Federal Workers’ Medical Records Collection Plan Moves Forward Amidst Privacy Concerns

The Trump administration is advancing a contentious plan to collect the medical records of millions of federal workers and retirees, alongside their family members, a move that privacy advocates and Democratic lawmakers argue raises significant privacy risks. The Office of Personnel Management (OPM) has issued a notice indicating its intention to routinely gather identifiable personal health information on over 8 million individuals. This notice, published last month, is set to take effect on July 24, after which OPM can commence its data collection.
This initiative, spearheaded by Vice President JD Vance, aims to identify and curtail alleged fraud and overpayments within the Federal Employees Health Benefits (FEHB) and Postal Service Health Benefits (PSHB) programs, which collectively represent an annual expenditure of approximately $80 billion, with the federal government covering roughly $50 billion and enrollees contributing the remaining $30 billion. The administration asserts that this comprehensive data analysis is crucial for ensuring the integrity of these taxpayer-funded programs.
Shifting Data Handling and Persistent Scrutiny
In response to initial privacy concerns voiced by insurers and other stakeholders, OPM has stated that the identities of enrollees will be "pseudonymized" before their health data is reviewed by agency analysts. This process involves removing direct identifiers such as names, addresses, and Social Security numbers. However, the agency’s notice also explicitly reserves the right to re-identify these records.
Under the new directive, 65 insurance companies will be mandated to regularly submit detailed data to OPM. This information will encompass names, addresses, physician details, diagnoses, prescription histories, and payment records for healthcare services rendered through the FEHB and PSHB programs.
Furthermore, in a significant expansion of the original proposal, OPM also intends to access records held by Medicare, the federal health insurance program for individuals aged 65 and older, as well as those with disabilities. This aims to examine claims from federal employees and retirees, and their dependents, who utilize both Medicare and the FEHB or PSHB programs.
A Timeline of Evolving Policy and Opposition
The genesis of this plan can be traced back to a proposal first reported by KFF Health News. The initial notice, released in December, lacked specific details regarding the administration’s intended use of the collected health information and did not mandate that insurers redact identifying data. This ambiguity fueled widespread concern among privacy advocates, federal employee unions, and lawmakers.
Senator Mark Warner (D-Va.), a vocal critic of the plan, expressed his reservations, stating, "Clearly, this administration has not earned our trust with Americans’ sensitive data. If OPM wants to work in good faith to reduce fraud, they should come to Congress, including to folks like me who are engaged on this issue and represent many federal workers and retirees and their families, and work to build consensus and trust before implementing these sweeping changes."
Rationale for Data Collection: Combating Fraud
OPM General Counsel Kurt Dykstra maintains that the extensive collection of detailed medical records is essential for the administration’s mission to detect and prevent fraud. He explained that the data could reveal "potential anomalies in usage patterns that could be related to the individual, but really also could be related to the provider, the treater, the clinic – whoever it is that’s actually providing the care." Such findings could then be referred to OPM’s Office of the Inspector General for further investigation.
While Dykstra acknowledged that healthcare fraud is a known issue, he was unable to provide specific instances of federal workers, retirees, or their family members engaging in such fraudulent activities when pressed by KFF Health News.
Privacy Safeguards: Pseudonymization and its Limitations
The agency’s revised approach includes pseudonymization, a process where direct identifiers are stripped from the data. Birth years will be retained, and a "technical staff" within OPM will receive member IDs, which will be scrambled into unique, different numbers before being shared with other agency personnel.
However, privacy experts caution that pseudonymization may not offer complete protection. Matt Fisher, a health privacy lawyer, noted that while OPM’s notice largely aligns with the Health Insurance Portability and Accountability Act (HIPAA), the member ID assigned by insurers could still be used to identify individuals. "The described process arguably comes down to trusting internal controls in OPM to ensure that data is walled off as proposed," Fisher commented. "The ideal would be for only truly de-identified information to be shared in the first place."
Joseph Lorenzo Hall, a technologist at the Center for Democracy & Technology, emphasized that the richness of the data itself can make identification possible, even with pseudonymization. "The richer the data, the more likely it is going to be identifying," Hall stated. "In this case, you may be the only person in a region that has that particular kind of medical procedure, condition, or even prescription. All of those things can be extremely identifying, even when you remove or obfuscate or pseudonymize direct identifiers."
This concern is amplified by historical instances where employers have been accused of misusing employee health information. For example, a recent lawsuit filed by Meta employees alleged that the tech giant used artificial intelligence to target individuals with medical conditions or those who had taken medical or family leave for layoffs.
Broader Context and Federal Employee Concerns
The OPM’s plan has generated unease among federal employee unions and workers who have experienced significant workforce reductions and alleged politically motivated firings during the Trump administration. These past experiences have contributed to a climate of distrust regarding the government’s handling of sensitive personal information.
The National Active and Retired Federal Employees Association (NARFE) has indicated that while OPM’s latest notice offers more detail on data usage and safeguarding compared to its predecessor, further security measures are desirable. John Hatton, NARFE’s staff vice president for policy and programs, stated, "It’s a big improvement over the last notice, which was very lacking in detail and explanation for why they wanted all the medical claims data and how they’re going to protect the privacy of the data. We’d be open to seeing even more security around the privacy of the data so there really is a clear wall."
Many federal retirees opt to maintain their FEHB plans and enroll in Medicare upon reaching age 65. This dual enrollment offers enhanced coverage and allows family members to remain covered under FEHB plans. OPM’s request for data extends to these dual enrollees, seeking cost and service utilization records from the Centers for Medicare & Medicaid Services.
Analysis of Implications
The Trump administration’s push to collect federal workers’ medical records, even with the introduction of pseudonymization, represents a significant expansion of government access to highly sensitive personal data. While the stated objective is to combat fraud within substantial federal health benefit programs, the inherent privacy risks remain a primary concern for many stakeholders.
The effectiveness of pseudonymization as a privacy safeguard is a subject of ongoing debate. Critics argue that the retention of birth years and the agency’s explicit right to re-identify records undermine the purported privacy protections. The potential for data breaches or unauthorized access, coupled with the sensitive nature of health information, raises questions about the long-term security of this data.
The administration’s approach also raises broader questions about the balance between government oversight and individual privacy rights, particularly within the federal workforce, which has previously experienced periods of heightened scrutiny and personnel actions. The ongoing dialogue between OPM, lawmakers, and advocacy groups will likely shape the future implementation and oversight of this controversial data collection initiative. The coming months will be critical in determining whether the administration’s stated goals of fraud reduction can be achieved without compromising the privacy and trust of millions of federal employees and their families.







