
A fight that began quietly in December has turned into one of the most closely watched privacy disputes in the federal benefits world. The Office of Personnel Management wants far more detailed health claims data on the roughly 8 million people covered by the Federal Employees Health Benefits (FEHB) and Postal Service Health Benefits (PSHB) programs. Lawmakers, unions, and retiree groups say the plan is legally shaky and dangerously broad. OPM says it’s the only way to finally get serious about fraud that has been draining the program for years. Both sides have now put their arguments on the record — and the gap between them is narrower than it was in the spring, but still real.
Takeaways
- What’s changing: OPM finalized a rule (effective June 23, 2026) expanding the health claims data it collects from FEHB and PSHB insurance carriers — including more detailed prescription, provider, and billing codes.
- Why OPM says it needs this: To catch healthcare fraud, waste, and billing abuse in something closer to real time, rather than years after the fact.
- How your identity is supposed to be protected: OPM says direct identifiers (name, SSN, address) are stripped before it receives the data, and your Member ID is scrambled through a hashing process before analysts use it.
- The catch: OPM acknowledges it retains the technical ability to reverse that scrambling and re-identify records for certain “operational” purposes — which is different from data being permanently de-identified.
- Who’s pushing back: NARFE, AFGE, and congressional Democrats say pseudonymized data isn’t the same privacy guarantee as true de-identification under HIPAA, and want firmer, binding commitments from OPM.
- What hasn’t happened: Your individual medical records are not being reviewed one-by-one by OPM staff. The stated goal is pattern-level fraud analysis, not case-by-case review.
- What’s next: The public comment period on the rule closed July 23, 2026. Whether OPM tightens its privacy commitments further, or Congress intervenes, remains unresolved.
Background
Last December, OPM quietly published a notice proposing that the 65-plus insurance carriers participating in FEHB and PSHB submit monthly reports containing service-use and cost data — medical claims, pharmacy claims, provider information, and healthcare encounter data — without explicitly stating that personal identifiers would be stripped out beforehand.
The proposal drew little attention until April, when it became public that the data could include prescription records, diagnoses, treatment histories, and provider information for enrollees and their family members. Sixteen Senate Democrats, led by Sens. Adam Schiff and Mark Warner, wrote to OPM Director Scott Kupor on April 19 demanding the agency withdraw the plan, arguing it was “illegal and dangerous” and risked exposing federal workers’ most sensitive information to cyberattacks, unauthorized access, and political misuse. A group of 10 House Democrats sent a similar letter two days earlier, specifically flagging the risk that the data could be used to identify employees who had sought abortion care, contraception, IVF, gender-affirming care, or HIV prevention medication.
The American Federation of Government Employees and the National Active and Retired Federal Employees Association (NARFE) also raised objections, with AFGE pointing to statements from health law experts and insurers — including CVS Health — questioning whether the collection could be reconciled with HIPAA.
What OPM Actually Proposed in June
On June 23, OPM published a formal Privacy Act System of Records Notice (SORN) in the Federal Register, modifying and renaming the system from “Health Claims Data Warehouse Records” to “Health Benefits Claims and Cost Records” (OPM/Central-15). The notice does several things:
- Folds in PSHB. The system now explicitly covers Postal Service Health Benefits enrollees alongside traditional FEHB participants.
- Expands the data fields. New categories include National Drug Codes and J-codes for prescriptions, more detailed provider-charge and payer information (including pharmacy rebate data), and dates of service.
- Adds new “routine uses.” The notice authorizes disclosures to other federal agencies administering health benefits programs, and — notably — a new routine use tied to the Treasury Department’s “Do Not Pay” fraud-prevention system under a 2025 executive order.
- Describes a pseudonymization process. According to the notice, OPM’s Office of Inspector General will pass OPM an encrypted copy of carrier data with names, Social Security numbers, phone numbers, and addresses (apart from ZIP code) replaced with null values, and date of birth reduced to year only. The Member ID — the one identifier retained in usable form — is then run through a salted cryptographic hash before OPM analysts see it, producing what OPM calls a “pseudonymized” dataset for routine analysis.
Critically, the notice states that OPM retains the technical ability to re-identify records for “authorized operational purposes” such as data-quality validation, and that identifiable data is used elsewhere in the system to build “person-level longitudinal records.” The comment period on the SORN closed July 23, 2026, though the modified system technically took effect on publication (with the new routine uses effective as of the comment deadline).
OPM’s Case: Fraud, Not Surveillance
Kupor laid out OPM’s rationale in a June 11 post on the agency’s “Secrets of OPM” blog, built around a Justice Department fraud case involving a Georgia therapist accused of billing FEHB carriers for sessions that never occurred — including, in one instance, more than 24 hours of billed sessions in a single day. The fraud allegedly occurred between 2019 and 2022; Kupor’s point was that OPM’s Inspector General only catches this kind of abuse years after the fact, and recovers little of the money even then.
Kupor argued that FEHB and PSHB together cost roughly $80 billion a year and are growing 10-12% annually, and that industry-wide fraud rates in large health programs run an estimated 3-5% — implying $2.4 billion to $4 billion a year in potential federal healthcare spending lost to fraud, waste, and abuse. He said OPM currently lacks the claims-level analytic tools that Medicare, Medicaid, and most large self-insured private employers already use to catch billing anomalies — like implausible billing volumes — in close to real time rather than years later.
On privacy specifically, Kupor wrote that he shares the “very real and legitimate concern” about government access to medical records, and described the pseudonymization approach as the mechanism that lets OPM “data mine” the records without analysts being able to map data back to an individual plan participant. He noted OPM has used a similar approach with Medicare data for years.
NARFE’s Response: Pseudonymized Is Not De-Identified
NARFE’s reaction, laid out in a comment letter to Kupor dated July 23, credits OPM with real movement from the December version of the plan — but draws a sharp technical and legal line between what OPM has offered and what NARFE says HIPAA privacy protections require.
NARFE’s central objection is that pseudonymization is not de-identification. Under HIPAA’s standards, de-identified data has had identifiers removed (or been statistically certified as non-identifying) to the point where re-identification is not reasonably possible. Pseudonymized data, by contrast, retains a re-identification path — in this case, a hashed Member ID that OPM’s own SORN acknowledges can be reversed by authorized personnel for operational purposes. NARFE argues that distinction is not academic: it means the privacy protection depends on internal policy and personnel access controls that “any future administration” could change, rather than on a technical guarantee.
NARFE also flags a gap between what Kupor described in his blog post and what OPM is actually bound to do under the published SORN. Many of the specific safeguards Kupor detailed — the stripping of identifiers, the hashing process — appear in the blog post but are described in less binding terms in the formal notice. NARFE is asking OPM to convert description into obligation: making de-identification the default rather than pseudonymization, making the safeguards mandatory rather than discretionary, keeping cryptographic key material walled off from enrollment files, and explicitly barring any personnel-related use of the data.
What Happens Next?
OPM still must finalize how the data collection program will operate, including technical privacy protections, data security procedures, and oversight of the information. Federal employee organizations and members of Congress are likely to continue monitoring the proposal before any long-term implementation.
What to Watch
Three threads are worth tracking heading into the fall:
- Whether OPM revises the SORN again. OPM softened its approach once already between December and June in response to pressure; NARFE’s letter gives the agency a specific, technical list of changes it says would resolve its concerns.
- Congressional action. The April letters from Senate and House Democrats requested a withdrawal that did not happen; whether lawmakers pursue further oversight — hearings, legislation, or funding riders — once Congress returns from recess is unclear.
- Carrier compliance questions. Some carriers reportedly raised their own HIPAA compliance concerns about the original December collection. Whether the June revisions resolve those concerns for insurers themselves, separate from the employee-group objections, hasn’t been fully aired out publicly.
For federal employees and retirees, the practical bottom line right now: the SORN is in effect, OPM has committed publicly to a pseudonymization approach it says protects individual identities during routine analysis, and it has retained the technical and legal ability to re-identify records in certain circumstances. Whether that satisfies HIPAA’s health-oversight-agency exception, as OPM contends, or falls short of it, as NARFE and congressional critics argue, is likely to remain contested at least through the rulemaking and oversight process ahead.

