Thursday report

Thursday report

Simplicity is a virtue.

From Washington, DC,

  • The American Hospital Association News reports,
    • “The departments of Health and Human Services, Labor and the Treasury [and the Office of Personnel Management] issued a final rule May 28 intended to improve the functioning of the No Surprises Act (NSA) independent dispute resolution process. The rule streamlines communication between payers, providers and certified IDR entities and clarifies timelines and processes. It improves the functionality of the IDR process by finalizing various changes, including allowing up to 50 items and services to be batched in the same payment dispute. The final rule also increases access to the IDR process by reducing the administrative fees associated with it. The AHA supported many of these changes in comments on the proposed rule.”
  • The rule decreases the federal government fee for handling an NSA arbitration from $115 per party to $15 per party. The FEHBlog expects the arbitrators’ fees to increase accordingly over time. No good deed, etc.
  • The FEHBlog also expected the final rule to include an administrative remedy that would allow providers and payers to enforce or challenge arbitration awards.
  • The FEHBlog agrees with AHIP’s comments on the final rule.
    • “While the focus on addressing flawed incentives in the IDR process is a significant first step, more action is needed to protect Americans from unconscionable price gouging by some PE-backed providers and IDR middlemen.” – Chris Bond, AHIP spokesman”
  • Tammy Flanagan, writing in Govexec, discusses “[w]hat retiring feds should do before asking for help.
    • “Clear timelines, complete records and focused questions can make retirement problems easier to resolve, especially as agencies face mounting workloads.”
  • Federal News Network tells us,
    • “The Postal Service is putting immediate restrictions on nonessential spending to avoid running out of cash sooner than expected.
    • “Postmaster General David Steiner wrote in a memo Tuesday that the restrictions will impact hiring, travel and training as well as other areas of spending. Departments within USPS may be asked to provide a summary of “cost-containment actions taken and expected savings.”
    • “Steiner told members of the House Oversight Committee in March that USPS will run out of cash in early 2027, as long as it continues to pay its bills on time. But USPS is relying on some emergency measures to conserve cash.
    • “As you are aware, we are currently experiencing a temporary cash-flow shortage that requires us to take decisive steps to manage our available resources responsibly,” Steiner wrote in the memo. “To protect core operations and ensure that we can continue meeting all essential obligations, we are implementing immediate restrictions on non-essential spending across all departments.”

From the Food and Drug Administration front,

  • MedPage Today reports,
    • “The FDA’s vaccine advisors voted 8 to 0, with one abstention, in favor of a monovalent XFG vaccine for COVID-19 shots for the 2026-2027 season.
    • “The Vaccines and Related Biological Products Advisory Committee (VRBPAC) also discussed the need to target the long-simmering BA.3.2 variant, also known as “cicada,” though most expressed confidence that targeting XFG was the right way to go.
    • “The XFG variant is the most common variant in the U.S. right now, and looking at the other JN.1 variants that may be coming up, I still think that the BA.3.2 variant is not as common. I think we have to keep surveillance very vigilant though,” said Anna Durbin, MD, of Johns Hopkins Bloomberg School of Public Health in Baltimore, adding that the “immunogenicity of the vaccines looks good, so I was very comfortable voting yes.”
  • Fierce Pharma relates,
    • “AstraZeneca has fired another volley in its bladder cancer competition with Merck’s Keytruda, with the FDA on Thursday clearing its PD-L1 inhibitor Imfinzi as part of the first immunotherapy combo regimen in patients with high-risk non-muscle-invasive bladder cancer (NMIBC) who haven’t previously received standard of care Bacillus Calmette-Guérin (BCG) treatment. 
    • “The green light clears Imfinzi in the indication alongside BCG induction and maintenance therapy, AZ said in a May 28 release. 
    • “This marks the second recent bladder cancer nod for Imfinzi, which was approved in March of last year in muscle invasive bladder cancer (MIBC), in that instance in combination with the chemotherapies gemcitabine and cisplatin ahead of bladder-removing surgery and then on its own following the procedure.”
  • and
    • “As AbbVie continues to capitalize on its ImmunoGen deal, the growth of commercial antibody-drug conjugate (ADC) Elahere, another of the acquired company’s clinical assets has crossed the FDA finish line. 
    • “The FDA on Wednesday announced the approval of AbbVie’s CD123-direct ADC pivekimab sunirine-pvzy, which will hit the market under the Decnupaz moniker, as a treatment for adults with the rare blood cancer blastic plasmacytoid dendritic cell neoplasm (BPDCN). 
    • “The condition is a rare and aggressive cancer of the bone marrow and blood that can also affect organs like the lymph nodes, spleen and skin. Most patients with BPDCN present with purple-colored skin lesions and the malignancy is often diagnosed in more men than women, with most patients aged 60 years and older.” 
  • Health Exec tells us,
    • “The U.S. Food and Drug Administration (FDA) said it’s aware of an issue with IV tubes, where black matter has been found within the walls of the plastic walls, signaling a contamination issue.
    • “ICU Medical said samples containing the particulates are being returned for analysis to help identify the problem. Until then, the devices are being removed from use and distribution.
    • “Typically sterile, these tubes are used to connect medication and fluid bags to patients, as administered through an IV line.
    • “ICU Medical and the FDA said in an announcement this could be a potentially high-risk issue, though there was no mention of patient injuries. The FDA described the notice as an early alert regarding a potential safety issue.”

From the judicial front,

  • Modern Healthcare reports,
    • “Clover Health won a lawsuit [in the U.S. District Court for the Southern District of Georgia] challenging its 2026 Medicare Advantage star ratings.
    • “A federal court ruled that 20 quality measures the Centers for Medicare and Medicaid Services used are improper.
    • “The decision could have industrywide implications because CMS rated all Medicare Advantage insurers on those metrics. 
    • “CMS filed a motion to reconsider the ruling.

From the public health and medical / Rx research front,

  • The American Hospital Association News reports,
    • “The Centers for Disease Control and Prevention today released a report highlighting data on patients hospitalized during a 2025 measles outbreak centered in West Texas. There were 762 confirmed cases during the outbreak, which lasted from late January through mid-August 2025. The report found that of the 60 hospitalized patients, nearly 91% were children and adolescents under age 18 and nearly 56% were age 4 or younger. Additionally, 4 out of 5 hospitalized adults age 18-44 were pregnant women in their third trimester. Available medical records of 54 patients were reviewed. All 54 were found to be unvaccinated or had an unknown vaccination status.”
  • Healio relates,
    • “Measures of ideal heart health including healthy levels of physical activity, BMI, BP and sleep were associated with lower risk for severe COVID-19 among people with no history of heart disease during the pandemic, researchers reported.
    • “For every 1 standard deviation increase in total American Heart Association’s Life’s Essential 8 score, individuals without prior CVD experienced an approximately 20% reduced risk for severe COVID-19 infection, according to data published in the Journal of the American Heart Association.”
  • Health Day adds,
    • “Being incredibly fit shouldn’t increase a young adult’s risk of dangerous irregular heart rhythm, a new study says.
    • “Young male athletes and fitness buffs aren’t more likely to develop atrial fibrillation, despite earlier studies that showed an apparent link, researchers reported May 21 in the journal Circulation.
    • “Our study shows that there are good reasons to nuance and tone down the message, which has been widespread at times, that high levels of fitness or participating in races would pose a big risk to a person’s cardiovascular health,” said lead investigator Marcel Ballin, an associated researcher at Uppsala University in Sweden.
    • “The risk of atrial fibrillation is certainly not zero, but that said, the benefits are significantly greater,” he said in a news release.”
  • and
    • “Adopting low-insulinemic and planetary health diets during menopause is associated with optimized weight management, according to a study published online May 20 in JAMA Network Open.
    • “Tong Xia, M.D., Ph.D., from Brigham and Women’s Hospital in Boston, and colleagues compared dietary patterns and their associations with weight gain and obesity risk in the years surrounding menopause. The analysis included 38,283 women participating in the Nurses’ Health Study II, with 12-year observations surrounding menopause.
    • “The researchers found that after adjusting for age, race and ethnicity, marital status, income, postmenopausal hormone therapy use, parity, smoking, alcohol, energy intake, physical activity, and baseline body mass index, the reverse empirical dietary index for hyperinsulinemia (EDIH; quintile 5 versus 1) was associated with the largest reduction in weight gain (mean, −0.28 kg/year). The lowest risk for incident obesity was seen with the Planetary Health Diet Index (PHDI; hazard ratio, 0.46) and reverse EDIH (hazard ratio, 0.51). The largest positive correlations in the EDIH were seen with red or processed meats, sodium, and French fries, while for the PHDI, the largest positive correlations were seen with nuts, unsaturated fats, whole-grain carbohydrates, and vegetable protein.” 
  • The Washington Post informs us,
    • Ozempic was supposed to be a gut story. Then Allison Shapiro looked at the brain scans.
    • An assistant professor at the University of Colorado Anschutz, she was part of a team studying 13 teens and young women with a hormonal disorder affecting the ovaries who were put on GLP-1 drugs. As part of testing to catalogue the effect of the medication on their bodies, Shapiro took snapshots of their brains before and after.
    • She was astonished to find extensive changes.
    • Within only a few months, the brain connections in the salience network, which helps target attention, had multiplied.
    • “We didn’t expect to see this effect, and we really don’t know what it means,” Shapiro said.”

  • BioPharma Dive tells us,
    • “An RNA-based shot developed by GSK and Ionis Pharmaceuticals helped wipe out hepatitis B in about a fifth of the patients who received it in a pair of clinical trials, according to study results published Thursday in the New England Journal of Medicine.
    • “Called bepirovirsen, the shot could represent an important advance for people with chronic hepatitis B infections, less than 1% of whom can achieve such a “functional cure” with the help of oral antivirals. None of the participants who received a placebo hit that mark in the two trials presented Thursday.
    • ‘The Food and Drug Administration is already reviewing an approval application for bepirovirsen, and has granted the drug “fast track” and “breakthrough therapy” designations that could speed up its evaluation. An approval decision is expected no later than Oct. 26.”
  • Genetic Engineering and BioTechnology News points out,
    • “Biohub, the non-profit research organization co-founded by Priscilla Chan, MD, and Mark Zuckerberg, has now unveiled the latest update to the ESM protein language model family, with expanded capabilities in binder design and protein function mapping for therapeutic discovery. The release comes just seven months after Biohub recruited the team behind EvolutionaryScale. 
    • “The system includes ESMC (Evolutionary Scale Modeling Cambrian), a language model trained on approximately 2.8 billion sequences drawn from a breadth of life, including organisms adapted to extreme environments, and more than 20,000 types of proteins found in the human body. Evolutionary information encoded in ESMC is translated into atomic-resolution protein structures and interactions using the design engine and prediction model, ESMFold2. 
    • “Alex Rives, PhD, head of science at Biohub and former chief scientist at EvolutionaryScale, presented the work at this week’s “AI in Biology” symposium at Cold Spring Harbor Laboratory.  
    • “These models aim to transform the earliest stages of drug discovery by making biology more programmable. While traditional discovery workflows rely on slow and resource intensive experimental screens to identify promising drug candidates, rational protein design guided by in silico predictions has the potential to dramatically accelerate development timelines. 
    • “We’re at an exciting point in protein biology where accurate digital representations allow asking experimental questions at a scale that wouldn’t be possible in the laboratory,” Rives told GEN Edge.”  

From the U.S. healthcare business front,

  • Modern Healthcare reports,
    • “Highmark Health recovered in the first quarter after reporting losses last year, the health system and insurer announced Thursday.
    • “The Pittsburgh-based nonprofit company reported a 1,308% jump in first-quarter net income to $183 million and a 1,340% improvement in operating income to $216 million. Revenues grew 3.8% to $8.3 billion. Highmark Health lost $175 million in 2025.
    • “Highmark Health Plans’ strategic adjustments in Medicare and Medicaid drove the rebound, Highmark Health Chief Financial Officer and Treasurer Carl Daley said.” 
  • Fierce Pharma relates
    • “The top pharmacy benefit manager (PBM) in the U.S., CVS Caremark, will restore coverage to obesity products from Eli Lilly, allowing a significant number of patients to gain access to the drugs through their existing insurance.
    • “CVS will begin covering Lilly’s GLP-1 pill Foundayo on Monday of next week, June 1, while coverage of Lilly’s injected treatment Zepbound begins on October 1. CVS Caremark, which is the pharmacy chain’s drug benefits unit, is the largest PBM in the country.”
  • and 
    • “CVS Health is growing its partnership with Salesforce, leveraging its agentic AI-driven Agentforce Health to boost personalization in its call centers.
    • “The companies announced on Thursday morning that the platform will connect data across CVS, including Aetna and Caremark, to make it easier for call center teams to address a member’s unique needs in a single interaction when possible.
    • “The Agentforce tool will surface critical insights to call center teams in advance, preparing them more effectively for conversations. The goal, the partners said, is to improve the experience for both the member and the workers through a more streamlined interaction.”
  • OptumRx, writing in Linked In, discusses the four drug classes that drive spending.
    • Inflamatory conditions drugs,
    • Oncology drugs,
    • Diabetes drugs, and
    • Obestty Drugs.
  • Beckers Payer Issues points out,
    • “CVS Health’s insurance branch will roll out “Aetna Mental Health On Demand” in 2027, the company said in a May 28 news release.
    • “Aetna members who are at least 13 years old will be able to access licensed clinicians via chat, phone or video. These professionals are trained on a “single-session intervention model” to drive immediate impact, such as through crisis management. Clinicians can provide a personalized plan, advocate for members, connect them with more resources and help with follow-ups and further care coordination.
    • “The platform also contains integrated AI tools for note-taking and administrative tasks. Clinicians participated in hundreds of chats and were able to respond to members within 13 seconds, the news release said about an initial rollout.” 
  • Healthcare Dive tells us,
    • “Teladoc Health said Thursday it is partnering with Walmart to add its virtual care services to the retail giant’s digital healthcare platform.
    • “With the partnership, Teladoc’s virtual care offerings — including urgent care, dermatology and nutrition support — are now available through Walmart’s Better Care Services platform, which connects customers to third-party digital health providers. 
    • “The deal should put Teladoc’s services in front of more potential patients, Kelly Bliss, president of the company’s U.S. group health business, told Healthcare Dive. “We have the largest nationwide network of virtual care providers in the country, and so we want to activate that network and our clinical services wherever people are making health decisions,” she said.”
  •  and
    • “Amazon’s healthcare leader is stepping down from this summer, and the co-founder of telehealth company Amwell will replace him, the retail and technology giant said Wednesday. 
    • “Neil Lindsay, who became senior vice president of Amazon Health Services in 2021, is leaving to pursue personal projects, he said in a message to Amazon employees.
    • “Dr. Roy Schoenberg, the former co-CEO of Amwell who helped found the telehealth provider two decades ago, will start as new head of Amazon’s health business on July 1. Lindsay will stay on as an advisor to Schoenberg through the end of the year.”
  • Per MedTech Dive.
    • “Ōura plans to roll out a swath of health and wellness features in June, following the launch of its latest smart ring.
    • “Among the new additions will be a tool to track nighttime blood pressure patterns and the ability to view nighttime breathing data over a 30-day period. Ōura announced the features, along with its Ōura Ring 5, on Thursday.
    • “Jason Russell, vice president of consumer software product at Ōura, told MedTech Dive that the blood pressure feature is intended to show trends in overnight changes and the relationship to daily habits, such as sleep, stress and exercise. 
    • “Ōura plans to offer blood pressure signals as a wellness feature, meaning it would not be regulated as a medical device, but there are some limitations on what it can tell users.”  

Cybersecurity Saturday

From the War with Iran front,

  • Cybersecurity Dive reports yesterday,
    • “Iranian government-backed hackers are using spear-phishing attacks and remote access Trojans (RATs) to spy on “high-value sectors” in the U.S. and the Middle East as part of Tehran’s response to the U.S.-Israeli war, according to Palo Alto Networks.
    • “The company’s Unit 42 researchers recently discovered six new RATs that an Iran-linked group the researchers call Screening Serpens has used for espionage purposes. The group “has increased its operations” since the war began, the researchers said, and malware metadata suggests that it has attacked “targets across the U.S., Israel and the [United Arab Emirates] as well as two additional Middle Eastern entities.”
    • “Screening Serpens — which other researchers call UNC1549Smoke Sandstorm and Nimbus Manticore — has “consistently set its sights on high-value sectors,” Palo Alto Networks said, especially in the aerospace, defense and telecommunications industries.
    • “A defining characteristic of these recent campaigns is the deep personalization of the attackers’ lures,” researchers wrote. “By leveraging tailored social engineering tactics, including fake job requisitions and spoofed video conferencing meeting invitations, the attackers lure victims into initiating the infection chain, thereby exposing their organizations to further exploitation.”
  • Industrial Cyber adds,
    • “Ransomware groups are increasingly being used as proxy weapons in geopolitical cyber warfare, enabling nation-states to exert pressure on their adversaries while maintaining plausible deniability. What used to be financially motivated cybercrime and targeting can now influence operations and cause operational disruption. While the change has been incremental, it has been unmistakable. Criminal groups, ideological hacktivists, and state-aligned adversaries are converging and sharing environments, infrastructure, tactics, techniques, and procedures (TTPs), access brokers, and, at times, even strategic objectives.
    • “Operations linked to Iran demonstrate the sprawl between cybercrime, espionage and industrial sabotage as ever closer. A recent investigation exposed claims by pro-Iran hackers that they altered on-the-ground conditions to target critical wheat reserves, demonstrating how cyber activity can directly affect food security and industry. Once the contact is made, these adversaries can choose how and when to attack.”

From the Project Glasswing front,

  • Anthropic offers a look back at the project’s first month.
  • The Wall Street Journal adds,
    • “Anthropic is letting Mythos users [participating in Project Glasswing] share cybersecurity threats with others who may face similar vulnerabilities.
    • “Anthropic modified its previous stance amid concerns that limiting access to the information could hurt smaller companies.
    • “The new policy highlights challenges facing artificial-intelligence companies that are restricting access to their best models.’

From the cybersecurity policy and law enforcement front,

  • Cyberscoop reports,
    • “Two cybersecurity-focused members of Congress agreed Thursday [May 21, 2026] that reductions to the Cybersecurity and Infrastructure Security Agency have done too much damage to an agency essential to defending civilian networks against foreign adversaries.
    • “Rep. Don Bacon, R-Neb., and Rep. James Walkinshaw, D-Va., spoke during a panel at the National Cyber Innovation Forum. Despite representing different parties, and serving on different congressional committees, the two lawmakers offered closely aligned assessments of CISA’s role and the consequences of recent cuts.” * * *
    • “In the model both lawmakers endorsed, they pushed for CISA to play more of a role after an intrusion, helping affected entities restore their networks while the FBI works to identify the source. Walkinshaw said advanced artificial intelligence expands the attack surface and makes that kind of centralized support more important.”
  • The Wall Street Journal relates,
    • “State cybersecurity officials urged the federal government on Thursday to roll back cuts to cybersecurity programs, arguing that deteriorating federal support weakens defenses just as artificial intelligence and nation-state belligerence are introducing significant new threats.
    • “Technology and cyber officials from New York, Florida and Tennessee told a House Homeland Security Committee hearing that states must now defend against advanced threats as federal backing diminishes.
    • “The witnesses cited the pending expiration of the State and Local Cybersecurity Grant Program, significant budget and workforce cuts to federal agencies and new limits on the information-sharing platforms that state governments rely on to track threats.”
  • Cyberscoop adds,
    • “Securing some of the open-source technology that serves as the backbone for all modern digital infrastructure is going to require some “hard decisions” amid a wave of malware attacks, the leader of the Cybersecurity and Infrastructure Security Agency said Thursday [May 21, 2026].
    • “The open-source community is one that I’m particularly worried about when we start to think about rapid escalation of vulnerability discovery,” acting director Nick Andersen said, referencing a cartoon about how key technologies that underpin the internet are often maintained by a single person.” * * *
    • “CISA has been working with industry and others “to modify our approach to vulnerability management, modify our approach to coordinated vulnerability disclosure, modify our approach to remediation, with the explicit understanding that we’re just not going to be able to keep up using traditional mechanisms,” Andersen said, speaking at the National Cyber Innovation Forum in Washington, D.C.
    • “The government and private sector can work together to identify the biggest threats and then give them the right level of attention, he said. On the federal government side, that means working to get a full picture of the extent of reliance on open-source technologies.” 
  • and
    • “President Donald Trump said he would postpone the release of an executive order that would set up a 90-day testing and vetting regime for frontier AI models, hours before the White House was set to publicly announce the signing. 
    • “Speaking to reporters in the Oval Office Thursday [May 21, 2026], Trump said he opted to delay the order “because I didn’t like certain aspects of it” and expressed concerns that it could harm U.S. AI industry competition with countries like China. 
  • Cyberscoop tells us,
    • “Authorities arrested and unsealed charges against a Canadian man accused of running Kimwolf, one of the most far-reaching DDoS botnets on record, the Justice Department said Thursday.
    • “Jacob Butler was arrested Wednesday [May 20, 2026] in Ottawa, Canada, and awaits extradition to the United States where he is charged with aiding and abetting computer intrusions and, if convicted, faces up to 10 years in prison.
    • “Investigators said the 23-year-old, also known as “Dort,” was a principal administrator of Kimwolf, a variant of the record-setting Aisuru DDoS botnet that spread like wildfire and eventually took over more than 2 million Android TV devices after its operators figured out how to abuse residential-proxy networks for local control.”
  • and
    • “European authorities took down a prominent virtual private network service and arrested the alleged administrator behind an operation that cybercriminals used to steal data, commit fraud and ransomware attacks, Europol said Thursday [May 21, 2026]. 
    • “First VPN, which was promoted on Russian-speaking cybercrime forums, gained popularity for providing services that allowed users to hide their infrastructure and identities. Officials said the service was entrenched in the cybercrime world and appeared in almost every major recent cybercrime investigation aided by Europol.
    • “For years, cybercriminals saw this VPN service as a gateway to anonymity,” Edvardas Šileris, head of Europol’s European Cybercrime Centre, said in a statement. 
    • “They believed it would keep them beyond the reach of law enforcement,” Šileris added. “This operation proves them wrong. Taking it offline removes a critical layer of protection that criminals depended on to operate, communicate and evade law enforcement.”
  • Security Week adds,
    • “Authorities in North America and Europe have participated in a law enforcement operation to disrupt First VPN, a popular cybercrime service used for ransomware and other attacks.
    • “According to the FBI, First VPN has been active since 2014, providing 32 exit nodes across 27 countries at the time of its disruption. The service, advertised on Russian-language dark web cybercrime forums, has been used by at least 25 ransomware groups for network reconnaissance and intrusions.”
    • “Bitdefender, which was involved in the takedown, pointed out that the 506 users are a subset of First VPN’s customer base, and investigators will determine which of them can be linked to criminal operations. 
    • “Some will be traced to known ransomware groups. Others will reveal fraud operations, data theft campaigns, or cybercrime-as-a-service infrastructure we didn’t know existed,” Bitdefender said.
    • “New anonymization services will appear. The economic demand hasn’t changed. But each takedown shortens the operational window of the next service and raises the barrier for actors who relied on turnkey solutions,” the cybersecurity firm added. “First VPN advertised itself as a service criminals could trust to keep them beyond law enforcement’s reach. The operation proved that claim wrong, and every actor evaluating the next anonymization service now knows the same risk exists.”

From the cybersecurity breaches and vulnerabilities front,

  • Health Exec reports,
    • “The largest public health system in the U.S. confirmed in a filing with the Department of Health and Human Services that a data breach on its network impacted 1.8 million patients, exposing their personal data to hackers.
    • “The data breach, which was said to have lasted for months, was revealed by NYC Health + Hospitals in March. At the time, the health system said it first discovered “suspicious activity” on its network in February, at which time it moved to “immediately” secure its systems from access by the unauthorized third-party.
    • “An investigation found cybercriminals had been inside its IT infrastructure since November 2025, stemming from a breach on an unnamed vendor the organization contracts with for services.”
  • Dark Reading relates,
    • “Defenders are dealing with an influx of vulnerabilities like never before, and patch prioritization has never been more critical, according to Verizon Business’s 2026 Data Breach Investigations Report (DBIR). This year’s report confirmed several ongoing trends on the vulnerability exploitation and around threat actors abusing AI, for example — but the 2026 DBIR more broadly promotes sticking to the cybersecurity fundamentals as the industry undergoes massive change.
    • “And indeed, defenders in the past year have been tasked with handling everything from self-replicating worms infesting software components to preparing for large language models (LLMs) that can supposedly discover critical zero-day vulnerabilities all on their own.
    • “Most striking in the DBIR might be the statistics that show vulnerability exploitation to be the most common initial access vector for breaches last year, up 31% from the previous year. Meanwhile, only 26% of critical vulnerabilities (defined as those in CISA’s Known Exploited Vulnerability catalog) were fully remediated by organizations in 2025, compared to 38% the previous year. Just over half (58%) were partially remediated last year, and 16% remained unaddressed.” * * *
    • “While organizations perhaps got worse at patching, Verizon also observed a dramatic increase in the number of vulnerability detections observed year over year, likely driven by AI-assisted bug hunting. “There were 68.7 million records in the 2022 dataset and 527.3 million in 2025 — almost eight times the volume,” the DBIR reads.”
  • The HIPAA Journal tells us,
    • “Verizon has published its 2026 Data Breach Investigations Report, which shows that the healthcare sector continues to be targeted by cybercriminal groups. The sector is having to contend with sustained multi-vector attacks, including ransomware, unpatched vulnerabilities, and human error. Regardless of the cause, the attacks are putting patient privacy, safety, and care at risk.
    • “Verizon tracked 1,492 healthcare incidents for its 2026 report, including 1,438 confirmed data disclosures, a majority of which were due to ransomware-driven system intrusions achieved through multiple attack vectors, including the exploitation of vulnerabilities (20%), phishing attacks (14%), stolen credentials (11%), and employee errors (11%). Threat actors are being given far too big a window of opportunity to exploit known vulnerabilities. Verizon found that in 2025, only 26% of critical vulnerabilities were fully remediated, with a median time for resolution stretching to 43 days. In healthcare, where complex legacy systems are the norm, the window of opportunity is greater, giving threat actors a wide attack window.
    • “While external actors accounted for the majority of incidents, insider breaches remain common in healthcare. Internal actors were behind 19% of breaches. As Verizon notes, human error continues to be a chronic source of breaches. The human element was involved in 54% of incidents, including misconfigurations, misdirected communications, the loss/theft of unencrypted devices, and poor cyber hygiene.
    • “The most common human-related cause of healthcare data incidents was misdelivery, which accounted for around 40% of incidents, followed by loss incidents at around 25%, and misconfigurations at around 20%. While greater investment in cybersecurity will help to address the 81% of breaches due to external actors, security awareness training plays an important part in preventing data breaches. Employees need to be made aware of security fundamentals and be taught the importance of practicing good cyber hygiene. Social engineering was the third main cause of healthcare breaches in 2025, the majority of which were due to phishing, followed by pretexting – these attack techniques need to be covered in depth in training courses.”
  • CISA added ten known exploited vulnerabilities (KVEs) to its catalog this week.
  • Cybersecurity Dive adds,
    • “The Cybersecurity and Infrastructure Security Agency is now letting security experts nominate vulnerabilities to the agency’s Known Exploited Vulnerabilities catalog.
    • “CISA on Thursday [May 21, 2026] published a form that technology vendors, independent researchers and anyone else can use to warn CISA that hackers are exploiting a vulnerability and it should be added to the KEV.
    • “This new reporting capability enhances CISA’s ability to identify, validate, and quickly share critical threat information,” Chris Butera, CISA’s acting executive assistant director for cybersecurity, said in a statement. “Early detection and coordinated vulnerability disclosure are among the most powerful tools we have to reduce risk at scale.”\
  • and
    • “Hackers stole data from thousands of GitHub repositories, the code-hosting giant said on Tuesday [May 19, 2026].
    • “While we currently have no evidence of impact to customer information stored outside of GitHub’s internal repositories (such as our customers’ enterprises, organizations, and repositories), we are closely monitoring our infrastructure for follow-on activity,” the company said in a post on X.
    • “On Wednesday [May 20, 2026], the company confirmed that attackers had compromised roughly 3,800 repositories after a GitHub employee used a malware-infected Visual Studio Code extension.
    • “We continue to analyze logs, validate secret rotation, and monitor for any follow-on activity,” GitHub said.”
  • Cyberscoop informs us,
    • “The FBI is warning organizations and defenders about Kali365, a growing phishing-as-a-service platform that retrieves Microsoft 365 access tokens, issuing a public service announcement Thursday [May 21, 2026]. 
    • “The toolkit bypasses multi-factor authentication and abuses OAuth device code authorizations via phishing lures impersonating common enterprise services. This technique grants cybercriminal-controlled applications access to Microsoft 365 accounts, opening victims up to a host of follow-on malicious activity, including data theft, fraud, extortion and ransomware attacks.
    • “Kali365 is one of many rapidly emerging device-code phishing tools, which are gaining popularity as a more effective means for cybercriminals to circumvent security controls while abusing legitimate Microsoft device authorization pages, according to researchers.
    • “Instead of gaining access to accounts via phishing kits that steal credentials and second-factor authentication codes, device-code phishing platforms connect a malicious app to a legitimate account with a single code. The process requires fewer steps and less interaction with the user, but victims do have to copy-and-paste a code generated by the Kali365 platform to grant access.”
  • Cyber Insider points out,
    • “Hidden audio commands can hijack AI voice assistants and transcription tools without users hearing anything unusual, according to new research set to be presented at the IEEE Symposium on Security and Privacy next week.
    • “The study shows that carefully crafted audio clips can elicit unauthorized actions from audio-language models (LALMs), including downloading files, sending emails, and performing web searches.
    • “The attack, dubbed “AudioHijack,” was developed by researchers from Zhejiang University, Nanyang Technological University, and the National University of Singapore. The team describes the attack as a form of “auditory prompt injection,” in which malicious instructions are embedded in ordinary audio using adversarial perturbations that remain nearly imperceptible to human listeners.
    • “Large audio-language models are increasingly powering voice assistants, meeting transcription services, customer support bots, and multimodal AI systems capable of both understanding and generating speech. Some platforms can also interact with external tools and services, allowing them to search the web, operate apps, or execute commands on behalf of users. According to the researchers, these capabilities significantly expand the attack surface.
    • “Attackers could potentially hide malicious prompts inside music, videos, voice notes, or even live conversations uploaded to AI services. The paper also describes scenarios in which hidden audio could be injected into Zoom meetings or multimedia content processed by AI assistants.”
  • The Hacker News notes,
    • “In February 2026, a phishing-as-a-service (PhaaS) platform called EvilTokens went live. Within five weeks, it had compromised more than 340 Microsoft 365 organizations across five countries. 
    • “The targets of the platform received a message asking them to enter a short code at microsoft.com/devicelogin and complete their normal MFA challenge, then walked away believing they had verified a routine sign-in. They had actually handed the operator a valid refresh token scoped to their mailbox, drive, calendar, and contacts, with the lifespan of a tenant policy rather than a session.
    • ‘The operator never needed a password, never tripped an MFA prompt, and never produced a sign-in event that looked like an intrusion. The attack succeeded because the OAuth consent screen has become an instinctive click, and the controls built to stop credential phishing do not look at the consent layer.
    • “Security researchers call the resulting condition consent phishing or OAuth grant abuse. The phishing click that mattered last decade handed over a password. The phishing click that matters now hands over a refresh token, and it sits structurally below the identity controls most organizations still treat as the perimeter.”

From the ransomware front,

  • Sophos reports,
    • “SophosLabs analysts investigated WantToCry ransomware attacks that involved the threat actors abusing the Server Message Block (SMB) service for initial access and then exfiltrating files to attacker-controlled infrastructure for remote encryption. The detection surface is significantly reduced because WantToCry operates without local malware execution, and there is no post-compromise activity beyond exfiltrating files and rewriting them to disk.
    • “The WantToCry name appears to be a reference to the notorious WannaCry (also known as WCry) ransomware worm, which propagated via a vulnerability in SMB at the start of 2017. While WantToCry is not self-propagating and there is no evidence to suggest that the two operations are connected, organizations with internet-exposed SMB services are similarly at risk.” * * *
    • “As with all ransomware activity, prevention remains key to mitigating the threat of remote ransomware operations like WantToCry. Preventive measures include disabling the SMBv1 protocol across the organization, removing “guest” or anonymous SMB access, and blocking inbound SMB traffic (ports TCP/139 and TCP/445) at all internet-facing firewalls. Additionally, it is important to ensure that backups cannot be accessed via SMB protocols.
    • “Organizations should also implement network-level controls and file content monitoring to address this attack methodology effectively. A tool like Sophos CryptoGuard can identify, block, and roll back encryption activity performed via SMB protocols.
    • “WantToCry relies on weak authentication and internet exposure rather than on software vulnerabilities or malware delivery mechanisms. Extended detection and response (XDR) solutions can identify reconnaissance and brute-force attempts against SMB services, providing early warnings of potential WantToCry operations.”
  • Bleeping Computer relates,
    • “Threat actors brute-forced VPN credentials and bypassed multi-factor authentication (MFA) on SonicWall Gen6 SSL-VPN appliances to deploy tools used in ransomware attacks.
    • “During the intrusions, the hacker took between 30 and 60 minutes to log in, do network reconnaissance, test credential reuse on internal systems, and log out.
    • “SonicWall warned in a security advisory for CVE-2024-12802 that installing the firmware update alone on Gen6 devices does not fully mitigate the vulnerability, and a manual reconfiguration of the LDAP server is required. Failing to do so leaves open the possibility of bypassing MFA protection.”
  • The American Hospital Association lets us know,
    • “Microsoft announced May 19 that it disrupted operations of Fox Tempest, a threat actor operating as a malware-signing-as-a-service used by cybercriminals to deploy malicious code, including ransomware. Microsoft said Fox Tempest has enabled attacks on a range of sectors in the U.S. and internationally, including health care, education, government and financial services. The actor has been linked to other ransomware groups, including INC, Qilin and Akira. 
    • “One component of modern security is that software packages need to be digitally signed to prove their authenticity,” said Scott Gee, AHA deputy national advisor for cybersecurity and risk. “Normally, these signatures can only be provided by trusted, verified sources. Fox Tempest provided these signatures to malware so that it appeared to be legitimate to security systems. This service enabled a number of ransomware actors to attack health care and other sectors. Microsoft has revoked over 1,000 certificates issued by Fox Tempest. Hospitals and health systems should ensure that certificate verification is enabled on their cybersecurity toolsets.” 
  • and
    • “Cyberattacks against hospitals, health systems and mission-critical health care third-party providers have surged in recent years. While these attacks often involve theft of patient data and medical research, the most concerning are high-impact ransomware attacks that continue to shut down critical medical systems, resulting in disruption and delays to health care delivery. There is no doubt that these types of disruptive attacks create a direct risk to patient and community safety. To be clear, these are not data-theft crimes, they are in fact “threat to life” crimes.
    • “The perpetrators of these foreign-based ransomware attacks are primarily, but not exclusively, Russian-speaking or based in Russia. Other adversarial nations that provide shelter for dangerous international criminals to launch cyberattacks against the U.S. are the usual suspects — Iran, China and North Korea.
    • “There have been thousands of ransomware and data theft attacks targeting U.S. health care over the last several years. In fact, the FBI reported that in 2025 alone, the health care sector suffered 460 ransomware attacks, far more than any other critical infrastructure sector. Since 2020, over 3,200 hacking incidents have been reported to the Department of Health and Human Services Office for Civil Rights, impacting 574 million individuals. Many incidents were actually encryption ransomware attacks accompanied by data theft — “the double extortion,” in which the perpetrators demand an additional ransom for both a decryption key to unlock systems and in exchange for not publishing stolen patient health records.
    • “The silver lining? We have a great deal of “battle experience” and tough lessons learned, which has helped us collaborate to harden systems and prepare for impact and recovery. We at the AHA, working with victims, the field and the federal government, have also been able to reliably identify strategic cyber risk related to third parties, patient safety and supply chain.
    • The top three risks are
      • Geopolitical tensions
      • Cyberattacks agains third parties, and
      • Autonomous Artificial Intelligence-generated and -facilitated Cyberattacks.

From the cybersecurity defenses front,

  • Cyberscooop reports,
    • “On Wednesday [May 20], Microsoft released two new red teaming tools — Rampartand Clarity — meant to help developers design more secure agentic software and assist incident responders in the face of ongoing breaches.
    • Rampart is built on top of PyRIT, an existing open automation framework Microsoft developed for red teaming generative AI systems. But while PyRIT scans already-built systems for security flaws, Rampart is made to continuously test code for vulnerabilities during the development process, encoding both adversarial and benign testing scenarios into the software development pipeline to flag exploitable bugs and dependencies.
    • “Microsoft said Rampart was built to focus on cross-prompt injection attacks, where “an agent retrieves or processes potentially poisoned content from documents, emails, tickets, and other data sources that manipulate behavior indirectly.” It also confirms fixes or exploits work as intended through multiple rounds of testing, as opposed to tools that perform “single shot validation.”
    • “The second tool, Clarity, can be run as a desktop app, a web interface or directly embedded into a coding agent to provide real time security engineering guidance to developers at the outset of a project. It can categorize and track different business objectives related to the code and highlight downstream security implications along with more secure by design alternatives.”
  • Per Dark Reading,
    • “AI Agents Are Shifting Identity Security Budget Dynamics.”
    • “AI agent projects are proliferating throughout the enterprise, and those AI agent identities require management, security, and governance. New Omdia research shows the AI agent identity budget dynamics are very different than traditional IAM projects.”
  • Per Cyberscoop commentaries,
    • “The Canvas breach proved that prevention is no longer enough.
    • “Cybercriminals brought down the most widely used learning platform in North America. The Canvas breach is a blueprint for how SaaS attacks now work — and a warning about how unprepared most organizations still are.”
  • and
    • “The readiness paradox: Why a false sense of cyber confidence is becoming a liability
    • “As AI expands the attack surface and alert fatigue grows, cyber exposure management offers a clearer path to understanding where risk truly concentrates and how to reduce it before a crisis hits.”
  • Here is a link to Dark Reading’s CISO Corner.

Friday report

Simplificity is a virtue.

From Washington, DC

  • Roll Call reports,
    • “The House Appropriations Committee advanced a draft fiscal 2027 Legislative Branch spending bill on Wednesday that would slash the budget for the Government Accountability Office by nearly one-quarter and give a boost to Capitol Police.
    • “The party-line vote of 34-28 came after a contentious markup stretching late into the evening, as Democrats argued the GAO cut would undermine its mission.”
  • The Hill informs us,
    • “Federal Reserve Chair Kevin Warsh was sworn in Friday beside President Trump, kicking off his term as the new head of the central bank at a critical time for the U.S. economy.” * * *
    • “Warsh, 56, returns to the Fed board after serving as a member from 2006 to 2011. He was nominated to the Fed by former President George W. Bush, whom he served as a White House economic adviser before becoming the youngest Fed board member in history.
    • A graduate of Stanford University and Harvard Law School, Warsh also worked at Morgan Stanley and served in various academic and advisory roles outside of his government service. 
    • Warsh was most recently a fellow at Stanford’s Hoover Institution, an influential conservative think tank known for its close ties to prominent Republican policymakers.
  • Healthcare Dive relates,
    • “The HHS is continuing its crackdown on healthcare fraud, launching a program that will use artificial intelligence to examine audits from states and other federal grant recipients — and potentially affect Medicaid funds.
    • “The Office of the Assistant Secretary for Financial Resources will look across all states to analyze at least five years of audits that grantees file annually with the federal government, the department said Thursday. 
    • “The agency says past audits include internal control issues and “chronic” noncompliance. If recipients aren’t able to fix those problems, the HHS could temporarily withhold payments, hold back future funds, or suspend or terminate awards.”

From the Food and Drug Administration front,

  • The American Hospital Association News reports,
    • “The Food and Drug Administration has issued an early alert for all heart pump controllers by Abiomed, which sent a correction notice to all customers with updated use instructions. The FDA said that Abiomed identified an issue where if a patient is treated with a left ventricular Impella device and experiences an extended period longer than 80 minutes with no residual pulsatility, the Abiomed Automated Impella Controller may be forced to restart due to an internal software error.” 
  • Per an FDA news release,
    • “Today, the U.S. Food and Drug Administration approved Hepcludex (bulevirtide-gmod) injection to treat chronic hepatitis delta virus (HDV) infection in adults without cirrhosis (advanced liver scarring) or with compensated cirrhosis. Bulevirtide is the first FDA-approved treatment for chronic HDV infection, a serious and life-threatening condition that can cause rapid development of liver fibrosis (scarring), liver cancer, liver failure, and even death.
    • “Today’s approval fills a critical gap in care for patients with chronic HDV infection, who until now have had no FDA-approved therapies available,” said Wendy Carter, D.O., Acting Director of the Office of Infectious Diseases in FDA’s Center for Drug Evaluation and Research. “For individuals living with this chronic viral infection, this new treatment option offers hope in managing a disease that can rapidly progress to serious liver complications.”

From the judicial front,

  • Bloomberg Law reports,
    • “The importance of the $885 million antitrust verdict this week against Takeda Pharmaceuticals Co. Ltd. had less to do with the nine-figure damages than ending private plaintiffs’ losing streak challenging deals delaying cheaper generics.
    • “The Boston federal jury’s finding that Takeda improperly paid a competitor to delay it from bringing a generic version of its Amitiza constipation medication to market marked the first time a private plaintiff won at trial in a reverse-payment case.
    • “Most challenges to deals between branded drug companies and generic makers either settle or are dismissed before reaching trial, with the more nuanced agreements sometimes making it to a jury. Three have been tried before a jury since the US Supreme Court put drugmakers on notice that the dealings could run afoul of antitrust laws. Until Monday, juries had rejected plaintiffs’ claims each time. 
    • “I expect the case to send ripples through legal departments — if not boardrooms — across the country,” said Robin Feldman, a law professor at the University of California in San Francisco who studies pharmaceutical regulation and intellectual property. She called the verdict a “groundbreaking decision.”

From the public health and medical / Rx research front,

  • The Centers for Disease Control and Prevention announced today,
    • “RSV activity started later than usual in most parts of the United States, but illnesses are not more severe than recent years. Activity has peaked in most regions of the country. Because of the later start, some areas of the country may continue to see higher levels of RSV through May. Emergency department visits and hospitalizations for RSV are highest among infants and children less than 4 years old. COVID-19 activity is low in most areas of the country. Seasonal influenza activity is low.”
  • The University of Minnesota’s CIDRAP reports,
    • “As the nation moves closer to topping last year’s measles total in just the first half of 2026, the Centers for Disease Control and Prevention (CDC) today confirmed 59 new cases in a nationwide outbreak that has now reached 1,952 infections. 
    • “All but nine cases are locally acquired, with the rest related to international travel. The total for all of last year was 2,288 confirmed cases.”
  • and
    • “Although an Ebola outbreak is growing rapidly in central Africa, experts say it doesn’t pose a public health threat to the United States.
    • “The outbreak, centered in the Democratic Republic of the Congo (DRC), has grown to nearly 750 suspected cases and more than 170 deaths, the World Health Organization (WHO) announced today. Although the risk from Ebola in the DRC is high, the risk of global spread is low, WHO Director-General Tedros Adhanom Ghebreyesus, PhD, said. 
    • “Many US infectious diseases experts agree.
    • “This is a horrible situation in affected areas of Africa,” said Michael T. Osterholm, PhD, MPH, director of the Center for Infectious Disease Research and Policy (CIDRAP) at the University of Minnesota, which publishes CIDRAP News. “But for the world, it is not.”
    • “That’s because Ebola, which spreads through contact with bodily fluids, is far more difficult to spread than the airborne respiratory viruses that Americans have confronted in recent years, such as influenza, COVID-19, measles, and even the Andes strain of the hantavirus, which recently caused an outbreak on a cruise ship.”
  • BioPharma Dive points out,
    • “ASCO26: 5 data snapshots ahead of the year’s biggest cancer drug meeting.
    • “Clinical trial abstracts posted Thursday ahead of this year’s ASCO meeting gave a peek at anticipated datasets from Merck, BioNTech, Eli Lilly and Moderna.”
  • Per a National Institutes of Health news release,
    • “A team of researchers at the National Institutes of Health (NIH) have unveiled new details about the events GLP-1 receptor agonists trigger within neurons, which have been largely unexplored until now. A study in mice identified key intracellular signaling processes that are tied to the weight-loss effects of the GLP-1 drug semaglutide. The findings improve our understanding of how increasingly prevalent GLP-1s may influence human behavior and identify new opportunities to potentially enhance treatment.
    • “The weight-loss benefits of GLP-1s are well documented and scientists generally know the brain regions associated with these effects. However, several questions remain, such as why responses to medication differ between patients and why the effects for most eventually plateau.
    • “We know much less about the nuts and bolts of what goes on within the neurons that these medications target. By digging into these mechanisms, we’re beginning to answer some of these questions,” said co-corresponding author Andrew Lutas, Ph.D., an investigator at NIH’s National Institute of Diabetes and Digestive and Kidney Diseases (NIDDK).”
  • CNN reports,
    • “Pregnant women are routinely advised to take prenatal vitamins for their health and their baby’s development. Now, a new study published Monday in JAMA Network Open concluded that children whose mothers received higher-dose vitamin D supplements during pregnancy performed better on certain memory tests at age 10.”
  • MedPage Today relates,
    • “Preserved global brain structure appeared to buffer cognitive decline in people with Alzheimer’s pathology.
    • “Younger-appearing brains had weaker links between pathology and poorer outcomes in multiple cognitive domains.
    • “Other measures of brain reserve or cognitive reserve showed no clear protective cognitive effect.”
  • Health Day tells us,
    • “Middle-aged people who have migraine with an aura could be more at risk for stroke.
    • “Those who had migraine with aura had a 73% increased risk of stroke
    • “Middle-aged men who suffered any kind of migraine had a more than 3.5-fold increased risk of stroke.”
  • and
    • “Use of calcium, vitamin D, or combined supplementation has little to no effect on the prevention of fractures and falls in adults, according to a review published online May 20 in The BMJ.
    • “Olivier Massé, Pharm.D., from CIUSSS du Nord-de-l’Île-de Montréal, and colleagues conducted a systematic review and meta-analysis to examine the effect of calcium, vitamin D, or combined supplementation on fractures and falls in adults. A total of 69 trials, with 153,902 participants, were included in the review.
    • “Most trial participants were community dwelling (87 percent) and not at high fracture or fall risk (73 percent). The researchers found that little to no effect was found from use of calcium supplements (risk ratio, 0.91), vitamin D supplements (risk ratio, 1.00), or combined supplementation (risk ratio, 0.91) for the primary outcome of any fracture. There was little to no effect on other fracture and fall outcomes seen for calcium, vitamin D, or combined supplementation, based mainly on moderate-to-high certainty of evidence. After extensive exploration of heterogeneity across multiple subgroup analyses, the findings remained robust.”
  • BioPharma Dive informs us,
    • “The outlook for an experimental Parkinson’s disease drug dimmed on Thursday with the announcement that it had failed a key clinical trial.
    • “Developed through a partnership Denali Therapeutics and Biogen, the drug is designed to inhibit an enzyme tied to one of the most common genetic drivers of Parkinson’s: a gene called LRRK2. When this gene mutates, it causes the waste disposal systems in cells to malfunction, leading to the buildup of toxic proteins that damage and destroy neurons.
    • “In 2022, Biogen and Denali kicked off what would ultimately become a nearly 650-person trial that pitted their drug against a placebo. The companies are now saying this mid-stage study showed the drug — codenamed BIIB122 — was not significantly better at slowing the disease progression, as measured by a well-known scale clinicians use to assess how Parkinson’s is affecting a patient’s movement and daily life.”

From the U.S. healthcare business and artificial intelligence front,

  • Per an EBRI news release,
    • “The Employee Benefit Research Institute (EBRI)/Greenwald Research Consumer Engagement in Health Care Survey found that the majority of insured individuals still receive health insurance through their employer.
    • “Employment-based health coverage remained the dominant source of health insurance for privately insured adults, with six in 10 receiving coverage through their own job.” * * *
    • “Coverage patterns have been largely stable, with about one-third enrolled in individual-only coverage and most others covering a spouse or partner.”
  • Fierce Pharma relates,
    • “With both Novo Nordisk’s and Eli Lilly’s oral GLP-1s establishing their footing in the U.S. obesity market, the companies’ respective Wegovy pill and orforglipron tablet Foundayo are making their mark on prescription trends for a class previously confined primarily to injectables.
    • “Looking at the past four weeks, total U.S. GLP-1 prescriptions were up 3.6%, compared to 1.8% at the same time last year, analysts at Citi wrote in a Friday note to clients, citing script tracking data from IQVIA. The Citi team attributed that momentum to the ability of Novo’s and Lilly’s new oral launches to “broaden and reshape the market” for obesity incretin drugs.”
  • MedCity News considers whether “Mark Cuban’s Cost Plus Wellness Appeal to Employers?”
    • Employer advocates said Cost Plus Wellness could help spur more direct contracting and transparency in healthcare, though they questioned whether the model can scale and adequately measure provider quality and outcomes.
  • Beckers Hospital Review reports,
    • “Philadelphia-based Penn Medicine reported an operating income of $238.5 million (2.4% margin) for the nine months ended March 31, up 46.3% from $163 million (1.9% margin) in the same period last year, according to financial documents filed May 20.
    • “The results follow the April 1, 2025, acquisition of Doylestown (Pa.) Health. Doylestown Hospital, a 245-bed teaching hospital, became Penn Medicine’s seventh hospital and is now known as Penn Medicine Doylestown Health.”
  • STAT News tells us,
    • Retro Biosciences, the longevity startup backed by OpenAI CEO Sam Altman, has raised more money at a $1.8 billion valuation, it announced Friday. 
    • “Retro has a big mission: Add 10 healthy years to the human lifespan. It is seeking to do that by using a variety of technologies, including in vivo gene therapies, cell replacement therapies, and other approaches to spur younger, healthier cells into aging tissues.
    • “The company is currently running its first clinical trial — testing a pill designed to enhance the body’s ability to better clear out protein aggregates in patients with Alzheimer’s disease. Retro CEO Joe Betts-LaCroix told the audience at STAT’s Breakthrough Summit West on Tuesday that the trial is going “super good” and that researchers haven’t seen any dose-limiting toxicities. He said he anticipates releasing some data from the trial around August.”  
  • Fierce Healthcare informs us,
    • “Innovaccer acquired CaduceusHealth to combine its AI platform with the company’s revenue cycle management services and staff to serve ambulatory care providers.
    • ‘Innovaccer, founded in 2014, built software solutions to unify enterprise data and applies AI to automate manual tasks and streamline workflows for payers and providers. Last year, it rolled out Flow Auth, an AI-powered prior authorization solution that is part of Flow by Innovaccer, an AI-powered revenue cycle suite designed to modernize financial operations for health systems. Other capabilities include Flow Capture, an autonomous medical coding solution and Flow Collect, an AI-powered denial management and revenue recovery tool.
    • “Innovaccer claims that it now serves over 200 health systems and payers, 95% of community pharmacies and 80 million patient lives across the United States. Flow is built on Gravity, Innovaccer’s healthcare AI infrastructure platform.”
  • and
    • “Eugene, Ore.-based Ksana Health is undertaking a multi-institutional research effort aimed at creating a new class of artificial intelligence to advance mental health and substance use disorder treatment and prevention.
    • “The software company was awarded a $17.9 million contract by the U.S. Department of Health and Human Services (HHS) to create a Large Health Behavior Model (LHBM). Its goal is to train AI models on smartphones and other wearables data, including sleep, mobility and language use linked to large scale electronic health records (EHRs).
    • “This initiative augments Ksana’s current efforts to shift behavioral healthcare from episodic, subjective assessment toward continuous, data-driven health promotion, reducing healthcare spending, improving quality of life, and reaching populations that currently lack access to effective behavioral health support,” said Tony Scripa, Ksana Health COO and project co-investigator, in a statement.”
  • and
    • “More than seven in 10 Medicare members report feeling confusion or uncertainty when navigating online health information, a new whitepaper from CVS Health found. 
    • “The research (PDF) drew insights from Medicare-eligible consumers through surveys, interviews and ethnographic studies. 
    • “Seventy-one percent of respondents report an eagerness to use more digital health care tools and 86% report an eagerness to use them. However, 58% of respondents report that low digital health literacy is negatively impacting their ability to manage their health. 
    • “We’re caring for the fastest-growing and most clinically complex population in the country, and what we found in the research challenges a common assumption—older adults actually are more open to engaging with technology than many think,” said Dr. Benjamin Kornitzer, M.D., Aetna senior vice president and CMO, in a statement. “It creates a real opportunity to meet them where they are and provide day-to-day support, whether it’s managing medications, following up after a visit, or staying on track with chronic conditions. Technology and engagement can help them live healthier, more independent lives.”
    • “As a result, CVS said it is applying insights from the research across its digital offerings, including clearer navigation, stronger accessibility features and added privacy and security transparency.” 

Cybersecurity Saturday

From the cybersecurity policy front,

  • Cyberscoop reports,
    • “The House Homeland Security Committee is digging into Anthropic’s AI model Mythos in a series of briefings and hearings, as questions proliferate on whether and how the federal government will make use of the technology touted for its ability to autonomously uncover cyber vulnerabilities.
    • “Wednesday [May 13] brought a closed-door briefing for the House Homeland Security Committee from Anthropic. The chairman of the panel’s cybersecurity subcommittee said he is planning to hold a hearing on the topic. And committee Democrats are requesting a classified briefing with Anthropic.
    • “A committee aide who attended the briefing said it included a live demonstration of Mythos, “allowing members to see firsthand how advanced AI can identify and reason through software vulnerabilities. What we saw reinforced the urgency of ensuring that federal agencies, including our civilian cyber defenders, can responsibly access and deploy the most advanced U.S. models to find and patch vulnerabilities before foreign adversaries or criminal actors exploit them.” * * *
    • “There’s a divide on which federal agencies are using Mythos thus far. For example: CISA reportedly isn’t, but the National Security Agency is.” 
  • GovCon Wire adds,
    • Anthropic’s Project Glasswing and Claude Mythos announcement may have sparked concerns across the cybersecurity community, but Pentagon technology leaders say the emergence of Mythos-style AI models could ultimately strengthen U.S. cyber defense capabilities rather than weaken them.
    • Katherine Sutton, DOW [Department of War] assistant secretary for cyber policy, emphasized that the focus should not solely remain on the offensive risks associated with advanced cyber AI, according to Breaking Defense. 
    • “I hear a lot of people talking about challenges and threats when they talk about Mythos,” Sutton said. “[But] there’s huge opportunity in these models. One of the foundational things that they’re going to enable is the development of secure code.”
  • Cyberscoop points out,
    • “Two of the most advanced artificial intelligence models — Anthropic’s Claude Mythos Preview and OpenAI’s GPT-5.5 — have significantly surpassed the already-accelerating pace at which AI systems are completing autonomous cybersecurity tasks, according to separate findings published Wednesday by the United Kingdom’s AI Security Institute (AISI) and Palo Alto Networks.
    • “The AISI, which conducts pre-deployment evaluations of frontier AI models on behalf of the British government, said both Claude Mythos Preview and GPT-5.5 have substantially exceeded the doubling trend the institute had been tracking since late 2024. Whether the results represent an isolated capability jump or the start of a new, faster trajectory remains unclear.”
  • Cybersecurity Dive relates,
    • “In February, a coalition that includes corporate titans JPMorgan Chase, Mastercard, AT&T and Berkshire Hathaway Energy launched the Alliance for Critical Infrastructure (ACI), vowing to take the lead in helping infrastructure sectors work more closely together to understand and mitigate the shared cybersecurity risks they face. Reading between the lines, the message was clear: The critical infrastructure community, increasingly alarmed at the Trump administration’s retreat from decades-long partnerships, is trying to fill the growing void of coordination and leadership.” * * *
    • “Government budget cuts and personnel losses have made it much harderfor agencies to support and advise infrastructure operators, and the White House has encouraged states to take over historically federal responsibilities for protecting local utilities. Amid those changes, infrastructure firms like the ones that founded the ACI say the private sector must step up.
    • “Ben Flatgard, the ACI’s chairman, noted that the private sector manages the vast majority of U.S. infrastructure. “We can’t outsource that responsibility or the risk management practices that come along with it,” he said in an interview with Cybersecurity Dive. “We need to own the solution for that as well.”
    • “Many experts say that while the government must retain a leadership role in protecting critical infrastructure, it’s a good sign that private companies want to assume more of the burden.”
  • Per a Cybersecurity and Infrastructure Security Agency (CISA) news release,
    • “CISA and the Group of Seven (G7) international partners—Germany, Canada, France, Italy, Japan, the United Kingdom, and the European Union—have released joint guidance, Software Bill of Materials for AI – Minimum Elements, to help public and private sector stakeholders improve transparency in their artificial intelligence (AI) systems and supply chains.
    • “A software bill of materials (SBOM) acts as an “ingredients list” for software that better positions organizations to understand their supply chains and make risk-informed decisions about how to protect their critical systems. The guidance builds on CISA’s previous work with federal and international partners to establish a shared vision for a software bill of materials and provides recommendations on minimum elements that should be included in an SBOM for AI. Because AI systems are software systems, these recommendations should be considered in addition to the general minimum elements for an SBOM
    • “While not exhaustive or mandatory, the supplemental minimal elements outlined in this guidance reflect the consensus of G7 experts and will expand over time to keep pace with the rapid advancement of AI technology.” 

From the cybersecurity breaches and vulnerabilities front,

  • Cybersecurity Dive lets us know,
    • “Seven out of every 10 organizations suffered at least one identity-related breach over the past year, according to a report released Tuesday [May 12] by Sophos. Organizations, on average, reported three separate identity-related incidents during that time.
    • ‘Two-thirds of ransomware victims said the cyberattack stemmed from an identity-related incident, said Sophos. The report is based on a survey of 5,000 IT and cybersecurity leaders across 17 countries. 
    • “The mean recovery cost was $1.64 million, read the report, and the median cost was $750,000. Seven of every 10 respondents reported recovery costs of more than $250,000.”
  • Bleeping Computer adds,
    • “Initial access broker KongTuke has moved to Microsoft Teams for social engineering attacks, taking as little as five minutes to gain persistent access to corporate networks.
    • “The threat actor tricks users into pasting a PowerShell command that ultimately delivers the ModeloRAT, which has been previously seen in ClickFix attacks [12].
    • “Initial access brokers (IAB) like KongTuke typically sell company network access to ransomware operators, who use it to deploy file-theft and data-encrypting malware.
    • “Cybercriminals have increasingly adopted Microsoft Teams in attacks, reaching out to company employees and pretending to be IT and help-desk staff.”
  • CISA added two known exploited vulnerabilities (KVEs) to its catalog this week.
  • Security Week reports,
    • ‘For the first time, Google has identified a zero-day exploit believed to have been developed using artificial intelligence.
    • “The company published a new report on Monday [May 11]. summarizing its observations on the use of AI in the cyber threat landscape, drawing on data collected recently by Gemini, Google Threat Intelligence Group (GTIG), and Mandiant. 
    • One of the most notable findings is that a prominent cybercrime group leveraged AI to develop a zero-day exploit designed to bypass two-factor authentication (2FA) on an open source web-based system administration tool. The exploit was implemented in a Python script.
    • The hacker group and the targeted tool have not been named, but Google said it worked with the impacted vendor to prevent mass exploitation, which appeared to be the threat actor’s plan.
    • “Although we do not believe Gemini was used, based on the structure and content of these exploits, we have high confidence that the actor likely leveraged an AI model to support the discovery and weaponization of this vulnerability,” Google explained.
  • Fand
    • “Linux distributions are informing users about a new kernel vulnerability that can be exploited by a local attacker to escalate privileges to root.
    • “Dubbed Fragnesia and officially tracked as CVE-2026-46300, the issue resides in the kernel’s XFRM ESP-in-TCP subsystem, allowing an unprivileged attacker to gain root permissions by overwriting sensitive system files. 
    • “A majority of Linux distributions are affected, and they have started releasing patches.
    • “A proof-of-concept (PoC) exploit is available, but there is no evidence that Fragnesia has been exploited in the wild.
    • “Similar to Dirty Frag, Fragnesia exploits a vulnerability in the XFRM ESP-in-TCP subsystem to achieve a memory write primitive in the kernel,” Microsoft’s threat intelligence team said.” 
  • The Wall Street Journal relates.
    • “Security researchers say they have discovered a new way of circumventing Apple’s AAPL 1.07%increase; green up pointing triangle state-of-the art security technology, using techniques they discovered while testing an early version of Anthropic’s M”ythos AI software in April.
    • “:The researchers with Calif, a Palo Alto-based security research company, say the software they wrote links together two bugs and a handful of techniques to corrupt the Mac’s memory and then gain access to parts of the device that should be inaccessible.
    • “It is what’s known as a privilege escalation exploit, and if it were chained together with other attacks it could be used by a hacker to seize control of the computer.
    • “The technique is noteworthy because Apple has put so much effort into locking down MacOS, said Michał Zalewski, a security researcher who formerly worked at Google and who reviewed the Calif research but wasn’t involved in the testing. 
    • “Apple, which is deploying and testing frontier AI models to test and patch vulnerabilities, is reviewing the Calif report to validate its findings. “Security is our top priority, and we take reports of potential vulnerabilities very seriously,” a company spokeswoman said.”

From the ransomware front,

  • Cyberscoop reports,
    • “Instructure, the company behind Canvas, said it reached an agreement with the cybercriminals who threatened to leak a trove of sensitive data they claim was stolen during a prolonged cyberattack on the widely used education tech platform.
    • “Pressure was mounting on the company as widespread outages left schools, students and teachers temporarily unable to access critical data late last week when the company took Canvas offline after the attackers defaced the platform’s login page. By Friday, the company said Canvas — a central hub for K-12 and university coursework, exams, grades and communication — was back online and fully operational. 
    • “ShinyHunters, a decentralized crew of prolific cybercriminals that researchers affiliate with The Com, claimed responsibility for the attack on its data leak site and was attempting to extort the company for an unknown ransom amount. 
    • “Instructure didn’t outright say it paid a ransom, but insisted the agreement provided all necessary assurances. “The data was returned to us. We received digital confirmation of data destruction (shred logs),” the company said in an update Monday [May 11]. * * *
    • “The House Homeland Security Committee on Monday published a letter to [Instructure CEO Steve] Daly seeking a briefing with him or a senior leader at Instructure by May 21. 
  • and
    • “Foxconn, one of the world’s largest manufacturers of electronics sold by major tech vendors, is recovering from a cyberattack that disrupted some of the company’s factories in North America.
    • :Nitrogen, a ransomware group that’s known for targeting organizations in the manufacturing, construction and technology sectors, claimed responsibility for the attack on its data leak site and said it stole 8 terabytes of data spanning more than 11 million files. 
    • “The threat group posted screenshots of some of the allegedly stolen data and claimed it compromised “confidential instructions, projects and drawings from Intel, Apple, Google, Dell, Nvidia and many other projects.” 
    • “Foxconn is famously known as the primary assembler of Apple iPhones. Apple and the other companies allegedly impacted by the attack did not respond to a request for comment.” ***
    • “Nitrogen was first observed in 2023, using ALPHV, one of the most prevalent ransomware variants at that time, Cynthia Kaiser, senior vice president at Halcyon’s Ransomware Research Center, told CyberScoop. The group started using stolen code from Conti, another formerly prolific ransomware variant, in 2024 to build its own custom attack tools to hit Windows and VMware server environments, she added.”
  • Cybersecurity Dive relates,
    • “West Pharmaceutical Services on Wednesday [May 13] said it has contained a ransomware attack it suffered earlier this month and is restarting critical systems, including manufacturing, receiving and shipping, at certain locations, according to an update on its website
    • “The Exton, Pa.-based company, one of the world’s leading makers of drug-delivery devices and solutions, confirmed that data was stolen and encrypted in the attack, in a Monday filing with the Securities and Exchange Commission.” * * *
    • “Palo Alto Networks Unit 42, handled incident response to the attack, according to an assurance letter shared by the pharmaceutical services company. The letter confirms that the ransomware attack was contained and any malicious binaries and unauthorized persistence mechanisms were neutralized.” 
  • The HIPAA Journal adds,
    • Ransomware groups have claimed responsibility for attacks on Advanced Family Surgery Center in Tennessee, Orem Eye Clinic in Utah, and Belmont Aesthetic & Reconstructive Plastic Surgery in Virginia/Washington D.C.
  • Dark Reading notes,
    • “A new threat campaign is using RubyGems as a dead drop to store exfiltrated data, but the attacker’s long-term plans are less clear. 
    • “Software development security vendor Socket published research concerning a campaign dubbed “GemStuffer,” where an attacker abused the RubyGemspackage registry “as a data transport mechanism rather than a conventional malware distribution channel,” according to a blog post. RubyGems is a package manager for the Ruby programming language, and acts as a way for developers to distribute Ruby programs or libraries, which are referred to as “gems.”
  • Checkpoint Research posted its first quarter 2026 ransomware report.
    • Key Findings
      • Consolidation after peak fragmentation: The top 10 ransomware groups accounted for 71% of all Q1 2026 victims, a sharp reversal from the fragmentation seen in Q3 2025. The ransomware ecosystem is once again consolidating around fewer, more dominant operators.
      • Volume stabilization at historically high levels: There were 2,122 victims posted on data leak sites (DLS), making this period the second-highest Q1 on record. The long growth trend is stabilizing.
      • Qilin’s sustained dominance: Qilin maintained its position as the most prominent ransomware operation for the third consecutive quarter, posting 338 victims.
      • The Gentlemen is the breakout story of Q1 2026 reaching the third place on the global ransomware list, increasing their victim count from 40 victims in Q4 2025 to 166 in Q1 2026.
      • LockBit 5.0 comeback confirmed: LockBit posted 163 victims in Q1 2026, climbing to fourth place.
  • Dark Reading adds,
    • “Tables Turn on ‘The Gentlemen’ RaaS Gang With Data Leak
    • “An OPSEC failure provides a window into what helped the ransomware group rise: a generous affiliate model, opportunistic TTPs, and an effective organizational structure.”
  • CSO discusses the economics of Ransomware 3.0.
    • “The uncomfortable truth your board needs to hear is this: The question is no longer whether your organisation will face a sophisticated threat actor. For any organisation of meaningful size, operating in a connected supply chain, with digital customer relationships, the question is how well-prepared you are when it happens. The economics of ransomware as a criminal enterprise have never been stronger. Attack-as-a-service platforms have lowered the barrier to entry. Ransom payment data is analysed and used to calibrate future demands. These groups study your financial filings.
    • “Investing in incident response capability — in people, process and technology — is not a cost centre decision. It’s the only bet that pays off in both the prevention scenario and the response scenario. Insurance pays out after the damage is done. A mature response architecture reduces the damage itself.
    • “The organisations that navigated the Cl0p MOVEit campaign of 2023 with the least disruption weren’t the ones with the biggest insurance policies. They were the ones who had mapped their data flows, limited unnecessary MOVEit exposure and had a response team that could move within hours rather than days.”

From the cybersecurity defenses front,

  • Cybersecurity Dive reports,
    • “OpenAI on Monday [May 11] launched a new cybersecurity initiative called Daybreak, which uses its large language models, Codex’s agentic capabilities and security partners to root out risk and call defense into action. The rollout is OpenAI’s answer to Anthropic’s Mythos model which debuted to limited preview last month and has highlighted weak security spots in software across various industries. 
    • “Like with Anthropic’s Project Glasswing, which sought tech vendors to support Mythos, OpenAI will work with industry and government partners to deploy cyber-capable models that are meant to build autonomous cyber defense capabilities into software from the start. Cloudflare, Cisco, CrowdStrike, Oracle and Zscaler are among a group of companies already using the technology, OpenAI said. Unlike Mythos, Daybreak is publicly available, and companies can request an assessment of their security risks.
    • “As AI providers compete for their share of the enterprise market with cybersecurity tools, tech leaders should experiment with all of their options, said Jeff Pollard, VP, principal analyst at Forrester, in an email to CIO Dive. “Take someone with responsibility for innovation in tech and cybersecurity and have them play with these capabilities to see what they offer,” he said.”
  • and
    • “Organizations are allocating more money for security against physical threats but the money is coming with more board oversight, and confusion remains over who has the lead role in physical security and how to blend physical security with cybersecurity, an EY survey finds. 
    • “Almost 80% of organizations say they increased the allocation for physical security over their last budget cycle, in some cases by as much as 50%, according to the EY Forensic & Integrity Pulse, based on responses from 250 executives and board members to a March survey.  
    • “Leaders are beginning to recognize gaps in crisis management and physical security preparedness as threats and risk evolve,” EY says in the report, released May 5.”
  • Dark Reading adds,
    • “AI Drives Cybersecurity Investments, Widening ‘Valley of Death’
    • “In a role reversal, investment dollars in security startups exceeded the value of mergers and acquisitions in 1Q26 by more than $1 billion, a rare occurrence.”
  • Security Week notes,
    • “Mythos Proves Potent in Vulnerability Discovery, Less Convincing Elsewhere
    • “Independent benchmarking finds Mythos highly effective for source code audits, reverse engineering, and native-code analysis, though its exploit validation and reasoning capabilities remain inconsistent.”
  • TechTarget explains how to implement zero trust for AI.
  • CSO informs us,
    • “Penetration tests of AI-based systems are revealing a greater percentage of high-risk flaws than those discovered in legacy systems.
    • “Security consultancy Cobalt’s annual State of Pentesting Report reveals that 32% of all AI and large language model (LLM) findings are rated as high risk — nearly 2.5 times the rate (13%) of severe flaws found in enterprise security tests more generally.”
  • Here is a link to Dark Reading’s CISO Corner.

Friday report

From Washington, DC

  • Roll Call informs us,
    • “Republican leaders in Congress scored some victories this week in nominations and appropriations but struck out on easily advancing their partisan “reconciliation 2.0” proposal to fund immigration enforcement.
    • “The bill faces a hurdle in the form of the Senate Parliamentarian, who on Thursday evening advised that several provisions violate the Senate’s restrictive Byrd rule — and more could be coming. 
    • “This throws an obstacle in the way of the GOP’s efforts to provide some $72 billion in funding for immigration enforcement by President Donald Trump’s June 1 deadline, as Republicans will have to rewrite parts of the package to pass it with the filibuster-proof budget reconciliation process, requiring a simple-majority vote to pass, instead of the 60-vote threshold required for regular legislation.
    • “Republicans are expected to try to rewrite the legislation to remedy the violations or, if that’s not possible, remove the offending provisions ahead of a Homeland Security Committee markup of the title next week. 
    • “Senate Parliamentarian Elizabeth MacDonough was expected to hold a second “Byrd bath” Friday to hear arguments from Democratic and Republican Senate staff about the Judiciary Committee’s portion of the bill, including Secret Service money for security upgrades tied to Trump’s White House ballroom project.” 
  • Mercer Consulting reports,
    • “With the midterm congressional elections approaching and healthcare affordability top of mind for voters, lawmakers are actively considering new healthcare transparency reforms, including requirements for providers to show plainly what patients will have to pay and new billing standards for hospitals.
    • “Senate Health, Education, Labor and Pensions Committee Chairman Bill Cassidy, R-LA, highlighted such price transparency legislation — Patients Deserve Price Tags Act (S 2355/HR 5582) — during a field hearing in Louisiana during last week’s congressional recess. Cassidy’s interest could signal that the legislation, which has may cosponsors from both parties, could soon see action at the Committee. 
    • “The bill would codify and expand current hospital price transparency rules that were established in the first Trump administration by extending requirements to clinical diagnostic laboratories, imaging centers, and ambulatory surgical centers. It would also make the prices that hospitals post clearer by requiring actual dollar-and-cents amounts, not estimates, as well as sharply increase financial penalties for hospitals and insurers that fail to disclose their negotiated rates. In addition, group health plans and insurers would have to give patients upfront, personalized cost estimates through an online self-service tool, as well as paper or phone options, before care is provided. The bill also ensures group health plans have access to claims data and prohibits third-party administrators from restricting that access.
    • “While several plan sponsor trade groups publicly support the legislation, they are working with lawmakers to make certain provisions more workable and better aligned with the PBM-focused transparency rules enacted in the Consolidated Appropriations Act, 2026 and proposed by the Department of Labor.”
  • AHIP lets us know “What They Are Saying: Broad Range of Experts Agree on a Root Cause of Healthcare Cost Crisis.”
    • “The evidence continues to underscore that making healthcare more affordable requires policymakers to address the root causes of high costs head-on through common-sense solutions like cracking down on anti-competitive hospital mergers and implementing site-neutral payment reforms.
    • “To learn more about how rising hospital costs are driving premiums higher and what policymakers can do to address it, visit AHIP.org/CostConnection.”
  • Fierce Healthcare relates,
    • “A bipartisan group of lawmakers in both chambers of Congress has reintroduced a bill aimed at barring companies from owning both a pharmacy benefit manager and retail pharmacies.
    • “The bill, called the Patients Before Monopolies (PBM) Act, would force conglomerates that include a PBM to divest pharmacies that they own. The legislation has existed in some form since 2024, and since its first introduction, Arkansas has implemented a similar legislation at the state level.
    • “Last month, Tennessee legislators also passed a bill that would prevent PBMs from owning pharmacies, which the governor is expected to sign into law.”
  • Mercer adds,
    • “Several developments in 2026 signal that the Trump administration is committed to improving behavioral health benefits for group health plan participants and beneficiaries — but the administration intends to put its own stamp on enforcement of the Mental Health Parity and Addiction Equity Act and propose new rules interpreting the landmark law.”
  • Per an HHS news release,
    • “The Substance Abuse and Mental Health Services Administration (SAMHSA), a division within the U.S. Department of Health and Human Services (HHS), announced today that it has awarded $255 million to Vibrant Emotional Health (Vibrant) to administer the 988 Suicide & Crisis Lifeline. The 988 Lifeline is a national network of more than 200 local crisis contact centers managed by a SAMHSA-funded network administrator. The 988 Lifeline has received more than 25 million contacts via call, text, chat, and ASL videophone since its launch.”
  • Modern Healthcare notes,
    • “The Centers for Medicare and Medicaid Service solicited the healthcare industry on ways it can identify and prevent fraud.
    • “The anti-fraud push drew cautious support, with providers and insurers seeking clear guardrails.
    • “Providers and insurers urged CMS to target high-risk services and avoid sweeping actions that would hamper care.” * * *
    • “New policies should focus on high-risk activities and not burden the ”vast majority of healthcare providers that are honorable in pursuing a mission to provide high-quality healthcare,” wrote the American Health Care Association/National Center for Assisted Living, which represents long-term care providers.
    • “The agency should also be careful not to add administrative burden since hospitals “already operate under extensive oversight requirements,” the American Hospital Association wrote.”
  • Beckers Payer Issues explains the federal crackdown on healthcare fraud, waste and abuse.
  • Newfront brings us up to date on the 2026 PCORI fee, which applies to FEHB and PSHB plan carriers.
    • “IRS Notice 2025-61 adjusts the Patient-Centered Outcomes Research Institute (PCORI) fee to $3.84 per covered individual for health plan years ending on or after October 1, 2025 and before October 1, 2026, including 2025 calendar plan years. This represents a 37-cent increase from last year’s $3.47 PCORI fee.
    • Action Item: The annual PCORI fee must be reported and paid to the IRS by July 31, 2026, via the second quarter Form 720 (Rev. June 2026).”
  • HR Dive points out,
    • “The U.S. Equal Employment Opportunity Commission plans to end employee demographic data reporting, according to a proposal sent to the White House on Thursday.
    • “The agency wants to get rid of EEO-1, EEO-2, EEO-3, EEO-4 and EEO-5 reporting requirements. EEOC also wants to axe reporting requirements related to Title VII of the Civil Rights Act, the Americans with Disabilities Act, the Genetic Information Nondiscrimination Act and the Pregnant Workers Fairness Act.
    • “EEO-1 reporting has been a cornerstone of HR duties, required by firms with 100 or more employees and federal contractors with 50 or more employees that meet certain requirements. EEOC and analysts have used it to assess demographic data nationally, and — while the process is sometimes viewed as burdensome — employers have reportedly used the collected data for self-assessments regarding nondiscrimination and diversity.”
  • The Census Bureau notes,
    • “Since 2020, city centers of many major U.S. metro areas have had sluggish population gains, with some places even declining. But where growth did occur, it was mostly on the outer edges of these metro areas — with some exceptions.”

From the Food and Drug Administration front,

  • Fierce Pharma reports,
    • “With the ink barely dry on outgoing commissioner Marty Makary’s resignation, another top regulator may be heading for the exit at the FDA. 
    • “Tracy Beth Høeg, M.D., Ph.D.—who was named acting director of the agency’s Center for Drug Evaluation and Research (CDER) following the departure of veteran oncologist Richard Pazdur, M.D., last December—is now expected to depart in Makary’s footsteps, Reuters reported Friday, citing three sources familiar with internal plans at the regulator.” * * *
    • “Reuters clarified in its report that the CDER chief’s departure is likely, but that the decision has not yet been finalized.” 
  • and
    • “With the help of DNA testing company Natera and its personalized molecular residual disease (MRD) blood test Signatera, Roche’s PD-L1 inhibitor Tecentriq has chalked up its eleventh U.S. indication in the form of a new bladder cancer approval.
    • “Tecentriq and subcutaneous Tecentriq Hybreza can now be used as an adjuvant treatment for adult patients with muscle-invasive bladder cancer (MIBC) who have circulating tumor DNA molecular residual disease (ctDNA MRD) following a cystectomy, as identified by Signatera.” 
       
  • Biopharma Dive relates,
    • “The Food and Drug Administration has placed a clinical hold on Aardvark Therapeutics’ drug for Prader-Willi Syndrome, escalating a trial stoppage that began when signs of potential heart problems were detected in a study of healthy volunteers. 
    • “Aardvark said Thursday it will “unblind,” or reveal which enrollees in a late-stage trial received ARD-101, in order to help investigators and regulators determine whether the drug is safe and effective enough to continue testing in humans.
    • “The company has dosed 68 people in the placebo-controlled Phase 3 trial and another 19 in an open-label extension study, both which were intended to measure whether ARD-101 can address the “hyperphagia,” or insatiable hunger, distinctive to Prader-Willi. The cardiovascular concerns emerged from a safety trial in healthy people who’d received much higher doses than what was administered in the other studies.” 
  • Cardiovascular Business tells us,
    • “Stryker Sustainability Solutions, an Arizona-based division of Stryker focused on reprocessing single-use medical devices, has recalled certain lots of several reprocessed electrophysiology (EP) catheters. The recall, which covers more than 8,000 devices overall, was initiated after the company identified incomplete seals due to a process control issue.
    • “According to the U.S. Food and Drug Administration (FDA), this is a Class II recall. This means the agency believes the devices “may cause temporary or medically reversible adverse health consequences.”
  • The Wall Street Journal points out,
    • “Twenty people in Japan who took Amgen’s rare-disease drug Tavneos have died, and at least 22 developed a potentially fatal liver injury, according to Kissei Pharmaceutical, which sells the medicine in the country.
    • “Kissei told doctors Friday to stop prescribing the drug to new patients.
    • “The Japanese drugmaker said the 20 deaths occurred in people who had suffered a serious liver “impairment” and attributed 13 of the deaths to a condition, called vanishing bile duct syndrome, marked by the destruction of the ducts that carry bile out of the liver.
    • “Kissei said causal links to Tavneos hadn’t been confirmed in all 20 deaths.” * * *
    • “The medicine went on sale in Japan in 2022, according to Kissei. Also that year, Amgen bought the drug’s developer, ChemoCentryx, for $3.7 billion.
    • “In January, the FDA asked Amgen to voluntarily pull the drug from the U.S. market, but Thousand Oaks, Calif.-based Amgen refused.
    • “Then in March, the FDA said it had identified 76 global cases of serious liver injury linked to Tavneos, including eight deaths. Most were reported in Japan. Of the 76 global cases the FDA identified, seven involved the syndrome, and three of those patients died.
    • “In late April, the FDA moved to formally begin withdrawal proceedings.”

From the public health and medical / Rx research front,

  • The Centers for Disease Control and Prevention announced today,
    • “As of May 15, 2026, the amount of acute respiratory illness causing people to seek health care is very low.
    • “RSV activity started later than expected in most regions of the United States, though illness is not more severe compared with recent seasons. RSV activity has peaked in many regions of the country. This unusual timing means higher levels of RSV activity may continue into May for some regions.
    • “COVID-19 activity is low in most areas of the country.
    • “Seasonal influenza activity is low.”
  • The University of Minnesota’s CIDRAP reports,
    • “The Centers for Disease Control and Prevention (CDC) today confirmed 51 new measles cases in a nationwide outbreak that has now reached 1,893 infections. All but nine cases are locally acquired, with the rest related to international travel.
    • “The agency reported two new outbreaks, for a total of 27. Last year the nation saw 48 outbreaks and 2,288 cases for the entire year. The United States could top that total in the coming months.
    • “Of this year’s cases, 21% involve children younger than 5 years, and 76% involve kids and young adults up to 19 years. Among all 2026 patients, 92% have been unvaccinated or have an unknown vaccine status. Six percent of patients this year have been hospitalized, compared with 11% last year.”
  • The American Hospital Association News relates,
    • “A Centers for Disease Control and Prevention report released May 14 found that U.S.-reported dengue cases in 2024 increased 359% above the annual average from 2010-2023. Dengue is a mosquito-borne viral disease that can cause mild to severe illness and death. There were 3,798 cases reported to the CDC in 2024, compared to the average of 828 from 2010-2023. The report found that 97.2% of cases in 2024 were travel-associated and that 2.8% were acquired locally. Individuals age 50-59 accounted for 21.8% of cases, and 57.5% of cases occurred in Hispanic or Latino individuals. In addition, 36.1% of patients were hospitalized and a total of six patients died. Most travel-linked cases were acquired in the Caribbean (34.1%), North America (24.3%) and Central America (15.6%).” 
  • Health Day informs us,
    • People who have survived a heart attack appear to have a higher risk of brain decline into dementia, a new study says.
    • On average, heart attack survivors have a yearly 5% increased risk of developing cognitive impairment, researchers reported today in the journal Stroke.
    • “Having had a heart attack in the past may speed up the decline in memory and thinking over time,” said lead researcher Dr. Mohamed Ridha, an assistant professor of neurology at Ohio State University in Columbus.
    • “Given the rising burden of dementia and cognitive decline among Americans, it is important to understand how cardiovascular disease affects their brain health,” Ridha said in a news release. “This knowledge can help heart attack survivors take steps to improve their brain health as they age.”
  • and
    • “Offering sigmoidoscopy screening reduces colorectal cancer (CRC) incidence in men and women — with a greater reduction among men — and reduces CRC mortality in men, according to a study published online May 12 in the Annals of Internal Medicine.
    • “Edoardo Botteri, Ph.D., from the Norwegian Institute of Public Health in Oslo, and colleagues report on the benefits of sigmoidoscopy after 23 years in a randomized controlled trial involving persons aged 50 to 64 years. A total of 100,210 persons were randomly assigned to screening with once-only sigmoidoscopy with or without one fecal immunochemical test or to no screening. The intention-to-screen analyses included 98,654 persons: 20,552 in the screening group and 78,102 in the no-screening group.
    • “The researchers found that the 23-year cumulative risk for CRC was 4.3 and 6.0 percent in the screening and no-screening groups, respectively, among men. The corresponding risks were 4.2 and 4.7 percent among women. In men, the 23-year cumulative risk for CRC death was 1.4 and 2.2 percent in the screening and no-screening groups, respectively, while in women, the corresponding risks were 1.3 and 1.4 percent. The strongest effect was seen for rectosigmoid cancer. Screening benefits were not changed with the addition of fecal blood testing.”
  • Healio adds,
    • “The survival benefit conferred by lung cancer screening in real-world settings may be smaller than observed in the pivotal trial on which national screening guidelines are based, study results suggest.
    • “Veterans receiving primary care in the VA health system exhibited a threefold higher risk for all-cause mortality than participants in the randomized National Lung Screening Trial (NLST) who had similar age and tobacco history.
    • “This is one of the first times we have been able to directly compare people who were enrolled in the trial with people in a real-world cohort who are eligible for screening,” Alison S. Rustagi, MD, PhD, assistant professor in University of California San Francisco’s department of medicine, told Healio. “It is not often that we see hazard ratios on the order of 3 in observational analyses. This shows a profound difference between these two populations.”
  • Per Medscape.
    • “Orforglipron, an oral GLP-1 receptor agonist, helps maintain weight loss after injectable therapies like tirzepatide and semaglutide, offering a practical continuation option for patients. Cardiometabolic benefits are largely preserved despite some weight regain.”
  • Per an National Institutes of Health news release,
    • “A group of pediatric eye disease researchers supported by the National Institutes of Health (NIH) has launched an open-access tool designed to help manage pediatric cases of amblyopia, a condition in which the brain fails to properly develop normal vision in one or both eyes early in life. It is the leading cause of preventable single-eye (monocular) vision loss, affecting three of every 100 children in the nation. The tool is aimed at expanding access to evidence-based amblyopia clinical-decision-making expertise amidst a shortage of pediatric eye care specialists in the United States.
    • “This online tool quickly distills the relevant literature into individualized treatment advice for busy clinicians anywhere with internet access. Those without internet access can utilize the article figures as clinical reference sheets,” said article lead author, Allison Summers, O.D., associate professor, Oregon Health & Science University, Portland.” * * *
    • “Known as the Amblyopia Navigator Decision-Support Instrument (ANDI), the tool is designed to guide any eye doctor through the diagnosis of amblyopia. Once amblyopia is diagnosed, ANDI helps to guide the eye care clinician without specialty training in pediatric eye care through management options. The tool helps the eye doctor determine the best glasses prescription for the patient based on a few clinical findings. The tool also helps the doctor determine how long to monitor whether glasses alone are improving vision, which can work for up to a third of children without any further treatment.
    • “If glasses are not enough, ANDI walks the eye doctor through next steps: patching the stronger eye for a couple of hours a day, using atropine eye drops to temporarily blur the stronger eye, or considering newer digital treatments delivered through specially designed games or videos. If a child stops making progress, the tool advises whether to increase the intensity of treatment, switch approaches, reassess the glasses prescription, or refer to a specialist. It provides steps for follow-up visits and what signs of recurrence to watch for after treatment ends. The tool can be used at an initial visit, or any follow-up visit in their amblyopia care journey.
    • “ANDI was developed by PEDIG, an NIH-funded research network with over 400 investigators, and it draws on evidence from 147 published studies. To access ANDI, go to https://public.jaeb.org/pedig.”

From the U.S. healthcare business and artificial intelligence front,

  • Mercer consulting offers “bold strategies” for payers to better control high cost members.
    • “While stop-loss coverage can help mitigate risk, many employers are finding it’s no longer enough. Unsurprisingly, “more focused management of high-cost claimants” is the top priority of large US health plan sponsors in their strategic planning for the next few years. In this post, we’ll discuss four areas where focused efforts can help employers rein in costs.”
      • Understand your data: Analyzing claims to gain clarity. 
      • Strategic oversight of medical specialty pharmacy and gene/cell therapies. 
      • Take a peekaboo view into neonatal intensive care unit management. 
      • Outlier inpatient stays.
  • Fierce Healthcare reports,
    • “CVS’ Omnicare unit has secured court approval to sell its business to virtual care company GenieRx Holdings, the healthcare giant announced Thursday.
    • “GenieRx, which offers an array of virtual health and medication services, is a joint partnership between Milrose Capital, a private equity firm, and Integro Asset Management, a healthcare-focused investment firm. Per court documents, the deal includes $250 million in cash as well as certain other liabilities, such as payroll expenses.
    • “In the announcement, CVS said that in combining with GenieRx, Omnicare will “have the opportunity to strengthen its service.” It will also continue to support it current clients in the lead up to closure, which is expected later this year, pending needed regulatory approvals.”
  • Beckers Hospital Review discusses “three barriers to GLP-1 adherence — and how systems are overcoming them.
    • Patients discontinue therapy early
    • Care models incompatible with sustained support
    • Costs and side effects deter patients.
  • Fierce Pharma tells us,
    • Total prescriptions for Eli Lilly’s Foundayo reached 10,248 for the week that ended May 8, up from 7,335 the prior week, according to IQVIA data cited by Citi. While still on the rise, Foundayo’s growth pace continued to lag behind that of Novo Nordisk’s Wegovy pill during the same stage of their launch. 
    • Wegovy’s total scripts rose by 1.3% week over week to nearly 446,000, as its share in the obesity GLP-1 market climbed 0.1 percentage point to 40.5%, according to Citi.
    • However, Wegovy’s growth apparently didn’t come from its oral formulation. Wegovy pill scripts landed at about 137,000 for the week, down from roughly 143,000 the prior week, marking the first time that the pill’s scripts have fallen since the oral launch in early January.
    • Scripts from the Wegovy pill made up 31% of total Wegovy scripts for the period, down 2 percentage points from the previous week. Still, Citi analysts argued that this roughly one-third of share “suggests preferences for oral formulations.”
    • Even as Wegovy gained ground, Lilly’s Zepbound remained the obesity market leader, with 59.5% share, as its nearly 656,000 scripts marked 0.8% growth week over week. 
  • Beckers Payer Issues offers payer perspectives on artificial intelligence tools.
    • “Using AI solutions to augment the work done by humans is an attractive solution for many payers.
    • “Getting started with these technologies, however, can feel daunting.
    • “To learn more about what it takes for payers to successfully incorporate AI and support more members, Becker’s Healthcare recently spoke with Chris Caramanico, CEO of Elligint Health, Amy Qureshi, RN, executive vice president of product strategy at Elligint Health, and Steven Tolle, chairman of the board at Elligint Health. Mr Tolle has significant experience developing and implementing AI from his time at IBM, Merge and IgniteData and addition serves as Chief of AI Strategy at Elligint Health.”
  • Fierce Healthcare adds,
    • Nearly 80% of payers now prefer implementing vendor-built artificial intelligence tools rather than developing internal capabilities, a new survey from Innovaccer found.
    • The survey draws insights from 63 health insurer organization leaders, including regional health plans to national carriers, the healthcare technology and AI company said in a press release. Respondents were polled in mid-December 2025 to mid-January, and include senior and C-suite executives.
    • Innovaccer CEO and co-founder Abhinav Shashank told Fierce Healthcare that the shift to outsourced solutions reflects the focus of how to “truly operationalize AI.” 
    • “What we are seeing is an emergence of how do you have platforms that companies can effectively offer that allow for more agentic orchestration,” Shashank said. “Because the reality of it is the technology is going to be a massive addition to how payers operate.” 
  • NBC News relates,
    • “Over the past two years, medical providers across America have quietly embraced a new AI tool called OpenEvidence to help them make clinical decisions, brush up on medical knowledge and even prepare for their licensing exams. The service, a sort of chatbot for doctors, was used by about 65% of U.S. doctors across almost 27 million clinical encounters in April alone, the company told NBC News.
    • “Everyone is using it,” said Dr. Anupam Jena, an internal medicine physician at Massachusetts General Hospital in Boston and a professor of healthcare policy at Harvard. “Its growth really has been exponential.”
    • “NBC News spoke with over two dozen doctors, hospital administrators, medical students and healthcare researchers from Hawaii to Maine to explore the rise of OpenEvidence. Each individual said they either used it regularly themselves or knew someone who did.
    • “Almost two-thirds of physicians — or roughly 650,000 doctors — in the U.S. actively use OpenEvidence, while another 1.2 million use it internationally, OpenEvidence representatives said. With its quick and tailored replies, OpenEvidence has become an AI-era equivalent of consulting a colleague for their expert opinion, though the software can also write patient discharge notes and provide custom study tools for doctors’ medical exams.”

Tuesday report

From Washington, DC,

  • The American Hospital Association News adds,
    • “The Department of Health and Human Services Administration for Community Living has launched the first phase of its Health at Home Challenge, a competition to support community care networks that have partnered with health care providers supporting dually eligible Medicare and Medicaid beneficiaries. Each phase of the competition offers up to $2 million in prize funding for winning teams. The first phase, currently underway and continuing through July, will reward up to 10 teams for implementation strategies to scale comprehensive services that reach high numbers of dually eligible and near-dually eligible beneficiaries. The second phase will reward up to five teams for accelerating implementation of winning strategies from the previous phase. Phase three will reward up to three teams for demonstrating the scale and impact of the winning programs selected from phase two.”
  • Federal News Network reports,
    • “Federal employee workplace disputes are coming under more scrutiny from a top committee Republican who argues that agencies have an “excessive reliance” on reaching case settlements rather than pursuing litigation.
    • “House Oversight and Government Reform Committee Chairman James Comer (R-Ky.) is raising concerns over what he described as high numbers of “sue-and-settle” cases involving federal employees. He suggested that if agencies litigated more cases, they would likely win more often.
    • “Comer’s letter, sent this week to the Office of Personnel Management, cited Merit Systems Protection Board data from fiscal 2005 to fiscal 2015 that showed during that time, 68% of federal employee cases reached settlements. And out of cases that were litigated, more than 80% of agency adverse action decisions were upheld.”

From the Food and Drug Administration front,

  • The Wall Street Journal reports,
    • “Food and Drug Administration Commissioner Marty Makary resigned Tuesday after months of policy fights with top officials in the Department of Health and Human Services and the White House.
    • “His departure became official after President Trump signed off last week on a plan to fire Makary, The Wall Street Journal previously reported. Makary offered his resignation, effective Tuesday.
    • “Everybody wants that job,” Trump said. “Marty is a terrific guy and he’s going to go on and lead a good life. He was having some difficulty.” He added on his Truth Social platform that Kyle Diamantas, the deputy commissioner for food, would take over leading the agency in an acting capacity.
    • “The president also posted a text message from Makary that included his resignation and a list of what he considered his accomplishments, such as reducing drug-review times. “It’s been the honor of a lifetime to serve as your FDA Commissioner. I am forever grateful,” Makary said.”
  • MedTech Dive reports,
    • “Artera has received Food and Drug Administration clearance for an artificial intelligence tool that predicts the likelihood of a certain form of breast cancer developing distant metastases.
    • “The clearance, which Artera disclosed Wednesday, covers technology that uses histopathology images and clinical variables to stratify patients into low- and high-risk groups.
    • “Insights into the risk of distant metastases could improve decisions about the use of treatments including chemotherapy, the company said.”
  • and
    • “Johns Hopkins University spinoff Bayesian Health received 510(k) clearance for an artificial intelligence tool to help detect sepsis early.
    • “Sepsis is a life threatening response to infection. Detecting sepsis earlier can improve a patient’s chance for survival. Once a clinician suspects sepsis, the clock has been running, often for hours or even days, Bayesian Health founder and CEO Suchi Saria said in a Tuesday statement.
    • “Other Food and Drug Administration-authorized sepsis tools on the market require a physician to suspect sepsis first. Bayesian’s system, which uses electronic health records and AI, can detect sepsis nearly two to 48 hours faster than traditional methods, the company said.”
  • The American Hospital Association notes,
    • “The Food and Drug Administration has identified a Class I recall of convenience kits by Aligned Medical Solutions that contain recalled Namic Angiographic Control Syringes by Medline.”

From the public health and medical / Rx research front,

  • STAT News reports,
    • “Alcohol is wreaking havoc on U.S. public health. American society looks the other way.”
    • “Confronting heavy drinking could be one of the best ways to improve health and save lives.”
    • * * * “Of 178,000 deaths that occur each year from alcohol, roughly one-third are from causes like car crashes and alcohol poisoning. The rest are from cancer, heart disease, liver failure, and other chronic conditions that result from sustained heavy drinking. As far as drugs are concerned, alcohol’s toll is only outpaced by the prolonged damage of tobacco. 
    • :But though the U.S. has dramatically cut tobacco use, it has never made a serious effort to curb alcohol-related harms other than in the infamous era of Prohibition. Over twice as many Americans consumed alcohol in 2024 than used tobacco products, federal estimates suggest.” * * *
    • “Recent polls suggest drinking levels have reached historic lows in the U.S., with about half of adults abstaining. Last year, while much of the alcohol industry struggled against new headwinds, the nonalcoholic sector grew. Companies launched alcohol-free products and shifted their marketing to align with health-conscious customers. 
    • “Strikingly, there is little evidence that the mocktail trend is driving actual health improvements, experts told STAT. That may be because of lagging data. Or it may reflect how in many cases, market research suggests drinkers are adding nonalcoholic beverages to their rotation, rather than switching over entirely. The groups that could most benefit from cutting back, including heavy drinkers, may not be interested at all.
    • “Meanwhile, heavy and binge drinking — practices known to be particularly harmful to health — have remained at pandemic levels among key groups, including older adults and teenagers. Five million underage people used alcohol in 2024, and over half of those 12 to 20 years old engaged in binge drinking, defined as four or more drinks in one sitting for women, or five for men.”  
  • MedPage Today relates,
    • “Despite improvements in survival, the incidence of stage IV breast cancer increased significantly from 2010 through 2021, according to a U.S. population-based cohort study.
    • “The age-adjusted incidence rate of de novo stage IV breast cancer significantly increased from 9.5 cases per 100,000 females in 2010 to 11.2 cases in 2021, an annual percentage change (APC) of 1.2% (95% CI 0.8-1.6), reported José P. Leone, MD, of the Dana-Farber Cancer Institute in Boston, and colleagues.
    • “Among males, there was also a statistically significant increase in stage IV incidence, from 0.12 cases per 100,000 in 2010 to 0.20 cases in 2021, an APC of 3.7% (95% CI 1.0-6.5), they noted in JAMA Network Open.
    • “Moreover, the incidence of stage IV breast cancer increased significantly across age groups and numerically across all races and ethnicities.”
  • and
    • “Two non-pharmaceutical approaches for irritable bowel syndrome (IBS) feasibly offered patients symptom relief, according to research presented at the annual Digestive Disease Week meeting. 
    • “In a post-hoc analysis of a small single-arm trial, IBS patients’ mean scores on a 0-100 scale dropped from baseline for pain (37 to 21.6), discomfort (48.4 to 27.4), distention (54.8 to 30.9), and bloating (54.4 to 31.8) after 2 weeks of an oral, palatable elemental diet followed by a 2-week follow-up period, reported researchers led by Ali Rezaie, MD, of Cedars-Sinai Medical Center in Los Angeles.
    • “Even after reintroduction of a regular diet, “a 2-week elemental diet significantly improved abdominal pain and other IBS symptoms across subtypes using FDA-recommended responder endpoints,” Rezaie and colleagues wrote in their poster. “Larger, long-term studies are needed to confirm durability and understand how it works.”
    • “And in a sham-controlled randomized trial, people with IBS who used a virtual reality (VR) program to deliver cognitive behavioral therapy (CBT) reported greater symptom improvement after 8 weeks, with scores of 244.3 versus 295.6 with sham on a 0-500 scale where higher numbers indicate more severe symptoms (P=0.026), reported Christopher Almario, MD, of Cedars-Sinai Medical Center, and colleagues.”
  • Health Day informs us,
    • “About 8,500 steps a day may be the sweet spot for keeping weight off after dieting, new research shows.
    • “The findings — recently published in the International Journal of Environmental Research and Public Health — are also scheduled for presentation this week at the European Congress on Obesity in Istanbul.
    • “The most important — and greatest — challenge when treating obesity is preventing weight regain,” said lead researcher Marwan El Ghoch, a professor in biomedical, metabolic and neural sciences at the University of Modena and Reggio Emilia in Italy. 
    • “Around 80% of people with overweight or obesity who initially lose weight tend to put some or all of it back on again within three to five years,” he said. “The identification of a strategy that would solve this problem and help people maintain their new weight would be of huge clinical value.”
  • The Wall Street Journal lets us know,
    • “Novo Nordisk said certain patients on its higher-dose Wegovy shot lost 27.7% of their body weight on average in a trial.
    • “The Danish drugmaker said those patients who reacted faster to treatment by losing at least 15% of their weight after the first six months went on to achieve the nearly 28% total weight loss after about a year and a half.
    • “The company said the majority of the weight loss, around 84%, from using its Wegovy shots comes from losing body fat while preserving muscle function and improving muscle health.
    • “The data was presented at the European Congress on Obesity in Turkey.”
  • Cigna Health, writing in LinkedIn, discusses how employers can take advantage of Mental Health Awareness Month.
    • “Key Takeaways
      • “Offering mental health benefits is not enough—employees need a clear, guided path to find, understand, and use them.
      • “Benefits literacy is a productivity lever—clear navigation can reduce delays in care and protect vitality.
      • “Small design moves—one starting point, steady education—make the difference between availability and utilization.”
  • Fierce Healthcare considers “the broken pipeline of mental healthcare for LGBTQ teenagers.”
  • Beckers Hospital Review identifies the sixteen hospitals recognized by HealthGrades for deserving Outstanding Patient Experience, Patient Safety Excellence, and America’s Best Hospitals distinctions for 2026.
    • The organization evaluated 3,020 hospitals that submitted at least 100 patient experience surveys to CMS’ Hospital Consumer Assessment of Healthcare Providers and Systems between January and December 2024. Hospitals were evaluated on patient survey data on 10 patient experience measures. Recipients of the outstanding patient experience award earned the highest overall experience scores.
  • Fierce Pharma points out,
    • “Alkermes has chalked up a quick clinical win from its $2.37 billion acquisition of Avadel, reporting Tuesday that a phase 3 study of the sodium oxybate Lumryz met all primary and key secondary endpoints in a rare sleep disorder.
    • “The positive readout from the Revitalyz trial in idiopathic hypersomnia comes three months after Alkermes bagged Lumryz upon closing the Avadel buyout. By demonstrating its ability to significantly reduce daytime sleepiness and other symptoms, Lumryz is moving one step closer to helping Avadel investors realize the deal’s full value.”

From the U.S. healthcare business and artificial intelligence front,

  • Yesterday, the FEHBlog linked to a Modern Healthcare article about Optum Rx’s decision to implement a “new pharmacy care model that fundamentally changes how pharmacy benefits are priced and delivered — replacing traditional approaches tied to drug prices set by manufacturers or prescription volume with a transparent, fee‑based structure offered to every Optum Rx PBM customer. Here is a link to OptumRx’s news release about this decision.
  • Healthcare Dive adds,
    • “Employers are looking for a simpler pharmacy benefits model, particularly an approach that eliminates rebates to send savings directly to patients, according to a survey released last week.  
    • “More than 90% of employers surveyed agreed a rebate-free model would improve transparency into prescription drug prices, according to the research by communications and reputation management firm Penta Group for Evernorth Health Services, which operates the Express Scripts pharmacy benefit manager. 
    • “Additionally, 91% said an approach that removed rebates is easier to understand, and 90% reported it would improve employee satisfaction and drug affordability.” 
  • Fierce Healthcare relates,
    • “Providence’s turnaround efforts are continuing to gain steam, securing the 51-hospital nonprofit a $111 million net operating income (1.5% operating margin) for the start of 2026 and its third consecutive quarter on the right side of zero. 
    • “Financial performance numbers released Monday afternoon showed a roughly $360 million year-over-year operating improvement, when it had logged a -3.5% operating margin. Compared to then, Providence grew its operating revenues by 4.1%, to nearly $7.5 billion, while shrinking its operating expenses by 0.9%, to a bit over $7.3 billion. 
    • “The numbers, Providence said, reflect “deliberate steps” it’s taken over the past couple of years to reverse longstanding losses and generally tighten up the ship as financial headwinds, such as Medicaid funding cuts, loom for providers. 
    • “These, the West Coast system said in a release, include “streamlining its leadership structure, reducing duplication of services, renegotiating commercial payer contracts and sharpening its focus on core services—including transferring ownership or partnering with others on non‑core services.” 
  • Fierce Pharma tells us,
    • “Since Roche launched its long-acting eye disease medicine Vabysmo in 2022, Bayer and Regeneron have seen the impact on sales of their rival treatment Eylea, with the U.S. biotech taking a bigger hit.
    • “Bayer has managed to keep its annual Eylea sales relatively stable as they have toggled between 3.1 billion euros and 3.3 billion euros in each of the last four years. But that’s coming to an end this year as biosimilar competition is hitting the German company with full force.”
    • “In the first quarter (PDF), Bayer’s Eylea sales were down 24% year over year to 623 million euros ($731 million). They also declined sequentially by 11%. None of this is a surprise as Bayer has projected Eylea sales to drop 20% to 25% this year.”
    • “However, it wasn’t all bad news for Bayer’s Eylea franchise, as Chief Financial Officer Wolfgang Nickl cited “continued positive volume development” for Eylea’s longer-acting 8 mg formulation, which now accounts for 46% of the company’s overall Eylea sales.”
  • Beckers Health IT informs us,
    • “Cleveland Clinic’s quantum computing program has moved from a pilot phase to a fully operational “innovation engine” integrated with AI, according to Lara Jehi, MD, chief research information officer at the health system.
    • “It’s been a whirlwind, and we’ve made much more progress — and much faster — than we originally anticipated,” Dr. Jehi told Becker’s.
    • “Cleveland Clinic started its quantum computing journey in 2023 when the organization formed a 10-year partnership with IBM to create a joint accelerator center to advance healthcare discoveries using AI and cloud computing. As part of that deal, IBM installed its first private-sector, on-premise quantum computing system in the U.S. at Cleveland Clinic. The quantum computer, dubbed IBM’s Quantum System One, is dedicated to healthcare research and was installed at the Lerner Research Institute on Cleveland Clinic’s main campus.”

Weekend update

Happy Mothers Day!

  • Per an HHS news release,
    • “On Mother’s Day, the U.S. Department of Health and Human Services launched Moms.gov, a groundbreaking website for new and expecting mothers. This first-of-its-kind resource offers guidance and information to support the health and well-being of mothers and their families.
    • “Moms.gov also supports expecting parents who are navigating difficult or unexpected pregnancies. It features information about pregnancy centers, Federally Qualified Health Centers, nutritional guidance, Trump Accounts, and other resources that allow maternal and infant health to thrive.”
  • Per a Labor Department news release,
    • “The U.S. departments of Labor, Health and Human Services, and Treasury announced a proposed rule that would create a new category of limited excepted benefits to further expand the ability of employers to offer meaningful fertility benefits to their employees. 
    • “The proposed rule is a central component of the Trump administration’s efforts to expand American families’ access to fertility benefits. It builds upon President Trump’s Executive Order “Expanding Access to In Vitro Fertilization,” which announced that it is the policy of the administration to ensure reliable and affordable access to in vitro fertilization to support American families.” * * *
    • “The proposed rule would establish a new category of limited excepted benefits. Excepted benefits are generally exempt from the market reforms under the Affordable Care Act and certain other federal health care coverage laws. This new category would apply limiting principles similar to those already in place for other limited excepted benefits. 
    • “The proposed rule sets a few main requirements for the benefits: 
      • “Substantially all of the benefits must be for diagnosis, mitigation, or treatment of infertility or related reproductive health conditions.
      • “Benefits are capped at a combined lifetime maximum of up to $120,000 for the participant and their beneficiaries, indexed for inflation for plan years starting after 2028.
      • “Employers must provide a notice that clearly describes the coverage and meets other specified requirements.
    • “Comments are due 60 days from its publication in the Federal Register. 
    • Read the notice of proposed rulemaking on limited excepted fertility benefits.”
  • While the FEHBlog has not yet read the proposed rule, he noticed that the proposed rule amends the Public Health Service Act and therefore may impact the FEHB and PSHB programs.

From Washington, DC,

  • Tomorrow, the Senate will take a final vote on S. Res. 690, “authorizing the en bloc consideration in Executive Session of (49) certain nominations on the Executive Calendar.” The FEHBlog does not notice any noteworthy nominations on that list.
  • Here is a Roll Call discussion of other actions under consideration on the Hill this week.
  • Federal News Network reports,
    • “The Postal Service is floating the possibility of Congress stepping in to provide more financial assistance to keep the largely self-funded agency from running out of cash early next year.
    • “Postmaster General David Steiner said USPS hasn’t officially pitched the idea to Congress, but it’s an option lawmakers should consider to get the agency on firmer financial footing. Steiner said USPS will spend the next month refining its wish-list of legislative proposals before sharing it with Congress.
    • “Steiner told members of the House Oversight Committee in March that USPS will run out of cash in early 2027, as long as it continues to pay its bills on time. But USPS is relying on some emergency measures to conserve cash.
    • “To the credit of Congress, they’re not looking for short-term band-aids, but for long-term solutions,” Steiner said Friday at a public meeting of the USPS Board of Governors.”

From the public health and medical / Rx research front,

  • The Wall Street Journal reports,
    • ‘The U.S. Centers for Disease Control and Prevention is sending staff to the Canary Islands to meet a cruise ship with a hantavirus outbreak.
    • “The MV Hondius has a hantavirus outbreak that has killed three people and infected five others; the rare Andes variant is confirmed.
    • “Seventeen American passengers from the ship will be quarantined at the University of Nebraska Medical Center’s National Quarantine Unit.” * * *
    • “The facility looks more like a hotel than a hospital. People quarantining at the center are asked not to leave their rooms and receive, essentially, room service brought to their door, said Dr. Michael Wadman, medical director of the National Quarantine Unit at University of Nebraska Medicine.” * * *
    • “If any cruise ship passengers are quarantined and develop symptoms, they will be moved to the nearby Nebraska Biocontainment Unit—a facility isolated from the rest of Nebraska’s medical center, designed to treat patients infected with highly hazardous infectious diseases, according to Nebraska Medicine.
    • “A CDC official said Saturday that ship passengers will be monitored for around six weeks, or 42 days, but not necessarily only in Nebraska. The official said authorities will coordinate with some passengers and local jurisdictions for at-home monitoring, though it wasn’t clear how many people were going home or when.”
  • MedPage relates,
    • “The CDC has issued a Health Alert Network (HAN) health advisory on hantavirus, urging clinicians to be aware of the potential for imported cases of hantavirus disease in connection with an outbreak of Andes virus aboard a cruise ship.
    • “While the risk of broad spread in the U.S. is “considered extremely unlikely at this time,” the agency noted that early symptoms can be easily confused with influenza or other viral illnesses. In addition, the virus may not be accurately detected in body secretions and excretions within the first 72 hours of symptom onset, so testing should be repeated after that window, the agency warned. * * *
    • “Several state health departments — including Arizona, California, Georgia, and Texas — confirmed to MedPage Today that they are monitoring individuals in their respective states. New Jersey also is monitoring two peopleopens in a new tab or window who were on the same flight as a woman who was symptomatic on board and later died.”
  • The Wall Street Journal tells us “After the hantavirus uutbreak here’s what cruise travelers should know.”
    • “The hantavirus outbreak aboard the MV Hondius has revived memories of Covid-era cruise chaos. Infectious-disease doctors say the current situation is very different.”
  • The Wall Street Journal also reports,
    • “A study of more than 57,000 iPhone users confirmed a correlation between hearing loss and slower walking speeds.
    • “The Apple and University of Michigan study used data people agreed to share via Apple’s Research app.
    • “Doctors state addressing hearing issues could lead to a longer, healthier life and recommend annual hearing tests.”
  • Healio informs us,
    • “Among adults with obesity, the risk for new physician-reported sleep apnea and new-onset obstructive sleep apnea significantly fell if they used vs. did not use a GLP-1 agonist, according to data from two studies.
    • “Both studies were published in Annals of the American Thoracic Society.

From the U.S. healthcare business and artificial intelligence front,

  • HR Dive reports,
    • “The merit increases employers awarded this year were only slightly below previous projections, with a mean 3.1% merit increase, versus a 3.2% projection in October 2025, according to the latest Mercer QuickPulse Compensation Planning Survey.
    • “Average total increases were 3.4%, versus a predicted 3.5%, per the report. 
    • “Meanwhile, just 4% of employers gave workers equal, across-the-board salary increases, also called “peanut butter” raises, rather than merit increases, Mercer found. Most still use a combination of individual performance and position relative to market value or relative to peers.”
  • Healio relates,
    • “The AI tools that benefit clinicians most are not always the glamourous ones contributing to drugs, robotics and therapeutics innovations, but could also be the mundane ones that help ease physician burnout. 
    • “That is according to David Ting, MD, keynote speaker at Digestive Disease Week.
    • “Ting, chief clinical product lead at Microsoft and primary care internist and pediatrician at Massachusetts General Hospital, told attendees he envisions a 2036 where AI products assist with the ordinary: workflow redesign, administrative burden and workplace collaboration.
    • “AI also might one day take center stage in reshaping the clinical environment and restoring the “joy of practice,” he said.”
  • BioPharma Dive tells us,
    • “Odyssey Therapeutics, a maker of medicines for autoimmune disorders, has brought in $279 million through an initial public offering that’s been more than a year in the making.
    • “Selling 15.5 million shares at $18 each, Odyssey on Thursday raised more than what it expected and became the latest drug company of late to top $250 million in IPO proceeds. The company also added another $25 million to its haul via a concurrent private stock sale at the IPO price. Odyssey is now the 11th biotech company to go public so far this year, according to BioPharma Dive data, and will start trading on the Nasdaq stock exchange on Friday under the ticker symbol “ODTX.”
    • “Odyssey is led by Gary Glick, a biotech veteran who’s led multiple drug startups that were later acquired. Glick launched the company in 2021 with backing from the likes of OrbiMed and SR One, and it’s since netted $727 million in venture funding.”
  • Healthcare Dive informs us,
    • “Staffing technology company Cross Country Healthcare has entered into an agreement to be acquired by private equity firm Knox Lane in an all-cash deal worth $437 million.
    • “The acquisition, which will take Cross Country private, values the company at $13.25 per share, a 31% premium over the staffing firm’s closing stock price on Wednesday, according to a press release. It’s expected to close in the third quarter if the deal clears regulatory approval.
    • “The deal comes months after Cross Country and travel nursing agency Aya Healthcare abandoned plans to combine following antitrust scrutiny from the Federal Trade Commission.”
  • That’s a better outcome than Spririt Airlines experienced.  

Cybersecurity Saturday

From the Iranian war front,

  • Cybersecurity Dive reports,
    • “A threat group linked to Iranian intelligence has been running a months-long false-flag operation to hack organizations in the U.S. and other countries under the guise of a criminal ransomware group, according to a report released Wednesday [May 6] by researchers at Rapid7. 
    • “The state-sponsored threat group, tracked as MuddyWater, operated a social engineering campaign beginning in early 2026 that abused Microsoft Teams to harvest credentials and bypass multifactor authentication. 
    • “The attacks were made to look as if they were the work of Chaos, a ransomware-as-a-service group that has been active since 2025. Researchers said the false flag creates ambiguity that could affect how security teams investigate an intrusion. 
    • “If an operation looks like ransomware, defenders may initially treat it as financially motivated cybercrime rather than a state-linked operation,” Christiaan Beek, vice president of cyber intelligence at Rapid7, told Cybersecurity Dive. “That can slow attribution, complicate response, and give the actor plausible deniability.”

From the cybersecurity policy and law enforcement front,

  • Dark Reading reports,
    • “It’s been a brutal 16 months since the Cybersecurity and Infrastructure Security Agency (CISA) has had a Senate-confirmed director. Now, a new name has bubbled up as a possible pick to take over the beleaguered agency: Tom Parker, a low-key, British-born cybersecurity expert known for business savvy, technical expertise, and decades of focus on the delicate economics of cybercrime and cyber defense. 
    • “Reports say that although he has not yet been officially nominated, Parker is a contender to get the nod from new Department of Homeland Security Secretary, Markwayne Mullin. A request for comment from Dark Reading to DHS was referred to the White House, which has not yet responded. 
    • “Parker however tells Dark Reading that despite recent reporting, he has not had any “direct engagement” with the administration on taking on the role, but would welcome the conversation.” 
  • Federal News Network adds,
    • “The Office of Management and Budget (OMB) picked a long-time federal technology manager to take over as the deputy federal CIO. Thomas Flagg is set to assume that role. Federal News Network has learned that Federal CIO Greg Barbaccia made the announcement to agency CIOs yesterday. Flagg, who is the Education Department CIO, will replace Drew Mykelgard, who left in September to join the private sector after three-plus years in the role. Barbaccia wrote in his email that Flagg stood out among a large number of candidates because of the depth and seriousness of his experience across multiple technology leadership roles. Flagg also worked at the Labor Department for 11 years before moving to Education in 2025. 
  • Cybersecurity Dive reports,
    • “The Cybersecurity and Infrastructure Security Agency (CISA) wants to help critical infrastructure operators keep their systems running during a major cyberattack or other serious incident.
    • “CISA on Tuesday [May 5, 2026,] released guidance as part of an international “CI Fortify” initiative focused on activities that infrastructure operators can take to isolate the effects of a cyber intrusion and recover from them.
    • “In a geopolitical crisis, the critical infrastructure organizations Americans rely on must be able to continue delivering—at a minimum—crucial services,” acting CISA Director Nick Andersen said in a statement. “They must be able to isolate vital systems from harm, continue operating in that isolated state, and quickly recover any systems that an adversary may successfully compromise.
    • “The new guidance, modeled on advice that the Australian government published in 2025, comes as intelligence agencies warn that China might sabotage Western critical infrastructure to keep the U.S. and its allies from interfering with Beijing’s long-rumored invasion of Taiwan. China’s Volt Typhoon hacking campaign indicated that Beijing had already begun laying the groundwork for such disruption, prompting U.S. officials to step up warnings about the dangers of interdependencies in operational technology.”
  • and
    • “The U.S. government’s AI security center will evaluate frontier models from Google, Microsoft and xAI before their release to determine whether the models’ advanced capabilities pose cybersecurity risks.
    • The newly announced plan for the National Institute of Standards and Technology’s (NIST) Center for AI Standards and Innovation (CAISI) to conduct “pre-deployment evaluations” represents the U.S. government’s most significant attempt yet to get ahead of security threats from powerful AI systems.
    • “Independent, rigorous measurement science is essential to understanding frontier AI and its national security implications,” CAISI Director Chris Fall said in a statement. “These expanded industry collaborations help us scale our work in the public interest at a critical moment.”
  • The Wall Street Journal adds,
    • “The White House is weighing a new government-review process for artificial-intelligence tools that the government deems to pose cybersecurity risks, a move that could further expand its oversight of AI in response to Anthropic’s powerful Mythos model.
    • “The White House is considering a cybersecurity-focused executive order that could include formalizing a government oversight group to create standards for the most powerful AI models, such as Mythos, people familiar with the discussions said. The goal is to protect consumers and businesses from cyberattacks and other disruptions caused by the premature release of such models, and a range of ideas are being considered, the people said. 
    • ‘The internal conversations show how Mythos has forced the Trump administration to recalibrate aspects of its laissez-faire approach to AI oversight. The administration has unwound Biden administration efforts to implement safety standards and attacked states trying to impose regulations, hoping to ease constraints tech companies face in rolling out new models.” 
  • Cyberscoop notes,
    • “The Cybersecurity and Infrastructure Security Agency has gotten “by far” the biggest gains from artificial intelligence automation in its security operations unit to help analysts sift through threats, but it’s also proven valuable elsewhere within the agency, CISA officials said Tuesday.
    • “It’s “really allowing those analysts to do triage very fast, so they focus on what matters versus the noise,” Tammy Barbour, acting chief of application management at CISA, said. “They’re able to do a lot of real-time, quick looks before events happen in most places.”
    • “Barbour, speaking at the UiPath FUSION Public Sector event hosted by Scoop News Group, said automation has also been a boon to CISA’s Technology Operations Center.
    • “The top analysts are able to quickly respond to customers who are reaching out to talk and asking questions, and be able to get real-time efficiencies with that,” she said.”
  • Security Week tells us,
    • “A Latvian member of the Karakurt ransomware gang was sentenced to 8.5 years in prison in the US for his involvement in extorting victims.
    • “The individual, Deniss Zolotarjovs, 35, of Latvia, was arrested in Georgia in December 2023 and extradited to the US in August 2024. He pleaded guilty in July 2025.
    • “Associated with the infamous Conti group and also known as TommyLeaks, Schoolboys Ransomware Gang, and Blockbit, Karakurt was one of the most notorious ransomware groups half a decade ago.”
  • Cyberscoop informs us,
    • “Two U.S. nationals were sentenced to 18 months in prison for running laptop farms that facilitated North Korea’s expansive remote IT workers scheme, the Justice Department said Wednesday.
    • “Matthew Issac Knoot and Erick Ntekereze Prince both received and hosted laptops at their residences to dupe U.S. companies into thinking remote IT workers they hired were located in the country. The pair’s separate schemes impacted almost 70 U.S. companies and generated a combined $1.2 million in revenue for the North Korean regime.”
  • Bleeping Computer adds,
    • “A 34-year-old Virginia man was found guilty of conspiring to destroy dozens of government databases after getting fired from his job as a federal contractor.
    • “In 2016, Sohaib Akhter and his twin brother and co-defendant Muneeb Akhter were also sentenced to several years in prison after pleading guilty to accessing U.S. State Department systems without authorization and stealing the personal information of dozens of co-workers and a federal law enforcement agent who was investigating their crimes.
    • After serving their sentences, the two brothers were rehired as government contractors by a company that worked with more than 45 federal agencies and hosted government data on servers in Ashburn.
    • “When the company discovered Sohaib Akhter’s felony conviction, it terminated both brothers’ employment during an online remote meeting on Feb. 18, 2025,” the Justice Department said. “Immediately after being fired during this meeting, the brothers sought to harm their employer and its U.S. government customers by accessing computers without authorization, write-protecting databases, deleting databases, and destroying evidence of their unlawful activities.”

From the cybersecurity breaches and vulnerabilities front,

  • Cyberscoop reports,
    • “A defense technology company with Department of Defense contracts exposed user records and military training materials through API endpoints that lacked meaningful authorization checks, according to an account published by Strix, an open-source autonomous security testing project.
    • “The issue affected Schemata, an AI-powered virtual training platform used in military and defense settings. According to Strix, an ordinary low-privilege account was able to access data across multiple tenants, including user listings, organization records, course information, training metadata and direct links to documents hosted on the Schemata’s Amazon Web Services instances.”
  • CISA added three known exploited vulnerabilities (KVES) to its catalog this week.
  • SC Media points out,
    • “The Cybersecurity and Infrastructure Security Agency (CISA) is reportedly considering shortening remediation deadlines for vulnerabilities added to the Known Exploited Vulnerabilities catalog, according to Reuters.
    • “Citing two sources familiar with the matter, Reuters reported Friday [May 1, 2026] that CISA Acting Director Nick Anderson and U.S. National Cyber Director Sean Cairncross were discussing proposals to cut KEV deadlines for federal civilian executive branch agencies from an average of two to three weeks to just three days.
    • The discussion was reportedly spurred by the emergence of advanced AI tools such as Anthropic’s Claude Mythos and OpenAI’s GPT-5.4-Cyber that have the potential to identify and exploit flaws at unprecedented speed.
    • A CISA spokesperson declined to comment on whether such discussions were taking place or whether a decision had been made.
  • Security Week lets us know,
    • “Microsoft has warned organizations in the United States about a sophisticated phishing campaign that uses a “code of conduct review” theme to lure victims to a malicious website.
    • “The tech giant observed more than 35,000 attempts between April 14 and 16. The malicious emails were received by users across roughly 13,000 organizations in 26 countries, but 92% of the targets were in the US. 
    • “Many of the messages were received by users in the healthcare and life sciences, financial services, professional services, and technology and software sectors.” * * *
    • “Enterprises at risk of being targeted in this and similar phishing campaigns have been provided with recommendations for mitigating attacks, as well as threat-hunting queries and indicators of compromise (IoCs).”
  • Cybersecurity Dive relates,
    • “Hackers could exploit vulnerabilities in Progress Software’s MOVEit Automation tool to improperly access businesses’ data, the software maker said in a recent advisory.
    • “Exploitation of the two flaws — an authentication-bypass vulnerability tracked as CVE-2026-4670 and a privilege-escalation vulnerability tracked as CVE-2026-5174 — could “lead to unauthorized access, administrative control, and data exposure,” according to Progress Software’s advisory.
    • “The newly patched flaws represent serious security weaknesses in a widely used managed-file-transfer program that helps organizations transfer data between self-hosted servers, cloud platforms and third-party vendors.
    • “Progress Software urged customers to upgrade to the latest version of the software, which fixes both vulnerabilities.”
  • Per Dark Reading,
    • “Researchers have spotted a modular cloud worm that will clear you of any infections by the dangerous supply chain attacker “TeamPCP,” free of charge. The catch: It wants your secrets.
    • “SentinelLabs named the program “PCPJack” in a new blog post,and described it as “well developed” — effective, with a few inexplicable but superficial oddities. Affected organizations stand to lose secrets associated with their cloud, container, developer, productivity, and financial services, unless they implement cloud security best practices, concealing passwords and keys behind vaults and multifactor checks.”
  • Per Bleeping Computer,
    • “A fake version for the Claude AI website offers a malicious Claude-Pro Relay download that pushes a previously undocumented backdoor for Windows named Beagle.
    • “The threat actor advertises Claude-Pro as a “high-performance relay service designed specifically for Claude-Code” developers.
    • “The fake website is a simplistic attempt at mimicking the legitimate site for the popular Claude large language model (LLM) and an AI assistant, using similar colors and fonts.
    • “However, the facade falls apart when it comes to links, as they are mere redirects to the front page, researchers at cybersecurity company Sophos say in a report today.”

From the ransomware front,

  • Edscoop reports,
    • “ShinyHunters, the prolific criminal hacker and extortion group, on Thursday [May 7, 2026] provided additional details about its recent breach of Canvas, the learning management system developed by Instructure, with hopes of coaxing payments from some of the nearly 9,000 educational institutions it claims are affected.
    • “After announcing on May 1 that it had exfiltrated several terabytes of data containing the personal information of 275 million users, it announced a deadline of Thursday [May 7] before “everything is leaked and there will be no chance at a negociation for anyone. Instructure has not even bothered speaking to us to understand the situation or to even negociate with us to prevent the release of this data. Our demand was not even as high as you might think it is.”
    • “On Thursday, the group presented to Canvas users a second message and extended the deadline for payment until May 12. “ShinyHunters has breached Instructure (again). Instead of contacting us to resolve it they ignored us and did some ‘security patches’,” the note reads. The group advised affected schools to consult security professionals and use the Tox messaging protocol to negotiate a “settlement.”
    • “The attached list of affected institutions includes many school districts, along with well-known universities, including Cambridge, Columbia, Cornell, Georgetown, Harvard, MIT and UC Berkeley.”
  • The Wall Street Journal adds on May 8, 2026,
    • Canvas, one of the most widely used education apps, said it had restored services after pulling the plug in the middle of finals week at many colleges to deal with a cybersecurity incident.
    • From Berkeley to Harvard, students at thousands of colleges and high schools temporarily lost access to their coursework on Thursday afternoon after a hacking group posted a ransom note on the platform.  
    • The company behind Canvas, Instructure Inc., said the intruders had accessed some customer data, including names, email addresses and student ID numbers, as well as messages between Canvas users. The company said it hasn’t found that passwords or financial information were involved. The investigation is ongoing and it has notified the Federal Bureau of Investigation.
    • “We have since confirmed that the unauthorized actor carried out this activity by exploiting an issue related to our Free-For-Teacher accounts,” the company said on its website. “As a result, we have made the difficult decision to temporarily shut down Free-For-Teacher accounts.” 
  • Security Week relates,
    • “The RansomHouse ransomware group has taken credit for the recent attack on the cybersecurity firm Trellix.
    • “The Trellix hack came to light this week when the company announced on its website that part of its source code repository had been breached.
    • “Based on our investigation to date, we have found no evidence that our source code release or distribution process was affected, or that our source code has been exploited,” the company stated.
    • “No other information has been shared by Trellix, but it has promised to release additional details after it completes its investigation.”
  • Industrial Cyber tells us,
    • “New data from BlackFog shows ransomware activity remaining structurally elevated, with attacks continuing to operate at high volume while expanding their data-centric focus across both disclosed and undisclosed incidents. The analysis highlights that threat actors are increasingly prioritising data theft and extortion over traditional encryption-only disruption, reflecting a broader shift in how ransomware operations monetise compromise. It also underscores that incidents continue to span multiple sectors and geographies, reinforcing that ransomware is no longer episodic but persistent, industrialised, and embedded across the global threat landscape.
    • “A total of 264 publicly disclosed ransomware attacks were recorded, representing a 15% decrease compared to the same period the previous year, BlackFog disclosed in its ‘Q1 2026 Ransomware Report.’ Despite this decline, activity remained steady throughout the first quarter, with 91 attacks in January, 83 in February, and 90 in March. Healthcare remained the most targeted sector, accounting for 72 attacks (27%), reflecting the continued focus on organizations with sensitive data and limited tolerance for operational disruption. Government entities experienced 32 attacks (12%), while the technology sector followed with 28 attacks (11%).” 

From the cybersecurity business and defenses front,

  • The Wall Street Journal reports,
    • “OpenAI said it was previewing a powerful artificial-intelligence model capable of finding software vulnerabilities for a limited group of partners, adding to an industry race to give customers the most advanced cyber capabilities.
    • “The ChatGPT maker said it was releasing GPT-5.5-Cyber, a version of its most capable AI model, to a limited group of users that do vital security work. Other versions of GPT-5.5 are available to customers that do broader cyber work or general queries.
    • “The announcement followed consultation with the White House, which is working with top AI companies on the release of models that present national-security risks. Federal agencies and congressional committees have also been briefed on the latest capabilities.
    • “OpenAI Chief Executive Sam Altman said last week that the company was beginning to roll out the model to trusted cyber partners.”
  • Security Boulevard assesses Anthropic’s Project Glasswing.
  • Security Week relates,
    • “Cisco on Monday announced its intent to acquire Astrix Security, a startup focused on securing non-human identities (NHIs) such as API keys, service accounts, and OAuth tokens increasingly used by applications and AI agents.
    • “In a blog post, Cisco said the acquisition is aimed at extending zero trust principles to the emerging “agentic workforce,” where AI agents and machine identities are rapidly expanding the enterprise attack surface. Astrix’s technology is designed to help organizations discover, govern, and secure these identities, including detecting excessive privileges and real-time threats. 
    • “Astrix provides visibility into non-human identities and the activity of AI-driven agents, along with lifecycle management and automated detection and remediation of over-privileged, unnecessary, or malicious access — including compromised credentials and rogue agent behavior. Cisco plans to integrate these capabilities into its broader security platform, including identity intelligence, secure access, and Duo IAM.”
  • Cybersecurity Dive tells us,
    • “Businesses are confident that AI will improve their cybersecurity posture, even as they neglect more fundamental security tools like identity management and zero-trust networking, according to a “State of Workforce Password Security” report that the business software provider Zoho published on Tuesday.
    • “AI confidence also doesn’t match implementation readiness, the report found, with a massive gap between the share of companies expecting AI to help them with security and the share of companies ready to act on that potential.
    • “The report also contains data on the share of companies that experienced recent cyberattacks and the business world’s security spending plans.”
  • Tech Target identifies “top zero-trust use cases in the enterprise.”
    • “When applied correctly, zero trust can minimize an organization’s attack surface. Experts weigh in on the best use cases where zero trust can deliver results.”
  • Here is a link to Dark Reading’s CISO Corner.

Thursday report

From Washington, DC

  • Federal News Network reports,
    • “In the coming months, the Office of Personnel Management is expected to release a reworked version of its employee viewpoint survey that’s more focused on granular data and delivering realtime feedback.
    • “OPM Director Scott Kupor said his agency has been refining the survey to focus more on micro-level questions in order to more effectively gauge employee opinion.
    • “The goal is to get to a decision on what the kind of new survey format looks like so that we have time to do something over the course of this fiscal year for sure,” Kupor told Federal News Network in an interview Wednesday.”
  • Fedweek outlines the FEHB/PSHB eligibility rules for children.
    • “Both the Federal Employees Health Benefits program and Postal Service Health Benefits program, provide for coverage of spouses and children in their self plus one and family options. While enrollment changes typically happen during the open season each autumn, there are certain life events that involve adding children—for example from self plus one to self and family on the birth or adoption of a child.
    • “In both cases, it’s important to know who qualifies for coverage as a child, and when that may end.’
  • Thompson Reuters notes,
    • QUESTION: We recall that the Affordable Care Act (ACA) requires insured group health plans to satisfy nondiscrimination rules similar to those that apply to self-insured plans under Code § 105(h) (the eligibility and benefit tests). What is the status of those rules? Are employers that sponsor insured plans required to comply with them, and if so, when?
    • ANSWER: Under the ACA, insured group health plans generally must satisfy the nondiscrimination rules of Code § 105(h)(2), including “rules similar to” those in Code § 105(h) regarding nondiscriminatory eligibility, nondiscriminatory benefits, and controlled groups. The Code § 105(h) rules pre-date the ACA, prohibit certain discrimination in favor of highly compensated individuals, and apply only to self-insured health plans. The ACA applied similar requirements to insured plans, other than those that provide only excepted benefits or qualify for grandfathered status.
    • “Although insured group health plans initially were required to comply with the ACA nondiscrimination rules for plan years beginning on or after September 23, 2010, the IRS announced in Notice 2011-1 that compliance is not required until the agencies issue regulations or other guidance regarding how the rules apply to insured plans. To date, the agencies have not issued such regulations or guidance, so sanctions for failure to comply do not yet apply for insured plans. Note that the Code § 105(h) nondiscrimination rules continue to apply to self-insured health plans, including those that provide excepted benefits or are grandfathered. For example, the Code § 105(h) nondiscrimination rules continue to apply to health FSAs”.
  • Per an HHS news release,
    • “Today, the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) announced an Interim Final Rule (IFR) extending, for one-year, the compliance dates that recipients of HHS funding must meet for conforming web content and mobile applications to specific accessibility standards under Section 504 of the Rehabilitation Act of 1973 (Section 504).
    • “Under the revised timeline:
      • “Recipients with 15 or more employees will now have until May 11, 2027, to comply.
      • “Recipients with fewer than 15 employees will now have until May 10, 2028, to comply.

From the Food and Drug Administration front,

  • Fierce Pharma reports,
    • “After a surprise rejection at the beginning of 2026, the FDA has agreed to reconsider a T-cell therapy based on the same single-arm trial that the agency had previously found problematic.
    • “For Pierre Fabre Pharmaceuticals and Atara Biotherapeutics’ Ebvallo, the FDA agreed during a recent meeting that a single-arm study using an appropriate historical control “could serve as an adequate and well controlled study” in support of an application for approval, the two companies said Thursday.
    • “Pierre Fabre and Atara are aiming to get Ebvallo, also known as tabelecleucel or tab-cel, approved for patients with relapsed or refractory Epstein-Barr virus-positive post-transplant lymphoproliferative disease (EBV+PTLD) who have failed on an anti-CD20 regimen. Before the FDA, European regulators had already greenlighted the immunotherapy for the indication in 2022.”
  • MedPage Today adds,
  • and
    • “An investigational trivalent mRNA-based vaccine reduced confirmed flu illness by 26.6% through the end of the flu season compared with approved standard-dose vaccines in a randomized trial among adults ages 50 and older.
    • “The mRNA vaccine led to more adverse events, particularly injection-site pain and fatigue, but most were transient and mild without an excess of more serious risks.
    • “An FDA decision on approval is expected by August.”

From the public health and medical / Rx research front,

  • The Washington Post reports,
    • “Using the blood of a 56-year-old woman vaccinated against measles, scientists have isolated a fighting force of four potent virus-blocking antibodies that could pave the way toward a treatment for people exposed to the highly contagious respiratory disease making a comeback in the United States.
    • “A safe, highly effective vaccine for measles has been available since the 1960s, and the U.S. officially eliminated the disease in 2000, with sporadic cases and outbreaks. But dropping vaccination rates have sparked large outbreaks in multiple states, and the country is edging closer to the virus spreading freely again—which puts more people at risk.
    • “New ways to block or treat measles would be particularly important for people who are immunocompromised and babies under the age of 1, because they are not eligible for the vaccine, leaving them unprotected amid a growing number of cases.
    • “Measles was a problem that was solved. Until it wasn’t solved anymore,” said Erica Ollmann Saphire, president of the La Jolla Institute for Immunology who led the study published Thursday in the journal Cell Host & Microbe. But she and other scientists stressed that this approach was not a substitute for a vaccine.
    • “The treatment is always going to be more expensive than the vaccine. It’s the best bang for your public-health buck — this is for people that couldn’t be vaccinated,” Saphire said.”
  • MedPage Today adds, “A new systematic review in The BMJ reported that current evidence did not support causal associations between aluminium adjuvanted vaccines and serious or long-term health outcomes.
  • Infectious Disease Advisor notes,
    • “HIV pre-exposure prophylaxis (PrEP) uptake remains suboptimal among commercially-insured adolescents and young adults in the United States, highlighting the need for targeted interventions to address access barriers.”
  • The American Medical Association lets us know what doctors wish their patients knew about swimmer’s ear.
    • “Diving into pools or spending the day at the beach or lake can be the epitome of summer fun, but these aquatic adventures can also come with an unwelcome companion: otitis externa, commonly known as swimmer’s ear. This common affliction can sideline even the most dedicated water enthusiasts with its painful consequences. With the incidence of swimmer’s ear rising during the warmer months, understanding its causes, symptoms and prevention methods is essential for water enthusiasts of all ages.” 
  • The National Institute for Health Care Management’s May newletter discusses “Cancer Trends & Treatment Advancements”
  • Per BioPharma Dive,
    • “CellCentric, a biotechnology company developing an experimental drug for multiple myeloma, announced Wednesday it raised a $220 million Series D round to finance mid- and late-stage trials.
    • “Its lead drug, dubbed inobrodib, is an oral medicine that blocks a pair of proteins called “p300” and “CBP,” which in turn prevents the expression of certain key cancer-driving genes. CellCentric believes the treatment might be useful as an additive therapy across different lines of care in multiple myeloma. 
    • “The biotech is testing inobrodib in an all-oral combination involving Bristol Myers Squibb’s Pomalyst, as well as in conjunction with bispecific antibodies for myeloma such as Pfizer’s Elrexfio and Johnson & Johnson’s Tecvayli. It’s also evaluating use in a “maintenance” setting, where treatments are used to keep cancer from returning.”

From the U.S. healthcare business front,

  • Beckers Payer Issues reports,
    • “Blue Shield of California debuted its virtual-first Virtual Blue healthcare plan just over three years ago. Now, the data is rolling in.
    • “The program began in 2023 through a collaboration with tech-enabled healthcare platforms Accolade — now owned by Transcarent — and TeleMed2U. The program has no out-of-pocket costs for visits with virtual-only providers, can often deliver same-day care and now has more than 150,000 members. Blue Shield is even tacking virtual primary care options onto its Trio HMO plan, expanding offerings into the individual market.
    • “Tim Lieb, Blue Shield of California’s senior vice president of commercial markets, recently joined the “Becker’s Payer Issues Podcast” to discuss Virtual Blue’s early strengths and challenges.”
  • Healthcare Dive relates,
    • “Nearly 8 in 10 employers report GLP-1 drugs are driving heightened healthcare costs at their companies, pushing some to consider dropping coverage of the pricey weight loss medications, according to a survey released Tuesday by the Business Group on Health.
    • “Only 72% of employers that cover GLP-1s for weight management said they’d likely maintain that coverage next year, while 10% reported they likely wouldn’t, according to the group, which represents employers that provide health coverage. 
    • “Additionally, 87% of respondents said new oral versions of GLP-1 drugs would result in higher demand for the medications, but only 9% predicted prices would decrease.”
  • and
    •  Providing hospital-level care in patients’ homes was linked to better clinical outcomes, suggesting hospital-at-home programs could serve as a safe and efficient alternative to traditional inpatient care, according to a study published this week in JAMA Network Open. 
    • Hospital at home was associated with decreased emergency department use within 30 days of discharge and lower in-hospital mortality, according to the research. But patients at hospital-at-home programs saw no significant difference in hospital readmissions within 30 days. 
    • Additionally, adoption of hospital at home across the country is uneven, with few rural facilities participating, researchers wrote. The findings “underscore the need to address practical and implementation challenges to broaden equitable access,” they said.
  • Per Healthcare Cost Institute news releases,
    • Health care spending can differ dramatically depending on where Americans live, with costs varying by more than twofold from one metro area to another, according to new findings from the Health Care Cost Institute (HCCI). Charleston, WV, tops the list of the highest spending markets, with annual costs more than twice those in places like Bakersfield, CA, one of the country’s lowest spending areas.
    • The new data comes from the Health Cost Landscape, HCCI’s updated interactive platform that compares health care spending, prices, service use, and market dynamics across 269 metro areas in 45 states. The tool gives a clear, local look at how health care markets function and where consumers are paying the most for care.
  • and
    • “The Transparency in Coverage (TiC) regulations have introduced unprecedented visibility into negotiated health care prices in the United States. By requiring insurers to publish machine-readable files containing payer–provider contracted rates starting in 2022, the policy has created a new data source for studying price variation. However, the scale, inconsistency, and missing information within the TiC data mean that rigorous methodological work is required before it can be used for research. This brief explores the nature of this data, how it is accessed and processed, and how it can be used for analysis, with a detailed walkthrough of a real example examining childbirth prices in Pennsylvania.” * * *
    • “Transparency in Coverage data represent a significant advancement in the availability of information on negotiated health care prices, offering researchers a new lens into variation across payers, providers, and markets. As demonstrated in the childbirth analysis in Pennsylvania, TiC data can be used to replicate and extend findings from traditional claims-based research, particularly in understanding the range and distribution of negotiated rates across payers and providers.
    • “At the same time, the value of TiC data depends heavily on the methods used to create an analytic dataset. The raw data are not inherently research-ready and require substantial processing, including careful service definition, data cleaning, provider and payer entity resolution, and restrictions to ensure comparability. Without these steps, analyses may not be replicable and risk reflecting the messiness of the raw data rather than meaningful differences in prices. Additionally, the absence of utilization data remains a fundamental limitation, requiring integration with external sources to fully assess spending and average prices.
    • “Overall, TiC data should be viewed as a powerful but incomplete resource. When used appropriately, they can provide important insights into health care pricing dynamics and market structure. As data quality improves and methods continue to evolve, TiC data are likely to become an increasingly valuable complement to claims data in health services research.”
  • Per Fierce Healthcare,
    • “Hims & Hers launched an artificial intelligence agent embedded in its platform to help interpret biomarker lab results and provide users personalized insights about their health.
    • “The company launched its direct-to-consumer lab testing program for health biomarker testing back in November. The new agent AI, Labs AI, has been available to some customers in beta testing and will roll out to all Labs customers over time, the company announced Thursday.
    • “Hims & Hers’ Labs offers access to 130 biomarker tests across 10 health areas, including heart health, metabolism, hormones, inflammation and stress, as part of its strategy to extend into prevention and health screening. The new AI care agent makes customers’ lab results clearer, more useful and easier to engage with, according to Patrick Carroll, M.D., Hims & Hers chief medical officer.”
  • and
    • “Ardent Health topped the market’s revenue and earnings estimates, touting Wednesday solid adjusted admission and labor spend numbers despite what has proved to be a tumultuous first quarter for hospitals. 
    • “The publicly traded for-profit logged $1.6 billion of total revenue, which was up 7% year over year and 1.3% above Zacks Investment Research’s consensus estimate. Net income was $40 million, or 28 cents per share, beating the consensus estimate of 18 cents per share. 
    • “Similar to other for-profit health systems’ reports from the past few weeks, executives acknowledged the impacts of a weak respiratory season and severe winter storms on Ardent’s business, particularly in Texas, Oklahoma and New Jersey. That led to a 1.1% year-over-year decline in admissions, though CEO Marty Bonick said during Wednesday’s earnings call that the company “acted swiftly to reschedule surgeries and adjust labor to align with volume, mitigating the impact on our performance.”
  • Per Fierce Pharma,
    • “With an eye on the lucrative U.S. market, Italy’s Angelini Pharma will acquire rare disease specialist Catalyst Pharmaceuticals and its potential blockbuster, Firdapse, for $4.1 billion.
    • “Rome-based Angelini, a family-owned private company established in 1919, is paying $31.50 per share for Florida-based Catalyst. It is a 3% premium on Catalyst’s share price at close yesterday and a 21% premium on its price on April 22 before market activity hinted at public knowledge that a sale was in the offing. Bloomberg reported the potential buyout on April 27, triggering another stock surge.”
  • Per MedTech Dive,
    • “Roche has agreed to acquire PathAI, a Boston-based digital pathology firm, for up to $1.05 billion.
    • “Roche plans to pay $750 million upfront and up to $300 million in additional milestone payments, according to a Thursday announcement. 
    • “The acquisition is expected to close in the second half of 2026, subject to customary closing conditions, including antitrust and regulatory approvals.”

Midweek update

From Washington, DC,

  • The American Hospital Association News tells us,
    • “The White House May 4 released its National Drug Control Strategy, which, among other efforts, recommends effective primary prevention programs. The initiative increases the implementation of evidence-based prevention strategies; establishes new partnerships with organizations supporting youth health and expanding primary prevention; supports a national media and education campaign against drug use; and supports and enhances the federal drug-free workplace program.”
  • The Centers for Medicare and Medicaid Services announced,
    • “The Centers for Medicare & Medicaid Services (CMS) will provide eligible Medicare beneficiaries access to certain GLP-1 medications for $50 per month beginning July 1, 2026, through December 31, 2027.
    • “Under the Medicare GLP-1 Bridge, a time-limited demonstration, CMS is expanding access to innovative, evidence-based weight-loss treatments. Eligible individuals enrolled in Medicare Part D prescription drug plans will be able to access these medications at a predictable and affordable cost—$50 for a monthly supply. This approach reflects CMS’ continued focus on improving access to high-value treatments that support better long-term health outcomes.
    • * * * “Beginning July 1, Medicare beneficiaries with Part D coverage may be eligible to access certain GLP-1 medications at $50 for a monthly supply. Beneficiaries can talk to their doctor to determine whether a GLP-1 medication is right for them. CMS will share additional information for beneficiaries as the program begins.
    • “In addition, CMS continues to work with stakeholders—including providers, pharmacies, and manufacturers—to support implementation and ensure all partners have the information they need ahead of launch. 
    • “The Medicare GLP-1 Bridge builds on CMS’ broader efforts to improve access to innovative therapies and support healthier outcomes for Medicare beneficiaries. For additional “demonstration details, visit: https://www.cms.gov/medicare/coverage/prescription-drug-coverage/medicare-glp-1-bridge
  • U.S. Office of Personnel Management Director Scott Kupor, writing in his Secrets of OPM blog on Substack, optimistically discusses the state of artificial intelligence.
  • Meanwhile, KFF Health News reviews “Regulation of AI in Prior Authorization and Claims Review: A Look at Federal and State Consumer Protections.”

From the Food and Drug Administation front,

  • Per FDA news releases,
    • “The U.S. Food and Drug Administration today announced major steps in its bold initiative to modernize the agency. The agency launched Elsa 4.0, a significant upgrade to the agency’s internal AI tool available to all FDA staff, from scientific reviewers to investigators.  
    • “The agency also consolidated more than 40 disparate application and submission data sources, systems and portals across all FDA centers into a new platform called HALO (Harmonized AI & Lifecycle Operations for Data).The agency began integrating HALO and Elsa so that FDA staff can query data and build workflows without having to manually upload documents within each chat. The HALO consolidation is expected to enable more penetrating deployment of AI capabilities within agency operations. 
    • “Elsa’s new capabilities once again position FDA as a leader in deploying AI tools that empower staff,” said FDA Commissioner Marty Makary, M.D., M.P.H. “Removing tedious burdens for staff enables them to focus more on science and makes their work streams more efficient and enjoyable. We have some of the best scientists in the world and we need to take good care of them.”
  • and
    • The U.S. Food and Drug Administration today announced that it is piloting one-day inspectional assessments, as part of a broader initiative to make its inspectional resources more targeted and efficient. As part of this pilot, which launched in April, the agency is conducting shorter, focused screening assessments to complement standard FDA inspections. 
    • “One-day inspections can strengthen our inspectional approach by focusing our time and resources where they are most needed—enhancing our overall effectiveness,” said FDA Commissioner Marty Makary, M.D., M.P.H. “For the FDA, the ability to conduct shorter, targeted assessments allows for broader surveillance coverage, enabling the agency to assess more facilities and gather critical insights without compromising regulatory rigor. For industry, these assessments can provide timely feedback while minimizing operational disruption, particularly for lower-risk establishments.”
    • One-day inspectional assessments also support the development of more robust risk models across FDA programs. Data gathered through these assessments—such as recurring compliance themes, facility-specific risk scores, and discrepancies between registered and actual operations—can be used to better target future oversight activities.
  • MedTech Dive tells us,
    • “The Food and Drug Administration added neurosurgical supplies to its medical device shortages list on Wednesday.
    • “The regulator sent a letter to healthcare providers warning about disruptions in availability of neurosurgical patties, sponges and strip devices, which are used to absorb fluids and protect tissue during surgery.
    • “The FDA attributed the problem to recent supplier issues, noting that Medline Industries recently recalled its neuro sponge products. The agency expects the shortage to continue through the end of the year.”

From the public health and medical / Rx research front,

  • The New York Times explains,
    • “Hantaviruses have most likely been around as long as rodents, but little was known about these pathogens before the 20th century. This rare family of viruses that rodents carry has been cited as the source of a deadly outbreak aboard a cruise ship in the Atlantic Ocean.
    • “The virus is zoonotic, meaning it can be transmitted to humans from animals. And while outbreaks have been rare, it is one of the most widely distributed zoonotic viruses on Earth.
    • “Some are Old World hantaviruses and others are New World hantaviruses,” said Sabra Klein, a professor of molecular microbiology and immunology at the Johns Hopkins Bloomberg School of Public Health.
    • “Different species of the virus are carried by different rodents,” Dr. Klein said, adding that European strains cause less severe illnesses than those from Asia.
    • She noted that “there’s no vaccine, there’s no cure, there’s no money” in finding a cure “in part because these are so rare.”
  • The Wall Street Journal adds,
    • “Hantavirus is an unlikely source of contagion on a cruise ship. The virus isn’t as infectious between humans as fast-spreading respiratory illnesses like Covid-19 and the flu. 
    • “It belongs to a family of viruses carried by rodents and spread to humans through contact with infected urine, droppings or saliva. Only one strain—the Andes virus—has shown limited evidence of human-to-human transmission. Researchers in South Africa and Switzerland confirmed this week the virus involved in the suspected outbreak is the Andes strain.
    • “Human-to-human transmission of the Andes strain requires very close contact, like sharing food or living quartersaccording Steven Bradfute, an immunologist at the University of New Mexico Health Sciences Center whose lab has sequenced hantaviruses. “It doesn’t spread into huge outbreaks,” Bradfute said.
    • “WHO and other health authorities say the threat to public health is low. 
    • “Yet the ship’s passengers are at risk, as well as perhaps people they came into close and extended contact with after leaving the ship. That is why Oceanwide Expeditions, the Hondius’s operator, plus health authorities around the world and airlines, are mobilizing to trace the paths of the ship’s travelers.”
  • Fierce Healthcare reports,
    • “The Leapfrog Group highlighted broad improvements across several patient safety measures in this year’s spring release of hospital safety grades, the first reflecting changes made after a court-ordered removal of hospitals that declined to voluntarily submit information to the watchdog group. 
    • “Top marks were handed out to 917 hospitals, with Leapfrog outlining a particularly high share of “A” hospitals in the states of Connecticut (where 64% of hospitals received an “A”), Virginia (59%), South Carolina (51%), Utah (50%) and Montana (44%). 
    • “A hospital’s assigned grade is calculated by reviewing recent data on up to 22 patient safety measures, including a 10-part Medicare composite of reported patient safety and adverse events. Among these, Leapfrog said it saw “significant improvement” in 17 measures, including those related to healthcare-associated infections and medication safety plus multiple items related to patient experience. 
    • “The good news is that hospitals across the country are making meaningful strides in patient safety and helping save countless lives,” Leah Binder, president and CEO of The Leapfrog Group, said. “But not all hospitals are the same. That’s why it’s so important for people to consult Safety Grades and do their research when choosing a hospital.”
    • “Of note, the latest release excludes 450 hospitals that did not participate in Leapfrog’s 2024 or 2025 surveys.” 
  • Beckers Hospital Review points out the “eleven U.S. hospitals have earned consecutive “A” safety grades from The Leapfrog Group since 2012.” You can see “the list of Leapfrog’s five “F” hospitals here.
  • Pulmonary Advisor notes,
    • “While vaccinations showed protective trends, prior viral infections were generally linked to an increased likelihood of future respiratory illnesses.”
  • Per MedPage Today,
    • “Updated findings from a European randomized trial continued to show that colonoscopy screening significantly reduced colorectal cancer (CRC) incidence, but its impact on CRC mortality was less clear.”
  • Following up on recent Wall Street Journal articles, Cardiology Business relates
    • “Three of the leading U.S. cardiovascular health societies have joined forces for a new statement about the importance of multidisciplinary, patient-centered decision-making when managing patients with severe aortic stenosis (AS).
    • “The Society for Cardiovascular Angiography and Interventions (SCAI)American College of Cardiology (ACC) and Society of Thoracic Surgeons (STS) collaborated on the joint statement, calling it a response to “recent media coverage” about transcatheter aortic valve replacement (TAVR) and surgical aortic valve replacement (SAVR). The primary focus of the statement appears to a feature story published by The Wall Street Journal on April 23 that included interviews with patients who experienced significant complications after undergoing TAVR. 
    • “The joint statement highlights the fact that multidisciplinary heart teams are at the center of every treatment decision for patients who present with severe AS and require an aortic valve replacement. This has been the case for many years now, but coverage from The Wall Street Journal and other mainstream news outlets is sure to grab the attention of people unfamiliar with how such treatment decisions are made. 
    • “This statement serves as a fresh reminder for the general public that cardiologists and cardiac surgeons do not take these decisions lightly. The cardiology groups said years of hard work and dedication have gone into developing the framework that is now in place.”
  • Per MedTech Dive,
    • “Neptune Medical’s gastrointestinal robot met both of its primary endpoints in a clinical trial assessing the safety and feasibility of the system to perform colonoscopies.
    • “The study followed 50 adults who underwent screening, surveillance or diagnostic colonoscopy with the robotic endoscopy system at a single center in Poland for 14 days after the procedure.
    • “The results, announced Tuesday, showed no adverse events and a 100% rate of cecal intubation, where the endoscope is guided through the entire colon to the beginning of the large intestine.”
  • and
    • “Johnson & Johnson said Tuesday that a study evaluating the investigational Ottava robotic system in gastric bypass surgery met its safety and efficacy endpoints through 30 days. The average weight loss in that time frame was 30 pounds.
    • “Results from the 30-patient study were among the pre-clinical evidence included in J&J’s submission to the Food and Drug Administration, announced in January, for de novo classification of the robot in multiple procedures in the upper abdomen. 
    • “All procedures in the prospective, multicenter study were completed robotically on Ottava without conversion to a non-robotic approach, the company said. There were no adverse events related to the device.”

From the U.S. healthcare business front,

  • The Wall Street Journal reports,
    • “CVS Health exceeded first-quarter earnings expectations and raised its full-year adjusted-earnings guidance.
    • “The company reported first-quarter net income of $2.96 billion, driven by a turnaround at its Aetna insurance unit.
    • “Aetna’s medical-loss ratio was 84.6%, below analysts’ projections, but 2027 Medicare rates still fall short.”
  • Modern Healthcare relates,
    • “Humana plans to cut Medicare Advantage supplemental benefits in 2027 in a strategic shift for the insurer.
    • “Medicare Advantage payments are not keeping pace with medical costs, President and CEO Jim Rechtin said.
    • “Medicare Advantage membership was 22.6% higher in the first quarter.
    • “Humana downgraded its annual earnings guidance.”
  • Beckers Payers Issues tells us,
    • “Oscar Health reported a net income of $679 million in the first quarter of 2026, according to a May 6 earnings release. This marked the highest quarterly profit in the company’s history, nearly 2.5 times greater than profit in the first quarter of 2025.
    • “Membership reached roughly 3.2 million members, a 56% year-over-year increase. The company’s medical loss ratio was 70.5%, compared to 75.4% during the same period last year.
    • “Total revenue reached $4.6 billion, up 53% year over year. Earnings from operations were $704.1 million, more than double from the first quarter of 2025.
    • “The company also reaffirmed its 2026 guidance. The strong quarter follows a $443 million net loss in 2025.”
  • Fierce Healthcare informs us,
    • “Hinge Health boosted its full-year revenue outlook by $64 million as the company reported a stronger-than-expected first quarter and kicked off an expansion of its business beyond muscle and joint pain.
    • “The digital musculoskeletal (MSK) care provider, which went public nearly a year ago, brought in first-quarter revenue of $182 million, up 47% year-over-year from $123.8 million in Q1 2025. The company posted first-quarter adjusted earnings of 45 cents per share, significantly exceeding Wall Street analyst estimates of 12 cents per share. Hinge Health’s non-GAAP income from operations jumped 208% to $46.2 million compared to non-GAAP income from operations of $15 million during the same quarter a year ago.
    • “The company’s results easily topped Wall Street analyst estimates, with a revenue target of $172 million for the quarter and a Street estimate of $31.2 million for operating income.”
  • and
    • “Amwell, the telehealth platform formerly known as American Well, brought in $54.9 million in first-quarter revenue, down approximately 18% the same period a year ago, as executives discussed artificial intelligence and key contract renewals with investors on Tuesday.
    • “The company is shifting towards subscription revenue, and in Q1, subscription software revenue was 53% of total revenue at $24.9 million, which Chief Financial Officer Mark Hirschhorn said was down “approximately 23%” year-over-year in a May 5 call to discuss Q1 results. 
    • “Encouragingly, renewals and retention were higher than budgeted in the first quarter, providing greater confidence in the stability of our subscription base going forward,” Hirschhorn said.
    • “Amwell’s visit volume was down approximately 19% compared to a year ago, according to Hirschhorn, with 1.1 million visits in Q1. Hirschhorn said the figure is “is in line with the portfolio changes” previously disclosed by the company.”
  • The Wall Street Journal lets us know,
    • “BioNTech plans to shrink its workforce and manufacturing network to cut costs after Covid-19 vaccine demand waned.
    • “The company will affect 1,860 roles, about 22% of its 8,400-person workforce, and exit manufacturing plants.
    • “BioNTech will hand Covid shot supply to Pfizer, pivot to cancer therapies, and projects 500 million euros in annual savings by 2029.”
  • and
    • “Bayer agreed to acquire Perfuse Therapeutics, an eye disease drug specialist, for up to $2.45 billion.
    • “The acquisition aims to complement Bayer’s ophthalmology pipeline, following patent expiration issues with its Eylea drug.
    • ‘Perfuse’s lead drug candidate is an experimental treatment for glaucoma and diabetic retinopathy in mid-stage trials. Bayer will pay $300 million upfront.”
  • Per Fierce Pharma,
    • “Since the start of the decade, Eli Lilly has committed to spend more than $50 billion to bolster its United States manufacturing capabilities. But even that’s not enough to meet the needs of the rapidly growing pharma giant.
    • “On Wednesday, Lilly said that it has earmarked another $4.5 billion to further build up two of three planned production facilities in Lebanon, Indiana, some 28 miles northwest of Lilly’s headquarters in Indianapolis. The company revealed the new investment at a ribbon cutting ceremony for its genetic medicine plant in Lebanon, the first of the three new facilities at the site to become operational.
    • “Of the sum Lilly has pledged to spend for its domestic manufacturing in this decade, more than $21 billion has been allocated for the buildup in its home state. Lilly’s “evolving pipeline” and shifts in the anticipated demand for its products dictated the additional funding, the company said.”