What lands in your inbox

Most serious first, each item sourced and linked. On Business and Enterprise every item is rewritten against the devices you register, matched to your product portfolio, and checked against the policies and SOPs you upload. No hero images — a compliance professional's inbox is not the place for one.

This is a worked example. The publishers and advisory formats are real; the devices, documents and section numbers are invented. They have to be — an assessment is written for one organization against its own devices, and a finding cites a section of its own SOP, so neither can be shown here from a real record.

GRAPEBEAVER DAILY DIGEST

3 new items, sourced and scored

14 Aug 2026
Critical · 94 CISA ICS Medical Advisories · 13 Aug 2026 ICSMA-26-217-01
Authentication bypass in clinical gateway allows unauthenticated configuration change on the device network

Two of your registered devices are in scope. The advisory covers gateway firmware below 4.2.1; your CareLink CG-2 fleet is recorded at 4.1.7, and the VitalView M400 monitors behind it accept configuration from that gateway.

The bypass needs network adjacency rather than credentials, so the practical question is which VLANs the gateway is reachable from. Your profile notes a flat clinical network at two sites, which is where this would matter most.

The vendor has released 4.2.1. Nothing here is a compliance judgement — your own risk process decides whether this is a field action.

Affects: CareLink CG-2 clinical gateway, VitalView M400 patient monitor
Your documents: QMS-SOP-014 Vulnerability Handling (§4.2 Triage timelines) — consider an update; POL-002 Coordinated Disclosure (§3 Vendor contact) — review for continued accuracy
Suggestions for your own review; nothing has been changed. A controlled document changes under your change control, by its named owner.
High · 71 FDA Device Recalls · 12 Aug 2026 Z-1842-2026
Class II recall: patient monitor alarm may not sound at the configured threshold

Affects a device you track. The recall covers VitalView M400 units shipped before March 2026 under a specific alarm-profile combination.

The correction is a software update plus interim guidance to verify alarm settings after any profile change. Worth checking whether your post-market surveillance procedure treats an alarm-behaviour recall as a trigger for customer notification, since this one is distributed nationwide.

Affects: VitalView M400 patient monitor
Your documents: QMS-SOP-022 Post-Market Surveillance (§6.1 Recall triggers) — consider adding coverage
Suggestions for your own review; nothing has been changed. A controlled document changes under your change control, by its named owner.
Medium · 48 FDA Guidance Documents · 10 Aug 2026 FDA-2026-D-0112
Draft guidance: lifecycle management for AI-enabled device software functions

No registered device is directly in scope, and it is still in the comment period — but it is the one to read before your next submission if any function is model-driven.

The substance is in the attached PDF rather than the announcement: predetermined change control plans, and what the agency expects to see about training data provenance.

Your documents: STD-007 Secure Product Development (§9 Model change control) — consider adding coverage
Suggestions for your own review; nothing has been changed. A controlled document changes under your change control, by its named owner.
Source document: fda-ai-device-lifecycle-draft-guidance.pdf (38 pages) — open at the publisher. Our copy was retrieved 10 Aug 2026; always check the source for the latest version.

On Individual the same items arrive with the shared summary and no portfolio match — the sourcing and the severity ordering are identical, the rewrite and the document check are what Business adds.