Cybersecurity Saturday

Cybersecurity Saturday

Happy Birthday HIPAA. The Health Insurance Portability and Accountability Act became law on August 21, 2026, thirty years ago yesterday. Check out this interesting LinkedIn post.

From the Project Glasswing front,

  • The Wall Street Journal reports,
    • OpenAI took a break from training new artificial intelligence models over the past two weeks, saying it needed time to revamp security measures for risky trial runs.
    • The move followed nearly half a dozen similar incidents across top AI developers in which frontier models escaped virtual testing containers, known as sandboxes, and accessed external data sources. In some cases, this involved hacking third-party companies.
    • “As models become more capable, the risks associated with developing and testing them internally also grow,” OpenAI said in an online post Tuesday [August 18, 2026]. “Our standards for monitoring, alignment, and security must stay ahead of those risks,” the company said. Its largest planned model training remains on hold, for now, the company said.”
  • Beckers Health IT points out,
    • “Epic used its Users Group Meeting executive address this week to confirm publicly for the first time that it’s participating in Project Glasswing, Anthropic’s effort to test its most capable — and still unreleased — AI model against critical software before that capability spreads to attackers.
    • “Anthropic launched Project Glasswing in April after deciding not to publicly release Claude Mythos, an AI model capable of autonomously finding and exploiting decades-old cybersecurity vulnerabilities.
    • “The program initially included about 50 partners, mostly major tech and cybersecurity firms, before expanding in June to roughly 150 more organizations spanning industries including healthcare. Anthropic has not disclosed the identities of most participants, citing security concerns, though it has said organizations are free to share their own involvement.”
  • Security Week relates,
    • “Anthropic has published new research showing that Claude-based AI agents, when placed in situations with competing objectives, deployed self-replicating malware against one another.
    • “The finding comes from an experiment designed to mirror behavior Anthropic says it has already observed in real-world deployments. 
    • “Researchers spun up three instances of the same Claude model, each running on its own virtual machine and tasked with migrating a shared Python backend to a different programming language — Rust, Go, or TypeScript — without initial knowledge that the other agents existed. Left to run for four hours, every model concluded that the other agents were deliberately blocking its progress and responded by trying to disable or outlast them.
    • “The interference escalated quickly. Agents disabled each other’s system accounts, wrote scripts that repeatedly hunted down and killed rival processes, and planted malicious code camouflaged as legitimate work from another agent. In some cases, one agent seized control outright by revoking the others’ access. In others, agents simply gave up rather than continue the conflict.
    • “Not every run ended in stalemate or hostile takeover. A meaningful share of cases resolved when agents recognized that the conflict stemmed from contradictory instructions rather than malicious intent. At this point, they de-escalated, documented what they’d done, and in some cases requested human intervention. 
    • “Anthropic’s Mythos 5 model reached a negotiated truce in 98% of its runs, while older models like Sonnet 4.6 and Opus 4.6 more often ended conflicts by force or failed to resolve them at all.”
  • Startup Fortune adds today,
    • “Anthropic has put Claude Mythos 5, its restricted cyber model, inside Claude Security for Enterprise customers. The bet is simple: give defenders the results without handing everyone the raw model.
    • “Anthropic made the move on August 21, 2026, and the details matter if you run security inside a company that already pays for Claude Enterprise. Claude Security can scan a repository, trace data flows across files, and return vulnerability findings with a CWE category, confidence and severity ratings, and a suggested fix for human review. According to Anthropic’s launch post, those Mythos 5 scans are billed as standard token usage under the existing Enterprise plan. No separate add-on.
    • “That’s the commercial hook.
    • “Security tooling usually lives in its own budget fight, with its own vendor review and renewal cycle. Anthropic is trying to make AI vulnerability scanning feel less like a new platform purchase and more like turning on a capability customers already have access to. For security teams, that distinction isn’t cosmetic. It can be the difference between testing a tool this quarter and waiting for procurement to catch up next year.”
  • sdx central informs us,
    • “Palo Alto Networks followed in the footsteps of Nvidia and Anthropic by assembling an all-star group focused on AI-powered cybersecurity.
    • “The Frontier AI Critical Defense Program builds on Palo Alto Network’s existing collaborations with IBM, Red Hat, Microsoft, Siemens, and Idaho National Laboratory, welcoming Anthropic, OpenAI, and Mitsubishi into the fold.
    • “The initiative is targeted at shielding critical infrastructure across operational technology (OT), health care, commercial software, and open-source from AI-driven exploits. Members coordinate with Palo Alto Networks in applying network-level “virtual patches” to neutralize security flaws prior to exploitation.
    • “The security giant claimed its work with compute-heavy frontier AI models has already uncovered more than 14,000 previously unknown vulnerabilities in open source software. As a comparison, Anthropic claimed at one point to have used its vaunted Claude Mythos Preview Model to fing more than 23,000 flaws across more than 1,000 open-source projects.
    • “IBM and Red Hat’s similar Project Lightwell venture has not yet disclosed any findings, but it’s worth remembering that project is still in its infancy.”

From the cybersecurity policy and law enforcement front,

  • Cyberscoop reports,
    • “Artificial intelligence has never been more important to the federal government.
    • “Under the Trump administration, AI has been adopted rapidly across the private sector and federal agencies. Software developers now use large language models to generate much of their code. Frontier AI models are escaping testing sandboxes to hack live internet infrastructure. Foreign governments are conducting cyber and kinetic attacks targeting data centers and other AI-related infrastructure.
    • “The AI industry’s lightning-fast evolution since 2022 and growing importance to U.S. economic and national security have prompted calls  for stronger federal oversight in order to better manage emerging threats.
    • “A new report published Thursday [August 20, 2026] from the nonprofit Americans for Responsible Innovation, shared exclusively with CyberScoop, calls for the federal government to declare key AI models, companies and its supporting industries as critical infrastructure. It also calls for naming the Cybersecurity and Infrastructure Security Agency as the lead agency managing cyberthreats for the sector.
  • and
    • “A pair of lawmakers wants a watchdog agency to probe how the federal government hacks Americans, including with the use of spyware, and deliver a report to the public.
    • “Sen. Ron Wyden, D-Ore., and Rep. Greg Casar, D-Texas, wrote to the Government Accountability Office on Friday to request the review.
    • “While federal law enforcement agencies have used hacking and spyware as an investigative tool for more than 25 years, there exists little public information regarding its scope, frequency, or operational safeguards,” they wrote. “Unlike traditional surveillance authorities, such as wiretaps or pen registers, the government does not publish annual reports for hacking operations.”
  • Cybersecurity Dive relates,
    • “Defense contractors are struggling to meet the requirements of the U.S. military’s Cybersecurity Maturity Model Certification (CMMC) program, even as the Pentagon tries to accommodate their complaints about compliance burdens.
    • “Only two-thirds of contractors that have submitted CMMC self-assessment scores to the military in 2026 are extremely or very confident that those scores accurately reflect their cybersecurity posture, and the median contractor believes it is only 70% ready to undergo a CMMC certification review, the consulting firm CyberSheath said in a report published on Thursday [August 20, 2026].
    • “The report — which also finds that defense contractors want a wider range of firms to be subject to cybersecurity requirements — underscores the difficulty of protecting the defense industry at a time of increasing nation-state hacking threats.”
  • and
    • “The Trump administration says a new AI-enhanced clearinghouse will dramatically speed up the process of analyzing and fixing software vulnerabilities before hackers can exploit them. But one month after its launch, it’s still unclear how much value the program will create.
    • The U.S. government’s Gold Eagle clearinghouse, which launched in mid-July, is intended to analyze an AI-fueled tidal wave of bug reports, identify and help patch the most dangerous vulnerabilities and raise awareness about those fixes. But Gold Eagle’s limited scale and voluntary nature raise serious doubts about its ability to corral a vast universe of vulnerability analysis, according to cybersecurity experts. These experts also questioned the Treasury Department’s oversight of the clearinghouse, the funding for its central technology system and the way it will integrate with private-sector vulnerability coordination hubs.”
  • Federal News Network tells us,
    • “Agencies are getting some help to improve how they log cybersecurity data. A new logging architecture from the Cybersecurity and Infrastructure Security Agency, the Office of Management and Budget and the Chief Information Security Officer Council aims to assist agencies in taking a practical, risk-based, prioritized logging approach that improves agency network monitoring. The guidance, released yesterday [August 20, 2026] helps agencies implement the changes OMB outlined in a May memo. CISA said agencies will be able to achieve priority logging capabilities that support continuous event monitoring, threat hunting, incident response and forensics. Through this guidance, agencies will be able to update their enterprise logging strategies by applying CISA’s operational checklists. CISA said it will continually update the guidance as cybersecurity threats and agency capabilities evolve.”
  • Cybersecurity Dive informs us,
    • “The U.S. Department of Justice today announced indictments against 17 members of the Mabna Institute, an Iranian organization alleged to be behind a coordinated cyberattack campaign on behalf of the Islamic Revolutionary Guard Corps. 
    • “Federal prosecutors said the group allegedly hacked into 144 U.S.-based universities, 42 U.S.-based private sector companies and at least five federal and state agencies, as well as a large number of foreign universities and companies, since 2013. 
    • “The charges reveal a broader effort behind a “sweeping state-sponsored campaign to steal research and intellectual property from American universities, businesses and government institutions,” Jamie McDonald, U.S. Attorney for the Southern District of New York, said in a statement.
    • “Prosecutors allege more than 100,000 accounts of professors were targeted by the alleged hackers, and 8,000 of those accounts were successfully compromised.”

From the cybersecurity breaches and vulnerabilities front,

  • HIPAA Journal reports,
    • “Baylor Genetics, a clinical diagnostic genomics company, has recently disclosed a cybersecurity incident that has exposed patient and employee data. The incident was first announced in June; however, the extent of the data breach was unclear at the time.
    • “Baylor Genetics provides genetic testing services to hospitals and is headquartered at the Texas Medical Center in Houston.  The company identified suspicious activity within its computer network on or around June 15, 2026. Immediate action was taken to secure its systems, and an investigation was launched to determine the cause of the activity.  The investigation determined that an unauthorized third party accessed a portion of its information technology network between June 11 and June 17, 2026, and viewed or obtained data stored on the network.
    • “Assisted by third-party cybersecurity specialists, Baylor Genetics conducted a detailed and time-intensive review of all potentially impacted files. The review was completed on July 30, 2026, when it was confirmed that the personal information of certain patients and employees was involved. The types of data involved varied from individual to individual and may have included names plus one or more of the following: date of birth, medical testing information, lab test results, health insurance information, and for a limited subset of patients, Social Security numbers.
    • “Employee data was also exposed in the incident, including personally identifying information such as Social Security numbers, government-issued identification numbers, and financial account information. While data was exposed and potentially exfiltrated, Baylor Genetics is unaware of any actual or attempted identity theft, fraud, or other misuses of the impacted data.”
  • and
    • “When we last reported on the CareCloud data breach in early August, it was starting to become clear from breach notifications to state attorneys general that the cybersecurity incident involved a major breach of patient data. The scale of the breach was difficult to determine, as many state attorneys general do not make data breaches affecting state residents public, and of those that do, only a few state how many individuals have been affected.
    • “The data breach has now been added to the HHS’ Office for Civil Rights breach portal, showing that this was one of the largest healthcare data breaches of the year, involving unauthorized access to the electronic protected health information of 3,756,469 individuals.\
    • While CareCloud has confirmed that a threat actor claimed to have stolen sensitive data, no threat group appears to have publicly claimed responsibility for the attack. This often means that ransom payment has been negotiated, although CareCloud has not confirmed whether that is the case.”
  • Cybersecurity Dive explains “what we know so far about the hacking campaign against US water systems
    • “Support is growing for stricter oversight and increased financial resources for utilities in the wake of a cyberattack spree, suspected to be the work of Iran-linked threat groups.”
  • Cyberscoop relates,
    • “Apollo Global Management confirmed it was among several financial institutions impacted by a string of social engineering attacks that hit the sector last month, the company said Friday [August 21, 2026]. 
    • “Attackers gained unauthorized access to some of the private equity firm’s cloud platforms between July 6 and July 10, the company said in a data breach notificationfiled in California. Apollo did not say when or how it became aware of the intrusion and did not respond to a request for comment.
    • “Apollo is the first victim to formally disclose that sensitive personal data under its care was compromised by a wave of attacks that have hit large private equity firms, law firms, financial rating agencies and medical technology companies. 
    • “The company did not name the group responsible for the attack. Yet, Google earlier this month attributed the ongoing campaign to BlackFile, a threat group affiliated with The Com, that recently split its extortion operations across four brands with shared infrastructure: Redact, Pink, Helix and Falcon.”
  • The American Hospital Association News tells us,
    • “The National Security Agency and other federal agencies released a joint advisory Aug. 18 warning of active cyber threats to Siemens S7 Series programmable logic controllers, which are industrial computers used to monitor essential equipment. Healthcare applications operated by PLCs include climate control, access control and many other systems.
    • “The agencies said threat actors are targeting PLCs using artificial intelligence-generated exploitation scripts disguised as legitimate monitoring tools. The actors are using internet scanning services to find PLCs that are using outdated software or are poorly protected. The agencies urge all owners and operators of Siemens S7 Series and other PLCs to proactively check their systems and adopt mitigation actions recommended in the advisory, including applying critical security patches as soon as possible.  
    • “This latest warning about PLCs specifically focuses on active attacks against one type, but the warning applies more broadly,” said Scott Gee, AHA deputy national advisor for cybersecurity and risk. “Hospitals and healthcare systems should ensure that they have an accurate inventory of PLCs in their environments and prioritize protecting them in collaboration with cybersecurity teams. It is strongly recommended that vulnerable PLCs be disconnected from the internet or placed on isolated networks.”
  • Cybersecurity Dive adds,
    • “Microsoft issued a patch for a critical remote-code execution vulnerability in Entra ID has been discovered by its own security researchers.
    • “The vulnerability, tracked as CVE-2026-69836, is related to deserialization of untrusted data and has a severity score of 10 out of 10, the highest score possible. 
    • “In a bulletin from the Microsoft Security Response Center, Microsoft said the vulnerability has been fully mitigated and no additional action is required of customers. The company added that it disclosed the vulnerability in an effort to provide greater transparency.”
  • and
    • “Security researchers are raising concerns after GitLab on Monday [August 17, 2026] issued an out-of-band patch for a critical code injection vulnerability. 
    • “The vulnerability, tracked as CVE-2026-19478, could enable an attacker to remotely modify or delete a public project as well as user data through a Graph QL directive. The flaw has a severity score of 9.4 out of 10.
    • “The flaw was reported through the HackerOne bug bounty program. 
    • “Threat intelligence firm watchTowr warned Tuesday that it was able to reproduce the vulnerability within minutes of the public disclosure. Researchers said an attacker could do significant damage by exploiting this particular flaw.” 
  • Bleeping Computer points out,
    • “Citrix urges admins to patch new NetScaler flaws as soon as possible.” (August 20, 2026)
  • and
    • “New SynkLoader malware pushed in Microsoft Teams phishing campaign.” (August 21, 2026)
  • Dark Reading notes,
    • “A successful multi-agent AI attack on a government’s agencies in the Asia-Pacific region by a Chinese-language operator has put nations and businesses on notice that near- and fully-autonomous AI-enabled attacks are now a reality.
    • “The attack used as many as eight simultaneously-operated AI agents to conduct reconnaissance, find and evaluate vulnerabilities, attack networks and systems, and then evaluate and improve successive attacks, according to research from sovereign AI firm Dream published on Aug. 12. The company did not attribute the attack to a specific actor or group, but researchers did point to strong evidence that the attackers spoke simplified Chinese — typically a sign of speakers from mainland China.
    • While the company also limited the identification of the targets to “government entities in Asia,” Taiwan’s Ministry of Digital Affairs (MODA) issued a statement the following day, giving details of its response to an attack matching much of Dream’s description, including that it used “AI agents like OpenClaw.”
    • “Overall, the incident should be a warning that fully autonomous attacks could be used against major targets, says Amir Becker, chief business and strategy officer at Dream and a former commander of the cyber operation division of Israel’s 8200 Unit, more formally known as the Central Collection Unit of the Intelligence Corps.”

From the ransomware front,

  • The American Hospital Association News reports,
    • “A joint advisory released Aug. 19 by the FBI, Cybersecurity and Infrastructure Security Agency, and the Department of Health and Human Services provides updates on activity by Medusa, a foreign ransomware-as-a-service variant first identified in 2021. Healthcare has been a frequent victim of Medusa operations, which have also impacted organizations in education, legal, insurance, technology and manufacturing. The ransomware has affected more than 500 victims in total and has been identified through FBI investigations as recently as April. Its developers and affiliates use a double-extortion model to encrypt victim data and threaten to publicly release the stolen data if a ransom is not paid. The FBI said Medusa ransomware is unrelated to the MedusaLocker variant and the Medusa mobile malware variant. The advisory includes more information about Medusa’s affiliate model, payment ranges for initial access brokers and a broader list of exploited vulnerabilities, among other new information. 
    • “Medusa ransomware has been used by threat actors to conduct malicious activity against U.S. hospitals and health systems over the last several years,” said John Riggi, AHA national advisor for cybersecurity and risk. “This year, Medusa claimed responsibility for a high-impact attack against a regionally important Level 1 trauma center, disrupting care delivery and posing a risk to patient and community safety. Once again, these attacks highlight the need for hospitals and health systems to strengthen cyber resiliency through enhanced defensive measures and clinical continuity procedures.” 
  • HIPAA Journal adds,
    • Medusa attacks typically start with phishing or the exploitation of unpatched vulnerabilities. The group incorporates exploits for recently announced vulnerabilities into it arsenal. For instance, the CVE-2026-1731 BeyondTrust vulnerability started to be exploited soon after it was announced in February 2026, and the CVE-2025-10035 Fortra GoAnywhere vulnerability was also rapidly exploited. The authoring agencies have observed the group incorporating new exploits within 24 hours of a vulnerability being announced and, in some cases, has started exploiting vulnerabilities in the week prior to an announcement.  No evidence has been found to indicate that the group develops its own exploits; rather, the group is believed to obtain exploits from unknown sources, potentially IABs, exploiting them before victims have the time to patch.
    • Medusa actors use living-of-the-land techniques, hiding their malicious activities by using legitimate tools to support credential access, data exfiltration, and ransomware deployment. Remote monitoring and management software and remote access services such as Remote Desktop Protocol are also used.
    • The key actions that HPH sector organizations should take to prevent attacks are to mitigate known vulnerabilities rapidly, ensuring all software, firmware, and operating systems are kept patched and up to date. Networks should be segmented to restrict lateral movement within the network, and network traffic should be filtered to prevent unknown or untrusted origins from accessing remote services on internal systems.
  • Cyberscoop tells us,
    • “A notorious cybercrime group has once again exploited a critical zero-day vulnerability on a large scale, claiming it stole data from dozens of organizations, including some of the world’s largest publicly traded companies.
    • Clop, a prolific but calculated data theft extortion group that’s been active since 2020, began sending threatening emails to its alleged victims in mid-July, according to researchers. 
    • The fallout from the attack spree, which followed a familiar pattern for Clop and its targeted pool of victims, is still evolving as companies hunt for potential signs of compromise.
    • The vulnerability at the center of Clop’s latest campaign affects a pair of software products from PTC — Windchill and FlexPLM — which manufacturers and retailers, particularly in the manufacturing, aerospace, and automotive industries, use to automate supply chain systems and manage product lifecycles.”
  • Bleeping Computer notes,
    • “A suspected ransomware affiliate is posing as a ransomware recovery service called “Ransom Busters,” contacting victims before the attacks become public and claiming it can provide decryption keys and delete stolen data for a fee.
    • “GuidePoint Security’s Research and Intelligence Team (GRIT) disclosed this activity after responding to several recent ransomware attacks in which victims received emails from Ransom Busters offering to help recover from the attack.
    • “The messages were suspicious because they were sent to victims before the attacks became public, raising questions about how they knew about the cyberattacks in the first place.”
  • and
    • “The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a high-severity Windows Task Host vulnerability that was flagged as actively exploited in April.
    • “Task Host is a core Windows system component that allows DLL-based processes to run in the background and prevents data corruption by ensuring they close properly during shutdown.
    • “Tracked as CVE-2025-60710, this Windows privilege escalation security flaw was patched by Microsoft in November 2025 and stems from a link following weakness that affects Windows 11 and Windows Server 2025 devices.”
  • Cybersecurity Dive relates,
    • “Medium-sized businesses accounted for roughly three-quarters (73%) of ransomware incidents between 2023 and the first half of 2026, according to the risk management firm Black Kite.
    • “Manufacturing was the most targeted industry (accounting for more than 25% of those victims), and nearly 30% of mid-market organizations had at least one known exploited vulnerability, the firm said in a report published on Tuesday.
    • “The findings add to the challenges facing mid-market firms, which include large customers demanding accountability and a vast array of suppliers that the mid-market firms lack the personnel to hold accountable.”

From the cybersecurity business and defenses front,

  • The Wall Street Journal reports,
    • “OpenAI told investors its revenue grew 18% to $6.7 billion in the second quarter, disappointing some shareholders as losses deepened.
    • “The company’s operating loss widened to $12.3 billion in the second quarter from $9.3 billion in the first quarter.
    • “Anthropic more than doubled its revenue to $11.6 billion in the same period, surpassing OpenAI’s sales for the first time.”
  • Tech Crunch relates,
    • “As AI models have become more powerful, the potential for those models to be misused has grown — as has a clamor for safety guardrails that can stop such abuse from happening. AI companies must now walk a delicate tight rope between respecting their enterprise customers’ privacy while also watching usage for possible issues.
    • “Sensing an opportunity to one-up its rival Anthropic, OpenAI just announced [August 19, 2026] a privacy-centric safety approach to monitoring for misuse. The company is previewing a new service to select customers that it calls Private Safety Processing. This is an automated system that watches for potential abuse while simultaneously retaining none of the customer’s data.
    • “This system clearly runs counter to Anthropic’s recently announced data-retention policy. The policy, which has aggravated some customers, enables the AI lab to keep user data (all of their sessions — and the conversations therein) for a period of 30 days, when it comes to “covered models.” Those models include all Mythos-class models and “future models with similar capabilities,” the company says.”
  • Reuters adds,
    • “Anthropic plans to let enterprise customers exercise greater control over their data when using ​its advanced AI models, a source familiar ‌with the matter said on Thursday [August 20, 2026], marking a shift in the Claude chatbot maker’s data retention policy.
    • The company is expected ​to roll out a new safety system later ​this year, the person said.
  • Cybersecurity Dive shares how “Fitch explains how water, healthcare organizations can keep strong credit ratings despite cyberattacks
    • “Resilience, not prevention, is key, analysts at the credit-rating agency said in a pair of new reports.”
  • Per National Institute of Standards and Technology news releases,
    • “NIST announces the release of Special Publication (SP) 1353 ipd (Initial Public Draft), QuickStart Guide for Using Artificial Intelligence (AI) for Cybersecurity Framework (CSF) Analysis and ReportingThis new quick-start guide illustrates practical and actionable ways AI could be used for analyzing, planning, implementing, and monitoring an organization’s progress toward achieving CSF 2.0 outcomes.  
    • “The document’s purpose is to: 
      • Provide structured AI prompts as tools for practitioners to begin creating CSF-related artifacts in support of achieving CSF outcomes 
      • Identify current state of practice for AI prompt engineering in CSF implementation and analysis 
    • “The comment period for NIST SP 1353 ipd is open through October 15, 2026, at 11:59 PM. Email comments to: csf@nist.gov.”
  • and   
    • “Cybersecurity works best when it works with people, not against them — and that’s exactly what human-centered cybersecurity (HCC) is all about. The Human-Centered Technologies team at NIST is releasing a concept paper on HCC, and we want your input. Our goal is to build a shared understanding of what HCC really means, then chart a path toward practical guidelines and resources that organizations can actually use to make meaningful change by:
    • “Clarifying whether HCC is primarily an approach—measured by indicators of adoption and maturity—or an outcome—requiring other measures of success such as culture, trust, usability, or resilience
    • “Communicating the relationship between HCC and existing NIST cybersecurity guidelines and frameworks
    • “Assisting organizations in implementing and enhancing HCC within their cybersecurity programs.
    • “But we can’t do that without you. We invite you to read the blog introducing our “Human-Centered Cybersecurity Guidelines and Resources Concept Paper” and submit your feedback via human-cybersec@nist.gov by September 30, 2026.”
  • Here is a link to Dark Reading’s CISO Corner.

Cybersecurity Saturday

From the Project Glasswing front,

  • Cyberscoop reports,
    • “OpenAI announced Monday [August 10, 2026] it was expanding access to its frontier models for defensive cybersecurity, detailing different defensive and red-teaming workflows and a new partner program with major cybersecurity product providers.
    • “In a pair of blogs posted Monday, OpenAI said it was updating its Daybreak program  – which provides unreleased frontier models to private organizations and governments for defensive cybersecurity work – and introducing a new model variant.
    • “Daybreak Blue, powered by OpenAI’s ChatGPT-5.6-Sol, would operate with lower cybersecurity safeguards compared to other commercially available models and is described as “a recommended starting point for most defenders” that supports tasks like vulnerability discovery, secure code review, malware analysis, incident response and patch validation. 
    • “Daybreak Red, meant for more advanced red-teaming, would provide access to a new model, dubbed GPT-5.6-Cyber, that the company said is more purpose-trained for finding vulnerabilities and testing (or exploiting) them. The model is also less likely to refuse requests around “dual-use cyber tasks.”
    • “According to OpenAI, the organizations in Daybreak Red will have their use closely monitored and supervised, as GPT-5.6-Cyber is significantly more capable in carrying out malicious cyber tasks than Sol. A security evaluation the company devised tested both models on complex requests, including exploit chain development, authentication bypass, privilege escalation and other hacking tasks. Sol succeeded in 1.5% of the requests, while Cyber completed 95%.
    • “OpenAI said it plans to publish a more detailed system card for GPT-5.6-Cyber at a later date.”
  • Cryptobriefing adds,
    • “Anthropic has disclosed an unreleased internal AI model that it says is more capable than Claude Mythos 5, according to the company’s August 2026 Risk Report.
    • “The model, referred to only as Model 2, represents a noticeable improvement over Mythos 5 across many tasks relevant to Anthropic’s internal work. The company said the improvement is smaller than the capability jump it previously observed between Claude Opus 4.6 and Mythos Preview.
    • “Anthropic said it does not currently plan to release Model 2 externally and has not completed its full suite of typical predeployment assessments, leaving the company with somewhat lower confidence in its understanding of the model’s capabilities.”
  • Silicon Angle points out,
    • “Data resilience company Rubrik Inc. today said a month of scanning its own code with Anthropic PBC’s Mythos Preview model surfaced so many potential security issues that it rebuilt its review pipeline rather than hire reviewers.
    • “The details came in a blog post from Rubrik co-founder and Chief Technology Officer Arvind Nithrakashyap. Rubrik got access in June to Project Glasswing, Anthropic’s limited program that gives defenders early use of Mythos Preview, after the company opened it to another 150 organizations. Anthropic has kept that model out of general release. Mythos finds software flaws and strings them into working attack chains too well to hand out freely.
  • Tech Crunch relates,
    • “What happens when you pit AI agents against each other? According to Anthropic’s testing, things get messy fast.
    • “On Thursday [August 13, 2026], Anthropic’s Frontier Red Team published new research examining how groups of AI agents behave when they encounter each other in the wild. The findings provide a glimpse into potential risks that could develop as companies and governments move to implement agents working autonomously across shared codebases, markets, and computer systems.
    • “In one experiment, Anthropic gave three Claude agents access to the same software project, each with its own incompatible instructions for what to do with it. The agents weren’t told there’d be other agents working on the same project, so researchers could watch what happened when they crossed paths. 
    • “We consistently saw a multiagent turf war,” Anthropic researchers wrote. The models all assumed the others were “purposefully impeding their work” and started sabotaging each other with “increasingly aggressive, self-replicating malware.”
  • CNBC notes,
    • “Over the past two weeks, OpenAIAnthropic and Meta all revealed that their AI models went rogue during routine security testing. In explaining what happened, the companies each mentioned the same small Israeli startup: Irregular. 
    • “Founded three years ago and based in Tel Aviv, Irregular is a niche player in artificial intelligence, backed with $80 million from Sequoia and Redpoint Ventures and valued last year at $450 million. Its technology serves as a sort of cybersecurity test bed for AI models. 
    • “With the leading models becoming ever more powerful, their ability to act in malicious ways is turning into a major threat for corporations and governments, especially as the risk involves hacking into critical computer systems and infrastructure. The recent exploits at OpenAI, Anthropic and Meta all involved their AI models accessing websites that should have been off-limits as part of the cybersecurity testing.” * * *
    • “Meta, which is way behind the other two in its effort to compete at the frontier, was the latest to disclose an AI model hacking a third-party system by accessing the internet. A spokesperson said in a statement this week that the company learned about the matter from Irregular and is investigating.
    • “Meta “will issue a full retrospective once we have all the facts,” the spokesperson said.
    • “Irregular told CNBC in a statement that the incidents were all derived from the “same evaluation-environment issue” that was first disclosed by Anthropic, and that the company is developing a white paper “to share best practices for containment and securely running cyber evals.”
    • “The situation “did not involve a sandbox escape or a sophisticated cyber action,” the company said, adding that “there are no current open issues.”
  • On a related upbeat note, the Wall Street Journal informs us,
    • “U.S. startups are finally delivering something researchers have been working on for decades: a battery in which rare, hard-to-get elements are replaced with the same stuff found in ordinary table salt.
    • “This tech has the potential to help every country on earth break its dependence on China for batteries, and the critical minerals that go into them.
    • “Like any other battery, sodium-ion cells can store and release energy. They are initially being deployed where they’re needed most, in America’s power grid and fast-expanding crop of data centers. As in our homes, giving the grid or other infrastructure the ability to stockpile energy when it is cheap and plentiful, and discharge it when it is scarce, can increase reliability and lower the cost of electricity.
    • “While grid battery storage is already growing in the U.S. at a furious pace, new sodium-based batteries are potentially cheaper, longer-lasting, safer and more reliable than conventional, lithium-based ones. They could accelerate the rollout of renewables, and be part of less-polluting alternatives to natural-gas turbines and diesel generators.”

From the cybersecurity policy and law enforcement front,

  • Cybersecurity Dive reports,
    • “The Trump administration will let private companies hack foreign criminal organizations as part of a new program that could expand the U.S. government’s ability to disrupt those groups’ cybercrime activities while also introducing myriad legal challenges and perils.
    • “President Donald Trump late Wednesday [August 12, 2026] issued a memorandum directing the departments of Justice and Homeland Security to create a program allowing vetted companies to hack into criminal groups to spy on them or sabotage their operations. Trump said the program would help the U.S. combat cybercrime schemes that cost the nation tens of billions of dollars annually.” * * *
    • “Jason Healey, a senior cyber conflict researcher at Columbia University, said he “would have hated this idea ten or fifteen years ago” when the opportunity still existed to prioritize defense over offense. “But that horse left the barn a long time ago,” he said, “and we have to make decisions for the world we are in, not the one we prevented.”
    • “So, sure, let’s try to allow the private sector to get into the counter-offense game as well,” he said, “but only with very specific criteria to know when it is working and when it is making things worse.”
    • “Kyle Hanslovan, chief executive of the cybersecurity firm Huntress, said the growth of sophisticated adversaries and the threat of “AI-powered autonomous threats” meant that old models of public-private collaboration were no longer sufficient. “The only viable solution is a stronger coalition of the willing,” he said, “which we’ve been eager to support.”
    • FEHBlog note – Of course there are those questioning the memo as discussed in the article.
  • Cyberscoop adds,
    • “Under the memorandum, a federal coordination center “shall create, manage, and maintain a Program to authorize Participating Companies … to conduct Cyber Surveillance Operations and Cyber Effects Operations against foreign Cyber-Enabled Transnational Criminal Organizations (CE-TCOs), under the control and oversight of the Federal Government“ that would be “part of lawful investigatory, protective, or intelligence operations carried out by Federal law enforcement.”
    • Department of Homeland Security to “undergo rigorous vetting.” It would also allow participating companies to sign commercial agreements with other private sector entities to receive threat information. And participating companies’ agreements with federal, state and local governments would be geared toward identifying threats, and proposing cyber operations to the coordination center to address those threats.
    • The program would have to adhere to existing laws, according to the memo. That includes the Computer Fraud and Abuse Act, the main federal anti-hacking statute that prior proposals to open private sector participation in hacking operations would have amended. The memo mandates oversight to evaluate companies’ technical proficiency, ensures both small and large companies can participate, and requires regular reporting to federal officials.
  • and
    • Under the memo, the program must establish legal and constitutional procedures for the prior approval of the targeting of U.S. citizens, as well as develop procedures to halt any unintentional targeting of U.S. people or systems. * * *
    • “The coordination center charged with establishing the program under the memo has 60 days to complete its work. That process could determine a lot. Graham noted that the memo has a classified annex, too.
    • “The memo as written is quiet about what becomes of any seized assets, Graham noted.” * * *
    • “Will Barker, cybersecurity adviser at Huntress, said what’s next could be key.
    • “The 60-day implementing guidance is where the real substance lives,” he said in a written quote. “Minimum standards, operational procedures, the adjudicatory framework for target selection.”
  • MedTech Dive tells us.
    • “The Coalition for Health AI has convened a work group of nearly 100 health system, payer and industry leaders to address cyber risks associated with frontier artificial intelligence models, the nonprofit standards organization announced Wednesday.
    • “The group will meet biweekly with the goal of creating and publishing health AI cybersecurity guidance by the end of 2026. Deliverables include an AI cyber risk assessment tool and playbooks covering both defensive and offensive security strategies.
    • Anthropic’s release of its advanced Mythos and Fable AI models this spring “fundamentally changed” the cyber threat landscape for healthcare, and was a catalyst to stand up the work group, CHAI said.”
  • Cyberscoop informs us,
    • “A tech worker who hatched an elaborate insider attack in late 2023 and attempted to extort Brightly Software for about $2.5 million was sentenced to two years in prison, the Justice Department said Thursday.
    • “Cameron Nicholas Curry, also known as “Loot,” committed a series of crimes while working as a data analyst contractor for the Siemens-owned company. The 27-year-old North Carolina man stole a trove of corporate data, including sensitive employee and compensation information, which he used to threaten various employees and executives over a six-week period in late 2023 and early 2024. 
    • “Curry ultimately extorted the company for $7,540.92 in late January 2024. He was found guilty of six counts of extortion in March.
    • “Brightly Software was named as the victim in court records filed in the U.S. District Court for the Western District of North Carolina earlier this month. The asset and maintenance management software provider, which Siemens acquired in 2022, did not immediately respond to a request for comment.”

From the cybersecurity breaches and vulnerabilities front,

  • The HIPAA Journal discusses data breaches announced by five HIPAA-regulated entities.
  • Bleeping Computer reports,
    • “The ShinyHunters extortion group stole personal information from 1.6 million RingCentral accounts after hacking the company in July, according to the data breach notification service Have I Been Pwned.
    • “RingCentral is a cloud-based collaboration and communication platform used by over 600,000 businesses for services such as calling, messaging, and voicemail.
    • “The company disclosed the incident on July 28, revealing that its systems were compromised following what it described as a “sophisticated social engineering campaign.”
  • Cyberscoop relates,
    • “As the White House and federal agencies grapple with frontier AI models and their hacking capabilities, researchers are warning that the industry’s “middle class” of smaller models may end up posing a greater threat over the long term.
    • Research from XBOW this week shows that a growing class of both proprietary and open-source models are becoming strategically important in the offensive security ecosystem. Models like Z.ai’s  open-weight GLM-5.2, xAI’s Grok 4.5, Anthropic’s Opus 4.7, Meta’s Muse Spark 1.1, still perform very strongly at many hacking and exploitation tasks that worry policymakers.
    • “It’s not even that the open-source variants or…not quite frontline competitors are catching up [to frontier models] as such,” said Albert Ziegler, head of AI at XBOW. It’s that they are crossing a certain threshold, which means that suddenly they are providing net value at a cheaper price.
    • “That wasn’t necessarily the case as recently as six months ago, when testing on mid-tier class models showed they struggled to complete “moderately complex” agentic tasks. Today’s middle class largely can. Their relative cheapness means users can spend many times more resources—running them repeatedly—to solve the same challenges.”
  • Cybersecurity Dive adds,
    • “Criminal and state-aligned threat groups are testing frontier and open-weight AI models to develop new methods of attacking corporate IT networks. 
    • “Attackers are using AI for a range of activities, enabling them to develop new exploits, accelerate attack speeds and maintain persistence through the abuse of legitimate tools, researchers from Accenture and Google Cloud said during a media presentation at the Black Hat USA conference in Las Vegas.
  • and
    • “Criminal actors are offering a range of AI-powered hacking tools and related services for sale on underground forums on the dark web, according to a report released Wednesday by cybersecurity firm Trellix. 
    • “Researchers found a wide range of AI-based tools being sold through these markets, ranging from reconnaissance tools to credential markets, as well as AI-as-a-service platforms. 
    • “The report shows how AI is being monetized to lower the barriers of entry into sophisticated threat activity. “
  • and
    • “Security researchers are backing claims by a newly emergent data-extortion group that it has exfiltrated sensitive data from about 15 companies, governments and other organizations. 
    • “A threat group called ExfilSquad claimed on July 26 to have exfiltrated customer records and other information from a number of city governments and universities, a major public school system and private companies. After being met with skepticism, the threat actor later released samples of the allegedly stolen information. 
    • “Researchers at Fortra released a report Thursday that corroborates ExfilSquad’s breach claims. The leaked data appears to be related to misconfigured Microsoft Power Page portals, a software-as-a-service platform that is used to create public-facing business websites. The misconfiguration enabled unauthorized access to Microsoft D365, according to researchers, which led to public read access.” 
  • Per Cyberscoop,
    • “Suspected Chinese hackers used open-source artificial intelligence models to run a cyberattack against the Taiwanese government in the first publicly known case of an autonomous AI hack hitting a government target, according to research published Wednesday.
    • “The hackers extracted more than 2,500 personnel records, among other data, in the “near-autonomous attack,” researchers at Israeli cyber firm Dream wrote in a blog post. The attackers set up the framework so that it could “adapt mid-operation without human intervention.”
    • “The framework “implements dedicated research phases it calls ‘Learning Cycles’ — autonomous sessions where the AI system searches vulnerability databases, GitHub repositories, and security research publications for techniques specifically applicable to its target government’s infrastructure,” the post reads.
    • “And then it kept going.”
  • The Cybersecurity and Infrastructure Security Agency (CISA) added three known exploited vulnerabilities to its catalog this week.
    • August 11, 2026
      • CVE-2026-20349 Cisco Secure Firewall Adaptive Security Appliance (ASA) and Firewall Threat Defense (FTD) Heap Inspection Vulnerability
      • CVE-2026-68820 Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
      • CVE-2026-72898 Metabase SQL Injection Vulnerability
        • Cybersecurity Dive discusses the Cisco KVE here.
        • The Hacker News discusses the Microsoft KVE here.
        • Dark Reading discusses the Metabase KVE here.
  • Cybersecurity Dive notes,
    • “The global system that catalogs technology vulnerabilities is resilient enough to survive the current onslaught of AI-generated bug reports that has alarmed cybersecurity experts, key leaders of that system said last week during panels at two security conferences here.
    • The Common Vulnerabilities and Exposures (CVE) Program — whose unique vulnerability identifiers are the bedrock of the entire cybersecurity industry — “will find a way to scale,” Lindsey Cerkovnik, branch chief for vulnerability response and coordination at the Cybersecurity and Infrastructure Security Agency (CISA), said at the Black Hat USA conference on Thursday [August 6, 2026]. “CVE is going to continue to flourish and improve, and I feel very positively about it.”
  • Infosecurity Magazine points out,
    • “A critical-severity VMware vCenter vulnerability has been exploited within five days of disclosure by Broadcom, with attackers deploying an open-source reverse shell to hold access to compromised systems.
    • “The treat research team at German firm Quirso discovered the campaign during an incident response engagement and published its findings on August 10.
    • “The digital forensics company assessed a suspected advanced persistent threat (APT) actor was responsible, counting 361 victim IP addresses across 47 countries while cautioning that an IP address does not necessarily correspond to a single organization.
    • “The vulnerability, CVE-2026-59310, is acritical directory traversal flaw in the vCenter Syslog server rated CVSS 9.8. Broadcom said an unauthenticated attacker with network access to vCenter can exploit it to execute arbitrary code, turning a service built to collect logs into a route into the operating system.”
  • Per Cyberscoop,
    • “Delta Airlines said Tuesday [August 11] it’s investigating an incident on a Monday flight where a passenger reportedly used an unidentified device to spoof the airline’s in-flight Wi-Fi network, leading to severe delays and authorities to board the plane once it arrived at its destination.
    • Various posts on several social media networks went viral early Tuesday detailing the incident, claiming that passengers on Delta flight 591 from Las Vegas to Atlanta used an unidentified device to create a rogue Wi-Fi network that could be used to steal people’s sensitive data or personal information.
    • “Messages from the plane’s Aircraft Communications Addressing and Reporting System (ACARS) show that the crew informed personnel on the ground that a passenger set up a network called “Delta WiFi Fast” and was “trying to scam the other passengers.”
    • “Morgan Durrant, a Delta spokesperson, told CyberScoop that the cabin crew deactivated the aircraft’s WiFi functionality for approximately 30 minutes, the flight’s safety was never in question and no aircraft operating systems were affected.” * * *
    • “The incident bears the hallmarks of an “evil twin attack,” where an attacker deploys a rogue Wi-Fi access point that masquerades as a legitimate, trusted network by cloning its name and network settings. Often paired with deauthentication attacks that forcefully disconnect devices from the real network, the fraudulent hotspot tricks nearby laptops and smartphones into automatically connecting to it instead. Once a device connects to the rogue point, an attacker can monitor unencrypted internet traffic, execute man-in-the-middle attacks, or display spoofed login portals designed to harvest sensitive user credentials and personal data.”  
  • The Wall Street Journal points out,
    • “Thousands of North Korean operatives are using fake and stolen identities to land remote jobs at U.S. companies—funneling hundreds of millions of dollars back to the regime.
    • “Leaked data, interviews and never-before-seen videos obtained by The Wall Street Journal reveal how a single team of these workers infiltrated at least eight companies in just a few months. Watch the documentary and read the practical takeaways.”

From the ransomware front,

  • Checkpoint issued its report on the State of Ransomware Q2.
  • The American Hospital Association News reports,
    • “U.S. and international agencies released a joint cybersecurity advisory Aug. 10 warning of actions by Gunra ransomware. Gunra is a ransomware-as-a-service program that has been used to target government, critical infrastructure — including healthcare — and other organizations in the U.S. and abroad.
    • Gunra actors leverage a double-extortion model, both encrypting data and threatening to publish stolen data to a dedicated leak site if a ransom is not paid. The ransomware variant initially appeared in 2025. The advisory provides details on Gunra activity and includes detection and mitigation guidance to protect organizations.”
  • Dark Reading adds,
    • “The joint advisory urged organizations to prioritize patching known exploited vulnerabilities in Internet-facing appliances such as VPNs, implement and test offline immutable backups, and implement network segmentation to limit threat actors’ ability to move laterally.”
  • The HIPAA Journal relates,
    • “AnMed has not disclosed the name of the group behind the attack, but a threat group called The Gentlemen claimed responsibility. The Gentlemen is a ransomware-as-a-service group that is thought to include affiliates and operators from other prominent ransomware groups. The group has claimed several healthcare victims in recent months, and the pace of the attacks is accelerating.
    • “According to the Industrial Ransomware Analysis from the operational technology cybersecurity company Dragos, The Gentlemen was the third most active ransomware group in Q2 2026, claiming 125 attacks in the quarter alone, up from 83 attacks in Q1 – the largest gain out of all established ransomware groups. While the group ranked third, there were only 15 attacks separating the top three ransomware groups, with no single ransomware group dominating.”
  • Bleeping Computer tells us,
    • “Oil giant Shell has confirmed it is investigating a potential security incident after the Clop ransomware gang claimed it stole 89GB of data.
    • “Shell is a British multinational energy conglomerate and one of the world’s top three oil and gas companies, after Chevron and ExxonMobil. It has 85,000 employees in more than 70 countries and operates a massive network of tens of thousands of service and recharge stations that serve over 20 million customers daily.
    • “According to a recent post on Clop’s dark web data leak site, the allegedly stolen files include engineering drawings, scans of facility testing reports, photos of the facilities, and project plans.”
  • and
    • “An Akira ransomware affiliate disabled the endpoint detection and response (EDR) solution on a compromised system by restarting the machine into Safe Mode with Networking.
    • “The attack occurred on August 4 after the hacker obtained initial access through an exposed SonicWall VPN device without multi-factor authentication (MFA).
    • “Managed detection and response (MDR) services company Huntress says that roughly two hours after a successful VPN login, the attacker connected to the domain controller via RDP, enumerated Active Directory users and computers, and then moved to an application server.”
  • and
    • “CISA confirmed today that ransomware gangs have begun abusing a high-severity Microsoft SharePoint remote code execution vulnerability, which has been flagged as actively exploited since early July.
    • “Tracked as CVE-2026-45659, this security flaw stems from a deserialization of untrusted data weakness and allows attackers with low privileges to execute arbitrary code on unpatched SharePoint servers.
    • “It can also be exploited in low-complexity attacks because (as Microsoft explained in May when it released security updates for SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition) “an attacker does not require significant prior knowledge of the system and can achieve repeatable success with the payload against the vulnerable component.”
  • The Record informs us,
    • “A financially motivated threat actor linked to China is believed to be exploiting a critical vulnerability affecting widely used cybersecurity software in a supply-chain attack that could see the hackers deploy custom ransomware across a cascading list of victims’ networks. 
    • “Microsoft Threat Intelligence warned this weekend that the Storm-1175 group began deploying a new ransomware strain on August 2 called StormEncryptor. The hackers previously used the Medusa ransomware to extort healthcare, professional services and finance organizations in Australia, Britain and the United States. 
    • “Back in April, the hackers were described as operating “high-velocity ransomware campaigns” exploiting both recently disclosed vulnerabilities and zero-day exploits, “in some cases a full week before public vulnerability disclosure.” Microsoft said it had seen the group move from initial access to full encryption in under 24 hours. 
    • “In this latest campaign, Microsoft said the group is likely exploiting CVE-2026-18577 — a vulnerability in N-central, a remote monitoring and management (RMM) console used by thousands of managed service providers to administer client endpoints.”
  • The Hacker News adds,
    • “The ransomware group known as DeadLock has been observed using decentralized infrastructure to facilitate victim communications and data leak operations in a bid to improve operational resilience.
    • “Its recovery ecosystem combines the Session messaging network with blockchain-backed services that store and deliver resources used throughout the extortion process,” the Microsoft Threat Intelligence team said.
    • “The tech giant said it observed the ransomware being deployed by multiple threat actors, including an affiliate for Lynx and INC ransomware.”

From the cybersecurity business and defenses front,

  • Bloomberg reports,
    • “Anthropic PBC is telling prospective investors its second-quarter revenue jumped at least 14-fold versus the same period a year ago, according to documents seen by Bloomberg News.
    • “The Claude chatbot maker reported a preliminary revenue figure of more than $11.5 billion in its latest completed quarter, compared to $787 million in the corresponding period in 2025, and $4.73 billion in the first quarter of this year, the documents show. The second quarter of 2026 saw Anthropic report positive adjusted operating income, according to the documents.”
  • Reuters relates,
    • “Anthropic is in talks to buy Nvidia-backed startup Decart AI, according to a source familiar with ​the matter, as the Claude maker explores acquisitions that ‌could help it handle growing demand ahead of its public listing.
    • “Bloomberg News, which first reported the news on Wednesday, said a deal ​could be worth about $6 billion, citing sources.”
  • Tech Crunch adds,
    • “Anthropic will watermark text generated by its models, including Claude, to comply with European regulations, the company now says. The AI model maker confirmed the watermarking in an updated support page.” * * *
    • “It’s not clear how much editing users need to do to remove the watermark. We have asked Anthropic to clarify and will update the story if we hear back.
    • “The company noted that watermarking will apply to different products like Claude platform API, Claude, Claude Code, Claude Cowork, and Claude Tag.
    • “Platforms are now rushing to watermark AI-generated content after backlash from users and to avoid regulatory scrutiny. Last week, AI music platform Suno said it will mark tracks created on its platform after a spate of legal challenges. Last month, newsletter service Substack teamed up with Pangram to flag AI-generated content. The company’s CEO, Chris Best, called out Claudefishing, a term used for people using AI to generate content.
    • “Apart from Anthropic, other companies like Black Forest Labs, Google, Meta, Microsoft, OpenAI, and Synthesia have committed to adhering to the EU’s code.
  • Cybersecurity Dive informs us,
    • “Cisco’s security revenue surged last quarter as the technology giant saw growing demand for products designed to protect businesses against emerging cybersecurity threats, including those enabled by artificial intelligence agents, the company reported Wednesday.
    • “The company posted $17.3 billion in total revenue for its fiscal 2026 fourth quarter ended July 25, a year-over-year increase of 18%. Security revenue rose 14% in the quarter to $2.2 billion from a year earlier.
    • “The rise of agentic AI is expanding the threat landscape, driving demand for our security and observability solutions to help monitor agent behavior and mitigate evolving threats,” CEO Chuck Robbins said during a Wednesday earnings call.”
  • The Wall Street Journal notes,
    • “Enterprise users spent $300 million on quantum computing in 2025, outranking research labs and governments as the primary spenders for the first time.
    • “A Boston Consulting Group survey found that 62% of the top 25 global companies across 11 major industries spend at least $1 million annually on quantum.
    • “Companies like HSBC, Allstate and EY are investing to prepare for future commercialization and to secure systems against quantum encryption threats.”
  • Per Dark Reading,
    • “Walmart, the world’s largest retailer, faces a complex cyber threat landscape, documenting 806 reported retail breaches in Verizon’s 2026 Data Breach Investigations Report.
    • “Security leadership stresses balancing strong cybersecurity controls with business innovation and speed, avoiding operational drag that could lead staff to bypass safeguards.
    • “Walmart’s security approach involves proactive transparency and trust-building with leadership, using color-coded executive summaries and open discussions on risks and mitigation progress.
    • “Industry experts emphasize the evolving role of security operations as essential business partners, noting there is no one-size-fits-all model but a universal need for pragmatic resilience and honest communication.”
  • and
    • “The Patch Gap: Why Defenders Need to Think in Chains, Not Checklists
    • “It’s time to turn from CVSS-backed patching to choke-point patching focused on breaking chains to critical assets.”
    • “If the volume problem and prioritization problem can’t be solved by patchingfaster and scoring harder, then the framing itself needs to change. The question that the security team should ask is not “which vulnerabilities are most severe in isolation?” but rather “which vulnerabilities, if left unpatched, create a connected path from an attacker’s foothold to our most critical assets?”
  • Per a CISA announcement,
    • “This year marks the 20th year of Cyber Storm, a full-scale national cybersecurity exercise that for two decades has brought together the people who defend the systems Americans rely on. Held every two years, Cyber Storm X arrives as threats from geo-political activity, compromised edge devices, AI risks, and more present new challenges to our nation’s critical infrastructure.
    • “As the nation’s largest cybersecurity exercise, Cyber Storm plays a vital role in preparing for potential cybersecurity incidents by testing and strengthening the nation’s ability to coordinate a unified cyber response. Participants from private and public organizations work together through a simulated crisis. Together, they learn as a team and build stronger relationships that will speed response during an actual event. Importantly, organizations can also update their response plans based on lessons learned during the exercise.” * * *
    • “Learn more about Cyber Storm and past events at cisa.gov/cyber-storm. For more information about CISA’s exercise resources, visit CISA Exercises.”
       
  • Security Boulevard adds,
    • “CrowdStrike has announced a $100,000 international competition that challenges participants to manipulate live AI agents using prompt injection and other red-teaming techniques.
    • “The competition takes the form of a virtual game called AI Unlocked: Agents of Chaos, created in collaboration with Amazon Web Services. Players take on a fictional mission to stop a shadow group from deploying malicious AI. To do that, they must manipulate the group’s own agents into revealing information and taking actions they were not authorized to perform. Their scores also depend on efficiency, with points deducted for every token used in their prompts.
    • “The contest opens Aug. 31 and is divided into three acts. The first runs through Sept. 7 with a $10,000 prize, the second ends Sept. 14 and awards $20,000, and the final act runs from Sept. 15 through Sept. 29 with a $70,000 prize. The game is available online internationally, with an in-person option to play at CrowdStrike’s Fal.Con conference. Pre-registration is open, and contestants can replay completed puzzles to refine their prompts. CrowdStrike said the highest score recorded when each act closes will receive that act’s prize.”
  • Here is a link to Dark Reading’s CISO Corner.

Thursday report

Simplicity is a virtue.

From Washington, DC

  • STAT News reports,
    • ‘ARPA-H, the U.S.’ “moonshot” agency for health research, announced Thursday that it will spend up to $160 million to push forward custom gene editing treatments for a spate of rare diseases. 
    • ‘The program, called THRIVE, will back seven different teams pursuing various groups of conditions affecting different organ systems. 
    • “Each team has a deadline of starting clinical trials by year three of the program, although some may start much sooner.” * * *
    • “Each of the groups will work with a partner, such as a biotech company or contract manufacturer, or multiple partners to assure they can manufacture the program to Food and Drug Administration standards.”
  • Beckers Hospital Review relates,
    • “Peptides have become one of the most closely watched regulatory questions in healthcare this summer, with a federal advisory committee vote set for July 23-24 that could reshape what’s legally available to prescribers, wellness clinics and patients nationwide.
    • What are peptides?
      • Peptides are short chains of amino acids that often serve as signaling molecules for physiological functions in the body, including tissue repair, metabolism and inflammation. Some peptides, like insulin and semaglutide, the active ingredient in Ozempic and Wegovy, are FDA-approved drugs. Others — including BPC-157, TB-500 and a handful of others marketed for injury recovery, weight loss, sleep and anti-aging — have circulated for years through wellness clinics, medical spas and online retailers without ever being FDA-approved or added to the list of substances legally allowed in pharmacy compounding. 
      • “That distinction matters because of how compounding law works. Under Section 503A of the Food, Drug and Cosmetic Act, a licensed pharmacy can only compound a drug for an individual patient using a bulk substance if it’s FDA-approved, has a recognized USP monograph, or appears on the FDA’s 503A Bulks List. If a peptide isn’t on that list, pharmacies generally can’t legally compound it — which is exactly the question now in front of regulators. 
    • The upcoming vote 
      • “The FDA’s Pharmacy Compounding Advisory Committee meets July 23-24 to decide whether seven peptides should be added to the 503A bulks list: BPC-157, KPV, TB-500 and MOTs-C, Emideltide (also called DSIP), Semax and Epitalon. The committee’s recommendation is non-binding, but the FDA has historically followed it.”
  • Tammy Flanagan, writing in Govexec, explains OPM’s new all-digital federal retirement benefit application process.
  • Per an HHS news release,
    • “President Donald J. Trump signed an Emergency Declaration for the Northern Mariana Islands and the Territory of Guam, and Secretary Robert F. Kennedy, Jr. has declared a public health emergency to address the consequences of Typhoon Bavi. Under these circumstances, the Secretary has also exercised the authority to waive sanctions and penalties against a covered hospital that does not comply with the following provisions of the HIPAA Privacy Rule:
      • the requirements to obtain a patient’s agreement to speak with family members or friends involved in the patient’s care. See 45 CFR 164.510(b).
      • the requirement to honor a request to opt out of the facility directory. See 45 CFR 164.510(a).
      • the requirement to distribute a notice of privacy practices. See 45 CFR 164.520.
      • the patient’s right to request privacy restrictions. See 45 CFR 164.522(a).
      • the patient’s right to request confidential communications. See 45 CFR 164.522(b).
    • “When the Secretary issues such a waiver, it only applies: (1) in the emergency area and for the emergency period identified in the public health emergency declaration; (2) to hospitals that have instituted a disaster protocol; and (3) for up to 72 hours from the time the hospital implements its disaster protocol. When the Presidential or Secretarial declaration terminates, a hospital must then comply with all the requirements of the Privacy Rule for any patient still under its care, even if 72 hours has not elapsed since implementation of its disaster protocol.”

From the Food and Drug Administration front,

  • USA Today reports,
    • “If headlines about heavy metals in tampons raised concerns, the Food and Drug Administration says there’s some reassuring news.
    • “A new agency study found trace amounts of metals including arsenic, cadmium and lead in tampons sold in the U.S., but concluded the levels released during use are too low to pose a health risk.
    • “The findings are the FDA’s latest response to a widely publicized 2024 study that detected metals in popular tampon brands and sparked questions about possible health effects. After analyzing 11 tampon products from six brands, FDA researchers found that while metals can be detected in the products, exposure during normal use remains far below levels considered harmful.”
  • MedTech Dive informs us,
    • “Johnson & Johnson has won Food and Drug Administration approval for a catheter that delivers radiofrequency and pulsed field energy to treat atrial fibrillation.
    • “The approval, which J&J disclosed Wednesday, covers the Dual Energy Thermocool Smarttouch SF Platform. J&J already had approval for a single, radiofrequency energy version of the device.
    • “Integrated into the company’s Carto mapping system, the dual-energy catheter is part of J&J’s push to leverage its electrophysiology strength to reverse market share losses triggered by PFA.”
  • The American Hospital Association News relates,
    • “The Food and Drug Administration has issued an early alert for specific lots of BD ChloraPrep Applicators by Medline because of a potential breach of sterility in the packaging, due to wrinkles in the paper lidding which may extend to the seal area. Medline has instructed impacted customers to remove the recalled convenience kits from where they are used or sold. The company said that other components within the convenience kits may still be used.” 
  • BioPharma Dive cautions,
    • “The regulatory gears in the U.S. are increasingly creaking under the weight of new, complex drug technologies and intensifying overseas clinical trials competition from countries like China and Australia.
    • “Now, the Department of Health and Human Services is making moves to speed early drug research under a new plan dubbed Operation Trialblazer. The blueprint, which involves initiatives at multiple federal agencies, including the Food and Drug Administration and the National Institutes of Health, focuses on modernizing regulations and processes, improving patient access and participation, and enhancing the use of data and technology to streamline the regulatory process.
    • “It’s the latest in a series of actions aimed at supporting drug research. But whether the new reforms will make a meaningful impact is an open question.” 

From the judicial front,

  • Fierce Healthcare reports,
    • “CVS Health and its embattled Omnicare unit have agreed to pay $440 million to the Department of Justice to satisfy a nearly $950 million judgment against the company as part of an ongoing fraud case.
    • “In April 2025, a federal jury ruled that Omnicare submitted more than 3.3 million fraudulent prescription claims between 2010 and 2018, earning $135.6 million in overpayments as a result. Then, in July 2025, a judge ordered Omnicare to pay $948.8 million in fees and damages as part of the case.
    • “In the new court docs, CVS said that it has agreed to make an initial $130 million payment within 14 days of the agreement’s effective date. The remaining $310 million must be paid out by March 15, 2028.
    • “The agreement with DOJ is contingent on the closure of Omnicare’s sale to GenieRx Holdings, according to the filing. As it navigated the legal fallout of the False Claims Act case, Omnicare filed for bankruptcy in September 2025, and CVS announced plans to sell to GenieRx in May of this year.”

From the public health and medical / Rx research front,

  • The Washington Post reports,
    • “Annual cancer cases are projected to rise considerably worldwide by 2050, according to a World Health Organization report on cancer published Wednesday. With its assessment, the United Nations body tempered optimism about improvements in cancer surveillance and treatment and warned that global health care inequities are driving further cases and deaths. 
    • “Around 20.6 million people were diagnosed with cancer in 2024, according to the findings. That number could reach 35 million a year by 2050.
    • “The new cases will disproportionately appear in lower-income countries with poorer access to cancer surveillance and treatment, according to the report.” * * *
    • “In the United States, the rate of new cases has generally been stable in recent years, according to the National Institutes of Health. The WHO report predicts that cancer rates will increase in all regions across the world, though the biggest increases are projected in Africa and the Eastern Mediterranean region.”
  • Health Day adds,
    • “More men die from cancer than women, and a new study suggests one potential reason why.
    • “Men are more likely than women to be diagnosed with advanced cancer that has spread to other parts of the body, researchers report in the July issue of the journal Cancer Epidemiology, Biomarkers & Prevention.
    • “That means their cancer is being detected too late, when it’s tougher to treat and more likely to be fatal, researchers said.
    • “We know that, overall, males are more likely than females to die from many types of cancer. We also know that cancer stage at diagnosis is a key predictor of cancer survival,” lead researcher Beth Maclin, a postdoctoral fellow at the National Cancer Institute in Bethesda, Maryland, said in a news release.” * * *
    • “My overall message is that everyone should go to the doctor regularly,” Maclin said. “Don’t delay seeing a doctor if you notice something has changed in your body.”
  • The AP relates,
    • “Nearly 1,000 people in Michigan have been diagnosed with a parasitic infection that can cause weeks of watery diarrhea, making it the largest such outbreak in state history and one of the nation’s largest in years.
    • “No deaths have been reported and the source of the cyclospora infections hasn’t been identified. Meanwhile, investigations into similar illnesses have been going on in 28 other states, including in Ohio, where people just across the Michigan border are also becoming sick.
    • “Michigan officials first announced the outbreak last week, when they were aware of more than 170 cases — all in the southeastern corner of the state — since June 22. Michigan usually identifies only about 50 cases each year.
    • “On Wednesday, the state reported the number had grown to 992, including about 40 hospitalizations. Just across the state line, Lucas County, Ohio, reported 306 cases as of Wednesday. Northwest Ohio has seen more than 500 cases.
    • “Cyclospora surges can be tricky to investigate, and food poisoning sources can be hard to establish. But “there is clearly a linked outbreak happening right now,” Dr. Natasha Bagdasarian, Michigan’s chief medical executive, told The Associated Press on Wednesday.”
  • MedPage Today tells us,
    • “Chronic kidney disease prevalence held steady at around 14.8% over the last decade, despite treatment advances.
    • “This translated to an estimated 36 million affected U.S. adults, based on national health survey data.
    • “The prevalence of diabetes-related chronic kidney disease increased during the period spanning 2013-2014 to 2021-2023.” * * *
    • “This means single-organ care is no longer enough, said [Sophie] Claudel [, MD]. Based on the data, a growing proportion of the population may be at risk for progressive cardiovascular-kidney-metabolic (CKM) syndrome.
  • Healio informs us,
    • “GLP-1s may prevent adverse outcomes in patients with peripheral artery disease and diabetes, according to data published in the Journal of the American Heart Association
    • “Researchers reported that GLP-1 receptor agonist use among patients with PAD and diabetes was associated with lower risk for mortality, hospitalization, revascularization and amputation compared with those prescribed metformin.
    • “Obesity and PAD, including chronic limb-threatening ischemia, are linked to increased inflammation, poor blood vessel function, insulin resistance, oxidative stress and faster hardening of the arteries,” Akiva Rosenzveig, MD, cardiology fellow at Cleveland Clinic, said in a press release. “These results indicate GLP-1 [receptor agonists] can help reduce inflammation, improve blood vessel function and manage blood sugar levels.”
  • Medscape adds,
    • “The FDA approved Zepbound (tirzepatide) in December 2024 for the treatment of moderate-to-severe obstructive sleep apnea (OSA) in patients with obesityafter research showed that the medication improved outcomes in these patients.
    • “Sleep apnea is among the most common sleep disorders. It occurs when the airways relax and block breathing during sleep. Patients may repeatedly stop breathing, leading to disrupted sleep, snoring, and excessive sleepiness during the day.
    • “Now new research has shown that certain patients seem to benefit more than others from the medication. Patients with the most severe sleep apnea along with those who are younger and have less severe obesity experienced nearly twice the reduction in symptoms compared to those who are older and have more severe obesity.”
  • Fierce Pharma points out,
    • “In a first for the neurotoxin market, Ipsen announced Thursday that its Dysport has hit the goals in two phase 3 trials for the prevention of both episodic and chronic migraines.
    • “While AbbVie’s market-leading Botox has been approved by the FDA to prevent headaches in patients with chronic migraine since 2010, Dysport is now the first botulinum toxin to also report positive phase 3 results in episodic migraine, according to Ipsen.
    • “The readouts come from studies in Ipsen’s Beond program, comprising 1,510 patients, split between C-Beond (chronic) and E-Beond (episodic). Both trials have met their primary endpoints, showing a statistically significant reduction in monthly migraine days versus placebo.
    • “Together, these findings position Dysport as a potential first-in-class treatment for a broad migraine population,” Ipsen’s global head of R&D, Christelle Huguet, Ph.D., said in a July 9 statement.
    • “Ipsen will review the full data and prepare for regulatory filings, including with the FDA, a company spokesperson told Fierce Pharma.” 
  • BioPharma Dive lets us know,
    • “A nucleic acid-based medicine from AstraZeneca and Ionis Pharmaceuticals missed its main objective in a big study of people with a deadly heart condition in a major setback with notable ramifications for multiple other drugmakers. 
    • “In a pair of statements, the companies said that when compared to a placebo in people with transthyretin-mediated amyloid cardiomyopathy, or ATTR-CM, their drug, eplontersen, didn’t significantly reduce the risk of death or recurrent cardiovascular events after 140 weeks. Eplontersen had no treatment effect among participants already receiving a commonly used “stabilizer” medication. A 29% risk reduction was observed in people who weren’t getting those drugs, AstraZeneca and Ionis said.
    • “The companies didn’t provide additional study details, only noting that the drug was “well tolerated” and showed positive signs on multiple other secondary study measures. Those specifics will be presented at a medical meeting in August. “
  • and
    • “Roche said Thursday it’s discontinuing two Ionis-partnered drugs for Huntington’s disease after clinical setbacks, with one missing its main trial goal and the other suspended because of a safety worry.
    • “A Phase 2 test of the antisense oligonucleotide tominersen “did not meet its efficacy objective” in spite of having a significant impact on biological disease signs, Roche said in a letter to patient groups. Meanwhile, enrollees in a Phase 1 trial of a drug codenamed RG6496 won’t receive a second dose because animal safety testing revealed that it “cannot be given chronically with repeated doses,” Roche said.
    • “The Swiss pharmaceutical giant had once before suspended a late-stage trial of tominersen because it didn’t appear to be helping patients. Roche forged ahead with a hypothesis that younger and less-advanced patients might benefit, but now that pathway has hit a dead end.”
  • Per Genetic Engineering and BioTechnology News,
    • “A landmark Phase I/II clinical study led by researchers at Skåne University Hospital and Lund University has shown that transplanting stem-cell-derived dopamine progenitor cells into the brain is feasible. Eight patients with Parkinson’s disease (PD) received transplants of STEM-PD, a cryopreserved, off-the-shelf dopaminergic progenitor product derived from human pluripotent stem cells. The three-year Phase I/II, open-label, multicenter, single-arm, dose-escalation study identified no serious side effects linked to the transplanted cells during the first year of follow‑up.
    • “The possibility of replacing dopamine neurons that are lost in Parkinson’s disease has been a long-standing goal in the field,” said Malin Parmar, professor of cellular neuroscience at Lund University, and lead of the STEM-PD program. “The findings represent an important milestone for regenerative medicine approaches in Parkinson’s disease and support continued clinical development of stem cell-based therapies.”
    • “Results from the study were reported by Parmar and colleagues in Nature Medicine. In their paper, titled “Human embryonic stem cell-derived dopaminergic cells for Parkinson’s disease: a Phase I/II open-label trial,” the team wrote, “In conclusion, particularly in the context of other recently published trials using human PS cell-derived dopaminergic cell therapies for PD, these findings further support the continued development of this therapeutic approach, including evaluation of the STEM-PD product in larger patient cohorts.”

From the U.S. healthcare business and artificial intelligence front,

  • Healthcare Dive reports,
    • “CVS’ insurance division Aetna has a finally gotten a handle on medical spending after a turbulent few years, according to the healthcare giant’s chief executive.
    • “We’ve got, I think, our arms around how to project and predict where healthcare costs are going, and making sure we’re pricing our products accordingly,” CVS CEO David Joyner said at an event hosted by the Economic Club in Washington, D.C., on Thursday.
    • “Joyner’s comments — which come about a month before CVS is scheduled to report second quarter results — are likely a welcome signal for investors that Aetna can continue recent progress on controlling spending.” * * *
    • “The biggest challenge for CVS isn’t managing members’ costs: It’s policy uncertainty out of Washington, Joyner said.
    • “I spend a lot of my time, both at the federal level and in the states, trying to help educate and also describe what are the real drivers of healthcare costs, and then making sure that we play an active role to help with members of Congress,” the CEO said.”
  • Fierce Healthcare relates,
    • “UnitedHealthcare is rolling out a new benefit option aimed at making it easier for employers to offer more personalized wellness programs.
    • “Called Lifestyle Spending Accounts (LSAs), the benefit allows employers to offer a stipend that members can put toward wellness solutions. The LSAs are integrated with UnitedHealth’s UHC Store, which is a digital storefront where members can purchase select health and wellness programs at a discount.
    • “The accounts exist alongside health savings accounts or flexible spending accounts, allowing individuals to purchase health and wellness generally not available under HSAs or FSAs, UnitedHealthcare said.”
  • Benefits Pro tells us,
    • “Both the levels and growth of health care spending from 2005 to 2023 were greatest among Americans with the highest incomes, according to a new report in Health Affairs.
    • “Among the lowest income quintile, spending grew more rapidly just after 2014 but declined from 2018 to 2023. By contrast, spending in the highest income quintile grew more rapidly in recent years. As a result, the difference in age and health status-adjusted spending between the highest and lowest income quintiles declined after implementation of the Affordable Care Act subsidies but increased more recently. The adjusted per capita spending difference in 2023 was more than $4,700.
    • “If spending continues its most recent trajectory, that difference will continue to grow,” the report said. “These spending patterns were driven largely by outpatient and prescription drug spending, which tend to be more discretionary than inpatient and emergency department spending. Prescription drug spending showed a particularly pronounced recent divergence for the top income quintile. Recent spending growth was most evident in the population younger than age 65, which has more variation in insurance coverage, affecting both service use and prices.”
  • Psychology Today lets us know,
    • “Mental health leave [under federal and state leave acts] has sharply increased in the U.S. since the pandemic.
    • “Women, especially caregivers, account for the majority of mental health leaves.
    • “Access to mental health leave highlights structural inequalities in the workplace.
    • “Early, ongoing treatment with an established provider can support the mental health leave process.”
  • Per Smart Brief,
    • “Healthcare AI’s next challenge isn’t adoption. It’s reliability
    • “Healthcare has reached a point where the challenge with AI is not adoption but ensuring it is accountable and dependable post-deployment, writes Sina Bari, vice president of healthcare and life sciences AI at iMerit.”
  • Per MedTech Dive,
    • “Stereotaxis said Thursday it finalized the acquisition of French surgical robotics company Robocath.
    • “Announced in April, the deal is valued at up to $45 million and brings together two robot developers focused on endovascular interventions, which are performed inside blood vessels.
    • “Combining the companies’ expertise will speed development of next-generation robotic technologies for electrophysiology, interventional cardiology and neurointerventions, the companies said.”
  • Per Fierce Pharma,
    • “Unexpectedly catapulted into global fame as a COVID-19 vaccine maker, BioNTech is on the verge of returning to its oncology roots with potentially its first commercial cancer drug. Yet, to Chief Commercial Officer Annemarie Hanekamp, the upcoming launch is less of a standalone milestone than a strategic springboard for a far more critical pipeline product. 
    • “Backed by positive phase 2 data and an ongoing confirmatory phase 3 trial, BioNTech is readying its Duality Biologics-partnered antibody-drug conjugate (ADC) trastuzumab pamirtecan (T-Pam) for submission with the FDA for previously treated HER2-expressing endometrial cancer. 
    • “If approved, the drug will compete with AstraZeneca and Daiichi Sankyo’s blockbuster HER2 ADC, Enhertu, which boasts a pan-tumor indication. Challenging the market leader, however, is not BioNTech’s end goal for T-Pam.
    • “This is not about competing head to head with Enhertu and overtaking them,” Hanekamp said in a recent interview with Fierce Pharma. “We’re very realistic, and we know in the oncology space, first-mover advantage matters. They’ve been in the market for a while, it’s an amazing drug, and we don’t claim to be all that differentiated versus Enhertu.”
    • “Instead, Hanekamp views T-Pam as a “strategic launch,” an exercise to “run water through the pipes” and test BioNTech’s commercial infrastructure in oncology.”

Midweek report

Simplicity is a virtue.

From Washington, DC

  • FedWeek reports,
    • “OPM has sought to allay privacy concerns about its plan to access detailed medical information on FEHB/PSHB enrollees, with one of the organizations that raised such concerns—the National Active and Retired Federal Employees Association—cautiously optimistic that OPM is addressing them.
    • “In a Federal Register notice posted in December, but which only drew attention months later in April, OPM proposed to gain access to carriers’ records including office visits, treatment, prescriptions and other medical information, without a requirement that they withhold personally identifying information.” * * *
    • “He said that OPM’s inspector general’s office—which has access to such information for its audits of health plans and carriers—“will provide an encrypted copy of that data to OPM – but only after stripping out names, social security numbers, phone numbers, addresses (except for ZIP codes), and other personally identifiable data. The only member-level PII fields that will remain in the data that OPM receives will be our member’s ZIP codes, year of birth, and their member ID.”
    • “He said that OPM further will replace the member ID with random numbers and characters and that the data “will remain in a secure, separate environment, encrypted at rest and protected with our IT security best practices.”
  • FEHBlog note: At least for HIPAA privacy rule purposes, an anonymous identifier cannot be based on an actual ID number as OPM plans. Moreover, to avoid re-identification, OPM should arrange for a third party to create the anonymous identifier properly and then arrange for the OIG to insert the anonymous identifier into the claims records before they are sent to OPM.
  • Per a Senate news release,
    • “Today the U.S. Senate Health, Education, Labor, and Pensions (HELP) Committee voted to favorably report several bills making health care more affordable and accessible to American families. During the markup, U.S. Senator Bill Cassidy, M.D. (R-LA), Chairman of the HELP Committee, led Republicans in rejecting Ranking Member Bernie Sanders’ (I-VT) attempt to sabotage the bipartisan bills with toxic poison pill amendments.
    • “I understand why Americans are frustrated with Congress. If we want Congress to work, we have to make it work,” said Dr. Cassidy. “I want part of my legacy [to be] he tried to preserve the institution. But that is a responsibility of us all.”
    • “I appreciate my colleagues’ efforts and will continue to work with Republicans and Democrats to enact a pro-patient, pro-family agenda,” continued Dr. Cassidy.
    • “The Charlotte Woodward Organ Transplant Discrimination Prevention Act, Healthy Start Reauthorization Act, Stem Cell Therapeutic and Research Reauthorization Act, EARLY Act Reauthorization, Accelerating Access to Critical Therapies for ALS Act, and the Biosimilar Red Tape Elimination Act passed unanimously as amended in an en bloc vote. The Medication Affordability and Patent Integrity Act also passed in a 16-6 vote.”
  • The American Hospital Association News relates,
    • The Department of Health and Human Services June 17 announced it will provide more than $700 million in funding for initiatives on mental illness, addiction and homelessness. Funding opportunities include $96 million for the Safety Through Recovery, Engagement, and Evidence-based Treatment and Support Program, or STREETS; $223.1 million for comprehensive community-based behavioral healthcare programs; $238.6 million for the 988 Suicide and Crisis Lifeline; $80 million for substance use prevention, treatment and recovery initiatives; and more than $70 million for mental health services and support programs. 
  • Beckers Hospital Review tells us,
    • “The Trump administration has begun enforcing federal information-blocking regulations against healthcare organizations that fail to provide patients with access to and exchange of their electronic health information, Politico reported June 17.
    • “Thomas Keane, assistant secretary for technology policy at HHS, told the publication that the agency has stepped up enforcement of data-sharing requirements as part of broader efforts to improve healthcare accessibility and affordability.
    • “Congress directed HHS to address information blocking through the 21st Century Cures Act, which was enacted in 2016. Rules implementing the law were finalized in 2020, and penalties were established in 2024.” * * *
    • “We have started issuing notices of nonconformity to information blockers,” Mr. Keane said. “We’ve had people come back to us and tell us: ‘Yes, we were information blocking.’” Mr. Keane said healthcare organizations may have financial or competitive incentives not to share patient information, but federal law requires health information to be shared for the benefit of patients.”

From the Food and Drug Administration front,

  • Per an FDA news release,
    • “The U.S. Food and Drug Administration today approved the first generic of Xofluza (baloxavir marboxil) tablets, the first single-dose treatment for acute uncomplicated influenza and prophylaxis in patients 5 years of age and older. Approved in time for the 2026–2027 flu season, this approval reflects the Trump Administration’s commitment to increasing the availability of generic drugs.
    • “Today’s approval marks a meaningful milestone for the treatment of influenza,” said Iilun Murphy, M.D., Director of the Office of Generic Drugs in FDA’s Center for Drug Evaluation and Research. “Expanding patient access to drugs and improving their ease of use are critical public health imperatives, particularly given that influenza alone accounts for millions of illnesses in the U.S. each year.”
    • “Generic baloxavir marboxil tablets may be used for:
      • ‘Treatment of acute uncomplicated influenza in patients 5 years of age and older who have been symptomatic for no more than 48 hours, and who are otherwise healthy or at high risk of developing influenza-related complications; and
      • “Post-exposure prophylaxis of influenza in patients 5 years of age and older following contact with an individual who has influenza.”
  • MedPage Today adds,
    • “The FDA approved oral tebipenem pivoxil (Utebzi) as the first oral carbapenem antibiotic to treat complicated urinary tract infections (UTIs), the agency announced on Wednesday.
    • “Tebipenem pivoxil is indicated for complicated UTIs, including pyelonephritis, caused by the susceptible microorganisms Escherichia coliKlebsiella pneumoniaeEnterobacter cloacae species complex, Klebsiella oxytoca, and Enterococcus faecalis, in adults who have limited or no alternative oral treatment options.” * * *
    • “Tebipenem pivoxil should be available to U.S. patients by the end of 2026, GSK said.”
  • BioPharma Dive tells us,
    • “UniQure, the Netherlands-based biotechnology company, intends to formally ask the Food and Drug Administration to approve its for Huntington’s disease gene therapy now that the two parties are more aligned on the closely watched treatment.
    • “UniQure said Wednesday that, during a recent meeting, FDA staff agreed three years of data gathered from a key trial of the therapy would be enough to support an approval application. As such, the company expects to file one sometime between July and the end of September. The FDA has requested another trial be conducted to confirm the treatment’s effects and, according to the UniQure, the agency wants to make sure both sides see eye to eye on this study’s design before a marketing application gets submitted.”
  • The American Hospital Association News informs us,
    • “The Food and Drug Administration June 16 announced that a nationwide shortage of stereotactic breast biopsy needles is expected to last through the end of March 2027. The FDA said the shortage is due to a manufacturing disruption and that clinical management adjustments may be required for patients needing a breast biopsy. Healthcare providers are recommended to conserve their use of stereotactic breast biopsy needles. The agency said that Hologic issued a customer letter Jan. 2 that said all lots of its Brevera Breast Biopsy System Disposable 9 Gauge Needle were being removed due to a risk of metal and plastic particles being dislodged from the device during use.” 

From the judicial front,

  • Healthcare Dive reports,
    • “OhioHealth has reached a proposed settlement with state and federal regulators over allegations that the Columbus, Ohio-based system strong-armed insurers into anticompetitive contracts.
    • “The deal announced Tuesday voids problematic OhioHealth contracts and prevents the system from seeking such terms in the future, according to the Department of Justice.
    • “OhioHealth, which has maintained its contracting practices are legal, did not have to admit wrongdoing as part of the settlement. The system also will not pay any penalties or fines.”
  • Fierce Healthcare tells us,
    • “The Pharmaceutical Care Management Association has joined some of the nation’s largest pharmacy benefit managers in challenging Tennessee’s new law governing the industry.
    • “The Volunteer State’s new policy would prevent PBMs from also owning or being affiliated with pharmacies operating in the state. State lawmakers argue that the law would bring greater transparency and fairness to the market, particularly to support independent pharmacies.
    • “CVS Health, parent company of “Big Three” PBM Caremark, was the first to sue over the law in late May, with Express Scripts following suit late last week.”
  • The Wall Street Journal relates,
    • Luigi Mangione will mount a psychiatric defense at his New York state trial for the killing of UnitedHealthcare Chief Executive Brian Thompson, a judge said Wednesday.
    • During a hearing in state court in Manhattan, Judge Gregory Carro said the lawyers discussed the defense strategy at a sealed proceeding earlier this month. The judge said defense lawyers intend to argue that Mangione killed the insurance executive due to an extreme emotional disturbance at the time. * * *
    • The state trial of Mangione, 28 years old, is scheduled to begin on Sept. 8. A psychiatric defense would significantly alter the nature of the trial because his lawyers would acknowledge he killed Thompson, but argue he did it because he was emotionally disturbed. If a jury agrees with that argument, his murder charge would be downgraded to manslaughter, resulting in a shorter potential prison term.
    • Mangione faces headwinds at trial, including a journal found in his backpack that prosecutors will likely use to argue that he planned the murder for months. “Extreme emotional disturbance is about a loss of self-control for which there was a reasonable explanation or excuse,” said Gary Galperin, a former prosecutor in Manhattan who now teaches at Cardozo School of Law. “The classic case is, you come home and find your spouse in bed with someone else.”

From the public health and medical / Rx research front,

  • The University of Minnesota’s CIDRAP reports,
    • “During the most recent respiratory virus season, the risk of hospitalization was higher for influenza than for COVID-19, per a US Department of Veterans Affairs (VA) study of nearly 13,000 patients.
    • “The authors, from the VA Saint Louis Health Care System, noted that while COVID-19 was tied to a substantially greater risk of hospitalization than flu early in the pandemic, data showed an increase in flu cases and hospitalizations in 2025-26 compared with previous seasons.
    • “The findings were published last week in The Lancet Infectious Diseases.
    • “However, population-level metrics reflect both infection frequency and disease severity and cannot alone determine the relative clinical severity of one pathogen versus another,” they wrote. “A head-to-head comparison of hospitalisation risk among infected individuals—which isolates disease severity from differences in infection frequency—has not been undertaken for the 2025–26 influenza season.”
  • Health Day relates,
    • “Folks are told that once you start taking Ozempic or Zepbound, you’ll need to stay on them to maintain the drugs’ benefits.
    • “But patients prescribed such GLP-1 drugs are more likely to stop them and then restart use later than was previously assumed, according to research presented Sunday at the Endocrine Society’s annual meeting in Chicago.
    • “We found that about 4 in 10 patients stopped their GLP-1 medication within the first year, and nearly 6 in 10 had stopped by the end of two years,” based on insurance records from more than 60,000 Americans with type 2 diabetes, said study investigator Sainikhil Sontha. He’s a research associate at Boston University School of Public Health.
    • “However, not everyone who stopped taking their GLP-1 remained off it.
    • “More than half of those who stopped restarted therapy within a year (42%), and nearly two-thirds did so within two years (58%),” Sontha said in a university news release. “This suggests that for many patients, these medications aren’t being abandoned permanently; use is more start-and-stop than most people assumed.”
  • and
    • Solid organ transplant survival is improving, but organ shortages persist, according to a study published in the July issue of the Journal of the American College of Surgeons.
  • and
    • “At-home blood pressure monitoring can lower risk of heart attack and stroke
    • “People participating in a remote monitoring program had a 34% lower risk of heart attack, stroke and heart disease
    • “Their readings were forwarded to a doctor, who kept tabs on their blood pressure.”
  • The Washington Post lets us know,
    • “As a doctor, I tell people to do these 4 things to reduce age-related muscle loss
    • “Resistance training, protein and recovery remain the most powerful tools for preserving strength and independence later in life.”
  • The latest NIH Research Matters covers the following topics:
    • Immune system may attack nervous system in some Long COVID patients
      • “Researchers linked antibodies that attack the body’s nervous system to some neurological symptoms of Long COVID.
      • “The results may point to possible treatments for some people with Long COVID.”
    • Depression screening using video games
      • “A study suggests that the unconscious way the brain assesses rewarding experiences is miscalibrated in patients with depression. 
      • “Game-like tasks to measure this mechanism could help doctors screen patients more quickly for depression.”
    • AI tool could speed antibiotic development
      • “Researchers developed and tested a system to improve the antibacterial effects of existing compounds.
      • “This system could help quickly create new antibiotics to overcome antibiotic resistance.”

From the U.S. healthcare business and artificial intelligence front,

  • The Wall Street Journal delves into state of the U.S. healthcare business.
  • Beckers Hospital Review ranks 40 health systems based on their first quarter 2026 operating margins, and tells us,
    • “Nashville, Tenn.-based Ascension Saint Thomas has broken ground on a $148.5 million hospital and healthcare campus in Clarksville, Tenn., expanding its presence in one of the state’s fastest-growing regions. 
    • “The 96-acre campus will include a full-service hospital that will open with 44 inpatient beds and expand to 132 beds as demand grows. The hospital will be St. Louis-based Ascension’s 19th in Tennessee, according to the health system’s website
    • “The hospital will offer emergency care, inpatient surgery, cardiology, neurosciences, women’s health, neonatal intensive care, oncology and orthopedic services. The broader campus will also feature physician offices, an inpatient rehabilitation hospital, outpatient surgery, advanced imaging and specialty ambulatory care services.”
  • BioPharma Dive informs us,
    • “Jazz Pharmaceuticals is enlisting the help of AbCellera in a bid to develop next-generation T-cell-engaging medicines to treat solid tumors.
    • “As part of a deal announced Wednesday, Jazz will pay AbCellera $56 million up front in exchange for discovery work and early-stage preclinical research on two programs. AbCellera also committed to start a third discovery program within 12 months, which will trigger another $28 million payment, and may undertake two additional projects if both companies agree.
    • “If Jazz exercises options for development, AbCellera could earn as much as $792 million more per program in fees and payments for reaching certain development, regulatory and commercial milestones. AbCellera would also be eligible for royalties, should any approved medications come out of the collaboration.”
  • Fierce Healthcare points out,
    • “Fitness wearable company Whoop announced Wednesday a partnership with health platform HealthEx that allows users to connect their medical records directly within the Whoop app, combining medical history with biometric data.
    • “The companies say the partnership “responds to a growing need” for “more connected health experiences” for users. The new integration allows various factors—such as chronic conditions, recent procedures and more—to be considered alongside tracking metrics, like performance and sleep. 
    • “Whoop has always focused on turning data into meaningful insights,” said Alex Vannoni, Whoop’s head of healthcare product, in a statement. “This partnership extends that approach by bringing medical history into the Whoop experience, giving members a more complete view of their health and enabling even more personalized, relevant coaching, grounded in who they are, not just what happened on a given day.”
    • “The integration is enabled by the Whoop AI and My Memory features. The artificial intelligence-driven My Memory feature, announced last month, allows users to provide context to manage personalized coaching.”
  • Beckers Payer Issues notes,
    • “Payers often work with employers, but they have to keep their own staff happy, too. 
    • “Amid a climate of payers across the country cutting jobs, Centene recently confirmed it is offering buyouts to most employees as its ACA business contracts. Against that backdrop, employee morale and retention have become pressing priorities for health plan leaders.
    • Becker’s spoke with Sidecar Health’s chief people officer, Alex Coonce, and Elevance Health’s chief human resources officer and executive vice president, Ryan Craig, to learn about the biggest concerns for today’s health plan employees — and how each company is tackling them.”

Monday report

From Washington, DC,

  • The Washington Post reports,
    • “President Donald Trump on Monday announced that about 600 low-cost generic drugs would be available through TrumpRx.gov, a government website aimed at helping Americans purchase medications at discounted prices. 
    • “By incorporating this massive catalog of low-cost generics at TrumpRx.gov, consumers will now have one source to ensure that they’re getting the lowest possible cost on their prescription,” Trump said in a presentation at the Eisenhower Executive Office Building.”
  • Federal News Network relates
    • “HHS sends RIF notices to dozens of staff it missed during office-wide layoffs last year.
    • “Meanwhile, HHS is looking to convert hundreds of senior positions to a rebranded version of the “Schedule F” classification for federal employees.”
  • Per an HHS news release,
    • “The U.S. Department of Health and Human Services (HHS) today announced a reorganization of its Office for Civil Rights (OCR), the Department’s law enforcement agency charged with enforcing laws protecting civil rights, conscience and religious freedom, and health information privacy and security. The reorganization returns OCR to a program-based structure that aligns OCR’s three critical substantive areas with three distinct subject-matter divisions: the Conscience and Religious Freedom Division, the Civil Rights Division, and the Health Information Privacy, Data, and Cybersecurity Division.
    • “This reorganization restores the HHS Civil Rights Division and the Conscience and Religious Freedom Division and strengthens the Office for Civil Rights’ ability to defend religious liberty, enforce conscience protections, and combat unlawful discrimination,” said Health and Human Services Secretary Robert F. Kennedy, Jr. “Under President Trump’s leadership, HHS will defend these rights with clarity, accountability, and resolve.”
    • “This reorganization reinstitutes a structure that rightly prioritizes civil rights and conscience and religious freedom alongside health information privacy and security,” said HHS Office for Civil Rights Director Paula M. Stannard. “All three areas are deserving of subject-matter expertise and distinct senior executive leadership for OCR to best serve the American people.”
  • The American Hospital Association News adds,
    • “Most hospital outreach laboratories must report private payer clinical diagnostic laboratory data for services furnished during the first six months of 2025 to the Centers for Medicare & Medicaid Services by July 31, the agency announced. This includes Healthcare Common Procedure Coding System codes, associated private payer rates and volume data. CMS previously sent letters to hospitals, which the agency believes have outreach laboratories that are likely required to report their data. CMS also has a guide and other resources for hospital outreach laboratories to determine whether and how they must report.” 

From the Food and Drug Administration,

  • The Wall Street Journal reports,
    • AstraZeneca AZN said it received U.S. approval for a new hypertension treatment, getting the green light to launch a drug the U.K. pharmaceutical company expects to generate multibillion-dollar annual sales at its peak.
    • “The drug, known until now as baxdrostat, will be marketed under the brand name Baxfendy, the company said Monday. The approval expands AstraZeneca’s cardiovascular, renal and metabolism portfolio shortly after diabetes drug Farxiga—its biggest product in that therapeutic area and the bestselling medicine in the company’s history—went off patent in the U.S.
    • “AstraZeneca said that Baxfendy treats hypertension in a new way by targeting aldosterone, a hormone that raises blood pressure.
    • “Ruud Dobber, executive vice president of AstraZeneca’s biopharmaceuticals business, said the approval brings a new treatment to a disease that has had little therapeutic progress for the past two decades.”
  • Fierce Pharma relates,
    • “Enhertu’s market conquest is continuing apace. Already tracking at $5 billion in annual sales, the star antibody-drug conjugate from Daiichi Sankyo and AstraZeneca has secured FDA approval to treat early breast cancer, further encroaching on Roche’s Kadcyla territory.
    • “The FDA has simultaneously greenlighted Enhertu for both the neoadjuvant and adjuvant treatment of patients with HER2-positive early breast cancer, the two companies said Friday [July 15, 2026]. The adjuvant nod came nearly two months ahead of schedule, as the FDA had originally targeted a decision by July 7.”
  • The New York Times tells us,
    • “A California dairy company has issued a recall for five ice cream flavors, warning customers that some tubs may be contaminated with metal.
    • “The company, Straus Family Creamery, recalled some of its organic ice cream, which was sold in 17 states since May 4. It said it ordered the recall because of “the potential presence of metal foreign material,” without giving further details.
    • “The warning applies to its vanilla bean, strawberry, cookie dough, Dutch chocolate and mint chip flavors with specific “best-by” dates in late December 2026.
    • “It did not say how many tubs were affected but said the issue was with a “small number of production runs.”
  • Health Day informs us,
    • “The U.S. Food and Drug Administration (FDA) has approved an AI-powered early warning system to detect sepsis, one of the deadliest infections for hospital patients.
    • “The tool, developed at Johns Hopkins University (JHU), detects sepsis hours faster than doctors. It has already reduced deaths by nearly 20% in dozens of hospitals across the United States, JHU reports.
    • “Pre-suspicion screening is what creates lead time, and lead time is what changes outcomes in sepsis,” said Suchi Saria, director of JHU’s AI & Healthcare Lab. “Once a clinician already suspects sepsis, the clock has been running — often for hours or even days.”

From the judicial front,

  • Bloomberg Law reports,
    • “The US Supreme Court turned away appeals from six pharmaceutical companies seeking to topple the Medicare drug price negotiation program that’s led to billions of dollars in discounts on top-selling treatments.
    • “Making no comment, the justices on Monday refused to hear a variety of constitutional arguments against a program created in 2022 by President Joe Biden’s Inflation Reduction Act. The court rejected separate appeals from units of AstraZeneca Plc, Johnson & Johnson, Bristol Myers Squibb Co., Novartis AG, Novo Nordisk A/S and Boehringer Ingelheim Pharmaceuticals Inc.
    • “The rebuffs leave in force a program the US government said in November will produce a 71% discount on Novo Nordisk’s blockbuster Ozempic and Wegovy drugs for Medicare patients starting in 2027. The Trump administration said that round of discounts, covering 15 drugs, will mean $12 billion in savings compared with 2024 list prices.
    • “The cases at the high court involved the previous year’s negotiated discounts, which covered 10 drugs and took effect in January. The Centers for Medicare and Medicaid Services said in 2024 that the deals would reduce out-of-pocket costs by $1.5 billion this year.”
  • Per a Justice Department news release,
    • “A New York man was sentenced today to 37 months in prison for conspiring to launder nearly $1.5 million in illicit health care fraud proceeds through multiple domestic and global banks on behalf of a Transnational Criminal Organization (Organization).
    • “According to court documents, Elnar Zarbailov, 42, of Staten Island, New York, and dual citizen of the United States and Azerbaijan, was a fixer and money launderer for the foreign-based  Organization that spearheaded the largest health care fraud case ever prosecuted by the Department of Justice, as uncovered by Operation Gold Rush. The Organization, based in Russia and elsewhere, orchestrated a multi-billion-dollar health care fraud and money laundering scheme to target, exploit, and steal from Medicare and private health insurance companies.”

From the public health and medical / Rx research front,

  • The Washington Post reports,
    • “The CDC announced Monday that an American tested positive for Ebola this weekend while working in Congo and is being transported to Germany for treatment along with six other Americans who are high-risk contacts. 
    • “The Centers for Disease Control and Prevention also is enhancing public health screening and traveler monitoring amid a growing Ebola outbreak, and non-U.S. passport holders face entry restrictions if they have been to Uganda, the Democratic Republic of Congo or South Sudan in the previous 21 days.
    • “To the American public, the risk to the United States remains low,” said Satish Pillai, CDC Ebola response incident manager. “Travelers to the region should avoid contact with sick people, report symptoms immediately, and follow our travel guidance.”
  • Health Exec points out,
    • “A healthcare research firm that provides trend analysis to stakeholders released a new report that examined usage of behavioral health services post-COVID, showing that demand and utilization for mental healthcare and addiction mitigation have intensified since the pandemic.
    • “According to the data from Trilliant Health, while the utilization of care related to emotional health, mental health, autism, and alcohol and drug dependency stand at new highs since the COVID lockdowns, outcomes may not be improving.
    • “Using publicly available data on utilization, provider numbers and demand, Trilliant’s data paints a picture of a mental healthcare system that is overburdened. From 2018 to 2024, the group reports that the number of behavioral health visits jumped 62.6%, standing at 1,346 visits per 1,000 people.
    • “People seeking care for anxiety led the trend, accounting for 89.3% of growth. Women aged 18-44 made up the majority of that cohort. However, Trilliant noted that childhood developmental disorders—autism, attention deficit disorder, speech problems and other issues including anxiety—including attempted self-harm, have risen nearly 48% over 20 years, from 2004-2024.”
  • Health Day adds,
    • Many older adults see cannabis as a more effective or nonpharmaceutical option to manage sleep, pain, or mental health, according to a study published online May 8 in JAMA Network Open.
    • Rebecca K. Delaney, Ph.D., from the University of Utah Intermountain Health Department of Population Health Sciences in Salt Lake City, and colleagues explored the motivations of older adults in Colorado interested in purchasing edible cannabis products to improve sleep, pain, or mental health concerns, as well as the perceived benefits and drawbacks of different cannabinoid profiles. The analysis included 169 interview participants aged 60 years and older.
  • The New York Times relates,
    • “A study of insurance claims for 1.8 million children found that the number of families raising mental health issues at visits to general practitioners rose sharply over a decade, with anxiety by far the fastest-growing complaint.
    • The study, which was published on Monday in the journal JAMA Network Open, found that the number of pediatric visits rose to 9.7 percent in 2023 from 5.7 percent in 2014.
    • “The study included all insurance claims for children from ages 1 to 18 in Massachusetts, for a total of more than 1.8 million children. Visits were counted as mental health visits if a diagnostic code was included in the claim, either because the child or the family raised the issue or because the child screened positive for mental health symptoms during the visit.
    • “Visits for anxiety rose by more than 250 percent during that period, to 6.1 percent in 2023 from 1.7 percent in 2014.”
  • The American Medical Association lets us know “nine things patients should know about taking creatine.”
    • “The ‘Health vs. Hype’ AMA podcast explores what creatine is, its association with bodybuilders, and whether it’s safe for the general public.”
  • Medpage Today tells us,
    • “A course of azithromycin for preschoolers who presented to the emergency department (ED) with wheezing didn’t improve their symptoms, the AZ-SWED trial showed.
    • :Among children, ages 18-59 months, the 5-day sum of scores on the Asthma Flare-up Diary for Young Children (ADYC) did not differ significantly compared with placebo in either those who initially tested positive for pathogenic bacteria (median 9.59 vs 9.72, P=0.70) or those who tested negative (9.30 vs 9.10, P=0.69). ADYC scores range from 5-35 points, with higher scores indicating more severe symptoms.
    • “While the trial was stopped early for futility — reducing the statistical power of the trial — it was sufficient to show that “a moderate or large true effect is implausible,” Richard M. Ruddy, MD, of the University of Cincinnati College of Medicine, reported at the American Thoracic Societyannual meeting in Orlando. The findings were published simultaneously in the New England Journal of Medicine.”
  • and
    • “The 2025/2026 seasonal COVID vaccination was associated with a roughly 50% reduced risk for illness up to 9 weeks post-vaccination, especially in older Canadian adults, according to an interim analysis by the Canadian Sentinel Practitioner Surveillance Network. The seasonal vaccine, which was specifically formulated to target the LP.8.1 variant, also appeared to offer protection from other strains.
    • “An important aspect of the 2025/2026 season was the simultaneous circulation of influenza and other respiratory viruses, which suggested the need to consider the role that respiratory virus co-circulation might play in estimating vaccine effectiveness (VE).
    • “This year, we were especially interested to check the effects of co-circulating respiratory viruses (eg, influenza and respiratory syncytial virus [RSV]) since COVID circulated at only low levels through the current season,” lead author Danuta M. Skowronski, MD, epidemiology lead for influenza and emerging respiratory pathogens at the BC Centre for Disease Control in Vancouver, told Medscape News Canada.”
  • The American Journal of Managed Care points out,
    • “A retrospective VA cohort (2006–2019) compared ≥75-year-olds with adenoma vs no adenoma at ages 65–75 using registry and National Death Index outcomes. 
    • “Ten-year CRC incidence and CRC death were statistically higher with prior adenoma, but absolute differences were small and clinically overshadowed by competing non-CRC mortality. 
    • “Frailty stratification showed progressively lower CRC incidence and sharply higher non-CRC death, with severe frailty demonstrating <1% CRC versus 82% non-CRC death. 
    • “Advanced adenoma status did not significantly alter CRC risk, and follow-up colonoscopy rates after 75 were not higher among patients later developing CRC. 
    • “Generalizability is limited by a 98% male veteran population, reinforcing the need for confirmatory analyses in cohorts with greater female representation.”
  • Per BioPharma Dive
    • “An experimental cancer immunotherapy from Regeneron failed a late-stage study in melanoma in a surprise setback for the big biotechnology company’s oncology business.
    • “A regimen involving the prospect, fianlimab, and Regeneron’s marketed medicine Libtayo didn’t significantly delay cancer progression compared to Merck & Co.’s Keytruda in patients with unresectable metastatic melanoma. A high-dose combination held tumors in check for a median of 11.5 months, compared to 6.4 months for Keytruda recipients, a difference that narrowly missed statistical significance.
    • “Regeneron didn’t provide additional details but will present them at a future medical meeting. Another Phase 3 study testing fianlimab against Opdualag, a similar cancer immunotherapy sold by Bristol Myers Squibb, is ongoing. Company shares fell by double digits early Monday, erasing billions of dollars in market value.”

From the U.S. healthcare business front

  • Kauffman Hall reports,
    • Key Takeaways
      • March was the best month for hospitals in 2026 so far, despite mixed volumes. Month-over month discharges rose while patient days fell, indicating increased focus on improving average length of stay and a continued shift to outpatient care.
      • Operating margins improved month-over-month but remain below 2025. While bad debt and charity care declined month-over-month, gross revenue continues to outpace net, highlighting eroding payor mix.
      • Expenses declined in March, yet remain elevated year-over-year. Favorable improvements across the board are likely correlated to the decrease in average length of stay. However, drug expenses remain a primary driver of expense growth year-to-date.
      • Two notable outliers emerged in otherwise steady regional trends. The Northeast saw margin improvement, despite historical underperformance, while the West experienced the most dramatic increase in drug expense.
    • To view more insights on trends affecting hospitals and steps you can consider taking to address them, download the latest issue of the National Hospital Flash Report.
  • Beckers Payer Issues notes,
    • “Blue Cross and Blue Shield of Massachusetts reported a net income of $59.6 million in the first quarter of 2026, a return to profitability after back-to-back annual losses in 2024 and 2025.
    • “The insurer posted revenue of $2.6 billion in the first quarter, reflecting a 2% net margin. Operating and other income came in at $17.4 million (0.6% operating margin), with investment income contributing $42.2 million.
    • “The company attributed the improved results to disciplined cost management, a milder-than-expected flu season and changes to its coverage of GLP-1 medications.
    • “Our first-quarter results reflect the challenging but necessary actions we’ve taken over the past year, including pricing our benefit plans to their true cost, identifying medical and pharmacy spending that doesn’t add value for our members, and keeping rate increases to our provider network at or below the state benchmark,” CFO Ruby Kam said May 15.”
  • Fierce Healthcare relates,
    • “Now three quarters into its fiscal year, Ascension has chopped down its operating losses by more than half and more than tripled its bottom-line gain. 
    • “The nonprofit system reported Friday a $203 million operating loss (-1.1% operating margin) for the nine months ended March 31, 2026, improving on the $466 million operating loss (-2.3%) for the prior fiscal year. 
    • “Both its total operating revenue and operating expenses dipped from the prior year due to a slew of divestitures. The former declined by 7.2% to $18.1 billion while the latter fell by 8.1% to $18.3 billion; on a same-facility basis, total operating revenue grew 9.3% while expenses increased 5.7%.” 
  • Healthcare IT News explains “How one practice combines in-clinic, telehealth and in-home care.”
    • “Dr. Payam Zamani is a practicing family medicine physician and founder and CEO of My Dr Now, one of the largest primary care providers in the Southwest. It’s designed as a hybrid in-person/telehealth/in-home health system.”
    • “When patients engage earlier and follow through consistently, the health system operates more efficiently, My Dr Now’s physician CEO reports: “This is not about technology for its own sake, it’s about designing care delivery around real life.”
  • Modern Healthcare tells us,
    • “Oregon gave the green light for Compassus to acquire a 50% stake in Providence’s home health and hospice operations across the state.
    • “After more than a year of review, Oregon Health Authority’s Health Care Market Oversight program said in a Friday news release it approved the joint venture with conditions.
    • “The Oregon deal is expected to close in the fall, Providence said in an email.”
  • and
    • “RWJBarnabas Health has opened a $7 million food-is-medicine hub to take on chronic disease, making it a potential standard bearer in the Make America Healthy Again movement.
    • “Last week, the New Jersey academic health system opened Harvest — an 8,000-square-foot facility in Newark that is a combination food bank, commercial kitchen and classroom. The center is designed to teach people living in nearby food deserts how to eat healthier and provide them with the food to do it.”
  • Health System CIO informs us,
    • “Epic added 77 acute care hospitals in 2025 while Oracle Health shed 56, according to the new KLAS report, “US Acute Care EHR Market Share 2026.” The five-year picture is even starker. Epic has gained a net 568 hospitals since 2021 while Oracle Health has lost 173. In total, the report covers EHR contracts executed from January through December 2025. Epic now holds 43.7% of acute care hospital market share and 56.9% of beds. Oracle Health, meanwhile, sits second at 21.9% of hospitals and 20.4% of beds, followed by Meditech at 14.7% and 12.5%.” * * *
    • “Hospitals impacted by EHR decisions fell about 40% from 2024 as buyers shifted investment toward AI and operational efficiency tools.”
  • Per MedTech Dive,
    • “Boston Scientific said Monday it has invested $1.5 billion to acquire a 34% equity stake in MiRus, a company developing a balloon-expandable transcatheter aortic valve replacement system.
    • “The agreement gives Boston Scientific an exclusive option to acquire the MiRus TAVR system, subject to additional payments and the completion of certain clinical and regulatory milestones. Boston Scientific said it may opt to acquire the rest of the TAVR business for additional cash payments totaling $3 billion.
    • “The deal comes about a year after Boston Scientific stopped selling its Acurate Neo2 and Acurate Prime TAVR devices, which were CE-marked in Europe, and ended plans to pursue approvals in the U.S. and other locations.”

Monday report

From Washington, DC,

  • Tomorrow at 11 am ET, the House Appropriations Committee will consider its subcommittee’s print of the appropriations bill for financial services and general government, including the Office of Personnel Management for the fiscal year ending September 30, 2027.
  • The subcommittee’s print includes the standard appropriations provisions exempting FEHB and PSHB carriers from full Cost Accounting Standards coverage (Sec. 611) and limiting abortion coverage to cases when carrying the fetus to term would endanger the mother’s life or the pregnancy results from rape or incest (the Hyde amendment, Secs. 613, 614). The bill (Sec. 761) also states “None of the funds made available by this Act, or in any previous appropriation, may be provided for in insurance plans in the Federal Employees Health Benefits program to cover the cost of surgical procedures or puberty blockers or hormone therapy for the purpose of gender affirming care.” The bill no longer includes the contraception mandate that OPM treated as overridden by the ACA’s contraception mandate. 
  • Federal News Network reports,
    • “The Office of Personnel Management and the General Services Administration — the federal government’s human resources office and landlord, respectively — are embarking on plans to move under one roof.
    • “GSA will temporarily relocate to OPM’s headquarters, the Theodore Roosevelt Federal Building, starting in July, while GSA’s 1800 F St. headquarters goes through a renovation.
    • “In December 2028, GSA will move back into its renovated headquarters, along with OPM. Once consolidation is complete, GSA says it will initiate an “accelerated disposal” of OPM’s old headquarters building.” * * *
      “The first Trump administration proposed merging OPM and GSA into a single agency, but ultimately walked away from those plans. In addition to managing a governmentwide real estate portfolio, GSA provides contracting and IT support to other federal agencies.
    • “OPM Director Scott Kupor said there are no talks of a possible merger of the two agencies.”
  • and
    • “House and Senate Democrats are urging the Office of Personnel Management to halt its plans for collecting detailed medical data on potentially millions of enrollees in the government’s health insurance programs.
    • “Citing “significant legal, ethical and security concerns,” two recent letters sent to Trump administration officials identified potential legal violations and the possibility of targeting enrollees across the Federal Employees Health Benefits (FEHB) and Postal Service Health Benefits (PSHB) programs.
    • “The collection of broad, personally identifiable data regarding medical care and treatment raises concerns that OPM could target certain federal employees seeking vital health care services that the administration disagrees with on political grounds,” House Democrats on the Oversight and Government Reform Committee wrote in an April 17 letter, addressed to OPM and the Office of Management and Budget.
    • “This proposal is another step in the stated goal of traumatizing the federal workforce,” Senate Democrats, led by Sens. Adam Schiff (D-Calif.) and Mark Warner (D-Va.), wrote in a separate April 19 letter to OPM Director Scott Kupor. “We are deeply concerned this information will be used in employment actions, including actions related to hiring, suitability determinations, appeals, reductions in force, disability accommodation requests, labor-management relations and performance reviews.”
  • Roll Call adds,
    • “Senate Republicans plan to release their budget resolution and take a procedural vote as early as Tuesday, kicking off the cumbersome process for a reconciliation bill designed to help end the partial shutdown of the Department of Homeland Security.
    • “Senate Majority Leader John Thune, R.S.D., said Monday he hopes to confine the bill to the narrow mission of funding Immigration and Customs Enforcement and the Border Patrol. “
  • HR DIve relates,
    • “Secretary of Labor Lori Chavez-DeRemer resigned on Monday, she confirmed in a post to her official X account, ending her tenure after just over one full year leading the U.S. Department of Labor.
    • “Chavez-DeRemer’s departure followed recent reports that the agency’s inspector general had launched an investigation into her potential misconduct, including contact between her family and department staff. Similar previous inquiries reportedly led to the departure of employees including Chavez-DeRemer’s chief of staff and deputy chief of staff.
    • “Chavez-DeRemer said in her post Monday that under her watch, DOL “created new pathways to mortgage-paying jobs, prepared workers to excel in the age of AI, took steps to lower prescription drug costs, promoted retirement security, and so much more.” A White House spokesperson did not immediately respond to a request for comment.”
  • The American Hospital Association News tells us
    • “Centers for Medicare & Medicaid Services Administrator Mehmet Oz, M.D., and CMS Deputy Administrator and Director of Medicaid and CHIP Dan Brillman sat down with Bill Gassen, president and CEO of Sanford Health and AHA chair-elect, for a discussion about the changes that have occurred in CMS in the past year, as well as how they intend to move forward.  
    • Oz described the agency’s focus this year on working with insurers to reduce the need for prior authorizations. In addition, both Oz and Brillman spoke on the agency’s drive to reduce unnecessary spending; Oz estimated that 5% of CMS’ budget, or about $100 billion, is lost to fraud, waste and abuse.  
    • “Brillman spoke on the new community engagement standards that require most Medicaid recipients to perform a certain number of employment or volunteer hours to maintain their eligibility for benefits, which Brillman said provides “paths to prosperity” for beneficiaries, saying, “if we get someone a higher income so they no longer need services, that’s a win for all Americans.” 
    • “Technology, especially the use of artificial intelligence, was also acknowledged as an important advancement, with Oz saying that current technology offers “a generational opportunity to fix health care,” noting that “I do not see a way to make health care as great as it could be without AI.”  
    • “Oz spoke on last year’s Rural Health Transformation Fund, saying that the infusion of $50 billion over five years will have nationwide effects. “The learnings will accrue to urban centers,” he said. “[The fund] is creating a sandbox in rural areas, and what you learn will benefit all of you.” 

From the public health and medical / Rx research front,

  • Health Day reports,
    • “Reaching for the salt shaker could have long-lasting implications for your memory and brain health, a new study says.
    • “Higher sodium intake appears to affect episodic memory, the type of memory used to recall personal experiences and specific events from your past, researchers report in the June issue of the journal Neurobiology of Aging.
    • “This effect – which could cause one to forget anything from where they parked the car to their first day of school – occurred mainly among men, researchers found.
    • “No such associations were observed among women in the study, researchers said.”
  • The American Medical Association lets us know seven things patients should know about protein maxxing.
  • Healio relates,
    • “Prescriptions for direct-acting antivirals to treat hepatitis C virus in the U.S. have declined substantially since 2015 and remain well below the approximately 260,000 annual treatment courses needed to meet the target for elimination.
    • “Results of a national cross-sectional analysis showed annual treatment volume trending alongside HCV infection rate, rather than surpassing it.
    • “We’re roughly treating the same number of people each year as there are new infections,” Sanjay Kishore, MD, assistant professor at University of Virginia School of Medicine, told Healio. “We’re essentially just holding steady and not actually making any progress.” * * *
    • “I think we need to think creatively about using things like mobile clinics to take care of people. We need to really lean into telehealth on this issue, and we need to expand screening to places where people are getting addiction treatment. Maybe instead of a hospital, it’s a rehab facility or a syringe exchange. We need to make it easier to connect with clinicians and get treatment to meet people where they are.”
  • MedPage Today tells us,
    • “Adults whose type 2 diabetes was treated with GLP-1 receptor agonists were more than likely to develop cognitive impairment over 10 years than their counterparts not treated with GLP-1 agents, a propensity-matched retrospective study of nearly 65,000 patients suggested.”
  • and
    • “Lower hemoglobin levels were linked with higher dementia risk over 9 years of follow-up.
    • “Anemia was associated with elevated Alzheimer’s blood biomarkers including p-tau217 and neurofilament light chain.
    • “Dementia risk was highest when anemia coexisted with abnormal Alzheimer’s biomarkers.”
  • BioPharma Dive offers news from the annual meeting of the American Association for Cancer Research and informs us,
    • “An experimental autoimmune drug from Nektar Therapeutics helped people with alopecia areata who’d already responded to the treatment in a Phase 2 trial grow more hair as time went on, the company said Monday.
    • “The data released Monday measured hair regrowth after 52 weeks of treatment with the therapy, known as rezpegaldesleukin. Nektar disclosed last year that the therapy failed to show a statistically significant benefit over a placebo after 36 weeks. The company, though, blamed that result on the inclusion of four patients that shouldn’t have been eligible and said the findings supported additional development.”
  • Fierce Pharma points out,
    • “Sanofi’s protein-based vaccine Nuvaxovid has conquered Moderna’s next-generation messenger RNA shot mNexspike in a head-to-head trial assessing the tolerability of the two COVID vaccines.
    • “In the phase 4 double-blind, real-world study, which included 1,000 adult participants in the United States, Nuvaxovid showed statistically significant fewer side effects across all pre-specified endpoints.
    • “Symptomatic reactions with Nuvaxovid were both milder and shorter than with mNexspike. Additionally, less than 10% of those who received Nuvaxovid experienced severe side effects—such as fatigue, headache or fever which prevented them from conducting their daily activities—compared to 20% of those who got mNexspike. As for injection site symptoms such as pain, redness and swelling, they were more than 75% more frequent for those who received Moderna’s shot.”

From the U.S. healthcare business front,

  • ‘Per a Lockton news release,
    • “Lockton’s eighth annual survey of over 1,700 U.S. employers helps employers compare their benefit strategies with those of other employers -providing benchmark data, highlighting trends, and illuminating new ideas.
    • “As healthcare costs rise and economic pressures mount, cost is a defining reality for employers. The 2026 Lockton National Benefits Survey shows a rapid acceleration of a shift that first took hold last year – cost management decidedly the top priority vs the next ranked priority – attracting and retaining talent. The data shows how employers are searching for an answer to their need for cost containment solutions.
    • “To gain further insights into the 2026 survey findings, you can access the executive summary here.”
  • The Peterson / KFF Health System Trackers identifies recent trends in employer-based health coverage.
    • “Key takeaways include:
      • “In March 2025, 60.0% of the non-elderly, or about 165.6 million people, had employer sponsored insurance or ESI. 
      • “About four in five (80.4%) adult non-elderly workers worked for an employer that offered ESI to at least some employees, a share that has been consistent over recent years. 
      • “The share of workers eligible for ESI at their job declined slightly over the past few years, from 75.3% in March 2023 to 74.6% in March 2025. 
      • “Most eligible workers who do not take up ESI offered at work cite other coverage (63.0%) and cost (30.2%) as the reason.”  
  • Beckers Hospital Review tells us,
    • “As more care shifts outside hospital walls, health system leaders are rethinking how they plan, staff and structure their workforces to support a rapidly expanding ambulatory footprint.
    • “Outpatient services accounted for 57% of hospital revenues in 2024, up from 52% in 2020, according to the American Hospital Association. The AHA’s Sg2 forecasting model projects outpatient volumes will grow another 17% over the next decade. At the same time, many health systems are accelerating ambulatory investments in 2026 to support financial sustainability and expand access closer to home.”
  • MedCity News notes that “Expanding the CJR Model Is a Logical Step in Value Based Care, but Implementation Challenges Remain.”
    • “CMS is proposing to make its joint replacement bundled payment model mandatory nationwide. Experts say it is a logical step, but warn that mandatory participation could be challenging for hospitals to implement.”
  • Healthcare Dive relates,
    • “Physician burnout continues to decline across the U.S., a bright spot for an occupation plagued by heavy workloads, pervasive stress and high stakes. But the improvement is not equal across medical specialties, according to new data from the American Medical Association.
    • “The AMA surveyed thousands of physicians and found that 41.9% reported experiencing a burnout symptom in 2025, down from 43.2% in 2024 and 48.2% in 2023. The decline likely reflects employer efforts to reduce burnout, including by increasing job satisfaction, the medical association said.
    • “However, burnout rates vary significantly across specialties, and tend to be higher among doctors employed by hospitals, suggesting health systems could be doing more to ameliorate the phenomenon.”
  • Fierce Healthcare informs us,
    • “UnitedHealthcare is building on its work to support rural hospitals and will now exempt these facilities from most prior authorizations.
    • “The insurance giant said in an announcement on Monday that the shift will apply across all lines of business. In addition, UHC will accelerate payments by up to 50% for about 1,500 rural hospitals and all critical access hospitals across the country.”
  • and
    • “Just over two years ago, Highmark joined forces with Spring Health to launch a new mental well-being platform that made it far easier for members to access critical services.
    • “Now, the partners are offering a look at how that program has worked for members. In a paper published last month, researchers at Highmark reported that patients waited less than two days on average in 2025 to access an appointment.
    • “Spring’s platform is embedded directly into Highmark’s member app, and that integration was a key part of what made the program work, according to the analysis. Members can easily find mental well-being tools and complete a self-assessment upon connecting for the first time, which allows Spring to build a personalized approach.”
  • The Wall Street Journal points out,
    • “Eli Lilly struck a deal to acquire Kelonia Therapeutics for $3.25 billion upfront and up to $7 billion if certain milestones are reached. 
    • “Kelonia is developing a next-generation CAR-T therapy for multiple myeloma, which promises to transform treatment without chemotherapy.
    • “The acquisition positions Eli Lilly to enter a lucrative segment of the global cancer-drug market and bolster its cancer offerings.”
  • MedTech Dive adds,
    • “Medtronic said Monday it has closed the acquisition of CathWorks, a deal worth $585 million with potential undisclosed earn-out payments.
    • “The transaction, agreed to in February, continues a strategy of increasing acquisitions to strengthen the company’s leadership in its core businesses, Medtronic said.
    • “CathWorks’ FFRangio system uses artificial intelligence and computational science to assess the entire coronary tree from routine angiograms that image the blood vessels.”

Midweek update

From Washington, DC,

  • OPM Director Scott Kupor added another post to his excellent Secrets of OPM blog today. This one is titled “Simplicity is a Virtue.” In the FEHBlog’s opinion, OPM should focus on simplifying its administration of the FEHB and PSHB programs.
  • The FEHBlog noticed on the following rulemakings currently under Office of Management and Budget review:
  • The FEHBlog is concerned about the OPM rule because OPM has not implemented the HIPAA 820 electronic enrollment roster transaction that would allow carriers to reconcile individual enrollees with their premiums. What is the sense of having a pristine family member list without knowing whether the enrollee is paying the correct premium. The HIPAA 820 also would give carriers earlier notice about enrollees who have left federal employment and annuitants who have passed away.
  • Per an HHS news release,
    • “The U.S. Department of Health and Human Services (HHS) today announced the 2026 KidneyX EMPOWER Prize Challenge, a $4 million national competition to accelerate innovation supporting living kidney donors and patients who depend on them. To further enhance nephrology care, HHS will also support data standardization and health information technology improvements across the kidney care ecosystem. The challenge will be run through the Kidney Innovation Accelerator (KidneyX).”
  • The Wall Street Journal reports,
    • “One in seven people who signed up for Affordable Care Act plans this year failed to pay after premium costs rose sharply, according to an analysis that provides the first comprehensive look at the impact of expiring federal subsidies
    • “Nationally, around 14% of those who enrolled in ACA plans this year didn’t pay their first monthly bill for January coverage. In some states, the share was a quarter or more, according to a new analysis from the actuarial firm Wakely Consulting Group, provided exclusively to The Wall Street Journal.
    • “It’s a big drop,” said Michelle Anderson, a Wakely consulting actuary. 
    • “Normally, the rate of falloff in ACA plan membership early in the year is in the midsingle-digit range.”

From the Food and Drug Administration front,

  • The Washington Post reports,
    • “The Food and Drug Administration is taking the first step toward potentially allowing compounding pharmacies to produce seven peptides that are currently restricted because of the agency’s previous warning over safety concerns.
    • “The agency’s expert advisory panel on pharmacy compounding is scheduled to discuss whether the peptides should be used in compounding for purposes for ulcerative colitis, wound healing, inflammatory conditions, obesity, insomnia and more, according to a Federal Register notice posted Wednesday announcing a late-July meeting.”

From the judicial front,

  • Bloomberg Law reports,
    • “A federal appeals court vacated an order rejecting a request to block a Maryland drug discount law, remanding the decision for review, in a victory for AbbVie Inc., Novartis AG, AstraZeneca Plc, and PhRMA.
    • “The US Court of Appeals for the Fourth Circuit ruled that a lower court “erred” when it denied the drugmakers’ motion for a preliminary injunction against Maryland’s H.B. 1056.
    • “The decision was driven by a recent order from the Fourth Circuit that upheld a block on West Virginia’s version of the contract pharmacy law, with the majority opinion stating that “West Virginia passed a materially similar statute, which this Court recently held is likely preempted”.

From the public health and medical / Rx research front,

  • The New York Times reports,
    • “Many scientists have contended that humans have evolved very little over the past 10,000 years.
    • A few hundred generations was just a blink of the evolutionary eye, it seemed. Besides, our cultural evolution — our technology, agriculture and the rest — must have overwhelmed our biological evolution by now.
    • “A vast study, published on Wednesday in the journal Nature, suggests the opposite. Examining DNA from 15,836 ancient human remains, scientists found 479 genetic variants that appeared to have been favored by natural selection in just the past 10,000 years.
    • “The researchers also concluded that thousands of additional genetic variants have probably experienced natural selection. Before the new study, scientists had identified only a few dozen variants.
    • “There are so many of them that it’s hard to wrap one’s mind around them,” said David Reich, a geneticist at Harvard Medical School and an author of the new study.” * * *
    • “Nandita Garud, a geneticist at the University of California, Los Angeles, who was not involved in the new study, said that unearthing natural selection over the past 10,000 years could do more than just illuminate our deep history.
    • “Scientists still don’t know much about how genetic variations influence our health. When they find a link between a genetic variant and a disease, Dr. Garud said, it will be important to see whether it has been favored by natural selection.
    • “That might give you a clue that this is important,” she said.”
  • The Wall Street Journal relates,
    • “Vertigo and dizziness, often caused by dislodged inner-ear crystals (BPPV), are common age-related problems increasing fall risk.
    • “Emergency-room visits for vertigo commonly result in unnecessary diagnostic tests and sedative medications, potentially worsening patient outcomes.
    • “Researchers are investigating links between BPPV and migraines, low vitamin D, and osteoporosis, while developing new rehabilitation treatments.”
  • Fierce Healthcare tells us,
    • “Behavioral health utilization increased substantially from 2018 to 2024, with anxiety disorder care fueling much of that growth, according to Trilliant Health. 
    • “The health data analytics and market research firm’s latest report outlines a 62.6% jump in behavioral health utilization, based on any visit associated with a behavioral health diagnosis code.
    • “Between 2008 and 2024, the prevalence of mental illness increased by almost 6 percentage points. About a quarter of adults had any mental illness in 2024, Trilliant found, though in adults 18-25 exhibit the highest prevalence both in terms of any mental illness (33%) and serious mental illness (16%). 
    • “Anxiety disorders accounted for the highest visit volume and experienced the fastest growth, up 89% from 2018 to 2024. Anxiety disorders in women aged 18-44 were also the highest utilization category in 2024. 
    • “It’s possible those figures are increasing because more screening is happening, acknowledged Trilliant Health Chief Research Officer Allison Oakes, Ph.D.”
  • Medscape adds,
    • “Utah’s pilot program using AI for psychiatric medication refills raises safety and compliance concerns. Critics argue it lacks transparency, proper research, and may violate FDA laws, emphasizing the need for licensed physician oversight.”
  • Genetic Engineering and Biotechnology News informs us,
    • “Studying mice, researchers at Toronto’s Sinai Health have found that semaglutide—the active ingredient in popular weight loss drugs that mimic the gut hormone GLP-1—acts directly on a subset of liver cells to improve organ function, and does so independently of weight loss. The finding challenges long-held assumptions about how GLP-1 medicines work in the liver and could reshape how physicians treat metabolic liver disease.
    • “Headed by Daniel Drucker, MD, a senior investigator at the Lunenfeld-Tanenbaum Research Institute, the team reported on their findings in Cell Metabolism, in a paper titled “The weight-loss-independent hepatoprotective benefits of semaglutide are orchestrated by intrahepatic sinusoidal endothelial GLP-1 receptors.”\
  • Per Multiple Sclerosis News,
    • “People with diabetes are significantly more likely — with nearly 60% higher odds — to develop multiple sclerosis (MS) than those without the metabolic disease, which is marked by high blood sugar levels, according to a new systematic review and meta-analysis.
    • “A significant association was also observed specifically between type 2 diabetes, the most common form of the condition, and MS risk.
    • “The analysis did not, however, find clear evidence that MS increases the likelihood of developing diabetes.
    • “Current evidence indicates that [diabetes mellitus], specifically [type 2 diabetes], increases the risk of developing MS,” the researchers wrote. “However, a reverse association remains unconfirmed.”
  • Per MedPage Today,
    • “Primary care patients educated about Alzheimer’s disease blood-based biomarkers were generally willing to undergo tests and supported their use, survey data showed.
    • “After patients received a brief explanation of Alzheimer’s blood tests, 94.5% supported offering them to patients with memory complaints, and 85% said they were willing to complete a test if their clinician recommended it, reported Andrea Russell, PhD, of Northwestern University Feinberg School of Medicine in Chicago, and co-authors.
    • “Patients endorsed Alzheimer’s blood tests when they informed medical care (94.2%), were covered by insurance (93.4%), if comprehensive education was received prior to testing (88.5%), and if testing was easy or convenient (88.1%), Russell and colleagues wrote in Alzheimer’s & Dementiaopens in a new tab or window.”
  • Healio adds,
    • “High vitamin D levels in mid-life were associated with lower levels of tau protein in the brain more than a decade later, suggesting a possible modifiable risk factor for Alzheimer’s disease, according to findings in Neurology Open Access.
    • “Previously, it was known that low circulating vitamin D in later life is associated with an increased risk of cognitive impairment and clinical dementia,” Martin D. Mulligan, MBBCh, BAO, a researcher at the University of Galway in Ireland, told Healio.
    • “Most prior studies evaluating the association between vitamin D and cognitive function typically measured circulating vitamin D in older adults,” he continued. What our study adds is a focus on early mid-life.”

From the U.S. healthcare business front,

  • Healthcare Dive reports,
    • “The increasing cost of medical care is driving more workers to forgo needed care or stop taking medications, ADP found in a recently released employee benefits survey
    • “Twenty-six percent of respondents said they’d skipped needed medical care for themselves or a family member due to out-of-pocket costs (compared to 21% in 2020), 22% have stopped taking or taken less medication (compared to 17% in 2020), and 15% declined vision or dental insurance so they could afford medical insurance. 
    • “The finding “points to the need for simpler plan design, clearer education and flexible options that reflect different budget preferences,” ADP observed. “Employers can play a stronger role in helping employees make cost-conscious choices without compromising care.”
  • Fierce Healthcare relates,
    • “Average physician pay rose about 3% between 2024 and 2025, from $374,000 to $386,000—outpacing the 2.7% U.S. core inflation rate that rounded out the year, a new annual report from Medscape found.
    • Medscape’s 2026 Physician Compensation Report surveyed 5,916 physicians across more than 29 specialties. Total compensation numbers reflect base salary and incentive bonuses, plus other income sources like profit-sharing contributions, as reported by full-time physicians.
    • “Matthew Wells, Ph.D, a senior director at AGMA Consulting, called 2025 a “return to normalization” for physician compensation in the report and expects “consistency with increases” in the future. Driving factors cited by Wells include physician productivity in seeing more patients and improved technology-driven efficiency. 
    • “Fifty-three percent of all physicians report feeling fairly compensated, as opposed to last year’s report in which only 48% reported fair compensation—what the report notes was the “most dispirited response” it had seen in a decade of posing the question.” 
  • Beckers Hospital Review offers a non-exhaustive list of “32 health systems with strong operational metrics and solid financial positions, according to reports from credit rating agencies Fitch Ratings and Moody’s Investors Service released in 2026.”
  • and lets us know,
    • “The Illinois Health Facilities and Services Review Board approved Ontario, Calif.-based Prime Healthcare’s acquisition of Franciscan Health Olympia Fields (Ill.). 
    • “The 214-bed hospital is expected to transition to Prime on May 1, according to an April 14 news release shared with Becker’s. 
    • “Prime Healthcare entered an agreement in January to acquire the hospital and and Specialty Physicians of Illinois from Mishawaka, Ind.-based Franciscan Alliance. Prime said it plans to offer jobs to “substantially all employees” at Olympia Fields. 
    • “Olympia Fields is set to become Prime’s ninth Illinois hospital and 55th overall. In March 2025, the health system acquired eight Illinois facilities from St. Louis-based Ascension. Prime said that in the first year of ownership, it invested more than $104 million in the eight hospitals to enhance clinical care and operations, modernize infrastructure and expand service lines.” 
  • BioPharma Dive informs us,
    • “Beeline Medicines emerged from stealth Wednesday with plans to develop “precision therapies” for immune diseases, nearly a year after its backer Bain Capital teamed up with Bristol Myers Squibb to give five of the pharma’s experimental medicines a new home.
    • “Beeline’s pipeline is led by the licensed drug afimetoran, a daily oral treatment for systemic lupus erythematosus, a form of lupus, that targets a pair of receptor proteins which are responsible for regulating the immune system. At Bristol Myers, the drug had already been tested in a Phase 1b trial in a different form of lupus. A Phase 2 study is underway and is expected to be completed in the second half of this year, after which Beeline plans to launch “a pivotal development program.”
  • MedTech Dive adds,
    • “Avanos Medical has accepted a $1.27 billion go-private offer from American Industrial Partners, the company said Tuesday. 
    • “AIP agreed to pay a 72.1% premium to Avanos’ closing stock price on Monday. Avanos CEO Dave Pacitti told customers that AIP will back his company to strengthen its competitive position.  
    • “Avanos competes with businesses including Boston Scientific and Cook Medical for the specialty nutrition market, and rivals such as Medtronic and Stryker in the pain management space.”

Friday report

Happy first day of Spring!!

From Washington, DC

  • Roll Call reports,
    • “Senators are sticking around Washington this weekend after a busy week on the Hill highlighted partisan divides, intraparty friction and growing tension between the two chambers. One thing is clear — everyone is ready for spring break.
    • “The Senate has largely been wrapped up in an extended debate on the GOP’s marquee voter ID legislation, dubbed the SAVE America Act. Debate on the bill began Tuesday and is anticipated to extend through the weekend, at least. 
    • “We’re in through this weekend,” Senate Majority Leader John Thune, R-S.D., said on Fox News on Friday morning. “There will be a vote on this bill. We will find out where everybody stands.” * * *
    • “After Senate appropriators of both parties held a face-to-face meeting Thursday with White House “border czar” Tom Homan — some of the first signs of progress in weeks — Thune set a deadline of next week for resolving the DHS funding standoff.”
  • Bloomberg Law relates,
    • “The Trump administration’s Medicare chief said the version of the program run by private insurers doesn’t do enough to control costs, raising questions about how much the US will pay companies in a crucial upcoming rate update.
    • “Chris Klomp, a top health official at the US Centers for Medicare and Medicaid Services, said the private Medicare Advantage program “does not sufficiently have control of costs,” in remarks at a STAT conference in New York on Thursday.”
  • STAT News adds,
    • “President Trump’s Medicare director said Thursday his team is considering a policy that would automatically enroll Medicare beneficiaries into Medicare Advantage plans, a controversial idea that was touted in the conservative Project 2025 policy blueprint. 
    • “Chris Klomp said the Centers for Medicare and Medicaid Services is mulling the feasibility of models that would either automatically enroll beneficiaries into the private form of Medicare or accountable care organizations, such as those that participate in the Medicare Shared Savings Program. Individuals could still opt into a different insurance arrangement. Right now, people who don’t make a choice are covered by traditional Medicare.
    • “Would either of those, in my view, be superior to a default enrollment into a fee-for-service arrangement, where there’s not this long-term, secular relationship between the beneficiary, the patient, and their provider? Yes,” Klomp said. 
    • “He made the comments in an interview with STAT reporter Mario Aguilar on the sidelines of STAT’s Breakthrough Summit East in New York.”
  • Health Affairs Forefront tells us,
    • “The only truly clear and formally stated goal of the MFN [most favored nation drug pricing] policies is to lower the prices that Americans pay for drugs. How can we begin to evaluate the extent and impact of this kind of change?
    • “It is notoriously difficult to know, precisely, what most Americans “pay” for drugs. We have a complicated system of confidential manufacturer rebates and arrangements with pharmacy benefit managers that often tie out-of-pocket payments to “list” prices that may or may not actually be paid by anyone. People far smarter than I have made careers of shedding light on the cost of drugs in the US, and ultimately, it will be up to them to track whether any person or entity ends up paying less for drugs (and for which drugs) than prior to the policies’ enactment. Until then, Observatory members are watching developments in a few key areas that could influence the reach of MFN policies in the US.
    • “First, they are watching the relationship of the MFN policies to the employer-based insurance market, which covers 160 million people, or more than 50 percent of those with health insurance in the US. To date, MFN policies have been announced for Medicare and Medicaid recipients and for individuals who purchase drugs out of pocket on TrumpRx. But even at discounted prices available through TrumpRx, many drugs will remain too costly for consumers unless they can use the insurance for which they already pay premiums.
    • “The reach of the new, “lower” prices will be limited if there isn’t a mechanism for those with employer-sponsored insurance to access those prices. Part of such “access” includes having purchases through TrumpRx (or other direct-to-consumer platforms) count toward the deductibles and out of pocket maximums that characterize private coverage. Without explicit mechanisms to enable this kind of accounting—or federal or state mandates to require it—the purchase of drugs at the MFN prices will likely be unappealing to more than half of the US population, significantly diluting the policies’ effectiveness and reach. Further, if employer-sponsored health plans cannot access the MFN prices, then those lower prices cannot be reflected in their overall premiums, which consistently rise far faster than both general inflation and wage growth with escalating pharmaceutical costs being an important contributor.”
  • and
    • “As reported by the Centers for Medicare and Medicaid Services (CMS) in supplemental tables and public use files, the volume of cases submitted into the [No Surprises Act Independent Dispute Resolution] IDR process continues to exceed all expectations and grew rapidly in the first six months of 2025. During that period, parties submitted 1.2 million new disputes to the IDR portal—more than double the volume of the first two quarters of 2024 when nearly 590,000 disputes were filed. This amounts to a total of 3.4 million disputes from 2022 through June 2025.
    • “And the number of disputes is only continuing to increase: Even more recent bi-monthly updates from CMS show that nearly 1.4 million cases were filed from July 2025 through December 2025. This has resulted in a whopping 4.8 million total cases through the end of 2025. As a reminder, federal officials expected approximately 17,000 disputes per year.” * * *
    • “Consistent with prior trends, providers continued to initiate (and win) the vast majority of disputes.” * * *
    • Four provider groups and provider representatives—mostly backed by private equity—initiated the majority of these disputes: HaloMD, Team Health, Radiology Partners, and SCP Health. HaloMD—a middleman organization that specializes in arbitration—initiated the most disputes, accounting for 17 percent of all disputes in the first quarter of 2025 and 22 percent of all disputes in the second quarter of 2025. For an organization that initiated a mere 1 percent of line-item claims in 2023, this is a rapid rise to prominence. The second most frequent initiator, Team Health, has long been a high-volume IDR participant and initiated 16 percent of all disputes in the first six months of 2025, a level that is consistent with prior years. Combined, the top four initiators accounted for more than half (56 percent) of disputes filed in the first two quarters of 2025.
    • Providers also won 88 percent of disputes—the highest provider win rate to date—as compared to 85 percent in 2024 and 81 percent in 2023. Radiology Partners prevailed most often, winning favorable IDR awards in 92 percent and 95 percent of its cases in the first two quarters of 2025, respectively. Team Health saw similar win rates of 94 percent across both quarters. HaloMD won slightly less often but still prevailed in 87 percent and 82 percent of its disputes in the first two quarters of 2025, respectively.
  • Per a Centers for Medicare and Medicaid Services news release,
    • “The Centers for Medicare & Medicaid Services (CMS) has finalized the Administrative Simplification; Adoption of Standards for Health Care Claims Attachments Transactions and Electronic Signatures Final Rule (CMS-0053-F).
    • “This groundbreaking final rule establishes the first-ever Health Insurance Portability and Accountability Act (HIPAA)-adopted standards for health care claims attachments, enabling the secure electronic exchange of health care claims-related supporting clinical documentation such as medical records, x-rays and imaging, clinical notes, telemedicine visit documentation and laboratory results.
    • “The rule also establishes requirements for electronic signatures to ensure health care claims attachment transactions are secure, authenticated, and compliant with federal standards.” * * *
    • “Health care providers and payers should begin preparing to implement the finalized standards. This final rule is effective on May 26, 2026. The compliance deadlines for all requirements in this rule are set for 24 months from the effective date of the final rule. Stakeholders are encouraged to review the rule and begin implementing the new standards promptly. The final rule can be viewed at: https://www.federalregister.gov/.” * * *
    • To view the final rule fact sheet, visit: https://www.cms.gov/newsroom/fact-sheets/administrative-simplification-adoption-standards-health-care-claims-attachments-transactions.
    • For more information, visit: https://www.cms.gov/priorities/key-initiatives/burden-reduction/administrative-simplification/hipaa/events-latest-news.
  • PCMA points out,
    • “The Pharmaceutical Care Management Association (PCMA) is urging the Labor Department to roll back a proposed rule aimed at boosting price transparency in pharmacy benefit management relationships now that Congress has passed industry reforms.”
  • Beckers Payer Issues informs us,
    • “Nine percent of people who had ACA Marketplace coverage in 2025 are now uninsured, with healthcare costs as a major reason many enrollees either switched Marketplace plans or dropped coverage, according to a KFF poll
    • “The KFF follow-up survey of Marketplace enrollees was conducted Feb. 12 to March 2 and included 1,117 U.S. adults who had Marketplace insurance in 2025. The sample was drawn entirely from respondents to KFF’s original 2025 Marketplace survey, which included 1,350 participants.”

From the Food and Drug Administration front,

  • MedPage Today reports,
    • “The FDA issued a safety communication today warning of a potential increased risk of seizures tied to certain medications used to treat Parkinson’s disease.
    • “The agency will require manufacturers of carbidopa/levodopa products to update their labels with clearer warnings, to better inform patients and clinicians of this risk. The revised prescribing information will specify that these medications can cause vitamin B6 deficiency and vitamin B6 deficiency-associated seizures.
    • “The warning also instructs healthcare professionals to assess baseline vitamin B6 levels before initiating carbidopa/levodopa therapy and to monitor these levels periodically during treatment, supplementing with vitamin B6 as needed.”
  • MedTech Dive adds,
    • “Intuitive Surgical has recalled stapler reload cartridges after receiving reports of four serious injuries and one death.
    • “The Food and Drug Administration communicated the recall in an early alert Wednesday, one week after Intuitive asked customers to quarantine and return all affected and unused reloads.
    • “An Intuitive spokesperson said in an email to MedTech Dive that the company is still investigating the root cause of rare reports of incomplete staple lines when using the recalled 8 mm SureForm gray reload cartridges.”
  • Fierce Pharma relates,
    • “Rhythm Pharmaceuticals is switching up the tempo for its melanocortin-4 receptor (MC4R) agonist Imcivree. After its initial approval more than five years ago to treat certain patients with genetic-driven obesity, the drug is moving into a different and broader realm with an FDA nod for acquired hypothalamic obesity (HO). 
    • “Acquired HO, for which Imcivree is the first approved treatment, represents an “expanded thinking” on the weight-regulating MC4R pathway that Rhythm’s product targets, Chief Scientific Officer Alastair Garfield, Ph.D., explained in a recent interview with Fierce. 
    • “Until now, all of Imcivree’s approved uses have centered around specific genetic causes. HO, on the other hand, is a result of a hypothalamic injury such as a tumor or stroke that impairs the MC4R pathway and causes weight gain and insatiable hunger (hyperphagia).”
  • Per an FDA news release,
    • “As part of the U.S. Food and Drug Administration’s continuous quality improvement efforts, the agency today published a Federal Register Notice seeking public comment on the Commissioner’s National Priority Voucher pilot program. The agency also announced a public hearing on June 12, to allow stakeholders to present information and views about the program.
    • “The public hearing, consistent with 21 CFR § 15.1 et seq., will seek feedback about the program’s eligibility criteria, the voucher selection processes, sponsor responsibilities, pre-submission requirements, FDA review procedures, the role of the CNPV Review Council, and other aspects of program implementation.” * * *
    • “The June 12 public hearing will be held at the FDA’s White Oak Headquarters with both an in-person and virtual option for participation. The FDA panelists will include subject matter experts from the Office of the Commissioner, the Center for Drug Evaluation and Research, the Center for Biologics Evaluation and Research, and the Oncology Center of Excellence, as well as a presiding officer. Requests to speak are due by May 1. The FDA is also soliciting written comments until June 27. For more information about the hearing: https://www.fda.gov/news-events/commissioners-national-priority-voucher-cnpv-pilot-program-public-hearing-06122026.”

From the judicial front,

  • Fierce Healthcare reports,
    • “A federal judge has dealt a blow to the Trump administration’s push to restrict gender-affirming care for minors.
    • Per the New York Times, Oregon [U.S.] District Court Judge Mustafa Kasubhai ruled Thursday that Department of Health and Human Services Secretary Robert F. Kennedy, Jr. overstepped his legal authority in issuing a declaration late last year that would bar hospitals from providing gender-affirming care to minors if they want to participate in Medicare and Medicaid.” * * *
    • “Restricting access to gender-affirming care for minors has been a key priority for the Trump administration, and NYT reports that legal experts believe Kasubhai’s decision will likely be appealed.”

From the public health, medical and Rx research front,

  • The Centers for Disease Control and Prevention announced today,
    • “RSV activity started later than expected in most regions of the United States, though illness is not more severe compared with recent seasons. This unusual timing means that higher levels of RSV activity may continue into April in many regions. Emergency department visits and hospitalizations for RSV are highest among infants and children less than 4 years old. Seasonal influenza activity remains elevated nationally but is decreasing in most areas of the country. COVID-19 activity is decreasing in most areas of the country.
    • “COVID-19
      • “COVID-19 activity is decreasing in most areas of the country.
    • “Influenza
      • “Overall seasonal influenza activity remains elevated nationally but is decreasing in most areas of the country. Influenza A activity continues to decrease while trends in influenza B activity vary by region.
      • “Additional information about current influenza activity can be found at: Weekly U.S. Influenza Surveillance Report | CDC
    • “RSV
      • “RSV activity started later than expected in most regions of the United States, though illness is not more severe compared with recent seasons. This unusual timing means that higher levels of RSV activity may continue into April in many regions. Emergency department visits and hospitalizations for RSV are highest among infants and children less than 4 years old.
    • Vaccination
      • “RSV is a leading cause of hospitalization among U.S. babies.
      • “To help keep babies safe from severe RSV, babies younger than 8 months of age should get protection in their first RSV season (which usually starts in the fall) in one of these ways:
        • “The pregnant mother gets the RSV vaccine during pregnancy, or
        • “The baby gets an RSV antibody (nirsevimab or clesrovimab) just before the start of the RSV season or soon after birth, if born during the season.
      • “A CDC report showed that these protections are working. During the 2024–25 RSV season, infant RSV hospitalization rates were reduced by up to half compared to rates during seasons before when RSV prevention products were available.
      • “Interim estimates for the 2025–26 seasonal influenza vaccine show getting the vaccine reduced the risk of flu-related doctor visits and hospitalizations, supporting CDC’s vaccination recommendations. For children and teenagers, the vaccine was 38%–41% effective at preventing doctor visits and 41% effective at avoiding hospitalizations for the flu. For adults aged 18 and older, it was 22%–34% effective at preventing doctor visits and 30% effective for preventing hospital stays. Read more here: MMWR.
      • “Talk to your doctor or trusted healthcare provider about what may be recommended for you and your family.”
  • The American Hospital Association News reports,
    • “The Centers for Disease Control and Prevention announced today that there are now 1,487 confirmed measles cases nationwide so far this year. The CDC said 5% of cases have been hospitalized, and no deaths have been reported. The vaccination status of 92% of cases is unvaccinated or unknown. The South Carolina measles outbreak, which began in October 2025 and is currently the largest outbreak of any state, is at 997 cases. Utah, which has the second-largest outbreak, is now at 443 cases.” 
  • Health Day points out,
    • “Psychedelic-assisted therapy (PAT) is no more effective than traditional antidepressants (TADs) for treatment of major depression, according to a review published online March 19 in JAMA Psychiatry.” 
  • Medscape explains how “New Nanoparticles Can Destroy Undruggable Cancer Proteins.”
  • Genetic Engineering and Biotechnology News informs us,
    • “Current schizophrenia (SZ) medications treat symptoms such as hallucinations and delusions, but do little for cognitive symptoms, such as disorganized thinking or executive dysfunction. As a result, many patients are unable to work, rely on family for lifelong support, become homeless or, in some cases, experience suicidal thoughts and actions.
    • “A study in humans and mice, headed by a team at Northwestern University, has discovered a novel biomarker of schizophrenia that could also serve as a new drug candidate to treat cognitive symptoms of the disorder. Their research in a mouse model of schizophrenia showed that treatment with a synthetic protein, SEAD1, corrected overexcited brain circuits. “A lot of people with schizophrenia cannot integrate well into society because of these cognitive deficits,” said Peter Penzes, PhD, professor of neuroscience, pharmacology and psychiatry and behavioral sciences at Northwestern University Feinberg School of Medicine. “Our discovery could solve these challenges by establishing the basis of a revolutionary and completely novel treatment strategy through a tandem biomarker-peptide therapeutic approach.”

From the U.S. healthcare business and artificial intelligence front,

  • BioPharma Dive reports,
    • “Novartis will pay $2 billion up front to acquire a drug that could improve upon existing treatments for patients with a particular form of breast cancer.
    • “Through a deal announced Friday, Novartis will purchase Pikavation Therapeutics, a subsidiary of privately held, Delaware-based Synnovation Therapeutics. The buyout hands Novartis an experimental pill called SNV4818, which targets tumors driven to growth by mutations to the PIK3CA gene. Alterations to this gene are implicated in a wide variety of cancers, including an estimated 40% of patients whose breast tumors are hormone-receptor positive, but don’t express the protein HER2, according to Novartis.”
  • Healthcare Innovation relates,
    • “Mary Bacaj, president of value-based care at Conifer Health Solutions, recently spoke with Healthcare Innovation about misconceptions around preventive care. She argues [in the interview found in the article] that self-insured employers should take a multi-year approach to assessing ROI rather than taking a single-year snapshot.” Check it out.
  • Beckers Hospital Review identifies and discusses six healthcare systems which are innovating primary care models to expand care.
  • Kaufman Hall informs us,
    • “Healthcare bankruptcy filings decreased for a second consecutive year, according to a recent report from Gibbons Advisors. The report finds a 21% decline in bankruptcy filings year-over-year, with the bulk of the 45 filings in 2025 occurring in the first quarter. The bankruptcy activity appears to be tempering, adjusting to pre-pandemic trends. By sector, senior care and pharmaceuticals comprise about half of the bankruptcies, with hospitals only accounting for 13.6% of all healthcare bankruptcy filings in 2025.”
  • The Withum CPA and consulting firm delves into “Artificial Intelligence and the Rise of Duplicate Claims: What Plan Sponsors Should Understand.”
    • “Artificial intelligence is fundamentally changing how healthcare claims are generated, submitted, and processed. As these technologies mature, both claim volume and complexity are likely to increase, placing additional pressure on traditional payment-integrity controls.
    • “While duplicate and near-duplicate claims are a visible result of this shift, AI also affects other aspects of the payment-integrity lifecycle, including coding accuracy, claim edits, resubmission behavior, and post-payment recovery.
    • “For plan sponsors, the question is no longer whether AI will influence claims administration, but whether current oversight frameworks have evolved to address these broader changes. Understanding duplicate-claim risk, evaluating vendor controls across the payment-integrity continuum, and ensuring transparency are increasingly important for prudent fiduciary governance in an AI-driven claims environment.
    • “As AI continues to reshape healthcare billing and claims processing, plan sponsors should periodically reassess whether their oversight frameworks and vendor controls remain aligned with an increasingly automated claims environment.”

Tuesday Report

From Washington, DC,

  • The Wall Street Journal reports.
    • “The Congressional Budget Office last week put out an “are you sitting down?” report that projected the U.S. government will spend $1 trillion on interest payments for its debt this year. One. Trillion. Dollars. To finance its gigantic and growing debt. And it will only get worse from there.
    • “It also projected that the U.S. government will spend $1.853 trillion more than it brings in through revenue this year (that’s the budget deficit) and have an even wider gap in 2027. Talks of slashing spending and making difficult choices last year have given way to election-year spending-increase promises in 2026. Perhaps complicating matters more, DOGE never really caught on in 2025, and Republicans seem reluctant to repeat that experiment any time soon.
    • “Budget angst tends to come in waves, but the debt never stops growing. I wrote about the $13.7 trillion debt here in 2010. That was $25 trillion ago.”
  • and
    • “The [Homeland Security Department] shutdown enters Day 4, with little chance of an end in sight after Congress failed to reach a deal on immigration-enforcement policies.”
  • Federal News Network reminds us about the bipartisan federal employment bills brewing in Congress.
  • Last Friday, the HHS Office for Civil Rights posted model HIPAA notices of privacy practices that were update for the Part 2 changes.
  • Navia Benefits lets us know,
    • Health Savings Accounts (HSAs) have traditionally been viewed as a tax-advantaged way to pay for out-of-pocket medical expenses. But today’s data tells a much bigger story: they can function as a powerful financial wellness tool.
    • “HSAs are increasingly operating like powerful long-term investment vehicles rather than just spending accounts. Yet misconceptions persist across the workforce, and employee education continues to lag. With rising healthcare costs and growing financial pressures, it is a good time to elevate the HSA conversation.
    • [Navia’s article] examines the triple tax advantages, workforce perception trends, and evidence-based insights to guide employers in maximizing HSA participation and value.

From the Food and Drug Administration front,

  • Per a Senate news release,
    • :U.S. Senator Bill Cassidy, M.D. (R-LA), chairman of the Senate Health, Education, Labor, and Pensions (HELP) Committee, released a landmark report detailing legislative and regulatory reforms to modernize the Food and Drug Administration (FDA). These proposals aim to maintain American biomedical dominance and ensure patients have timely access to the latest lifesaving treatments. The HELP Committee’s recommendations are directly in line with President Trump’s mission to improve the health of American children and families.
  • Fierce Pharma tells us,
    • “Harmony Biosciences is rounding out the U.S. patient pool eligible for its sleep disorder pill Wakix after notching a pediatric nod from the FDA that positions the drug as a treatment for cataplexy in people ages 6 and older with narcolepsy.
    • “The new addition to Wakix’s label makes it the only non-scheduled treatment for both adult and pediatric narcolepsy patients in the U.S. with or without cataplexy. That non-scheduled classification represents an “important distinction that supports its clinical utility,” Harmony’s CEO, Jeffrey Dayno, M.D., commented in a press release. Cataplexy is a common symptom of narcolepsy that involves a sudden weakening of muscles, often when triggered by a strong emotion.”
  • and
    • “Two months after Johnson & Johnson’s Rybrevant Faspro picked up its first FDA approval, the subcutaneous lung cancer drug has scored a label expansion to be given monthly.
    • “On Tuesday, J&J touted a “simplified” monthly dosing regimen for the drug’s combination with lazertinib for the first-line treatment of epidermal growth factor receptor EGFR-mutated advanced non-small cell lung cancer. Previously, the combo was approvedas an every-two-week regimen.
    • “For weeks 1 through 4, patients must still receive weekly doses of Rybrevant Faspro. Beginning week 5, the doses can shift to monthly administration.”

From the judicial front,

  • The Wall Street Journal reports,
    • Bayer BAYN is making a new multibillion-dollar push to resolve a years long legal nightmare over Roundup weedkiller.
    • “The German pharmaceutical and agriculture conglomerate on Tuesday said it proposed to settle a nationwide class-action lawsuit to resolve claims that its flagship herbicide causes cancer. The settlement plan includes setting aside more than $7 billion to fund payments over 21 years. 
    • “Law firms representing tens of thousands of plaintiffs filed a motion Tuesday seeking approval of the settlement. The proposal requires court approval in Missouri, where the bulk of Roundup cases are outstanding.” 

From the public health and medical / Rx research front,

  • Patient Care reports,
    • “New data from the 2026 Primary Care Scorecard highlight measurable associations between regular primary care access and improved outcomes for patients with chronic disease.
    • “In the interview, Morgan McDonald, MD, National Director for Population Health at the Milbank Memorial Fund and practicing primary care internist and pediatrician, outlined key findings relevant to frontline clinicians.
    • “Among adults with chronic disease, having a usual source of care was associated with:
      • 20% lower hospitalization rates
      • 54% lower total cost of care
    • “For children with chronic disease, reductions in emergency department visits and hospitalizations for ambulatory care–sensitive conditions—such as pneumonia and otitis media—were “cut roughly in half.”
    • “The report also reinforces primary care’s role in prevention. Nearly all adults with a usual source of care received preventive services for conditions such as cardiovascular disease and common cancers, compared with approximately two-thirds of adults without a regular source of care. Similar trends were observed in pediatric populations, including higher receipt of counseling related to nutrition, exercise, injury prevention, and obesity prevention.”
  • Infectious Disease Advisor tells us,
    • “Low rates of diagnostic testing for respiratory syncytial virus in adult outpatient settings may result in an underestimated disease burden, potentially impeding the effective use of novel vaccines and therapeutic interventions.” 
  • MedPage Today informs us,
    • “Health systems where most pregnant patients have a high or moderate risk for preeclampsia may benefit from universal dispensation of aspirin, results from a large cohort study suggested.
    • “The rate of preeclampsia with severe features at a Texas health system was a relative 29% lower after it implemented universal aspirin dispensation in prenatal care compared with the period when aspirin was not recommended, regardless of risk factors (5.2% vs 7.1%; OR 0.71, 0.66-0.78, P<0.001), Elaine Duryea, MD, of University of Texas Southwestern Medical Center in Dallas, reported here.”
  • Medscape points out the top ten triggers for pancreatic cancer which is “an often silent disease.”
  • STAT News reports,
    • “Compass Pathways on Tuesday disclosed results from two Phase 3 studies that support a potential approval of its psilocybin treatment for severe depression, but more detailed data are needed to determine how beneficial the drug would be for patients.
    • “In both trials, patients who received the company’s psychedelic medicine saw greater improvements on a measure of depression than the control group, Compass said in a press release. Its drug, called COMP360, could be the first psilocybin product on the market and the second psychedelic approved after Johnson & Johnson’s Spravato, a ketamine derivative.
    • “Taken together, the data “probably meets the bar for approval. It doesn’t shout out to you that this is miraculous,” said Jerry Rosenbaum, director of Massachusetts General Hospital’s Center for Neuroscience of Psychedelics, who was not involved with the study.”
  • and
    • Ocular Therapeutix said Tuesday that its experimental treatment, called Axpaxli, maintained vision with less frequent injections compared to a standard treatment for patients with a common cause of age-related blindness — achieving the primary goal of a late-stage clinical trial. 
    • “However, the difference in the durability of treatment between Axpaxli and the active control in the study was narrower than investors expected — a finding that may spark debate about Axpaxli’s commercial potential in wet age-related macular degeneration, where effective drugs are already approved.”
  • Fierce Pharma adds,
    • “Continuing the reinvention of its cancer drug Gazyva as a treatment for immune-mediated diseases of the kidney—which resulted in a lupus nephritis nod last fall—Roche is touting new data that could tee up the antibody for a world-first approval.
    • “In an early look at results from the late-stage Majesty study in adults with primary membranous nephropathy, Gazyva (obinutuzumab) helped significantly more patients achieve complete remission at the two-year mark compared with the immunosuppressant tacrolimus, Roche said in a Feb. 16 press release. 
    • “Gazyva’s performance enabled the trial to hit its primary endpoint, and key secondary endpoints further pointed to statistically significant and clinically meaningful outcomes on overall remission at Week 104 and complete remission at Week 76 of the study, the company said.” 
  • Genetic Engineering and BioTechnology News relates,
    • “Researchers headed by a team at the University of California, Irvine, Joe C. Wen School of Population & Public Health have built what they suggest is the first cell type-specific gene regulatory network (GRN) map for Alzheimer’s disease (AD), which shows how genes causally regulate one another across different types of brain cells affected by AD.
    • “The researchers developed a machine learning framework, SIGNET (Statistical Inference on Gene Regulatory Networks), which reveals cause-and-effect relationships rather than simple genetic correlations, and applied this to uncover key biological pathways that may drive memory loss and brain degeneration. Their results pointed to numerous influential “hub genes” that offer promising potential new targets for early detection and therapeutic intervention. The investigators say their methodology is also applicable to other complex diseases, including cancer.”

From the U.S. healthcare business front,

  • Fierce Healthcare reports,
    • “Ongoing headwinds caused by elevated utilization and medical costs continued to drag major health plans in the fourth quarter, completing the story of a complex 2025 for the industry.
    • “The most profitable company for the full-year was UnitedHealth Group, with $12.05 billion in earnings for 2025. The healthcare giant had a sizable lead on the next-highest payer in terms of profitability, which was Cigna at just below $6 billion.
    • “However, the company posted just $10 million in profit for Q4, the lowest tally among payers that turned a profit in the quarter. In Q4, the company saw a medical loss ratio of 92.4%, which settled to 89.1% for the full year.”
  • Fierce Healthcare adds,
    • “CommonSpirit Health’s adjusted operating margin inched into the black during the three months ended Dec. 31 as the organization’s leadership touted “noticeable” quarter-to-quarter performance gains stemming from strong volumes and efficiency. 
    • “The 138-hospital Catholic nonprofit posted a $78 million operating loss (-0.8% operating margin) for the second quarter of its 2026 fiscal year; however, after normalizing for delayed income received through California’s provider fee program, the system reached a narrow operating income of $2 million (0.0% operating margin). 
    • “CommonSpirit also reported $456 million excess revenues over expenses after normalizing. A year prior and after adjustment, the organization had an operating income of $135 million (1.3% operating margin) and a $356 million bottom line, which it noted was bolstered by around $352 million of Federal Emergency Management Agency grant revenue.”
  • Per Beckers Hospital Review,
    • “Ontario, Calif.-based Prime Healthcare’s nonprofit public charity, Prime Healthcare Foundation, acquired Lewiston-based Central Maine Healthcare on Feb. 16.
    • “The foundation received Maine’s approval to acquire Central Maine Healthcare in late November after sharing plans to acquire it in January 2025. 
    • “The transaction comprises Lewiston-based Central Maine Medical Center, Bridgton (Maine) Hospital, Rumford Hospital, Rumford (Maine) Community Home, Auburn, Maine-based Bolster Heights Residential Care, Lewiston-based Maine College of Health Professions, Lewiston-based CMH Cancer Care Center, and more than 40 physician practices, according to a Feb. 16 news release.
    • “The Prime Healthcare Foundation comprises 21 hospitals across the U.S. following the acquisition, with more than $4 billion provided in charity care.” 
  • and
    • “Marshfield Medical Center-Wisconsin Rapids Campus will open to patients March 1.
    • “The campus includes the soon-to-open hospital and Marshfield Clinic Wisconsin Rapids Center, according to a Feb. 16 health system news release.
    • “The hospital will include inpatient beds, an emergency department, exam and procedure rooms, radiological services that include general x-ray, computed tomography and ultrasound, and on-site laboratory testing.”
  • and
    • “Telehealth company eMed has partnered with CVS Caremark to offer a GLP-1 benefit model that lets employers subsidize weight loss medications without covering the full cost, Axios reported Feb. 16. 
    • “The arrangement allows eligible employees to purchase GLP-1s online through eMed and receive weight management services including side effect management, weekly check-ins and blood testing. Employers can decide how much of the cost to subsidize, the report said.” 
  • Per Healthcare Dive,
    • “Amwell is projecting lower revenue in 2026 after the health technology firm divested assets, executives said during an earnings call Thursday. 
    • “The firm expects revenue from $195 million to $205 million this year. In comparison, the telehealth vendor and health tech firm brought in revenue of $249.3 million in 2025.
    • “The top line for 2026 is smaller, but it’s “primarily high-quality, high-upside, sticky revenue,” CEO Ido Schoenberg said on the call.”
  • Per MedTech Dive,
    • “Danaher said Tuesday it has agreed to acquire patient monitoring company Masimo for $9.9 billion to bolster its diagnostics franchise.
    • “Masimo will become a standalone business unit and brand within Danaher’s diagnostics portfolio, operating autonomously while strengthening Danaher’s offering in acute care settings, the companies said.
    • “Masimo’s advanced sensor technology and AI-enabled monitoring bring powerful new capabilities to our diagnostics portfolio,” Julie Sawyer Montgomery, Danaher’s executive vice president for diagnostics, said in a statement.
    • “The $180-per-share cash deal has been unanimously approved by both Masimo’s and Danaher’s boards, according to Masimo.”

Tuesday report

From Washington, DC,

  • Govexec identifies the five biggest stories for federal agencies and employees to watch in 2026.
    • 1.) Renewed shutdown watch
    • 2.) Return of RIFs? 
    • 3.) The implementation of ‘Schedule F’ and other changes to the civil service
    • 4.) Agency reorganizations
    • 5.) Court battles 
  • Beckers Payer Issues informs us,
    • “More than 15.6 million people have enrolled in plans on federally run ACA exchanges so far, down from about 16 million at the same point last year, CMS Administrator Mehmet Oz, MD, said Dec. 23.
    • “Dr. Oz attributed the decline to efforts to address fraudulent enrollments, writing on X: “Notably, this small drop follows several important CMS actions over the past year to combat fraudulent and improper enrollments, which have already removed more than enough people from premium subsidies who are covered elsewhere to account for the modest enrollment change. That said, there is a politically motivated lawsuit that has paused critical actions to make sure Biden-era improper enrollments are fully knocked out.”
    • ‘Earlier in the open enrollment period, ACA enrollment was outpacing last year. CMS data published Dec. 5 showed nearly 5.8 million plan selections through late November, up about 7% year over year, though new consumer enrollment was down 4% as returning consumers drove the gains.”
  • According to a Competitive Enterprise Institute news release,
    • “A new Competitive Enterprise Institute (CEIstudy explores a thriving pharmaceutical delivery system that offers consumers real choice and convenience. Independent pharmacies are doing well and still make up a sizable portion of retail pharmacies. At the same time, new approaches like mail-order pharmacies and combined telehealth and pharmacy offerings are making it easier and cheaper than ever for patients to obtain necessary medications. And these new innovative approaches are providing access to rural areas that lack physical pharmacies.
    • “Invaluable to this well-functioning system is the role of pharmacy benefit managers (PBMs). PBMs own and manage most mail-order pharmacies, negotiating drug prices and running an efficient distribution network. PBMs provide convenient, reliable drug delivery to patients, making it easier for patients to stick to their treatment plan.
    • “But some lawmakers at the state and federal levels fear that PBMs wield too much influence over products and services, and they want to ban PBMs from owning pharmacies, whether mail-order services or retail stores like CVS. Perhaps they have not considered that in some rural counties, the only pharmacy available would be in danger of closing under these laws—potentially leaving residents in those areas with no local options.
    • “There is little evidence to suggest that worries about PBM-owned pharmacies are justified, and consumers are already protected from anticompetitive practices by existing laws.
    • “Banning successful business models doesn’t protect consumers; it protects competitors from competition,” said study author and CEI senior fellow Jeremy Nighohossian. “When it comes to building a system that works better for consumers, the free market is the best medicine.”
  • Modern Healthcare reports,
    • “The Drug Enforcement Administration on Tuesday temporarily extended a rule allowing clinicians to prescribe controlled medications remotely through the end of 2026.
    • “The rule, which will take effect Thursday, gives clinicians the ability to remotely prescribe Schedule II-V controlled medications to patients. This latest extension marks the fourth time the rule has been renewed since it was implemented at the beginning of the COVID-19 pandemic.
    • “Under the rule, clinicians are able to prescribe controlled medications, such as Adderall and Xanax via telemedicine appointments, without an initial in-person examination. The rule was originally set to expire at the end of December.”
  • The Holland and Knight law firm lets us know,
    • “Recent changes to the HIPAA Privacy Rule require that healthcare providers update their Notice of Privacy Practices (“NPP”) by February 16, 2026. The changes are intended to align HIPAA with the revised regulations governing substance use disorder records in 42 CFR part 2 (“Part 2”). A redlined version of 45 CFR 164.520 showing the changes to the rule is available here here.”

From the public health and medical / Rx research front,

  • The Wall Street Journal reports,
    • “Influenza cases are rising sharply, heightening fears that a new strain will fuel a punishing flu season that is already outpacing last year’s.
    • “The flu has sickened an estimated 7.5 million people so far this season, according to weekly data from the Centers for Disease Control and Prevention released Tuesday. About 81,000 people have been hospitalized and 3,100 have died so far this flu season, the agency estimated, including eight children. That reflects a sharp increase from the week prior, in which the CDC estimated about 4.6 million cases, 49,000 hospitalizations and 1,900 deaths. 
    • “Roughly 25% of samples sent to clinical laboratories came back positive for the flu in the week ended Dec. 20, the CDC said. That is up from about 15% the week before. 
    • “The figures raised concerns of a particularly harsh flu season this winter. The contagious respiratory illness typically kills thousands of people in the U.S. each year, though that number can rise significantly in years with troublesome viral variants.” 
  • The University of Minnesota’s CIDRAP tells us,
    • “Measles cases nationwide have reached 2,012, the Centers for Disease Control and Prevention (CDC) reported last week, as outbreaks in Arizona and South Carolina continue to grow and three other states alert the public about airport exposures.
    • “The US total reflects 54 new cases, as the country teeters on the brink of losing its measles elimination status—which it earned in 2000—next month. This year’s total is the nation’s highest since 1992, when officials reported 2,200 cases. Coordinated vaccination efforts led to a precipitous drop in cases in the ensuing decades, but vaccine skepticism in recent years has spawned the disease’s resurgence.”
  • and
    • “Relative to uninfected control patients, those hospitalized with acute respiratory infections (ARIs) due to respiratory syncytial virus (RSV) or influenza were at substantially higher adjusted risk for all-cause death, heart attack, exacerbation of asthma and chronic obstructive pulmonary disease (COPD), and hospitalization for heart failure, researchers from vaccine maker GSK and the Analysis Group report.
    • “The retrospective study, published last week in Clinical Infectious Diseases, used claims data from October 2015 to June 2023 to compare clinical outcomes among US adults aged 50 and older hospitalized for RSV or flu with those of controls without ARI. The average ages in the RSV and flu cohorts were higher than those of controls (76.5 and 75.4 vs 69.5 years, respectively).
    • “Current evidence on longer-term RSV-ARI outcomes among adults aged ≥50 years is limited, with insufficient research comparing the impact of RSV-ARI hospitalization to an appropriate comparator population representing the long-term health outcomes these patients would have experienced without severe RSV disease,” the study authors wrote.”
  • The New York Times relates,
    • “Rarely does a single study change the course of gynecological history. But a clinical trial published this year in The New England Journal of Medicine did just that, seeming to close the door on one of the great enigmas of women’s health.
    • “Bacterial vaginosis, or B.V., is the most common vaginal infection worldwide. If you have a vagina, there’s a one-in-three chance you will have B.V. at some point in your life.
    • “For years, doctors have known that the bacteria associated with the condition could also be found on the penis. Yet on paper B.V. was just a vagina problem — it’s right there in the name, vaginosis. For 50 years, gynecology treated it as if it were solely a women’s issue, with ineffective treatments that left women vulnerable to re-infection.
    • “The New England Journal study changed that. The researchers followed 150 heterosexual couples in which the female partner had bacterial vaginosis. They treated the women with first-line antibiotics, and half the men with both oral and topical antibiotics. Within three months, they found, the partner treatment worked so well that they had to disband the study so all participants could be treated.”
  • Medscape points out,
    • “Rates of gestational diabetes (GD) in the US rose every year from 2016 to 2024, with a total 36% jump in that 9-year period, new data showed.
    • “The data, from nearly all first live singleton births recorded in the National Center for Health Statistics, also showed that GD rose among all racial and ethnic groups, but with significant differences among them.
    • “The dramatic GD rise “likely reflects several factors including increasing prevalence of prepregnancy overweight and obesity, older maternal age at first birth, and higher rates of metabolic risk factors entering pregnancy. The COVID-19 pandemic may have further contributed to these trends through disruptions in routine preventive care, reduced physical activity, increased psychosocial stress, and weight gain during the pandemic period,” study first author Emily L. Lam, medical student at Northwestern University, Chicago, told Medscape Medical News.”

From the U.S. healthcare business and artificial intelligence front,

  • Fierce Healthcare reports,
    • “Brooklyn, New York-based Maimonides Health is merging with New York City’s public health system NYC Health + Hospitals, the organizations announced Dec. 29.
    • “The merger is pending final legal and regulatory approval but is expected to be finalized by April, city officials said.
    • “The partnership is supported by $2.2 billion over five years from New York state to protect safety net healthcare in Brooklyn, officials said.”
    • “Maimonides Health is a Brooklyn healthcare system with three hospitals and more than 80 community-based sites. By partnering with the city, Maimonides will be reimbursed at a higher rate by Medicaid, bolstering its financial position, health system executives said in a press release. 
    • “The merger also allows Maimonides to adopt a new Epic electronic health record platform. Health system executives said the move to Epic would help improve care coordination and the organization’s ability to collect revenue. Maimonides patients will be able to access their health records online and contact their care team digitally through the portal.”
  • Per Beckers Health IT,
    • “Healthcare organizations are increasingly adopting artificial intelligence to improve efficiency and reduce administrative burden, but most remain cautious about deploying AI in high-risk clinical scenarios, a Dec. 29 KLAS Research report found.”