FOIA'd CMS records on the Medicare AI prior-auth pilot: several hundred requests still unanswered at the end of March, one of them 83 days old — and the provider complaints name kyphoplasty and pain procedures by name
September 16, 2026 · 5 items
FOIA'd CMS records on the Medicare AI prior-auth pilot: several hundred requests still unanswered at the end of March, one of them 83 days old — and the provider complaints name kyphoplasty and pain procedures by name
Fierce Healthcare · Dave Muoio · September 15, 2026Practice operations
Roughly 1,000 pages of CMS documents, obtained by the Electronic Frontier Foundation through a FOIA lawsuit filed in March, covering the opening months of the WISeR model — Wasteful and Inappropriate Service Reduction — which uses AI to widen prior authorization inside traditional Medicare. Launched Jan. 1, running to end of 2031, live in Arizona, Ohio, Oklahoma, New Jersey, Texas and Washington. The records run into April 2026; CMS is still producing more.
The pilot's own turnaround goal is three days. The documents describe thousands of requests that blew past it, several hundred still unanswered as of the end of March, and one that had been open 83 days. Also logged: system downtime, mis-categorized approval requests, and miscommunication between vendors and the Medicare Administrative Contractors that broke required processes.
Two provider complaints are the part to actually read. One: "We have patients calling our offices crying in pain because their procedures are being delayed while awaiting approvals… A 3-4 day delay for necessary pain procedures is already difficult for vulnerable patients, but when providers cannot obtain answers for weeks, the situation becomes unacceptable." Another, submitted in all caps: "I have had to watch 3 patients cry at bedside for not hearing back on their prior auth for Kyphoplasty/vertebral augmentation procedures." Both name interventional pain and vertebral augmentation — our clients' exact procedural neighbourhood.
EFF's reading of the payment mechanics is the structural finding: CMS' payment methodology for WISeR vendors incentivizes more denials, through limited payment reductions tied to a vendor's aggregate quality scores. And CMS' own documents plan to expand beyond the initial 13 services to air ambulance transport, MRI scans, and some high-cost Part B medications. One vendor, Innovaccer — processing Ohio — told CMS before the Jan. 1 start that it needed more time, and was still clearing backlogs in early April.
Context, dated: the Senate rejected a bill to roll WISeR back on a party-line 46–50 vote in July, a week after the GAO determined the model is subject to the Congressional Review Act and should have gone to Congress before implementation. AHA and AMA have both pushed back.
Why it matters for an independent practice: This is the clearest picture yet of what "AI in the payment stack" costs a practice in practice, and none of it is about model quality — it is about queues. Three things follow directly. One: if MRI is on the expansion list, the imaging that gates a regen or interventional consult is next, so build the assumption of a multi-week authorization delay into how you schedule and how you set patient expectations now, not when it lands in your state. Two: the denial-incentive finding is the sentence to keep — when the entity reviewing your request is paid in a way that rewards saying no, appealing is not pessimism, it is arithmetic. Three, and this is the MMR angle: those two quotes are what your patients are already experiencing at somebody else's practice. A cash-pay regenerative option whose honest pitch includes "no prior authorization, no 83-day wait" just got a federal document to stand on — and the responsible version of that message says so without overpromising the clinical result.
Lens B breaks a 13-day hold: the FDA told a major sterile-drug manufacturer its quality system does not work — two years of out-of-limit microbes in its ISO 5 areas, and the same organisms turning up in consumer complaint samples
FDA · Warning Letter 320-26-123 to Bausch & Lomb Inc., Tampa FL · September 4, 2026Pharmacy
The inspection ran March 12–20, 2026 at Bausch & Lomb's Tampa sterile-manufacturing site. FDA's finding is not a paperwork lapse: "your firm does not operate an effective quality system in accord with CGMP," and the quality unit "is not enabled to exercise proper authority." Products are deemed adulterated under 501(a)(2)(B).
From 2023 to 2025 the firm routinely recovered out-of-limit microorganisms from aseptic ISO 5 areas — air, surface and personnel — including Serratia marcescens and Stenotrophomonas maltophilia, both water-associated, and kept producing without adequate CAPA. Environmental monitoring missed obvious locations (FDA names phones used in the aseptic processing area) and some growth media was cracked, i.e. incapable of growing what it was there to detect.
The line that should stop anyone who injects a purchased sterile product: organisms recovered from the facility — Pseudomonas aeruginosa and Aspergillus brasiliensis — were the same genus and species as those recovered from several consumer complaint samples. Separately, a July 2025 media-fill failure on line 16 produced two contaminated units, one fungal and one spore-forming gram-positive.
Observed technique, verbatim from the letter: operators reaching over exposed bottles to clear jams, failing to disinfect between handling sterile supplies, contacting the sterile portions of aseptic tweezers and returning those bottles to the line. FDA also notes media fills were substantially smaller than actual commercial batch sizes, so the simulation never tested the real risk.
15 business days to respond, to Francis Godwin, Director of CDER's Office of Manufacturing Quality. FDA asks the firm to contact the Drug Shortages Staff if remediation is likely to disrupt supply — the tell that this is big enough to move product availability.
Why it matters for an independent practice: No AI in this one; it runs under the "adjacent-but-actionable" rule that earned :+1: on the fake-MyChart item, and it is the most actionable thing on the board today for anyone running injectables. One: this is the FDA's own checklist of what aseptic failure looks like, and it is the right set of questions to put to your compounder or supplier — not "are you licensed," but "show me your environmental-monitoring trend data and your media-fill batch size relative to your commercial batch size." Two: the complaint-sample match is the argument for taking patient-reported post-injection reactions seriously as product signals rather than patient variation; this firm's own complaint samples were carrying its own facility's organisms and that is how it was found. Three: the shortage flag means a supply interruption is foreseeable, which is a purchasing conversation to have this week rather than a clinical one to have later.
72% of healthcare leaders admit AI tools are running in their organization with no formal IT approval — and 86% say they're confident they can control AI agents today
Healthcare IT News · Andrea Fox, Senior Editor · September 15, 2026Practice operations
Survey of 250 U.S.-based healthcare leaders responsible for security and AI strategy. 28% already have agentic AI in production and another 44% are piloting AI agents — so roughly seven in ten are past the talking stage. 88% expect AI agents to operate with some degree of autonomy across operational and clinical workflows.
The gap the report is named for: 86% said they are "fairly confident" they can fully control and govern AI agent actions today, while 72% admitted some AI tools or agents are deployed without formal IT approval. Those two numbers cannot both be comfortable.
57% ranked security in their top three concerns, and the specific risk they named was excessive or unnecessary access by agents that interact with clinical systems. The report's framing from Dr. Sean Kelly, Imprivata's chief medical officer: "An AI agent should be treated as a governable digital identity, with access appropriate to its role, clear limits on what it can do, and a record of its activity that can be monitored and audited."
The anonymous quote is the whole item. A senior manager at a 500–749-bed system: "Our hospital previously experienced an anomaly where AI autonomously exported patient information in batches. We were only able to quickly pinpoint the risk thanks to audit logs. Therefore, we only dare to expand the deployment of AI once our monitoring system is mature." Not a hypothetical, not a philosophy — a bulk PHI export that was caught by a log and nothing else.
Why it matters for an independent practice: This is the "who can reach PHI, under what BAA" shape that has drawn :+1: twice, and it is the second half of item 1: there, AI you cannot see is deciding whether your patient gets approved; here, AI nobody approved is reaching your patient's chart. For a practice of any size the translation is small and unglamorous. One: shadow AI in a ten-person clinic is not a governance program, it is the front-desk staffer who pasted a patient's history into a consumer chatbot to draft a letter — and the 72% figure says the large systems have not solved it either, so nobody should feel behind. Two: the actionable piece is the one the anonymous manager names — audit logs are what made the incident findable, so the question to ask any vendor before signing is "what record exists of what your agent read, and can I get it without asking you?" That is question 4 from the Sep 14 procurement framework, now with an incident attached. Three: "treat the agent as a digital identity with a role" is genuinely portable to a small practice — the agent gets its own login with its own permissions, never a staff member's.
Facebook clicks got 14% cheaper this year and lead cost barely moved — but dental leads still cost $61.56, the most expensive vertical in the set, and the two verticals closest to a cash-pay practice are where the gap is widest
Search Engine Land · Anu Adegbola · September 14, 2026Patient acquisition
Traffic campaigns, 2026 averages: click-through rate 1.93% (up 12.87% YoY), cost per click $0.60 (down 14.29% YoY). Only two industries saw traffic CPC rise — Shopping/Collectibles (+73.53%) and Sports & Recreation (+43.90%).
Lead campaigns: CTR 2.70% (up 4.25%), CPC $1.80 (down 6.25%), conversion rate 8.54%, cost per lead $27.39 — down only 0.98% YoY. So clicks got cheaper and leads did not. That spread is the entire story: the platform is delivering more traffic per dollar and the same number of leads out the other end.
The two verticals that proxy a cash-pay practice: on lead campaigns, Dentists and Dental Services CPC fell 41.72% and Health and Fitness fell 30.30% — among the biggest drops in the set. But on cost per lead, Dentists and Dental Services is the single most expensive vertical at $61.56, with Beauty and Personal Care second at $50.91 — against a $27.39 all-industry average and a $12.30 floor (Career and Employment).
WordStream's cross-platform note: Google Ads CPC is now more than double Meta's average CPC, with the caveat that Google Search typically captures stronger purchase intent. They attribute the improvements to bidding and campaign-optimization changes — i.e. the platform's own AI, which is why this sits in this feed at all rather than in a media-buying newsletter.
Why it matters for an independent practice: For an MMR client this is a budget conversation with numbers attached, and the honest reading is uncomfortable in a useful way. One: if your practice's Meta CPC dropped ~30–40% this year and your cost per patient did not move, the leak is not the ad — it is everything after the click, and the benchmark set now gives you the evidence to say so to a client who wants more ad spend. Two: a $61.56 dental lead and a $50.91 beauty lead are the closest public analogues to a regen consult, so they are a defensible floor for what a cash-pay orthobiologics lead should be expected to cost — anyone quoting dramatically less is either buying a different intent or counting a different thing. Three: Meta clicks at half of Google's price with weaker intent is the classic argument for splitting the funnel — Meta for the education and the follow-up-query work item 4 of yesterday's digest was about, Google for the patient already typing "PRP knee near me."
Meta shipped an MCP server that lets Claude or ChatGPT stand up a business's WhatsApp messaging just by being asked to — account creation, phone verification, API access, message templates, webhooks
TechCrunch · Sarah Perez, Consumer News Editor · September 15, 2026Buildable AI
The thing that shipped is the WhatsApp Business Tools MCP — a Model Context Protocol server that connects an AI coding agent (Claude, Cursor, Codex or ChatGPT are the ones named) directly to the WhatsApp Business Platform. Meta's framing: the setup previously required moving between the Developer Console, Business Manager, the API reference and an editor; now you describe what you want in a chat.
What the agent actually does, per Meta: creates the WhatsApp Business account, adds and verifies the phone number, registers it for Cloud API access, and checks Terms of Service status. Then it will write a message template from a description or edit an existing one, test messages and webhooks, and monitor the things that historically failed silently — ToS status, payment method, business verification.
This extends Meta's existing MCP lineup beyond ads and app-config management. TechCrunch's context line is the important one for anyone building: PayPal, Stripe, GitHub, Notion, Slack, Salesforce, Atlassian, X, Google and Microsoft all now ship MCP servers. MCP has quietly become the standard way a vendor exposes its product to an agent, which is a different fact than any individual launch.
Also noted: Meta's separate Social Technologies MCP can be used alongside it to discover API endpoints, search documentation and troubleshoot errors during setup.
Why it matters for an independent practice: Zero medicine here, and two uses. The build angle: this is the cheapest version of the thing every practice is being sold — patient messaging that answers, confirms and reminds — and the barrier that just fell is not the AI, it is the plumbing. The two-week integration project that used to justify an agency retainer is now a conversation with Claude. For MMR that cuts both ways: it makes messaging automation deliverable for small clients at a real margin, and it prices the setup work itself close to zero, so the durable service is the content and the escalation rules, not the wiring. The stewardship angle, and it is a hard line: WhatsApp is not a HIPAA-friendly channel for PHI in the U.S., Meta will not sign a BAA for it, and an agent that can create accounts and write templates on your behalf will not stop you from building something that asks a patient about symptoms. Use it for appointment logistics, directions, forms and "please call the office" — never for clinical content. And note the pattern from item 3 applies directly: this agent needs credentials to your business account, so it is precisely the "governable digital identity with its own limits" problem, arriving as a convenience.