Comment from Beth Anne Jackson
AnonymousOpposeIndividual
Summary: The commenter opposes the proposal, arguing that it fails to comply with HIPAA regulations regarding the de-identification of Protected Health Information (PHI) for Federal Employees Health Benefits (FEHB) beneficiaries. They contend that OPM does not meet the legal definition of a "health oversight agency" and that the disclosure exceeds the "minimum necessary" standard.
Because the US government is the employer of FEHB beneficiaries, it is essential that there be full de-identification of PHI - pursuant to the standard set forth in the HIPAA regulations - in order to ensure the security of PHI and, further, to ensure that PHI is not used to make employment decisions or for other non-allowable purposes under HIPAA. The United States Congress did not carve out federal employees and their families from HIPAA's privacy protections. There is no legitimate reason for OPM to have access to identifiable PHI on a massive scale like this, and there is an utter dearth of safeguards to protect FEHB beneficiaries from mis-use of their PHI.
From a legal standpoint, I question this proposal on the following grounds:
1. Is OPM actually a "health oversight agency," defined as an agency "that is authorized by law to oversee the health care system (whether public or private) or government programs in which HEALTH INFORMATION IS NECESSARY TO DETERMINE ELIGIBILITY OR COMPLIANCE." Health information is not necessary to determine eligibility for FEHB benefits - only employment status of the beneficiary or a family member as a federal employee. OPM contracts with insurers to not only administer benefits, but also to ensure compliance with the defined scope of benefits. The insurers should be performing reviews for fraud, advising relevant authorities when fraud is detected and disclosing information as necessary to pursue action against those committing fraud.
2. This massive disclosure does not meet the minimum necessary standard and no exception to the application of the standard applies - this disclosure is not "required by law" and, even if it were, the minimum necessary standard still applies. De-identified PHI is the "minimum necessary" in this situation.
All PHI is protected by HIPAA, and insurers and OPM must abide by the parameters of HIPAA when sharing the PHI of FEHB beneficiaries. CVS Health was absolutely right in its assessment of the original proposal, and nothing in the revised proposal cures the failure to comply with HIPAA.