Monday report

Monday report

From Washington, DC

  • Federal News Network reports,
    • “Federal employees’ retirement applications are continuing to flood the Office of Personnel Management. In February, another 31,000 retirement claims entered the agency’s systems. That puts OPM’s Retirement Services center at yet another record high of pending applications — now reaching above 65,000 cases with pensions that are yet-to-be finalized. That’s an 88% increase since OPM’s inventory last October, when retirements from the deferred resignation program first began trickling in.” 
  • The Government Accountability Office posted a report titled “Private Dental and Vision Insurance: Market Concentration Varied Among States.”
    • “As in health insurance markets, people looking for dental or vision insurance may face a concentrated market—i.e., only a few companies to choose from. Consumer choice may also be affected by “vertical integration”—e.g., when a vision insurance company owns the ophthalmologist’s practice and the company that makes glasses frames and lenses.
    • “Dental and vision insurance market concentration varied across states. Little research is available that shows the effects of concentration and vertical integration in these markets. Groups representing dental and vision care insurers, providers, and consumers shared varying opinions on potential effects.”
  • The American Hospital Association New tells us,
    • “March 8-14 marks Patient Safety Awareness Week. The AHA has several resources including podcasts, videos and reports that show how AHA members are advancing patient safety through innovative programs and technologies. LEARN MORE” 
  • Beckers Clinical Leadership adds,
    • “The use of artificial intelligence in diagnosis, rural healthcare access and federal funding cuts are among the most pressing patient safety concerns facing healthcare organizations in 2026, according to a new report from the Emergency Care Research Institute and the Institute for Safe Medication Practices.” * * *
    • “Here are the 10 most pressing patient safety challenges in 2026, per the report:
      • “Navigating the AI diagnostic dilemma
      • “Reduced access to rural healthcare increases health risks and disparities
      • “Increasing rates of preventable acute diseases in communities and healthcare settings 
      • “Effects of federal funding cuts on healthcare operations and patient safety 
      • “Lack of recognition and reporting of harm events
      • “Structural and systemic barriers inhibit equitable pain management for women
      • “Persistent workforce shortages continue to burden staff and restrict access to care 
      • “The impact on system improvement when a culture of blame hinders learning
      • “Emergency department boarding contributes to worse patient outcomes 
      • “Persistent gaps in manufacturer packaging and labeling design continue to undermine medication safety efforts.   

From the Food and Drug Administration front,

  • Fierce Pharma reports,
    • “The FDA is doubling down on its goal to increase biosimilar drug availability in the U.S. with a fresh draft guidance proposing more changes to streamline development of the cheaper biologic copies. 
    • “The newly proposed guidance (PDF) focuses on clinical pharmacokinetic (PK) testing, a core aspect of biosimilar drug testing that serves as a key comparative test to weigh a proposed biosimilar against the approved product it references.
    • “In its draft guidance, the FDA offers recommendations for streamlining unnecessary PK testing when “scientifically justified,” a change that could save biosimilar drugmakers up to 50% of their PK study costs, which equates to about $20 million, the agency said in a press release.
  • and
    • “In a dizzying span of seven months in 2022, Bristol Myers Squibb gained FDA approval for three new products, touting each with the potential to achieve $4 billion in peak sales. 
    • “While multiple myeloma drug Opdualag and cardiomyopathy treatment Camzyos became blockbusters last year, psoriasis med Sotyktu wasn’t close.
    • “With a new FDA nod in hand for Sotyktu, however, BMS can reach more patients with the oral med, which was acquired in the drugmaker’s 2019 buyout of Celgene for $74 billion.
    • “The U.S. regulator has endorsed Sotyktu as a treatment for adults with active psoriatic arthritis. It becomes the first drug in its class as a selective allosteric tyrosine kinase 2 (TYK2) inhibitor to be approved in the indication. The thumbs up comes on top of Sotyktu’s original FDA approval for moderate-to-severe plaque psoriasis.”

From the judicial front,

  • The AHA News reports,
    • “The U.S. District Court for the Southern District of Florida March 6 ruled in favor of five Florida hospitals in a case challenging the methodology used by the Leapfrog Group regarding hospital safety ratings. In particular, the court determined that Leapfrog’s methodology violated Florida’s unfair and deceptive business practices law. “Leapfrog’s change in methodology has no scientific basis, unfairly penalizes non-participating hospitals, and misrepresents hospital safety,” Judge Donald M. Middlebrooks wrote. The court’s injunction requires Leapfrog to cease assigning safety grades to hospitals, remove grades assigned to the plaintiff hospitals in 2024 and 2025, and issue corrective disclosures, along with other actions.”
  • Per a Justice Department news release,
    • “A Texas man was sentenced Friday to 90 months in prison for his role in a $59.9 million conspiracy to pay kickbacks and submit claims for medically unnecessary durable medical equipment (DME) to Medicare.
    • “According to court documents, Patrick Cassells, 65, of Fulshear, Texas, owned and operated three DME companies and concealed his role in one of those companies by falsely identifying another individual as the sole owner and manager in a Medicare enrollment application. Cassells paid illegal kickbacks to co-conspirators who sent him signed doctors’ orders and other paperwork necessary to bill Medicare for orthotic braces such as knee, back, shoulder and wrist braces. The kickbacks were disguised by referring to the doctors’ orders as “leads” and the services provided as “marketing.” Based on these orders, which were issued without doctors examining or treating the patients, Cassells submitted claims to Medicare that falsely represented that the braces were medically necessary. In total, through the three companies, Cassells caused over $59.9 million in false and fraudulent claims to Medicare, for which Medicare paid over $27 million. Cassells used proceeds of the fraud to purchase personal vehicles and vehicles that he intended to export to Nigeria.
    • “In June 2024, Cassells pleaded guilty in the Southern District of Texas to one count of conspiracy to commit health care fraud.
    • “In addition to the prison sentence, Cassells was ordered to pay $25,402,614.97 in restitution and forfeiture, and to forfeit four vehicles and three properties in the Houston area.”

From the public health and medical / Rx research front,

  • The Hill reports
    • “New data showed childhood obesity has hit a record high in recent years, while federal changes such as cuts to food assistance programs and a revamped food pyramid reignite debates over how to handle the issue.  
    • “A Centers for Disease Control and Prevention (CDC) report late last month showed more than 1 in 5 U.S. children and teenagers were obese between 2021 to 2023, compared to only 5.2 percent between 1971-1974. The number of children with severe obesity in recent years has hit 7 percent.
    • “School meals, physical activity and weight loss drugs have all become talking points in the problem, which is a major issue in the “Make America Healthy Again” movement associated with Health and Human Services Secretary Robert F. Kennedy Jr.
    • “Experts point to school meals and increased activity as key ways to address childhood obesity, with research showing school meals are the healthiest eating options some students have all day.  
    • “They’re noting that this increase in obesity occurred during COVID-19 and that jump in childhood obesity happened during the years when millions of kids lost access to reliable school meals. So, when schools closed for virtual learning, children lost a critical source of daily nutrition,” said Erin Hysom, senior child nutrition policy analyst on the Child Nutrition Programs and Policy team for the Food Research & Action Center.” 
  • The American Medical Association lets us know what doctors wish their patients knew about multiple sclerosis.
  • Brown & Brown released a guide for employers on how to support women’s heart health.
  • MedPage Today tells us,
    • “Infection with Kaposi sarcoma-associated herpesvirus (KSHV) is the cause of Kaposi sarcoma, a type of cancer where lesions grow on the skin and other parts of the body.
    • “This CDC report detailed 46 cases of suspected donor-derived KSHV-related complications among 153 transplant recipients from 2021-2025, roughly five times the number of cases reported from 2016-2020.
    • “Of the 74 transplant recipients identified as having a KSHV infection, 61% developed Kaposi sarcoma.” * * *
    • “A key challenge is the lack of an FDA-approved serology assay to screen for KSHV in donors and recipients. The existing assay for clinical testing is operator-dependent and not easy to scale, Durand noted. A molecular PCR-based assay could theoretically monitor transplant recipients for infection, she added, “but we don’t know who to monitor, how often to monitor, nor what to do with a positive test.”
    • “Despite the challenges, Durand recommended that clinicians keep the KSHV diagnosis in mind, particularly in lung and liver recipients who present with signs and symptoms that might be explained by the virus.”
  • and in better news,
    • “Along with the use of AI, routine screening mammograms could identify women at higher risk of cardiovascular disease, a retrospective cohort study suggested.
    • “A greater amount of AI-calculated breast arterial calcification on imaging was associated with an increased risk of major adverse cardiovascular events.
    • “These findings indicate an opportunity to use routine mammograms for early cardiovascular risk stratification without additional radiation exposure.”
  • Health Day tells us,
    • “Telemedicine has not led to a significant rise in new mental health patients from rural or underserved communities
    • ‘High use of virtual visits led to a 3.6% decrease in the total number of new patients seen by therapists
    • “State licensing laws are likely the barrier to reaching patients across state lines.”
  • Genetic Engineering and BioTechnology News informs us,
    • “Researchers at Washington University School of Medicine in St. Louis have developed genetically altered astrocytes that express chimeric antigen receptors (CARs) as a promising immunotherapy system capable of clearing accumulations of amyloid-β (Aβ)—a hallmark pathological feature of Alzheimer’s disease (AD)—in the brains of mice.
    • “Recently approved anti-Aβ antibody therapies have shown moderate success in slowing AD progression. However, these treatments require large doses, repeated administration, and are associated with potentially serious side effects.
    • “To reduce the frequency of treatment and potentially improve the efficacy of anti-amyloid therapy, scientists headed by Marco Colonna, MD, the Robert Rock Belliveau, MD, professor of pathology at WashU Medicine engineered CAR-expressing astrocytes—CAR-As, as a new type of cellular immunotherapy. Their tests in mice showed that a single injection of the CAR-A treatment prevented amyloid plaques from developing when given before plaques start to form. A single treatment in animals that had already developed plaques also cut the amount of amyloid plaques in half.
    • “This study marks the first successful attempt at engineering astrocytes to specifically target and remove amyloid beta plaques in the brains of mice with Alzheimer’s disease,” said Colonna. “Although more work needs to be done to optimize the approach and address potential side effects, these results open up an exciting new opportunity to develop CAR-astrocytes into an immunotherapy for neurodegenerative diseases and even brain tumors.”
  • STAT News points out,
    • “Xenon Pharmaceuticals said Monday that its treatment for a common type of seizure disorder significantly reduced the frequency of those seizures compared to a placebo — achieving the main goal of a Phase 3 clinical trial. 
    • “The new study results also exceeded the treatment effect reported in the company’s previous mid-stage study. 
    • Xenon said it expects to seek the approval of its drug, called azetukalner, with the Food and Drug Administration in the third quarter. 
    • “In the Phase 3 study, a 25 mg dose of azetukalner reduced the frequency of seizures over a month by 53% compared to 10% in the placebo arm. The difference, just under 43 percentage points, was statistically significant. Participants were treated for 12 weeks.
    • “A 15 mg dose of azetukalner also reduced seizure frequency more than placebo with statistical significance.” 
  • Per BioPharma Dive,
    • “Bristol Myers Squibb said Monday that a regimen including its experimental protein-degrading drug mezigdomide produced positive results in a late-stage trial of patients with relapsed or refractory multiple myeloma.
    • “Investigators found that a combination of mezigdomide and two other standard myeloma therapies was associated with a “statistically significant and clinically meaningful improvement” in progression-free survival when compared to treatment with those two other drugs. Bristol didn’t provide specifics, but said that safety findings were “consistent” with the known profile of mezigdomide and the other components of the regimen.
    • “Mezigdomide is one of several protein-degrading therapies that Bristol Myers acquired in 2019 buyout of Celgene and sees as successors to blood cancer drugs Revlimid and Pomalyst. Another, iberdomide, hit one of its primary goals in a Phase 3 study late last year and is now under review by the Food and Drug Administration.”
  • and
    • “Roche’s experimental drug giredestrant missed the main goal of a Phase 3 trial testing it as an initial treatment for breast cancer, the company said Monday. A combination of the therapy and Pfizer’s Ibrance failed to delay progression or death compared to Ibrance and hormone treatment.
    • “The data is a blow to the Swiss drugmaker’s ambitions for giredestrant, which is already under Food and Drug Administration review in people whose breast cancer has progressed and succeeded in staving off relapses after surgery.
    • “The trial’s failure will also likely reinforce doubts about the commercial potential of drugs in giredestrant’s class, called oral SERDs. The two approved drugs in the class, Menarini’s Orserdu and Eli Lilly’s Inluriyo, have so far only been approved for people whose breast cancer carries a certain mutation.”

From the U.S. healthcare business and artificial intelligence front,

  • Modern Healthcare announced its Leading Women 2026. Congrats to them.
  • Fierce Healthcare announced its Fierce 15 healthcare companies.
  • BioPharma Dive reports,
    • “Novo Nordisk will begin offering its popular obesity drugs on Hims & Hers’ telehealth platform, ending a messy dispute that resulted in a lawsuit and a crackdown by U.S. drug regulators. 
    • “Under a deal announced Monday, Hims will provide access to Novo’s GLP-1 medicines — the diabetes drug Ozempic and the injectable and pill forms of the weight loss therapy Wegovy — to U.S. consumers at the same prices as other telehealth firms. Hims will no longer promote “compounded” versions of GLP-1 drugs on its website or in advertisements, and will give existing patients the chance to switch to “FDA-approved alternatives,” according to a statement from Novo. 
    • “Novo will, as a result, dismiss its patent infringement lawsuit against Hims while “reserving the right to refile in the future.” News of the deal was first reported by Bloomberg.”
  • Beckers Hospital Review adds,
    • “Amazon Pharmacy has added Eli Lilly’s Zepbound KwikPen in the 2.5-mg starter dose for $299 per month through its cash-pay model.
    • “Zepbound is a multidose injectable medication approved for chronic weight management and, more recently, moderate-to-severe obstructive sleep apnea. With a valid prescription, Amazon customers can order the KwikPen online for home delivery, including same-day delivery in nearly 3,000 cities and towns, according to a March 9 news release. That reach is expected to grow to 4,500 locations by the end of 2026.
    • “Amazon Pharmacy has supplied GLP-1 medications since 2021 and works with partners including LillyDirect, WeightWatchers, UpScriptHealth and Noom. To date, the company said, its platform has saved customers “more than $200 million,” with GLP-1s representing the largest share of savings, according to the release.”
  • and
    • “New York City-based NewYork-Presbyterian is beginning to see early signals from its hospital-at-home program, which launched in November 2025 as health systems across the country continue testing whether acute-level hospital care can be delivered safely in patients’ homes.
    • “The model allows certain patients who would otherwise require inpatient admission to receive hospital-level treatment at home through a combination of in-person nursing visits, remote patient monitoring and virtual physician oversight. Programs like these expanded rapidly during the COVID-19 pandemic under a federal waiver that allowed hospitals to bill Medicare for hospital-at-home services.
    • “Although the waiver was extended until 2030, many health systems are still evaluating whether the care model can deliver consistent outcomes and operational reliability outside traditional hospital walls.
    • “At NewYork-Presbyterian, early data has been encouraging.”
  • Per a Blue Cross news release,
    •  “New research from the Blue Cross Blue Shield Association (BCBSA) and its data analytics partner Blue Health Intelligence® (BHI®) suggests that the growing use of AI in hospital billing is driving higher health care costs by increasing the number and severity of diagnoses billed without any record of the expected treatment.
    • “Analyzing de-identified claims data from tens of thousands of maternity admissions nationwide, researchers found a sharp increase in cases coded for acute posthemorrhagic anemia, a serious condition that typically requires interventions such as blood transfusions. However, many patients coded with the diagnosis never received those treatments.
    • “Something is disconnected,” said Dr. Razia Hashmi, BCBSA’s vice president of Clinical Affairs. “Among hospitals showing the fastest rise in diagnoses of post-partum anemia, the rise in patients coded with this condition wasn’t paired with the level of care we would have expected, and the patterns we’re seeing point to AI‑enabled coding.”
    • “The cost impact is significant, reaching approximately $2.3 billion in spending:
      • “Researchers estimate that roughly $663 million in inpatient spending and at least $1.67 billion in outpatient spending may be tied to more aggressive, AI-enabled coding practices nationwide.”
  • Healthexec shares “four points about healthcare AI that notable experts are emphasizing in the public square.”
  • Per MedTech Dive,
    • “Agilent Technologies said Monday it agreed to acquire Biocare Medical for $950 million in cash to expand its pathology portfolio.
    • “Biocare’s antibody, reagent and instrument business complements Agilent’s offerings in clinical and research pathology and includes immunohistochemistry and in situ hybridization, Agilent said. 
    • “Since 2021, Biocare has generated annual double-digit revenue and profit growth. Revenue exceeded $90 million in 2025. The laboratory instruments and services provider is buying Biocare from an investor group led by Excellere Partners and GHO Capital Partners.”
  • and
    • “Zimmer Biomet shared data on its smart knee implant at the American Academy of Orthopaedic Surgeons conference on Wednesday.
    • “The company found that patients who used its Persona IQ implant with a care management platform had better outcomes a year after surgery than people with a traditional knee implant. 
    • “Mike Anderson, Zimmer’s clinical strategy associate director, said the results of the analysis showed that the company’s technology was associated with lower rates of revision surgery and periprosthetic joint infection, less use of opioids, and fewer visits to urgent care and physical therapy.” 

Cybersecurity Saturday

From the Iran War front,

  • Security Week reports,
    • “The Iranian APT MuddyWater has hacked into the networks of several organizations in the US, including an aerospace and defense contractor, Broadcom’s Symantec and Carbon Black threat hunting team reports.
    • “The threat actor has been present in the environments of an airport, a bank, a non-governmental organization operating in the US and Canada, and a software company with a presence in Israel.
    • “According to the Broadcom experts, the APT’s activity has continued “in recent days following US and Israeli military strikes on Iran that have sparked conflict in the region”.
  • Cybersecurity Dive adds,
    • “Pro-Russia threat actors have formed a loose coalition with Iran-nexus hacking groups in response to the bombing campaign launched by the U.S. and Israel on Iran. 
    • “The groups began working together Monday under the #OpIsrael campaign, with a focus on targeting critical infrastructure and exfiltration of data, according to researchers at Flashpoint.” * * *
    • Researchers at Palo Alto Networks Unit 42 estimate that about 60 threat actors, including Iran-nexus and Russia-aligned groups, might be involved in various levels of hacking activity since the bombing campaign began.”  
  • The American Hospital Association News tells us,
    • “The FBI is reminding critical infrastructure organizations to implement mitigations from a June 2025 fact sheet on potential actions by Iranian-affiliated cyber actors who may target U.S. devices and networks due to geopolitical tensions. The fact sheet explains how cyber actors often exploit targets with unpatched or outdated software with known common vulnerabilities or passwords.  
    • “In the context of the ongoing conflict with Iran, it is particularly important to ensure that we are implementing cybersecurity measures to defend against the known tactics used by Iranian state-sponsored hackers or pro-Iranian hackers acting independently,” said John Riggi, AHA national advisor for cybersecurity and risk. “Besides seeking to exploit common vulnerabilities and default passwords, they also target internet-connected operational technology and industrial control systems. These systems may be present in hospitals in the form of HVAC, water, life-safety and building automation systems. It is recommended that cyber teams closely coordinate with facilities and building engineers to identify internet-facing OT and ICS systems, assess the need for internet connectivity and ensure they are patched and secure.”

From the cybersecurity policy and law enforcement front,

  • The Wall Street Journal reports,
    • “The Trump administration published its new cyber strategy Friday [March 6], framing digital security in the context of broader geopolitical issues and promising to incentivize the private sector to identify and disrupt cyber adversaries.
    • “Compared with the Biden administration’s 2023 National Cybersecurity Strategy, which ran more than 35 pages and detailed dozens of policy initiatives, the new document is far shorter at five pages and sets out broad principles for future policy decisions and priorities.”
  • Cyberscoop adds,
    • “The strategy “calls for unprecedented coordination across government and the private sector to invest in the best technologies and continue world-class innovation, and to make the most of America’s cyber capabilities for both offensive and defensive missions,” the White House said in a statement accompanying its release.”
    • “Trump also signed an executive order Friday directing agencies to take action to combat cybercrime and fraud.”
  • The Congress did not resolve the Department of Homeland Security shutdown this week.
  • Fedscoop reports,
    • “The Department of Homeland Security is undergoing an overhaul of its IT and information security leadership, with multiple sources telling FedScoop there is a broad realignment underway at the department to replace key technology leaders.
    • “FedScoop has learned that at least two DHS officials are being replaced: Chief Information Security Officer Hemant Baidwan and Deputy CISO Amanda Day. 
    • “The reorg among IT officials comes as other leadership is changing at the department. President Donald Trump announced Thursday that Secretary of Homeland Security Kristi Noem will be leaving the position at the end of March. Trump has nominated Sen. Markwayne Mullin, R-Okla, as her replacement.
  • Cybersecurity Dive adds,
    • “The confirmation prospects for Sean Plankey, President Donald Trump’s nominee to lead the Cybersecurity and Infrastructure Security Agency, have dimmed further following Plankey’s unceremonious departure from a job at the Department of Homeland Security.
    • “Security personnel escorted Plankey out of a DHS facility on Monday, a person familiar with the matter told Cybersecurity Dive, confirming an incident first reported by CBS News. Plankey announced on Wednesday that he had left his job as a senior Coast Guard adviser to DHS Secretary Kristi Noem, but he framed his departure as a voluntary one intended to help him focus on his nomination to serve as CISA director.”
  •  Per an HHS news release,
    • “Today [March 5], the U.S. Department of Health and Human Services’ (HHS) Office for Civil Rights (OCR) announced a settlement with MMG Fusion, LLC (MMG), a Maryland software company, concerning potential violations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy, Security, and Breach Notification Rules. MMG is a business associate as it receives protected health information (PHI) from HIPAA covered entities and its software is used to communicate directly with patients of covered entities.” * * *
    • “The settlement resolves an investigation that OCR initiated in March 2023 after receiving a complaint concerning an unreported security incident at MMG, and the posting of PHI on the dark web. OCR’s investigation determined that in December 2020, an unauthorized actor infiltrated MMG’s information system and accessed PHI [of 15 million people], including names, phone numbers, mailing addresses, email addresses, dates of birth, and dates and times of medical appointments.” * * *
    • “The resolution agreement and corrective action plan may be found at https://www.hhs.gov/sites/default/files/ocr-mmg-fusion-hipaa-agreement.pdf [PDF, 264 KB].”
  • Cybersecurity Dive informs us,
    • “An international coalition led by Microsoft and Europol has taken down the operations of Tycoon 2FA, a notorious phishing-as-a-service platform that helped cyber criminals gain access to millions of email accounts across the globe. 
    • “Microsoft obtained a court order from the U.S. District Court from the Southern District of New York to seize 330 active domains used to back the core infrastructure of Tycoon 2FA.
    • “Taking this infrastructure offline cuts off a major pipeline for account takeovers and helps protect people and organizations from follow-on attacks such a data theft, ransomware, business email compromise and financial fraud,” Steve Masada, assistant general counsel at Microsoft’s Digital Crimes Unit, said in a blog post published Wednesday.” 
  • Bleeping Computer lets us know,
    • “The FBI has seized the LeakBase cybercrime forum, a major online forum used by cybercriminals buy and sell hacking tools and stolen data.
    • This seizure action is part of an international joint operation coordinated by Europol, known as “Operation Leak,” that involved law enforcement agencies in 14 countries.
    • On March 3 and 4, the FBI and law enforcement agents shut down LeakBase by seizing two of its domains, posting seizure banners, and warning LeakBase members of the seizure after collecting further evidence.” * * *
    • Today’s [March 4] announcement follows the disruption of RaidForums in 2022 and BreachForums in 2023, two cybercrime marketplaces that preceded it, as well as the BreachForums founder’s conviction and sentencing in 2025.
  • and
    • “A U.S. government contractor’s son, accused of stealing more than $46 million in cryptocurrency from the U.S. Marshals Service, was arrested Wednesday on the island of Saint Martin.
    • “The arrest was the result of a joint operation between the FBI and France’s elite Groupe d’Intervention de la Gendarmerie Nationale, FBI Director Kash Patel announced on Thursday.
    • “Last night, John Daghita – a U.S. government contractor who allegedly stole more than $46 million in cryptocurrency from the U.S Marshals Service – was arrested on the island of Saint Martin by the French Gendarmerie’s premier elite tactical unit in a joint operation with the @FBI,” Patel said.”
  • Cyberscoop points out,
    • “Russian national Evgenii Ptitsyn pleaded guilty to running the Phobos ransomware outfit that extorted more than $39 million from more than 1,000 victims globally, the Justice Department said Wednesday.
    • “Ptitsyn assumed a leadership role in the Phobos ransomware group in January 2022, yet his criminal activities began by April 2019, according to court records. He continued leading the cybercrime syndicate until May 2024 when he was arrested in South Korea. Ptitsyn was extradited to the United States in November 2025.
    • “Federal prosecutors dropped multiple charges against Ptitsyn as part of a plea agreement he signed last month. He faces up to 20 years in prison for wire fraud conspiracy.
    • “Ptitsyn agreed to forfeit $1.77 million in assets and is required to pay at least $39.3 million in restitution, representing the full amount of his victims’ losses.

From the cybersecurity breaches and vulnerabilities front,

  • The Wall Street Journal reports on March 6,
    • “U.S. investigators believe hackers affiliated with the Chinese government are responsible for a cyber intrusion on an internal Federal Bureau of Investigation computer network that holds information related to some domestic surveillance orders, according to people familiar with the matter.
    • “The scope and severity of the intrusion aren’t known, and the investigation is in its early stages, the people said. Any preliminary conclusions could change as investigators gather more information. 
    • “If China is confirmed to be responsible for the breach, it would signal the latest intrusion by Beijing’s hackers of computer systems related to law-enforcement surveillance orders, which contain highly sensitive material.
    • “A notification sent in recent days to some lawmakers in Congress said the FBI began investigating the matter last month, the people said. The intrusion involved hackers accessing an unclassified system that contains information about the calls and internet activity of criminal suspects and others under government surveillance. Information in the system includes incoming and outgoing calls, IP and website addresses and some routing information, but doesn’t include the contents of calls or digital communication.” 
  • Cybersecurity Dive adds,
    • “A total of 90 zero-day vulnerabilities were exploited in the wild in 2025, according to a report released Thursday by Google Threat Intelligence Group.
    • “Of that total, almost half of the exploited vulnerabilities were used against enterprise-grade technology, marking an all-time high. 
    • “Exploitation from state-sponsored groups targeted networking and security tools with a strong emphasis on edge devices, which often lack endpoint detection and response capabilities, according to GTIG researchers. 
    • “China-nexus groups remain the most prolific state-sponsored groups, with a long history of detailed knowledge of vulnerable devices. 
    • “They have a significant zero-day development ecosystem that includes industry, academia, and government,” John Hultquist, chief analyst at GTIG, told Cybersecurity Dive.”
  • Bleeping Computer relates,
    • “TriZetto Provider Solutions, a healthcare IT company that develops software and services used by health insurers and healthcare providers, has suffered a data breach that exposed the sensitive information of over 3.4 million people.
    • “The firm, which has been operating under the Cognizant umbrella since 2014, disclosed that it detected suspicious activity on a web portal on October 2, 2025, and launched an investigation with the help of external cybersecurity experts.
    • “The investigation revealed that unauthorized access began nearly a year before, on November 19, 2024.’ * * *
    • “Affected providers were alerted on December 9, 2025, but customer notification started in early February 2026. According to a filing Maine’s Attorney General submitted today [March 6], the number of exposed individuals is 3,433,965.
    • “TriZetto says that payment card, bank account, or other financial information was not exposed in this incident. Also, the company is not aware of any cases where cybercriminals have attempted to misuse this information.”
  • CISA added seven known exploited vulnerabilities to its catalog this week.
    • March 3, 2026
      • CVE-2026-21385 Qualcomm Multiple Chipsets Memory Corruption Vulnerability
      • CVE-2026-22719 Broadcom VMware Aria Operations Command Injection Vulnerability
        • Cybersecurity News discusses the Qualcomm KVE here.
        • Bleeping Computer discusses the VM Aria KVE here.
    • March 5, 2026
      • CVE-2017-7921 Hikvision Multiple Products Improper Authentication Vulnerability
      • CVE-2021-22681 Rockwell Multiple Products Insufficient Protected Credentials Vulnerability
      • CVE-2021-30952 Apple Multiple Products Integer Overflow or Wraparound Vulnerability
      • CVE-2023-41974 Apple iOS and iPadOS Use-After-Free Vulnerability
      • CVE-2023-43000 Apple Multiple products Use-After-Free Vulnerability
        • The Hacker News discusses the Hikvision and Rockwell KVEs here.
        • Bleeping Computer discusses the Apple KVEs here.
  • Cyberscoop adds,
    • “Cisco released information on a pair of max-severity vulnerabilities in its firewall management software Wednesday that unauthenticated, remote attackers could exploit to obtain the highest level of access to the underlying operating system or on affected devices.
    • “The vulnerabilities — CVE-2026-20079 and CVE-2026-20131 — affect the web-based interface of Cisco Secure Firewall Management Center (FMC) Software, regardless of device configuration, the vendor said.
    • “Cisco disclosed the critical vulnerabilities one week after it warned that attackers have been exploiting a pair of zero-days in Cisco’s network edge software for at least three years. That campaign, which is ongoing, marked the second series of multiple actively exploited zero-days in Cisco edge technology since last spring. 
    • “Both campaigns prompted the Cybersecurity and Infrastructure Security Agency to issue emergency directives months after the attacks were first detected, and both attack sprees were underway for at least a year before they were discovered.” 
  • and
    • “Google disclosed one actively exploited zero-day vulnerability Monday, warning that the high-severity defect affecting an open-source Qualcomm display component for Android devices “may be under limited, targeted exploitation.”
    • “The memory-corruption vulnerability — CVE-2026-21385 — which Google’s Androidsecurity team reported to Qualcomm Dec. 18, affects 234 chipsets, Qualcomm said in a security bulletin. Qualcomm said it notified customers of the vulnerability Feb. 2.
    • “Qualcomm declined to say when the earliest known instance of exploitation occurred, how many victims have been directly impacted, and what occurred during the 10-week period between the reporting and public disclosure of the vulnerability. 
    • “We commend the researchers from Google’s Threat Analysis Group for using coordinated disclosure practices,” a Qualcomm spokesperson told CyberScoop. “Fixes were made available to our customers in January 2026. We encourage end users to apply security updates as they become available from device makers.”
  • and
    • “North Korean threat groups are using artificial intelligence tools to accelerate and expand the country’s long-running scheme to get remote technical workers hired at global companies for longer durations, Microsoft Threat Intelligence said in a report Friday. 
    • “AI services are empowering North Korean operatives across the attack lifecycle. Attackers have turned AI into a “force multiplier” that bolsters and automates their efforts to conduct research on targets, develop malicious resources, achieve and maintain access, evade detection, and weaponize tools for attacks and post-compromise activities, researchers said.
    • “Microsoft said a trio of groups it tracks as Coral Sleet, Sapphire Sleet and Jasper Sleet are using AI to shorten the time it takes to create digital personas for specific job markets and roles. These groups frequently leverage financial opportunities or interview-themed lures to gain initial access.”
  • The Hacker News notes,
    • “Cybersecurity researchers have disclosed details of a new phishing suite called Starkiller that proxies legitimate login pages to bypass multi-factor authentication (MFA) protections.
    • “It’s advertised as a cybercrime platform by a threat group calling itself Jinkusu, granting customers access to a dashboard that lets them select a brand to impersonate or enter a brand’s real URL. It also lets users choose custom keywords like “login,” “verify,” “security,” or “account,” and integrates URL shorteners such as TinyURL to obscure the destination URL.
    • “It launches a headless Chrome instance – a browser that operates without a visible window – inside a Docker container, loads the brand’s real website, and acts as a reverse proxy between the target and the legitimate site,” Abnormal researchers Callie Baron and Piotr Wojtyla said.”

From the ransomware front,

  • The Record reports,
    • “The University of Hawaiʻi Cancer Center said up to 1.2 million people had information leaked as a result of a ransomware attack on its epidemiology division last year. 
    • “Hackers accessed records containing Social Security numbers (SSNs) and driver’s license numbers collected from the Hawaiʻi State Department of Transportation as well as City and County of Honolulu voter registration records from 1998, according to a statement released by the organization last week.” * * *
    • “In January, the university sent a report to the state legislature that said the cyber incident was first discovered on August 31, 2025.” * * *
    • “Naoto Ueno, director of the University of Hawaiʻi Cancer Center, apologized for the incident last week and said the organization was “committed to transparency.” 
    • “The university said the attackers encrypted and likely exfiltrated data, prompting them to notify law enforcement and hire cybersecurity experts to resolve the situation. The cybersecurity firm obtained a decryption tool and secured “an affirmation that any information obtained was destroyed.”  
    • “University officials claimed there is “no evidence that any of the information has been published, shared or misused.” The group responsible for the attack was not identified.”   
  • Cybersecurity Dive relates,
    • “Identity has replaced malware as the biggest threat vector opening the door for ransomware attacks, Cloudflare said in an annual threat report published on Tuesday.
    • “Hackers’ increasing use of legitimate credentials, rather than malicious code, is making it harder for defenders to detect and contain their attacks.
    • “Cloudflare’s new report also discussed nation-state threat actors’ behavior and how artificial intelligence is changing attacks.”
  • Mobihealth News interviews Scott Doerr, virtual CISO, or vCISO, at Fortified Health Security, [who] previews his upcoming talk at the 2026 HIMSS Global Health Conference & Exposition, where he will discuss how healthcare companies can strengthen their preparedness for ransomware attacks. 

From the cybersecurity business and defenses front,

  • Cyberscoop reports,
    • “CrowdStrike Holdings reported record earnings in the fiscal fourth-quarter, defying investor concerns about the rising use of agentic AI potentially curbing demand for cybersecurity software and services. 
    • “The Texas-based cybersecurity company said total revenue grew 23% on a year-over-year basis, to $1.31 billion in the quarter ended Jan. 31. 
    • “Annual recurring revenue, a closely watched metric among cybersecurity companies, grew 24%, to $5.25 billion. 
    • “The results come at a time of growing market anxiety about how AI adoption could render traditional software — including cybersecurity tools — obsolete. CrowdStrike executives acknowledged those larger industry concerns and noted the Q4 performance was a demonstration that certain companies were well-positioned to compete in the new marketplace.” 
  • ZDNet adds,
    • “Anthropic, OpenAI, and Google tools can automate code debugging. 
    • “But cybersecurity is too complex a problem for these tools to solve. 
    • “AI’s biggest contribution may be to reduce avoidable software flaws. 
  • Healthexec relates,
    • “In January, National Security Agency (NSA), released protocols for the U.S. Department of War to achieve “zero trust” security across the agency, meaning any access to the network must come from something continually inside it. While such a setup would be technically demanding for healthcare, the American Hospital Association (AHA) said it may be time for facilities to start moving in that direction.
    • “Zero trust security would mean radical changes for hospitals, where a countless number of devices have access to networks, including everything from EHRs to medical devices, to tablets and smartphones used for communication.
    • “What the NSA wants the Department of War to adopt is a system where no one gains access to a network from the outside, meaning no logins or passwords. In fact, even systems connected to the network from the inside are not automatically trusted.
    • “In other words, every user, device, and system must continually prove they are allowed access—and access is limited strictly to what’s necessary.
    • “The ethos of zero trust means that it’s assumed even the network itself isn’t safe, hence the continuous verification. Something like a two-factor authentication app displaying a constant active code would be required to log on.”
  • The AHA News adds,
  • SC World tells us,
    • “The 2026 Zero Trust World conference kicked off here Wednesday (March 4) with a particularly optimistic keynote by futurist and TV host Jason Silva and also featured a last-minute addition in the form of a talk by former White House CIO Theresa Payton.
    • “But it was the smaller sessions, including a dark-web primer and a live Security Now! podcast broadcast featuring cybersecurity veterans Steve Gibson and Leo LaPorte, that stole the show during the first day of ThreatLocker’s annual user conference.”
  • Tech Target explains “how to perform a data risk assessment, step by step.”
  • Here’s a link to Dark Reading’s CISO Corner.

Thursday report

From Washington, DC

  • The House of Representatives today passed the Department of Homeland Security Appropriations Act, 2026 (HR 7744) by a 221 to 209 vote. The Senate , however, failed to invoke cloture on a similar bill (HR 7147) by a 51-45 vote (60 votes required), meaning the ongoing DHS shutdown will continue.
  • Per a Senate news release,
    • “U.S. Senator Bill Cassidy, M.D. (R-LA), Chairman of the U.S. Senate Health, Education, Labor, and Pensions (HELP) Committee, delivered remarks during today’s hearing on how the U.S. Office of National Coordinator for Health Information Technology (ONC) is improving health outcomes using patient health information.
    • “Click here to watch the full hearing.”
  • Govexec reports,
    • “The Trump administration will continue working to shrink the size of the federal workforce after already shedding more than 300,000 employees, a White House official said on Thursday, who suggested a leaner civil service will be more effective as a result of its reduced stability. 
    • “Continuing to reduce the size of the federal government and its workforce remains “priority number one,” Office of Management and Budget Deputy Director for Management Eric Ueland said at a government efficiency conference in Washington, adding it would contribute to the goal of tackling waste, fraud and abuse. He pledged that individual agencies would ensure consistent and transparent communication on their plans, so employees would at least have a clear roadmap of what is to come even if they disagree with the destination.” * * *
    • “Scott Kupor, the Office of Personnel Management [OPM] Director who also spoke at the panel, said his agency is not giving agencies any specific targets for workforce reduction.” * * *
    • “He added the needs of government will continue to grow, but agencies must find ways to add to their portfolios without adding staff.” 
  • Per an OPM news release,
    • “The US Office of Personnel Management (OPM) today announced the launch of the Attorney Talent Network.
    • “The Attorney Talent Network enables attorneys from across the United States to connect directly with federal recruiters and explore career opportunities in the federal government. By joining the network, attorneys can make their resumes searchable, receive notifications about job openings, and be alerted to upcoming hiring events.” * * *
    • “Attorneys interested in joining can create or log in to their USAJOBS account, upload their resume, and opt in to share their profile with federal recruiters through the here.
    • “For more information or to join the Attorney Talent Network, click here.”
  • The American Hospital Association News tells us,
    • “The Departments of Health and Human Services and Education March 5 announced a new initiative to increase nutrition education in medical schools beginning this fall for the next academic year. The agencies announced commitments from 53 schools for the program, which will provide at least 40 hours of nutrition education or a 40-hour competency equivalent for medical students. HHS also announced $5 million in funding for a multi-phase education challenge by the National Institutes of Health to support medical schools, nursing residency, nutrition science and dietitian programs that integrate nutrition education into their curricula. Additionally, HHS said that Public Health Service officers will be required to complete nutrition-focused continuing education hours as part of their career development.”
  • Newfront offers RxDC reporting considerations for 2026 filings.
  • Per an AHIP news release,
    • “A new national survey finds American workers hold consistently positive views of employer-provided health care coverage, with nearly nine in 10 expressing satisfaction with their plans and strong majorities valuing the financial security and peace of mind their coverage provides.
    • “Employer-provided coverage is the backbone of our nation’s health care system, delivering high-quality, affordable health care and financial security to more than 180 million Americans. These findings confirm once again that Americans strongly value their employer-provided health coverage and want policymakers to support the longstanding partnership between employers and health plans,” said AHIP president and CEO Mike Tuffin.
  • Modern Healthcare points out,
    • “A health insurance industry-backed coalition is going after hospitals in a bid to capitalize on Washington’s bipartisan focus on affordability and rising healthcare costs.
    • “Better Solutions for Healthcare launched its “Hospital Watch” campaign last month. The organization’s website links to news articles and data that are unflattering to the hospital sector. A banner on the home page reads, “Shining a Light on Corporate Hospital Systems’ Role in Driving America’s Healthcare Cost Crisis.”
    • “The effort could prove well-timed. Over the past few years, Congress has focused on drug prices and pharmacy benefit managers — as has President Donald Trump — and on health insurance premiums and industry practices. Their attention may be shifting to providers.”

From the Food and Drug Administration front,

  • The Wall Street Journal lets us know,
    • “Federal health officials, facing criticism from lawmakers for recent rejections of rare-disease drugs, attacked an Amsterdam-based biotech company seeking approval of a Huntington’s disease treatment and accused it of lying.
    • “The public criticism of Uniqure by officials at the Food and Drug Administration and Health and Human Services department was unusual for agencies that normally shy away from commenting on products still under consideration.
    • “The attacks risk further angering members of Congress who have been pressing the Trump administration to be more open to approving rare-disease therapies, after FDA officials rejected or delayed some applications for approval of some new drugs.”
  • STAT News explains,
    • “Is it better to approve a drug with undetermined or debatable benefits that is later found not to be effective?
    • “Or, is it better to reject or block a drug with undetermined or debatable benefits that is later found to be effective?
    • “These are two fundamentally different regulatory philosophies. Peter Marks, the former FDA regulator of cell and gene therapies, was firmly in the “approve now” camp. He believed in maximal flexibility, one might even call it absolute permissiveness.
    • “If there was a chance a treatment could help a patient with a rare disease, even if the data were equivocal, Marks was willing to approve it. Rejecting that drug and later learning that it was effective is a far worse outcome, in Marks’ view.
    • “Vinay Prasad, Marks’ successor at the FDA, takes a maximalist approach in the other direction. He wants to approve drugs that work with certainty. The regulatory bar is high.
    • “Uncertainty — anything outside the statistical fence — is a disqualifier. For Prasad, approving a drug without proven benefit is false hope. Approving a drug that later ends up being ineffective is the worst outcome.
    • “Two regulators, two extreme regulatory philosophies, one replacing the other.
    • “The rare disease community is suffering whiplash. Drugmakers are frustrated. Investors are sitting on their wallets.”
  • Fierce Pharma reports,
    • “Since discontinuing its two branded versions of asthma inhaler Flovent at the start of 2024, GSK has still produced “authorized generic” versions of the treatment, which are the same products with different labels distributed by another firm.
    • “Now, true competition has finally arrived for GSK’s Flovent in the form of an FDA approval for Glenmark’s fluticasone propionate inhalation aerosol. The inhaled corticosteroid, which reduces inflammation in the lungs, is a maintenance treatment and can be used by patients ages 4 and older to prevent wheezing and shortness of breath.
    • “As the first company to gain FDA approval for a Flovent generic, Glenmark receives 180 days of exclusivity before other makers of generics can enter the market. Glenmark will begin distributing fluticasone this month, the company said in a release.”
  • Radiology Business reports,
    • “The U.S. Food and Drug Administration has approved the first artificial intelligence-powered imaging device for breast cancer surgery. 
    • “Manufacturer Perimeter Medical Imaging announced the news on Tuesday after earning premarket approval for “Claire” (formerly the Perimeter OCT B-Series). The product also has received Breakthrough Device designation, with it designed to enhance surgeon’s ability to detect difficult-to-see cancers during surgery. 
    • “This could potentially reduce the need for repeat operations and save excess healthcare costs, the company contends. 
    • “Repeat breast cancer surgeries due to residual disease remain a significant clinical, health and economic burden,” Perimeter CEO Adrian Mendes said in a statement March 3. “Claire’s FDA approval marks a major milestone in breast cancer care, as we advance our goal of reducing repeat surgeries so that no patient has to be told ‘we didn’t get it all.’”
    • “Mendes said the Dallas-based company plans to roll out the product nationwide in the coming weeks. Claire combines proprietary AI with wide-field OCT imaging, enabling high-res, real-time evaluation of excised tumor margins. The system purportedly can deliver 10 times higher resolution when compared to standard X-ray and ultrasound.” 
  • BioPharma Dive adds,
    • “PepGen is in a holding pattern on its request to include U.S. patients in a Phase 2 trial of a muscle disorder treatment after the Food and Drug Administration put a partial halt on the study.
    • “The agency did not raise any questions about the company’s data in patients with the condition known as myotonic dystrophy type 1, or DM1, instead focusing on previously submitted preclinical work, PepGen said Wednesday. Specifically, the FDA seems concerned about drops in blood pressure in a study of mice that have not been seen in humans, analysts wrote.
    • “PepGen said it’s working with the FDA to address the concerns as quickly as possible. The company is continuing its Phase 2 work elsewhere and recently got permission to open the “Freedom2” studyto patients in New Zealand, Australia and South Korea.” 

From the judicial front,

  • Per a Justice Department news release,
    • “Brad D. Schimel, United States Attorney for the Eastern District of Wisconsin, announced today that Kinex Medical Company, LLC, agreed to pay $6,925,000 to resolve allegations that it violated the False Claims Act by submitting false claims to Medicare, TRICARE, and other federal programs.
    • “Based in Waukesha, Wisconsin, Kinex sells and distributes durable medical equipment, including knee, shoulder, and hip braces, to patients across the United States. After receiving information from a whistleblower, the United States investigated and alleged that the company submitted false claims to Medicare, TRICARE, the Federal Employees Health Benefits Program (FEHBP), and the Office of Workers Compensation Programs of the Department of Labor (OWCP). 
    • “Specifically, the United States alleged that from 2019 through 2024, Kinex provided patients covered by these programs with medical braces that the patients did not need and then billed Medicare, TRICARE, FEHBP, and OWCP as if the braces had been necessary. The United States also alleged that Kinex convinced the patients to accept the braces by waiving costs like patient co-pays and by giving the patients other equipment for free.
    • “In addition to paying nearly $7 million to resolve the allegations concerning these false claims, Kinex also entered into a Corporate Integrity Agreement with the United States Department of Health and Human Services, Office of the Inspector General (HHS-OIG), to ensure compliance with applicable regulations going forward.”
  • Fierce Healthcare relates,
    • “The Federal Trade Commission (FTC) may be nearing settlements with the remaining two pharmacy benefit managers involved in a lawsuit over insulin pricing.
    • “In a court filing (PDF) posted this week, the agency disclosed that it is making “significant progress” in talks with both CVS Health’s Caremark and UnitedHealth Group’s Optum Rx on the heels of a broad settlement with Cigna’s Express Scripts.
    • “In late January, the FTC suspended the administrative case against Express Scripts, indicating a settlement was in the works. That settlement was later confirmed Feb. 4, with the PBM agreeing to a slew of changes to resolve allegations that it unlawfully and artificially inflated the price of insulin.
    • “In the filing, the agency pushed back the date for an evidentiary hearing and oral arguments in the case by 21 days, to late March, to allow for greater negotiation time.”

From the public health and medical / Rx research front,

  • MedPage Today reports,
    • “Initiation of a GLP-1 receptor agonist was tied to lower risks of several substance use disorders (SUDs) in adults with type 2 diabetes, according to a target trial emulation using data on veterans.
    • “In patients without a history of any SUD, those who started a GLP-1 drug versus an SGLT2 inhibitor had a reduced risk of a composite outcome of all SUDs, including alcohol, cannabis, cocaine, nicotine, opioid, and other SUDs (HR 0.86, 95% CI 0.83-0.88), reported Ziyad Al-Aly, MD, of the VA Saint Louis Health Care System, and colleagues.
    • “Benefits also extended to those with pre-existing SUDs, the researchers wrote in The BMJ.” 
  • The AAMC shares information about
    • GLP-1 pills for weight loss are here. How will they change obesity care?
  • and
    • What you need to know about the updated childhood vaccination schedule.
  • Cardiovascular Business informs us,
    • “A new implantable artificial intelligence (AI) device that modulates venous pressure to increase renal perfusion in diuretic-resistant heart failure patients was associated with positive 90-day data in the first-in-human RELIEF-FIH study. Researchers presented the data at the THT 2026 conference in Boston.
    • “The Relief System from Relief Cardiovascular is a first-of-its-kind device. The goal of the device is to better manage heart failure congestion at home. It is one of many new heart failure technologies aimed at finding new ways to reduce heart failure rehospitalizations, which are a major driver for healthcare costs.
    • “The Relief System incorporates a valve and sensor implant that uses AI to intelligently modulate venous pressure using hemodynamic data. The system actively adjusts flow in the inferior vena cava (IVC), which lowers venous pressure to drive durable decongestion in heart failure. It uses a daily transmission of hemodynamic data to adjust the valve through a cloud-enabled interface.”

From the U.S. healthcare business and artificial intelligence front,

  • Beckers Payer Issues reports,
    • “Excellus BlueCross BlueShield ended 2025 with a 1.4% operating loss totaling $108 million, as medical and drug claims climbed 16% year over year to nearly $7 billion. The insurer said March 5 the results are its largest annual claims increase in nearly 20 years.
    • “Last year, Excellus spent roughly $19 million daily on medical and drug benefits for its 1.5 million members. The company’s 2025 medical loss ratio was 92%, and it recorded a 2% net margin and $150 million in net income. Reserves closed the year at $1.7 billion, which is equal to less than three months of claims and operating expenses.
    • “Medicare Advantage drove most of the cost increase.”
  • and
    • “Three of four Regence health plans ended 2025 with operating losses as medical and drug costs climbed across Oregon, Washington, Idaho and Utah, according to results published by the organizations on March 2.
    • “The Washington plan was the hardest hit. Regence BlueShield reported an operating loss of nearly 8% on total revenue of $2.38 billion and a net loss of 3.1%. The plan paid $2.17 billion in care for its fully insured members, with per-member costs rising more than 15% year over year. Total membership at the end of 2025 was 1.58 million.
    • “In Oregon, Regence BCBS posted a 1.3% operating loss on revenue of $3.18 billion, though investment returns pushed the plan to 1.5% net income. The plan paid $2.9 billion in care for fully insured members, at $6,022 per member, up 15% from 2024. Total membership was roughly 950,000 at the end of 2025.
    • ‘Regence BlueShield of Idaho also ran an operating loss, at 0.5% on revenue of $752 million, but finished with net income of 2.5% because of the strength of investment returns. Per-member costs rose more than 22%, the steepest increase among the four plans. The plan had more than 350,000 members at year’s end.
    • “Regence BCBS of Utah reported net income of 3.5% on total revenue of $1.45 billion, slightly above its 10-year average of 3%, driven by strong member retention and investment income. The plan paid $1.31 billion in care for fully insured members, with per-member costs rising nearly 5%. Membership held at roughly 740,000.”
  • The Commonwealth Fund tells us,
    • “Changing how we pay for primary care can incentivize clinicians to deliver the right care at the right time. Historically, clinicians have been retroactively paid a fee for each service they provide. Known as fee-for-service (FFS), this practice encourages clinicians to provide more services, rather than efficiently deliver comprehensive care. Although it can lead to more care, it may not lead to better health outcomes.
    • “Instead, we could use payment to encourage primary care clinicians to deliver appropriate, efficient care in coordination with other clinicians. An increasingly common way to do this — value-based payment (VBP) — ties clinicians’ payments to their performance on outcomes, including the cost and quality of care. Specific outcomes include the way clinicians manage patients’ chronic conditions or the minimization of avoidable hospitalizations. The evidence shows that changing how we pay for primary can improve patients’ outcomes, including reducing avoidable hospitalizationsand increasing access to coordinated care.
    • “Despite the promise of VBP, some primary care practices have been left behind, and their patients haven’t been able to benefit. Policymakers and payers are particularly worried about low participation among rural, small, and independent practices, as well as community health centers (CHCs) that face unique barriers to participation.
    • “In this blog post, we assess current rates of primary care physician (PCP) participation in VBP, using data from the 2025 Commonwealth Fund International Health Policy Survey of Primary Care Physicians. We also highlight opportunities to design value-based models to account for the needs of different practice settings, such as small or rural practices.”
  • STATNews relates,
    • “Digital chronic care company Omada reported a quarterly profit for the first time since going  public less than a year ago, the company revealed while announcing  its full year 2025 earnings Thursday. 
    • “Omada also provided earnings guidance for 2026, suggesting the company will continue to grow as it capitalizes on the demand for popular GLP-1 obesity medications.
    • ‘Omada earned $260 million in revenue in 2025, 53% more than the year before — above top-end preliminary results the company announced at the J.P. Morgan Healthcare Conference in January. In August, shortly after it went public, it projected top-end earnings of $241 million for the year.
    • “Notably, the company reported $5 million in net income in the fourth quarter of 2025 — the first time the company has turned a net profit. 
    • “We’re pretty ahead of schedule on a lot of positive financials,” Omada CEO Sean Duffy told STAT.”
  • Modern Healthcare tells us,
    • “CVS Health plans to launch a health technology subsidiary later this year that will offer an artificial intelligence-based platform designed to help consumers access healthcare information and services. 
    • “The platform will allow patients to find providers, compare costs of care and centralize their health records and information, CVS said. It also will make recommendations for the next steps of care for patients with chronic conditions and offer care management through a digital health portal between visits.
    • “The Health100 consumer platform, slated to launch midyear, will use agentic AI and be powered by Google Cloud technology, including Gemini AI programs.
    • “It will be rolled out first to CVS Health customers and not all features will be available upon launch, a spokesperson said. It will be expanded to other consumers, and outside providers and other companies can opt in to participate, the spokesperson said.”
  • Healthcare Dive adds,
    • “Amazon Web Services rolled out a suite of agentic artificial intelligence tools Thursday that aim to handle a range of healthcare tasks, like helping patients schedule appointments and summarizing medical data for clinicians. The product, called Amazon Connect Health, includes five capabilities: verifying patients’ identities; handling appointment scheduling; creating summaries of patient medical histories; creating clinical notes based on conversations between clinicians and patients; and generating medical codes from clinical documentation. 
    • “Amazon Connect Health should help patients more easily access care and assist with clinicians’ administrative work, according to Naji Shafi, general manager and director of healthcare AI at AWS. “Our healthcare workers are overburdened, drowning in administrative complexity, and it’s costing everyone,” he said.” 
  • Per Beckers Health IT,
    • “Optum is expanding its collaboration with Microsoft to introduce new AI-powered capabilities within Optum Real, a real-time claims platform designed to connect payers and providers and streamline reimbursement workflows.
    • “In a March 5 news release, the companies said the new capabilities combine Optum’s healthcare data and analytics expertise with Microsoft technologies including Azure, Dragon Copilot and Microsoft Foundry. The platform aims to give providers a unified view of clinical and operational data while helping teams identify coverage issues, automate documentation tasks and address prior authorization requirements earlier in the care process.”
  • Fierce Healthcare informs us,
    • “Eli Lilly has officially launched Employer Connect, its direct-to-employer platform for its obesity medications, after teasing the rollout late last year.
    • “The drugmaker said in an announcement that the program is aimed at supporting employer choice and enabling them to build the solution that works best for them and their workforces. It will launch with more than 15 independent program administrators as partners, which allows employers to select multiple models.
    • “Coverage for GLP-1s remains a key challenge for employers to navigate, as there is significant demand for the drugs that often come at a high cost. Within the program, Lilly will offer Zepbound KwikPen to network pharmacies at a discounted $449 price.
    • “What the patient ultimately pays could vary based on the employer’s cost sharing model and which partner they lean on, per the announcement.”
  • Fierce Pharma points out,
    • “Galderma has significantly raised its peak annual sales estimate for Nemluvio (nemolizumab) to more than $4 billion, doubling its previous projection of more than $2 billion. The update follows what CEO Flemming Ørnskov described as an “outstanding launch trajectory” for the inflammatory skin condition drug in its first full year on the market. 
    • “Driven by strong adoption in its existing indications of atopic dermatitis and prurigo nodularis (PN), Nemluvio posted $452 million in 2025 sales. Growth accelerated sharply in the second half of the year, with the period contributing $321 million to the total. It comes as real-world experience with the IL-31 receptor inhibitor exceeded initial expectations, Ørnskov said on Galderma’s fourth-quarter earnings call Thursday.”
  • and
    • “After delivering solid sales growth in a difficult 2025, Germany’s Merck KGaA may have a tougher go of things this year, which the company is crediting in part to a predicted onslaught of U.S. generics to its multiple sclerosis blockbuster Mavenclad. 
    • Approved by the FDA in 2019, Mavenclad delivered its third straight year of blockbuster sales in 2025, charting nearly 17% growth over the previous year to 1.2 billion euros ($1.4 billion) worldwide, Merck KGaA reported Thursday. In North America specifically, the drug reeled in 635 million euros ($735 million) last year, Merck noted in a detailed earnings report issued(PDF) March 5.” * * *
    • “[I]n an unfortunate turn for Merck, recent efforts to stave off Mavenclad patent challenges in the U.S. have fallen short, prompting the drugmaker to more or less throw in the towel on future growth for the MS med stateside. 
    • “In particular, Merck’s guidance for the year—anticipating sales between 20 billion euros and 21 billion euros, or -1% to 2% growth— “assumes no U.S. sales of Mavenclad from March 2026 amid generic competition.”  

Tuesday report

From Washington, DC

  • The Hill reports,
    • “Top Democrats are whipping against the Department of Homeland Security (DHS) funding bill expected to come to the floor this week, even as Republicans press them to support it in the wake of the U.S. attacks on Iran. 
    • “The White House and Democrats have been locked in an impasse over a deal to reopen DHS, as the minority party calls for the administration to overhaul Immigration and Customs Enforcement (ICE) following the killings of two U.S. citizens in Minnesota by federal agents.” 
  • Per a CMS news release,
    • “Today, the Centers for Medicare & Medicaid Services (CMS) released Medicare.gov Enhanced Login options. By providing people with Medicare these options, Medicare.gov is helping users better manage their health care information by delivering more login choices. People with Medicare do not need to create an account to access general Medicare information or their individualized Medicare information. If someone chooses to create an account, Medicare is providing new and free options with enhanced security to help protect their Medicare information.”
  • Beckers Payer Issues adds,
    • “Medicare Advantage plans looking to maintain no-premium models could face 50% cuts to supplemental benefits and $1,000 more in older adults’ cost exposure in 2027, according to February reports commissioned by health insurance trade association AHIP.
    • “Wakely Consulting Group conducted the research. The groups evaluated how CMS’ proposed 0.09% 2027 payment increase for MA would play out for insurers and their beneficiaries. AHIP sent the findings to CMS in a Feb. 25 letter.”
  • The Paragon Health Institute notes,
    • “The [Medicare] primary base hospital payment rate for inpatient services—known as the Inpatient Prospective Payment System (IPPS) operating base rate—has increased by 30 percent since 2016, mainly because of statutory formulas.  The outpatient services base rate—known as the Outpatient Prospective Payment System (OPPS) conversion factor—has increased by 26 percent since 2016, also mainly because of statutory formulas. Meanwhile, the physician base payment rate—known as the Physician Fee Schedule (PFS) conversion factor—has declined by 7 percent over the same period.
    • “The declining PFS conversion factor and the rising hospital base rates are not an accident but a result of policy choices made by Congress.” * * *
    • “To reduce distortions, hospital payments in Medicare should be subject to similar fiscal sustainability pressures as physician payments. Policymakers should consider proposals that address distortions and, in particular, site neutral payment policies that equalize payments for the same services across all providers.” 
  • Per an Institute for Clinical and Economic Review news release,
    • “The Institute for Clinical and Economic Review (ICER) today posted a Special Report on Entyvio® (vedolizumab, Takeda Pharmaceutical Co. Ltd.) for the treatment of ulcerative colitis and Crohn’s disease. This report will be submitted to the Centers for Medicare & Medicaid Services (CMS) as part of the 2026 public comment process defined in CMS guidance on Medicare Drug Price Negotiations for price applicability year 2028. 
    • Downloads: Final Report
    • “Over three million people in the United States suffer from inflammatory bowel diseases like ulcerative colitis and Crohn’s disease. Our special report focuses on the medical evidence for and value of Entyvio, which is commonly used to treat both conditions,” said ICER’s President and CEO Sarah K. Emond, MPP. “We recognize that our report will be one of many inputs CMS may consider, and we hope that it will support their ongoing efforts to build a reliable, value-based, transparent drug price negotiation process on behalf of the American people.”
  • Per an OPM news release,
    • “The US Office of Personnel Management (OPM) today announced Kurt Dykstra as General Counsel.
    • “Dykstra is an accomplished attorney with nearly three decades of experience handling complex workforce issues, regulatory compliance, internal investigations, and governance. His career spans corporate law, higher education, financial services, and public service, including leadership roles as a law firm shareholder, university counsel, college president, bank executive, mayor, and Major in the US Army Reserve.
    • “As OPM’s Chief Legal Officer, Dykstra will lead the Office of the General Counsel and advise the director and agency leadership on legal and policy matters.
    • “Kurt is a proven leader with the judgment and experience to help guide OPM through complex legal and workforce challenges,” said OPM Director Scott Kupor. “He understands how strong governance, accountability, and sound legal strategy support effective government. I am confident his leadership will help ensure OPM continues to serve federal employees and the American people with integrity and excellence.”
  • The Wall Street Journal relates,
    • “Patient Advocate Foundation and Patient Access Network Foundation merged, creating a nonprofit with over $800 million in assets.
    • “Kevin Hagan is chief executive of the combined Patient Advocate Foundation, which aims to serve patients facing rising costs.
    • “The combined foundation will launch a TotalAssist program in July and offer more than 130 disease-specific financial assistance funds.”

From the Food and Drug Administration front,

  • STAT News reports,
    • “The Food and Drug Administration has been talking a big game about bringing artificial intelligence to patients. In January, when it announced relaxed rules for certain AI products, Commissioner Marty Makary said the agency is “developing a new regulatory framework for AI.” 
    • “How the agency will regulate rapidly-evolving uses of generative AI is one of the big questions facing health technology developers. Large language models’ wide-ranging applications evade simple measures of safety and efficacy, challenging the FDA’s longstanding approach to device validation — and the agency has yet to authorize a device that relies on generative AI. But a recent breakthrough designation from the FDA could offer hints about its approach to regulating patient-facing chatbots that fall under its purview. 
    • “In November, the FDA quietly handed one of its breakthrough device designationsto a chatbot for patients recovering from joint replacement surgery. Under development by RecovryAI, which is coming out of stealth as it announces the designation, the LLM-powered device would be prescribed to patients to use in the 30 days after surgery. It will encourage them to check in twice a day about their sleep, activity, diet, and other elements of recovery, answering questions and escalating to a care team when necessary.” 
  • Radiology Business adds,
    • “An artificial intelligence-enabled tool capable of accurately predicting an expectant mother’s delivery date has received the U.S. Food and Drug Administration’s De Novo clearance. 
    • “Ultrasound AI—a company that specializes in medical imaging AI applications—on Monday announced the clearance of its flagship Delivery Date AI technology. The product is a cloud-based software as a medical device that predicts delivery dates using ultrasound imaging alone. This could help to better prepare both patients and providers for potential complications, reducing the likelihood of preterm birth. 
    • “It was trained on a diverse dataset of over 1 million ultrasound images and evaluated via a peer-reviewed study, published in the Journal of Maternal-Fetal & Neonatal Medicine. The study, which included nearly 6,000 patients, determined AI could achieve an accuracy of 0.92 R² value for predicting the day a mother would deliver her child using only standard ultrasound images. 
    • “Delivery Date AI can be easily integrated into most ultrasound systems. Ultrasound AI indicates that installation takes just a few minutes and offers organizations scalability while also potentially reducing long-term costs by improving maternal outcomes.” 
  • Per an FDA news release,
    • “The U.S. Food and Drug Administration today announced the issuance of 30 warning letters to telehealth companies for making false or misleading claims regarding compounded GLP-1 products offered on their websites. 
    • “It’s a new era. We are paying close attention to misleading claims being made by telehealth and pharma companies across all media platforms—and taking swift action,” said FDA Commissioner Marty Makary, M.D., M.P.H. “Compounded drugs can be important for overcoming shortages or meeting unique patient needs—but compounders should not try to compound drugs in a way that circumvents FDA’s approval process.”
    • “This is the second group of warning letters sent to telehealth firms since the agency launched in September a crackdown on misleading direct-to-consumer pharmaceutical advertisements. Over the past six months, the agency has sent thousands of letters warning pharmaceutical and telehealth firms to remove misleading ads, more than had been sent over the entire preceding decade.”
  • Per BioPharma Dive,
    • “Pierre Fabre Pharmaceuticals has asked the Food and Drug Administration for an urgent meeting to discuss why the agency rejected a cell therapy for a post-organ transplant malignancy, the company said Tuesday, following claims by partner Atara Biotherapeutics that the agency contradicted its previous guidance.” * * *
    • “The regulatory dispute over Ebvallo is one of a series of recent squabbles between drugmakers and the FDA related to previous agreements on approval standards. On Monday, UniQure learned it will have to conduct another trial of a Huntington’s disease gene therapy. Last month, the agency initially refused to review a flu vaccine from Moderna before quickly changing course.”

From the judicial front,

  • Medical Economics tells us,
    • “Advanced analytics and multi-agency coordination are shortening investigative timelines and expanding parallel civil FCA, criminal, administrative, and state litigation exposure from a single operational issue. 
    • “Enterprise-level FCA theories are emphasizing systems, governance, and vendor relationships, with sustained focus on managed care, prescription drugs, and medically unnecessary services. 
    • “Medicare Advantage risk adjustment scrutiny is extending to incentive design, retrospective addenda, chart review vendors, and documentation tools that may be construed as rewarding coding intensity. 
    • “Telehealth platforms face continued controlled-substance risk despite extended prescribing flexibilities, with enforcement targeting clinical legitimacy, marketing representations, cross-state compliance, and decision-making controls. 
    • “Cybersecurity and privacy failures are becoming enforcement multipliers via FCA cyber-fraud theories, CCPA actions, and HIPAA tracking-technology scrutiny involving adtech and analytics data sharing.”
  • STAT News reports,
    • “Moderna has agreed to pay Roivant up to $2.25 billion to settle claims that the mRNA vaccine developer infringed on Roivant’s patents in its Covid-19 shot.
    • “Roivant will receive $950 million and then another $1.3 billion if Moderna’s attempts to have parts of its liability offloaded to the federal government fail upon appeal. If the full amount is paid, it will be among the largest patent settlements in history. 
    • “It is probably the largest ever,” said Jacob Sherkow, a professor of law and medicine at the University of Illinois Urbana-Champaign.
    • “The settlement comes less than a week before the two companies were set to go to a jury trial in Delaware, where legal experts say Moderna may have faced an uphill battle.\

From the public health and medical / Rx research front,

  • The Washington Post reports,
    • To live long, be strong.
    • That’s the poetic implication of a new study of longevity and mortality in a large group of women aged 63 to 99.
    • “In the study, published in February in JAMA Network Open, researchers checked the women’s health, fitness, grip strength and lifespans. By analyzing that data, they hoped to tease out the importance of muscular strength for healthy aging.
    • “The results “were a bit of a surprise,” said Michael J. Lamonte, lead author of the study and a professor of epidemiology and healthy aging at the University of Buffalo in New York. Strength turned out to be a key — and singular — contributor to longer lives, he said, reducing the risk for early death by a third or more, even when the researchers took into account people’s aerobic fitness, health, age and exercise habits.”
  • The American Medical Association lets us know what doctors wish their patients knew about cystic fibrosis.
  • MedPage tells us,
    • “A meta-analysis found that women lost more weight than men while taking a GLP-1 receptor agonist.
    • “Biological differences, such as estrogen levels and body composition, may explain why women respond more to these agents.
    • “Weight loss was consistent across many other patient subgroups broken down by age, race and ethnicity, body mass index, and HbA1c.”
  • and
    • “Lithium carbonate might have slowed decline in verbal memory in a pilot study.
    • “However, the treatment did not meet a prespecified threshold for the trial’s primary outcomes.
    • “Earlier research suggested lithium may offer neuroprotective benefits in Alzheimer’s and dementia.”
  • Genetic Engineering and BioTechnology News points out,
    • “Immune monitoring is useful to monitor processes like vaccination and during diseases like infectious disease, cancer, and autoimmunity. However, detection of antigen-specific lymphocytes is challenging given that are low in frequency and have a dispersed distribution.
    • “Now, the first bandage-like, painless, microneedle patch that can sample the body’s immune responses from the skin has been developed. The device detects inflammatory signals within minutes and collects specialized immune cells within hours without the need for blood draws or surgical biopsies.
    • “The study appears in Nature Biomedical Engineering in the paper, “Leveraging tissue-resident memory T cells for non-invasive immune monitoring via microneedle skin patches.
    • “The patch is helping researchers and clinicians study immune responses in aging and skin autoimmunity, including vitiligo and psoriasis. In the future, it could make it easier to track how people respond to vaccines, infections, and cancer therapies by complementing traditional blood tests and biopsies while being far easier on patients.”
  • Per BioPharma Dive,
    • “Shares of Aardvark Therapeutics lost more than half their value after safety worries led the biotechnology company to halt testing of its most advanced drug prospect. 
    • “Aardvark said Friday that, “out of an abundance of caution,” the company has voluntarily paused dosing and enrollment in a Phase 3 trial of ARD-101, an experimental drug it’s been developing for the rare genetic disease Prader-Willi syndrome. According to Aardvark, trial monitors detected “reversible cardiac observations” during a routine safety check in a study of healthy volunteers.” 
  • and
    • “Kyowa Kirin will stop all trials of an eczema drug once seen as a possible future blockbuster, claiming a new safety review has led the company to believe that the treatment’s risks may outweigh its benefits.
    • “In a Tuesday statement, the company said a planned evaluationconducted by the company and former development partner Amgen in recent weeks unearthed “emerging concerns of malignancies” related to treatment with a therapy known as rocatinlimab. These concerns included one new confirmed case and another suspected case of Kaposi’s sarcoma, a cancer that forms around skin lesions.”
    • “The findings suggest a potential link between onset of the cancer and the drug’s mechanism of modulating an immunogical pathway called OX40. While the overall number of cases is below expected background rates, the “characteristics” involved “raised a plausible biological concern that cannot be excluded,” the company said.
    • “All studies will be discontinued after study participants complete their required safety follow-up visits, Kyowa Kirin added.”

From the U.S. healthcare business front,

  • Beckers Hospital Review relates,
    • “Rochester, Minn.-based Mayo Clinic recorded an income from current activities of $1.5 billion (6.8% margin) in 2025, up from $1.3 billion (6.5% margin) in 2024.”
  • and
  • and
    • “Nacogdoches County Hospital District in Nacogdoches, Texas, unanimously approved a new lease agreement with Dallas-based Tenet Healthcare on Feb. 27, The Nacogdoches Daily Sentinel reported March 2.
    • “The 15-year lease agreement designates Nacogdoches Memorial Hospital and Cecil R. Bomar Rehabilitation Center as campuses of Nacogdoches Medical Center. Tenet, which operates Nacogdoches Medical Center, will assume daily operations of Nacogdoches Memorial Hospital.”
  • and
    • “Nashville, Tenn.-based HCA Healthcare and Ascension are planning competing freestanding emergency departments in Fairview, Tenn., a fast-growing community in western Williamson County.”
  • Fierce Healthcare tells us,
    • “Health systems interested in preserving their operating margins will need to be proactive in addressing a growing minority population responsible for an outsized share of care utilization: patients with multiple chronic conditions. 
    • “In a newly released analysis of 2025 claims data, Vizient found that 11% of the U.S. population with multiple chronic conditions accounted for 52% of inpatient admissions. These patients also represented 35% of emergency department visits and 32% of office visits.
    • “To put it another way—compared to those without any chronic disease, these patients have about 10 times more inpatient admissions and ED visits, as well as six times as many office visits. Further, ED and office visits among those with multiple chronic conditions are projected over the next decade to grow at nearly double the rate of those with a single chronic condition, who are also higher care utilizers.
    • These patients pose a major financial challenge for providers due to their unfavorable payer mix. Specifically, Vizient found that 72% of inpatient admissions for those with multiple chronic conditions were covered by Medicare and another 10% by Medicaid. 
  • and
    • “Grow Therapy, a hybrid mental health provider, has clinched $150 million to build out physician and employer relationships.
    • “The series D round was led by TCV and Growth Equity at Goldman Sachs Alternatives, with participation from new investors BCI and Menlo Ventures. 
    • ‘Physicians and employers are newer customer types for Grow but have been the focus of the platform’s growth over the past five years. The capital will also be used to strengthen the tech powering Grow and enhance the user experience for patients, therapists and other partners.
    • “Grow has amassed a range of partners that today includes 125 payers, provider groups like Circle Medical, health systems like Kaiser Permanente and employers. Primary care docs are of particular focus to Grow right now, given they deliver 60% of the nation’s mental healthcare.” 
  • MedTech Dive informs us,
    • RadNet has struck a 230 million euros deal to buy radiology artificial intelligence company Gleamer.
    • “The takeover, which the companies disclosed Monday, gives RadNet control of devices that are used in more than 25 indications and are forecast to generate about $30 million in annualized recurring revenue this year.
    • “Buying Gleamer will expand the capabilities RadNet acquired through the DeepHealth buyout in 2020, particularly in X-ray, and accelerate its expansion outside the U.S. Gleamer will be integrated into DeepHealth, a full-owned subsidiary of Radnet.”

Cybersecurity Saturday

From the cybersecurity policy and law enforcement front,

  • Cybersecurity Dive reports,
    • “The Trump administration late Thursday removed the scandal-plagued acting director of the Cybersecurity and Infrastructure Security Agency, injecting fresh uncertainty into the operations of an agency already grappling with a morale crisis as it tries to protect the U.S. from sophisticated hacking threats.
    • “The Department of Homeland Security reassigned Madhu Gottumukkala, the deputy CISA director who had led the agency in an acting capacity since last May, to a position at DHS headquarters. Nick Andersen, the executive assistant director for CISA’s Cybersecurity Division and one of the few remaining political appointees at the agency, will step in as acting director.”
  • Federal News Network adds,
    • “Sen. Ron Wyden (D-Ore.) is blocking the Trump administration’s nominee to lead both U.S. Cyber Command and the National Security Agency. Wyden said Lt. Gen. Joshua Rudd, who currently serves as the deputy commander of U.S. Indo-Pacific Command, lacks the experience needed to immediately step into the dual leadership role. The lawmaker added that when it comes to U.S. cybersecurity, “there is simply no time for on-the-job learning, the threat is just too urgent for that.”
  • Gov Info Security relates,
    • “A bipartisan group of senators called on the federal government to update the regulations governing healthcare cybersecurity through a Thursday vote sending a bill aimed at bolstering sector resilience to the full Senate.
    • ‘The Senate Health, Education, Labor and Pensions Committee voted 22 to 1 to advance the Health Care Cybersecurity and Resiliency Act, a bill that requires publishing cybersecurity guidance for rural medical practices and improved coordination between federal agencies.
    • It has the backing of a healthcare cybersecurity working group that includes committee Chair Bill Cassidy, R-La.
    • “The legislation would additionally bolster an apparently stalled effort to update the HIPAA Security Rule that the Department of Health and Human Services published during the final weeks of the Biden administration (see: What’s in HHS’ Proposed HIPAA Security Rule Overhaul?).
    • “The bill would enforce many of the proposed rule’s updates, including requiring HIPAA-covered organizations and business associates to adopt multifactor authentication and encryption, to conduct audits, including penetration testing. It additionally calls for “other minimum cybersecurity standards” to be determined by the HHS secretary, “in consultation with private sector organizations, based on landscape analysis of emerging and existing cybersecurity vulnerabilities and consensus-based best practices.”
    • “The fate of the Biden administration’s proposed HIPAA overhaul is uncertain at this point. The HHS Office of Civil Rights is expected to make some kind of decision in May on whether it will move forward with the proposals, or perhaps issue a revised version of proposed rulemaking.”
  • Cyberscoop notes,
    • “An ex-L3 Harris executive was sentenced to over seven years in prison Tuesday after pleading guilty to selling eight zero-day exploits to a Russian broker in exchange for millions of dollars.
    • “Peter Williams, 39, admitted to two counts of theft of trade secrets in U.S. District Court in Washington, D.C., last year, acknowledging he took at least eight exploits or exploit components while working at Trenchant, a specialized cybersecurity unit owned by L3Harris. Prosecutors said the materials were intended for restricted use by the U.S. government and allied partners.
    • “Authorities said Williams sold the stolen information to a broker that advertised itself as a reseller of hacking tools and described it as serving multiple customers, including the Russian government. In court, the government referred to the buyer as “Company 3,” but details read aloud during the plea hearing pointed to Operation Zero, a Russian exploit broker that publicly markets itself online as a platform for purchasing zero-day vulnerabilities.”

From the cybersecurity breaches and vulnerabilities front,

  • Cybersecurity Dive reports,
    • “Federal agencies have until Friday evening [February 27] to update certain Cisco networking devices that are vulnerable to compromise, the Cybersecurity and Infrastructure Security Agency said on Tuesday [February 24].
    • “In an emergency directive about Cisco’s Software-Defined Wide-Area Networking (SD-WAN) systems, CISA said it was “aware of a cyber threat actor’s ongoing exploitation” of two vulnerabilities in Cisco Catalyst SD-WAN Manager and Catalyst SD-WAN Controller devices and called the activity “an imminent threat to federal networks.”
  • and
    • “The Cybersecurity and Infrastructure Security Agency on Thursday warned that a malware variant previously used in attacks against Ivanti Connect Secure environments may remain undetected on systems. 
    • “In March 2025, CISA issued an alert about the malware, dubbed Resurge, in connection with exploitation of CVE-2025-0282, a stack-based buffer overflow vulnerability in certain versions of Ivanti Connect Secure and other Ivanti products. 
    • “The agency has since analyzed three samples from a critical infrastructure provider’s Ivanti Connect Secure device after hackers exploited the flaw to gain initial access. The analysis shows that Resurge can remain latent on a device until a remote hacker attempts to contact the device.” 
  • Cyberscoop adds,
    • “Would-be attackers spent 2025 swimming in a sea of more than 40,000 newly published vulnerabilities, VulnCheck said in a report released Wednesday, but only 1% of those defects, just 422, were exploited in the wild.
    • “As the deluge of vulnerabilities grows every year, and CVSS ratings lose significance for vulnerability management prioritization, some defenders are turning to research on known exploited vulnerabilities to narrow their scope of work and place more emphasis on verified risks. 
    • “The growth in CVE volume is ludicrous, not necessarily unfounded, but it’s large. Defenders don’t know what to pay attention to,” Caitlin Condon, vice president of security research at VulnCheck, told CyberScoop. “Prioritization is still a huge problem.”
    • “Too many defenders and researchers are paying attention to defects and unsubstantiated exploit concepts that aren’t worth their time, Condon added. “The indicators of risk that used to be semi reliable, now no longer are.”
  • and
    • “Cyberattacks reached victims faster and came from a wider range of threat groups than ever last year, CrowdStrike said in its annual global threat report released Tuesday, adding that cybercriminals and nation-states increasingly relied on predictable tactics to evade detection by exploiting trusted systems.
    • “The average breakout time — how long it took financially-motivated attackers to move from initial intrusion to other network systems — dropped to 29 minutes in 2025, a 65% increase in speed from the year prior. “The fastest breakout time a year ago was 51 seconds. This year it’s 27 seconds,” Adam Meyers, head of counter adversary operations at CrowdStrike, told CyberScoop.
    • “Defenders are falling behind because attackers are refining their techniques, using social engineering to access high-privilege systems faster and move through victims’ cloud infrastructure undetected.”
  • Cybersecurity Dive points out,
    • “Hackers are increasingly integrating artificial intelligence into all phases of the cyberattack life cycle, with the technology regularly analyzing target information, generating phishing emails and providing coding assistance, security firm ReliaQuest said in a report published on Tuesday [February 24].
    • “Other recent reports from IBM and cyber insurer Resilience similarly highlight how AI has changed the threat landscape.
    • At the same time, a new Sophos report said it was important to put in perspective AI’s ‘capabilities and impact.”
  • LinkedIn informs us,
    • “One of the largest data breaches in U.S. history is even bigger than was known. The Conduent cyberattack has now affected more than 25 million Americans, according to a recent update. The January 2025 incident exposed Social Security numbers, medical records and other sensitive information. Conduent is one of the largest contractors for the U.S. government, providing mailroom, printing and payment processing services for state government benefit offices — meaning it manages “a large amount of personal information belonging to a large swath of the United States,” per TechCrunch.”
  • Cybersecurity Dive adds,
    • “Hackers working for the Chinese government broke into more than 50 telecommunications companies and government agencies in 42 countries, in a campaign that exploited cloud platforms’ legitimate features to hide the attackers’ tracks.
    • “The attacker was using API calls to communicate with [software-as-a-service] apps as command-and-control (C2) infrastructure to disguise their malicious traffic as benign,” researchers at Google’s Threat Intelligence Group and Mandiant said in a report on Wednesday.
    • “Google said the “prolific, elusive” China-linked hacker team, which it tracks as UNC2814, “has a long history of targeting international governments and global telecommunications organizations across Africa, Asia, and the Americas.”

From the ransomware front,

  • The Mississippi Clarion Ledger reports,
    • “Officials with the University of Mississippi Medical Center stated the hospital system is “getting closer to full functions” following a cyberattack on Feb. 19 that disrupted operations.
    • “UMMC issued a statement Friday, Feb. 27, stating after being able to access patient records, clinics statewide will resume normal operations and scheduled appointments on Monday, March 2.
    • “UMMC also stated that on March 2, clinics will begin reaching out to patients to reschedule appointments that were cancelled. Officials added that UMMC clinics will reopen with extended hours and additional days in order to accommodate patients as soon as possible.
    • “All hospitals and emergency departments located in Jackson, Madison County, Holmes County and Grenada remain open.”
  • Cybersecurity Dive relates,
    • “UFP Technologies, a Massachusetts-based medical device maker, said it is investigating a cyberattack in mid-February that led to some of its company data being stolen or potentially destroyed, according to a regulatory filing
    • “The company said the attack, which was detected Feb. 14, impacted most of its IT network, as well as its billing and label-making capabilities for customer deliveries. The company said it was able to continue operations using data backups and implementing contingency plans.
    • “This was a classic ransomware attack that appeared to have impacted many, but not all, of our IT systems,” Ronald Lataille, chief financial officer at UFP Technologies, said Wednesday on a quarterly conference call with analysts. “Data was taken and then destroyed.”
    • “The company is still trying to figure out how much sensitive information, including personally identifiable data, may have been impacted by the attack, according to the 8-K filing with the Securities and Exchange Commission. However, the company does not currently believe the attack will have a material impact on its financial condition.”
  • The Hacker News adds,
    • “The North Korea-linked Lazarus Group (aka Diamond Sleet and Pompilus) has been observed using Medusa ransomware in an attack targeting an unnamed entity in the Middle East, according to a new report by the Symantec and Carbon Black Threat Hunter Team.
    • “Broadcom’s threat intelligence division said it also identified the same threat actors mounting an unsuccessful attack against a healthcare organization in the U.S. Medusa is a ransomware-as-a-service (RaaS) operation launched by a cybercrime group known as Spearwing in 2023. The group has claimed more than 366 attacks to date.
    • “Analysis of the Medusa leak site reveals attacks against four healthcare and non-profit organizations in the U.S. since the beginning of November 2025,” the company said in a report shared with The Hacker News.”
  • The Register informs us,
    • “Ransomware payments cratered in 2025, but it seems like the cybercrooks launching the attacks didn’t get the memo.
    • “That’s the headline from Chainalysis’ 2026 Crypto Crime Report, which shows total on-chain ransomware payments falling for a second straight year, even as victim counts and leak site pressure continue to climb.
    • “Ransomware gangs pulled in about $820 million in 2025, roughly 8 percent less than the year before, as the share of victims paying dropped to an all-time low of 28 percent. That drop might sound like progress if the wider picture weren’t so bleak: the median ransom demand jumped from $12,738 in 2024 to $59,556 in 2025, and the number of publicly claimed attacks climbed along with it.
    • “Despite the relative stability in total payments, ransomware attacks surged across multiple vectors in 2025, with eCrime.ch data showing a 50 percent YoY increase in claimed ransomware victims, marking the most active year on record,” Chainalysis said.”
  • Help Net Security adds,
    • Intrusions continue to center on credential access and timed execution outside standard business hours. The Sophos Active Adversary Report 2026 analyzes 661 incident response and managed detection and response cases handled between November 1, 2024 and October 31, 2025, spanning organizations in 70 countries.
    • “The dataset examines how attackers gain access, how quickly they reach key systems, and when ransomware and data theft occur.” * * *
    • “Timing patterns show that the most disruptive stages of ransomware incidents often occur when organizations are operating with reduced staffing. In 88% of ransomware cases, encryption was deployed during non business hours.
    • “Data exfiltration followed a similar pattern, with 79% of theft activity also occurring outside the typical workday.
    • “Off hours deployment increases the likelihood that encryption or large scale data transfers proceed without immediate interruption. It places emphasis on monitoring coverage that extends beyond standard schedules.”

From the cybersecurity business and defenses front,

  • Dark Reading reports,
    • “The cybersecurity venture capital market experienced unprecedented activity in 2025, driven primarily by the rush to AI-native security solutions and a massive surge in mergers and acquisitions that reached record levels.
    • “In 2025, VC firms invested $119 billion in cybersecurity businesses, with 400 M&A transactions accounting for the majority of funding and another 820 financing deals totaling nearly $21 billion, according to data from Momentum Cyber, a cybersecurity investment bank. The total value of M&A, financing, and IPO activity in 2025 nearly tripled that of deals in the previous year.”
  • and
    • “Cybersecurity experts are calling for a major shift in how companies handle data breaches and security failures, arguing that greater transparency and specific detail disclosure about how and why they occur is essential if the industry hopes to effectively reduce cyber-risk.
    • “At the upcoming RSAC Conference, threat research experts Adam Shostack and Adrian Sanabria will make the case for greater incident transparency and the need for structured feedback loops in cybersecurity, in a session aptly titled “A Failure Is a Terrible Thing to Waste: The Case for Breach Transparency,”scheduled for Monday, March 23.”
  • Cybersecurity Dive informs us,
    • “The AI era is transforming what CISOs do and how they do it, the enterprise software firm Splunk said in a report published on Tuesday [Feburary 24].
    • “Nearly all CISOs have been assigned to manage their organizations’ AI governance responsibilities, the report found, a significant expansion of “their already overwhelming mandates.”
    • CISOs interviewed in the report expressed both an awareness that they needed to use AI and a range of concerns about its potential harms.”
  • Dark Reading relates,
    • “As one ransomware community shutters in RAMP, two more pop up to take its place. 
    • “Rapid7 today published an analysis of that ransomware ecosystem after US authorities seized infrastructure tied to the notorious RAMP cybercrime forum last month. For years, RAMP has been the primary vehicle for acquiring ransomware-as-a-service (RaaS) affiliates, but the Jan. 28 interagency sting led by the FBI forced many cybercrime outfits to find a new means to sell their wares. 
    • “Rapid7’s Alexandra Blia and Efi Sherman in this week’s blog post identified two potential forums where attackers might go next. The bigger takeaway, however, is that the cybercrime ecosystem is fragmenting, and defenders will need to adapt.”
  • and
    • A newly developed method for gauging the impact of an OT cybersecurity incident could pave the way for more accurate measurement and response to an event, and also shine light on risk and business ramifications.
    • The Operational Technology Incident (OTI) Impact Score — which will be unveiled today [February 24] at the ICS/OT industry’s S4x26 Conference in Miami — aims to provide rapid clarity on the actual effects of OT cyber incidents, which often get over- or under-hyped, according to Dale Peterson, co-creator of the OTI model and head of ICS/OT consulting and research firm Digital Bond.
    • The OTI model, inspired by the Richter Scale used for measuring earthquake intensity and impact, is meant for OT business executives, governments, cyber insurers, the media, and the general public, according to Peterson, who is the founder and program chair of S4.
  • Here is a link to Dark Reading’s CISO Corner.

Friday report

From Washington, DC

  • Fierce Healthcare reports,
    • “The Trump administration has proposed flat rates in Medicare Advantage (MA) for 2027, and insurers argue in new commentary that those levels do not reflect the realities of the program.
    • “In late January, the Centers for Medicare & Medicaid Services (CMS) released its annual proposed advance notice governing MA and Part D. 
    • “The proposal includes a net payment rate increase of 0.09% in MA, meaning levels will be essentially flat if the plan becomes final.
    • “The proposed rule drew immediate ire from the industry, which is already navigating significant financial challenges in this market. Multiple leading players have elected to exit certain MA markets. 
    • “In official comments (PDF) submitted Wednesday to the CMS, the AHIP said the proposed rule “risks undermining CMS’ goal of providing beneficiaries with stable, affordable choices during the annual enrollment period.”
    • “At a time of sharply rising medical costs and high utilization of medical services, the combined effect of the proposed policy changes and growth rates will not keep pace with the cost of caring for seniors in 2027,” the organization, which is the largest lobbying group representing insurers, said in its comment letter.”
  • MedPage Today relates,
    • A top health official at the Centers for Medicare & Medicaid Services (CMS) [Chris Klomp] hedged on payment reform, but committed to helping physicians address prior authorization challenges, during the American Medical Association’s (AMA) National Advocacy Conference.”
  • Per Beckers Health IT,
    • “CMS has rolled out an app directory for Medicare recipients as part of the agency’s push to digitize healthcare.
    • “The Medicare App Library seeks solutions that fall under one of three use cases: “kill the clipboard,” conversational AI assistants, or diabetes and obesity prevention and management.
    • “We are calling on health app developers, tech-enabled organizations, and innovators to voluntarily align around a shared framework for data and access that empowers people, improves care, and accelerates progress,” CMS stated Feb. 23. “This is a movement, not a mandate. It is a call to action, not a regulation. Let’s show what’s possible when we work together — and finally bring healthcare into the modern era.”
  • Federal News Network tells us
    • “Tens of thousands of federal employees at U.S. Customs and Border Protection are expected to continue receiving pay during the Department of Homeland Security’s current funding lapse, according to an email viewed by Federal News Network.
    • “CBP, a component of DHS, plans to use discretionary funding from the One Big Beautiful Bill Act to exempt and continue paying more than 57,600 agency employees who have been working throughout the partial shutdown this month. Details of the agency’s decision come from an email sent this week by the National Treasury Employees Union, obtained by Federal News Network.
    • “Under the current shutdown, CBP will “exempt” and provide pay to a large portion of its workforce, including law enforcement personnel and certain civilian agency employees. Some other CBP employees, however, are still considered “excepted” and will not receive pay until after the shutdown ends.”
  • MedTech Dive informs us,
    • “The Trump administration is imposing a six-month moratorium on Medicare enrollment for certain suppliers of durable medical equipment, prosthetics and orthotics, or DMEPOS, as part of a broader plan to combat fraud in healthcare.
    • “The administration said Wednesday that the nationwide halt on enrollment would give the government time to consider more actions “to further mitigate longstanding instances of fraud, waste, and abuse perpetrated by certain DMEPOS companies.”
    • “The temporary freeze applies to all applications for initial enrollment and changes in majority ownership for medical supply companies.
    • “Durable medical equipment includes items such as walkers, wheelchairs, oxygen equipment, hospital beds, continuous positive airway pressure machines and blood sugar monitors.”
  • NCQA, writing in LinkedIn, announced its “Advanced Primary Care Pilot Program” and invited readers to “Meet Our Primary Care Partners!”
  • The Labor Department’s Employee Benefits Security Administration let us know about extending the public comment period on its proposed Improving Transparency Into Pharmacy Benefit Manager Fee Disclosure rule to April 15, 2026.

From the Food and Drug Administration front,

  • MedTech Dive tells us,
    • “The Food and Drug Administration on Tuesday posted a warning letter sent to Beta Bionics in late January.
    • “The letter raised concerns with how the diabetes tech company handled complaints of severe low and high blood sugar associated with its automated insulin delivery system. The FDA also flagged problems with the company making modifications to its device without notifying regulators.
    • “In an annual report filed Tuesday, the company said it has already taken several corrective actions, including improvements to the processes identified in the warning letter. The company is also preparing a written response to the letter.”
  • Cadiovascular Business informs us,
    • Cara Medical, a medtech company focused on advanced imaging technologies, has secured U.S. Food and Drug Administration (FDA) clearance for its new platform that noninvasively visualizes a patient’s cardiac conduction system.
    • “The CARA System, which previously earned the FDA’s breakthrough device designation, was designed to help interventional cardiologists and electrophysiologists plan ahead before procedures and then guide them during treatment. It can be used for structural heart interventions such as transcatheter aortic valve replacement (TAVR) as well as pacing procedures.
    • “The newly cleared system includes two primary components. The CARA Metis Simulator is a preprocedural planning software that identifies the cardiac conduction axis on CT angiography results and generates a 3D map of the patient’s conduction system. The CARA Atlas Navigator, meanwhile, overlays that map onto live fluoroscopic images to assist with intraprocedural guidance. 
    • “Artificial intelligence (AI) algorithms play a role in both components, extracting metadata and detecting the user’s catheter for visualization, but all AI calculations can still be confirmed by a physician.”

From the public health and medical / Rx research front,

  • The Centers for Disease Control and Prevention announced today,
    • “Seasonal influenza activity remains elevated nationally. RSV activity is elevated and increasing in some areas of the country. Emergency department visits and hospitalizations for RSV are highest among infants and children less than 4 years old. COVID-19 activity is decreasing nationally but remains elevated in some areas of the country.
    • “COVID-19
      • “COVID-19 activity is decreasing nationally but remains elevated in some areas of the country.
    • “Influenza
      • “Seasonal influenza activity remains elevated nationally. Influenza A activity is decreasing while influenza B activity is increasing nationally and in most areas of the country.
      • “Additional information about current influenza activity can be found at: Weekly U.S. Influenza Surveillance Report | CDC
    • RSV
      • “RSV activity is elevated in many areas of the country, including emergency department visits and hospitalizations among infants and children 4 years and younger.
    • Vaccination
      • “National vaccination coverage for COVID-19, influenza, and RSV vaccines remains low for children and adults. COVID-19, influenza, and RSV vaccines can provide protection against severe disease. It is not too late to get vaccinated this season. Talk to your doctor or trusted healthcare provider about what vaccines are recommended for you and your family.”
  • The University of Minnesota’s CIDRAP tells us,
    • “The US Centers for Disease Control and Prevention (CDC) has ended its investigation into the recent multistate infant botulism outbreak traced to ByHeart powdered formula and lowered the total case number by three. In a Public Health Alert issued earlier this week, California, CDC, and Food and Drug Administration scientists reported 51 infections, but yesterday the CDC said it has excluded three suspected cases, for a total of 48 (28 confirmed, 20 probable) in November and December 2025. While the outbreak is over, investigators continue to probe how Clostridium botulinum bacteria got into the formula, the CDC said.
    • “A report published yesterday in the CDC’s Morbidity and Mortality Weekly Report describes how officials used artificial intelligence (AI) to identify contaminated ice in a beer cooler as the source of a 2024 Salmonella enterica outbreak at a county fair. Ice is an uncommon vehicle for Salmonella spread at public events, noted author Katherine Houser, RN, of the Brown County Health Department in Mount Sterling, Illinois. The outbreak sickened 13 people (seven confirmed, six probable cases). AI tools helped synthesize background information to support and contextualize the environmental health team’s assessment, Houser said.”
  • The CDC also announced today,
    • “As of February 26, 2026, 1,136 confirmed* measles cases were reported in the United States in 2026. Among these, 1,130 measles cases were reported by 28 jurisdictions: Arizona, California, Colorado, Florida, Georgia, Idaho, Illinois, Kentucky, Maine, Minnesota, Nebraska, New Mexico, New York City, New York State, North Carolina, North Dakota, Ohio, Oklahoma, Oregon, Pennsylvania, South Carolina, South Dakota, Texas, Utah, Vermont, Virginia, Washington, and Wisconsin. A total of 6 measles cases were reported among international visitors to the United States. 
    • “There have been 10 new outbreaks** reported in 2026, and 90% of confirmed cases (1,023 of 1,136) are outbreak-associated (152 from outbreaks starting in 2026 and 871 from outbreaks that started in 2025).”
  • MedPage Today informs us,
    • “Identical stool samples sent to seven direct-to-consumer microbiome testing companies produced substantially different bacterial profiles and health assessments.
    • “Across 18 commonly reported microbial genera, no company’s results matched the consensus; and only three genera of 1,208 identified taxa appeared in every report.
    • “Researchers attributed the discrepancies to differences in laboratory methods and analysis pipelines, and say the results underscore the need for standardized testing and quality controls.”
  • The Wall Street Journal considers
    • “Why All The Fuss About Bone Density?
    • “Like most of my peers, I’m being bombarded daily with hectoring advice about my bones. What’s a 40-something woman to do?” * * *
    • “For guidance, [the journalist] consult[s] with Dr. Karen Tang, the author of “It’s Not Hysteria: Everything You Need to Know About Your Reproductive Health (but Were Never Told),” who offers a more measured take.” 
  • Medscape adds,
    • “A low-dose, single pill that combines three antihypertensive treatments is as effective as standard-dose monotherapy — in some cases even better — for treating mild-to-moderate hypertension, according to the first phase 3 double-blind trials comparing the medications.
    • “Investigators for the HM-APOLLO-301 and HM-APOLLO-302 phase 3 clinical trials, which were published in the Journal of the American College of Cardiology, contend there is now concrete evidence to support the efficacy of the single-pill therapy.
    • “They argue that starting with the traditional single-agent therapy and then titrating up can delay blood pressure control, increase the possibility of adverse effects, and affect patient adherence.”
  • The University of Minnesota’s CIDRAP relates,
    • “The results of a randomized controlled trial (RCT) indicate that meningococcal B vaccine is not effective at preventing gonorrhea infection in high-risk groups.
    • “The results, presented this week at the Conference on Retroviruses and Infections by a team of Australian researchers, show that among gay and bisexual men with a history of gonorrhea infection who received either the 4CMenB vaccine or placebo, gonorrhea incidence was essentially the same—roughly 48% in both arms.
    • “The 4CMenB vaccine is designed to protect against four serogroups of Neisseria meningitidis, which can cause invasive meningococcal disease. But in recent years, observational studies have suggested 4CMenB might also provide moderate cross-protection against Neisseria gonorrhoeae, the bacterium that causes gonorrhea—one of the most common sexually transmitted infections (STIs) worldwide.” 
  • Genetic Engineering and Biotechnology News reports,
    • “CAR T cell therapy has revolutionized the treatment of many blood cancers, but has shown little success against solid tumors, which account for more than 85% of all cancers.
    • “Columbia University researchers have now developed a new form of highly sensitive CAR T cells, known as HIT T cells, that aims to overcome one of the biggest barriers in solid tumor immunotherapies, which is the way that solid tumors lack a single, widely shared surface target.
    • “Headed by Michel Sadelain, MD, PhD, director Columbia Initiative in Cell Engineering and Therapy (CICET), the researchers engineered an ultra-sensitive and highly selective chimeric antigen receptor called an HLA-independent T cell (HIT) receptor, which is capable of detecting even the smallest amounts of the protein CD70 on tumor cells.”

From the U.S. healthcare business front,

  • Healthcare Dive reports,
    • “Elevance is consolidating control of its health insurance businesses under Felicia Norwood, its head of government benefits, as the company looks to improve coordination across its Medicaid, Medicare and commercial plans and — hopefully — bolster waning profits.
    • “Mark Kaye, Elevance’s CFO, will also take on leadership of health services division Carelon as current president Peter Haytaian leaves to spend more time with his family, according to a press release Thursday announcing the executive changes.
    • “Haytaian will leave the role effective May 4 and stay on as an advisor through the end of the year. The executive first joined Elevance in 2012 through its acquisition of Amerigroup before becoming president of Carelon in 2021.”
  • Beckers Payer Issues adds,
    • “Longtime UnitedHealth Group executive Heather Cianfrocco is leaving the company.
    • Ms. Cianfrocco has served as executive vice president of governance, compliance and information security at UnitedHealth since April 2025. She briefly served as CEO of Optum from 2024 to 2025 before being succeeded by Patrick Conway, MD, who previously led Optum Rx. 
    • “After 24 years, I am saying goodbye to the team at UnitedHealth Group,” she wrote on LinkedIn Feb. 27. “I am leaving with so much pride in what we have accomplished together. I’ve had the privilege of working alongside some of the most talented, mission-driven people who show up every day determined to make health care easier to navigate, more affordable and more human.”
  • Beckers Hospital Review notes,
    • “CVS Caremark is expanding its use of Surescripts’ Touchless Prior Authorization platform to accelerate approvals for select specialty medications.
    • “The prior authorization technology connects directly to patients’ EHRs to gather required clinical data and match it with prior authorization criteria, according to a Feb. 25 news release. When requirements are met, CVS Caremark can approve medications automatically in as little as 22 seconds.
    • “The platform is currently used for select specialty drugs, including Vivitrol and Epidiolex, which treat substance use disorder and epilepsy. These medications typically require complex approvals because of their high impact and specialized clinical use cases.”
  • Healthcare Dive tells us,
    • “Teladoc Health projects membership in its business-to-business integrated care unit will decline this year, in part due to the expiration of enhanced Affordable Care Act subsidies, management said during a fourth-quarter earnings call Wednesday.
    • “The company expects 97 million to 100 million members in U.S. integrated care in 2026, down from 101.8 million at the end of last year. 
    • ‘Teladoc expects the decline will be driven by enrollment reductions at some client health plans in government programs, which were impacted by the lapse of more generous financial assistance for ACA coverage, CEO Chuck Divita said on the call.”
  • Fierce Healthcare adds,
    • “Walgreens is wading into the self-pay GLP-1 space, going head-to-head with telehealth subscription offerings.
    • “The retail pharmacy giant launched a digital weight management service to offer access to personalized, clinician-guided support for weight loss. The service expands Walgreens’ virtual healthcare platform and provides patients with access to licensed doctors and nurse practitioners, FDA-approved medication options and ongoing virtual support, according to the company in a press release.
    • “Virtual visits through the weight management service cost $49 with no requirement for a monthly subscription. The program, currently available in 28 states, is intended for eligible overweight and obese adults ages 18-64 who plan to self-pay for their GLP-1 medication.”
  • Healthexec summarizes news from “the 2026 ViVE conference, part of HLTH, [which] just wrapped up in California. On the show floor, people from across the healthcare and health IT space gathered for four days of events, thought leader insights and product showcases on the floors of the Los Angeles Convention Center. 

Tuesday report

From Washington, DC

  • Bloomberg Law reports,
    • “Another reconciliation bill represents a “tremendous opportunity”for Republicans to pass key policy priorities before the midterm elections, a House GOP tax-writer said Monday.
    • “Rep. Beth Van Duyne (R-Texas), a member of the House Ways and Means Committee, said at a Bloomberg Government roundtable that Republicans want a second shot at passing several provisions that were axed from their first reconciliation bill passed last year.
    • “It was a heavy lift to do reconciliation 1.0,” Van Duyne said. “But I think there’s a lot of parts of that bill that got washed out in the Byrd bath that we would like to be able to see put in reconciliation 2.0.” * * *
    • “Republican leaders including Ways and Means Chairman Jason Smith (R-Mo.) along with President Donald Trump have been cool to the idea of starting work on a second party-line bill given how challenging it was to pass the first bill, though a number of rank-and-file GOP lawmakers have clamored for it.
    • “There’s a lot of very strong bills that would be productive to be able to have passed and the only way that we can do that is put it in reconciliation,” Van Duyne said.”
  • and
    • “More than three dozen employers, insurers, and patient advocacy groups are askingthe Trump administration to intervene in the arbitration process for surprise medical bills. 
    • “Dysfunction under the No Surprises Act has flooded the courts with cases of alleged fraud on both sides. Insurers accuse providers of knowingly submitting ineligible claims to the arbitration process, while providers allege insurers are misleading arbitrators on key payment metrics.
    • “Health insurance companies and employers are losing the vast majority of cases under the law. Data from the Centers for Medicare & Medicaid Services, which oversees the arbitration process, show that providers are winning 88% of the time. But courts are largely siding with insurers when providers allege they aren’t paying up, saying that enforcement resides with the CMS.
    • “The Office of Management and Budget is reviewing a final rule to improve the independent dispute resolution process, which requires arbitrators to settle out-of-network bills between doctors and insurers. The rule has languished since the Department of Health and Human Services first proposed it in November 2023 as a series of legal challenges from the Texas Medical Association unfolded in the courts.
    • “More transparency and accountability is needed for companies that oversee arbitration, the ERISA Industry Committee, American Benefits Council, Business Group on Health, Elevance Health, union 32BJ Health Fund, and others said in a letter Tuesday.”
  • FEHBlog note — With regard to transparency, one of the factors that the arbitrators consider is patient acuity. A health plan can only guess at that factor. That’s unreasonable. The arbitration process should better align with American Arbitration Association rules for baseball arbitration.
  • Mobihealth News relates,
    • “Dr. Mehmet Oz, administrator of the Centers for Medicare and Medicaid Services (CMS), said during an Action for Progress event focused on addiction and mental health that AI avatars are the best way to help rural communities access mental healthcare.
    • “We do not have enough practitioners for mental health support in these areas,” Dr. Oz said during the event.
    • “I’m telling you right now. There’s no question about it – whether you want it or not – the best way to help some of these communities is going to be AI-based avatars.”
    • “He proposed using agentic AI with the ability to conduct early mental health intakes, customize support to a patient’s needs and understand what a patient is “up to.”  
    • “[These tools] will pick up subtle little nuances in how you’re saying things – if you do it on purpose, it’s actually cool to find out – that will alert the avatar, but more importantly, the doctor they are going to report to that there is something going on,” Oz said. “And there will always be a doctor.”
    • “He framed the use of AI avatars to be used in conjunction with clinicians as, he said, humans are biologically designed to interpret facial cues, such as happiness, boredom, excitement and more, before a person verbalizes it.
    • “The key question is how do we use AI thoughtfully in that setting? If we do it right, we’ll build a much more sustainable healthcare system around mental health issues,” Oz said.”  

From the Food and Drug Administration front,

  • Fierce Pharma reports
    • “Four years after the FDA issued its most heavy-handed form of a rejection to the prior company behind pegzilarginase, the U.S. regulator has now given the treatment a thumbs-up.
    • “Scoring the accelerated nod is Immedica Pharma for Loargys as a therapy for hyperargininemia in the ultrarare genetic disorder Arginase 1 deficiency (ARG1-D). The approval covers patients age 2 and older, with the therapy to be used in conjunction with a protein-restricted diet. 
    • “Loargys, which is also known as pegzilarginase, is a recombinant human enzyme designed to lower levels of arginine in patients who are unable to break down the amino acid. It is the first treatment to address the elevated levels of plasma arginine associated with the disorder.”
  • and
    • “Sanofi and Regeneron’s megablockbuster immunology drug Dupixent has gained yet another FDA approval, this time in allergic fungal rhinosinusitis (AFRS).
    • “The U.S. regulator signed off on the drug as a treatment for adults and children ages 6 and older with AFRS based on late-stage trial data showing Dupixent reduced nasal signs and symptoms and systemic corticosteroid use or surgery compared to placebo, according to a Feb. 24 press release.” * * *
    • “Harmony Biosciences is rounding out the U.S. patient pool eligible for its sleep disorder pill Wakix after notching a pediatric nod from the FDA that positions the drug as a treatment for cataplexy in people ages 6 and older with narcolepsy.
    • “The new addition to Wakix’s label makes it the only non-scheduled treatment for both adult and pediatric narcolepsy patients in the U.S. with or without cataplexy. That non-scheduled classification represents an “important distinction that supports its clinical utility,” Harmony’s CEO, Jeffrey Dayno, M.D., commented in a press release. Cataplexy is a common symptom of narcolepsy that involves a sudden weakening of muscles, often when triggered by a strong emotion.” * * *
    • “Two months after Johnson & Johnson’s Rybrevant Faspro picked up its first FDA approval, the subcutaneous lung cancer drug has scored a label expansion to be given monthly.
    • “On Tuesday, J&J touted a “simplified” monthly dosing regimen for the drug’s combination with lazertinib for the first-line treatment of epidermal growth factor receptor EGFR-mutated advanced non-small cell lung cancer. Previously, the combo was approved as an every-two-week regimen.”
  • and
    • “Just three months after further scaling back its support for the struggling hemophilia A gene therapy Roctavian, the company is walking away altogether by pulling the treatment from the market. 
    • “The move follows a “comprehensive effort” to identify a potential buyer for the therapy, BioMarin explained Monday in its fourth-quarter earnings press release.” 

From the public health and medical / Rx research front,

  •  Health Day relates,
    • “You don’t need to look buff or tough, but muscle strength can influence how long you’ll live, a new study says.
    • “Older women with greater strength had a significantly lower risk of death during an eight-year follow-up, researchers recently reported in JAMA Network Open.
    • “The study measured women’s grip strength and ability to rise from a seated to standing position — two tests commonly used to determine seniors’ strength levels.
    • “Women had a 12% lower death rate for every 15 additional pounds of grip strength they exhibited during testing, researchers found.
    • “Likewise, they had a 4% lower death rate for every 6 seconds faster they could complete five sit-to-stand chair raises, results showed.”
  • and
    • “Teens who use weed are twice as likely to develop psychotic or bipolar disorders, a new study says.
    • “They also are more likely to have depression and anxiety, researchers reported Feb. 20 in JAMA Health Forum.
    • “As cannabis becomes more potent and aggressively marketed, this study indicates that adolescent cannabis use is associated with double the risk of incident psychotic and bipolar disorders, two of the most serious mental health conditions,” researcher Dr. Lynn Silver said in a news release. She’s a program director at the Public Health Institute in Oakland, California.
    • “More than 10% of 12- to 17-year-olds in the U.S. have used weed within the past year, researchers said in background notes. By their senior year in high school, about 26% of U.S. teenagers have tried it.”
  • and
    • “Side effects like nausea or vomiting are common among folks taking Ozempic/Wegovy, but they’ll grin and bear it if they think they’re losing weight, a new study finds.
    • “The drugs’ perceived effectiveness — lost weight, less appetite, fewer food cravings — outweigh GI side effects, researchers reported recently in the Journal of Medical Internet Research.”
  • MedPage Today informs us,
    • “Hepatitis B vaccination rates among U.S. newborns have fallen by more than 10 percentage points over the past 2 years.
    • “Those rates climbed steadily for 6 years, peaking at 83.5% in February 2023 before dropping to 73.2% by August 2025.
    • “The drop began months before the CDC’s Advisory Committee on Immunization Practices voted in December to stop universally recommending the birth dose.”
  • and
  • Per an NIH news release,
    • “A study funded by the National Institutes of Health (NIH) reduced new HIV cases by 70% in rural Kenya and Uganda by pairing digital tools with tailored HIV services delivered by community health workers and clinicians. This successful strategic implementation of existing healthcare infrastructure and available HIV prevention and treatment options could become a model for reducing HIV incidence in other countries, including the United States. The findings were presented today at the 33rd Conference on Retroviruses and Opportunistic Infections (CROI 2026) in Denver.”  
  • Here’s a link to the latest edition of NIH’s Research Matters which covers the following topics:

From the U.S. heathcare business and artificial intelligence front,

  • The Wall Street Journal reports,
    • Novo Nordisk NOVO.B plans to slash U.S. list prices for its popular weight-loss and diabetes drugs Wegovy and Ozempic by up to half starting next year.
    • Under the changes, both Ozempic and Wegovy will list for $675 a month, effective Jan. 1, 2027. That is half of the current price tag for anti-obesity therapy Wegovy and a 34% cut for diabetes treatment Ozempic. The price cuts also will apply to pill versions of both injections, including one sold as Rybelsus.
    • The reductions escalate a price war with rival Eli Lilly LLY -1.40% in one of the fastest-growing, most hotly contested categories in pharmaceuticals.
  • Optum Rx, writing in LinkedIn, discusses the next phase of the GLP-1 revolution.
  • STAT News relates,
    • “In the last year and a half, direct-to-consumer telehealth company Hims & Hers has become a leading voice in the debate over compounded GLP-1 weight loss medications. On Monday, it announced earnings from the last quarter of 2025 after a whirlwind month that raised questions about the regulatory risks of the company’s compounding model and the threat of an investigation. 
    • “In the call, Hims & Hers CEO Andrew Dudum addressed the increased scrutiny on compounded GLP-1s and its impact on the business’s bottom line, emphasizing Hims’ other medications, including for weight loss. “We believe there’s a really durable weight business,” said Dudum, “even if you think you’re kind of in a draconian scenario of compounding GLP-1s not being there.”
  • Fierce Healthcare tells us,
    • “Employers are spending more on women’s and family health, but that is not always being felt by employees, a new report finds.
    • “The Maven Clinic released its fifth annual State of Women’s & Family Health Benefits report, which is based on responses from over 2,000 HR leaders and nearly 5,000 full-time employees across the U.S., U.K., Canada and India. The report highlights how rising healthcare costs are reshaping how employees seek care and what actions employers are considering to help address those costs.
    • “Though employers reported a 39% average increase in women’s and family health benefits offered year-over-year, the share of employees who felt their benefits support them “very well” dropped 10% on average. Globally, across all benefits, employers were slightly more likely to add or enhance benefits in the next year compared to those in the U.S.”
    • “From Maven’s perspective, all the report’s findings highlight the need for an integrated approach to benefits and care delivery.
    • “We think that the category continues to show importance, and that is a positive,” Stephanie Glenn, chief commercial officer at Maven, told Fierce Healthcare. 
    • “But the gap in what’s being offered and what employees are feeling exists because of a lack of thoughtful integration, she added. “Unless it’s a coordinated offering, if you get a one-time email about a new benefit, it’s very disjointed. You don’t understand what it looks like,” she said.”
  • Healthcare Dive tells us,
    • “Thirty-one thousand Kaiser Permanente nurses and other healthcare professionals in California and Hawaii ended a major strike Tuesday after about a month on the picket lines. 
    • “In a statement Monday, the workers’ union, the United Nurses Associations of California/Union of Health Care Professionals, said “significant movement” at the bargaining table over the past two days prompted leaders to end the strike.
    • “Returning members to their patients and their livelihoods is the clearest path to securing a final agreement and building on the progress achieved during the strike,” the UNAC/UHCP said.”
  • and
    • “Home health and hospice provider Enhabit has agreed to be taken private by private equity firm Kinderhook Industries in a deal worth $1.1 billion.
    • “Under the deal terms announced Monday, shareholders will receive $13.80 in cash per share, representing an almost 25% premium over Enhabit’s closing stock price on Feb. 20. 
    • “The Dallas-based provider — which has almost 250 home health locations and over 115 hospice locations in 34 states — will cease trading on the New York Stock Exchange when the deal closes, which the companies expect to happen in the second quarter this year.”
  • Beckers Hospital Review notes,
    • “For the first time, women now make up the majority of physicians in U.S. training programs, according to the Association of American Medical Colleges’ annual report on residency trends. 
    • “In the 2024-25 academic year, women accounted for 50.2% of residents and fellows across all specialties and subspecialties, per the report. The figure marks a stark contrast from the 1970s, when women comprised less than 10% of physicians, and reflects decades of steady growth in female representation in medical schools and training programs.”
  • and
    • “If healthcare IT were golf, CIOs would take a few mulligans.
    • “Choosing and installing an EHR is often one of the biggest, most complicated decisions IT leaders will ever make, and some executives told Becker’s they would do things differently if they could go back in time.”
  • Per MedTech Dive,
    • “Medtronic on Tuesday priced a planned initial public offering for its MiniMed diabetes spinoff at up to $784 million.
    • “MiniMed plans to price its IPO between $25 and $28 per share across 28 million shares. Underwriters will also have the option to buy an additional 4.2 million shares at the IPO price.
    • “Medtronic first announced plans to spin out its diabetes business into a separate, publicly traded company in May. The new firm would be the only company in the market that sells both insulin pumps and continuous glucose monitors.”

Monday report,

From Washington, DC,

  • The Hill reports,
    • “Lawmakers return to Capitol Hill this week facing an uphill climb to fund the Department of Homeland Security (DHS) as Republicans see an opening after President Trump’s State of the Union address on Tuesday despite few signs that Democrats are willing to compromise on their demands.”
  • The Congressional Budget Office tells us,
    • “The Congressional Budget Office regularly updates the Congress on our projections of the Hospital Insurance (HI) Trust Fund’s financial position as well as changes in our outlook on that position. This blog post serves as that update.
    • “The HI trust fund is used to pay for benefits under Medicare Part A, which covers inpatient hospital services, care provided in skilled nursing facilities, home health care, and hospice care. The fund derives its income from several sources. Over the next 30 years, about three-quarters of its annual income comes from the Medicare payroll tax and roughly one-eighth comes from income taxes on Social Security benefits. The rest comes from other sources.” * * *
    • “The year in which the HI trust fund’s balance is exhausted in our current projections, 2040, is 12 years earlier than in our most recent estimate of that date, which was published in March 2025. Measured in relation to taxable payroll, the trust fund’s 25-year actuarial deficit is 0.17 percentage points greater in the current projections than in last year’s. (Measured in relation to GDP, the actuarial deficit is 0.07 percentage points greater than we projected last year.) Those changes are driven largely by projections of less income to the fund. Projections of greater spending also contribute to the changes.”
  • STAT New reports,
    • “More evidence is starting to show the government’s arbitration process to settle out-of-network bills has morphed into a cash cannon for doctors and medical groups.
    • Jinghong Chen of Payer Perspectives sifted through the latest federal data covering the arbitration process created by the No Surprises Act and found that not only are medical groups winning nearly nine out of every 10 cases, they are also getting paid more than anyone can imagine.
    • “The NSA’s arbitration process encouraged the use of the “qualifying payment amount” — essentially the average in-network rate that providers in a given area have agreed to — as a benchmark for disputes. How quaint. Instead, medical groups have fought for, and won, astronomically higher amounts. 
    • “Radiologists are winning offers that are, on average, almost 500% of the typical in-network rate, according to Chen’s analysis. Surgeons are getting payments for contested services that are a median 1,320% above the in-network rate. Neurology and neuromuscular procedures have median winning offers of nearly 2,400% above the in-network average.”
  • Govexec informs us,
    • “Federal supervisors are poised to soon face limitations on how many employees they can rate as above average in their annual performance reviews after the Trump administration on Monday proposed upending the process for evaluating civil servants. 
    • “The Office of Personnel Management’s proposed rule would implement the first major overhaul of the federal employee performance management system in decades. The Trump administration is aiming to correct for what it views as inflated ratings within the federal workforce. 
    • “The rule, which OPM will formally release on Tuesday, largely mirrors a draft version Government Executive exclusively obtained and reported on in December.”
  • The Affordable Care Act regulators announced today their decision to extend the public comment period for the proposed rule that appeared in the Federal Register on December 23, 2025, titled “Transparency in Coverage” from February 23, 2026, to March 2, 2026.
  • The New York Times reports,
    • “Adding to a rapid shake-up of the leadership at federal health agencies, the Centers for Disease Control and Prevention announced on Monday that Dr. Ralph Abraham had resigned as the agency’s principal deputy director.
    • “His departure thins the ranks of vaccine skeptics at the agency’s helm, a sign of the administration’s pivot away from the agenda pursued thus far by Health Secretary Robert F. Kennedy Jr. and his appointees.
    • “Dr. Abraham’s resignation, which comes less than three months into the job, was effective immediately, the agency said in a statement on its website.” 

From the Food and Drug Admininstration front,

  • Beckers Hospital Review tells us,
    • “Eli Lilly has launched a multidose version of its blockbuster weight loss drug Zepbound that gives patients a month’s worth of treatment in a single injection pen.  
    • “On Feb. 23, the drugmaker said the FDA approved a label expansion for Zepbound (tirzepatide) to include the four-dose, single-patient-use KwikPen. The device contains four weekly doses, reducing the number of pens patients need each month compared with single-dose injectors.
    • “The KwikPen will be available by prescription for self-paying patients through LillyDirect, Eli LIlly’s direct-to-consumer platform. Prices start at $299 per month for the lowest dose. Patients choosing the self-pay option can access all approved doses in either the multidose pen or single dose vial at the same price, the company said.”
  • Per an FDA news release,
    • “The U.S. Food and Drug Administration today issued draft guidance for sponsors seeking approval for targeted individualized therapies by generating substantial evidence of effectiveness and safety when randomized controlled trials are not feasible due to small patient populations. 
    • “The draft guidance, issued by the Center for Biologics Evaluation and Research and Center for Drug Evaluation and Research, specifically discusses genome editing and RNA-based therapies such as antisense oligonucleotides but leaves open the potential that this framework may apply to additional tailored therapeutics provided they directly address the underlying specific cause of the disease.” * * *
    • “The draft guidance, Considerations for the Use of the Plausible Mechanism Framework to Develop Individualized Therapies that Target Specific Genetic Conditions with Known Biological Cause, is available for public comment. Comments must be submitted within 60 days of publication in the Federal Register at Regulations.gov.”
  • Per Fierce Pharma,
    • “Vanda Pharmaceuticals is riding a regulatory roller coaster over the last few months. December brought an FDA thumbs up for its new motion sickness drug Nereus. Then in January, the U.S. regulator re-upped its rejection of Vanda’s Hetlioz for jet lag disorder.
    • “Now in February, the agency has issued another new drug approval to Vanda, signing off on Bysanti as a first-line treatment for schizophrenia or for manic or mixed episodes associated with bipolar I disorder. 
    • :The atypical antipsychotic tablet, also known as the chemical compound milsaperidone, has demonstrated in clinical trials its bioequivalence to Vanda’s Fanpat (iloperidone), which has been approved in the same two indications.”
  • and
    • “Only a month after Jazz Pharmaceuticals said it had signed a deal to sell an FDA priority review voucher (PRV) for $200 million, a new PRV transaction involving Fortress Biotech and an unnamed buyer shows that the trend of rising voucher prices is still going strong.
    • “Monday morning, Fortress said its subsidiary, Cyprium Therapeutics, has entered into an agreement to sell a recently received rare pediatric disease priority review voucher for $205 million. Cyprium got its hands on the PRV as part of the FDA’s recent approval of injected copper replacement therapy Zycubo as the first treatment approved in the U.S. for the rare neurodegenerative disorder Menkes disease.
    • “While another company, Sentynl Therapeutics, is handling development and commercialization of Zycubo under a 2023 agreement, the deal called for Sentynl to transfer the PRV back to Fortress/Cyprium after the approval.”  

From the public health and medical / Rx research front,

  • STAT News reports,
    • “Women’s bodies are different from men’s in ways that medicine is still learning. Meanwhile, their risk of serious cardiovascular events can be underestimated if their distinct risk profiles are blurred with men’s. 
    • “The latest example of important sex differences centers on the plaque burden in coronary arteries — a measure of fat and cholesterol deposits that also accounts for blood vessel size. 
    • “Women tend to have lower volumes of plaque than men, but their total plaque burden is higher because the fatty deposits take up a larger fraction of their smaller coronary arteries. Their risk for a heart attack or hospitalization for chest pain emerged when their plaque burden was lower than men’s, and their risk climbed more steeply, too, a new study published Monday in Circulation: Cardiovascular Imaging concluded.”
  • The Washington Post relates,
    • “Obstetrician Jeanne Conry has long paid attention to the “1,300-day window”— the months before conception through a child’s second birthday. Studies show nutrition and lifestyle during this period can shape pregnancy outcomes and the long-term health of the babies. Conry began to wonder if such factors could also influence autism.
    • “She is now helping lead an educational push aimed at alerting women to their exposure to toxins, stress and infections during this narrow and consequential window — guided by the idea that what happens then may subtly shape eggs or sperm, and in turn, influence a child’s development long before pregnancy begins.
    • “The more we research, the more we see links between different chemical exposures and autism so if we reduce those links we will ideally reduce cases,” Conry said.”
  • STAT News also informs us,
    • “Novo Nordisk’s next-generation weight loss drug CagriSema, one of the company’s key hopes to help it regain its footing in the increasingly competitive obesity market, failed in a key study that compared it to rival Eli Lilly’s tirzepatide, Novo said Monday. 
    • “The open-label REDEFINE 4 study was designed to test whether CagriSema could help patients lose the same amount of weight as those who received tirzepatide, which is sold as Zepbound and Mounjaro. But over 84 weeks, patients in the CagriSema arm saw a weight loss of 20.2%, versus 23.6% for those getting tirzepatide. Statistically, the results did not show that CagriSema performed equivalently to Lilly’s drug — what’s known as non-inferiority.” 
  • The Hill adds,
    • “An ingredient in the prescription diabetes drug Mounjaro was found to reduce alcohol intake in rodents, according to a recent study. 
    • “In the study, published in early January in the medical journal eBioMedicine, researchers in Sweden, South Carolina and Brazil looked at how the ingredient, tirzepatide, affected rodents. The researchers found that alcohol’s “rewarding properties” were lessened by the ingredient and that behaviors including the voluntary consumption of alcohol and binge drinking dropped.
    • * * * “In summary, our findings indicate that tirzepatide influences alcohol-related responses in ways that appear to have clinical potential. Tirzepatide consistently reduced alcohol intake across different drinking paradigms and both sexes without signs of tolerance development,” the researchers wrote.
    • “Perhaps more significantly, tirzepatide’s effects on relapse behaviours suggest it might help decrease relapse vulnerability, a finding that could prove important for therapeutic applications,” they added.”
  • The American Medical Association lets us know “What doctors wish patients knew about food allergies.”
    • “Milk, eggs, peanuts, tree nuts, fish, shellfish, wheat, soy and sesame are the “Big Nine” food allergies. Two allergists share more about food allergies.”
  • NPR adds,
    • “Ultra-processed foods are industrially manufactured products that contain ingredients rarely found in your kitchen, such as preservatives, artificial sweeteners, colorings, natural flavors and emulsifiers. Numerous studies have shown that these foods increase the risk of a host of health problems, including diabetesheart diseasedepression and obesity.
    • “When people ask me about ultra-processed foods, they’re often most confused about grains, carbohydrates and starches,” says Dr. Dariush Mozaffarian, who leads the Food is Medicine Institute at Tufts University. These foods include breads, crackers, pretzels, pea snaps, veggie straws, pastas and puffed rice or corn. “People want to know how to choose more healthful versions of these products,” he says.
    • “So Mozaffarian gives his patients two practical rules of thumb to follow when selecting grains and starches: the 10 to 1 test and the water test.”
  • Cardiovascular Business points out,
    • “The risk of death following percutaneous coronary intervention (PCI) remains incredibly low, according to new findings published in The American Journal of Cardiology.[1] When it does occur, acute myocardial infarction (AMI), cardiac arrest and infection are two of the most common reasons.
    • “Estimating the risk of periprocedural mortality after percutaneous coronary intervention (PCI) is crucial for risk stratification and quality assessment,” wrote Dimitrios Strepkos, MD, a researcher with the Minneapolis Heart Institute Foundation, and colleagues. 
    • “Strepkos et al. examined data from the PROGRESS-COMPLICATIONS registry, focusing on more than 22,000 patients who underwent PCI from 2014 to 2024 at one of two high-volume U.S. facilities. The overall technical success rate was 78.3%. While 14.8% of patients underwent atherectomy as part of the procedure, 6.1% underwent intravascular lithotripsy.”

From the U.S. healthcare business and artificial intelligence front,

  • The Wall Street Journal reports,
    • Merck MRK is shaking up the leadership of its main pharmaceutical unit as the U.S. drugmaker braces for sales pressure later this decade.
    • “The Rahway, N.J.-based company said Monday it will split its human-health business into two divisions. One will house its cancer drugs, including the blockbuster Keytruda. The immunotherapy accounts for nearly half of total Merck sales but is due to lose U.S. patent protection in 2028, exposing it to lower-cost copycat competition.
    • “The second new division—the specialty, pharma and infectious-diseases business unit—will sell noncancer products, including the HPV vaccine Gardasil, diabetes drug Januvia and newer products such as lung-disease treatment Winrevair. 
    • “Merck is counting on this unit to generate big sales growth to offset the expected Keytruda sales decline.” 
  • Beckers Hospital Review reports,
    • “Nacogdoches (Texas) County Hospital District is eyeing a new lease agreement with Dallas-based Tenet Healthcare that would merge Nacogdoches Memorial Hospital with Nacogdoches Medical Center, ABC affiliate KTRE reported Feb. 19.
    • “Under the proposed deal, the two hospitals would operate under unified management.
    • “Consolidating the hospitals would help the district sustain care for the community’s underserved population while benefiting from the resources and support of a larger health system, David Schaefer, vice president of the hospital district’s board, told the media outlet.” 
  • MedTech Dive notes,
    • “Guardant Health has acquired MetaSight Diagnostics for $59 million in upfront cash to bolster its multi-disease detection pipeline, the company said Thursday. The deal includes up to $90 million in payments tied to future commercial performance and regulatory approvals.
    • “MetaSight uses mass spectrometry multi-omics technology to find biomarkers associated with acute and chronic diseases in serum samples. Tests for colorectal cancer, an area of focus for Guardant, and liver disease-associated fibrosis were MetaSight’s two most advanced programs just before the acquisition.”  
  • Fierce Healthcare points out,
    • “As providers rapidly adopt artificial intelligence technology for clinical documentation, there is a demand for AI clinical assistants that meet the needs of specialty medicine practices.
    • “Health tech company Nextech recently launched its next-generation AI assistant, called Cora, along with its clinical documentation feature, Cora Scribe, to provide AI technology that was designed with specialty workflows in mind, according to the company.
    • “Nextech provides electronic medical record and practice management software to specialty physician practices as well as revenue cycle management (RCM), customer relationship management (CRM) and other software systems. The company supports 16,000 physicians, more than 5,500 practices and 60,000 office staff members in the clinical specialties of dermatology, ophthalmology, orthopedics, plastic surgery and medical spa practices.”
  • The American Hospital Association News adds,
    • “The AHA responded to a request for information today from the Department of Health and Human Services on the adoption and use of artificial intelligence in clinical care. The AHA urged HHS to synchronize and leverage existing AI policy frameworks to avoid redundancy, remove regulatory barriers that inhibit the development and deployment of AI tools, adopt policies ensuring the safe and effective use of AI, and align incentives and address infrastructural factors necessary to expand AI in health care.  
    • “The AHA’s comments build upon previous responses to RFIs on regulation and reimbursement for AI, including an RFI from the Office of Science Technology Policy on ways to reduce regulatory burden for AI, an RFI from the Food and Drug Administration on measuring and evaluating AI-enabled medical devices, and RFIs from the Centers for Medicare & Medicaid Services on payment for AI tools through the calendar year 2026 Outpatient Prospective Payment System proposed rule and CY 2026 Physician Fee Schedule proposed rule.”

Cybersecurity Saturday

From the cybersecurity policy and law enforcement front,

  • Cyberscoop reports from its Cybertalks event held earlier this week.
    • “Department of Health and Human Services official said Thursday that HHS is devoting a lot of attention to the security of third-party service providers after the 2024 Change Healthcare cyberattack.
    • “That attack, which is widely regarded as the biggest ever in the sector — including by HHS’s Charlee Hess, who spoke Thursday at CyberTalks presented by CyberScoop — began with hackers exploiting the lack of multifactor authentication set up on a remote access portal at Change Healthcare.
    • “It wasn’t a hospital, it was a company most people have never heard of and had major impacts on our sector and threatened the liquidity of our entire health care system,” said Hess, director of the healthcare and public health sector cybersecurity at the Administration for Strategy Preparedness and Response division. “We recovered from that, but we realized there are third-party risks lurking in our health care system, and we don’t even know they’re there. Where are those entities or systems that will have an outsized impact on our sector?”
  • and
    • “A top FBI cyber official said Salt Typhoon, the Chinese cyber espionage group behind the widespread compromise of U.S. telecommunications infrastructure in 2024, continues to pose a broad threat to both America’s private and public sectors.
    • “Michael Machtinger, deputy assistant director for cyber intelligence at the FBI, touted improved partnerships between the telecommunications industry and government in the wake of the campaign while speaking at CyberTalks, presented by CyberScoop, in Washington D.C. Thursday.
    • Companies who engaged with the FBI and federal agencies like CISA early after the campaign went public “have been without a doubt the most successful in mitigating the impact of the Salt Typhoon intrusions,” he claimed.”
  • and
    • “The Trump administration wants to boost the use of artificial intelligence for security in a way that doesn’t increase the number of targets for adversaries to attack, a top official with the Office of the National Cyber Director said Thursday.
    • “The administration will “promote the rapid implementation of AI enabled cyber defensive tools to detect, divert and deceive threat actors who continue targeting our vital systems and sectors,” Alexandra Seymour, principal deputy assistant cyber director for policy, said at CyberTalks, presented by CyberScoop. “We want to ensure that as Americans, companies and agencies deploy AI to defend themselves, they are not inadvertently making themselves more vulnerable by widening the attack surface.”
    • “Overall, “We’re working with our interagency and White House colleagues to promote AI-driven success while addressing concerns about AI security and countering AI abuse by adversaries,” she said.
    • “The focus on AI is expected to get further attention from a forthcoming national cyber strategy and the implementation of that strategy due to follow.”
  • Federal News Network adds,
    • “The National Institutes of Standards and Technology is launching a new project around standards for artificial intelligence agents, with NIST positioning the project as key to advancing agentic AI innovation.
    • “NIST’s Center for AI Standards and Innovation (CAISI) announced the “AI Agent Standards Initiative” this week. The project aims to foster “industry-led technical standards and protocols that build public trust in AI agents, catalyze an interoperable agent ecosystem, and diffuse their benefits to all Americans and across the world,” NIST said in a release this week.
    • “AI agents can now work autonomously for hours, write and debug code, manage emails and calendars, and shop for goods, among other emerging use cases,” NIST added. “While the productivity promise is enticing, the real-world utility of agents is constrained by their ability to interact with external systems and internal data. Absent confidence in the reliability of AI agents and interoperability among agents and digital resources, innovators may face a fragmented ecosystem and stunted adoption.”
    • While NIST’s press release positioned the project around innovation, the initiative’s opening products are centered on security. Since AI agents can take actions autonomously, tech experts say they present significant safety and security concerns.
    • “The initiative’s initial outputs includes a request for information on “AI agent security.” The deadline for responses to the RFI is March 9.”
  • Per February 19, 2026, HHS news release,
    • “[T]he U.S. Department of Health and Human Services’ (HHS) Office for Civil Rights (OCR) announced a settlement with Top of the World Ranch Treatment Center (TWRTC), a substance use disorder treatment provider in Illinois, for a potential violation of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Security Rule.” * * *
    • “The settlement resolves an investigation of TWRTC that OCR initiated after receiving a breach report that TWRTC filed in March 2023. TWRTC reported that, as a result of a successful phishing attack, an unauthorized third party accessed ePHI through a workforce member’s email account. TWRTC concluded that the ePHI for 1,980 patients was compromised by the attack. OCR’s investigation found evidence that TWRTC failed to conduct an accurate and thorough risk analysis to determine the potential risks and vulnerabilities to the confidentiality, integrity, and availability of the ePHI TWRTC holds as required by the HIPAA Security Rule.
    • “Under the terms of the resolution agreement, TWRTC agreed to implement a corrective action plan that OCR will monitor for two years, and paid $103,000 to OCR.” * * *
    • “The resolution agreement and corrective action plan may be found at: https://www.hhs.gov/sites/default/files/ocr-ra-cap-twrtc.pdf [PDF, 249 KB]
  • Cyberscoop reports,
    • “A Ukrainian national who ran multiple operations to aid the North Korean government’s expansive scheme to  hire remote IT workers at U.S. companies was sentenced to five years in prison, the Justice Department said Thursday.
    • “Oleksandr Didenko stole U.S. citizens’ identities and created more than 2,500 fraudulent accounts on freelance IT job forums, money service transmitters, email services, and social media platforms to sell the proxy identities to North Korean workers. The 29-year-old pleaded guilty to multiple crimes related to the six-year scheme in November 2025.” * * *
    • “U.S. law enforcement has racked up some wins by seizing stolen cryptocurrency and targeting U.S.-based facilitators who provide forged or stolen identities for North Korean operatives. 
    • “Yet, the regime’s scheme runs deep. North Korean nationals have infiltrated many top global companies, and researchers continue to uncover evidence of new tactics and techniques operatives have used to evade detection.”

From the cybersecurity vulnerabilities and breaches front,

  • Bleeping Computer tells us,
    • “PayPal is notifying customers of a data breach after a software error in a loan application exposed their sensitive personal information, including Social Security numbers, for nearly 6 months last year.
    • “The incident affected the PayPal Working Capital (PPWC) loan app, which provides small businesses with quick access to financing.
    • “PayPal discovered the breach on December 12, 2025, and determined that customers’ names, email addresses, phone numbers, business addresses, Social Security numbers, and dates of birth had been exposed since July 1, 2025.
    • “The financial technology company said it has reversed the code change that caused the incident, blocking attackers’ access to the data one day after discovering the breach.
    • “On December 12, 2025, PayPal identified that due to an error in its PayPal Working Capital (“PPWC”) loan application, the PII of a small number of customers was exposed to unauthorized individuals during the timeframe of July 1, 2025 to December 13, 2025,” PayPal said in breach notification letters sent to affected users.”
  • The Cybersecurity and Infrastructure Security Agency (CISA) added eight known exploited vulnerabilities to its catalog during this shutdown week.
    • February 17, 2026
      • CVE-2008-0015 Microsoft Windows Video ActiveX Control Remote Code Execution Vulnerability
      • CVE-2020-7796 
      • CVE-2024-7694 TeamT5 ThreatSonar Anti-Ransomware Unrestricted Upload of File with Dangerous Type Vulnerability
      • CVE-2026-2441 Google Chromium CSS Use-After-Free Vulnerability
        • Cybersecurity News discusses the MS Windows KVe here.
        • The Hacker News discusses the other three KVEs here.
    • February 18, 2026
      • CVE-2021-22175 GitLab Server-Side Request Forgery (SSRF) Vulnerability
      • CVE-2026-22769 Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials Vulnerability
        • DeV discusses the Gitlab KVE here.
        • Bleeping Computer discusses the Dell KVE which demands immediate attention.
    • February 20, 2026
      • CVE-2025-49113 RoundCube Webmail Deserialization of Untrusted Data Vulnerability
      • CVE-2025-68461 RoundCube Webmail Cross-site Scripting Vulnerability
        • The Hacker News discusses these KVEs here.
  • Cybersecurity Dive reports,
    • “A critical vulnerability in BeyondTrust Remote Support is facing an increase in threat activity, with hackers deploying SparkRAT and vShell backdoors and using remote management tools to conduct reconnaissance, according to a blog post released Thursday by Palo Alto Networks’ Unit 42. 
    • “Multiple BeyondTrust Remote Support users have been confirmed targets, and a range of industries have been impacted, including financial services, technology, higher education, legal services and healthcare among others. 
    • “The vulnerability, tracked as CVE-2026-1731, is an operating system command injection flaw that also impacts some older versions of BeyondTrust Privileged Remote Access. 
    • “The flaw was originally discovered by researchers at Hacktron and disclosed to BeyondTrust.”
  • Per an HHS announcement,
    • “The Department of Health and Human Services (HHS) encourages Healthcare and Public Health (HPH) sector organizations to review and address a critical vulnerability identified in BeyondTrust Remote Support and Privileged Remote Access solutions in light of rising cyber attacks affecting the sector.
    • “BeyondTrust published Security Advisory BT26-02 regarding a critical pre-authentication remote code execution vulnerability, identified as CVE-2026-1731, affecting Remote Support and older versions of Privileged Remote Access. The vulnerability carries a CVSSv4 score of 9.9 and may be triggered through specially crafted client requests, potentially allowing an unauthenticated remote attacker to execute operating system commands in the context of the site user. 
    • “The vulnerability affects Remote Support version 25.3.1 and prior and Privileged Remote Access version 24.3.4 and prior, with remediation available through specific patches or by upgrading to fixed versions. BeyondTrust issued patches on February 2, 2026, which were automatically deployed to instances with the update service enabled and fully applied to Software as a Service environments. BeyondTrust applied patches to all SaaS customers as of February 2, 2026, and instructed self-hosted customers to manually apply updates or upgrade to supported versions where necessary. For additional information, organizations are encouraged to review the BeyondTrust Security Advisory.”
  • Dark Reading relates,
    • “New data suggests a cyber espionage group is laying the groundwork for attacks against major industries.
    • “The “React2Shell” vulnerability is already almost a few months old, but it’s far from over. An unknown but possibly state-sponsored threat actor has been using a newly discovered, maturely named toolkit — “ILovePoop” — to probe tens of millions of Internet protocol (IP) addresses worldwide, looking for opportunities to exploit React2Shell. A report from WhoisXML API, shared with Dark Reading, suggests the threat actor might be out for big game: government, defense, finance, and industrial organizations, among others, around the world but particularly in the United States.
    • “A few months later, the situation has yet to calm down, Pham says. “There are still tens of thousands of vulnerable instances exposed on the internet, and additional botnets have added React2Shell to their arsenals. It has also been confirmed in ransomware campaigns,” she says. 
    • The big difference now is that the attacks have gotten more sophisticated, as the attackers have had more time to gameplan. “The post-exploitation tradecraft has gotten more sophisticated over time. We are seeing things like PeerBlight’s use of the BitTorrent DHT as a resilient C2 fallback, which is a technique designed specifically to survive traditional domain takedowns,” Phams says.” * * *
    • “Patching a deep-rooted vulnerability like React2Shell isn’t as simple as clicking an “Update” button.”
  • and
    • “When Hillai Ben Sasson and Dan Segev set out to hack AI infrastructure two years ago, they expected to find vulnerabilities — but they didn’t expect to compromise virtually every major AI platform they targeted.
    • “The two researchers — who work in offensive and defensive research, respectively, at cloud-security firm Wiz — wanted to experiment with how they could attack the AI infrastructure being deployed as part of foundational models, AI services, and in-house AI projects. Yet, what started as simple attacks on the AI supply chain — such as abusing the widely used Pickle format to run arbitrary code — evolved into a comprehensive threat assessment spanning five distinct layers of the AI stack.
    • “They plan to present the lessons learned over their two years of research at the upcoming RSAC Conference in March. Perhaps the most important lesson: Focus on the infrastructure used to to train, run, and host AI services, and not on prompt-injection attacks, says Segev, a security architect in the Office of the CTO at Wiz.”
  • and
    • “A growing phishing-as-a-service (PhaaS) tool reliably undermines traditional methods for detecting phishing attacks, both technical and psychological.
    • “Starkiller,” described this week by researchers at Abnormal AI, is packaged and sold with a sleekness comparable to legitimate software-as-a-service (SaaS) platforms. It’s got a clean, retrofuturist dashboard, sporting real-time campaign analytics. It gets periodic updates, and even allows its cybercriminal users to log in using two-factor authentication (2FA).
    • “It’s got substance to back up its style, too. Its website advertises “enterprise-grade phishing infrastructure” for “campaigns that bypass modern security systems.” Though its self-reported 99.7% success rate is almost certainly fictional, it really does help attackers bypass many of the traditional phishing security techniques so many enterprises rely on, according to Abormal AI’s research.”
  • Cybersecurity Dive notes,
    • “The vulnerability of the “connective tissue” of the AI ecosystem — the Model Context Protocol and other tools that let AI agents communicate — “has created a vast and often unmonitored attack surface” that is making it easier for hackers to use AI to launch cyberattacks, Cisco said in a report published Thursday [February 19].
    • “Cisco said AI tools’ increasing ability to “execute processes, access databases, and push code on behalf of humans” has become the dominant AI risk and warned companies not to give AI “unsupervised control over critical business functions.”
    • “The new report also described nation-state hackers’ use of AI and warned businesses about potential AI supply-chain crises.”

From the ransomware front,

  • Bleeping Computer reports,
    • “The University of Mississippi Medical Center (UMMC) closed all its clinic locations statewide on Thursday [February 19] following a ransomware attack.
    • “UMMC has over 10,000 employees and, as one of the largest employers in Mississippi, operates seven hospitals, 35 clinics, and more than 200 telehealth sites statewide. The medical center includes the state’s only children’s hospital, only Level I trauma center, only organ and bone marrow transplant program, and the only Telehealth Center of Excellence, one of two across the United States.
    • “As revealed on Thursday afternoon, the cyberattack took down many of its IT systems and blocked access to the Epic electronic medical records. While UMMC cancelled outpatient and ambulatory surgeries/procedures and imaging appointments, officials said hospital services continue via downtime procedures.”
  • The HIPAA Journal points out ransomware attacks against three other healthcare entities.
    • “Issaqueena Pediatric Dentistry in South Carolina, Enhabit Home Health & Hospice in Texas, and AltaMed Health Services in California have announced that patient data has potentially been compromised in ransomware attacks.”
  • Per an Arctic Wolf news release,
    • “Arctic Wolf®, a global leader in security operations, today [February 17] published the 2026 edition of its Threat Report, which analyzes hundreds of real‑world incident response engagements and threat intelligence findings from the past year. The report reveals a continued rise in data‑theft‑driven extortion, sustained pressure from ransomware groups, and a significant increase in attacks that leverage remote access tools rather than technical exploits.
    • “In 2025, ransomware, business email compromise (BEC), and data incidents once again dominated Arctic Wolf’s caseload, accounting for 92% of all incident response engagements. While ransomware remained the most common category, data‑only extortion incidents surged 11x year over year, signaling a strategic shift as threat actors adapt to improved organizational recovery capabilities. The report also finds that 65% of non‑BEC intrusions stemmed from abuse of remote access technologies like RDP, VPN, and RMM tools; which is a dramatic rise that underscores attackers’ preference for low‑friction entry points.
    • “Attackers continue to rely on operational efficiency – logging in instead of breaking in, stealing data instead of encrypting it, and exploiting trusted tools rather than complex vulnerabilities,” said Ismael Valenzuela, vice president, Labs, Threat Research & Intelligence, Arctic Wolf. “Organizations that invested in visibility, identity security, and disciplined remote access controls were far more resilient throughout the year.”
  • Cybersecurity Dive adds,
    • “Hackers are using ransomware to accelerate the timeline for cyberattacks, moving on average four times faster than just a year ago, according to an incident response report released Tuesday by Palo Alto Networks. 
    • “AI is being used for reconnaissance, phishing and scripting, and operational execution in many cases. In the most efficient attacks, groups exfiltrate data just 72 minutes after initial access. 
    • Identity is a primary element in attacks, showing up in 90% of incident response cases. Threat groups are increasingly using stolen identities and tokens to gain entry without triggering security warnings.  
    • “Once an attacker has legitimate credentials, they’re not breaking in, they’re logging in,” Sam Rubin, a senior vice president at Palo Alto Networks’ Unit 42, told Cybersecurity Dive. “When an adversary blends into normal traffic, detection becomes incredibly challenging for even mature defenders.”
    • “The report is based on analysis of more than 750 incident response casesacross the globe that involved Unit 42 analysts and researchers.” 
  • Qualsys assesses “What Is Black Basta Ransomware and How to Mitigate Attack.”
  • IT Brew considers how a ransomware attacker thinks.
    • “When it comes to ransomware criminals, the answers can vary. Some organizations are sophisticated businesses where hackers are treated as employees with HR departments and paid time-off, while others are more ramshackle.
    • “But they’re all dangerous—and after your data. Mike Puglia, general manager of cybersecurity labs at Kaseya, told IT Brew that financial motivation has been the constant motive of ransomware attackers. The tactics are much the same between groups: gaining access, exploiting vulnerabilities, escalating privileges, and deploying an encrypter to hold the data for payment.
    • “It’s Whac-a-Mole, or a game of cat and mouse, between defenders and attackers, and as soon as one hole is closed, suddenly the next wave comes,” Puglia said.”
  • Per an HHS announcement,
    • “The National Institute of Standards and Technology (NIST) hosted a virtual event titled Resources for Ransomware Risk Management on January 28, 2026. The event focused on ransomware as a persistent risk to organizations of all sizes and sectors and emphasized the need for cross-sector collaboration to develop practical resources for reducing ransomware risk. Speakers from NIST, the Center for Internet Security, and the Institute for Security and Technology (IST) provided an overview of available ransomware risk management resources designed to help organizations establish foundational safeguards and build effective strategies. Featured resources included the NIST Ransomware Risk Management Cybersecurity Framework 2.0 Community Profile, published as an initial public draft, and the IST and Ransomware Task Force Blueprint for Ransomware Defense, which offers an actionable framework tailored for small to medium-sized enterprises. Presenters described the development and use of these resources and discussed ongoing and future efforts in ransomware risk management, with the session allowing time for audience questions and discussion. For additional details, refer to the Ransomware Risk Management webinar.”

From the cybersecurity business and defenses front,

  • The Wall Street Journal reports,
    • Palo Alto Networks PANW lifted its full-year revenue outlook after recording a jump in second-quarter profit driven by continued demand for cybersecurity services.
    • “However, the company issued per-share earnings guidance for its current quarter below Wall Street expectations, in part as it contends with higher costs for memory and storage. It plans to raise prices later in the fiscal year to offset the increases.
    • “The stock, which has dropped 11.2% to start the year, fell 8% in late trading Tuesday to $150.46.
    • “The Santa Clara, Calif.-based company on Tuesday [February 17] said it now expects full-year revenue to come in between $11.28 billion and $11.31 billion, up from a range of $10.5 billion to $10.54 billion.
    • “The raised revenue view came after Palo Alto reported a profit of $432 million, or 61 cents a share, for its fiscal second quarter, compared with a profit of $267.3 million, or 38 cents a share the prior year.”
  • Cybersecurity Dive adds,
    • “As investors worry that existing software and services could be rendered obsolete, Palo Alto Networks CEO Nikesh Arora said the rapid acceleration of AI should not be considered a threat to cybersecurity. 
    • “Arora addressed the concerns on Tuesday during the company’s fiscal second-quarter conference call, where the surge in AI dominated much of the discussion. 
    • “As AI becomes more pervasive across the enterprise, it expands the attack surface area, more infrastructure, more machine-to-machine activity and new classes of risk that simply didn’t exist before,” Arora said. “In that environment, security cannot sit on the sidelines.”
    • “Arora said despite the current sentiment about software and AI, the company believes that security is the enabling layer “that allows innovation to move forward safely and at scale.”
  • and
    • “Businesses need to pay attention to identity security and third-party risk management to avoid falling prey to hackers whose techniques have evolved, the risk intelligence company Dataminr said in a threat report published on Wednesday [February 18].
    • “2025 marked a clear shift from ‘frequent but contained’ cyber losses toward fewer events with materially larger financial and mission impact,” the report said, attributing the shift to “multi-vector attacks” leveraging stolen credentials, data theft, operational disruptions and regulatory exposure.
    • “Dataminr’s report contains several high-priority recommendations for enterprises, including about supply chain security and the need to look beyond a vulnerability’s severity score.”
  • Dark Reading offers “A CISO’s Playbook for Defending Data Assets Against AI Scraping.”
    • “Discover a strategic approach to govern scraping risks, balance security with business growth, and safeguard intellectual capital from automated data harvesting.”
  • Cyberscoop relates,
    • “Anthropic is rolling out a new security feature for Claude Code that can scan a user’s software codebases for vulnerabilities and suggest patching solutions.
    • “The company announced Friday that Claude Code Security will initially be available to a limited number of enterprise and team customers for testing. That follows more than a year of stress-testing by the internal red teamers, competing in cybersecurity Capture the Flag contests and working with Pacific Northwest National Laboratory to refine the accuracy of the tool’s scanning features.
    • “Large language models have shown increasing promise at both code generation and cybersecurity tasks over the past two years, speeding up the software development process but also lowering the technical bar required to create new websites, apps and other digital tools.
    • “We expect that a significant share of the world’s code will be scanned by AI in the near future, given how effective models have become at finding long-hidden bugs and security issues,” the company wrote in a blog post.”
  • Tech Target shares a “CISO’s guide to demonstrating cyber resilience.”
    • “Elevating cybersecurity to a state of resilience requires a security team to adapt and strengthen defenses. The result should be that a future attack is less likely to succeed.”
  • Here is a link to Dark Reading’s CISO Corner.

Cybersecurity Saturday

From the cybersecurity policy front,

  • Per a February 11, 2026, Cybersecurity and Infrastucture Security Agency news release,
    • “The Cybersecurity and Infrastructure Security Agency (CISA) unveiled its 2025 Year in Review today, spotlighting bold achievements that strengthened the nation’s cyber and physical security in 2025. The report underscores CISA’s commitment to innovation, resilience, and collaboration. This report is a snapshot of goals achieved for this past year. Year over year CISA’s goals change as the threat landscape evolves and as we lean into core mission objectives as determined by the Administration’s policies. 
    • “The Year in Review is more than a report – it’s proof of CISA’s unwavering commitment to protecting the infrastructure and systems Americans count on every day,” said CISA Acting Director Madhu Gottumukkala. “From safeguarding federal networks to equipping communities with tools to reduce risk, our team delivered measurable results in 2025. And we’re not slowing down – we will lead with innovation, resilience and partnership to stay ahead of tomorrow’s threats.”
  • Federal News Network reports,
    • “Sen. Ron Wyden (D-Ore.) is pledging to keep his hold on the nominee to lead the Cybersecurity and Infrastructure Security Agency. Wyden said he will continue to object to Sean Plankey’s nomination until CISA releases a 2022 report on security flaws in the U.S. telecommunications system. Wyden previously held up Plankey’s nomination for much of last year over the same issue. (Sen. Ron Wyden (D-Ore.) floor remarks – Congress.gov)”
  • Cyberscoop tells us,
    • “A recent attempt at a destructive cyberattack on Poland’s power grid has prompted the Cybersecurity and Infrastructure Security Agency to publish a warning for U.S. critical infrastructure owners and operators.
    • Tuesday’s alert follows a Jan. 30 report from Poland’s Computer Emergency Response Team concluded the December attack overlapped significantly with infrastructure used by a Russian government-linked hacking group, and that it targeted 30 wind and photovoltaic farms, among others.
    • “CISA said its warning was meant to “amplify” that Polish report. In particular, CISA said the attack highlighted the threats to operational technology and industrial control systems, most commonly used in the energy and manufacturing sectors.
    • ‘And CISA’s alert continues a recent agency focus on securing edge devices like routers or firewalls, after a binding operational directive last week to federal agencies to strip unsupported products from their systems.”
  • Cybersecurity Dive relates,
    • “The Cybersecurity and Infrastructure Security Agency wants critical infrastructure partners’ feedback on the scope of its cyber-incident reporting regulation as the agency homes in on a final version of the long-awaited rule.
    • “In a notice set for publication in the Federal Register on Friday [January 13], CISA announced a series of town hall meetings where different sectors will be able to share their thoughts about the pending rule, which Congress required in the 2022 Cyber Incident Reporting for Critical Infrastructure Act.
    • A draft version of the CIRCIA rule, published in April 2024, gave covered infrastructure operators 72 hours to report substantial cyber incidents to the government. Business groups and some lawmakers objected to the scope of the information that companies would need to report, as well as to the breadth of companies covered under the regulation.
    • “In its new announcement, CISA said it “appreciates stakeholders’ interest and concern that CISA implement CIRCIA to maximize its impact on improving our nation’s cybersecurity posture while minimizing unnecessary burden to entities in critical infrastructure sectors.”
    • “The agency wants infrastructure operators to share “specific, actionable improvements” to CIRCIA that “clarify or reduce” the burden of the planned reporting requirement while still giving the government ample information about the cyber-threat landscape.”
    • The virtual town hall meeting for the Emergency Services Sector, Government Facilities Sector, Healthcare and Public Health Sector is scheduled for March 17, 2026.
  • Federal News Network reports,
    • “The Cybersecurity and Infrastructure Security Agency plans to designate 888 of its 2,341 employees as excepted during a shutdown. All of those employees would go without pay during a shutdown.
    • “A shutdown forces many of our frontline security experts and threat hunters to work without pay— even as nation-states and criminal organizations intensify efforts to exploit critical systems that Americans rely on—placing an unprecedented strain on our national defenses,” Acting CISA Director Madhu Gottumukkala toldlawmakers this week.
    • “The cyber agency’s core responsibilities include defending federal agency networks and working with critical infrastructure to strengthen their security.
    • “Gottumukkala said that a shutdown would delay the deployment of new cyber services to federal networks and the sharing of guidance with critical infrastructure partners. It would also likely delay CISA’s work to finalize a landmark cyber incident reporting rule.

From the cybersecurity vulnerabilities and breaches front,

  • CISA added eleven known exploited vulnerabilities to its catalog this week.
    • February 10, 2026
      • CVE-2026-21510 Microsoft Windows Shell Protection Mechanism Failure Vulnerability
      • CVE-2026-21513 Microsoft MSHTML Framework Security Feature Bypass Vulnerability
      • CVE-2026-21514 Microsoft Office Word Reliance on Untrusted Inputs in a Security Decision Vulnerability
      • CVE-2026-21519 Microsoft Windows Type Confusion Vulnerability
      • CVE-2026-21525 Microsoft Windows NULL Pointer Dereference Vulnerability
      • CVE-2026-21533 Windows Remote Desktop Services Elevation of Privilege Vulnerability
        • SecPod discusses these KVEs here
    • February 12, 2026
      • CVE-2024-43468 Microsoft Configuration Manager SQL Injection Vulnerability
      • CVE-2025-15556 Notepad++ Download of Code Without Integrity Check Vulnerability
      • CVE-2025-40536 SolarWinds Web Help Desk Security Control Bypass Vulnerability
      • CVE-2026-20700 Apple Multiple Buffer Overflow Vulnerability
        • Nopsec discusses the MS Configuration KVE here.
        • WNEsecurity discusses the Notepad++ KVE here.
        • Rapid7 discusses the Solarwinds KVE here.
        • Bleeping Computer discusses the Apple KVE here.
    • February 13, 2026
      • CVE-2026-1731 BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnerability
        • The Hacker News discusses this KVE here.
  • Cybersecurity Dive informs us,
    • “Security researchers warn that threat groups are exploiting critical vulnerabilities in SmarterMail, a business email and collaboration server that small to medium-sized businesses use as an alternative to Microsoft Exchange. 
    • “A China-linked threat actor, tracked as Storm 2603, has exploited an authentication bypass vulnerability tracked as CVE-2026-23760 to deploy Warlock ransomware, according to a blog released Monday by researchers at Reliaquest. 
    • “The hacker abuses legitimate administrative functions to hide its activity from security teams. It then installs a digital forensic tool called Velociraptor to maintain access in preparation for potential ransomware attacks, according to Reliaquest. 
    • “SmarterTools, the parent company behind SmarterMail, confirmed in a Feb. 3 blog post that its own network was impacted by a Jan. 29 breach.” 
  • and
    • “More than 80% of exploitation activity targeting critical vulnerabilities in Ivanti Endpoint Manager Mobile were traced to a single IP address hiding behind a bulletproof hosting infrastructure, according to a report released Tuesday by GreyNoise. 
    • Researchers warn that several of the most shared indicators of compromise linked to the current threat campaign indicate no activity linked to Ivanti EPMM. The concern is that security teams may therefore be looking for the wrong information, as current IoCs indicate scanning for Oracle WebLogic instead, according to GreyNoise researchers.”
  • Cyberscoop notes,
    • “A new report from Google found evidence that state-sponsored hacking groups have leveraged AI tool Gemini at nearly every stage of the cyber attack cycle.
    • “The research underscores how AI tools have matured in their cyber offensive capabilities, even as it doesn’t reveal novel or paradigm shifting uses of the technology.
    • J”ohn Hultquist, chief analyst at Google’s Threat Intelligence Group, told CyberScoop that many countries still appear to be experimenting with AI tools, determining where they best fit into the attack chain and provide more benefit than friction.
    • “Nobody’s got everything completely worked out,” Hultquist said. “They’re all trying to figure this out and that goes for attacks on AI, too.
    • “But the report also reveals that frontier AI models can build speed, scale and sophistication into a myriad of hacking tasks, and state-sponsored hacking groups are taking advantage.”
  • Bleeping Computer points out,
    • “Threat actors are abusing Claude artifacts and Google Ads in ClickFix campaigns that deliver infostealer malware to macOS users searching for specific queries.
    • “At least two variants of the malicious activity have been observed in the wild, and more than 10,000 users have accessed the content with dangerous instructions.
    • “A Claude artifact is content generated with Antropic’s LLM that has been made public by the author. It can be anything from instructions, guides, chunks of code, or other types of output that are isolated from the main chat and accessible to anyone via links hosted on the claude.ai domain.”
  • and
    • “A set of 30 malicious Chrome extensions that have been installed by more than 300,000 users are masquerading as AI assistants to steal credentials, email content, and browsing information.
    • “Some of the extensions are still present in the Chrome Web Store and have been installed by tens of thousands of users, while others show a small install count.
    • “Researchers at browser security platform LayerX discovered the malicious extension campaign and named it AiFrame. They found that all analyzed extensions are part of the same malicious effort as they communicate with infrastructure under a single domain, tapnetic[.]pro.”
  • and
    • “A new variation of the fake recruiter campaign from North Korean threat actors is targeting JavaScript and Python developers with cryptocurrency-related tasks.
    • “The activity has been ongoing since at least May 2025 and is characterized by modularity, which allows the threat actor to quickly resume it in case of partial compromise.
    • “The bad actor relies on packages published on the npm and PyPi registries that act as downloaders for a remote access trojan (RAT). In total, researchers found 192 malicious packages related to this campaign, which they dubbed ‘Graphalgo’.
    • “Researchers at software supply-chain security company ReversingLabs say that the threat actor creates fake companies in the blockchain and crypto-trading sectors and publishes job offerings on various platforms, like LinkedIn, Facebook, and Reddit.”
  • TechRadar advises
    • “If you’re using an older Android phone, Google has a message you probably don’t want to hear.
    • “More than 40% of Android devices worldwide no longer receive critical security updates, leaving over 1 billion phones exposed to malware and spyware attacks, according to the company.
    • “The problem isn’t a sudden flaw but a slow drift. Android adoption data shows most users are still running software versions that Google no longer fully supports. While recent confusion around Google Play system update dates has raised concerns, Google says that the issue is cosmetic.
    • “The real issue is simpler and more serious: phones running Android 12 or older are now outside the security safety net.”

From the ransomware front,

  • The HIPAA Journal reports,
    • “A new record was set for ransomware attacks last year, with disclosed ransomware attacks increasing by 49% year-over-year to a record-high of 1,174 attacks, according to Black Fog’s 2025 State of Ransomware Report. There was also a 37% year-over-year increase in undisclosed attacks, with 7,079 victims added to dark web data leak sites in 2025. The figures indicate that globally, 86% of ransomware attacks are not disclosed by victims.
    • “Data theft almost always occurs with ransomware attacks. In 2025, 96% of attacks involved data exfiltration prior to file encryption, which results in greater organizational harm. Data exfiltration has contributed to the significant increase in breach costs, as data theft results in greater reputational harm and increased regulatory exposure. In 2025, the average cost of a data breach was $4.44 million globally, and $7.42 million for healthcare data breaches. Healthcare retained its position as the sector most targeted by ransomware groups in 2025, accounting for 22% of disclosed attacks. All sectors experienced an increase in attacks in 2025, apart from education, which saw a 13% year-over-year decrease in attacks.
    • “The breakup of large ransomware groups has led to a fragmentation of the ransomware ecosystem, and the number of active ransomware groups continued to increase in 2025. Black Fog tracked 130 different ransomware groups in 2025, of which 52 were new groups that emerged in 2025, a 9% increase from 2024. Several groups that emerged in 2025 have disproportionately targeted the healthcare sector, including Sinobi, Insomnia, and Devman. Devman issued the largest ever ransom demand of $91 million in 2025 for its attack on China’s real estate development company Shimao Group Holdings. World Leaks, widely believed to be a rebrand of Hunters International, has also claimed several healthcare victims, as have all of the top three most prolific and dangerous ransomware groups of the year: Qilin, Akira & Play.”
  • Cybersecurity Dive adds,
    • “Ransomware attacks on the IT sector were higher in each quarter of 2025 than in the same quarters of 2024, with the sector ranking third behind manufacturing and commercial facilities on hackers’ target lists, according to a new report from the Information Technology Information Sharing and Analysis Center.
    • “Nearly half of all ransomware attacks that the IT-ISAC tracked occurred in the U.S., far surpassing the totals in other countries.
    • “The food and agriculture sector also saw a significantly higher number of ransomware attacks in 2025 than it did in 2024, according to a new report from that sector’s ISAC, which shares leadership with the IT-ISAC.”
  • The Federal Trade Commission has issued its own 2025 ransomware report according to Executivegov.
    • “The Federal Trade Commission has reported that ransomware and other malware-based attacks represent only 2.23 percent of all fraud complaints submitted to the agency.
    • “In the 2025 Ransomware Report published Friday, the FTC shared that, between July 2023 and June 2025, tech support scams were among the most reported fraud types.
    • “About 1 percent of the 42,972 reports the FTC received that allegedly originate from China are ransomware. The majority of the complaints are related to online shopping fraud.
    • “Complaints tied to Russia, Iran and North Korea are relatively rare, with the three countries accounting for only 0.05 percent of all fraud reports the FTC received from 2023 to 2025.”
  • Morphisec calls attention to
    • “Ransomware isn’t slowing down. It’s scaling, adapting, and finding new ways to slip past defenses that many organizations still trust implicitly.  
    • “The Ransomware Reality Check 2026 infographic paints a clear, data-driven picture of the risk landscape ahead: from skyrocketing demands to sophisticated execution methods that beat traditional detection technologies.”  
  • Per Security Week,
    • “Mere data exfiltration is no longer a lucrative approach for ransomware groups, and threat actors may increasingly rely on encryption to regain leverage, Coveware notes in a new report.
    • “Following a series of highly successful data-exfiltration-only attacks conducted by known groups such as Cl0p, other ransomware groups adopted the trend, stealing victims’ data without encrypting it.
    • “The campaigns targeting MOVEitCleo, and Oracle E-Business Suite (EBS) customers are proof that the approach no longer delivers return on investment, Coveware says.
    • Cl0p, it explains, started this trend with a simple strategy: it acquired an exploit for a zero-day vulnerability in a popular enterprise file transfer or data storage product, hacked as many instances as possible for data exfiltration, and extorted each compromised entity into paying a ransom.
    • I”n 2021, the group likely made tens of millions of dollars using this tactic in the Accellion campaign, when over 25% of the impacted organizations likely paid a ransom. Roughly 20% of the entities impacted by the GoAnywhere MFT hack also paid a ransom.
    • “In the subsequent campaigns, however, the victims’ willingness to pay dropped significantly: less than 2.5% of those affected by the MOVEit breach paid, and almost none paid in the Cleo and Oracle EBS incidents, Coveware says in its latest ransomware trends report.”
  • Per Cyberscoop,
    • “Ransomware groups crop up like weeds, angling for striking positions in a crowded field rife with turnover, infighting and unbridled competition. Yet, they rarely emerge, as 0APT did late last month, claiming roughly 200 victims out of the gate.
    • “Researchers have thus far seen no evidence confirming 0APT attacked any of its alleged victims, which includes high-profile organizations. Alleged victim data samples and the structure and size of placeholder file trees published by 0APT place further doubt on the group’s supposed criminal escapades. 
    • “Most signs suggest the group is running a massive hoax, but at least some of the threat 0APT poses is grounded in truth. The group’s inflated pretense may be a ruse to create a sense of momentum, gain recognition and attract affiliates.
    • “While 0APT is probably bluffing about the victims it has already compromised, it is not bluffing on the technical capabilities of its actual ransomware,” Cynthia Kaiser, senior vice president at Halcyon’s ransomware research center, told CyberScoop.”

From the cybersecurity business and defenses front,

  • The Wall Street Journal reports,
    • The European Union approved Google’s $32 billion acquisition of cybersecurity startup Wiz, a win for the Alphabet unit’s GOOGL  * * *
    • “Google announced the all-cash deal in March 2025, betting that bringing Wiz under its cloud business would help it fast-track improvements in cloud security and enhance its ability to use multiple clouds, both trends that have gathered pace in the artificial-intelligence era.
    • “Wiz provides cybersecurity software for cloud computing and has presences in New York; Arlington, Virginia; London and Tel Aviv.
    • “The deal—cleared by U.S. antitrust authorities in November last year—was flagged to the EU’s merger watchdog for screening in January.”
  • Cyberscoop relates,
    • “Proofpoint announced Thursday [February 12] it has acquired Acuvity, an AI security startup, as the cybersecurity company moves to address security risks stemming from widespread corporate adoption of agentic AI.
    • “The acquisition strengthens Proofpoint‘s capabilities in monitoring and securing AI-powered systems that are increasingly handling sensitive business functions across enterprises. 
    • “Financial terms of the deal were not disclosed, but Ryan Kalember, Proofpoint’s chief strategy officer, told CyberScoop that the acquisition was beyond a pure “technology acquisition,” with Acuvity’s engineering team slated to join the California-based company. 
    • “Acuvity specializes in visibility and governance for AI applications, including the ability to track how employees and automated systems interact with external AI services and protect custom AI models developed within organizations. The startup’s platform monitors AI usage across multiple deployments, from web browsers to specialized infrastructure including Model Context Protocol (MCP) servers and locally installed AI tools.”
  • Per a February 13 CISA news release,
    • “For years, CISA has responded to an unending wave of cyber incidents targeting edge devices embedded in the Nation’s federal networks and critical infrastructure. The common culprit? 
      • Unsupported hardware and software residing on the edge of organizational networks that vendors are no longer maintaining.
    • Nation-state adversaries have seized these weak points, exploiting them to gain unauthorized access, maintain persistence, and compromise sensitive data. These neglected devices are more than just vulnerabilities; they threaten the Nation’s security, privacy, and resilience. 
    • As the operational lead for federal cybersecurity, CISA recently took a large step toward addressing this systemic risk by issuing Binding Operational Directive (BOD) 26-02, a mandate for federal civilian agencies to identify and replace end-of-support (EOS) edge devices, stay current with software updates, and patch known vulnerabilities. While directed to federal agencies, we strongly encourage all organizations to adopt similar actions. 
    • However, we as a community can and must do more. Managing the lifecycles of hardware and software products can quickly become a daunting, resource-intensive task—especially without an efficient way to determine the EOS status for hardware and software. 
    • Enter OpenEoX: a machine-readable, international standard that transforms how product lifecycle information is exchanged across software, hardware, services, and AI models. By introducing much-needed standardization and automation, OpenEoX brings transparency, efficiency, and unity to asset management. By integrating OpenEoX across the community, both hardware and software producers and consumers can together turn the tide on one of the most serious cyber threats facing the Nation: EOS hardware and software.” * * *
    • Additional Resources
  • Meritalk relates,
    • The FBI Cyber Division’s latest initiative, Operation Winter SHIELD, is growing as more field offices join the cybersecurity defense campaign that aims to turn lessons from investigations into high-impact actions that organizations can take to strengthen their defenses. 
    • The bureau launched Operation Winter SHIELD on Jan. 28 as a two-month effort that spotlights one of 10 “high-impact actions” each week. The initiative is designed to help organizations reduce common breach pathways and harden critical infrastructure systems against nation-state and criminal cyber threats. 
    • Since its announcement, numerous FBI field offices across the nation have voiced their support for the operation – some of the latest field offices to join this week include SeattlePhiladelphia, and Anchorage
    • In a video announcement, FBI Cyber Division Assistant Director Brett Leatherman said the campaign distills insights from real-world investigations into practical steps that organizations can take immediately. 
    • “Every winter storms test our infrastructure. Power grids, water systems, and supply chains are pushed to their limits, but the most critical threats to infrastructure don’t come from the weather. They come through our networks,” Leatherman said. 
      • The 10 actions outlined by the FBI include: 
      • Adopt phish-resistant authentication 
      • Implement a risk-based vulnerability management program 
      • Track and retire end-of-life technology on a defined schedule 
      • Manage third-party risk 
      • Protect security logs and preserve them for an appropriate time period 
      • Maintain offline immutable backups and test restoration 
      • Identify, inventory, and protect internet-facing systems and services 
      • Strengthen email authentication and malicious content protections 
      • Reduce administrator privileges 
      • Exercise your incident response plan with all stakeholders 
  • Per Dark Reading,
    • “Microsoft Under Pressure to Bolster Defenses for BYOVD Attacks
    • “Threat actors are exploiting security gaps to weaponize Windows drivers and terminate security processes in targeted networks, and there may be no easy fixes in sight.”
  • Here is a link to Dark Reading’s CISO Corner.