The Trump administration is moving forward with a controversial plan to collect the medical records of millions of federal workers, retirees, and their family members.
The Office of Personnel Management (OPM) announced in a notice posted last month that it will begin routinely collecting identifiable personal health information on more than eight million individuals. The notice is set to take effect on July 24, allowing the collection to start thereafter. Privacy advocates and Democrats have raised concerns and called on the agency to drop the plan.
In response to privacy concerns raised by insurers and others, OPM now says it will “pseudonymize” enrollees’ identities—removing names, addresses, and Social Security numbers—before its analysts review the data sets. Birth years will be retained, and OPM’s technical staff will receive member IDs that are scrambled into unique numbers for internal use. However, the agency retains the right to reidentify records when needed.
Sixty‑five insurance carriers will be required to routinely transmit detailed health data—including names, addresses, physician information, diagnoses, prescriptions filled, and payment details—to OPM for the Federal Employees Health Benefits (FEHB) and Postal Service Health Benefits (PSHB) programs. The agency also seeks to access Medicare claims for individuals who are dually eligible, expanding its data collection beyond the original proposal reported by KFF Health News.
In its latest notice, OPM argues that the extensive data set is essential to uncover fraud and overpayments in the FEHB and PSHB programs, which cost roughly $80 billion annually. About $50 billion is covered by the federal government and $30 billion by enrollees. The Trump administration, led by Vice President JD Vance, has intensified efforts to address what it describes as widespread abuse of publicly funded health benefits.
The initiative still faces criticism for failing to sufficiently safeguard the privacy of federal workers and their families.
“Clearly, this administration has not earned our trust with Americans’ sensitive data,” said Senator Mark Warner (D‑VA) in an emailed statement to KFF Health News. “If OPM wants to work in good faith to reduce fraud, they should come to Congress—including to folks like me who are engaged on this issue and represent many federal workers and retirees and their families—and work to build consensus and trust before implementing these sweeping changes.”
The original notice, posted in December, sparked concerns in part because it did not specify what the Trump administration planned to do with the sensitive health information it receives and did not instruct insurers to redact identifying information.
OPM General Counsel Kurt Dykstra said the detailed records are critical to the administration’s mission of rooting out fraud and could help identify fraud perpetrated not only by medical providers but also by enrollees. When pressed for specific examples, he noted only generally that health‑care fraud occurs.
The information could reveal “potential anomalies in usage patterns that could be related to the individual, but really also could be related to the provider, the treater, the clinic—whoever it is that’s actually providing the care,” Dykstra explained in an interview. Suspicious records could be referred to OPM’s Office of the Inspector General for further investigation, which could include “determining who’s involved and what the potential issues are, what the ramifications look like.”
OPM’s plan to collect and analyze medical records has prompted unease among unions and federal workers, who have faced mass firings and layoffs—often citing political retribution—since President Donald Trump took office.
Health‑privacy lawyers say that while pseudonymizing workers’ details is a step in the right direction, it might not go far enough to protect their privacy. OPM’s notice largely complies with the Health Insurance Portability and Accountability Act (HIPAA), said attorney Matt Fisher, but he noted one exception: the member ID that insurers provide enrollees can still be used to identify them.
“The described process arguably comes down to trusting internal controls in OPM to ensure that data is walled off as proposed,” Fisher said in an email. “The ideal would be for only truly de‑identified information to be shared in the first place.”
Insurers regularly share claims information with employers who offer health plans to employees in an effort to control costs. Because employers are not covered by HIPAA, large data sets are typically de‑identified, meaning insurers remove names, addresses, and other direct identifiers to comply with the law.
Employers, too, have been accused of using health information to target employees for dismissal. A recent lawsuit by a group of Meta employees alleges the tech giant used artificial intelligence to flag workers who had taken medical or family leave for potential layoffs.
“The richer the data, the more likely it is going to be identifying,” said Joseph Lorenzo Hall, a technologist at the Center for Democracy & Technology. “In this case, you may be the only person in a region that has that particular kind of medical procedure, condition, or even prescription—all of which can be extremely identifying, even when you remove or obfuscate direct identifiers.”
Most federal retirees continue with FEHB plans after turning 65 and enroll in Medicare, which offers more comprehensive coverage while allowing family members to stay on FEHB. OPM wants to analyze medical records for these dual‑eligible enrollees as well and is requesting all of their cost and service‑use records from the Centers for Medicare & Medicaid Services.
John Hatton, staff vice president for policy and programs at the National Active and Retired Federal Employees Association, said OPM’s latest notice provides more detail on how the agency intends to use and safeguard the sensitive health information it will receive. “It’s a big improvement over the last notice, which was very lacking in detail and explanation for why they wanted all the medical claims data and how they’re going to protect the privacy of the data,” Hatton noted.
“We’d be open to seeing even more security around the privacy of the data so there really is a clear wall,” he added.
Also Read
- Lack of defibrillators could put 16m at risk of death by cardiac arrest in England and Wales
- Angel Reese’s Knee Injury Merits Caution: The Critical Role of Medical Clearance Beyond Recovery Signs
- U.S. Drug Shortages Climb to 227 Medications as CT Contrast Agents and Chemotherapy Drugs Remain Critically Scarce
- The Devastating Impact of Creutzfeldt-Jakob Disease: Reflections on the Passing of David Austin
