If you’re enrolled in the Federal Employees Health Benefits (FEHB) Program or the Postal Service Health Benefits (PSHB) Program, you’ve probably never thought about where your FEHB health claims data goes after your insurance company processes it. But a proposal from the Office of Personnel Management (OPM) has sparked months of debate over exactly that question.
At the center of the discussion is a new data collection initiative that would allow OPM to receive detailed health claims information from FEHB and PSHB insurance carriers. OPM says the information will help improve oversight of the program, while federal employee organizations argue the agency still hasn’t provided enough answers about privacy and data security.
Key Takeaways
- OPM plans to collect FEHB health claims data from insurance carriers each month.
- The agency says names, Social Security numbers, and other direct identifiers will be removed before it receives the data.
- Federal employee organizations, including NARFE and AFGE, say important privacy questions remain unanswered.
- Federal employees do not need to take any action, and participation is not optional because the data is submitted by insurance carriers.
What OPM Wants to Collect
The proposal originated with a December 2025 notice directing FEHB and PSHB carriers to submit monthly claims-level information covering more than eight million federal employees, retirees, postal employees, and eligible family members.
The information includes medical claims, pharmacy claims, provider information, and healthcare utilization data.
According to OPM, the objective is to better understand healthcare costs, utilization patterns, quality of care, and overall program performance. The agency has also said the FEHB health claims data could help identify fraud, improve oversight, and support future policy decisions affecting the FEHB and PSHB programs.
OPM maintains that this is not an effort to review individual employees’ medical histories but rather to analyze trends across the program as a whole.
How the Data Is Protected
Following significant criticism from employee organizations and insurers, OPM revised its approach.
Before OPM receives the information, the agency’s Office of the Inspector General removes direct personal identifiers, including names, Social Security numbers, telephone numbers, and street addresses.
The remaining member identifier is then replaced with a randomized code before being transmitted to OPM. While ZIP code, year of birth, medical claims, prescription information, and provider data remain, OPM says the information it receives cannot be directly linked back to a specific individual.
The agency points to its experience handling similarly protected Medicare data as a model for safeguarding the information.
Why Employee Groups Still Have Concerns
Although federal employee organizations acknowledged that OPM’s revised process is an improvement, they argue it doesn’t fully resolve their concerns.
The National Active and Retired Federal Employees Association (NARFE) has said that pseudonymized data is not the same as fully de-identified data under HIPAA standards. The organization has asked OPM to provide more details about who will have access to the records, how long the information will be retained, whether contractors or outside entities could access the data, and what additional safeguards will be in place.
The American Federation of Government Employees (AFGE) has raised similar concerns, while several health insurers and privacy experts have questioned whether the collection strikes the right balance between program oversight and protecting enrollee privacy.
In June 2026, OPM also updated the system through the Federal Register to formally include PSHB participants within the same records framework, expanding the scope of the collection beyond traditional FEHB enrollees.
What This Means for Federal Employees
At this point, federal employees and retirees don’t need to do anything. The data is submitted by insurance carriers rather than individual enrollees, and there is currently no separate opt-in or opt-out process.
Still, the discussion is worth following. While OPM says the information is designed to improve oversight of one of the nation’s largest employer-sponsored health insurance programs, employee organizations continue to push for clearer answers about privacy protections, data retention, and oversight before considering the issue settled.
For now, the debate isn’t over whether OPM should understand how the FEHB program is performing. It’s about how much FEHB health claims data the agency should retain, who can access it, and whether the safeguards are strong enough to protect the millions of federal employees, retirees, and family members whose information is included.
If you have questions about how your personal health information is handled today, your FEHB or PSHB carrier’s privacy notice remains the best place to understand your current protections.
Frequently Asked Questions
Is OPM collecting my personal medical records?
No. OPM says it will receive claims data after direct identifiers, such as names and Social Security numbers, have been removed. However, the remaining claims information still contains detailed healthcare and prescription data, which is why some organizations continue to raise privacy concerns.
Do I need to opt in or opt out?
No. The information is submitted by FEHB and PSHB insurance carriers. Individual enrollees are not required to take any action.
Why does OPM want FEHB health claims data?
OPM says the data will help analyze healthcare costs, utilization, quality, program performance, and potential fraud across the FEHB and PSHB programs.
Why are federal employee organizations objecting?
Groups such as NARFE and AFGE say OPM has not fully explained who will have access to the data, how long it will be retained, and whether the privacy protections are sufficient.
Is the program already in effect?
OPM has been moving forward with implementation, but the proposal has undergone revisions following public comments, and employee organizations continue to seek additional privacy safeguards.















