7/28/26 – NARFE National President William Shackelford submitted formal comments to the Office of Personnel Management (OPM) on July 23, responding to its notice regarding its collection of medical claims data of Federal Employees Health Benefits (FEHB) and Postal Service Health Benefits (PSHB) program participants. NARFE acknowledged that the revised notice, together with a public explanation issued by OPM Director Scott Kupor, responds to several concerns the association raised earlier — including a process for pseudonymizing personally identifiable data. But NARFE indicated that serious concerns remained.
The comments identify three specific reasons for concern. First, the bulk of the substantive explanation resides in a blog post rather than in the Federal Register notice, which is the operative legal instrument; a blog post can be revised or removed without notice or comment, leaving members to detect and litigate any departure after the fact. Second, protections described in the blog post appear in the notice in qualified or discretionary terms — pseudonymization applied “wherever practicable,” disclosures “ordinarily” made in pseudonymized form — or not at all.
Third, and most fundamentally, NARFE asked for de-identified data, and OPM has offered pseudonymized data, which are not the same standard. De-identified data falls outside the HIPAA Privacy Rule; pseudonymized data is fully identifiable data with identifiers reversibly replaced, and OPM concedes the records remain Privacy Act records precisely because it retains the ability to re-identify them. That risk is heightened, NARFE argues, because OPM holds both the hash key and the FEHB and PSHB enrollment files from which the hashed identifiers derive — re-identification would require not code-breaking but only a decision to combine two assets the same agency already controls.
The letter offers seven recommendations. NARFE asks OPM to restate the pseudonymization protocol in mandatory rather than permissive language and to memorialize it in the OIG data sharing agreement, the Privacy Impact Assessment, and internal policy subject to IG audit; to make HIPAA de-identification the default and pseudonymization the exception, justified analysis by analysis; to establish hard technical and administrative separation between key custody and enrollment data, subject to periodic OIG verification; and to make the re-identification exception exhaustive rather than illustrative, with senior-official approval, logging, and annual aggregate reporting.
The comments further urge OPM to explain why it did not adopt a data-minimizing design — such as running queries against the database the OIG already maintains, or modeling the CMS External Data Gathering Environment, under which record-level data stays in the originating environment — and to narrow defined routine uses, specify a retention and key-destruction schedule, and define “encounter data,” a term left undefined across four iterations of the notice. Most pointedly, NARFE asks OPM to state affirmatively that no data in the system will be used for personnel actions, suitability, fitness, security clearance adjudication, reduction in force, or performance management, noting that OPM is not merely a health oversight agency but functionally the employer of the workforce whose medical claims it proposes to hold.
