Imagine you run a chain of restaurants, and each location tracks its own food-poisoning complaints. You want a national picture of which dishes cause trouble, but no restaurant wants to share its raw complaint logs — bad for lawsuits, bad for brand. So instead, each location sends you a lightly blurred summary statistic: 'our seafood complaint rate is roughly this high.' You combine those blurred summaries into a national estimate that's surprisingly accurate, even though you never saw a single individual complaint. That's the core mechanism here, transplanted from restaurants to surgical device failures. The committed claim: a federated Bayesian conjugate protocol (Gamma-Poisson posteriors with Rényi-differential-privacy noise on natural parameters) produces dramatically better held-out predictive scores for thrombectomy adverse-event rates than the standard federated-learning workhorse FedAvg, when both operate under the same privacy budget. The numbers are stark: Poisson log-score of -5.78 versus -26.58, nearly a 5× gap in favor of the conjugate approach. The architecture choice is the quiet star of the paper. Rather than treating adverse-event rate estimation as a generic SGD problem and bolting on DP-SGD (which is what FedAvg-with-DP does), the authors exploit the fact that Gamma-Poisson models have closed-form sufficient statistics. Privacy noise is added directly to natural parameters — shape and rate — rather than to gradients. This is a much tighter fit between the statistical model and the privacy mechanism, and the benchmark confirms it. The data substrate is the complete FDA MAUDE cohort for product code NRY (thrombus-retrieval catheters): 8,617 reports, 6,491 classified into five complication classes, partitioned across K=8 manufacturer sites. The integrity picture is mixed in instructive ways. On the positive side, the dataset is public (FDA MAUDE), the classification rules are described as transparent keyword matching, and the authors are upfront that MAUDE lacks procedure denominators — meaning outputs are relative rate orderings, not absolute risks. That denominator caveat is critical and honestly reported. On the negative side, there's no independent replication, no pre-registration, no released code mentioned, and the five complication classes were defined by the authors' own keyword rules, which introduces some circularity in what counts as a 'hit.' The non-private federated model outperforming centralized pooling (+3.19 vs +2.93) is perhaps the most interesting secondary finding. It suggests that manufacturer-specific complication profiles are real heterogeneity, not noise — federation isn't just a privacy compromise, it's a better model of the data-generating process. This is the kind of result that makes federated learning advocates happy for the right reasons. The paper is a 3-page workshop contribution at IROS 2026 (Surgical Digital Twins workshop), and should be read at that scale. It's a proof-of-concept showing that conjugate Bayesian models are a natural fit for privacy-preserving adverse-event surveillance, not a full system paper. The big missing piece is procedure denominators: without knowing how many thrombectomies each manufacturer's devices were used in, you cannot move from relative rate orderings to actual risk estimates that would change clinical decisions. The framing as a 'belief layer for surgical digital twins' is ambitious packaging for what is, mechanistically, a fairly clean application of known Bayesian federated inference to a specific FDA dataset. The novelty is in the application domain and the demonstration that conjugate models crush FedAvg under matched privacy budgets in this setting — not in the statistical machinery itself.