If you are enrolled in Federal Employees Health Benefits (FEHB) or Postal Service Health Benefits (PSHB), your medical claims, along with those of your spouse and any covered dependents, are among the more than eight million people whose data is already flowing into a federal system that has drawn months of congressional scrutiny.
The privacy dispute is not settled. Six Senate Democrats sent Office of Personnel Management (OPM) Director Scott Kupor a follow-up letter on September 16, 2026, arguing that the privacy protections OPM has put in place still fall short, and gave the agency a September 25 deadline to respond in writing.
The letter does not describe a new OPM proposal. It is a response to the modified System of Records Notice (SORN) OPM published on June 23, 2026, which was covered in detail here in July. Nothing about the underlying data collection has changed as a result of the senators’ letter. What has changed is the pressure on OPM to justify it, and lawmakers have now set a specific date by which they want an answer.
What This Means for You and Your Family
OPM’s health claims records cover more than active federal employees. According to the senators’ letter, the system as a whole touches more than eight million people, encompassing annuitants, spouses and other family members, former spouses and former family members, Postal Service employees and their families, certain tribal employees, and some separated employees covered through FEHB or PSHB plans.
The letter specifically raises concerns about dependents whose health information is included in a family member’s coverage. For example, a young adult covered under a parent’s FEHB plan could have claims involving reproductive or sexual health, mental health, or substance use included in the system even though the employee who carries the insurance never received those services. The senators are asking OPM for additional safeguards governing how information about family members can be accessed and used.
There is nothing for enrollees to do right now. The modified SORN is already in effect, and its new routine uses took effect July 23. The senators’ letter does not change enrollee obligations or health coverage. There is no individual opt-out process for the claims collection described in the SORN, and the senators are not proposing one in their letter. The practical relevance for now is awareness: FEHB and PSHB enrollees and their covered family members are among the people whose claims information is included in this system, and the debate over how that information can be used and protected is still unresolved.
What the Senators Are Arguing
The reason lawmakers still consider this a risk comes down to a technical dispute over what OPM’s privacy protections actually accomplish. The letter’s central argument is one that the National Active and Retired Federal Employees Association (NARFE) raised in its own comment letter to OPM in July: pseudonymized data is not the same thing as de-identified data.
Under OPM’s June SORN, direct identifiers such as names and Social Security numbers are removed or nulled from the claims data used for analysis, while other identifying information is modified or limited. Birth dates, for example, are reduced to birth year, and the Member ID is transformed using a cryptographic hash. OPM describes the resulting claims data as “pseudonymized.” But the senators argue, citing National Institute of Standards and Technology (NIST) guidance, that pseudonymization does not eliminate the possibility of re-identification. OPM’s system also preserves mechanisms through which authorized personnel can re-identify records when OPM determines that doing so is necessary for an authorized purpose.
The senators argue that the combination of a stable identifier with information such as ZIP code, birth year, provider, service dates, diagnoses, procedures, and drug information can create a longitudinal health history that remains linkable over time even after direct identifiers have been removed. OPM’s own notice, as reported by Federal News Network, also lists members’ sex among the retained fields alongside these categories. That same reporting found that access is not limited to a small analytics team: OPM personnel, contractors, and other authorized staff can access the data for their official duties. The notice also authorizes certain outside disclosures, including sharing information with law enforcement in connection with possible violations of law, with the Department of Justice for litigation, and with government agencies handling suspected fraud, waste, or abuse.
Ten Demands and a Deadline
The letter lists ten specific actions the senators want OPM to take. Among them:
- Suspend further implementation of the expanded collection while the concerns raised by lawmakers are addressed
- Publish an analysis explaining why the individual data fields being collected are necessary and why less identifiable or aggregated information would not be sufficient
- Create enforceable safeguards preventing health claims information from being used in employment or personnel decisions, including hiring, firing, and disability accommodation matters
- Prohibit disclosure of claims information to law enforcement based on suspected violations arising from lawful health care
- Reevaluate the 30-year retention schedule for health claims records
- Establish protections for dependents and other family members, including safeguards against using one person’s claims information to investigate another family member
- Explain what human review, error-correction, and anti-bias safeguards would apply before an automated fraud-detection alert could result in a referral to OPM’s Office of Inspector General
That last request reflects a concern that automated systems could flag unusual billing patterns without understanding the medical circumstances behind them. Complicated or uncommon treatment, care involving multiple providers, or unusual coding patterns can appear anomalous in claims data even when there is a legitimate clinical explanation. The senators therefore want OPM to explain what human review would occur before an automated alert could lead to an investigation.
The retention demand is worth a closer look as well. The SORN calls for health claims records to be kept for 30 years, and the senators argue that a stable pseudonymous identifier, held that long, still lets claims tied to the same person be connected over time even with direct identifiers removed. They want OPM to justify why that length of time is necessary or adopt a shorter retention period.
The senators requested a written response and a congressional briefing from OPM no later than September 25, 2026. OPM has not formally responded to the letter itself, but a spokesperson gave Federal News Network a brief statement after the letter became public, saying the agency is focused on “eliminating fraud, waste and abuse in federal benefits plans, while ensuring personally identifiable information is protected.” That statement does not address the ten specific requests made by the senators.
A Precedent Lawmakers Are Watching
The letter’s warning about health data potentially being used for personnel actions is not entirely hypothetical. Federal News Network reported in September that the Pentagon has been searching protected medical records to identify service members with a current or past diagnosis of gender dysphoria as the Defense Department implements the administration’s restrictions on military service in those circumstances. That reporting is not part of OPM’s civilian health claims data collection system, since it involves military rather than FEHB or PSHB records. But it provides a real-world example of the broader concern raised by the senators: that health information collected for one purpose could later be used in decisions affecting an individual’s employment or service. The senators are therefore asking for enforceable restrictions on how OPM’s claims data can be used rather than relying solely on current agency policy.
What Happens if OPM Misses the Deadline
The September 25 deadline was set by the senators in their oversight letter; it is not a statutory deadline that automatically forces OPM to suspend the data collection or change the SORN. The senators also say OPM did not respond to their earlier April 2026 letter seeking withdrawal of the original proposal.
If OPM does not respond by September 25, the letter itself does not compel the agency to change course. Lawmakers could pursue additional oversight through further correspondence, hearings, appropriations, or legislation, but the September 16 letter does not specify what action they would take next. For now, the June SORN remains in effect unless OPM modifies it or another legal or legislative action intervenes.
For more background on how the data collection works and what OPM has said in its own defense, see the earlier coverage: FEHB Privacy: What OPM’s New Data Rule Means for You and OPM Wants Access to Federal Employees’ & Retirees’ Medical Records; Lawmakers Say No.

