FDA just told five peptide sellers that "research use only" is not a defense — and that shipping bacteriostatic water alongside makes the water itself a drug
September 2, 2026 · 8 items
FDA just told five peptide sellers that "research use only" is not a defense — and that shipping bacteriostatic water alongside makes the water itself a drug
FDA · posted Sep 1, 2026 · September 1, 2026Pharmacy
FDA posted five CDER warning letters on the same day — Peak Performance Peptides, Royal Peptides LLC, NuScience Peptides LLC, Peptide Partners LLC, and TXP Innovations LLC dba Tex Peptides — all charging "Unapproved New Drugs / Misbranded." Letters were issued Aug 24 and hit the public index Sep 1.
The named products are exactly the ones circulating in the regen/aesthetics world: semaglutide, retatrutide, tesamorelin, SS-31, PT-141, plus "bac water," pulled from a July 2026 review of the seller's own site.
The mechanism is the part to read twice: FDA states the "research use only / not for human consumption" disclaimer does not save them. Selling bacteriostatic water next to the peptides is characterized as "provid[ing] the means to prepare an injectable drug for human administration" — which makes the bacteriostatic water a drug too. The disclaimer is treated as contradicted by the storefront around it.
Signed by Tina Smith, M.S., Captain USPHS, Director of FDA's Office of Unapproved Drugs and Labeling Compliance. 15 business days to respond.
Why it matters for an independent practice: Straight talk — this is not an AI story, it's a compounding-enforcement story, and it's here because `topics.md` puts peptide and GLP-1 compounding squarely in Lens B. It's also the single most consequential thing that happened to Atiba's client base this week. Any regen or aesthetics practice sourcing peptides through a "research chemical" vendor is now on notice that FDA reads the whole storefront, not the disclaimer — and a doctor whose supply chain gets named in a warning letter has a trust problem long before he has a legal one. Worth a proactive note to clients about where their peptides actually come from.
An airport that kills 60% of its own AI projects has more to teach a medical practice about agentic AI than most health systems do
Healthcare IT News · Adam Ang · September 1, 2026Buildable AI
Joe Chiu, consultant at Changi Airport Group, in his closing keynote at HIMSS26 APAC: "Many times, we have to abandon certain projects because it doesn't give us the assurance that they're safe." Agentic AI, he argues, is categorically riskier than generative AI because the system decides on its own — and in airports as in medicine, a wrong machine decision has consequences you can't take back.
The number that makes it real: Chiu estimates more than 60% of CAG's projects never make it through the experimentation process. Killing things is the process, not a failure of it.
Their architecture answer is reuse, not rebuild — an AI layer over existing middleware with custom agents, an MCP server, guardrails and AI-ops capabilities shared across applications. Chiu calls them "Lego blocks" assembled around a specific business need. Notably: custom agents trained per use case, not one general-purpose model trusted to behave once deployed.
They also built in-house data engineers, scientists and developers rather than outsourcing wholesale — explicitly to retain the IP and the institutional knowledge instead of renting it back from a vendor.
Why it matters for an independent practice: This is the "0% medical, extrapolate" shape, and the extrapolation is unusually clean. A practice deploying an AI receptionist or an agentic intake flow is doing exactly what CAG is doing: handing decisions to software in a setting where a wrong one costs something real. Three transfers: (1) build narrow agents per task — a booking agent, an intake agent — rather than pointing a general assistant at your front desk and hoping; (2) budget for a kill rate, because a practice that has never abandoned an AI pilot isn't disciplined, it's just not checking; (3) the in-house-vs-vendor point is the P4 independence argument — the practice that owns its automation logic keeps its leverage, the one that rents an all-in-one platform is a switching cost away from captured.
27% of the plug-ins and "skills" that AI agents install off the internet fail a basic safety check — and pharma is one of the two industries buying hardest against it
TechCrunch · Ram Iyer · September 1, 2026Buildable AI
Israeli startup AIR came out of stealth with $50M across two seed rounds ($10M led by Sequoia, then $40M led by Greenoaks, closed within weeks of each other). Founders Yair Saban (CEO) and Niv Hoffman (CTO) came out of Unit 8200's offensive-security side.
The number worth keeping: AIR says its platform currently filters out about 27% of the add-ons and skills it finds online — roughly one in four of the things an AI agent might reach out and install on its own.
Saban's framing is the useful bit: "In the early 2000s, whenever you installed a driver, the driver didn't need to be signed… You don't have that with skills or plug-ins or MCPs, and it's a shame, because it's the same mechanism, it's the same lesson, but we haven't learned it." The real attack, he argues, isn't hacking the agent — it's poisoning the content the agent reads.
Of AIR's 20+ customers, roughly a quarter are large enterprises, and Saban says the strongest demand is in heavily regulated industries — financial services and pharmaceutical companies. Sequoia's Bogomil Balkansky: "This is not a scanning problem, it is a continuous re-verification problem."
Why it matters for an independent practice: Full disclosure, this is a funding announcement and those usually get skipped here — it's running because the 27% is a finding, not a press release. And it's the exact stewardship question a practice has to answer before it automates anything: the n8n workflow, the AI receptionist, the ChatGPT connector wired into the calendar — every one of those is an agent installing components nobody re-audits after day one. A skill that was safe in June is not automatically safe in September if its maintainer's account got compromised. The practical move isn't buying AIR; it's writing down which integrations touch patient data, who maintains each one, and when you last looked. That list does not currently exist at most practices, and pharma buying this hard is the tell that it should.
Amazon's health AI gives Prime members five free visits, then charges $29 — and a practicing physician argues that's a patient-acquisition play aimed at independents
Medical Economics · Robert Resnik, M.D., MBA · August 28, 2026Patient acquisition
The offer, in numbers: eligible Prime members get up to five no-cost direct-message visits covering 30+ common conditions, with pay-per-visit virtual care after that starting at $29.
Resnik's argument is about which conditions: colds, flu, allergies, reflux, UTIs, pink eye, erectile dysfunction, hair loss — the standardizable, prescription-linked complaints. Skim those off and what's left for the independent practice is the multimorbid, time-expensive, undercompensated work.
He puts it in market-structure terms, not convenience terms, pointing to the FTC allowing Amazon's $3.9B One Medical acquisition to close in 2023 despite commissioner objections about concentrating health data.
His five prescriptions for practices: build a credible digital front door (online scheduling, fast portal response, same-day access, after-hours options); treat AI as infrastructure, not substitute; gain scale through IPAs/CINs/ACOs; demand interoperability; and treat health AI as a market-structure problem rather than a vendor-selection one.
Why it matters for an independent practice: This is the independence principle with a price tag attached. The MMR-relevant read: a practice cannot out-convenience Amazon on a $29 UTI visit and shouldn't try — the defensible ground is the relationship and the complex care Amazon has no interest in. But "we're better at relationships" is worth nothing if a prospective patient can't book online at 9pm and hears back in three days. The digital front door is now table stakes, not a differentiator — it's the price of staying in the consideration set at all. Worth auditing across the client roster: which of them can a patient actually book with, right now, without calling?
An iPad camera that turns "patient's range of motion looks better" into an actual number
HIMSS TV via Healthcare IT News · Aug 31, 2026, 9:18 AM · August 31, 2026Regenerative medicine
Zaw Thet, cofounder and CEO of Exer AI, on using computer vision through everyday device cameras — an iPad camera, not a motion-capture lab — to analyze human movement.
The output is the point: objective data clinicians can use to assess patient mobility, in place of a subjective visual estimate recorded in a note.
Why it matters for an independent practice: Being straight with you on two things. First, this is a short HIMSS TV interview, so it's thinner on specifics than today's other items — two real bullets, and I'd rather post two true ones than pad to four. Second, it's carrying the entire regen lens today (see the wrap for why). It earns the slot anyway because objective movement measurement is the thing orthobiologics has always been weakest at: a PRP or BMAC patient who "feels better at 8 weeks" is a testimonial, but a patient whose measured shoulder abduction went from 96° to 141° is evidence — and evidence is what survives a skeptical referring physician, an insurer, and an AI Overview that's deciding which local practice to cite. Commodity cameras collapse the cost of collecting it. For MMR, outcome data a practice actually owns is also the rarest and most citable content asset there is.
OpenAI wired ChatGPT into Epic — read-only, and gated behind a BAA
TechCrunch · Ivan Mehta · September 1, 2026Practice operations
The integration covers Epic's EHR, which holds data for over 325 million patients. Clinicians can import appointment notes, lab results, medications and specialist documentation and summarize them; in some deployments they get pre-visit review and clinical timelines without leaving the patient chart.
Read-only. OpenAI specifies the AI does not write anything back into the record.
A new Healthcare Public Data plug-in pulls from ClinicalTrials.gov, CMS Coverage, RxNorm, DailyMed and PubMed — aimed at trial eligibility criteria, medication identifiers, coverage policy versions and provider records.
OpenAI says it collected over 4,300 physician responses across 27 clinical use cases and found 99.1% of responses were safe. Context TechCrunch supplies: 300 million health-related queries a week to ChatGPT; a Florida pastor sued days before this rollout alleging a near-fatal recommendation, and a May suit from family members over dosage advice.
Organizations with a Business Associate Agreement can now use ChatGPT Work, Codex, apps and connectors in their workspace for compliant workflows.
Why it matters for an independent practice: The BAA sentence is the whole story for an independent practice. The capability now exists for anyone with a Workspace and a signed agreement — so the question stops being "can we?" and becomes "who in this office is pasting chart data into a chatbot, and is that the instance the BAA covers?" Two different answers to that question are the difference between a workflow and a breach. And 99.1% safe is a vendor's number on a vendor's test set — it is a floor to interrogate, not a clearance.
Search Console's AI performance report went live for every site on Aug 31 — and so did the switch that hides you from AI Overviews
Search Engine Land · Barry Schwartz · August 31, 2026Patient acquisition
After months of slow rollout, both the AI performance report and the Search generative AI control are now available to everyone with a Search Console account, globally. Google added the line to its docs verbatim: "Note: As of August 31, 2026, we've rolled out this control to all websites worldwide."
The report shows how your content performs in AI responses, AI Mode, and AI Overviews — broken out by impressions, pages, countries, devices and dates. It does not include click data.
The new toggle lets a site block its content from appearing in AI Overviews, AI Mode, and AI Overviews in Discover. Google's framing: "website owners can decide if they want their site to appear in and help ground responses in our generative AI Search features."
Google says sites that opt out "will not receive traffic or impressions from our generative AI features" — but the control is not used as a ranking signal for search results outside those AI features, so flipping it should not hurt core web search.
Why it matters for an independent practice: For a year every MMR conversation about AI search has run on inference. As of Sunday there is a report with a number in it. Concrete move this week: open every client's Search Console, pull the AI performance report, and save it — that is the baseline you will be measured against for the next twelve months, and it only exists going forward. Second move: leave the opt-out alone. A practice that hides from AI Overviews disappears from the surface patients now read first and gets no ranking credit for the sacrifice. The only reason to touch it is a client who genuinely wants zero AI grounding on their clinical content — and that is a conversation, not a setting.
CMS granted a growth-factor bone graft a Medicare add-on payment — orthobiologics got a coverage win
Ortho Spine News · Noah Simmons · September 2, 2026Regenerative medicine
Medtronic announced that CMS has granted a New Technology Add-on Payment (NTAP) for INFUSE Bone Graft for TLIF, effective October 1, 2026.
NTAP is a Medicare fee-for-service inpatient mechanism: it pays hospitals additional reimbursement on qualifying cases when a new technology's cost exceeds the standard payment amount, specifically to lower the financial barrier to early adoption before standard rates are updated.
INFUSE is described as the first and only growth-factor technology approved for use in spine fusion procedures. It received FDA premarket approval for TLIF earlier this year, following a Breakthrough Device Designation and a prioritized review timeline.
Named quote: Dave Breiter, VP of Clinical, Medical, Regulatory Affairs and Health Economics for Medtronic's Cranial & Spinal Technologies business.
Why it matters for an independent practice: Almost every regen practice we serve is cash-pay because payers won't touch biologics. A federal payer just agreed to pay extra for one. Be precise about what that does and doesn't do: this is inpatient, hospital-side, and specific to one PMA-approved product — nothing about your billing changes tomorrow. What changes is the argument. "Biologics are unproven and uncovered" is now a sentence with an exception in it, and the exception is the product that ran Breakthrough Designation → PMA → NTAP in order. That's the sequence. Evidence bought the coverage — which is worth saying out loud to any physician who thinks the path runs the other way.