Now anyone reading that article over the weekend was probably very confused, since the death of Alex Pretti isn’t exactly a DATA breach.
And, of course, Minnesota doesn’t have a “department of homeland security.”
It does, however, have a Department of Human Services…and THAT was what was breached.
“A single user inappropriately accessed private data within the Minnesota Department of Human Services (DHS) ecosystem, potentially impacting 303,965 individuals, officials report.”
This was not a hack per se, but a case in which a legitimate person accessed something they shouldn’t have accessed. Certainly a breach, and the person’s access was terminated.
You know what the problem is with these AI medical bots? They hallucinate and do inaccurate stuff. When you use humans for your medical needs, they’re gonna get it right.
The company that replaced a steel mill with a hospital is in a bit of trouble with the U.S. Department of Justice, in an action started under the Biden Administration and concluded under the Trump Administration.
“Affiliates of Kaiser Permanente, an integrated healthcare consortium headquartered in Oakland, California, have agreed to pay $556 million to resolve allegations that they violated the False Claims Act by submitting invalid diagnosis codes for their Medicare Advantage Plan enrollees in order to receive higher payments from the government….
“Specifically, the United States alleged that Kaiser systematically pressured its physicians to alter medical records after patient visits to add diagnoses that the physicians had not considered or addressed at those visits, in violation of [Centers for Medicare & Medicaid Services (CMS)] rules.”
Now of course you can code a bot to perform fraud, but it’s easier to induce a human to do it.
The U.S. National Institute of Standards and Technology (NIST) says that we should…drumroll…adopt standards.
Which is what you’d expect a standards-based government agency to say.
But since I happen to like NIST, I’ll listen to its argument.
“One way AI can prove its trustworthiness is by demonstrating its correctness. If you’ve ever had a generative AI tool confidently give you the wrong answer to a question, you probably appreciate why this is important. If an AI tool says a patient has cancer, the doctor and patient need to know the odds that the AI is right or wrong.
“Another issue is reliability, particularly of the datasets AI tools rely on for information. Just as a hacker can inject a virus into a computer network, someone could intentionally infect an AI dataset to make it work nefariously.”
So we know the risks, but how do we mitigate them?
“Like all technology, AI comes with risks that should be considered and managed. Learn about how NIST is helping to manage those risks with our AI Risk Management Framework. This free tool is recommended for use by AI users, including doctors and hospitals, to help them reap the benefits of AI while also managing the risks.”
“A subject is a human user or NPE, such as a device that issues access requests to perform operations on objects. Subjects are assigned one or more attributes.”
If you have a process to authorize people, but don’t have a process to authorize bots, you have a problem. Matthew Romero, formerly of Veza, has written about the lack of authorization for non-human identities.
“Unlike human users, NHIs operate without direct oversight or interactive authentication. Some run continuously, using static credentials without safeguards like multi-factor authentication (MFA). Because most NHIs are assigned elevated permissions automatically, they’re often more vulnerable than human accounts—and more attractive targets for attackers.
“When organizations fail to monitor or decommission them, however, these identities can linger unnoticed, creating easy entry points for cyber threats.”
Veza recommends that people use a product that monitors authorizations for both human and non-human identities. And by the most amazing coincidence, Veza offers such a product.
People Require Authorization
And of course people require authorization also. They need authorization:
Oh yeah…and to access privileged resources on corporate networks.
It’s not enough to identify or authenticate a person or NPE. Once that is done, you need to confirm that this particular person has the authorization to…launch a nuclear bomb. Or whatever.
Your Customers Require Information on Your Authorization Solution
If your company offers an authorization solution, and you need Bredemarket’s content, proposal, or analysis consulting help, talk to me.
I’m sure you’ve heard the empowerment gurus on LinkedIn who say that people working for companies are idiots. Admittedly it seems that too many companies don’t care about their employees and will jettison them at a moment’s notice.
So what do the empowerment gurus recommend? They tell people to take control of their own destiny and work for themselves. Don’t use your talents to fatten some executive’s stock options.
Google Gemini.
However, those of us in the United States face a huge barrier to that.
The average annual premium for employer-sponsored family coverage totaled about $27,000 in 2025, according to [the Kaiser Family Foundation]. This is coverage for a family of four.
But workers don’t pay the full sum. They contributed just $6,850 — about 25% — toward the total premium, according to KFF. Employers subsidized the rest, paying about $20,000, on average.
By comparison, if the enhanced ACA subsidies expire next year, the average family of four earning $130,000 would pay the full, unsubsidized premium for marketplace coverage.
Their annual insurance premiums would jump to about $23,900, more than double the subsidized cost of $11,050 — an increase of almost $12,900, according to the Center on Budget and Policy Priorities.
Google Gemini.
Do how do those who oppose Communist subsidies propose to solve ACA healthcare costs?
By providing people with an annual health savings account funding of…checks notes…$1,500.
Perhaps I’m deprived because of my 20th century math education, but last I checked $1,500 in funding is less than $12,900 in losses.
People who are on COBRA, or a similar program such as Cal COBRA, experience similar sticker shocks.
So my advice to people is to do one or both of the following:
Get employer-subsidized healthcare.
Marry someone with employer-subsidized healthcare.
We all agree that deepfakes can (sometimes) result in bad things, but some deepfakes present particular dangers that may not be detected. Let’s look at how deepfakes can harm the healthcare and legal professions.
But I don’t want to talk about the general issues with believable AI (whether it’s Sora 2, Nano Banana Pro, or something else). I want to hone in on this:
“Sora 2 security risks will affect an array of industries, primarily the legal and healthcare sectors. AI generated evidence continues to pose challenges for lawyers and judges because it’s difficult to distinguish between reality and illusion. And deepfakes could affect healthcare, where many benefits are doled out virtually, including appointments and consultations.”
Actually these are two separate issues, and I’ll deal with them both.
Health Deepfakes
It’s bad enough that people can access your health records just by knowing your name and birthdate. But what happens when your medical practitioner sends you a telehealth appointment link…except your medical practitioner didn’t send it?
Grok.
So here you are, sharing your protected health information with…who exactly?
And once you realize you’ve been duped, you turn to a lawyer.
This one is not a deepfake. From YouTube.
Or you think you turn to a lawyer.
Legal Deepfakes
First off, is that lawyer truly a lawyer? And are you speaking to the lawyer to whom you think you’re speaking?
Not Johnnie Cochran.
And even if you are, when the lawyer gathers information for the case, who knows if it’s real. And I’m not talking about the lawyers who cited hallucinated legal decisions. I’m talking about the lawyers whose eDiscovery platforms gather faked evidence.
Liquor store owner.
The detection of deepfakes is currently concentrated in particular industries, such as financial services. But many more industries require this detection.
When I remember to transcribe my meetings, and when I CAN transcribe my meetings, my meeting transcriber of choice happens to be otter.ai. And if I’m talking to a healthcare prospect or client, and when they grant permission to transcribe, the result is HIPAA compliant.
Is the medical facility working with the right patient?
Hackensack Meridian Health in New Jersey claims that it knows who its patients are. It has partnered with CLEAR for patient identification, according to AInvest. Among the listed benefits of the partnership are enhanced security:
“CLEAR1 meets NIST’s Identity Assurance Level 2 (IAL2) standards, a rare feat in the healthcare sector, ensuring robust protection against fraud.”
I last discussed Syneos Health on August 15, in a popular post on early stage commercialization. When I checked for recent news I discovered that Syneos Health received a commercialization setback in India for the QL2107 Injection.
[T]he Subject Expert Committee (SEC) functional under the Central Drugs Standard Control Organization (CDSCO) has rejected its Phase III clinical trial proposal for QL2107 Injection….
After detailed deliberation, the committee opined that, “the proposed clinical trial is focused completely on Pharmacokinetic (pK) parameters. Moreover, primary objective and secondary objective of phase-III study protocol has not been demonstrated for confirmation of therapeutic benefit and efficacy end point. Hence, the committee didn’t recommend to conduct the clinical trial in India.”
So what is the QL2107 Injection? First off, it comes from a Chinese company.
Qilu Pharmaceutical is one of the leading vertically integrated pharmaceutical companies in China focusing on the development, manufacturing and marketing of active pharmaceutical ingredients (APIs) & finished formulations….Dedicated to offering more affordable medicines to the world and improving people’s well-being, Qilu has exported its products to over 100 countries.
The literature on QL2107 repeatedly refers to Qilu Pharmaceutical rather than Syneos Health. But presumably there’s a partnership somewhere.
According to this website, QL2107 is a “pembrolizumab biosimilar,” a fancy way to say that it is similar to pembrolizumab (brand name Keytruda®), a monoclonal antibody with possible anti-cancer applications. It’s already undergone clinical trials.
But a Phase III clinical trial is special. The Gilead Clinical Trials website defines the four phases of clinical trials, including the third:
Phase 3 trials continue to evaluate a treatment’s safety, effectiveness, and side effects by studying it among different populations with the condition and at different dosages. The potential treatment is also compared to existing treatments, or in combination with other treatments to demonstrate whether it offers a benefit to the trial participants. Once completed, the treatment may be approved by regulatory agencies.
Although there is a fourth phase, continuous monitoring, that is obviously important.
Imagen 4.
In summary, QL2107 is not a home run or even a triple. At least in India, it’s stuck at second.
While I’ve previously addressed pharma commercialization in terms of ensuring that patients use (and purchase) their medications, commercialization occurs long before that. After all, for a prescription drug to be available on the market, it has to get to the market in the first place.
“Early-stage biopharma companies have traditionally had limited options for getting their first asset to market. In most cases, they pursue deals with larger partners and lose or limit rights to their asset, or become a fully integrated company through heavy investment and a great deal of risk.”
Syneos Health has a solution for that. To learn the details of Syneos Health’s full-service pharma commercialization solution, visit this page.
Oh, and the company also has case studies.
“We helped build a European commercial capability via a comprehensive commercialization partnership, introducing a Commercial Leadership function to support the design and execution of the overall launch plan and integrate other services. We were able to scale quickly and establish commercial operations, designed a European launch plan and forecast and launched within three months in one EU country, with a subsequent sequenced launch through Europe, despite the ambiguities of COVID-19.
“In 12 weeks, we provided a full virtual infrastructure that included Field Teams, MSLs, Access Teams, Marketplace and Access/Pricing Consulting, Advertising, Public Relations and Medical Communications, increasing operational efficiencies through integrated Communications teams to reduce duplication in effort across promotional channels and recruiting, training and deploying sales reps, achieving an annual run rate of >$200 million.
“We partnered with the commercial team to provide all commercial launch services, offering crucial global leadership that enabled the team to dynamically scale up and down to respond to changing launch timelines and to balance short- and long-term financial objectives. With a heavy emphasis on market development, we empowered the customer to be fully engaged and aligned with all communities and show an in-depth understanding of market dynamics.”