States race to launch rural health transformation plans

posted in: All news | 0

By Sarah Jane Tribble, Arielle Zionts and Maia Rosenfeld, KFF Health News

Imagine starting the new year with the promise of at least a $147 million payout from the federal government.

Related Articles


States go their own way as RFK Jr. shifts federal vaccine policy


MN physicians describe ‘chaos and fear’ due to immigration actions


The US is on the verge of losing its measles elimination status. Here’s why that matters


New diet guidelines say to double up on protein, but nutrition experts are wary


RFK Jr.’s MAHA movement has picked up steam in statehouses. Here’s what to expect in 2026

But there are strings attached.

In late December, President Donald Trump’s administration announced how much all 50 states would get under its new Rural Health Transformation Program, assigning them to use the money to fix systemic problems that leave rural Americans without access to good health care. Now, the clock is ticking.

Within eight months, states must submit revised budgets, begin spending, and show the money is going to good use. Federal officials will begin reviewing state progress in late summer and announce 2027 funding levels by the end of October.

The money — divided into unique allocations for each state, ranging from $147 million for New Jersey to $281 million for Texas — represents the first $10 billion installment from the five-year, $50 billion program. Congress created the fund as a last-minute sweetener in Trump’s One Big Beautiful Bill Act last summer to offset the outsize fallout anticipated in rural communities from the statute’s nearly $1 trillion in Medicaid spending cuts over the next decade.

Federal officials crafted the fund to give states “space to be creative,” Mehmet Oz, administrator of the Centers for Medicare & Medicaid Services, said on a call with reporters after announcing the funding Dec. 29. “Some states will fail, and we will learn from that.”

The money was divided according to a complicated formula.

In 2026, each state will receive an equal $100 million share under the law for the first half of the money, plus additional funding from the second half. Oz’s staff steered payouts from the second portion based on each state’s rural score, as well as results from a “technical” scoring system for project proposals.

Within hours of the announcement, academics and researchers began to parse the awards to better understand why some states received more than others, including whether the awards reflected any partisanship or political favoritism.

At first glance, total awards do not appear to favor states governed by either Republicans or Democrats. But one academic data analysis teased out the amount awarded for each state’s technical score, which is the part determined by the discretion of agency officials.

The analysis was performed at the University of North Carolina’s Cecil G. Sheps Center for Health Services Research, which specializes in rural health. A KFF Health News review of the Sheps Center data found that states with Republican governors tended to receive more money for the parts of their application based on the technical score. Democratic-controlled states crowded the bottom quarter of those technical score awards.

Overall, though, the state awards reveal wild variation in how much money each state will get per rural resident, almost a hundredfold difference between the top and bottom.

In an emailed statement to The Arizona Republic, a spokesperson for Arizona’s Democratic Gov. Katie Hobbs accused the administration of shortchanging rural residents in the state, which was awarded $167 million this year from the program.

CMS spokesperson Chris Krepich said in an emailed statement to KFF Health News that “politics played no role in funding decisions.”

On the December call, Oz pushed states to start working on policy actions championed by the administration — such as approving presidential fitness tests and restricting food benefits — that could require legislative approval.

Half of states promised to mandate the presidential fitness test, Oz said. Many states also proposed food waivers under the Supplemental Nutrition Assistance Program, known as SNAP, which would limit low-nutrition items such as soda. He also said some states promised to teach health care professionals about nutrition. And others confirmed they will repeal certificate-of-need laws, which require companies to prove that new health facilities they want to open are necessary.

Krepich said CMS’ new Office of Rural Health Transformation is hiring program officers to serve as point people for three or four states. Many states are setting up their own offices to oversee the new funding.

Oz highlighted Alabama’s “big maternity initiative with robotics doing ultrasounds” and said states are tackling issues ranging from behavioral health to obesity.

A KFF Health News review of state “ project abstracts” and “ spotlights” released by CMS shows that many states plan to address the workforce challenges in rural areas. Delaware, for example, plans to use its funding to create the state’s first four-year medical school with a rural primary care track.

A third of states said they want to improve electronic health records, and every state mentioned telehealth.

Many state legislatures must pass laws to distribute the funding to their state offices. Meanwhile, state officials are hiring staff, organizing advisory committees, and preparing to dole out money.

“I’m excited about what’s next,” said Terry Scoggin, former interim chief executive of the Texas Organization of Rural & Community Hospitals, or TORCH. Texas was awarded the biggest allocation. The money will bolster a rural hospital funding bill Republican Texas Gov. Greg Abbott signed last year, Scoggin said.

More than two dozen cash-strapped rural hospitals in Texas have closed or been converted to clinics since 2005, a nationwide trend that hit the Lone Star State particularly hard. The state has the largest rural population in the United States. Texas’ allocation amounts to about $66 per rural resident, according to a KFF policy analysis. By contrast, Rhode Island was granted about $6,300 per rural resident.

Scoggin said he has “a ton of concerns” about companies taking the money instead of it helping rural hospitals and residents. “I was blown away about how many for-profit companies reached out.” The companies have also called rural hospitals and asked to work with them to apply for state money, he said.

The awards should be judged on how they benefit rural residents because “the stated goal of the program is to improve rural health,” said Paula Chatterjee, an assistant professor of medicine at the University of Pennsylvania who co-authored a Senate Finance Committee memo on the transformation fund.

Researchers at the Sheps Center conducted the analysis to estimate how much money states received from the technical score, which is the portion of funding based on the quality of their proposals and state policy actions that align with “Make America Healthy Again” priorities.

New Mexico won the least amount of technical funding, with less than 10% of its award based on the discretionary metrics. Alaska won the largest technical award, according to the Sheps Center data.

Texas, Nebraska, New Hampshire, and Hawaii rounded out the top five recipients of technical funding. In addition to New Mexico, the other lowest technical awards went to Michigan, New Jersey, Arizona, and California.

Mark Holmes, director of the Sheps Center, declined to comment on whether he saw any political bias in the awards but said the nuance in the final portion of discretionary awards based on technical scores is important because those dollars can be redistributed and potentially clawed back in future years.

“We can be fairly certain that every state will get at least a slightly, if not a vastly, different amount next year based on this re-pooling and reallocation piece,” Holmes said.

States now have a limited time to show they’re using the money effectively to secure future funding.

But they can’t start spending yet. CMS followed standard grant procedures and is requiring each state to submit revised budgets before they can draw down money, Krepich said.

States have until Jan. 30 to resubmit their budgets, and CMS then has 30 days to respond, according to the standard Notice of Award. Under that timing, some states may not have cash in hand until March.

“CMS is working closely with states to complete this process as efficiently as possible,” Krepich said.

©2026 KFF Health News. Distributed by Tribune Content Agency, LLC.

4 in 5 small businesses had cyberattacks last year and almost half of those were AI powered

posted in: All news | 0

One more reason things cost more today: cybercrime.

A survey by the Identity Theft Resource Center, a San Diego-based education and victim resource nonprofit, found that 38% of small businesses hit by a cyberscam or breach in the previous 12 months passed those losses to customers by raising prices.

Another key finding: Cybercrime against small businesses is increasingly fueled by artificial intelligence.

“The era of predictable, human-scale threats has been superseded by a new reality of automated, intelligent and massively scalable attacks powered by AI,” said the report, which discusses trends in threats, prevention and attacks. It also gives detailed recommendations about network and application security, data protection and employee and contractor practices. (The survey reached out to more than 650 companies across more than 12 industries in August.)

Eva Velasquez, the CEO of the Identity Theft Resource Center, said the results offer a stark reminder that hackers aren’t picky. They will grab data and money from anyone, including large and small businesses, and individuals.

“When we think about risk, it really is all businesses,” Velasquez said. From mom and pops to large companies, “They’re all attractive to hackers.” Small businesses sometimes don’t pay enough attention to cybersecurity “because they think they’re not vulnerable. They think, ‘Well, why would anybody target me?’”

Not only are they being targeted, but they are being successfully breached, some multiple times a year. Two or three breaches in a 12-month period was the most common pattern. Another 34% had one breach and almost 12% had four or more.

One encouraging shift: The percentage of companies with one or two breaches increased from 2024, while the percentage of companies with more than two breaches dropped. Perhaps companies are improving their cybersecurity protocols after a first or second breach.

The report, however, said companies being hit only once says something about cyber attackers’ methods.

“Threat actors appear to be focusing on opportunistic, high-volume strikes. This alters the risk calculus for (small businesses), shifting the primary challenge from defending against a determined, persistent adversary to repelling a continuous barrage of single-shot attacks from a multitude of sources.”

The nonprofit helps individuals for free, and business in some cases get charged fees used to fund its free services. The nonprofit faced a significant drop in federal government grants last year, but remains financially robust thanks to private donors and unclaimed awards from class action settlements, Velasquez said.

“Our services remain available at the same level they were prior to changes in the federal grant processes/availability,” Velasquez said.

AI attacks have skyrocketed

Four out of five small businesses reported they were victims of a security or data breach in the past 12 months — a statistic unchanged from a year before.

But the nature of these attacks has changed, with AI taking center stage.

In past surveys of small businesses that suffered cyber and data breaches, incidents were caused by insecure cloud environments, ransomware, hackers, malicious employees or contractors, lapses by remote workers, software flaws and attacks on third-party vendors, the report said.

AI was not even named as a cause, as recently as 2024.

But in 2025, 41% of small business victims said AI was the root cause of a recent attack.

Generative AI can craft “highly personalized social engineering attacks that mimic the tone and context of legitimate internal communications,” the report says.

Hackers now are launching large-scale, automated attacks that cover a lot more ground, Velasquez said.

In cybercrime, AI is the great equalizer. Sophisticated scams can be carried out by less knowledgeable wrongdoers who use generative AI.

“These tools are effectively democratizing advanced attack capabilities that were once the domain of highly skilled actors,” the report said.

The cause for data and cyber breaches that saw the biggest percent drop in 2025, compared to 2024, was remote work — which makes sense, as workers have returned to offices. Every other cause of attacks has also dipped, perhaps as scammers and data thieves turned to AI.

While AI was added to the list and some causes became less prevalent, no cause disappeared.

Paying the price

When small businesses suffer a breach or fraud, the financial hit can include lost revenue, legal costs, fines and penalties, insurance, marketing and security overhauls.

Adding up these expenses, the survey found that 37% of companies lost more than $500,000 last year, per incident. A quarter lost up to $250,000 and another quarter lost between $250,000 and $500,000.

To recoup costs, companies used cash reserves, turned to investors for funds, cut jobs, or tapped credit and cyber insurance. They also adopted a new tactic: 38% raised prices.

“This represents a significant, inflationary macroeconomic ripple effect stemming directly from the worsening cyberthreat landscape for small businesses,” the report said.

One reason for this change may be that other sources of funding were harder to come by. A smaller percentage got money from investors to respond to cyber and data breach incidents in 2025 than 2024. Also, fewer companies turned to cyber insurance, with almost a quarter of companies saying they had “difficulty obtaining or renewing cyber insurance” after a breach. “This suggests that as the frequency and cost of claims have risen, insurers have responded by adjusting underwriting standards.”

Compared to 2024, fewer companies cut jobs as a way to offset losses due to cybercrime: 18%, down from 27%.

Relying less on insurance and investors, and opting to cut fewer jobs as a result of cyber breaches, may have each or all contributed to the raising of prices.

Preventing losses

Which sensitive data did crooks slink away with?

Employee data was most commonly accessed in breaches, with customer data and company IP both ranking close behind.

To fight back, some companies have robust tools in place, but the survey also found a disturbing trend. “The implementation of critical security measures, such as multi-factor authentication, has declined,” it said. One reason, the report posited: company leaders are overwhelmed and “neglecting the very basics that provide an effective defense.”

Velasquez and her nonprofit urge companies to keep studying known and evolving threats and to keep adapting their cybersecurity practices.

“The single most critical access control for any (small business) to implement is MFA,” the report said. MFA stands for multi-factor authentication — a system of safety checks where a request to access secure information has to be vetted through multiple, independent channels. MFA makes it “significantly harder for attackers to use stolen passwords.”

Examples of these are free authenticator apps (like Google Authenticator), SMS codes that get sent to a user’s phone when they try to log in using a password, and physical hardware tokens.

The report cited an “alarming decline in MFA adoption for internal systems,” from around 33% in 2024 to around 27% in 2025. This “represents a critical, high-priority vulnerability that SBs must address immediately.”

‘A societal shift’

“Really good companies with robust cybersecurity can have a breach,” Velasquez said. “It’s not an automatic indicator of negligence.”

But companies with less robust cybersecurity are far more at risk.

The report has six pages of tips for preventing cyber and data breaches and countering AI-powered attacks. These range from what kind of training companies should offer to how firewalls should be set up, to data encryption best practices and more.

Small businesses need to strengthen their prevention, but Velasquez also made this pitch to consumers: don’t turn away from companies that are taking steps to protect your data, even if it’s annoying.

That crushingly long four-second delay until a verification text message arrives, the extra screen taps involved in using an authenticator app — those are a sign a company is doing things right.

“One of the conflicts that we have is convenience versus security. And businesses are fighting this tension between, ‘I have to be secure and I have to make people jump through hoops to prove that they are who they say they are, so that I can protect their data, their account, their information.’ And individuals going, ‘I want convenience.’”

“If we have a societal shift where we understand that some friction, a little bit of inconvenience, is actually good for us,” she said.

A company that asks you to do those things is one you should do business with, Velasquez added, “because you know that they have put measures in place to protect you and your data.”

Federal officers detain a 5-year-old boy who school official says was used as ‘bait’

posted in: All news | 0

By HALLIE GOLDEN

A 5-year-old boy arriving home from preschool in Minnesota was taken by federal agents along with his father to a detention facility in Texas, school officials and the family’s lawyer said, making him the latest child caught up in the immigration enforcement surge that has riled the Twin Cities in recent weeks.

Federal agents took Liam Conejo Ramos from a running car while it was in the family’s driveway on Tuesday afternoon, Columbia Heights Public Schools Superintendent Zena Stenvik said during a news conference Wednesday. The officers then told him to knock on the door to his suburban Minneapolis home to see if other people were inside, “essentially using a 5-year-old as bait,” she said.

Stenvik said the family has an active asylum case and has not been ordered to leave the country.

“Why detain a 5-year-old?” she asked. “You cannot tell me that this child is going to be classified as a violent criminal.”

Department of Homeland Security spokesperson Tricia McLaughlin said in a statement that “ICE did NOT target a child.”

She said Immigration and Customs Enforcement was conducting an operation to arrest the child’s father, Adrian Alexander Conejo Arias, who McLaughlin said is from Ecuador and in the U.S. illegally. He fled on foot without the boy, she said.

“For the child’s safety, one of our ICE officers remained with the child while the other officers apprehended Conejo Arias,” McLaughlin said, adding that parents are given the choice to be removed with their children or have them placed with a person of their choosing.

Stenvik said another adult who lives at the home was outside when the father and son were taken, but agents wouldn’t leave Liam with that person. DHS didn’t immediately to respond an email Thursday asking if Conejo Arias had asked to keep his son with him.

Liam and his father were being held in a family holding cell in Texas, Marc Prokosch, the family’s lawyer, said during the news conference.

“Every step of their immigration process has been doing what they’ve been asked to do,” Prokosch said of the family’s asylum claim. “So this is just cruelty.”

Minnesota has become a major focus of immigration sweeps by DHS-led agencies. Greg Bovino, a U.S. Customs and Border Patrol official who has been the face of the crackdowns in Minneapolis and other cities, said 3,000 “of some of the most dangerous offenders” have been arrested in Minnesota in the last six weeks.

Julia Decker, policy director at the Immigrant Law Center of Minnesota, said advocates have no way of knowing whether the government’s arrest numbers and descriptions of the people in custody are accurate.

Liam is the fourth student from Columbia Heights Public Schools who has been detained by ICE in recent weeks, said Stenvik. A 17-year-old student was taken Tuesday while heading to school, and a 10-year-old and a 17-year-old have also been taken, she said.

The district is made up of five schools and about 3,400 students from pre-K to 12th grade, according to its website. The majority of the students come from immigrant families, according to Stenvik.

She said they’ve noticed their attendance drop over the past two weeks, including one day where they had about one-third of their students out from school.

Ella Sullivan, Liam’s teacher, described him as “kind and loving.”

“His classmates miss him,” she said. “And all I want is for him to be safe and back here.”

___

Associated Press reporter Kathy McCormack contributed to this story.

Related Articles


Army orders military police to get ready for a possible Minneapolis deployment, AP source says


Autopsy finds Cuban immigrant in ICE custody died of homicide due to asphyxia


Minnesota corrections officials again dispute ICE numbers on criminals


DFL state lawmakers decry ICE tactics toward U.S. citizens


Immigration officers assert sweeping power to enter homes without a judge’s warrant, memo says

Woman who led a protest at a St. Paul church service has been arrested, Bondi says

posted in: All news | 0

A woman who led an anti-immigration enforcement protest that disrupted a service at a Minnesota church has been arrested, Attorney General Pam Bondi said Thursday.

Bondi announced the arrest of Nekima Levy Armstrong in a post on X days after protesters during Sunday service entered the Cities Church in St. Paul, where a local official with U.S. Immigration and Customs Enforcement serves as a pastor.

The Justice Department quickly opened a civil rights investigation after the group interrupted services by chanting “ICE out” and “Justice for Renee Good,” referring to the 37-year-old mother of three who was fatally shot by an ICE officer in Minneapolis earlier this month.

“Listen loud and clear: WE DO NOT TOLERATE ATTACKS ON PLACES OF WORSHIP,” the attorney general wrote on X.

Levy Armstrong, a civil rights attorney and prominent local activist, had called for the pastor affiliated with ICE to resign, saying his dual role poses a “fundamental moral conflict.”

“You cannot lead a congregation while directing an agency whose actions have cost lives and inflicted fear in our communities,” she said Tuesday. “When officials protect armed agents, repeatedly refuse meaningful investigation into killings like Renée Good’s, and signal they may pursue peaceful protesters and journalists, that is not justice — it is intimidation.”

Prominent leaders of the Southern Baptist Convention have come to the church’s defense, arguing that compassion for migrant families affected by the crackdown cannot justify violating a sacred space during worship.

This is a breaking news story. Check back for updates.

Related Articles


Army orders military police to get ready for a possible Minneapolis deployment, AP source says


Autopsy finds Cuban immigrant in ICE custody died of homicide due to asphyxia


Minnesota corrections officials again dispute ICE numbers on criminals


DFL state lawmakers decry ICE tactics toward U.S. citizens


Immigration officers assert sweeping power to enter homes without a judge’s warrant, memo says