The Trump administration is pursuing unprecedented access to the personally identifiable medical records of millions of federal employees, retirees and their families. A recent notice from the Office of Personnel Management (OPM) indicates a significant shift in the type of health information the agency intends to collect, potentially granting the government visibility into specific prescriptions filled and the exact treatments sought by federal workers.
This proposal would require 65 insurance companies to submit monthly reports containing identifiable health data to the OPM. The scope of this request is vast, affecting more than 8 million Americans, including mail carriers, retired members of Congress, and federal employees along with their immediate family members. By seeking federal workers’ medical records access on this scale, the administration is moving toward a level of data collection that has prompted immediate concern among legal and health policy experts.
The OPM’s notice, which was posted and distributed to insurers in December, specifically requests “service use and cost data.” This detailed request includes pharmacy claims, medical claims, provider data, and encounter data. According to the agency, the acquisition of this data is intended to ensure that the insurance plans provided remain “competitive, quality, and affordable.”
The Scope of Identifiable Health Data Collection
The central point of contention is the requirement for “identifiable” data. Typically, large-scale health data analysis for policy or cost-improvement purposes relies on anonymized or aggregated data to protect patient privacy. However, the OPM notice does not instruct insurance companies to redact identifying information. This omission places a significant administrative burden on insurers, who would require specific federal guidance to complete such a process if they wished to protect member privacy.

The affected populations are those covered under the Federal Employees Health Benefits (FEHB) or the Postal Service Health Benefits plans. Because these plans cover not only the employees but also their retirees and immediate family members, the resulting database would be one of the most comprehensive collections of sensitive health information held by a single government personnel agency.
Potential Implications for Privacy and Personnel
While the OPM maintains that the data is for system improvement and cost analysis, experts in health law warn of the risks associated with such granular information. Sharona Hoffman, a health law ethicist at Case Western Reserve University in Ohio, noted that the agency would obtain “very, very detailed and granular data about everything that happens.”
The primary concern raised by Hoffman is the potential for this information to be weaponized. She suggested that the more detailed information the government possesses, the greater the risk that it could be used to “discipline or target people who are not cooperating politically.” This concern highlights a tension between administrative cost-saving goals and the privacy protections typically afforded to medical records.
Legal and Operational Concerns
The proposal has created unease among the 65 insurance companies involved, as well as legal experts who question the legality of the OPM acquiring such a sweeping database. Beyond the legalities of the request, there are significant concerns regarding the agency’s technical capacity to safeguard this volume of sensitive health information from breaches or unauthorized access.
The request for monthly reports ensures a real-time or near-real-time stream of health data, moving beyond static annual reports to a dynamic monitoring system of the health status and medical needs of the federal workforce. Despite the gravity of these concerns, OPM spokespeople have not responded to repeated requests for comment regarding the safeguards in place or the specific legal authority under which this data is being requested.
Key Data Points Requested by OPM
- Medical Claims: Detailed records of healthcare services billed to insurance.
- Pharmacy Claims: Specifics on prescriptions filled by employees and their families.
- Encounter Data: Records of visits to healthcare providers, regardless of whether a claim was filed.
- Provider Data: Information regarding the specific doctors and facilities used for treatment.
What This Means for Federal Employees
For the 8 million individuals affected, this policy represents a potential erosion of the boundary between personal health management and employment records. The shift toward identifiable data means that the government would not just know how much is being spent on healthcare, but who is receiving what specific treatment.
The impact extends beyond current employees to retirees and family members, who may not have a direct employment relationship with the current administration but whose data would still be transmitted to the OPM via their insurance providers. This creates a broad umbrella of surveillance over the health histories of a significant portion of the U.S. Population.
As this regulation moves forward, the focus will likely shift to whether insurance companies comply with the request without redaction or if legal challenges are mounted to protect the privacy of the millions of federal workers and retirees involved.
Currently, there is no confirmed date for a public hearing or a formal deadline for the first set of monthly reports, though the notice was issued in December. Further updates will depend on OPM’s response to the concerns raised by insurers and health policy experts.
We invite our readers to share their perspectives on healthcare privacy and government data collection in the comments below. Please share this report to keep others informed about evolving health policy.
Keep reading