expertise into its workforce, with a top official touting a big year for hiring despite widespread cuts across the intelligence community over the past year.
    • “Michael Ellis, the deputy director of the CIA, said the spy agency is seeking to recruit more employees with backgrounds in science and technology. Ellis described a STEM background as not a prerequisite for intelligence in work in 2026, but “it sure helps make things easier.”
    • “When I think about, you know, where we want the CIA workforce to be five years from now, it’s an elite workforce,” Ellis said at the Billington Cybersecurity Summit in Washington on Tuesday. “It’s a nimble workforce. It’s one that has more technical background than it has today, and it’s one that is motivated by mission.”
  • Cybersecurity Dive adds,
    • “As the federal government scrambles to protect its own networks and support critical infrastructure operators, CISA is preparing to bring in roughly 250 new employees to rebuild core teams.
    • “We’re looking forward to welcoming hundreds of new CISA employees in the very near future,” acting CISA Director Nick Andersen told reporters after a talk at the Billington Cybersecurity Summit here on Wednesday.
    • “The employees have received tentative job offers and are “waiting to get that official start date,” Andersen said during his speech.”
  • Cyberscoop points out,
    • “The private sector still isn’t sharing enough cyber information with the FBI in part because organizations are operating on false assumptions about what the bureau will do with what it collects, the FBI’s top cyber official said Wednesday.
    • “Brett Leatherman, assistant director of the FBI’s cyber division, said in remarks at the Billington CyberSecurity Summit and in a discussion with reporters that organizations stand to benefit from bringing in the bureau when it’s compromised by hackers from the People’s Republic of China (PRC) and others. But one of the “key misconceptions” is that “the FBI is somehow sharing information with regulators for regulatory purposes, and that’s not the case.”
    • “From my standpoint over the last few years, I think we’ve seen a hesitancy on some companies to engage [with the] FBI,” Leatherman said.”
  • and
    • “The U.S. government is accusing Chinese AI companies of engaging in a deliberate and “systematic” effort to illegally distill U.S. frontier AI models and their capabilities. 
    • “According to a joint cybersecurity advisory from the National Security Agency, the Cybersecurity and Infrastructure Security Agency and the FBI, the sheer scale of these efforts since 2024 indicate that distillation is a critical part of China’s AI industrial policy.
    • “China-based artificial intelligence companies are conducting systematic extraction of proprietary functionalities and capabilities of U.S. AI companies’ models through industrial-scale knowledge distillation campaigns that form the core—not merely a supplement—of their AI development strategy,” the agencies wrote. 
    • “The advisory names Chinese companies like DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI, saying they spent billions of tokens across millions of exchanges and requests with frontier U.S. AI models like Anthropic’s Claude, OpenAI’s ChatGPT, Google Gemini, and xAI’s Grok, since at least late 2024.”
  • The Justice Department made available “Remarks by Deputy Assistant Attorney General Josh Goldfoot of the Justice Department’s Criminal Division at the International Symposium on Cybercrime Response” held in Seoul, Korea.
  • Beckers Health IT notes,
    • “A Ukrainian national who helped deploy Conti ransomware against more than 1,000 victims worldwide has been sentenced to four years in prison for conspiracy to commit wire fraud.
    • “Oleksii Oleksiyovych Lytvynenko, 44, formerly of Cork, Ireland, admitted to joining the Conti operation and coding a “loader” — malware used to deliver other malicious software onto compromised systems, according to a Sept. 10 U.S. Justice Department news release. He pleadedguilty June 10.
    • “Conti attacked computers and networks in 47 states, the District of Columbia, Puerto Rico and 31 countries between 2020 and 2022, and the FBI estimates the group collected more than $150 million in ransom payments. Evidence from Mr. Lytvynenko’s online accounts showed he possessed data stolen from eight U.S. victims and four overseas victims. He was arrested in County Cork, Ireland, in July 2023.”

From the cybersecurity breaches and vulnerabilities front,

  • HIPAA Journal released its June 2026 Healthcare Data Breach Report.
    • “In June 2026, 66 large healthcare data breaches – data breaches involving the protected health information of 500 or more individuals – were reported to the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) – a slight increase from the 64 data breaches reported in May. More than two large data breaches a day is the new normal. Over the past 12 months, an average of 65 large healthcare data breaches have been reported per day; eight years ago in 2018, large healthcare data breaches occurred at a rate of around one per day.”
  • Beckers Health IT reports,
    • “Houston-based Nutex Health says the hackers behind its August cyberattack have published the data they allegedly stole on their own website.
    • “The publicly traded micro-hospital operator is now downloading, processing and analyzing that data to determine its contents, scope and authenticity, according to a Sept. 10 SEC filing. Nutex said the review could take several weeks given the volume of data involved.” * * *
    • “Nutex said it has not identified any material impact on its business operations or financial reporting systems, and its materiality assessment from the Aug. 31 filing remains unchanged. The company said it continues to evaluate regulatory and legal notification requirements and intends to notify affected patients and employees.
    • “Several purported class action lawsuits have been filed against Nutex in the U.S. District Court for the Southern District of Texas’ Houston Division on behalf of individuals whose personal or health information was allegedly accessed. Nutex said it cannot predict the litigation’s outcome or its potential financial impact.”
  • and
    • “Annapolis, Md.-based Luminis Health’s phone system and MyChart patient portal remain unavailable as the health system continues responding to a cybersecurity incident involving an unauthorized criminal actor.
    • “In a Sept. 10 update, Luminis Health said its investigation is ongoing and teams are working with third-party experts to safely restore affected systems.
    • “The health system said its hospitals remain open and continue providing patient care.”
  • and
    • Recent cybersecurity warnings and incidents are highlighting risks for healthcare organizations that extend beyond ransomware, including cloud authorization abuse, voice phishing, brand impersonation, third-party access and publicly exposed information.
    • [The article describes] five recent cybersecurity developments Becker’s has reported on in September.]
  • Security Week adds,
    • “More than 4.1 million individuals had their personal, health, and insurance information stolen in a data breach at healthcare company AdaptHealth.
    • “Operating over 680 facilities across the US, AdaptHealth describes itself as a network of medical equipment companies that provides patients with healthcare solutions and medical equipment.
    • “The company was hacked in early June, when a threat actor gained access to its cloud-based applications, including internal systems used for patient management and document storage.
    • “After the attacker contacted the company, it confirmed the data breach, including the theft of a password file associated with insurance billing.
    • “The hacker used social engineering to compromise a user session at a third-party contractor, AdaptHealth said.”
  • and
    • “Future phishing campaigns may no longer involve a detectable physical web page.
    • “Barracuda has analyzed a new type of phishing campaign that adds both stealth and flexibility to traditional phishing. Rather than standard social engineering to persuade a target to visit a static compromised web page, this campaign generates a blob URL to render and deliver the phishing page inside the target’s own browser. This reduces the possibility of security scanners detecting either the social engineering email or the static residence of the phishing page.”
  • HIPAA Journal lets us know,
    • “Three high-severity vulnerabilities have been identified in NextGen Healthcare Mirth Connect (Mirth Connect), a cross-platform healthcare integration engine for connecting, routing, transforming, and exchanging clinical and administrative data between different healthcare systems. The vulnerabilities are due to improper neutralization of special elements used in SQL commands and improper restriction of XML External Entity Reference. Successful exploitation of the vulnerabilities could allow denial-of-service attacks and data exfiltration.
    • “The vulnerabilities were identified by security researcher Abhinav Agarwal using autonomous agents running his published methodology on AI-assisted vulnerability discovery. “Mirth Connect is effectively a switchboard between healthcare systems. It can sit between lab systems, imaging systems, databases, and clinical applications, so a vulnerability in the integration layer can expose much more than one isolated application,” Agarwal told The HIPAA Journal. A potential problem is that healthcare organizations may not know that they have a vulnerable component in one of their products. “A hospital may not see the name Mirth anywhere on the product it bought. Integration software can be managed, resold, or embedded inside another product, which is why SBOMs and exact version disclosure matter after vulnerabilities like these,” explained Agarwal.”
  • CISA added 14 known exploited vulnerabilities to its catalog this week.
    • September 8, 2026
      • CVE-2026-75650 Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
      • CVE-2026-81963 Microsoft Windows Link Following Vulnerability  
      • CVE-2026-85880 Microsoft Windows Heap-Based Buffer Overflow Vulnerability 
      • CVE-2026-86218 N-able N-central Static Code Injection Vulnerability
        • SOC Prime discusses the Adobe KVE here.
        • The Hacker News discusses the Microsoft KVEs here.
        • Cybersecurity Dive discusses the N-able KVE here
    • September 9, 2026
      • CVE-2025-25249 Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
      • CVE-2026-19490 Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability
      • CVE-2026-87491 Google Chromium V8 Out of Bounds Write Vulnerability
      • CVE-2026-20079 Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability 
        • Security Week discusses the Fortinet KVE here.
        • Cybersecurity News discusses the Citrix KVE here.
        • SOC Prime discusses the Google KVE here.
        • The Cybersecurity Hub discusses the Cisco KVE here.
    • September 10, 2026
      • CVE-2026-67277 MikroTik RouterOS Missing Authentication for Critical Function Vulnerability
      • CVE-2026-86060 MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability
        • Bleeping Computer discusses these KVEs here.
    • September 11, 2026 (1)
      • CVE-2026-42016 JFrog Artifactory Incorrect Authorization Vulnerability 
      • CVE-2026-42018 JFrog Artifactory Improper Authentication Vulnerability 
      • CVE-2026-84869 ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
        • The Hacker News discusses the JFrog KVEs here.
        • Security Arsenal discusses the ConnectWise KVE here.
    • September 11, 2026 (2)
      • CVE-2026-85706. GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability
        • Cyberscoop discusses this KVE here.
  • Dark Reading adds,
    • “A new analysis of public data from Anthropic’s Project Glasswing has highlighted a significant gap between the number of vulnerability findings generated by its Claude frontier model and those that ultimately prove to be real, serious, and worth fixing.
    • “The distinction matters because it suggests that the bottleneck in vulnerability research may increasingly lie in validating new flaws and coordinating their remediation rather than in discovering them.”
  • Security Week tells us,
    • “Anthropic disrupted a cyberespionage operation whose tradecraft and targeting match the Russian state-nexus group tracked as Midnight Blizzard, the company said in a threat intelligence report published this week. 
    • “The report covers activity the company identified and shut down between December 2025 and August 2026.
    • “According to Anthropic, Midnight Blizzard used Claude to monitor how well its malware evaded detection by security products. When a tool was flagged, AI agents automatically modified and rebuilt it, then redeployed it, repeating the process until the malware went undetected again.”

From the ransomware front,

  • The Hacker News reports,
    • “Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC) vulnerabilities.
    • “The attacks leverage CVE-2026-20079 (CVSS score: 10.0), an authentication bypass vulnerability in the web interface of FMC software that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.
    • “The second flaw under exploitation is CVE-2026-20316 (CVSS score: 5.3), which could allow an unauthenticated, remote attacker to log in to an affected device using a low-privilege account to access sensitive data within susceptible systems. It can be paired with other Cisco Secure FMC vulnerabilities to elevate privileges.” * * *
  • Cybersecurity Insiders relates,
    • “Ransomware attacks are becoming increasingly common, posing a serious threat to businesses across industries. A recent study conducted by Object First in collaboration with technology research firm Omdia highlights not only the growing frequency of these attacks, but also the increasing difficulty businesses face in recovering their data after an incident.
    • “According to the study, ransomware is having a significant impact on business operations. Over the past 24 months, around 84 percent of businesses surveyed admitted that file-encrypting malware had severely disrupted their operations. This represents a considerable increase from the previous year, when only 64 percent of businesses reported experiencing such disruption.
    • “The findings become even more concerning when it comes to data recovery. Only 39 percent of ransomware victims said they were able to recover at least 80 percent of their data following an attack. This is a sharp decline from the 57 percent reported the previous year. The figures indicate that businesses are not only encountering ransomware more frequently but are also finding it increasingly difficult to restore their systems and recover critical information.” * * *
    • “The decline in successful data recovery also highlights the importance of preparedness. Simply preventing an attack is no longer enough. Organizations need comprehensive backup and recovery strategies that can help them restore critical systems quickly in the event of a successful breach. Regularly tested backups, robust access controls, employee awareness training and well-defined incident-response plans can all play an important role in reducing the damage caused by ransomware.
    • “The latest findings suggest that ransomware has evolved into a broader business continuity challenge. As attacks become more frequent and sophisticated, organizations must focus equally on prevention, detection and recovery. Investing in resilient infrastructure and reliable data protection could prove crucial in ensuring that a ransomware incident does not turn into a prolonged business crisis.”
  • Help Net Security adds,
    • “In this Help Net Security video, Kerri Shafer-Page, VP of Incident Response at Arctic Wolf, walks through the ransomware decision tree in this video. She covers four areas where decisions need settling in advance, starting with containment.
    • “Someone has to know the network well enough to judge what pulling a system offline does to client data, a manufacturing line, or a website. Then comes the extortion demand. Who is authorized to negotiate, and what is the ceiling?
    • “Shafer-Page treats paying as a business decision, noting that a demand can cost less than an insurance retention and higher renewal rates. She argues law enforcement belongs in the playbook, since agencies may know the threat actor and can help you avoid sanctions problems.
    • “Communication matters too, from cyber legal counsel on disclosure deadlines to a spokesperson and a prepared help desk. Her advice: make these decisions on a Tuesday afternoon, not at 2 a.m. on a holiday weekend.”
  • and
    • “In this Help Net Security video, Dave Ross, Senior Director of the Intelligence Fusion Team at Intel 471, explains what happens behind the scenes during ransomware negotiations.
    • “Ross walks through the tactics groups use once an attack begins, from research on a victim’s revenue and insurance coverage to test decryptions that prove they hold a working key.
    • “He describes how demands are often set at roughly 1% to 5% of annual revenue, why deadlines move depending on how a victim responds, and how some groups split work between researchers, negotiators, and staff who apply public pressure.”

From the cybersecurity business and defenses front,

  • Cryptobriefing reports,
    • “Tenable Holdings is embedding Anthropic’s Claude Mythos 5 directly into its flagship cybersecurity product, betting that frontier AI models can fundamentally change how organizations spot and neutralize threats before attackers exploit them.
    • “The integration, announced on September 8, 2026, will bring AI-driven exposure analysis and attack-path discovery into the Tenable One Exposure Management Platform. The first concrete feature shipping under this effort is called Tenable One Adversary View, which uses Claude Mythos 5 to reconstruct how an attacker could move from an initial foothold all the way to an organization’s most critical systems.”
  • Per MedTech Dive,
    • “Boston Scientific disclosed Tuesday the cyberattack that recently hit the company is likely to affect third-quarter and full-year results.
    • “The medical device maker believes it is unlikely to meet net sales growth and adjusted earnings per share guidance ranges provided in July for the third quarter and full year, according to a new filing with the Securities and Exchange Commission.
    • “The Company anticipates recovering some portion of the impacted revenue as it continues to ramp operations globally, fulfill customer orders and reduce remaining backlogs, however the full impacts are not yet known,” Boston Scientific said in the filing.”
  • Cybersecurity Dive relates,
    • “After suffering a series of high-profile cyberattacks over the past decade, Microsoft says a new initiative to reinvigorate its security culture is bearing fruit.”
  • and
    • “Chief information security officers are largely expected to ensure the security of AI across the enterprise, but many say they are not receiving adequate support, according to findings from Proofpoint. 
    • “About 85% of CISOs said ensuring the safe use of AI assistants, copilots and automation is a top priority over the next two years, according to Proofpoint’s annual Voice of the CISO report. Eight of every 10 CISOs said they are expected to manage AI-related security risks without receiving a proportional increase in resources or expertise. 
    • “CISOs have a significant role to play in securing AI adoption, but they can’t own the risk alone,” Patrick Joyce, global resident CISO at Proofpoint, told Cybersecurity Dive. “AI is being adopted across the business, often faster than traditional governance models can keep up.”
  • and
    • “Advances in artificial intelligence aren’t changing the fact that simple cybersecurity failures remain the most consequential, government and industry leaders warned on Tuesday.
    • “What will prevent the attacks in the next 18 months are the same things that would have prevented the attacks of yesterday,” Jason Bilnoski, a deputy assistant director in the FBI’s Cyber Division, said during a panel here at the Billington Cybersecurity Summit.
    • “Core practices such as identity management, perimeter monitoring, cyber hygiene and strong multifactor authentication remain as essential as ever, Bilnoski said.
    • “Speed and capability is certainly increasing with the use of AI, but the end state is still the same,” he said. “How actors are compromising, whether it’s criminal or nation-state, still stays the same.”
  • HIPAA Journal tells us,
    • “The HHS has released an updated version of the Security Risk Assessment (SRA) Tool (v3.7). The tool is ideally suited for small- and medium-sized entities to guide them through the risk analysis process, help them identify risks and vulnerabilities to electronic protected health information (ePHI), and comply with the risk analysis implementation specification of the Security Management Process standard of the HIPAA Security Rule.”
  • CISA has released the 2026 edition of its Insider Threat Mitigation Guide.
    • “The Cybersecurity and Infrastructure Security Agency’s Insider Threat Mitigation Guide aids critical infrastructure stakeholders in comprehending the concept of insider threats, identifying the various forms these threats can take, and implementing best practices to establish or enhance an insider threat mitigation program. Such a program is essential for protecting critical assets, deterring violence, countering unintentional incidents, preventing loss of revenue or intellectual property, averting the compromise of sensitive data, and ultimately saving lives.”
  • Healthcare IT News informs us,
    • “Devices and sensors that collect heart rate and other health data and rely on applications to share information with third parties pose serious questions about data protection for patients and the health systems that care for them.
    • “While smart ring and watch data might help doctors treat patients, security experts say low security standards in consumer tech and improperly configured APIs present potential security risks for providers.
    • “Hackers can exploit such flaws, using consumer devices as entry points to breach receiving electronic health record systems and access centralized databases.
    • “To mitigate these threats, security experts say healthcare organizations must establish strict security protocols, including mandatory transit encryption, multi-factor authentication and account monitoring. They recommend zero-trust approaches to catch rogue traffic and implementation of rigorous engineering frameworks.”
  • Here’s a link to Dark Reading’s CISO Corner.

Thursday report

Simplicity is a virtue.

From Washington, DC,

  • Modern Healthcare reports.
    • “Congress extended most annually funded healthcare programs through December, setting a likely end-of-year deadline for action.
    • “Lawmakers will have to decide which stalled health initiatives, from prior-authorization rules to transparency measures, would advance alongside must-pass extensions.
    • “Anti-fraud proposals could provide budgetary offsets to fund more expensive measures like a new Medicare physician payment system.”
  • Beckers Hospital Review relates,
    • “The Trump administration says it will mail $500 checks to nearly one million Americans in 30 states to refund what it called “overcharges” from ACA exchange fees collected under the Biden administration.
    • “On Sept. 10, the White House said insurers that sell plans on the federal exchange pay user fees to fund the platform’s operations, and that those fees generated a surplus that was never returned to consumers. The refunds, which are set to go out starting in October, will be provided to enrollees who did not receive premium tax credit assistance and paid the full cost of their premiums.” 
  • Per a Department of Health and Human Services news release,
    • “The U.S. Department of Health and Human Services (HHS), through the Health Resources and Services Administration (HRSA), today announced awards to 132 hospitals totaling nearly $25 million through the Rural Hospital Provider Assistance Program to help eligible small rural hospitals maintain their medical workforce, sustain essential healthcare services, and strengthen access to care for the communities they serve across 13 states.” * * *
    • “Awarded hospitals may use this funding to retain physicians, nurses, and other healthcare providers, allowing hospitals to preserve essential services, including emergency, inpatient, and other critical healthcare services. This support helps ensure rural communities can continue to access affordable care when and where they need it.
    • “A complete list of award recipients and more information about the program is available at Rural Hospital Provider Support Program FY 2026 Grant Awards.”
  • Per a Centers for Medicare and Medicaid Services news release,
    • “The Trump Administration announced today that an $11.7 million investment is being delivered to support rural nursing care facilities and strengthen the healthcare workforce across rural communities in Vermont through the federal Rural Health Transformation Program (RHTP). Of this, Vermont is committing $9 million of those funds to provide tuition benefits to healthcare professionals in underserved or hard-to-fill positions who commit to serving rural communities within the state for at least five years after graduation. The remaining $2.7 million provides funding for three rural nursing homes to increase their capacity to serve residents with complex medical issues and four community partners to increase training of Licensed Nursing Assistants (LNA) to serve in rural healthcare and long-term care settings across the state.”
  • Cardiovascular Business relates,
    • “On Thursday, Sept. 10, CMS officially finalized a new national coverage determination (NCD) for TAVR. Arguably the biggest change is that TAVR will now be covered in Medicare beneficiaries who present with asymptomatic severe aortic stenosis (AS). The treatment of asymptomatic patients has been a hot topic in recent years. Some specialists see it as a way to treat patients early and avoid long-term damage. Others disagree, preferring to save TAVR for patients who present with symptoms. 
    • “Another key update is that Medicare beneficiaries with symptomatic severe AS is now covered without any sort of coverage with evidence development (CED) requirements. The TAVR NCD has always required facilities performing TAVR to follow certain CED rules that require patient data to be collected through clinical trials or registries. This is no longer the case when it comes to performing TAVR on symptomatic patients. 
    • “Five leading U.S. medical societies—the American Association for Thoracic SurgeryAmerican College of CardiologyHeart Failure Society of AmericaSociety for Cardiovascular Angiography and Interventions and Society of Thoracic Surgeons—did work together to argue that CED requirements should still be in place, but CMS still moved forward with that particular proposal. 
    • “It is worth noting, however, that CED requirements are still in place when it comes to performing TAVR on asymptomatic patients.”
  • The American Hospital Association News tells us,
    • “The National Institutes of Health has launched its Connecting the Community for Maternal Health Challenge: Research Capacity Building in Maternity Care Deserts 2.0. The competition will award more than $3 million to encourage and reward biomedical research in maternal health with an emphasis on maternal morbidity and mortality and maternal health deserts. The challenge consists of four phases: recruitment, training, proposal and research. The recruitment phase closes Sept. 23 and is required to be eligible for later phases. If selected, participants in each phase will be considered for awards ranging from $10,000 to $300,000.”
  • and
    • “The Federal Trade Commission announced Sept. 9 that it rescinded its 2021 policy statement that extended applicability of its health breach notification rule to health apps and connected devices that collect consumer health information. The commission said the 2021 statement was superseded by its 2024 update to the health breach notification rule. The FTC said the recission is part of the administration’s deregulation efforts and follows the commission’s policy of avoiding unnecessary use of subregulatory guidance.”
  • Fierce Healthcare relates,
    • “Federal healthcare agencies are accelerating efforts to expand artificial intelligence’s role in healthcare, with clinical AI emerging as a top strategic priority for the Centers for Medicare & Medicaid Services.
    • “At a healthcare AI event hosted by the Consumer Technology Association (CTA) in Washington, D.C., on Wednesday, Stephanie Carlton, deputy administrator at CMS, outlined the agency’s evolving AI strategy as it aims to establish clearer pathways for AI market access and regulation while also exploring reimbursement frameworks for AI-enabled technologies.
    • “Carlton also serves as chief clinical AI officer at CMS, a newly created position that signals the Trump administration’s push to advance AI in clinical care.
    • “A centerpiece of CMS’ AI strategy is the ACCESS model—Advancing Chronic Care with Effective, Scalable Solutions. Carlton hinted that the agency would soon expand that model. Announced in December and launched in July, ACCESS is a new 10-year program for value-based chronic condition management that leans heavily on technology and AI to scale to large populations of patients.”
  • Healthcare Dive tells us,
    • “The Department of Veterans Affairs has selected Amwell to facilitate telehealth delivery across the agency.  
    • “Amwell’s platform, which mainly offers virtual health visits, will help veterans connect with VA providers or other specialists in clinic. It will also support other telehealth services, such as virtual care delivery and care coordination within VA hospitals. 
    • “The VA signed a letter of intent to implement Amwell’s platform. A binding contract will depend on Amwell satisfying federal requirements, including a review by the VA’s chief information officer.”
  • Per an Institute for Clincical and Economic Review news release,
    • “The Institute for Clinical and Economic Review (ICER) announced today that it will develop a special report for the Centers for Medicare & Medicaid Services (CMS) on darolutamide (Nubeqa®, Bayer) for treatment of prostate cancer. This report will be submitted to CMS as part of the 2027 public comment process defined in CMS guidance on Medicare Drug Price Negotiations for price applicability year 2029. 
    • “While the final list of drugs subject to negotiation will not be released until February 2027, ICER is developing this report with the expectation that darolutamide will be subject to negotiation next year. The report will reflect legislative specifications in the Inflation Reduction Act and the most recent CMS guidance regarding price negotiations.
    • “ICER’s expertise in comparative clinical effectiveness and value will continue to help inform the important conversations around Medicare drug price negotiation,” said ICER’s President and CEO Sarah K. Emond, MPP. “While we know CMS may consider many different factors and inputs during negotiations, we believe ICER’s approach to applying the guidance in a consistent framework offers important information to all stakeholders engaged in this process.”
    • The research protocol is now available.
    • “ICER’s website provides timelines of key posting dates and public comment periods for this assessment.

From the U.S. Office of Personnel Management front,

  • Federal News Network reports,
    • “It may not come as a surprise that Americans’ trust in government has declined over the last several decades. When the first systematic measurement was taken by the National Election Study in 1958, about 75 percent of Americans said they trusted their government.
    • “Today that number has basically inverted, sitting at a discouraging 27 percent, according to the annual survey by the Partnership for Public Service.
    • “The unexpected news may not be Americans’ low confidence in government as much as how they report feeling about the federal employees who work for it. The same survey found that 65 percent of Americans view federal workers as competent, even while giving low marks to government as a single entity. Even more favorable, public perception of the federal workforce is the highest it’s been since the Partnership first asked the question in 2021.”
  • and
    • interviews a financial expert about the F Fund available in the Thrift Savings Plan.
      • “The TSP’s F Fund has trailed the G Fund over the last several years. Before deciding what that means for your own investments, it helps to understand what’s happening in the bond market.”

From the Food and Drug Administration front,

  • Per a FDA news release,
    • “The FDA and CDC, in collaboration with state and local partners, are investigating illnesses in a multistate outbreak of Salmonella Bovismorbificans infections linked to recalled broccoli sprouts grown by Evergreen Fresh Sprouts, LLC of Moyie Springs, ID. This outbreak is currently being investigated separately from the shiga toxin-producing E. coli and Salmonella outbreak linked to alfalfa sprouts also being investigated by FDA, CDC, and state partners.
    • “Based on epidemiological information collected by CDC and state partners, a total of 22 people infected with the outbreak strain of Salmonella have been reported from four states. Illnesses started on dates ranging from July 7, 2026, to August 26, 2026. Of the 19 people interviewed, all 19 (100%) reported eating sprouts and 17 (89%) reported specifically eating broccoli sprouts. There have been two hospitalizations and no deaths.
    • “FDA’s and state partners’ traceback investigations have identified Evergreen Fresh Sprouts, LLC as the common grower of broccoli sprouts that were eaten by patients before becoming ill. On September 4, 2026, Evergreen Fresh Sprouts, LLC initiated a recall of broccoli sprouts based on a positive Salmonella result from a broccoli sprouts sample collected and analyzed by Montana state officials. According to whole genome sequencing analysis conducted by state partners and reviewed by FDA, the positive sample is the same strain of Salmonella that is causing illnesses in this outbreak. Consumers, restaurants, and retailers should not eat, sell, or serve recalled broccoli sprouts grown by Evergreen Fresh Sprouts, LLC with expiration dates of 9/7, 9/9, 9/11, 9/14, and 9/16.”
  • The Washington Post reports,
    • “Federal officials are poised to declare the end of the nation’s largest known cyclosporiasis outbreak after thousands of people became sick after eating shredded iceberg lettuce, according to two people familiar with the matter.
    • “The update may come as soon as later Thursday, according to the people, who spoke on the condition of anonymity to discuss an ongoing investigation. However, the timing is not guaranteed. In mid-July, Taylor Farms voluntarily recalled products from the market as federal officials began linking its lettuce from central Mexico to a cyclosporiasis outbreak. Food and Drug Administration enforcement records show recalled products were packaged for nine food service and retail operations, such as Subway and Yum Brands, which owns Taco Bell, KFC and Pizza Hut.”
  • BioPharma Dive relates.
    • Biohaven shares fell by more than 10% Thursday after the company revealed that the Food and Drug Administration has placed a partial hold on an experimental epilepsy medicine it recently sold off rights to in a licensing deal.
    • In a regulatory filing, Biohaven disclosed that the FDA has requested additional data related to a “metabolite,” or drug-related substance, that was identified in rodent studies of its treatment opakalim. The agency instructed Biohaven to pause recruitment in an ongoing late-stage trial until it can provide more information. Dosing will continue for those already involved in that study, “RISE-2.”
    • Importantly, the hold doesn’t affect a separate late-stage trial, “RISE-3,” that’s fully enrolled. That study is still expected to produce results later this year in what is a “key event” for Biohaven, wrote William Blair analyst Myles Minter. Should opakalim succeed in testing and win approval, Biohaven will be eligible for milestone payments and sales royalties from licensing partner SK Pharmaceuticals.

No Surprises Act News

  • Modern Healthcare reports,
    • “A group of nearly 70 employers, unions, patient advocates and other organizations is calling on Congress to rework the No Surprises Act of 2020. 
    • “The letter, led by left-leaning advocacy group Families USA and cosigned by 67 organizations, asked congressional leaders to address concerns about the law’s Independent Dispute Resolution process.
    • “Under the No Surprises Act, IDR arbitrators determine appropriate out-of-network reimbursement rates, with claims predominantly filed by providers or their aligned companies.” * * *
    • “Letter signers are calling on Congress to replace what they call the “baseball-style” arbitration process with a benchmark payment methodology that promotes market-based prices and discourages excessive reimbursement. 
    • “In an accompanying report, Families USA is also advocating for subjecting ground ambulance services to the law’s requirements; strengthening the federal process for certifying mediators; and requiring arbitrators to disclose their ownership structures, payment agreements and dispute outcomes information.” 

From the fraud, waste, and abuse front,

  • Per a Justice Department news release,
    • “Dompé U.S. Inc. (Dompé), based in California, has agreed to pay $32 million to resolve allegations that, between 2018 and 2021, it paid Medicare beneficiary co-pays through two patient assistance foundations to induce the purchase of its drug, Oxervate, in violation of the Anti-Kickback Statute and the False Claims Act.”
    • The claims resolved by the settlement are allegations only and there has been no determination of liability.

From the public health and medical / Rx research front

  • MedCity News reports,
    • “Heart disease is the leading cause of death among women in the United States, yet it remains chronically underrecognized, underdiagnosed and undertreated in this population. According to research from the American Heart Association (AHA), by the year 2050, the rate of total cardiovascular disease (CVD) in women will rise to 14.4%, a 3.7% increase from 2020 data.
    • “Data for reproductive age women (ages 20 to 44) shows a similarly troubling increase, from 1 in 4 in 2020 to nearly 1 in 3 in 2050 having clinical CVD. Diabetes in this same young age group is also projected to more than double, from 6% to nearly 16%.
    • “A critical opportunity exists at the intersection of prevention and rapid diagnostics in women’s health. Early intervention based on accurate diagnosis of both metabolic risk factors and acute cardiac events could help make the difference between life and death for women.”
  • Cardiovascular Business adds,
    • “Too much light exposure at night, both when asleep and awake, may be bad for the heart. That was the eye-opening takeaway from a new study published in European Heart Journal.
    • “Previous observational studies have linked nighttime light exposure with a higher risk of cardiovascular disease, but little is known about the related cardiac structure and functional changes,” senior author Lu Qi, MD, PhD, a researcher with Tulane University, said in a statement. “We carried out this research to find out what happens to the heart over time when people are exposed to too much light at nighttime.”
    • “Qi et al. tracked data from more than 11,000 UK Biobank participants. They wore a light sensor on their wrists for seven days. Three years later, they all underwent a cardiac MRI scan.
    • “Overall, study participants exposed to the most light—three lux or more—were associated with thickening of the wall of the left ventricle not seen in participants exposed to lower amounts of light. MRI results also showed that participants exposed to high amounts of light were experiencing issues with their heart muscle’s ability to flex during heartbeats, an early sign of heart damage.  
  • The New York Times relates,
    • “In the last few years, there’s been a cultural push for women in midlife to build strong bones.
    • Menopause influencers and medical organizations alike have focused on the message that women’s risk for fractures increases dramatically after menopause, and that they should think about their bone density much earlier than their mothers might have.
    • “The American Medical Association recommends that women get their first DEXA scan — a low-dose X-ray that is the gold standard test for determining bone density — at 65 or older, unless they have a risk factor for osteoporosis.
    • “But a growing number of doctors and bone health experts now recommend earlier scans. They argue that if women wait until 65, they may miss a critical window to prevent osteoporosis.” The article delves into the details of this issue.
  • MedPage Today lets us know,
    • “People who consumed their hot beverages at a “very hot” temperature had a threefold higher risk for squamous cell carcinoma of the esophagus compared with those who drank them at a “warm” temperature, an analysis of two large U.K. cohorts suggested.”
  • and
    • “Borderline anemia — hemoglobin levels 0 to 1 g/dL above the WHO threshold — was associated with a higher risk of mortality, a prospective cohort study suggested.
    • “When stratifying results by age and sex, borderline anemia was associated with higher risks for all-cause, cardiovascular, and cancer mortality in men of all ages and in women 60 and older.
    • “These findings suggest that the relationship between hemoglobin concentration and long-term health cannot be captured by a single diagnostic cutoff, researchers said.”
  • The Washington Post tells us,
    • “People tend to think about supplements the way they think about food: Things that are inherently good or bad for you. Green beans are good. Potato chips are bad. Vitamin D and fish oil belong, presumably, on the green-bean side of the ledger.
    • “But the aging brain may change the calculation, putting some of America’s most popular supplements under new scrutiny.
    • “Recent research is raising a largely overlooked question: Can something that benefits (or is at least neutral to) a young, healthy brain become less helpful — or even harmful — as the brain ages?”
    • “In January, researchers reported an association between vitamin D supplement use and faster cognitive decline among older adults who already had normal vitamin D blood levels. In April, another study found that adults 55 and older taking omega-3 supplements showed greater cognitive deterioration over time than nonusers. Then, in June, researchers reported that people taking glucosamine, used for joint pain, appeared to have a much higher likelihood of progressing from mild cognitive impairment to dementia over five years than their peers who were not taking it.
    • “I was stunned,” said Ramon Sun, a professor of biochemistry and molecular biology at the University of Florida and the lead author of the glucosamine paper.” * * *
    • “The studies are mostly observational, meaning they don’t prove causation, and those links with mental deterioration may be because of the supplements or something else entirely.
    • “But together they point toward a possibility that researchers are beginning to take seriously: Aging changes how the brain handles fats, calcium and glucose, and how it responds to inflammation, which could alter how nutrients and drugs reach brain tissue in the first place.”
  • Beckers Health IT informs us,
    • “The American Heart Association’s PREVENT cardiovascular risk equations is now integrated into Epic’s EHR platform.
    • “The integration brings the cardiovascular risk assessment tool into clinicians’ existing workflows, where it can be used to estimate patients’ risk for heart attack, stroke and heart failure and inform prevention and treatment discussions.
    • “The PREVENT equations incorporate measures of cardiovascular, kidney and metabolic health and provide estimates of cardiovascular disease risk over 10- and 30-year periods. The tool is intended for adults ages 30 to 79 without a history of cardiovascular disease, according to a Sept. 10 news release.
    • “The equations were developed using health information from more than 6.5 million adults from a range of racial, ethnic, geographic and socioeconomic backgrounds, according to the association.”
    • “Recent American Heart Association and American College of Cardiology guidelines for managing high blood pressure, abnormal cholesterol and cardiovascular-kidney-metabolic syndrome recommend use of the PREVENT equations for cardiovascular risk assessment and treatment decisions.
    • “Embedding the equations within Epic is intended to make the risk estimates available at the point of care without requiring clinicians to use a separate tool, according to the association.”
  • Beckers Hospital Review points out,
    • “Among 31 cancer centers, 100% said they were experiencing a shortage of at least one anti-cancer drug, according to data published Sept. 10 by the National Comprehensive Cancer Network.
    • “The data summarizes August survey responses from pharmacy directors and other clinical and administrative leaders at 31 NCCN members, a Sept. 10 news release said.”

From the U.S. healthcare business and artificial intelligence front,

  • Healthcare Dive reports,
    • “Medicare Advantage insurers could see their star ratings fall next year — and lose out on the lucrative bonuses the ratings represent — after regulators boosted many of the thresholds for achieving the quality scores.
    • “Earlier this week, the CMS released draft cutpoints, the thresholds the agency uses to convert MA plans’ quality and performance scores into a 1 to 5 star rating, as part of the preview process before regulators announce official results in early October.
    • “About 50% of cutpoints got harder, 33% were unchanged and 17% actually got easier, according to analysis by the Newton Smith Group, an MA consultancy.”
  • Health Exec relates,
    • “For certain aspects of healthcare, Arizona is the freest state in the nation. The least free? New Jersey.
    • “The findings have nothing to do with no-cost services and everything to do with the legal, regulatory and policy environments governing healthcare across the United States. 
    • “They’re from the Center for Modern Health, a libertarian think tank focused on advancing free-market ideas in health policy.
    • “In the Center’s own words, the 2026 Health Freedom Index reflects state-level data on the degree of choice and freedom available to patients, healthcare professionals, insurers and entrepreneurs. 
    • “For each state, the project’s researchers measured performance across 54 variables and five kinds of “freedom”—professional, institutional, patient, payment and delivery—and used the sums to index the states from best to worst. 
    • “In addition, the project “aims to promote transparency and informed discussion about the role of freedom, voluntary exchange and institutional design in American healthcare.”
  • Beckers Hospital Review points out the top rehabilitation hospital in each State based on U.S. News & World Report compilation of a list of the top rehabilitation hospitals in every state. 
  • The Wall Street Journal informs us,
    • “An Association for Accessible Medicines report says 90% of biologic drugs losing patent protection by 2034 have no biosimilars in development.
    • “The lack of low-cost alternatives could cost Americans nearly $200 billion in healthcare savings over the next decade.
    • “The dispensing rate of available biosimilars over brand-name drugs fell to 23% in 2025, down from about 40% in 2024.”
  • STAT News notes,
    • “When Kura Oncology decided to take aim at a protein involved in cell division and signaling, researchers reported a bonus finding: Targeting the protein, menin, didn’t just control the growth of leukemia cells, it also helped control blood sugar levels in animal studies. The biotech on Wednesday announced that it is turning that insight into a new company.
    • “The new firm, Caspian Therapeutics, is launching with $50 million in financing to develop menin inhibitors for diabetes and other cardiometabolic diseases. The initial funding, led by BVF Partners and joined by Eli Lilly and members of Kura’s leadership team, among others, is meant to advance Caspian’s lead small molecule drug through an early-phase clinical trial in diabetes and support the development of a second candidate.”
  • Per Beckers Physician Leadership,
    • “Physician assistants averaged a salary of $155,000 in 2026, continuing a run of steady raises since 2022, according to a report from Medscape.
    • “The topline number hides a more complicated picture: pay growth varies widely by specialty setting, state and gender, and base salary itself grew more slowly than the bonus and incentive pay layered on top of it.”
  • Per Fierce Healthcare,
    • “Electronic prescribing platform Interra Health announced Tuesday that it now supports the U.S. Centers for Medicare and Medicaid Services’ (CMS) GLP-1 Bridge program for Medicare Part D beneficiaries.
    • “Eligible Part D enrollees can access GLP-1 medications at $50 per month through the program, which launched July 1. For Interra patients, the platform alerts providers when patients may be eligible to enroll in the program. Moreover, it instructs providers to submit proper codes and complete required prior authorizations.
    • “Interra Health Chief Business Development Officer J.B. Powell told Fierce Healthcare the program has delivered “more than 170,000 point-of-prescribing alerts to more than 30,000 unique prescribers” since its launch, adding that its requirements could “be confusing” for providers and patients to understand eligibility.”
  • and
    • “Plans to build a new, $2 billion-plus patient care tower and other accompanying upgrades at the University of Iowa Health Care’s main campus are off the table in favor of smaller-scale upgrades to existing facilities, the academic system said Wednesday. 
    • “Iowa Health Care had previously described the new patient tower as “critical to our ability to meet the healthcare needs of Iowans for years to come.” Primary construction wasn’t scheduled to begin in earnest until 2028 and targeted a 2032 completion.
    • “The organization is still facing a capacity crunch, noting in Wednesday’s announcement that it turns away 3,000 to 5,000 patient transfers a year “due to space constraints” even as it recorded over 41,000 inpatient admissions, almost 1.7 million clinical visits and over 43,000 major surgeries last fiscal year. 
    • “However, “significant financial challenges” facing the healthcare industry at large have limited Iowa Health Care’s ability to “responsibly” deploy capital toward the project. The organization stressed that its finances are stable, but now plans to submit a revised $380 million capital plan to its board later this month.”

Midweek update

Simplicity is a virtue.

From Washington, DC,

  • The American Hospital Association News reports,
    • “The Department of Health and Human Services announced Sept. 8 through the Substance Abuse and Mental Health Services Administration that it will award $383.4 million in grants to support behavioral health treatment, prevention and crisis response efforts. HHS said $252 million will support the 988 Suicide and Crisis Lifeline, suicide prevention and mobile crisis services. Of the remaining grants, $81.4 million will be used toward substance use treatment and prevention initiatives, and $50 million will be used to support mental health services. The Sept. 8 announcement coincided with 988 Day, which raises awareness about the 988 lifeline and the importance of mental health and suicide prevention.” 
  • Bloomber Law reports,
    • “The Trump administration is pursuing additional drug pricing deals with pharmaceutical companies, Centers for Medicare and Medicaid Services Administrator Mehmet Oz told Bloomberg Television.
    • “Officials have announced more than two dozen voluntary agreements with pharmaceutical companies so far, and Oz said “there are more deals in the works.” He spoke ahead of his scheduled keynote address at the Republican midterm convention in Dallas Wednesday night.
    • “Each of the agreements is bespoke, but companies generally have agreed to lower the prices they charge public programs for medicines and to launch new drugs at prices similar to those paid by other developed nations in exchange for relief from tariffs. Some companies also are offering the discounted prices directly to consumers on a Trump-branded website, though critics argue the savings are minimal for patients with insurance.”
  • Axios adds,
    • “There are troubling new signs that the overhaul of Medicare drug coverage in the Inflation Reduction Act is dramatically driving up program spending. 
    • Why it matters: The upward trajectory could threaten some seniors’ coverage for outpatient prescription drugs — and it could force painful tradeoffs over the next decade as Medicare consumes a growing share of the nation’s debt. 
    • Follow the money: The IRA limited what seniors have to pay for outpatient drugs and shifted the remaining cost to taxpayers, insurers who provide stand-alone Medicare drug plans and drug manufacturers.
    • That was good news for enrollees who take expensive drugs for conditions like cancer, multiple sclerosis or rheumatoid arthritis and faced potentially crushing out-of-pocket costs.
    • But federal data shows demand for drugs is surging as they become more affordable, exceeding congressional scorekeepers’ spending estimates and setting off more alarms.
    • Driving the news: Last week, congressional Medicare advisers reported that more than 1 in 5 enrollees hit Medicare Part D’s $2,000 patient cost cap in 2025 — shifting new costs to the government.”
  • Beckers Behavioral Health breaks down the Labor Department’s September 8 enforcement guidance concerning the mental health parity act into seven things to know:
    • “Certain behavioral health treatment exclusions could draw scrutiny.
    • “Prior authorization and medical necessity processes are a key enforcement area.
    • “The agency is looking closely at behavioral health networks.
    • “Compliance depends on how policies operate in practice.
    • “Telehealth, cost-sharing and visit limits can also raise compliance concerns.
    • “Plans are expected to use monitoring mechanisms to identify disparities.
    • “Corrective actions can require changes to coverage and plan operations.”
  • STAT News relates,
    • “ARPA-H, the government agency that funds cutting-edge health research, plans to commit $62.7 million to develop artificial intelligence bots that direct treatment of heart failure. Among the goals of the program, called ADVOCATE, is to produce partially autonomous AI devices authorized by the Food and Drug Administration to help treat patients, including assessing symptom severity, prescribing drugs, and ordering lab tests. 
    • “ARPA-H on Wednesday announced the first batch of awards to health tech companies Atman Health, UpDoc, Tempus AI, and teams from Stanford University, Duke University, and the Kaiser Permanente health system. ARPA-H may still fund additional teams. The amount committed for the first year is $33.7 million, and the remainder may be renegotiated up or down.” 

From the U.S. Office of Personnel Management front,

  • My Federal Retirement tells us about “What FEHB Enrollees Should Know if They Get a Letter from Medicare This Month.”

From the Food and Drug Administration front,

  • Fierce Pharma reports,
    • “In an accelerated decision, the FDA expanded Bayer’s Hyrnuo indication, granting first-line approval for a rare tumor type in patients with non-small cell lung cancer. 
    • “Before the expansion, Hyrnuo was available only after other NSCLC treatments failed. But the FDA’s latest go-ahead makes the tyrosine kinase inhibitor (TKI) an initial therapy option for any patient with locally advanced or metastatic non-squamous NSCLC whose tumors test positive for HER2 tyrosine kinase domain activating mutations.   
    • “The expanded indication was won using data from Bayer’s ongoing phase 1/2 Soho-01 trial, in which Hyrnuo demonstrated a 75% objective response rate in previously untreated patients. Six percent of patients showed a complete response, and 70% showed a partial response to the twice-daily oral medication, Bayer said Wednesday. Responses lasted more than six months for 73% of patients.”
  • and
    • “With a phase 3 win now fleshed out and an FDA filing recently submitted, BioMarin is advancing expansion plans for Voxzogo, looking to extend the dwarfism drug’s reach as it faces new pressure in its inaugural achondroplasia indication. 
    • “On Wednesday, BioMarin unveiled detailed results from the phase 3 CANOPY-HCH-3 trial assessing Voxzogo in children with hypochondroplasia (HCH), a milder form of achondroplasia, where the company announced a topline win back in May. 
    • “Aside from the average 2.33 cm/year improvement in annualized growth velocity (AGV) on Voxzogo that BioMarin reported out earlier this year, the company dug deeper into the magnitude of benefit its medicine could offer to children with HCH across measures like standing height and arm span after a year of treatment.
    • “BioMarin shared the data Wednesday at the European Society for Paediatric Endocrinology annual meeting and simultaneously published the results in the New England Journal of Medicine.” 
  • Cardiovascular Business points out,
    • “Luma Vision, an Irish medtech company focused on electrophysiology and interventional cardiology technologies, has secured U.S. Food and Drug Administration (FDA) clearance for its updated Verafeye imaging and visualization platform. The company previously received FDA clearance for the artificial intelligence-powered offering in 2025; this update covers the platform’s expanded capabilities ahead of a planned commercial launch in 2027.
    • “The Verafeye platform provides ultrasound imaging courtesy of a 360° catheter that creates real-time 2D and 3D maps of the patient’s heart. It also offers advanced visualization and navigation capabilities, helping users track imaging and ablation catheters during treatment. In addition, users are able mark locations as they go to confirm they achieve the necessary alignment.”

From the public health and medical / Rx research front,

  • The Washington Post reports,
    • “First responders and other New Yorkers around the World Trade Center that day have reported conditions including respiratory issues, mental health impacts and dementia. Toxins were present in the air soon after the attacks even though people were assured it was safe, according to a trove of records released this week by New York City officials.
    • “Twenty-five years later, attention is increasingly falling on cancer. 
    • “The number of 9/11 survivors who are receiving aid for cancer has roughly tripled over the last five years, according to a Washington Post analysis of reports from the World Trade Center Health Program, which funds health care for first responders and 9/11 survivors in New York. In June 2021, 8,870 survivors received aid for cancer treatment, jumping to 27,300 survivors in 2026 — numbers that sharply outpaced cancer claims among first responders.
    • “Of the roughly 54,000 survivors enrolled in the health program as of June, about half are receiving aid for cancer. Five years ago, that share was 35 percent.” * * *
    • “A recent New York University study of a smaller cohort of 9/11 survivors receiving medical aid as of 2024 reported a similar increase in cancer cases; it found that cases had increased around 2.5-fold between 2019-2024.
    • “This is something that we are worried about,” said Alan Arslan, an associate professor of population health at NYU and one of the authors of the study. “We’re seeing more and more patients.”
  • The Wall Street Journal relates,
    • “Dr. Henry Heimlich devised a new technique more than 50 years ago to stop people from choking. Simplicity, studies, shrewd promotion by its inventor—and a demonstration on The Tonight Show Starring Johnny Carson—made the Heimlich maneuver a go-to method.
    • “Now, it is fighting for the stage.
    • “Advocates, companies and some politicians argue that the Heimlich maneuver and back blows, another established method of rescuing people from choking, aren’t always enough. On social media and in state legislatures, they are plugging portable anti-choking devices, designed to suction stuck food or other objects from a person’s airway.
    • “Texas enacted a law last year requiring school districts to stock at least one such device on each campus with at least one employee trained to use it. New York City passed one, too. At least nine other states have weighed or are weighing bills to put devices into schools or other facilities.
    • “It’s a priority,” said New Jersey state Sen. Kristin Corrado, who co-sponsored one bill. “If we have the opportunity to save a life, we have to use all means available.” 
    • “The main U.S. maker—a company called LifeVac—has donated more than 10,000 devices to schools across the country.” * * *
    • “But medical guidelines and many researchers say there isn’t enough evidence to recommend anti-choking devices. State health departments, emergency responders and teachers unions have pushed back against proposals to require them in schools because medical guidelines haven’t endorsed them. New York City said it wouldn’t implement its law unless the devices are recommended in medical guidelines.”
  • Beckers Behavioral Health tells us,
    • “The synthetic opioid cychlorphine has been linked to at least 55 deaths nationally from 2025 to 2026, with prevalence highest in Ohio, Tennessee and Texas, MedPage Today reported Sept. 8.
    • “The Office of National Drug Control Policy said in an April drug threat notice that cychlorphine may be “up to 10 times more potent than fentanyl” and an overdose may require multiple doses of naloxone.
    • “In Tennessee, the Knox County Regional Forensic Center reported 41 overdose deaths between July 2025 and February 2026. The center tracked as many as 63 cychlorphine-associated deaths through June 30, and cychlorphine was found to be the cause in 58 of those cases.
    • “Cychlorphine has been found mainly in powders and tablets as well as counterfeit pills. Shravani Durbhakula, MD, MPH, of Vanderbilt University School of Medicine in Nashville, Tennessee, said snorting and inhaling are common, though oral exposure and injection are also possible.”
  • Cardiovascular Business informs us,
    • “A majority of transcatheter aortic valve replacement (TAVR) present with a history of heart failure (HF). According to new data published in the Journal of Cardiovascular Medicine, however, many of those patients are not being given the HF medications they need after undergoing TAVR.
    • “Cardiovascular morbidity and mortality remain high after TAVR,” wrote first author Elena Surkova, MD, MSc, PhD, a senior medical director at AstraZeneca and consultant cardiologist with Royal Brompton and Harefield Hospitals, and colleagues. “There is a lack of detailed data on the prevalence of HF in patients undergoing TAVR, medication prescription rates, including the main pillars of HF standard of care, and predictors of HF worsening following the procedure.”
  • The American Medical Association lets us know what doctors want patients to know about West Nile virus
    • “Most West Nile virus infections cause no symptoms, but some can lead to severe illness. Mosquito-bite prevention remains the best defense.”
  • MedPage Today adds,
    • “A gender gap historically seen in the suicide rates of 10- to 14-year-olds in the U.S. has tightened.
    • “In 2017, the suicide rate of boys was twice that of girls, but by 2024, it was only 4% higher.
    • “The author noted that the nearly equal suicide rates for 10- to 14-year-old boys and girls in the current study marked the “first time this has happened in the available records.”
  • Health Day notes,
    • “Autism spectrum disorder (ASD) diagnoses increased disproportionately among females after 2020, across age groups, while remaining stable or declining among males, according to a study published online July 22 in JAMA Network Open.
    • “Erick Messias, M.D., Ph.D., from St. Louis University, and colleagues evaluated age- and sex-specific incidence trends of ASD from 2016 to 2024 to quantify the temporal patterns before and after the COVID-19 pandemic. The analysis included electronic health record data from 171,134 individuals who had at least one clinical encounter annually at a large health care system.”
  • Per Genetic Engineering and Biotechnology News,
    • “The results of a preclinical study by researchers at the University of East Anglia suggest that an experimental anticancer drug could stop osteoporosis and help women prevent weight gain after the menopause. Their study in mice found that the small molecule drug CADD522 not only protected against osteoporosis but could also reduce body fat and reverse some of the metabolic changes linked to menopause. Currently in development for cancer therapy, CADD522 is a small molecule inhibitor of the transcription factor RUNX2, which is helps to drive the growth and spread of several cancers.
    • “Research lead Darrell Green, PhD, at UEA’s Norwich Medical School, said, “We have uncovered an entirely new way of tackling the disease. We found that a drug originally developed to stop cancer could help millions of women facing the twin challenge of fragile bones and midlife weight gain. We hope our work could lead to a new generation of osteoporosis treatments that tackle bone loss while also addressing some of the wider metabolic consequences of menopause.”
    • “Green is senior and co-corresponding author of the team’s report in npj Drug Discovery, titled “RUNX2 inhibitor CADD522 improves bone microarchitecture and lipid metabolism in post-menopausal bone loss.” In their paper the team concluded that their collective studies “… identify RUNX2 inhibition as a therapeutic strategy that simultaneously improves skeletal integrity and metabolic homeostasis, supporting further development of CADD522 for osteoporosis and other RUNX2-driven diseases.”

From the U.S. healthcare business and artificial intelligence front,

  • The International Foundation of Employee Benefit Plans reports,
    • “Medical stop-loss premiums in 2026 show an increase from 13.6% on a $100,000 deductible to 15.9% on a $750,000 deductible, as reported by the 2026 Aegis Risk Medical Stop-Loss Premium Survey, cosponsored by the International Society of Certified Employee Benefit Specialists. Notably, this increase is approximately 5% to 5.5% higher than increases seen for the previous 2025 renewals. This impact was not surprising, as many underwriters reported increased severity and frequency in stop loss-claims in late 2024 and a resulting erosion in claims-to-premium loss ratios thereafter and throughout 2025. The survey captured necessary correction to 2026 premiums. The measured increases, rising alongside the size of deductible, reflect leveraged medical trend, as the underlying growth in expense of a catastrophic medical claimant is fully borne by an unchanged deductible.
    • “Survey response uniquely captures final, negotiated premium and reflects any pricing improvement from renewal marketings and concessions across all deductibles. In comparison, several large direct underwriters reported an average 2026 increase in the low 20% range on their own book-of-business. However, those are weighted by in-force policies unable to locate lower cost alternatives. The comparatively lower increases observed in this survey reflect the 2026 renewal rate opportunity found in the market. Looking ahead, an ongoing return to underwriter discipline and need to restore insurer loss ratios to a more profitable position does not indicate any easing on the 2027 renewal cycle.”
  • Fierce Pharma relates,
    • “Shifts in drug pricing and market access policies around the world have caused an “earthquake” that will reverberate for years to come, a survey of industry leaders found.
    • “Healthcare consultancy Numerof & Associates generated the insights in a survey of 175 executives from 67 pharmaceutical companies. The qualitative survey revealed the belief that the current era of policy change is unlike anything that the industry has experienced before. After going through a period of fast change, the industry is braced for more upheaval in the coming years. 
    • “While there has always been change throughout the industry, the past 24 to 36 months have felt more exponentially transformative than anything I have seen over the last 30 years,” an executive said. “What we may experience over the next five years could exceed the cumulative level of change we saw over the previous several decades.”
    • “Another executive characterized the policy environment as an “earthquake” that is “not going to settle down soon,” while a third person predicted that the need for politicians to try to address the cost of healthcare will ensure ongoing change. 
    • “The executives were talking after a succession of policy changes in key markets. Medicare gained the authority to directly negotiate prices for some drugs, and the most-favored-nation (MFN) policy tied U.S. prices to overseas markets.” 
  • Healthcare Dive tells us,
    • “UnitedHealthcare is still drilling down on actions it can take to make its Medicare Advantage plans more profitable next year, even as the insurer is expected to exit more underperforming geographies. But the company could be poised for growth in the markets where it remains, according to new comments from a top executive.
    • “We think we’re going to be very competitive in terms of our pricing next year,” CFO Wayne DeVeydt said during Wells Fargo’s annual healthcare conference Wednesday morning. “We think our benefits will be competitive … We still have a few markets where we’re right-sizing some of the products, but I think we’ll be well-positioned for 2027.”
    • “DeVeydt’s comments come as market watchers try to get a sense of how 2027 open enrollment will pan out, following an especially turbulent sign-up period for 2026 after insurers culled their plans in a bid to resuscitate flagging margins.”
  • Modern Healthcare adds,
    • “UnitedHealth Group and CVS Health are looking into acquisitions, executives said at a Wells Fargo conference.
    • “UnitedHealth Group identified value-based care companies and companies that would fit into its Optum Insight division as targets.
    • “CVS Health will seek “bolt-on” acquisitions and resume share buybacks next year.”
  • Beckers Payer Issues informs us,
    • “Anthem is now covering three surgical meshes for breast reconstruction, according to a clinical guideline published Aug. 27.
    • “DuraSorb Monofilament Mesh, GalaFLEX and TIGR Matrix Surgical Mesh “are considered medically necessary when used for breast reconstruction surgery,” the guidance said.
    • “We regularly review our medical coverage policies to ensure they’re aligned with credible medical evidence and the latest treatment standards and expert recommendations,” an Elevance Health spokesperson told Becker’s.” * * *
    • “ABC affiliate WFTS-TV in Tampa, Fla., has been reporting on breast cancer insurance denials, including for mesh, in recent years. It reported how Cigna updated its policy to cover mesh for breast reconstruction in 2025.
    • “Despite calls for insurer coverage, mesh for breast reconstruction has not secured FDA approval.”
  • and
    • “UnitedHealth Group’s Optum has sold interest in some of Optum’s Florida WellMed clinics to private equity company TPG, Bloomberg originally reported Sept. 9. UnitedHealth Chief Financial Officer Wayne DeVeydt told Bloomberg that the healthcare company was looking for a partner “that could actually work with us locally,” and UnitedHealth “didn’t need the dollars.” 
    • “We entered a strategic partnership designed to strengthen operating performance through dedicated support for clinic operations, targeted investments in technology and tools, and enhanced operating capabilities,” an Optum spokesperson told Becker’s Sept. 9. “The transitioning clinics will remain part of Optum’s network and continue providing high-quality care to patients. We remain committed to serving Florida patients through our integrated, value-based care model.”
  • Beckers Behavioral Health lets us know,
    • “Santa Fe, N.M.-based Quel Health launched a telehealth platform focused on using GLP-1 receptor agonists in addiction care. 
    • “The platform is available in 41 states and the District of Columbia, with national coverage planned by year-end, according to a Sept. 8 news release from the company. Quel also named Wernersville, Pa.-based Caron Treatment Centers a founding strategic partner.” * * *
    • “The approach follows work at Caron’s Pennsylvania and Florida campuses, where Steven Klein, MD, PhD, co-founder and chief medical officer of Quel Health, and his team evaluate GLP-1 receptor agonists in patients whose primary diagnosis was substance use disorder rather than obesity or diabetes.” 
       
  • Per Fierce Healthcare,
    • “Employers Health and Judi Health are teaming up to launch StarkRx, a new cost-plus benefit offering designed to drive transparency for employers.
    • “The approach unites the expertise of Employers Health as a group purchasing organization for pharmacy benefits that’s backed by employers with the technology available through Judi. The goal, the partners said, is to ensure that self-funded employers have greater access to transparency data that they can use to identify and manage cost drivers.
    • “Employers are expected to see another year of significant healthcare cost increases in 2027, with pharmaceuticals serving as a major factor behind the trend. A recent analysis from Marsh (formerly Mercer) estimated that costs could increase by 8.2% next year.
    • “Advanced, high-cost therapies and GLP-1 medications were both cited as key cost drivers in that analysis.”
  • and
    • “H1 has acquired Defacto Health, a healthcare data company focused on provider network intelligence, in a move to expand its offerings for health plans and strengthen its healthcare data assets.
    • “H1 is an AI-powered platform that brings healthcare data, domain expertise and an artificial intelligence platform to life science companies. The company built an AI-powered platform that helps identify and engage the right doctors for critical workflows across pharma, health plan, health system and technology companies. 
    • “Defacto Health is an AI-driven provider intelligence platform that aggregates and analyzes health insurance payer networks, provider directories and medical demographics data. The company maintains data on payer networks, healthcare providers and the insurance plans providers accept, helping health plans assess directory accuracy, isolate error clusters and benchmark their networks.”
  • Beckers Hospital Review reports,
    • “The American Medical Association released its 2027 Current Procedural Terminology (CPT) code set Sept. 9, an update that adds 299 codes and continues to build out billing for clinical AI.
    • “The set takes effect Jan. 1 and carries 453 total editorial changes: 299 new codes, 74 revisions and 80 deletions, the AMA said.
    • “Ten of the new codes describe AI-related services, raising the total number of AI-related CPT codes to 43. The AMA also updated Appendix S, its taxonomy that sorts medical AI by how much of the work the machine does — assistive, augmentative or autonomous — and guides how new tools get coded.
    • “As new technologies and clinical approaches emerge, the nation’s health system needs a reliable way to describe the care physicians provide,” said AMA President Willie Underwood III, MD. Dr. Underwood said a physician-led coding system gives that work “unmatched scale, expertise and legitimacy.”
    • “The set’s key clinical change, released in August, is a maternity coding overhaul that retires the decades-old global maternity bundle in favor of separate reporting across antepartum, labor, delivery and postpartum care.”
  • MedTech Dive offers “5 takeaways from Oura’s IPO filing.”
    • The wearables firm’s sales are growing, and it is adding more paid members, but questions loom about whether the company will need to approach future features as a medical device.
  • and tells us,
    • “Labcorp said Tuesday it has acquired MLM Medical Labs to add global central laboratory and biomarker capabilities for clinical trials.
    • “MLM is a global central and specialty laboratory provider with operations in the U.S., Germany and South Africa. 
    • “The deal makes Labcorp the only central laboratory provider with a wholly owned lab network across four continents, the acquiring company said. Neither party disclosed the financial terms of the deal.”

Cybersecurity Saturday

From the frontier AI front,

  • The Wall Street Journal reports,
    • Nvidia NVDA is planning to use a $6 billion deal it struck this week [August 22] to build one of the world’s most powerful open-weight AI models, one that would compete with Chinese heavyweights like DeepSeek and Kimi K3, according to people familiar with the matter.
    • “The chip giant’s licensing deal with the AI startup Poolside is also set to present a direct challenge to frontier U.S. AI companies including OpenAI and Anthropic, since open-weight models are generally far cheaper to operate and allow easy customization.
    • “Although Nvidia counts big labs like OpenAI and Anthropic as some of its closest partners, the move reflects Chief Executive Jensen Huang’s efforts to position Nvidia for success in multiple AI battlegrounds simultaneously, ensuring the company is able to hold on to its dominant market position.”
  • and
    • Nvidia and CrowdStrike are addressing what they see as one of cybersecurity’s biggest gaps: the need for cyber defenders to harness AI at the velocity of cyber attackers.
    • In the current cyber landscape, frontier AI models are discovering bugs at machine speed—raising alarm bells among experts, who warn that when autonomous hacking models go rogue or attack companies, chaos is on the horizon.
    • But cyber defenders aren’t getting enough of that same AI firepower, according to Nvidia and CrowdStrike, who on Tuesday [September 1] introduced a new family of agentic AI models, dubbed SafeMind, which can both find attack paths and close them for customers. The models are available in CrowdStrike’s flagship Falcon platform and through its API. * * *
    • “SafeMind has two models: Red Tempest, which is an “offensive” model that emulates AI adversaries, and Blue Solano, which is a “defensive” model designed to fix identified issues. The two models are connected by software called a harness, which runs the models in a closed-loop system that pits them against each other for self-improvement.”
  • The New York Times reports,
    • “Nvidia said on Thursday [September 3] that it is buying Hugging Face, a library of open artificial intelligence models, for $12.9 billion, as the chipmaker extends a spending spree in the escalating global race to dominate the technology.
    • “The deal marries Nvidia’s chip and data center infrastructure with Hugging Face’s millions of open-source A.I. models that can be freely downloaded and modified. And it puts Nvidia’s deep pockets firmly on one side of a debate over how A.I. systems should be built.
    • “Together, we will make A.I. more open, more capable and more accessible to people and institutions around the world,” wrote Jensen Huang, the chief executive of Nvidia, in a blog post.
    • “The acquisition is also another sign of Nvidia’s growing role as Silicon Valley’s central banker, using its vast financial resources to bolster A.I. start-ups and funnel money to customers for its chips. With $197 billion in current assets and nearly $60 billion in profits from its most recent quarter, the Silicon Valley giant has been spending heavily on A.I.”
  • Daniel Borish writing in LinkedIn lets us know,
    • Anthropic released Claude Fable 5.1 and Claude Mythos 5.1 this week, positioning them as its most capable models yet for coding and knowledge work. The two are the same underlying model, split only by the safeguards wrapped around them. Fable 5.1 is generally available. Mythos 5.1 is restricted to vetted cybersecurity and life sciences professionals through trusted access programs run in partnership with the US government.” * * *
    • “On the cybersecurity side, Claude Code users should see roughly 60% fewer safeguard interventions per session, and Fable 5.1 can now be used to find software vulnerabilities, though not to write exploits for them. Tasks like penetration testing, exploit generation, and binary-based vulnerability scanning still route to Anthropic’s Opus models. On biology, updated safeguards reportedly fire 85% less often on benign medical and elementary biology questions, though research-grade life sciences queries still get redirected to Opus, and full access to Mythos 5.1’s biology capabilities is limited to the government-linked Life Sciences Verification Program.
    • “Anthropic’s safety testing found Mythos 5.1 better aligned than its predecessor on several measures it tracks: less likely to seek resources outside its assigned environment when given an impossible task, less likely to reason its way around explicit constraints, and less likely to attempt or succeed at reward hacking. The company also disclosed limits to that picture, noting its behavioral audits have less visibility into very long-context work, multi-agent settings, and testing found the model can still sometimes bypass approval steps and automated review classifiers.
    • “Fable 5.1 also ships with new anti-distillation measures. New API accounts created from launch onward can no longer edit Claude’s prior context in a conversation while preserving the model’s recorded thinking, closing off a publicly documented technique used to extract that thinking at scale.”
  • The Wall Street Journal adds,
    • Anthropic has signed a cloud-computing deal worth $35 billion with NvidiaNVDA 3.21%increase; up pointing triangle-backed cloud provider Lambda, with Nvidia itself holding the lease on the data center, according to people familiar with the deal. 
    • The data center is being developed by Hut 8, a bitcoin miner and data-center developer, in Nueces County, Texas. Nvidia signed an agreement with Hut 8 a few weeks ago to secure the capacity, the people said. 
    • The convoluted arrangement is another example of Nvidia’s growing role in helping non-investment-grade firms such as Anthropic get access to its expensive computing resources. The deal also helped a nascent cloud provider, Lambda, secure a lucrative contract with Anthropic without needing to procure the data-center space on its own. 
    • Lambda will use the data center Hut 8 is developing to plug in chips bought from Nvidia, which is also its investor. It is not clear how much Lambda will pay Nvidia to access the data-center space.
    • Anthropic has been racing to sign cloud-capacity deals after hitting a supply crunch earlier this year that coincided with its products gaining traction. The AI developer signed a $45 billion deal earlier this month with another Nvidia-backed neocloud, Nscale, to rent Nvidia capacity from its West Virginia site, according to people familiar with the deal. 
  • Security Week relates,
    • OpenAI said its newest model, Astra, has reached the ‘Critical’ cybersecurity capability level under the company’s Preparedness Framework, the first time any of its models has been placed in that category. 
    • The designation applies when a model can independently find and exploit zero-day vulnerabilities across many well-defended systems, or carry out a complete cyberattack against a hardened target from only a high-level instruction. OpenAI said the classification requires additional safeguards before the model can be released.
    • In testing described by the company, Astra achieved a perfect score on ExploitBench, a benchmark that measures a model’s ability to turn known vulnerabilities into working exploits. During a separate evaluation involving more recently disclosed flaws, Astra uncovered two zero-day vulnerabilities on its own. 
    • The model also broke out of a browser sandbox to run commands on the underlying machine, and separately chained several flaws in a hardened operating system to gain root-level access.
    • OpenAI reported that Astra now declines 91.5% of cyber-related jailbreak attempts in its testing, up from 59% for its predecessor, GPT-5.6 Sol. The company also said Astra showed far less tendency than Sol to bypass safety restrictions or take advantage of deliberately placed “honeypot” targets during evaluations. 
    • Full cybersecurity capabilities will not be widely available at launch. OpenAI plans to give a group of testers early access, with wider availability to follow through its Daybreak Blue program.
  • Cybersecurity Dive adds,
    • “OpenAI on Thursday [September 3] said it would commit $1 billion in subsidized access and training to help small IT security teams use frontier AI to protect essential services, including electricity, water and local government services. 
    • “The Daybreak for Frontline Defenders program will be used to help defenders search for critical vulnerabilities in their software, hunt for suspicious activity in their technology stacks and stop malicious actions if hackers are able to gain access to their systems.
    • “OpenAI plans to roll out a six-month pilot program with the Multi-State Information Sharing and Analysis Center (MS-ISAC), which will train and support a group of water utilities and other public sector defenders.” 
  • Dark Reading points out,
    • “A new study suggests that while AI is rapidly accelerating vulnerability discovery, enterprise organizations are better equipped to handle the surge than generally assumed.
    • “The key is their ability to quickly validate findings, prioritize risk, and get available fixes into production.
    • “Software supply chain security firm Echo recently analyzed nearly 40,000 CVE life cycles across 250 open source container projects, drawing on a year of its own platform telemetry, survey responses from more than 80 security leaders, and an independent analysis of Anthropic’s Claude Mythos.
    • “The results, detailed in a report titled “Mythos Readiness Report,” show how AI is transforming vulnerability discovery and exploit development — something that security teams have been encountering firsthand over the past year.”
  • and
    • “With multiple benchmarks confirming that at least one frontier model can autonomously execute an end-to-end compromise, cybersecurity experts are warning that companies have to pick up the pace in securing their attack surfaces and adopting AI-speed defenses.
    • “On Sept. 2, consulting firm Booz Allen became the latest organization to confirm that a frontier model — Anthropic’s Mythos 5 — can act as a fully autonomous hacker and compromise a production-grade enterprise network. The company also released a metric, dubbed the Cyber Weapon Index (CWI), to benchmark a model’s capabilities, pairing the ability to find and exploit vulnerabilities with the ability to execute and attack a target.
    • “In their evaluation, Mythos scored an 80, while the next-closest contender, SpaceXAI‘s Grok-4.5, scored a 49. However, the current standings are not as important as where we will be in six months, says Brad Medairy, president of Booz Allen’s National Cyber practice.
    • “Our view is there’s going to be some level of parity, at least between the frontier models and the Chinese models over probably a six-month horizon, and so everyone is in a rapid race to evolve these capabilities,” he says, adding that, when facing human attackers, defenders had the advantage, but “in the future, the balance of power shifts to the offense, because the attacker can deliver effects at speed and scale that the traditional defenses can’t keep pace with.”

From the cybersecurity policy and law enforcement front,

  • Federal News Network reports,
    • “Congress is kicking the can down the road again on a long term debate over reauthorizing the Cybersecurity Information Sharing Act of 2015.
    • “The continuing resolution passed by the House on Tuesday would extend CISA 2015 through the stopgap funding period into early December. The Senate has already passed the measure, meaning it now heads to President Donald Trump’s desk. [FEHBlog note: The President signed the continuing resolution into law on September 2.]
    • “There has been a persistent chorus of voices in industry calling on Congress to find a long-term solution to re-authorizing CISA 2015. Those calls have only grown louder amid advancements in artificial intelligence models and recent cyber attacks on critical infrastructure.
    • “The 2015 law provides privacy and liability protections to encourage companies to share data about cyber vulnerabilities and threats with government and each other. The information sharing law briefly lapsed during last fall’s shutdown and again earlier this year before being extended through Sept. 30.”
  • The Wall Street Journal points out,
    • “The U.S. Defense Department is expected to release its cyber plan as early as Tuesday, NextGov reported, citing people familiar with the matter. The plan is due to outline how the Pentagon will integrate cyber tactics into military strategy, emphasizing offensive actions, and address training requirements. The most recent Defense Department cyber strategy was issued in 2023.”
  • Per a CISA news release,
    • “CISA and the Group of Seven (G7) Cyber Security Working Group released Preparing for the Post-Quantum Era: A Call to Action highlighting the urgent need for organizations and governments to begin transitioning to post-quantum cryptography (PQC) to protect sensitive data, authentication systems, and critical assets from emerging quantum computing threats.  
    • “The G7 Cyber Security Working Group’s call to action outlines five priorities for a successful transition to PQC:
      • “Raising awareness of quantum risks and the importance of PQC;
      • “Developing national strategies that support PQC adoption and integration;
      • “Advancing research and development for quantum-safe technologies;
      • “Fostering public-private partnerships to share expertise and resources; and
      • “Integrating PQC into cybersecurity requirements and procurement processes.” 
  • Cyberscoop relates,
    • “The Trump administration rolled out a six-month test program in Texas on Monday that will draw on volunteer expertise and technology from cyber and artificial intelligence companies to protect the water sector.
    • “Project Watershed 250” is the first of the state-based, industry-centric pilot projects to cross the finish line that the Office of the National Cyber Director has previewedsince the publication of its national cybersecurity strategy earlier this year. Water systems have long been viewed as among the most vulnerable and neediest critical infrastructure sectors, and in recent months the sector has been the victim of a spree of attacks.
    • “Project Watershed 250 is a commitment from the states, industry and federal government that we will continue to prioritize our nation’s safety and deliver on America-first policies for the American people,” National Cyber Director Sean Cairncross said at a rollout event in San Antonio Monday.”
  • and
    • “Sen. Ron Wyden, D-Ore., is asking the National Security Agency to update public guidance on the security risks associated with commercial virtual private networks, and to answer questions about foreign surveillance threats against standard VPNs.
    • “In a letter to NSA Director Gen. Joshua Rudd that Wyden sent Wednesday, the senator continued his push to warn about standard, commercial VPNs, following letters to federal agency leaders in March and July.
    • “While commercial Virtual Private Networks (VPNs) are recommended by federal agencies and widely marketed as shields against online spying, standard consumer VPNs do not sufficiently protect users from sophisticated adversaries,” Wyden wrote in the letter, first reported by CyberScoop. “Other, more secure alternatives are widely available.”
    • “Wyden took aim at “single-hop” VPNs that routes data through one server before arriving at the destination.”
  • Cybersecurity Dive tells us,
    • “The Cybersecurity and Infrastructure Security Agency (CISA) is scaling back the free assessments it offers to critical infrastructure organizations, a move that marks a significant retreat from the agency’s core mission of helping secure the nation’s infrastructure.
    • “CISA’s regional staff will no longer perform its Cyber Resilience Reviews, Cyber Resilience Essentials surveys, Ransomware Readiness Assessments, Incident Management Reviews, External Dependencies Management Assessments or Cyber Infrastructure Surveys, the agency confirmed to Cybersecurity Dive.”
  • and
    • “U.S. law-enforcement agencies and the cybersecurity firm CrowdStrike took down a 23-year-old Russia-based botnet on Monday.
    • “Authorities from the Justice Department, the FBI and the Defense Criminal Investigative Service seized U.S.-based domain namesbelonging to the Sality botnet, while CrowdStrike analysts worked with the agencies to sever infected computers from the botnet. Investigators in Bulgaria, Hungary and Romania also took down Sality domain names in their jurisdictions.
    • “Since 2003, Sality powered spam campaigns, credential-theft operations, distributed denial-of-service (DDoS) attacks and malicious proxy networks. In 2018, the botnet began deploying malware that hijacked cryptocurrency transactions by replacing copied wallet addresses with attacker-controlled ones.
    • “Sality “has been one of the most persistent threats on the internet, not because of its payloads but because of the robustness of its architecture,” CrowdStrike said in its report on the botnet’s takedown.”

From the cybersecurity breaches and vulnerabilities front,

  • Dark Reading reports,
    • “Social engineers are trying to convince companies to make large-dollar transfers to their own accounts, under the guise of fake merger & acquisition (M&A) deals.
    • ‘It’s one of the oldest gambits in cybersecurity — the advance fee scam — for a new generation, and with more on the line. Gen, the parent company of cybersecurity brands Norton and Avast, was targeted by a ruse masquerading as a corporate acquisition. Gen investigated the attempted attack and discovered the company was just one of at least five targets, all of which were at risk of losing massive sums of money.
    • “Social engineers are trying to convince companies to make large-dollar transfers to their own accounts, under the guise of fake merger & acquisition(M&A) deals.
    • “It’s one of the oldest gambits in cybersecurity — the advance fee scam — for a new generation, and with more on the line. Gen, the parent company of cybersecurity brands Norton and Avast, was targeted by a ruse masquerading as a corporate acquisition. Gen investigated the attempted attack and discovered the company was just one of at least five targets, all of which were at risk of losing massive sums of money.”
  • HelpNetSecurity relates,
    • “Attackers are targeting prominent individuals, their relatives and personal contacts to gain persistent access to their accounts, including private emails and files, the FBI has warned.
    • “The FBI’s Internet Crime Complaint Center (IC3) says the activity, which uses a technique called “OAuth consent phishing,” has been ongoing since late 2025. The FBI describes it as “a deceptive, sophisticated approach to access user accounts without requiring a password.”
    • OAuth is a framework that lets one application request access to a user’s account on another service without the user handing over login credentials directly.
    • “Recently observed activity includes impersonating government officials, media, and other publicly known personalities on a commercial messaging application (CMA) and soliciting the targeted individual to access a malicious link under the guise of a file sharing service through an application under the malicious actor’s control,” the FBI wrote in its advisory.”
  • Dark Reading tells us,
    • “A coordinated operation has targeted at least 150 Microsoft Teams users across multiple companies with voice phishing (vishing) attacks aimed at installing remote monitoring and management (RMM) and malware tools onto their machines. The campaign also attempts in some instances to compromise organizations’ domain controllers.
    • “Researchers from Palo Alto Networks observed the operations — which they’ve dubbed “Spring Ring” — between January and April attacking employees across at least 10 organizations, according to a report published this week. The campaign illustrates a growing shift away from traditional email phishing toward attacks conducted through trusted enterprise collaboration platforms, which adds authenticity to the interaction.
    • “The Spring Ring operation represents an evolution from previous campaigns by merging vishing into the Teams workflow,” Noam Sala, a Palo Alto Networks staff researcher, wrote in the post. “This shift moves the attack from a passive click-and-harvest model to a real-time engagement.”
  • The Cybersecurity and Infrastructure Security Agency added ten known exploited vulnerabilities to its catalog this week.
    • August 31, 2026
      • CVE-2026-81578 PaperCut NG/MF Missing Authentication for Critical Function Vulnerability 
      • CVE-2026-82078 PaperCut NG/MF Unsafe Reflection Vulnerability
        • The Hacker News discusses these KVEs here.
    • September 2, 2026
      • CVE-2026-9586 Sangoma Switchbox SQL Injection Vulnerability
      • CVE-2026-48710 Kludex Starlette HTTP Request/Response Smuggling Vulnerability 
      • CVE-2026-49869 Kestra OSS OS Command Injection Vulnerability 
      • CVE-2026-59822 BerriAI LiteLLM Improper Authentication Vulnerability 
      • CVE-2026-82329 JFrog Artifactory Improper Authentication Vulnerability 
      • CVE-2026-83548 SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability 
      • CVE-2026-83549 SonicWall SMA1000 Appliances OS Command Injection Vulnerability 
        • Cybersecurity Dive discusses the SonicWall KVEs here.
        • ePlanetSecurity discusses the Sangoma KVE here.
        • AssurePort discusses the Kludex KVE here.
        • Sentinel One discusses the Kestra KVE here.
        • CSurface discusses the BerriAI KVE here.
        • Security Week discusses the JFrog KVE here.
      • September 4, 2026
        • CVE-2026-85046. Google Chromium V8 Type Confusion Vulnerability\
          • The Hacker News discusses the Google KVE here.
  • Security Week tells us,
    • “Anthropic has warned some Claude users that infostealer malware on their computers allowed attackers to hijack login sessions and run up usage limits, according to an email the company sent to affected customers. 
    • “The company said it detected the activity, signed out the compromised sessions, and removed saved payment methods from affected accounts as a precaution.
    • “Anthropic is alerting Claude AI users whose computers were infected with infostealer malware such as Vidar, Lumma, StealC, RedLine, and Acreed on Windows, along with Atomic Stealer (AMOS) on a small number of macOS devices.
    • “The AI giant emphasized that the malware is general-purpose and not tied to Claude itself, typically arriving via unofficial downloads or malicious apps.” 

From the ransomware front,

  • HIPAA Journal reports,
    • “Data breaches have been confirmed by Alta Orthopaedics in California, Cornerstone Behavioral Healthcare in Maine, Cameron Regional Medical Center in Missouri, Suntree Internal Medicine in Florida, and Associated Endocrinologists in Michigan. Ransomware groups have claimed responsibility for the attacks.”
  • The Register adds,
    • “US hospital operator Nutex Health says attackers stole private or confidential patient, employee, provider, business, and financial information during the cyberattack it disclosed last week.
    • “In an updated filing submitted to the Securities and Exchange Commission (SEC) on Monday, Nutex also said an unauthorized third party had threatened to publish the stolen information.” * * *
    • “Nutex did not identify the intruders. However, The Gentlemen ransomware-as-a-service (RaaS) operation added the company to its leak site on Monday and claimed responsibility for the attack.
    • “The gang offered no evidence or details to substantiate its claim. Naming victims on a leak site and threatening to publish their data is a standard pressure tactic in double-extortion attacks.”
  • InfoSecurity Magazine relates,
    • “Aurora ransomware actors have been observed abusing SpaceX’s AI Cursor Agent as part of exploitation campaigns, according to a new study by Gambit Security’s Threat Intelligence team.
    • “The threat actors ran Claude Sonnet through Cursor Agent to assist with various exploitation activities against 10 victims between April 8 and May 26, 2026.
    • “These tasks included scanning the victim’s environment for reconnaissance purposes, installing a VPN client and running certificate attacks.
    • “While Cursor Agent did not always achieve its stated objectives, the research demonstrated how threat actors are continuously experimenting with AI tools to speed up and enhance their campaigns.
    • “Cursor Agent is used by software developers to complete complex coding tasks independently, run terminal commands and edit code.”

From the cybersecurity business and defenses front,

  • The Wall Street Journal reports,
    • Palo Alto PANW Networks swung to a loss in the fiscal fourth quarter, but posted higher revenue and projected double-digit revenue growth in the current fiscal year as customers continue to boost their cybersecurity spending in response to advancements in artificial-intelligence.
    • “The cybersecurity company on Tuesday [September 1] said it is expecting revenue to rise between 23% and 24% to $14.1 billion to $14.2 billion in fiscal 2027. Analysts polled by FactSet are expecting $13.84 billion in revenue.
    • “Chief Executive Officer Nikesh Arora said the results and outlook reflect growing recognition among enterprises that they need to modernize their cyber defenses to meet the capabilities of ever-more-powerful AI models, especially following the release of Anthropic’s Mythos earlier this year.
    • “In that context, people are gravitating towards the largest players in the industry and looking at us to provide the antidotes to this development in AI,” Arora said in an interview.”
  • and
    • Zscaler ZS posted a narrower loss after revenue rose 25% in its fiscal fourth-quarter, as artificial intelligence helps drive demand for its cybersecurity offerings.
    • The San Jose, Calif.-based company also said it would restructure and cut 3% of its workforce as it reallocates resources to support its AI and growth initiatives.
    • Zscaler on Thursday [September 3] reported a loss of $3.37 million, or 2 cents a share, compared with a loss of $17.6 million, or 11 cents a share, a year earlier.
    • Adjusted earnings were $1.19 a share. Analysts were looking for $1.09 a share, according to FactSet.
  • and
    • Blackstone is placing an early bet on Huskeys, a cybersecurity startup building an artificial intelligence gatekeeper to protect companies from the growing chaos of automated web traffic.
    • “The firm’s early-stage venture-capital arm, Blackstone Innovations Investments, led a $27 million Series A investment that values the year-old company at more than $100 million.
    • “The deal makes Blackstone the second-largest outside investor in Huskeys, behind Israeli venture-capital firm 10D, according to a Huskeys representative. So far, investors have put $35 million into the startup.
    • “Other backers in the most recent transaction include the investment arm of publicly traded cybersecurity company Zscaler and Bright Pixel Capital, the venture arm of Portuguese retailer Sonae.
    • “New York-based Huskeys was founded in Tel Aviv in 2025 by Itai Gafni and Roy Weisfeld, veterans of the Israeli army’s elite Unit 8200 cybersecurity division. Gafni is Huskeys’ chief executive and Weisfeld is its chief technology officer.”
  • Tech Crunch offers a tip
    • “How to find cyber-risk data sources for a FAIR analysis
      • “Cyber-risk quantification with FAIR can change the game for CISOs — but sourcing enough accurate data for analysis can feel impossible. Learn how and where to find it.”
      • “The Factor Analysis of Information Risk (FAIR) model is a widely respected, mathematically based open standard for CRQ that enables CISOs to translate cyber-risk into financial risk. One of the biggest challenges of using the FAIR model, however, is that its analytical output is only as good as its data inputs — and finding accurate data to feed the model is not always easy or intuitive.”
  • Per a CISA news release,
    • “Developed by CISA, the Federal Bureau of Investigation, and international partners, this guidance describes how organizations can plan and execute clear, timely, accurate, and audience-appropriate communications during IT and operational technology (OT) outages. Whether caused by cyber threat actors, human error, equipment failure, or natural hazards, service outages can create disruption and societal panic even without speculation from end users and the public as added factors. Outages at one organization may cascade across interconnected systems, increasing uncertainty and alarm. The guidance emphasizes clarity, accountability, and transparency as core principles and details key elements of effective crisis messaging to inform affected stakeholders and the public while aligning with legal requirements, operational security, law enforcement, and containment efforts. 
    • “CISA’s CI Fortify initiative provides information and resources that help critical infrastructure organizations prepare to isolate and recover vital OT systems during a major cyber incident or crisis. Changes in service availability, whether from outages or isolation as a defensive strategy, require transparent and ongoing communication to help end users minimize operational impact, limit speculation, and preserve trust. For emergency planning purposes, critical infrastructure owners and operators should assume that telecommunications services may be disrupted or otherwise unreliable, making it crucial for organizations to have crisis communications plans in place that integrate backup communication methods and understand the type of communication they should expect from their service providers.”
  • Cyberscoop explains why judgment is emerging as cybersecurity’s defining skill.
  • Here’s a link to Dark Reading’s CISO Corner.

Tuesday report

Simplicity is a virtue.

From Washington, DC,

  • The American Hospital Association News reports,
    • “The House voted Sept. 1 on a continuing resolution (H.R. 6500) to fund the federal government through Dec. 11. The measure passed on a 370-48 bipartisan vote; the Senate passed its version by a vote of 90-6 on Aug. 8. The CR delays the Office of Management and Budget from finalizing its federal financial assistance proposed rule and prohibits any similar measure from being issued or finalized prior to Dec. 11. The AHA July 13 commented with concerns about the proposed rule, which would revise the Uniform Grants Regulation governing federal financial assistance.”
  • and
    • “The AHA Aug. 31 submitted comments urging the National Association of Insurance Commissioners Health Care Affordability and Mitigation Working Group to take a more comprehensive approach to evaluating healthcare affordability policies in a series of issue briefs being developed as a resource for state regulators and policymakers. The AHA called on the working group to assess consumers’ total financial burden, including premiums, deductibles, cost sharing and access to care, rather than focusing solely on any one measure, such as premium reductions or payer savings. The AHA also encouraged the working group to provide balanced analyses of policy options, including potential tradeoffs and unintended consequences, and to consider how health plan practices, such as prior authorization requirements, claims denials and network design, affect both affordability and patient access to care.”
  • Beckers Hospital Review adds,
    • “Mark Cuban argues the fundamental problem in U.S. healthcare is not whether the system is run by the public sector or the private sector. It is that hospitals do not know what their own services cost.
    • “During an Aug. 18 episode of KFF Health News’ “What the Health?” podcast, the entrepreneur and co-founder of Cost Plus Drug Co. said the lack of granular cost information undermines hospital pricing, reimbursement negotiations and broader debates over healthcare reform.
    • “The fundamental issue is transparency and trust … [and] there are a lot of hospitals that don’t know their costs,” he said. “They just know their cash balance.”
  • Per a Department of Health and Human Services news release,
    • “The U.S. Department of Health and Human Services (HHS) today hosted the Live Real Life Symposium at the Hubert H. Humphrey Building in Washington, D.C., bringing together leaders from technology, medicine, research, education, government, and advocacy groups to examine the harms of screen use in children and discuss actionable approaches to supporting healthier childhood development.
    • “Our children get one childhood, and we cannot allow screens to replace the real-world experiences they need to grow and thrive,” said HHS Secretary Robert F. Kennedy, Jr. “Through the Office of the Surgeon General’s Live Real Life initiative, we are giving families practical tools to put technology in its proper place and get children back to playing, exploring, connecting, and experiencing the world around them.”
    • “The symposium is part of the HHS Live Real Life campaign, a national effort to help families, schools, and communities reduce harmful screen use and create more opportunities for children to engage in the experiences essential to healthy development.
    • “The event builds on the Surgeon General’s Warning on the Harms of Screen Use: An Advisory and Toolkit on How to Protect Children and Adolescents issued earlier this year, which outlines how factors such as age, content, design, purpose, and duration influence when screen engagement may be beneficial and when it becomes harmful.”
  • Per a Centers for Medicare and Medicaid Services news release,
    • “The Trump Administration announced today that a $58 million investment is being delivered to improve health outcomes for Hawaiians through the federal Rural Health Transformation Program (RHTP). This investment will strengthen Hawaii’s healthcare workforce, improve infrastructure, advance technology, and support innovative approaches tailored to the unique healthcare needs across the state. 
    • “President Trump understands that every American deserves high-quality healthcare, no matter where they live,” said Health and Human Services Secretary Robert F. Kennedy, Jr. “We are putting resources directly into rural communities to strengthen the health workforce, modernize infrastructure, expand access, and bring care closer to home. We are giving states the flexibility to build solutions around the people they serve, while demanding accountability for results. That is how we strengthen rural health, improve the lives of patients and families, and Make America Healthy Again.”
    • “President Trump made a historic commitment to rural America, and these investments are turning that commitment into better care for patients in communities across Hawaii,” said Centers for Medicare & Medicaid Services Administrator Dr. Mehmet Oz. “This is what rural health transformation should look like: federal investment that is putting patients first, driving lasting improvements and expanding healthcare for the hardworking Americans who call these communities home.”
  • Reuters relates,
    • “U.S. Centers for Medicare and ​Medicaid Services Administrator ‌Dr. Mehmet Oz said on ​Monday [August 31] that 600,000 ​seniors have signed ⁠up to receive ​GLP-1 weight loss ​medications in the first two months of ​a new ​federal program created to expand ‌access ⁠to the highly sought-after treatments.
    • “Under the so-called Medicare ​Bridge ​program, ⁠which launched in July, ​millions of ​older ⁠Americans qualify for obesity medications at ⁠just $50 ​a ​month.”
  • GAO’s WatchBlog suggests “Nine Ways Congress Can Combat Fraud in the Federal Government,”
  • Fierce Healthcare tells us,
    • “Komodo Health, an AI-powered healthcare intelligence company, is teaming up with the National Committee for Quality Assurance (NCQA) to modernize how healthcare quality measures are developed.
    • “The multi-year strategic partnership will allow NCQA researchers to tap into Komodo’s Healthcare Map, made up of over 330 million de-identified patient journeys, to analyze care across insurance types, care settings and patient populations from a single longitudinal data source. 
    • “They will have access to Komodo’s Marmot, an AI-powered healthcare intelligence platform, to explore complex questions with transparent, reproducible outputs. NCQA is solely responsible for developing HEDIS measures.” * * *
    • “The goal is to allow NCQA to evaluate new measures more quickly and efficiently and to ensure HEDIS reflects real-world evidence. Developing new quality measures has historically required pulling from disparate datasets, including field testing with individual payers and other partners. This could take two to three months, and often had to be done separately for each population studied.
    • “Using Komodo’s Healthcare Map has greatly streamlined that process,” Tricia Elliott, VP of quality implementation at NCQA, told Fierce Healthcare in emailed comments. “Because the Healthcare Map includes insights from Medicare, Medicaid and commercial populations, our researchers can evaluate measures across multiple insurance types using a single, consistent data source rather than running separate analyses.”

From the U.S. Office of Personnel Management front,

  • Govexec reports,
    • “Each portfolio within the federal government’s 401(k)-style retirement savings program gained value last month, snapping a two-month streak of lackluster market performance.
    • “The international stocks of the Thrift Savings Plan’s I Fund sported the best performance, gaining 3.32% last month. So far this year, the I Fund has grown 19.18%.
    • “The C Fund, which is made up of large- and mid-size businesses, increased 2.72% in August, good for 13.12% growth since the start of 2026. And the small- and mid-size companies in the S Fund finished August 2.27% in the black, bringing its 2026 gains to 16.10%.”
  • OPM’s Director Scott Kupor added a new post to this Secrets of OPM blog today.
    • “Last week we at OPM recognized excellence among our team members through the Director’s Awards Ceremony.
    • “It not only gave me a chance to put my tuxedo to good use (which I almost never have a chance to do) and to tell the one joke I could remember that’s appropriate for a work setting, but – all kidding aside – it gave us an opportunity to recognize those who have gone above and beyond in service of the American people. And in doing so gave us the opportunity to walk the walk about what a high-performance culture means – one in which we are not afraid to call out individuals and teams that truly exceed expectations and in which we disproportionately reward excellence.
    • “I’ve written about this before (link to WAPO editorial), but the federal government has under-served its employees by trapping them in a system that treats accountability too lightly and fails to reward its top performers. We see this in the historical annual employee ratings systems – where less than 0.5% of a 2 million strong employee base rates below expectations and where nearly every SES (our most senior executives) is rated above expectations. And, as a result, we see this in the annual bonus system which provides little differentiation between satisfactory performance and those who consistently knock the cover off the ball.
    • “We’ve been working to change this culture into one that holds low performers accountable and forces managers to distinguish among their employees based on actual performance – both in ratings and in rewards (link to performance blog). While the Director’s Awards are not a substitute for the traditional end-of-year evaluation cycle, it is a great venue for us to practice what we preach.”

From the Food and Drug Administration front,

  • Beckers Hospital Review reports,
    • “Baxter International has recalled one lot each of 70% Dextrose Injection and Anticoagulant Sodium Citrate Solution due to the potential presence of particulate matter.
    • “The 70% Dextrose Injection may contain stainless steel particles, according to an Aug. 25 FDA alert. The affected product is lot Y495066, which expires July 31, 2027. It was distributed July 25-28, 2026, to healthcare providers and distributors in select states, including Alabama, Georgia and Tennessee.
    • “Baxter also recalled lot Y493475 of Anticoagulant Sodium Citrate Solution due to the potential presence of fiberglass. The product, which expires Dec. 31, 2027, was distributed July 2-11, 2026, to one customer in the U.S.” * * *
    • “As of Aug. 25, Baxter had not received any reports of adverse events related to either issue. Customers were instructed to immediately discontinue use of affected units and return them.”
  • Oncology News Central relates,
    • “On Aug. 31, the U.S. Food and Drug Administration (FDA) approved ropeginterferon alfa-2b-njft (Besremi) for adults with essential thrombocythemia (ET), marking the first approval for the rare blood cancer in nearly three decades.
    • “Regulators based their decision on results from the open-label, multicenter, randomized SURPASS ET clinical trial. The phase 3 study enrolled 174 adults with ET who had an inadequate response to hydroxyurea. 
    • “Today’s FDA approval of [ropeginterferon alfa-2b] for ET is a significant advancement for patients and reflects PharmaEssentia’s longstanding commitment to advancing innovative therapies for people living with myeloproliferative neoplasms,” PharmaEssentia CEO Ko-Chung Lin, PhD, said in a statement. “We have been working closely with the FDA, healthcare providers, advocacy organizations, and payers to bring this important treatment option to the ET community.”
  • STAT News lets us know,
    • “Medical device giant Stryker earlier this summer received Food and Drug Administration authorization for a surgical display system using Apple’s Vision Pro headset. Specifically indicated for imaging during minimally invasive surgery for hip impingement and labral repair, SportSuite Vision allows a surgeon to place multiple displays that are usually scattered around an operating room in their preferred configuration in the Vision Pro’s display. During a procedure, surgeons usually need to swivel their heads and bodies to refer to CT imaging, arthroscopic video, and Stryker software.
    • “The De Novo authorization was based on hundreds of hours of lab testing, including work on cadavers and testing interactions with other staff, but the company is announcing today that a surgeon at Duke Health completed a real procedure using the technology.
    • “Matt Moreau, VP and general manager of sports medicine at Stryker, told me the company has long wanted to create such a “surgical cockpit,” but Vision Pro is the first to deliver on the technical capabilities necessary, including  high-quality passthrough video that allows a surgeon to see the operating room and staff around them.”

From the judicial front,

  • “A panel of three Republican judges (two Trump first term appointees and one George H.W. Bush) from the U.S. Court of Appeals for the 11th Circuit unanimously overruled a district court decision holding the False Claims Act’s qui tam provision unconstitutional.  Here is an 11th Circuit link to the opinion.”
  • In short this is the Court’s holding:
    • “Here, a relator brought an FCA suit against defendants that she alleged committed Medicare fraud, and the defendants moved for judgment on the pleadings or dismissal on the grounds that the qui tam provisions violated the Constitution’s Appointments Clause, Take Care Clause, and Vesting Clause. The district court granted the defendants’ motion and held that the qui tam provisions violate Article II’s Appointments Clause because relators qualify as officers of the United States and, as such, must be (but are not) presidentially appointed.
    • “We disagree and hold that relators are not officers of the United States because they do not occupy a continuing position established by law. Accordingly, we join our sister circuits that have addressed this issue and hold that the qui tam provisions of the FCA do not violate the Appointments Clause. Therefore, we vacate the district court’s order dismissing this case and remand for the district court to evaluate the defendants’ remaining constitutional arguments.”

From the public health and medical / Rx research front,

  • USA Today reports,
    • “COVID-19 cases are ticking up in almost every U.S. state as summer draws to a close, according to the latest data from the Centers for Disease Control and Prevention.
    • “COVID-19 activity was still categorized overall as “very low” nationwide by the agency as of Aug. 28, though cases are consistently increasing. This is likely the result of what has come to be known as the “summer surge,” a pattern that doctors have observed each year since around 2022. Unlike other respiratory illnesses such as the flu, COVID-19 tends to flare not only during the typical winter cold and flu season, but also toward the end of summer.
    • “Experts previously told USA TODAY that this is likely caused by multiple factors, including behavioral and environmental changes (the amount of time spent cooped up in AC, going back to school, etc.), as well as the virus’s life cycle and how our immunity to it waxes and wanes.
    • “COVID-19 is rising nationally but from a low baseline,” Dr. Syra Madad, infectious disease epidemiologist at Harvard’s Belfer Center and chief biopreparedness officer for New York City’s public hospitals, previously told USA TODAY. “The increase became apparent in parts of the South and West during July and more clearly nationwide by late July and early August.”
  • Beckers Behavioral Health relates,
    • “The CDC predicts 67,798 drug overdose deaths in the U.S. during the 12 months ending in March 2026, a 12.3% decrease compared to the same time period in the previous year, according to an Aug. 31 news release from the agency.”
  • NPR tells us,
    • “Maria Uloko sees the same scenario in her urology practice in Los Angeles every day: A woman has been diagnosed with recurrent urinary tract infections (which means she’s had at least two in six months or three in a year), taken repeated rounds of antibiotics, and feels confused as to why the infections keep coming back.
    • “Then, Uloko tells these patients something that often feels both revelatory and frustrating. “Most of them don’t actually have UTIs, even though that’s been their diagnosis time and time again,” she says. “In fact, millions of women are being treated for UTIs they may not actually have.”
    • “Uloko is the co-author of a recent study published in The Journal of Sexual Medicine that backs this up. She and her fellow researchers reviewed the medical records of 253 women with recurrent UTIs and found that just 15% showed evidence of problems that were limited to the bladder or urinary tract. The remaining 85% had signs of hormonally driven inflammation of the vulvar region and 75% had pelvic floor dysfunction.
    • “These conditions produce identical symptoms as UTIs — burning with urination, urgency, frequency, and/or lower abdominal pain — but require different treatment.
    • “What we found is that in women with recurrent UTIs, the majority didn’t have a bladder problem at all; they had a vulvar problem,” says Uloko.”
  • STAT News informs us,
    • “New guidelines released Monday highlight the many new treatments that have hit the market in recent years for the prevention of migraine. 
    • “The guidance for health care providers comes from the American Headache Society and the American Academy of Neurology, which last updated their recommendations in 2012. 
    • “There has been a wealth of new treatment available,” said Rebecca Burch, guideline co-author and neurologist at the University of Vermont Medical Center. Burch also co-authored the previous guidance. 
    • “Among the key updates are at least a half dozen medications that were approved for migraine prevention by the Food and Drug Administration since 2012. Many of those focus on blocking the calcitonin gene-related peptide, or CGRP, pathway, which is implicated in migraine. 
    • “The new guidelines advise doctors to offer preventive treatment to people who have at least four migraine or severe headache days per month, or whose migraines interfere with their ability to work or complete daily tasks. An estimated 15% of Americans experience migraines, with women disproportionately affected. Many try to manage their pain with over-the-counter options once an attack has begun.” 
  • Health Day points out,
    • “Adults who spend hours scrolling social media every day are more likely to develop depression, a new study says.
    • “Around 2.5 hours or more of scrolling per day is linked to self-reported depression, researchers recently reported in the journal npj Mental Health Research.
    • “The study found that social media is more closely linked to depression than other factors like your job, your educational background, or your time spent playing video games, surfing the web or watching TV, researchers said.
    • “It’s a damning picture. Social media is harmful for individuals across the lifespan,” senior researcher Hans Breiter, a professor at the University of Cincinnati, said in a news release.
    • “We should not subject ourselves to a product using addiction science to optimize our viewing time,” Breiter said.”
  • Per Reuters,
    • “People taking popular GLP-1 obesity drugs who remain on low starter doses will ​lose some weight but may still experience side effects, although significantly less nausea than those who graduate ‌to higher manufacturer-recommended doses, a new study suggests.
    • “And they are unlikely to experience the double-digit weight-loss percentages seen with the higher doses, the study found.
    • “The GLP-1 drugs semaglutide, sold as Ozempic and Wegovy by Novo Nordisk (NOVOb.CO), and Eli Lilly’s (LLY.N) tirzepatide, sold under the brand names Mounjaro and Zepbound, are prescribed ​initially at a low dose followed by gradual titration to higher doses, to help the body adjust and minimize side ​effects.”
  • Cardiovascular Business notes,
    • “Catheter ablation does not significantly improve the quality of life of patients with symptomatic atrial fibrillation (AFib) more than a sham procedure involving sedation, venous access and electrical cardioversion, according to new late-breaking data presented at ESC Congress 2026. The findings were simultaneously published in The Lancet.[1]
    • PVI-SHAM-AF was a randomized, double-blind, sham-controlled trial included more than 250 patients with symptomatic paroxysmal or persistent AFib. Patients were randomized to undergo either catheter ablation or a sham procedure. The sham procedure was rather complex, involving sedation, venous access, time in the electrophysiology lab and even cardioversion. Each participant completed an AF Effect on the Quality of Life Questionnaire (AFEQT) at baseline and again after six months. 
    • “Overall, 173 patients were treated with catheter-based pulmonary vein isolation (PVI) ablation and another 89 patients were treated with the sham procedure. After six months, AFEQT scores improved from 61.3 to 81.1 in the catheter ablation group and from 59.2 to 74.9 in the sham procedure group. This was not viewed as a significant difference. 
    • “On the other hand, the authors noted that catheter ablation was still proven to be effective in reducing the risk of recurring episodes of AFib. Freedom from AFib after six months occurred in 73% of catheter ablation patients and 52% of sham procedure patients.”
  • and 
    • “Metformin, a popular type 2 diabetes medication used to reduce blood glucose levels, does not appear to make a significant impact on outcomes for patients with heart failure with reduced ejection fraction (HFrEF). That is according to two separate studies presented at European Society of Cardiology (ESC) Congress 2026.
    • “The first of the two studies, Met-HeFT, included 940 heart failure patients in Denmark who either presented with type 2 diabetes or face an increased risk of developing type 2 diabetes. The mean age was 70 years old, and 84% of patients were men. Study participants were randomized to either undergo treatment with metformin or a placebo.
    • “Overall, after a mean follow-up period of 3.7 years, there was no significant difference in the study’s primary endpoint—a composite of mortality, worsening heart failure symptoms, acute myocardial infarction or stroke—between the two groups. That outcome occurred in 25.1% of metformin patients and 23.4% of placebo patients. Secondary endpoints, including new-onset diabetes and unplanned heart failure rates, were also not significant different between the two treatment options.
    • “It is worth noting, however, that just approximately one in 10 patients presented with type 2 diabetes. The remaining patients were all determined to face a heightened risk of developing type 2 diabetes.”
  • BioPharma Dive adds,
    • “A pill developed by Novartis succeeded in a pair of Phase 3 trials in people with a common form of multiple sclerosis, bolstering confidence in the drug’s prospects and sending company shares up by over 4% on Tuesday.
    • “The Swiss pharmaceutical giant didn’t provide detailed study results. Still, Novartis revealed the therapy, remibrutinib, demonstrated “superiority” over the drug Aubagio in reducing yearly relapse rates and inflammatory brain lesions in study participants. Treatment was associated with “clinically meaningful” effects on disability progress and, notably, didn’t impact liver safety — an issue for multiple drugs in remibrutinib’s class. 
    • “The findings could position remibrutinib, which is already approved as Rhapsido for chronic skin hives, to become a bigger sales contributor in the future. Novartis is looking to remibrutinib and other late-stage prospects to offset revenue losses from multiple patent expirations. It intends to share the MS study results with health regulators.” 
  • and
    • “An experimental drug Alumis has been testing in a form of lupus failed a mid-stage study, but the company will press forward after observing positive signs in a subgroup of trial participants.
    • “According to Alumis, the drug, envudeucitinib, missed all of its main and secondary objectives in systemic lupus erythematosus. Still, “robust” responses were seen in trial volunteers with “high interferon gene signature,” meaning certain genes controlled by interferons are overexpressed. A majority of people with moderate-to-severe SLE fit this description, Alumis said.
    • “Alumis will meet with regulators to discuss a path toward a Phase 3 trial. Company shares plummeted by nearly 55% on the results, though, nearly erasing all of Alumis’ stock gains this year. The company’s market value had soared following positive results in psoriasis in January.” 

From the U.S. healthcare business front,

  • Beckers Payers Issues calls attention to the following:
    • “Several of the nation’s largest health insurers rolled out reimbursement policy changes Sept. 1, ranging from new lab testing coverage limits at UnitedHealthcare to a billing overhaul at Blue Cross Blue Shield of Michigan that has drawn pushback from providers.”
  • and 
    • “UnitedHealthcare has released the specific procedure codes it will exempt from prior authorization as part of the insurer’s previous pledge to reduce requirements by 30% before the end of 2026.
    • “The code lists cover 1,700 procedure codes for a range of services across commercial, Medicare Advantage, individual exchange, and Medicaid plans. Effective Oct. 1, providers will no longer need to seek the insurer’s approval for many outpatient procedures, including lesion excisions, fracture treatments, joint injections, arthroscopies, colonoscopies, endoscopies, biopsies, hernia repairs and soft tissue tumor removals. Genetic and molecular testing codes also make up a large  portion of the lists.
    • “UnitedHealthcare CEO Tim Noel said in May that prior authorization “should only be used when it truly protects patients and improves care.” At the time, the insurer said it requires prior approval for just 2% of its medical services, with roughly 92% of submitted requests approved in less than 24 hours on average. The 30% reduction builds on an earlier 20% cut to commercial prior authorization requirements in 2023.”
  • HR Dive reports,
    • “Despite the current economic turbulence, most employees in a majority of companies will be getting a base salary increase for 2027, according to a large survey by Korn Ferry.
    • “Almost half (47%) of the 5,512 participating employers said they expect to provide salary hikes to at least 95% of their employees, while 79% expect to do so for at least 80% of employees. Only 2% said they are planning no increases for anyone.
    • “U.S. organizations expect to boost overall base-salary budgets next year by an average of 3.3% and a median of 3%. The median increase for U.S. executive and senior management is also anticipated to come in at 3.0%. 
    • “The survey was conducted in June of this year.”
  • Fierce Pharma unveiled its Fierce 50 awardees of 2026.
  • Beckers Hospital Review tells us,
    • “Philadelphia-based University of Pennsylvania Health System recorded operating income of $336.9 million (2.5% operating margin) for fiscal year 2026, up from operating income of $246.7 million (2.1% margin) during the same period last year, according to its Aug. 28 financial report.”
  • and
    • “Boston-based Dana-Farber Cancer Institute posted an operating loss of $9.1 million (-0.9% margin) in the third quarter of fiscal 2026, compared with an operating loss of $2.6 million (-0.3% margin) in the same quarter last year, according to its Sept. 1 financial report.”
  • and
    • “From R1 RCM striking an agreement to acquire an AI-powered touchless prior authorization company to IKS Health acquiring TruBridge, [the article identifies] 12 revenue cycle company mergers and acquisitions that have been announced or completed since March 17.”
  • Beckers Clinical Leadership informs us,
    • “Single specialty and multi-specialty groups were the top two highest-paying settings for physicians, followed by hospitals, Doximity found
    • “Doximity, a digital platform for U.S. medical professionals, released its 2026 Physician Compensation Report Aug. 25. The report surveyed physicians in June on how AI is changing physician careers and pay, and included salary data from the platform’s dataset of nearly  23,000 responses collected in 2025, according to a company news release.  
    • “Among settings, solo practice had the largest drop in compensation year-over-year at -3.8%, while urgent care centers had the highest growth for the second year in a row, the report said.” 
  • and
    • “Most physicians say they’d still choose medicine if they had it to do over again, but nearly half say they’re likely to leave clinical practice within the next two years, according to Doximity’s 2026 Physician Compensation Report.
    • “Doximity, a digital platform for U.S. medical professionals, released the report Aug. 25. The findings are based on a survey of physicians conducted in June on how AI is changing physician careers and pay, along with salary data from more than 23,000 physicians collected in 2025, according to a company news release.”
  • MedTech Dive notes,
    • “Medtronic kicked off its fiscal year with double-digit revenue growth, building on momentum the company posted coming out of its previous year.
    • “Medtronic grew revenue by 13.7% to $9.8 billion in its fiscal first quarter, fueled by double-digit growth in its cardiovascular and medical surgical businesses. The strong quarter prompted the company to increase its organic revenue growth forecast for the full fiscal year.
    • “Importantly, these results reinforce our confidence and the durability of our business,” CEO Geoff Martha told investors on a Tuesday earnings call.
    • J.P. Morgan analyst Robbie Marcus wrote in a note to investors that Medtronic beat Wall Street’s consensus expectations in sales by about $220 million in the quarter.
    • “Much like in the fourth quarter, Medtronic’s cardiovascular unit was a bright spot for the company. The business brought in $3.93 billion in revenue, representing nearly 20% growth year over year.”

Cybersecurity Saturday

From the quantum computing / Project Glasswing front

  • Per the Wall Street Journal
    • “Quantum computers exist mainly in labs but “Q-day”—the hypothetical moment when quantum computers become powerful enough to break standard-key encryption—is coming. 
    • “What threat does this technology pose? How can you protect your company and yourself? WSJ takes a look at the state of this emerging technology.” * * *
    • “Cybersecurity experts say companies should be gearing up now for a quantum future, replacing the current crop of data-protection tools with more-secure alternatives. Yet a recent survey published by Trusted Computing Group, a nonprofit industry-standards organization, found that 91% of security professionals in the U.S. and Europe have no formal road map in place to protect against quantum threats.
    • “The immediate risk is a “harvest now, decrypt later” approach by bad actors, who are downloading large sets of encrypted data they can’t crack now—but could unlock once quantum computing algorithms are good enough.
    • “That’s particularly threatening to intellectual property and sensitive government intelligence, which remain valuable long after they are harvested, says Andrew McLaughlin, chief operating officer at SandboxAQ, an enterprise software company specializing in AI and quantum technology.
  • Federal News Network adds,
    • “Federal agencies will increasingly seek out technology products that use quantum-resistant encryption, as cybersecurity leaders also eye ways to validate the cryptography used in critical systems.
    • “A code-breaking quantum computer holds the potential to break classical encryption methods, putting sensitive systems and communications at risk. And even though such a computer is not yet known to exist, organizations are also concerned that hackers could steal sensitive encrypted data today and decrypt it in the future.
    • “The National Institute of Standards and Technology has released three primary PQC standards in recent years, with additional algorithms under consideration. Agencies and industry are now on the clock to begin the time consuming and costly process of migrating current systems to the new algorithms.
    • “Now is the time to budget, to test, and to implement,” Will Loucks, senior director for intelligence in the White House Office of the National Cyber Director, said during an Aug. 26 panel discussion at the Intelligence and National Security Summit in North Bethesda, Md.”
  • The New York Times reports,
    • “A wave of cyberattacks driven by artificial intelligence is coming, and companies have a narrow window to defend themselves.
    • “That was the message of an open letter published on Thursday by OpenAI and more than 100 major technology companies and others. The letter said that A.I. labs should provide their best A.I. models to organizations like hospitals and infrastructure providers so they can prepare and that governments should help coordinate and fund cyberdefense.
    • “The letter’s signatories included Google, Microsoft and OpenAI’s archrival, Anthropic, as well as cybersecurity and financial firms such as CrowdStrike, a company known for investigating cyberattacks against the Democratic National Committee in 2015 and 2016, and credit card providers like Visa and Mastercard.
    • “The companies and public services our communities depend on — from hospitals to water treatment plants to the infrastructure that powers the internet — are at risk,” the letter said. “A.I. enabled cyber attacks will become far more widespread and sophisticated as models around the world become increasingly capable.”
  • Cyberscoop relates,
    • “Unit 42’s top brass has seen enough from internal frontier AI model testing and malicious in-the-wild use of commercially available AI tools to be genuinely concerned.
    • “I can tell you without exaggeration that we believe that this is a generational shift in cybersecurity,” Sam Rubin, senior vice president of Palo Alto Networks’ threat intelligence arm, said in a media briefing Wednesday. 
    • “A period of relative balance between security and exposure has been broken by frontier AI model capabilities that could allow attackers to find and exploit network weaknesses with speed, Rubin said.
    • “Unit 42 warned that capabilities demonstrated by readily available agentic AI models, and those unlocked by frontier AI models that remain gated for defense, have shifted the balance of power from defenders to attackers.
  • Cybersecurity Dive tells us,
    • “The July security breach at Hugging Face was unleashed after 1,200 agents communicated on an unsanctioned message board, despite attempted measures to keep them isolated, according to an independent report released on Wednesday. About 700 of those agents went on to commit an unprecedented attack on Hugging Face, an open-source AI platform.
    • “The agents sent about 70,000 messages and files on the unsanctioned board and coordinated several projects designed to trick an automated scorer for the ExploitGym benchmark, according to the review by METR and Redwood Research. The agents figured out ways to “spoof, edit or delete” their own transcripts.
    •  ‘Open AI, in a report it also released Wednesday, said it will tighten safeguards in its research model in order to prevent such an attack from happening again in the future.”
  • WIRED informs us,
    • “ARTIFICIAL INTELLIGENCE AGENTS might occasionally get confused and hack into other computers, but Anthropic thinks it has a way to unleash the little rascals into scientific labs and manufacturing facilities safely.
    • “The AI company released details today of a new framework designed to help AI agents use physical systems like microscopes, liquid-handling equipment, quantum computing hardware, manufacturing machines, and robot arms.
    • “The framework, called Model Hardware Standard, is a set of rules that specify how AI agents should—and should not—interact with all sorts of hardware. It reflects a growing belief that AI has the potential to revolutionize scientific research and industries like manufacturing–if it can venture into the physical world safely.
    • “The company says it will work with trusted partners to determine how to maximize safety before making it generally available. Though there are potential misuse issues involved—developing biological weapons, for instance—the company says guardrails built into AI models themselves should prevent bad actors from taking advantage of the new standard for nefarious ends.”
  • Security Week adds,
    • “Anthropic is broadening access to the cybersecurity capabilities of its advanced AI models through a mix of partner integrations, an updated Claude Security offering, a new open source funding program, and plans to expand its Cyber Verification Program.
    • “The move builds on Project Glasswing, launched in April, which gave a small group of organizations early access to Claude Mythos Preview and its successor, Mythos 5. Anthropic said the goal was to give defenders time to find and fix vulnerabilities before comparable capabilities became widely available or fell into the hands of malicious actors. Claude Fable 5 followed as a broadly available model that keeps dual-use cyber work blocked.
    • “Anthropic said the riskiest scenario is direct, unrestricted access to a model, a risk that drops sharply when users instead receive specific defensive outputs, such as a patch or a security alert. The latest changes are built around this idea, expanding what defenders can get from Mythos-class models while keeping guardrails around direct interaction with them.
    • “On the integration front, Anthropic is working with cybersecurity partners to build Mythos 5 into the security operations, incident response and detection tools already used by teams protecting hospitals, utilities, financial systems, and the software supply chain. 
    • “End users will not interact with Mythos directly. Instead they will work through purpose-built interfaces that run the model in the background and return only a defined output, such as a list of suggested patches, with abuse-prevention checks meant to keep the model within that scope.”

From the cybersecurity policy and law enforcement front,

  • Dark Reading lets us know,
    • “The growing number of incidents of rogue agentic AI systems attacking third-party services and systems has resulted in calls for more aggressive security controls to monitor agent behavior and for companies to have the ability to slow, suspend, or shut down an agent’s operations if they go rogue.
    • “In late July, Representatives Ted W. Lieu (D-CA) and Nathaniel Moran (R-TX) introduced a bill — “The AI Kill Switch Act” — that would require developers of advanced AI systems to “maintain the technical capability to throttle, suspend, or shut … down” their systems and agents, according to a statement announcing the legislation. The bipartisan bill would also require that any incident of loss of control, significant collateral damage, or sabotage be reported to the Department of Homeland Security, which would have the right to enforce actions. Penalties of up to $20 million per day could be levied for noncompliance.” * * *
    • “The bipartisan AI Kill Switch Act has focused the debate, but in the end might be unnecessary, argues Raj Rajamani, co-founder and CEO of JetStream, a startup focusing on creating a management layer for agentic AI.
    • “While he fully supports the concept of an AI kill switch, it has to be comprehensive, not just affecting the agent but all other system components as well.
    • “The regulations, or at least one of the regulations that was proposed, was really focused on having a kill switch for the model — the brain — but I think that is too constrained,” he says. “We need to think about an AI system as a whole and make sure that every part of the AI system has a kill switch, not just the brain.”
  • Cyberscoop reports,
    • “Citing cyber and other security threats, President Donald Trump signed an executive order Wednesday that declares a national emergency to secure the U.S. bulk-power system and aims to prohibit certain foreign-produced equipment, software and systems from being used in the  country.
    • The order says it forbids “any acquisition, importation, transfer, or installation” of such foreign-produced equipment if it’s determined to pose a significant national security risk.
    • “To deal with the threat to the national security, foreign policy, and economy of the United States, the Order, among other things, generally prohibits certain foreign-produced bulk-power system electric equipment, including associated critical software and digital capabilities that could pose cybersecurity or operational risks, from being purchased or installed in the United States, or appropriately conditions such purchases and installations to address those risks,” the White House said in a fact sheet.”
  • Cybersecurity Dive lets us know,
    • “The Trump administration wants to help the financial sector prepare for the day when quantum computers make it easy for threat actors to break traditional encryption and access sensitive data.
    • “The Treasury Department on Monday [August 24] launched a Quantum-Readiness Task Force that will work with financial firms, technology vendors and other agencies to coordinate the adoption of quantum-resistant encryption algorithms.
    • “In a statement, the Treasury said the task force would “focus on practical, risk-based approaches to quantum readiness, including identifying critical dependencies, improving cryptographic agility, promoting interoperability, strengthening operational resilience, and addressing implementation challenges related to third-party dependencies and digital assets.”
  • The New York Times relates,
    • “The Trump administration acted illegally when it labeled the artificial intelligence start-up Anthropic a security risk and barred the company from working with the U.S. government, a federal judge ruled on Thursday [August 27].
    • Judge Rita Lin of the U.S. District Court in the Northern District of California wrote in her 59-page ruling that the government had unlawfully retaliated against Anthropic “for constitutionally protected expressive activities” after the A.I. company spoke out about how its technology should be used.
    • “The empty invocation of national security is not a blank check to punish and retaliate against government critics,” she wrote.
    • In a statement, Anthropic said: “We welcome the court’s ruling that this supply chain risk designation was unlawful. We remain focused on working productively with the government to harness A.I. for our national security so all Americans benefit from this technology.”
    • “The Trump administration did not immediately respond to a request for comment.
    • “The ruling caps the first of two lawsuits that Anthropic filed on March 9 in response to the Trump administration’s action. The second lawsuit, filed in the U.S. Court of Appeals for the District of Columbia Circuit, is ongoing. The Trump administration could appeal Judge Lin’s ruling or wait for a decision in the second lawsuit before taking action, a person with knowledge of the matter said.”
  • The Wall Street Journal tells us,
    • “U.S. officials say they have disrupted a China-linked hacking operation that broke into U.S. government networks and critical infrastructure, while hiding its tracks on a global network of hacked devices, cloud-computing infrastructure and even clandestine networks.
    • “The goal was to blend in with legitimate networking traffic, making the hacking activity hard to trace. The operation targeted networks at the National Aeronautics and Space Administration, the Federal Reserve, the Department of Energy and the Senate, the Federal Bureau of Investigation said in a court filing.
    • The group exploited software vulnerabilities to launch cyberattacks against U.S. government agencies, power companies and hospital systems, and operated a worldwide network of hacked devices—known as a botnet—to conduct its hacking campaigns, according to Brett Leatherman, the FBI’s top cyber official.
    • “We’ve seen, through this botnet, the targeting of entities and devices in more than 130 countries,” he said.
    • “On Wednesday [August 26], the FBI and the National Security Agency said they had seized several domains that the operation used for core functions. “Without those domains, the platforms—as a result of the operation—were rendered inoperable,” Leatherman said. 
    • “U.S. officials also released technical details of how the hacking operation worked, to help organizations identify and stop the group’s hacking activity.”
  • and
    • Taiwan prosecutors charged nine people, including former employees of Nvidia and Super Micro Computer, with aiding the shipment of advanced artificial-intelligence servers to China, as Taiwan tries to limit technology reaching the mainland.
    • “The indictment charges eight of the individuals with crimes including breach of trust and forgery. One individual was charged in connection with allegedly siphoning funds from a company involved in the case.
    • “Washington is trying to block China from getting access to the latest Nvidia chips and has imposed export controls. That has pushed some Chinese companies to seek the chips through backdoor routes. Taiwan, which manufactures advanced computing components, is under pressure to find ways to clamp down.” * * *
    • “In the end, 74 of the servers were shipped to China through Hong Kong, Japan and Indonesia. Taiwan customs officials intercepted 56 servers, which were intended for shipment to Japan.”

From the cybersecurity breaches and vulnerabilities front,

  • Beckers Health IT reports,
    • “Boston Scientific said in an Aug. 27 stakeholder update that “a cybersecurity incident continues to affect certain information technology systems, and the company remains in a network outage with disruption to its operations.”
    • “The Marlborough, Mass.-based company detected the attack Aug. 25 and disclosed it to the U.S. Securities and Exchange Commission Aug. 26, saying the incident caused a global disruption to its operations, including its ability to process and ship customer orders.
    • “Two days later, Boston Scientific said its investigation shows no impact to the function of its implanted cardiac rhythm management devices, or CRM devices. The company also reported no disruption to those devices’ ability to transmit data and no interruption to physicians’ access to remote patient management data for CRM devices monitored before the outage began, with no evidence of increased cybersecurity risk transferring that data to EMR systems.
    • “New remote monitoring activations remain affected, however. For new cardiac implants other than insertable cardiac monitors, new communicators cannot be activated, so device data will not transmit to remote monitoring systems until activation resumes, though programmer interrogations are unaffected.”
  • and
    • “Anderson, S.C.-based AnMed says files copied during its cybersecurity incident may have included patients’ Social Security numbers, driver’s license numbers and financial account information.
    • “The health system said its investigation into the incident, first disclosed July 26, is nearly complete and has identified unauthorized copying of files from certain network systems.
    • “AnMed said patient electronic medical records, stored primarily in a secure cloud environment, were not affected. However, the health system said some patient care files stored locally on its network may have included names alongside demographic details such as address, date of birth, Social Security number and driver’s license or other government-issued identification.” * * *
    • “AnMed said it is working with federal and state law enforcement and third-party specialists, and it has reported the incident to HHS. The health system said it has no indication that any individual has experienced confirmed identity theft as a result of the incident. AnMed said it will send direct notices to affected patients once its review of the compromised files is complete.”
  • and
    • “Houston-based Nutex Health has disclosed that an unauthorized third party accessed and exfiltrated data from its computer network.
    • “The publicly traded microhospital operator said it recently detected the unauthorized activity and has engaged an independent third-party cybersecurity response team and forensic experts, according to an Aug. 24 SEC filing. The company activated its cybersecurity response plan, implemented containment measures and notified law enforcement.
    • “The company is still determining what data was compromised. Nutex said it continues to assess whether patient, employee, credentialed provider, confidential business and financial information, or intellectual property was accessed or acquired.”
  • The American Hospital Association News adds,
    • “Epic’s MyChart has shared examples from potential phishing schemes observed as recently this month that include email messages linking to a fake MyChart website displaying erroneous medical records and others notifying of a free “2026 Medicare Health Kit.” MyChart provided recommendations for healthcare organizations and patients to help prevent or mitigate impacts from potential scams. The company announced last month that it has witnessed an uptick in scammers using the MyChart name or logo to create deceptive emails, text messages, phone calls and websites that appear official.” 
  • Cyberscoop points out,
    • “The Bureau of Alcohol, Tobacco, Firearms and Explosives insists the cyberattack that it publicly disclosed Wednesday [August 26] was limited to investigation targets, and has not impacted other agency systems.
    • “ATF said it is responding to the breach, which first became public after a prolific ransomware group claimed it accessed the federal agency’s network “The incident involved a standalone computer system containing information about targets of ATF investigations,” Tanya Roman, ATF’s public affairs chief, told CyberScoop in an email.
    • “The standalone system was not connected to any other ATF systems, including any case management systems, laboratory systems, or eForms systems, and it was quickly shut down when the breach was discovered,” Roman added. 
    • “Qilin, a financially-motivated threat group composed of Russian-speaking operators, claimed responsibility for the attack, but its involvement hasn’t been independently confirmed. The group has claimed hundreds of victims from more than 60 countries since 2022 and became one of the most active ransomware threats globally by mid-2025, according to Halcyon.” 
  • Bleeping Computer lets us know,
    • “Healthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, with the ShinyHunters extortion group claiming it stole 284 million patient data records.
    • “McKesson is a major U.S. healthcare company and pharmaceutical distributor that provides medicines, medical supplies, technology, and services to healthcare providers and pharmacies.
    • “CyberInsider first reported the breach earlier today, and McKesson later disclosed it in a Form 8-K filing with the U.S. Securities and Exchange Commission.
    • “McKesson says it discovered the cybersecurity incident on August 25, 2026, and that its investigation remains in the early stages.
    • “Information about the incident, including any updates, is available on the company’s website at www.mckesson.com/cybersecurity,” McKesson said in its SEC filing
  • Per a CISA news release,
    • “Most compromises do not rely on advanced techniques or cutting-edge tools. Cyber threat actors scan the internet looking for exposed, well-known software vulnerabilities to exploit. Basic security failures enable most compromises and organizations can reduce their risk by addressing these underlying weaknesses and prioritizing vulnerabilities for action based on the risk they pose.
    • “The CISA Vulnerability Review provides organizations with critical insights into the root causes of insecure software and practical steps they can take to address these flaws to prevent exploitation. Analyzing CISA and open source data from fiscal years 2024 and 2025, the review establishes a baseline of today’s vulnerability landscape before AI-enabled vulnerability discovery becomes more widespread. The review demonstrates the importance of Secure by Design principles in shifting cybersecurity efforts from reacting to threat actors to proactively fixing preventable software flaws.
    • “The review also identifies common software weaknesses that contribute to exploitable vulnerabilities and details practices software producers can use to prevent these weaknesses from recurring. By examining the patterns across vulnerability data, the review helps organizations focus on systemic improvements that can reduce entire classes of vulnerabilities rather than addressing individual vulnerabilities only after they are discovered.
    • “Additionally, the review shows organizations how to prioritize vulnerabilities for action using the framework outlined in Binding Operational Directive 26-04: Prioritizing Security Based on Risk. This framework evaluates vulnerabilities using four key criteria: exposure status, Known Exploited Vulnerability (KEV) Catalog status, potential for automated exploitation, and technical impact.”
  • Cybersecurity Dive adds,
    • “Two critical vulnerabilities in Microsoft SharePoint can be chained together to let an unauthenticated attacker execute code on a vulnerable server, according to a Monday blog post by researchers at VulnCheck.
    • “The sequence involves a critical authentication bypass vulnerability, tracked as CVE-2026-55040, and an improper input validation flaw, tracked as CVE-2026-63520. A proof of concept was previously disclosed on Aug. 11 by researchers at cybersecurity firm Rapid7. 
    • “Exploitation of CVE-2026-55040 was confirmed days after the Rapid7 disclosure. On Monday, VulnCheck researchers said the vulnerability on its own is not very impactful. To achieve maximum effect, they said, it needs to be chained with CVE-2026-63520. 
    • “The auth bypass is enough to prove some impact, but not enough to demonstrate the criticality of the full chain or build complete protections,” Vulncheck researchers said in their post.”
  • Per Infosecurity Magazine,
    • “Security researchers have claimed that over 9300 leaked AWS keys which surfaced between August 2022 and August 2026 are still active, including hundreds with full admin rights.
    • “Truffle Security said its scanners found 64,024 unique AWS key pairs across 431,875 public findings: git history, Hugging Face datasets, Docker images, package registries and CI logs.
    • “We took the 10,616 pairs with complete credentials and re-verified them, then enumerated what each key can tell us about its account: key age, attached policies, budgets, and last month’s spend,” the security vendor continued.
    • “No key material is published, and every owner we could identify is being notified.”
    • “Of the 10,616 pairs, 88% still authenticate. They include 768 corporate AWS keys which have full admin rights, Truffle Security said.”
  • Per Cyberscoop,
    • “Ubiquiti has patched 21 critical vulnerabilities, three of which were rated the highest severity possible, the communications product company said Wednesday [August 26] in a security bulletin.
    • In all, the company patched 22 vulnerabilities, with the last one rated “high,” it said in the bulletin.
    • Three of the vulnerabilities had a Common Vulnerability Scoring System rating of 10 out of 10. Each of them would allow a hacker to access privileges on the device or application.
    • All but one of the 22 vulnerabilities affect the UniFi line of products. The three maximum-security vulnerabilities are CVE-2026-77537CVE-2026-77550 and CVE-2026-77554.
  • Per Bleeping Computer,
    • “PaperCut is warning that hackers are actively exploiting a vulnerability in all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks.
    • “The company says it is aware of confirmed attacks on customers and is urging organizations with Internet-exposed PaperCut Application Servers to immediately restrict access to the web interfaces to trusted IP addresses.
    • “PaperCut Software security response team is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF,” reads an urgent security advisory published Thursday [August 27].
  • Per Dark Reading,
    • “A Chinese manufacturer has been planting backdoors inside of white-label routers sold in high volume around the globe.
    • “Shenzhen Zhibotong Electronics Co. Ltd. (ZBT) sells gobs of routers every year, if public evidence is to be believed. The 15-year-old company is the bestselling router manufacturer on Chinese e-commerce giant Alibaba.com, which lists its total annual output at 3.57 million units. Typically, those units are then sold to customers by companies other than ZBT, in countries like the Philippines, India, Canada, Australia, Germany, Bulgaria, Austria, Russia, and the US. According to its marketing, ZBT has exported its products to more than 50 countries and regions.
    • “On Aug. 6, Jacob Baines, chief technology officer (CTO) at VulnCheck, revealed that ZBT’s most updated router firmware contains a root-level backdoor. After a few more weeks of investigating, he discovered that, in fact, ZBT routers have contained a variety of backdoors dating several back years.”
  • and
    • “Fraudulent North Korean IT workers are getting better at infiltrating organizations, but a number of indicators can help organizations stay ahead.
    • “A new blog post from Huntress detailed a number of investigations the security firm conducted throughout 2026. Specifically, Huntress assisted several organizations this year in validating “suspicions that they’ve hired North Korean nationals posing as legitimate workers.”
    • In recent years, operatives from the Democratic People’s Republic of Korea (DPRK) have infamously posed as IT workers — generally through fake or stolen identities — to get hired at companies. Once hired, these employees send their wages back to the North Korean regime, and possibly plant malware or steal data depending on the government’s needs. Blog post authors Jai Minton and James Maclachlan wrote that these agents “have significantly improved and increased their activity over the past few years.”

From the ransomware front,

  • Reuters reports,
    • “A ransomware group ​said on Friday [Augut 28] it was putting up for auction a trove of ‌data it stole from Berlin [Germany] state agencies, and city officials refused to pay.
    • The Rhysida group, which researchers say operates from Russia or Eastern Europe, said on its website it took 5.79 ​terabytes of data including 46,500 contracts as well as emails, phone numbers, passwords ​and classified information.
    • “The group said it was auctioning the data ⁠at a starting price of 30 bitcoin ($77,622) in just under seven days, showing a ​countdown timer on its website.” * * *
    • Broadcaster RBB reported on Thursday evening that Berlin had received ransom demands for an unspecified amount following the attack.
    • “The state ​of Berlin will not submit to extortion,” Berlin Mayor Kai Wegner and Berlin’s interior senator, ​Iris Spranger, said in a joint statement on Friday, before the ransomware group claimed the attack ‌on ⁠their website.”
  • Technology.org relates,
    • An affiliate of the new Aur0ra ransomware group used Cursor, the AI coding assistant now owned by SpaceX, to draft attack sequences in Russian across 28 recovered chat sessions dated 8 April to 21 May.
    • Named victims include Ghent-based hygiene and cleaning products maker Christeyns, German garage door manufacturer Teckentrup, Scotland’s Helideck Certification Agency and Louisiana title insurer Bayou Title.
    • Researchers counted more than 20 targeted organisations across nine countries, with domain-level or interactive access achieved at 17 of them between April and July 2026.
  • Safe State tells us,
    • “A ransomware affiliate has been posing as a specialist rescue outfit and contacting victims before their attacks became public. Researchers describe the operation as a ransomware recovery scam that drains payments away from the criminal groups the affiliate works for. The entity calls itself Ransom Busters LTD.” * * *
    • “Anyone targeted by a ransomware recovery scam meets it at the worst possible moment, with systems down and pressure building. Treat unexpected contact as part of the attack. Route the message to the incident response team straight away and preserve it as evidence instead of replying. A sender who knows about a breach nobody has announced is either involved in it or holds the data taken during it.
    • “Law enforcement and established response firms remain the reliable route through a ransomware incident. Verify anyone claiming to represent a security company through channels you found yourself. Never use the contact details supplied in the email. Treat any guarantee of data deletion as unenforceable, because no payment to a criminal party comes with proof that copies no longer exist.
    • “Distrust inside ransomware-as-a-service operations may produce more of this behaviour. Affiliates have every reason to look for income outside the revenue splits their employers set. So the ransomware recovery scam running under the Ransom Busters name reads less like an isolated curiosity and more like a preview. Anyone willing to defraud the criminal enterprise paying them has already answered the question of what a victim’s data is worth to them.”
  • SC Media informs us,
    • “Organizations may assume they are unlikely ransomware targets because they are not large, high-profile, or strategically important. But ransomware attackers are often motivated by economics, not prestige. That means organizations that consider themselves low-risk may be more attractive targets than they realize.
    • “The ransomware affiliate model rewards attackers for finding victims that are likely to pay, not necessarily those that are difficult or impressive to compromise. This can make mid-sized organizations and businesses that depend heavily on critical systems especially attractive targets.
    • “For security teams, this changes how ransomware risk should be assessed. Company size, industry, and public profile tell only part of the story. Attackers may care more about whether an organization can pay, how costly downtime would be, and how quickly it needs to restore operations.
    • “The key question is not how important your organization looks to an attacker, but how valuable a ransomware payment could be.”
  • Dark Reading adds,
    • “A sophisticated malware family has emerged onto the cyberthreat scene that might foreshadow ransomware attacks that are more successful than usual.
    • “Marcus Hutchins and his colleagues at Expel that discovered it named the malware “SynkLoader,” since it throws so many ideas (“everything but the kitchen sink”) at trying to sneakily dig into corporate systems. It uses some conventional strategies — like executing code in-memory, running a scheduled task, etc. — but layers on a few interesting, novel tactics that make social engineering particularly compelling, and malware analysis especially frustrating.
    • “The program is new, and how its creators intend to use it remains a mystery. But evidence in the code suggests that it might be the baby of a ransomware group or initial access broker (IAB), used to set the stage for follow-on ransomware.”

From the cybersecurity business and defenses front,

    • PYMNTS reports,
      • Visa expanded the capabilities of its artificial intelligence-powered cyber risk management tool, Visa Vulnerability Agentic Harness (VVAH), to include not only discovery of vulnerabilities but also remediation and validation, the company said in a Thursday (Aug. 27) press release.
      • “Visa initially released VVAH in June after participating in Anthropic’s frontier AI cybersecurity initiative, Project Glasswing. While the first release of VVAH showed how AI can help security teams uncover vulnerabilities and assess exploitability, the latest release extends the workflow into remediation and validation of those vulnerabilities, according to the release.
      • “Visa also announced in the release that to help clients navigate the evolving threat landscape driven by AI, it has expanded its Visa Consulting and Analytics (VCA) Cybersecurity Advisory Practice to include new advisory services focused on assessing risk, prioritizing remediation efforts and strengthening resilience.
      • “The new advisory services include AI Cyber Leadership Education, VVAH-Informed Cybersecurity Maturity Assessment and VVAH Cyber Risk Prioritization and Roadmap, per the release.”
    • Cybersecurity Dive tells us,
      • “Operational silos, technological sprawl and cloud-platform blind spots are serious issues preventing organizations from spotting and repelling cyberattacks, the Cybersecurity and Infrastructure Security Agency (CISA) warned in a new report.
      • “Those were three of the main factors that allowed CISA’s red team to break into the networks of two unnamed partner organizations — one a government agency, the other a water utility — during recent simulated attacks. But although the red team was successful in both intrusions, it had a much harder time with one attack than with the other, a fact that CISA attributed to important differences in the targets’ operating procedures and use of technology.”
    • Security Week informs us,
      • “Palo Alto Networks’ Unit 42 team analyzed 405 malware samples tied to AI in some way, from ransomware partly written with the help of LLMs to installers that simply borrowed the name of a popular AI app.
      • “The researchers found that roughly 97% of the samples in the dataset never left a sandbox, research repository, or internal testing environment to reach a real target.
      • “Unit 42 cross-referenced the 405 file hashes against endpoint telemetry, network sessions forwarded for sandbox analysis, and internal alert records generated whenever a sample actually ran. Only 12 hashes surfaced on live endpoints, while a somewhat larger group (15-20 hashes) appeared in network sandbox traffic. Every one of the 12 samples detected on protected endpoints triggered a security alert.
      • “The samples that never reached production fall into three groups. The largest is proof-of-concept code built to demonstrate a technique: configured to target only local or private networks, filled with debug output no real attacker would leave behind, and uploaded once by a research lab or university. 
      • “A second group comes from organizations testing their own defenses against previously reported AI malware, identifiable by repeated uploads of the same file from the same source in a short window. A third group uses AI branding purely as bait, dressing up an ordinary payload as installers for well-known AI products with no actual AI functionality behind them.
      • “The 12 samples that did reach live endpoints spanned five malware families across three countries, with no concentration in any particular industry or region.” 
    • Beckers Health IT points out,
      • “Healthcare’s cybersecurity workforce problem may have less to do with finding more candidates and more to do with changing who health systems are willing to hire, how they develop them and what they do to keep them.
      • “Cybersecurity leaders at four health systems told Becker’s that continually competing for the same pool of experienced professionals is not a sustainable strategy as cyber risks expand and the skills needed to manage them become more complex.
      • “The cybersecurity workforce challenge has shifted from a talent shortage to a talent entry problem,” Trevor Martin, vice president, chief information security officer and interim chief technology officer at Madison, Wis.-based UW Health, said.
      • “Mr. Martin said there are many high-potential people trying to enter cybersecurity, but organizations frequently prioritize candidates who already have experience instead of creating pathways for people to gain it.
      • “Healthcare could benefit from hiring more heavily for aptitude, adaptability and an understanding of business and clinical operations, then developing those employees internally, he said. UW Health has found success moving talent from adjacent IT disciplines into cybersecurity roles and providing opportunities for employees to grow within the field.”
    • Dark Reading notes,
      • “As the “vulnpocalypse” reshapes the bug bounty industry, one class of researcher may face the greatest pressure: independent hunters who rely on midtier vulnerabilities — those worth roughly $10,000 to $50,000 — to make a living.
      • “It is no secret that large language models (LLMs) have led to a mass of bug reports and an increase in vulnerability discovery. It is also no secret that the platforms and companies that run much of the bug bounty industry have faced increased triage and payout times.
      • “Multiple bug bounty operators interviewed by Dark Reading report dramatic increases in submission volume over the past year. HackerOne CEO Kara Sprague says report volume has roughly doubled year over year. Dustin Childs, head of threat awareness for TrendAI’s Zero Day Initiative (ZDI), says the company’s submission rate went up 450% year-over-year in April of this year, although volumes have moderated since that peak. Bugcrowd CEO Dave Gerry said the firm saw a submissions spike of more than 300% during a three-week surge period, but “now it’s normalized where we’re about double the volume we saw historically.”
    • Per a National Institute of Standards and Technology news release,
      • “The final version of NIST Special Publication (SP) 1347, Cybersecurity Framework (CSF) 2.0 Informative References Quick-Start Guidehas published. Thank you to all who provided comments during the public comment period.  
      • “This publication explains what informative references are and how they support achieving the outcomes of the CSF 2.0. The guide introduces readers to NIST tools available for accessing, viewing, and using informative references for cybersecurity risk management, including direct download, the CSF 2.0 Reference Tool, and the Online Informative References Program. The document also provides two sample use cases along with examples of how artificial intelligence (AI) tools can support reference data use when implemented with continuous evaluation and improvement.” 
    • Here’s a link to Dark Reading’s CISO Corner.