Federal Workers’ Medical Records Collection Plan Moves Forward Amidst Privacy Concerns

The Trump administration is accelerating its controversial initiative to gather the medical records of millions of federal employees, retirees, and their dependents, a move that has ignited significant privacy alarms among advocacy groups and lawmakers. The Office of Personnel Management (OPM) has finalized plans to routinely collect identifiable personal health information on over 8 million individuals, with the new regulations set to take effect on July 24th, empowering the agency to commence data acquisition at any point thereafter. This development comes despite persistent demands from privacy advocates and Democratic officials for the administration to abandon the program.
The OPM’s notice, published in the Federal Register, outlines a sweeping data collection effort that will require 65 insurance companies to regularly submit detailed health information. This includes names, addresses, physician details, diagnoses, prescription histories, and payment records for services rendered through the Federal Employees Health Benefits (FEHB) and Postal Service Health Benefits (PSHB) programs. In a significant expansion of the initial proposal, the agency also intends to access records held by Medicare, the federal health insurance program for individuals aged 65 and older, and those with disabilities, to scrutinize claims from federal employees and retirees who utilize both programs.
Addressing Privacy Through Pseudonymization: A Contentious Step
In response to escalating concerns from insurers and privacy stakeholders, the OPM has stated that it will implement a pseudonymization process for the collected data. This means that direct identifiers such as names, addresses, and Social Security numbers will be removed before the information is analyzed by agency personnel. Birth years will be retained, and a designated "technical staff" will receive member identification numbers, which will then be scrambled into different, unique codes before being disseminated to other OPM employees.
However, a critical point of contention remains: the OPM’s explicit retention of the right to re-identify these records. This provision has fueled anxieties that the pseudonymization is a superficial safeguard, rather than a robust protection of sensitive personal information. Privacy experts argue that the ability to re-identify individuals, even with pseudonymized data, poses a substantial risk, particularly given the detailed nature of the medical information being collected.
The Rationale: Combating Fraud and Overpayments
The OPM justifies this extensive data collection as a necessary measure to identify and curtail fraud and overpayments within the FEHB and PSHB programs. These programs represent a substantial financial undertaking, collectively costing approximately $80 billion annually, with the federal government contributing roughly $50 billion and enrollees covering the remaining $30 billion. The Trump administration, under the leadership of Vice President JD Vance, has intensified efforts to address what it characterizes as widespread fraud and misuse of taxpayer-funded health benefits.
OPM General Counsel Kurt Dykstra emphasized that the detailed records are indispensable for identifying fraudulent activities, not only by healthcare providers but also by beneficiaries. He explained that the data analysis aims to detect "potential anomalies in usage patterns that could be related to the individual, but really also could be related to the provider, the treater, the clinic – whoever it is that’s actually providing the care." Records flagged as suspicious by OPM analysts could subsequently be referred to the agency’s Office of the Inspector General for further investigation, potentially leading to the identification of those involved and the assessment of ramifications.
Criticism Mounts: Trust Deficit and Insufficient Safeguards
Despite the administration’s stated aims, the plan continues to draw sharp criticism for what many perceive as inadequate privacy protections for federal workers and their families. Senator Mark Warner (D-Va.) expressed profound skepticism, stating, "Clearly, this administration has not earned our trust with Americans’ sensitive data." He urged the OPM to engage with Congress and work collaboratively to build consensus and trust before enacting such sweeping changes, emphasizing the need for a transparent and cooperative approach to addressing fraud.
The initial OPM notice, released in December, lacked specificity regarding the intended use of the collected health information and did not mandate that insurers redact identifying details, which contributed significantly to the ensuing privacy concerns. Health privacy lawyers have noted that while pseudonymization is a step in the right direction, it may not offer sufficient protection.
Matt Fisher, a health privacy lawyer, commented that the OPM’s approach largely aligns with the Health Insurance Portability and Accountability Act (HIPAA), the federal law governing the privacy of sensitive health data. However, he highlighted a crucial exception: the member identification numbers provided by insurers to enrollees could still be used to identify individuals. Fisher suggested that the current process relies heavily on internal OPM controls to secure the data, advocating instead for the sharing of truly de-identified information from the outset.
Broader Implications and Historical Context
The OPM’s move occurs against a backdrop of increasing scrutiny of how employers and government agencies handle sensitive employee data. Insurers routinely share claims information with employers to manage costs, but to comply with privacy regulations, this data is typically de-identified. The potential for misuse of health information is a well-documented concern, exemplified by a recent lawsuit filed by Meta employees who accused the tech giant of using artificial intelligence to target individuals with medical conditions or those who had taken medical or family leave for layoffs.
Technologists and privacy advocates underscore the inherent risks associated with collecting rich datasets. Joseph Lorenzo Hall, a technologist at the Center for Democracy & Technology, explained that even with pseudonymized data, "The richer the data, the more likely it is going to be identifying." He elaborated that specific medical procedures, conditions, or even prescriptions can uniquely identify individuals, especially in cases where a person might be the sole recipient of a particular treatment within a geographic area.
The collection of Medicare data adds another layer of complexity, as many federal retirees continue their FEHB plans while also enrolling in Medicare for enhanced coverage. The OPM’s intent to analyze the records of these "dual enrollees" raises further questions about the scope and potential impact of the data collection on a vulnerable population.
Timeline of Developments
- December 2025 (Original Proposal): The OPM publishes its initial notice in the Federal Register, outlining plans to collect federal employees’ and retirees’ health data. This notice sparks immediate concern due to a lack of detail on data usage and privacy safeguards.
- Early 2026: Privacy advocates, Democrats in Congress, and federal employee unions voice strong opposition to the proposed plan, citing significant privacy risks. Insurers raise concerns about their ability to comply with the data collection mandate.
- Mid-2026 (Revised Plan): The OPM releases a revised notice, introducing the concept of pseudonymization to address privacy concerns. The agency also clarifies its intention to seek data from Medicare for dual enrollees.
- July 24, 2026 (Effective Date): The revised OPM notice officially takes effect, allowing the agency to begin the routine collection of personal health information from federal employees, retirees, and their families.
Acknowledging Improvements, Demanding Further Guarantees
John Hatton, staff vice president for policy and programs at the National Active and Retired Federal Employees Association, acknowledged that the OPM’s latest notice represents an improvement over the initial proposal, offering more clarity on data usage and protection. "It’s a big improvement over the last notice, which was very lacking in detail and explanation for why they wanted all the medical claims data and how they’re going to protect the privacy of the data," Hatton stated.
Despite this acknowledgment, Hatton stressed the ongoing need for enhanced data security and privacy safeguards. He expressed a desire for "even more security around the privacy of the data so there really is a clear wall," indicating that while progress has been made, the concerns of federal workers and retirees have not been fully assuaged. The administration’s continued pursuit of this data collection initiative underscores a broader debate about the balance between government oversight, the pursuit of fiscal accountability, and the fundamental right to privacy for millions of Americans. The coming months will likely see continued efforts by privacy advocates and lawmakers to ensure that robust protections are firmly in place, or to challenge the program’s implementation should perceived risks remain unaddressed.







