Last Updated: August 5, 2026

MAY 6, 2026 STATUS UPDATE: The OPM medical records collection has NOT been withdrawn. WAMU reported April 29 that opposition from FEHB carriers, federal employee unions, and privacy advocates continues to mount, with the proposal still active despite the closed comment period. Senate and House Oversight Democrats sent letters demanding withdrawal in late April; OPM has not responded substantively. The story is still scoring high on r/fednews (775+ post score this week), meaning federal employees are still anxious and looking for guidance. The Privacy Act access request and congressional contact playbook below remain the actionable steps.

The Office of Personnel Management published a formal request in December 2025 requiring all 65 FEHB health insurance carriers to submit monthly claims-level data on every enrolled federal employee, retiree, and family member. The data includes medical claims, pharmacy records, encounter data, and provider information on more than 8 million people covered by the Federal Employees Health Benefits Program.

The request does not clearly specify whether that data will be de-identified before submission. Privacy advocates say that gap is the whole problem.

Key Takeaways

  • OPM's December 2025 Information Collection Request requires 65 FEHB carriers to submit monthly medical claims, pharmacy claims, encounter data, and provider data on 8M+ enrollees.
  • The ICR does not state clearly whether the submitted data will be individually identifiable or de-identified, a critical omission that privacy advocates say creates serious risk.
  • OPM already operates a Health Claims Data Warehouse with similar data. This request expands and systematizes that collection.
  • There is no individual opt-out mechanism. Once enrolled in FEHB, you cannot prevent your insurer from complying.
  • Privacy advocates cite the 2015 OPM breach, in which 21.5 million records were stolen by foreign hackers, as evidence that OPM should not be trusted with a new sensitive database without strong safeguards.
  • You can file a Privacy Act access request with OPM to see what health records they currently hold on you.

What OPM Is Requesting

On December 12, 2025, OPM published a notice in the Federal Register titled "Agency Information Collection Request: Federal Employees Health Benefits and Postal Service Health Benefits Programs Service Use and Cost Data" (reference number 3206-NEW).

The request covers all 65 FEHB and Postal Service Health Benefits Program carriers. It requires:

  • Monthly submissions of claims-level data
  • Quarterly manufacturer rebate data
  • Data types: Medical claims, pharmacy claims, encounter data, and provider data

The FEHB program covers more than 8 million federal employees, retirees, postal workers, and their family members. It is the largest employer-sponsored health insurance program in the country, costing approximately $59 billion in fiscal year 2021.

OPM's stated legal authority is the HIPAA Privacy Rule at 45 CFR 164.512(d)(1), which permits covered entities, such as insurance carriers, to disclose protected health information to health oversight agencies without individual consent for oversight activities.

The comment period closed February 10, 2026.


The Data Gap That Has Privacy Advocates Alarmed

The ICR does not state whether the data submitted by carriers will be individually identifiable or de-identified.

That is not a minor technical detail. It determines whether OPM is building a database that links your name, SSN, and medical history, or an aggregate dataset used only for program-level analysis.

Civil Service Strong, a project of Democracy Forward, submitted formal comments on February 10, 2026, specifically targeting this ambiguity. Their analysis found the ICR:

  • Fails to explain how OPM will apply HIPAA's "minimum necessary" standard, which requires limiting health data collection to only what is needed for the stated purpose
  • Provides no assurances that OPM will not share collected medical data with other federal agencies for purposes unrelated to FEHB administration
  • Cites a demonstrated pattern from the current administration of sharing sensitive government data without adequate safeguards

Their filing pointed to January 2026 disclosures that SSA data had been sent to people with no formal relationship with the agency. An OPM request for millions of medical records, with no stated restrictions on what happens to that data afterward, fits the same pattern.

Under the Privacy Act (5 U.S.C. 552a), federal agencies may "maintain in its records only such information about an individual as is relevant or necessary to accomplish a purpose of the agency." Democracy Forward argues OPM's ICR does not meet that standard because it does not adequately justify why claims-level individual data, as opposed to aggregate or de-identified data, is necessary for FEHB oversight.


What Data Is Already Held: The Health Claims Data Warehouse

This is not OPM's first health data collection. OPM already operates the Health Claims Data Warehouse (HCDW), which contains medical claims, pharmacy information, enrollment data, and provider records for FEHB enrollees.

The December 2025 ICR represents an expansion: moving from existing, ad hoc collection to a formal, ongoing monthly requirement across all 65 carriers.

The HCDW is governed by OPM's own privacy policies and HIPAA. But the new ICR introduces several concerns that go beyond what the HCDW framework previously addressed, including the lack of clarity on de-identification and the absence of restrictions on inter-agency data sharing.

Here is what is known about the data types involved:

Data Type What It Includes
Medical claims Diagnoses, procedures, dates of service, provider, cost
Pharmacy claims Prescriptions filled, drug names, dosages, refill history
Encounter data Records of patient-provider interactions, including visits not billed as traditional claims
Provider data Which providers you see, their specialties, billing codes

Put those four together and you have a detailed medical profile. Pharmacy claims alone can expose chronic conditions, mental health treatment, and reproductive health decisions. That is not routine program oversight data.


Why the 2015 OPM Breach Is Impossible to Ignore

In June 2015, OPM disclosed two related breaches that together compromised:

  • 4.2 million current and former federal employee personnel records (names, SSNs, employment history)
  • 21.5 million background investigation records, including SF-86 forms with mental health history, foreign contacts, financial information, and 5.6 million sets of fingerprints

The attacks were attributed to Chinese state-sponsored hackers. It remains the largest known theft of federal government personnel data.

OPM contracted IDX to provide 10 years of free identity protection to affected individuals. That coverage expires September 30, 2026. If you were enrolled in IDX coverage from the 2015 breach, check your expiration date now.

OPM's security posture in 2015 was bad enough that Chinese state hackers sat inside its systems for more than a year before detection. Adding a new database of medical records to that same agency, without any public accounting of what has changed, is the specific concern advocates are raising. Not the idea of oversight data in general. The idea of OPM holding it.

The 2025-2026 DOGE period has added another layer. Courts found that OPM systems were accessed by DOGE personnel in ways that violated Privacy Act procedures, and a D.C. federal court allowed a Privacy Act lawsuit by five federal employees to advance to discovery in early 2026. The pattern of inadequate data controls is not limited to 2015.


NARFE Doubles Down: The April 14 Statement

On April 14, 2026, the National Active and Retired Federal Employees Association (NARFE) issued its second public statement on the OPM data request, this time calling out specific protective gaps in OPM's current plan. The first NARFE statement came at the February 10 comment deadline. The April 14 statement is notable because it escalates the advocacy posture and names specific demands.

NARFE National President Bill Shackelford laid out four gaps OPM has not addressed:

  1. No described data security measures. OPM has not publicly specified how the monthly claims submissions will be encrypted in transit, at rest, or during analysis.
  2. No access controls. NARFE argues OPM has not defined which staff, contractors, or partner agencies will have access to the claims-level records.
  3. No retention policy. There is no stated schedule for how long individual-level health records will be held before deletion or aggregation.
  4. No assurance against inter-agency sharing. OPM has not committed that the data will remain inside OPM and not be shared with DOJ, DHS, SSA, or other agencies for unrelated purposes.

Shackelford's statement: "NARFE strongly urges OPM to identify how it will protect the privacy of federal employee and retiree health data before moving forward with this collection."

NARFE's public pressure is not legally binding. But for federal employees, it is the most authoritative advocacy voice on the record, and it signals that the Federal Register comment period closing in February did not end the oversight conversation, it shifted it to direct advocacy pressure on OPM and Congress. Watch for NARFE updates if OPM issues a substantive response.


The picture changed on June 23, 2026, when OPM published a revised Privacy Act System of Records Notice renaming its health claims database "Health Benefits Claims and Cost Records" (OPM/Central-15). After a 30-day comment window, the notice's routine uses took legal effect on July 23, 2026.

Three details in the SORN matter more than the rename:

  • PSHB enrollees are now explicitly covered, folding postal workers and annuitants into the same claims system.
  • Medicare claims linkage was added for dual-enrollees, connecting FEHB and Medicare data for the same person.
  • OPM uses pseudonymization, not true de-identification. The agency retains a re-identification key, which means "de-identified" records can be tied back to you by anyone with access to the key.

Keep the two tracks straight, because the r/fednews threads mixing them up produce most of the confusion. The SORN (OPM/Central-15) is live: it governs the claims data OPM already holds and how it may be shared. The expanded monthly data collection (ICR 3206-NEW) is still pending: as of August 2026, OMB has not approved it, the 2027 carrier Call Letter did not include the new requirements, and the 65-carrier monthly feeds have not started.

In July 2026, NARFE escalated past its April statement with a letter to OPM Director Kupor making four technical demands: true de-identification as the default, mandatory rather than discretionary safeguards, hard separation of re-identification keys from enrollment files, and an explicit written prohibition on using health claims data for any personnel action. Those four demands double as the checklist for anything you ask Congress to do.

Your Privacy Rights Under the Privacy Act

The Privacy Act of 1974 (5 U.S.C. 552a) gives federal employees specific rights over records agencies maintain on them. Those rights apply to health records OPM holds through the FEHB program.

The law gives you five specific rights:

  1. Access records OPM maintains on you. Submit a Privacy Act access request to OPM's privacy office.
  2. Know whether your records have been disclosed and to whom, with limited law enforcement exceptions.
  3. Amend records you believe are inaccurate or irrelevant.
  4. Consent before disclosure, except for the Privacy Act's 12 enumerated exceptions, including "routine use" disclosures that agencies define in their System of Records Notices.
  5. Sue in federal district court for unlawful disclosures (5 U.S.C. 552a(g)).

The "routine use" exception is where disputes often land. Agencies define their own routine uses in Federal Register notices. If OPM establishes a routine use that permits sharing FEHB health data with, for example, other benefit administrators, law enforcement, or policy offices, it can do so without your consent, as long as the routine use is published.

HIPAA adds a layer of protection for health data specifically. The minimum necessary standard under 45 CFR 164.502(b) requires that when a covered entity requests or receives health information, it must make reasonable efforts to limit that information to the minimum necessary. Privacy advocates argue OPM's ICR does not demonstrate that standard has been applied.


The Defense Playbook: Five Verified Steps

There is no individual opt-out. What you have instead are five specific mechanisms, each with a legal citation, an address, and a deadline the agency must meet.

Step 1: See what OPM holds on you. File a Privacy Act access request under 5 U.S.C. 552a(d)(1). Write to OPM Privacy Office, 1900 E Street NW, Washington, DC 20415 (or privacy@opm.gov), label the letter and envelope "Privacy Act Access Request," and cite the system by name: OPM/Central-15, Health Benefits Claims and Cost Records. OPM must acknowledge within 10 business days and respond within 20 working days. This creates your documented baseline.

Step 2: See who has received your records. This is a different request from Step 1, and almost nobody files it. An accounting-of-disclosures request under 5 U.S.C. 552a(c)(3) forces OPM to list the date, purpose, and recipient of every documented disclosure of your records. Same address; label it "Privacy Act Accounting of Disclosures Request," cite 552a(c)(3) and OPM/Central-15, and specify a date range. This is the mechanism that answers the question actually driving the Reddit threads: has my health data been shared with another agency? You can combine Steps 1 and 2 in one letter. One limit to know: certain law enforcement disclosures under 552a(b)(7) don't have to appear in the accounting.

Step 3: Track what your insurer sent to OPM. Your FEHB carrier is a HIPAA covered entity, and 45 CFR 164.528 gives you an accounting-of-disclosures right against the carrier directly. Write to the carrier's HIPAA Privacy Officer, request an accounting of disclosures of your protected health information, and name OPM as a recipient of interest. The carrier has 60 days to respond and the accounting reaches back up to 6 years. Caveat: disclosures for treatment, payment, and health care operations are often excluded, so the response may understate routine claims feeds.

Step 4: Give Congress a specific ask, not a vibe. Reference "OPM Information Collection Request, OMB Control No. 3206-NEW" and ask your representative and senators to press for the four NARFE demands before any OMB approval: true de-identification, binding safeguards, key separation, and a written prohibition on personnel-action use of claims data. Ask for a GAO or Inspector General review of the claims system's security posture while you're at it. House Oversight and Senate Homeland Security members carry the most leverage.

Step 5: Use the union path for what it can actually do. A grievance under 5 U.S.C. 7121 runs against your employing agency, not OPM, so the ICR itself is beyond the grievance process. What your union can do: bargain over any agency-level implementation, make the personnel-use prohibition a formal bargaining objective, and feed the AFGE and NARFE national campaigns. Honest framing beats false hope here.

And four things not to do. Don't assume a Privacy Act request stops future collection; it doesn't. Don't disenroll from FEHB as a privacy protest; breaking the 5-year chain for retiree coverage is a disproportionate self-inflicted wound. Don't file an HHS Office for Civil Rights complaint about the ICR now; it hasn't been approved, so there's no carrier violation to complain about yet. And don't send Privacy Act requests to your agency's HR office; OPM holds the system, and requests go to OPM.

Read your FEHB carrier's privacy notices. Carriers are required to send HIPAA Notice of Privacy Practices updates. Those documents spell out exactly what your insurer discloses to OPM and under what legal authority. Most people never read them. Now is a good time.

Consider plan type at next open season. Fee-for-service plans and HMOs generate different types of encounter and claims data. If you have privacy concerns about a specific carrier's data practices, that is a legitimate factor to weigh when comparing plans.


Check Your FEHB Plan Coverage

Understanding your current FEHB coverage is the starting point for evaluating what health data your plan generates and submits. Use our free FEHB Calculator to compare plan costs, premiums, and coverage levels for your situation.


Frequently Asked Questions

What is OPM/Central-15 and is it different from the new data collection?

OPM/Central-15, renamed "Health Benefits Claims and Cost Records" in a June 23, 2026 notice, is the existing system where OPM stores FEHB claims data. Its updated routine uses took legal effect July 23, 2026, and now cover PSHB enrollees and Medicare linkage. It is separate from ICR 3206-NEW, the December 2025 proposal requiring all 65 carriers to submit expanded monthly claims feeds. As of August 2026, that proposal is still pending OMB approval and the feeds have not started.

How do I find out if OPM has already shared my health records with another agency?

File a Privacy Act accounting-of-disclosures request under 5 U.S.C. 552a(c)(3). It is a different mechanism from a records access request. Label the letter "Privacy Act Accounting of Disclosures Request," cite OPM/Central-15, give a date range, and send it to the OPM Privacy Office at 1900 E Street NW, Washington, DC 20415. OPM must acknowledge within 10 business days and the response must list the date, purpose, and recipient of each documented disclosure.

What medical data is OPM requesting from FEHB insurers?

OPM's Information Collection Request asks 65 FEHB carriers to submit monthly claims-level data including medical claims, pharmacy claims, encounter data, and provider data on all enrollees. The request does not clearly specify whether the data will be de-identified before submission, which is a central concern raised by privacy advocates.

Is my health data already being collected by OPM?

OPM already operates a Health Claims Data Warehouse (HCDW) that contains medical claims, pharmacy, enrollment, and provider information for approximately 8 million FEHB enrollees. The December 2025 Information Collection Request represents an expansion of that collection, requiring ongoing monthly submissions from all 65 carriers going forward.

Can I opt out of OPM collecting my FEHB health data?

There is currently no individual opt-out mechanism for this data collection. FEHB enrollment itself is voluntary, but once enrolled, you have no documented ability to prevent your insurer from submitting claims data to OPM under this request. You can file a Privacy Act access request with OPM to see what records they hold on you.

What is OPM's stated reason for collecting this data?

OPM states the data will enable it to oversee health benefits programs and ensure they provide competitive, quality, and affordable plans. OPM cites HIPAA's health oversight exception as the legal authority permitting FEHB carriers to share protected health information with OPM without individual consent.

Why does the 2015 OPM breach matter for this new data collection?

The 2015 OPM breach compromised 21.5 million background investigation records and 4.2 million personnel records, attributed to Chinese state-sponsored hackers. Privacy advocates argue that OPM's demonstrated history of catastrophic data security failures makes adding a new trove of sensitive medical data an unjustified risk, especially without strong safeguards against sharing that data with other agencies.

What can I do if I'm concerned about OPM collecting my medical data?

You can file a Privacy Act access request with OPM to see what health records they maintain on you, submit a complaint to your agency's privacy office, or contact your congressional representatives. Organizations like Democracy Forward have submitted formal comments opposing the collection. You can also review your FEHB plan options using the FEHB Calculator.



Disclaimer: This article is for informational purposes only and does not constitute legal advice. Privacy Act rights and HIPAA protections involve legal and factual complexities specific to each individual's situation. Consult qualified legal counsel for advice about your specific circumstances.

Sources: Federal Register ICR Notice 3206-NEW (Dec. 12, 2025), Democracy Forward / Civil Service Strong comment (Feb. 10, 2026), OPM Health Claims Data Warehouse Privacy Impact Assessment, OPM.gov FEHB Carriers, HHS HIPAA Privacy Rule Summary, DOJ Privacy Act Overview, Federal News Network: 2015 OPM breach coverage, GovExec: OPM April 2026 FEHB coverage