Why It Matters
A Congressional Research Service report examines a significant shift in how the Office of Personnel Management (OPM) plans to oversee federal employee health benefits. OPM wants to collect detailed medical claims data directly from health insurance carriers covering over 8 million federal employees, retirees, and their families.
The agency claims it has the legal authority to demand this data. However, it has sidestepped the standard rulemaking process by structuring the request under the Paperwork Reduction Act instead of following notice-and-comment procedures. This raises a key question: Does OPM's mandate actually require formal rulemaking under the Administrative Procedure Act? Once approved by the Office of Management and Budget, OPM could force carriers to comply.
The Big Picture
OPM signaled its intent in October 2025 to expand data collection. The agency published an initial notice on Friday, December 12, 2025, seeking medical claims data, pharmacy claims data, encounter data, and provider information from carriers. A follow-up notice appeared on Tuesday, June 23, 2026, modifying OPM's Privacy Act records system. As of mid-2026, approval was still pending.
OPM argues the data is necessary to manage costs, ensure competitive coverage, detect fraud and abuse, and evaluate new policies. The administration frames this as a cost-containment tool.
OPM claims authority under federal statute to collect this data. The law requires carriers to provide reasonable reports and allows OPM and the Government Accountability Office to examine carrier records. OPM also argues it qualifies as a health oversight agency and can obtain health information without individual authorization.
However, a trade organization representing FEHB carriers disputes this. They argue the statute does not extend to individual-level claims data on every enrollee. Whether OPM's mandate requires formal rulemaking remains unresolved, as OPM has not conducted notice-and-comment procedures.
Political Stakes
For the Administration: OPM views this data as essential to managing federal employee health costs and detecting fraud and waste.
For Congress: Congress could act through oversight or appropriations riders if it determines OPM exceeded its authority or failed to follow proper procedures.
For the Public: Federal employees and retirees face privacy risks if OPM's safeguards prove insufficient to prevent re-identification of health data.
The Bottom Line
Privacy protections remain unclear. OPM proposes pseudonymization: data would go to OPM's Office of the Inspector General, which would provide an encrypted copy to technical staff with identifying fields removed except for Member ID. Yet the request does not clearly specify whether data will remain individually identifiable or be fully de-identified. Stakeholders worry that even de-identified data could be re-identified using information OPM already holds on enrollees and their families. The notice also does not specify how the data would be used or whether third parties could access it.
Access the Legis1 platform for comprehensive political news, data, and insights.
Spot something wrong? Report an issue with this article