Federal employee groups remain concerned about the privacy provisions associated with the Office of Personnel Management's plan to collect claims-level health data on federal employees, retirees and their families as part an anti-fraud effort.

Federal employee groups remain concerned about the privacy provisions associated with the Office of Personnel Management's plan to collect claims-level health data on federal employees, retirees and their families as part an anti-fraud effort. J. David Ake/Getty Images

NARFE still has concerns with OPM’s plan to collect employee health care records

Last month, the Office of Personnel Management sought to assuage concerns about its request for claims-level data on federal workers’ health insurance usage. Employee groups say it’s still not enough.

The National Active and Retired Federal Employees Association on Thursday said the Office of Personnel Management still has not sufficiently protected federal workers and retirees as part of a plan to collect claims-level health data in an effort to root out fraud.

Last December, OPM published an information collection request that would require insurers who participate in the Federal Employee Health Benefits and Postal Service Health Benefits programs to provide monthly reports with identifiable health data on their enrollees, prompting concerns from ethicists, health care providers, employee groups and lawmakers alike.

In response to those concerns, OPM published a revised proposal last month, purporting to take steps to mask employees and retirees’ identities in the data collection. In an accompanying blog post, OPM Director Scott Kupor described how the anti-fraud effort would still protect workers’ privacy.

“In layman’s terms, OPM’s [Office of Inspector General] . . . will provide an encrypted copy of that data to OPM—but only after stripping out names, Social Security numbers, phone numbers, addresses (except for ZIP codes) and other personally identifiable data,” he wrote. “The only member-level [personally identifiable information] fields that will remain in the data that OPM receives will be our members’ ZIP codes, year of birth and their member ID. To further sanitize these records, OPM will scramble, or pseudonymize, the member ID information using a state-of-the-art cryptographic hashing process, replacing member ID with a random set of numbers and characters that is divorced from the real identity of the plan participant.”

But in a letter to Kupor Thursday, NARFE National President William Shackelford said that while his organization appreciates the steps taken thus far to shield FEHBP and PSHBP participants’ identities, he remains troubled by OPM’s insistence that it be able to re-identify employees via their health records in the future. Under the Health Insurance Portability and Accountability Act, health care data should be not just pseudonymized, but de-identified entirely, he wrote.

“NARFE’s position is straightforward. OPM has moved in the right direction,” Shackelford wrote. “But we asked for de-identified data and OPM has offered pseudonymized data, and those are not the same commitment. Pseudonymization does not remove the risk that our members’ health information will be linked back to them; it makes that linkage a matter of OPM’s discretion, exercisable by whoever holds the relevant authority in any future administration.”

Additionally, most of OPM’s reassurances about privacy and the data collection’s anti-fraud purpose exist solely within Kupor’s blog post, and not the proposal published in the Federal Register last month.

“What remains is otherwise the difference between description and obligation,” Shackelford wrote. “We ask OPM to convert what it has described into what it is bound to do: de-identification as the default and pseudonymization as the justified exception, mandatory rather than discretionary safeguards, hard separation of key material from enrollment files . . . and an explicit prohibition on personnel-related use.”

If you have a tip that can contribute to our reporting, Erich Wagner can be securely contacted at ewagner.47 on Signal.

NEXT STORY: Why your retirement experience may depend more on the agency than the benefit