CareChronicle logo

CareChronicle

Archives
Log in
Subscribe
August 17, 2026

AI watermarks could destroy anonymous writing — Week of August 10, 2026

The FTC comes for Epic, Medicare starts paying for AI, Congress questions rogue agents

CareChronicle

Issue №08 · Two-weeks in review: August 03 - 17, 2026


Two weeks in review: The FTC is probing Epic’s control of patient data just as ambient AI companies like Abridge are moving from documenting clinical decisions to helping shape them. This begs the question: who controls the intelligence layer around the EHR?

Meanwhile, Anthropic’s new text watermark has mostly been covered as an anti-cheating tool, but the underlying literature describes a system that can trace generated text back to individual users — a capability Anthropic says it won’t use, which is different from one it doesn’t have.

This week: Epic’s data moat draws federal scrutiny, a Mayo whistleblower case complicates its AI-leader narrative, Medicare puts real reimbursement dollars behind deployed AI, and agent security incidents reach Congress.


Privacy Watch:

Every journal got AI watermarking wrong.

WHAT HAPPENED: Anthropic, alongside other AI providers, are introducing machine-readable watermarks to comply with EU legislation. Anthropic is rolling this out globally, despite not being required to do so, because it says it can't yet reliably scope watermarking by region. Most of the controversy has focused on "AI slop," but determined offenders will simply route around it with open models and watermark-removal tools.

HOW DOES IT WORK? Anthropic's approach is based on SynthID: a secret key and the preceding text influence subsequent token choices, and those tiny branching decisions pile up into a statistical fingerprint that says "Claude was here."

an example of per-user watermarking, via “Provably Robust Multi-bit Watermarking for AI-generated Text”

HOW DOES THIS AFFECT YOU? Grants. Patents. Corporate contracts. Claude's watermark doesn't tell you how much Claude contributed, only that it did, so editing, translation, summarization, or full-document generation can all create risk. NIH allows limited AI use but can act against grants substantially developed by AI. For patents, detectable AI involvement could become evidence in a dispute over what the named inventor actually conceived.

Anthropic plans to expose watermark detection through an API.

WHAT ABOUT PRIVACY? Anthropic says they don't plan on tracking individual users. But the published watermark literature provides the recipe on how to do just that:

"Later, when some suspicious LLM-generated text used for malicious purposes is found, the service provider can identify and extract the watermark to trace the original user who generated the text."

Trusting that Anthropic et al. won't leverage this in the future is like letting someone install a flock camera array in your house and believing that they're not going to point it at you personally.

If AI editing becomes ubiquitous (think: Word, Grammarly, email editing, phone keyboards) your writing itself could eventually become an identifier. Whistleblowing, anonymous complaints, organizing against a government: all become traceable back to you.


Ongoing Story:

Mayo's AI ambitions meet governance allegations.

via Joe Ahlquist / Post Bulletin

Mayo wants to be healthcare's AI leader: The system says it has 500+ AI models in various stages of deployment and trained 20,000 employees through a voluntary AI program last year. CEO Gianrico Farrugia told Axios Mayo's constraint is no longer the models, but whether other hospitals have the infrastructure to use them: “I could give this to every hospital — and they can't use it.”

AI misconduct? A former Mayo AI governance leader says she was pushed out after raising alarms about AI misuse, privacy and research oversight. Mayo argues four of the five matters she reported weren't sufficiently tied to federal funding to support False Claims Act protection. It also argues her depression did not meet the ADA threshold and her leave did not cause her termination; the Post Bulletin notes she was fired while still on FMLA leave.


Digital Health Update:

Epic draws federal scrutiny, Abridge moves into their territory

Epic's data moat draws federal scrutiny: The FTC is investigating Epic, reportedly asking health-tech companies how the EHR giant grants or restricts access to patient data. Epic controls 43.7% of the U.S. acute-care EHR market (inpatient beds put that closer to 60%) and denies blocking competitors; Texas and Particle Health are separately challenging its data practices.

Meanwhile, Abridge is moving deeper into Epic's territory: The ambient-AI company says 300+ health systems have adopted its chart-aware decision support since April. More than half of eligible clinicians are now monthly users, according to Abridge, as the former scribe expands into patient-specific clinical guidance before, during, and after visits.

Patients have their own copilot: Roughly one-third of U.S. adults now use AI for health advice and 19% for interpreting medical tests. Physicians describe patients stopping medications, challenging vaccines or checking their recommendations against ChatGPT mid-visit: “Then why are you here?”


Government Watch:

Medicare Adopts AI

Medicare is putting real dollars behind AI adoption: Temporary NTAP payments are increasingly giving hospitals a financial reason to deploy new AI devices before their ROI is fully established. Starting October 1, Medicare will pay up to $137.53 per inpatient case using Aidoc's CT triage software. At the same time, CMS is phasing out the easier breakthrough-device route to NTAP, pushing future applicants back toward demonstrating substantial clinical improvement.

Coverage could get faster, too: CMS's proposed RAPID pathway could start national Medicare coverage roughly 60 days after FDA authorization for a narrow class of breakthrough devices studied in Medicare beneficiaries.


Interested in early access? Subscribe.

Cybersecurity:

Agents Invade the Real World

  • OpenAI agents breached Hugging Face: During security testing, agents built a hidden message board, shared exploits and eventually compromised Hugging Face after OpenAI initially thought it had contained the problem.

  • Anthropic's agent turned deceptive: UK evaluators found Mythos 5 responsible for 17 of 19 unauthorized actions, including malicious code and fake identities intended to trick a human into approving the code; no real-world harm was found.

  • Congress wants answers: House Democrats asked Sam Altman and Dario Amodei to testify under oath and demanded incident logs after agents from both companies accessed outside systems during testing.

  • Industry is building incident rules: More than 120 organizations, including Nvidia, Cisco and CrowdStrike, proposed SAFE, a shared reporting system for unauthorized agent activity and near misses modeled partly on aviation safety.

  • Healthcare is following suit: CHAI convened a nearly 100-member cybersecurity group, including CISOs from eight health systems, to build defensive and offensive playbooks for frontier-model risks.


AI Model Updates:

Open-weights Impress, Competition on Pricing

man in red hoodie standing
Photo by Joran Quinten on Unsplash
  • Model prices keep falling: OpenAI and Anthropic are cutting mid-tier prices sharply as cheaper Chinese models gain enterprise workloads; OpenAI says Luna fell 80%, while Anthropic priced Claude Opus 5 at roughly half its prior flagship level.

  • Meta reboots around open weights: Muse Glimmer is a 30B model built to run on a single GPU, with the larger Muse Spark 1.2 promised within weeks as Meta tries to close the gap with OpenAI and Anthropic.

  • Google replaces Flash in three weeks: Gemini 3.7 Flash is roughly half the price of 3.6 Flash and scores better on Google's coding and document benchmarks.

  • xAI ships Grok 4.6: The new model keeps Grok 4.5's $2/M input-token price; xAI claims better speed and capability but provided little benchmark detail.

  • OpenAI adds an ultrafast tier: GPT-5.6 Sol can reach up to 750 output tokens per second on Cerebras, with OpenAI saying one internal security workflow fell from 1–2 hours to 10–15 minutes.

  • Alibaba splits Qwen licensing: The smaller Qwen3.8-27B ships under Apache 2.0, while the 2.4T flagship requires separate permission for companies earning over $50M annually from AI services.


AI in Clinical Practice:

Trending Stories This Month

OpenAI Foundation backs hepatitis C follow-up: The Common Health Coalition is launching a $100M initiative using AI to identify patients lost to hepatitis C care, starting in four states. It aims to at least double cure rates within two years.

Ambient AI stops at the inbox: HSHS has rolled ambient documentation out to 320 physicians and APPs, but says inbox work remains too clinically nuanced to automate safely.

Ochsner credits workflow, not technology: Ochsner reports a 2% readmission reduction on units using virtual nurses for admissions, discharges, and transfers. Its CNO attributes the improvement primarily to standardized workflows and change management rather than the virtual-nursing technology itself.

AI training improves confidence, not much else: A study of 139 fifth-year medical students found a three-hour GenAI workshop substantially improved self-reported AI literacy and collaborative-learning attitudes, but produced no detectable change in patient-centered orientation.


You're reading CareChronicle. Reply with what you want more of — we read every note.

Don't miss what's next. Subscribe to CareChronicle:
Older → Full AI Communism — Week of July 27, 2026
Bluesky
Twitter
Powered by Buttondown, the easiest way to start and grow your newsletter.