Concerns are mounting as the Office of Personnel Management plans to collect personal health information from over 8 million federal employees and their families, raising significant privacy issues.
The Office of Personnel Management (OPM) announced last month that it will begin routinely collecting identifiable personal health information from more than 8 million individuals, despite growing concerns from privacy advocates and Democratic lawmakers. The new policy is set to take effect on July 24, allowing OPM to initiate data collection shortly thereafter.
In response to privacy concerns voiced by insurers and other stakeholders, OPM has stated that the identities of enrollees will be “pseudonymized.” This means that names, addresses, and Social Security numbers will be removed before the agency’s analysts review the extensive health datasets it will soon acquire.
However, the agency will retain birth years of enrollees and provide its technical staff with scrambled member IDs, which will be transformed into unique numbers before being shared with other personnel. Notably, OPM retains the right to reidentify these records if necessary.
As part of this initiative, 65 insurance companies will be mandated to send OPM detailed data, including names, addresses, doctor information, diagnoses, prescriptions filled, and payment details related to healthcare services covered under the Federal Employees Health Benefits (FEHB) and Postal Service Health Benefits (PSHB) programs.
In a notable shift from its original proposal, OPM has expressed interest in accessing Medicare records, which provide federally funded health insurance for older and disabled Americans. This will allow the agency to examine claims from federal employees, retirees, and their families who rely on both Medicare and the aforementioned health benefits programs.
OPM argues that this extensive data collection is essential for identifying fraud and overpayments in the FEHB and PSHB programs, which collectively cost approximately $80 billion annually. Of this, about $50 billion is covered by the federal government, while $30 billion is funded by enrollees. The Trump administration, led by Vice President JD Vance, has intensified efforts to combat what it describes as rampant fraud and misuse of publicly funded health benefits.
Despite these justifications, the initiative has faced criticism for insufficient privacy protections for federal workers and their families. Senator Mark Warner (D-Va.) expressed skepticism, stating, “Clearly, this administration has not earned our trust with Americans’ sensitive data. If OPM wants to work in good faith to reduce fraud, they should come to Congress and build consensus and trust before implementing these sweeping changes.”
The original notice released in December raised alarms partly because it lacked clarity on how the sensitive health information would be utilized and did not instruct insurers to redact identifying information.
OPM General Counsel Kurt Dykstra emphasized that the detailed records are vital for the administration’s mission to combat fraud, which can be perpetrated by both medical providers and enrollees. However, when asked for specific examples of fraud involving federal workers or their families, Dykstra could only speak generally about the occurrence of healthcare fraud.
According to Dykstra, the information collected could reveal “potential anomalies in usage patterns” that may be linked to individuals, providers, or clinics involved in delivering care. Records flagged as suspicious by OPM’s data analysts could subsequently be referred to the agency’s Office of the Inspector General for further investigation.
The plan to collect and analyze medical records has generated unease among unions and federal employees, particularly in light of mass firings and layoffs that some attribute to political retribution since President Trump took office.
Health privacy lawyers have noted that while pseudonymizing personal details is a positive step, it may not sufficiently safeguard privacy. Matt Fisher, a health privacy attorney, pointed out that while OPM’s notice generally complies with the Health Insurance Portability and Accountability Act (HIPAA), the member ID provided by insurers could still be used to identify individuals.
Fisher remarked, “The described process arguably comes down to trusting internal controls in OPM to ensure that data is walled off as proposed. The ideal would be for only truly de-identified information to be shared in the first place.”
Insurers typically share claims information with employers to manage costs, but since employers are not covered by HIPAA, large datasets are often de-identified to comply with the law. However, there have been accusations that employers misuse health information to target employees for layoffs. Recently, a group of Meta employees filed a lawsuit alleging that the company used artificial intelligence to identify employees for layoffs based on their medical or family leave status.
Joseph Lorenzo Hall, a technologist at the Center for Democracy & Technology, emphasized that even with pseudonymization, certain medical conditions can make it easy to identify individuals. “The richer the data, the more likely it is going to be identifying,” Hall stated. “In this case, you may be the only person in a region that has that particular kind of medical procedure, condition, or even prescription.”
Most federal retirees opt to continue with FEHB plans and enroll in Medicare upon turning 65, which offers more comprehensive coverage and allows family members to remain on FEHB plans. OPM is seeking to analyze medical records for these dual enrollees and is requesting all cost and service use records from the Centers for Medicare & Medicaid Services.
John Hatton, staff vice president for policy and programs at the National Active and Retired Federal Employees Association, noted that OPM’s latest notice provides more clarity on how the agency intends to use and safeguard sensitive health information. “It’s a big improvement over the last notice, which was very lacking in detail,” Hatton said. He added that there is still room for enhanced security measures to ensure a clear separation of sensitive data.
As the OPM moves forward with its data collection plans, the balance between combating fraud and protecting the privacy of federal employees and their families remains a contentious issue.
According to KFF Health News, the implications of this initiative will continue to unfold as stakeholders assess the potential risks and benefits of such extensive data collection.

