Comment from Anonymous

AnonymousOpposeIndividual
Summary: The commenter opposes the proposed modification of OPM/Central-15, arguing that it converts a program-administration claims warehouse into a broadly shareable government-wide data resource without adequate legal justification or safeguards. They specifically argue that the new routine uses fail the Privacy Act's compatibility requirement, include sensitive clinical data in payment-screening systems, and lack sufficient pseudonymization and oversight.
Re: Docket No. OPM-2026-0134; Privacy Act of 1974; System of Records — OPM/Central-15, "Health Benefits Claims and Cost Records," 91 FR 37439 (June 23, 2026) I write in opposition to the proposed modification of OPM/Central-15. The notice converts a program-administration claims warehouse covering more than 8 million federal employees, postal workers, annuitants, tribal employees, and their family members into a broadly shareable government-wide data resource, without adequate legal justification or enforceable safeguards. OPM should withdraw or substantially narrow the modification. 1. New routine uses (j), (k), and (l) fail the Privacy Act's compatibility requirement. A routine use is lawful only if disclosure is "compatible with the purpose for which [the record] was collected." 5 U.S.C. 552a(a)(7), (b)(3). These records are collected from carriers under 5 U.S.C. 8910 to administer and oversee the FEHB Program. Routine use (k), however, authorizes disclosure to any "Federal agency or Federal entity" for fraud, waste, and abuse efforts in programs under the RECIPIENT'S purview — purposes with no concrete relationship to FEHB administration. Under OMB's 1975 Guidelines (40 FR 28948, 28953), compatibility demands more than a generic anti-fraud rationale; reliance on E.O. 14243 and OMB M-25-32 cannot substitute for the statutory standard. Routine use (l) similarly sends FEHB claims-derived data to Treasury's Do Not Pay Working System for screening payments across ALL federal and even state-administered programs. 2. Clinical data does not belong in Do Not Pay. The Payment Integrity Information Act, 31 U.S.C. 3351-3358, contemplates eligibility screening against enumerated databases (death records, debarment lists, etc.). Nothing in PIIA requires or contemplates feeding diagnosis codes (ICD), procedure codes (CPT), drug codes (NDC/J-codes), and dates of service into a cross-government payment-screening system. If any DNP disclosure is retained, it must be expressly limited to enrollment and eligibility fields and must exclude all clinical and utilization data. 3. Pseudonymization here is not de-identification, and the notice concedes it. Records "remain subject to the Privacy Act because OPM retains the ability to re-identify records," Member ID is transmitted as-is before hashing, and the retained fields — five-digit ZIP code, year of birth, sex, provider identifiers, diagnoses, and dates of service — are well established in the re-identification literature (e.g., Sweeney) as sufficient to identify individuals when combined. Worse, the safeguard commitments are purely discretionary: pseudonymization applies "wherever practicable," and disclosures "ordinarily" will use pseudonymized records "unless identifiable information is reasonably necessary." These qualifiers permit identifiable disclosure at OPM's sole discretion, with no written-agreement requirement, no minimization standard, no audit or logging commitment, and no public reporting. Notably, OPM requires prior written CMS approval before redisclosing Medicare data (n.5) but imposes no equivalent gate on FEHB enrollees' own data. 4. The sensitivity of these records demands more, not less, protection. The system includes mental health, substance use disorder, reproductive health, and HIV-related claims. Routine interagency dissemination of such data — including under routine use (c) to state, local, and even foreign law enforcement based on an indication of a "potential violation of law" — will chill federal employees' willingness to seek care through their own health benefits. 5. The process is deficient. The modified system is "effective upon publication," and the routine uses become effective July 23, 2026 — the very day comments close — rendering this comment period a formality. OPM also eliminated the prior routine use for de-identified analytical sharing while substituting far broader identifiable-data pathways, a trade the notice nowhere justifies. Accordingly, OPM should: (a) withdraw routine uses (j), (k), and (l), or narrow them to FEHB/PSHB program integrity conducted by or for OPM; (b) limit any Do Not Pay disclosure to non-clinical eligibility fields; (c) make pseudonymization mandatory for all disclosures and analytical uses, striking "wherever practicable" and "ordinarily"; (d) require written data use, minimization, retention, and audit agreements — with prior written OPM approval, mirroring the CMS condition — before any external disclosure; (e) exclude or specially protect SUD, mental health, reproductive health, and HIV-related records; and (f) suspend the effectiveness of the new routine uses until comments are reviewed and addressed in a revised notice. Thank you for your consideration.

View on Regulations.gov