Privacy advocates fear massive fed health database

U.S. Office of Personnel Management wants to collect data from three health programs

By Jaikumar Vijayan, Computerworld |  Security, health care, privacy Add a new comment

Several privacy groups have raised alarms over plans by the U.S. Office of Personnel Management (OPM) to build a database that would contain information about the healthcare claims of millions of Americans.

The concerns have surfaced because the OPM has provided few details about the new database and because the data collected will be shared with law enforcement, third-party researchers and others.

In a letter to OPM Director John Berry, the Center for Democracy and Technology (CDT) and 15 other organizations asked the agency to release more details on the need for the database and how the data contained in it will be protected and used.

The OPM "should not create this massive database full of detailed individual health records without giving the public a full and fair chance to evaluate the specifics of the program," the letter cautioned.

It also called upon the OPM to delay its proposed Nov. 15 launch date for the database because there was not enough time for independent observers to evaluate the proposal.

According to the OPM, the planned Health Claims Data Warehouse is designed to help the agency more cost-effectively manage three health claims programs: the Federal Employee Health Benefit Program (FEHBP), the National Pre-Existing Condition Insurance Program and the Multi-State Option Plan.

The pre-existing condition program, which launched in August, and the multi-state option plan, which is scheduled to go into effect in January 2014, were both introduced earlier this year as part of the Affordable Care Act , the law designed to overhaul health care in the U.S. that was signed by President Obama in March. The OPM is in charge of administering the FEHBP as well as the two new programs.

In a formal notice published in the Federal Register last month, the OPM said that creating a central and comprehensive database would allow it to more actively manage the programs and ensure "best value for both enrollees and taxpayers."

As part of the effort, the OPM will establish direct data feeds with each of the three programs and will continuously collect, manage and analyze health services data. The data that the agency collects will include individuals' names, addresses, Social Security numbers and dates of birth, plus the names of their spouses and other information about dependents, and information about their healthcare coverage, procedures and diagnoses.

According to the so-called systems of record notice (SORN) that the OPM published in the Federal Register, the data collected will be de-identified, which means that details that would tie pieces of data to specific individuals would be removed. This process would occur "in many instances" and before an analysis is conducted, the OPM reports. However, the notice offers no details on how and when such de-identification will be done or the extent to which personal identifiers will be removed before analysis.

In addition to using the data for its own internal analysis, the OPM will also make it available, if required, for law enforcement purposes and for use in judicial or administrative proceedings, and to "researchers and analysts" inside and outside government for healthcare research purposes, the OPM notice said.

The OPM's notice is troubling for its lack of detail and the limited time it offers for evaluation, said Harley Geiger, policy counsel for the CDT.

"There are far too many unknowns about the program for it to be acceptable," at this point, Geiger said.

While the OPM, for instance, has indicated that the data it collects will help to better administer the three healthcare programs, there are no details why the data will be useful, he said.

The OPM did not respond to several requests for comment.

The OPM has also made little mention of how it plans to protect the data it collects or what its processes for de-identification are going to be, Geiger said. Regulations in HIPAA (the Health Insurance Portability and Accountability Act) require specific steps for making health care data anonymous, but there is no indication that the OPM will adopt those standards or something else, Geiger said.

The OPM's statement that it will share the data with third-party researchers and analysts is also deeply troubling, as is its willingness to make the data available for law enforcement and judicial purposes, he said.


Originally published on Computerworld |  Click here to read the original story.

ITworld LIVE

SecurityWhite Papers & Webcasts

Webcast On Demand

Seven Deadly Sins of Cloud Security (Video)

As cloud computing gains popularity, too few people are aware of the security threats that are emerging. In this short video, experts from HP discuss the latest cloud security threats and explain measures to help overcome them. Hear about the seven deadly sins of cloud security and learn how to avoid becoming a victim of poor security in your cloud environment.Intel and the Intel logo are trademarks of Intel Corporation in the U.S. and/or other countries.

Sponsor: HP & Intel

White Paper

Establishing a Strategy for Database Security is No Longer Optional

The options for securing increasingly valuable databases are very broad and deep, and can be confusing. This research provides an overview of three categories of controls that should be implemented to ensure that enterprise data is protected in the most efficient and effective manner.

White Paper

Database Activity Monitoring Is Evolving

Read the analyst report and learn how you can leverage the core capabilities of a DAP solution for better database security.

White Paper

Protecting Against Database Attacks and Insider Threats: Top 5 Scenarios

Read this new eBook to learn the top five scenarios and essential best practices for preventing database attacks and insider threats.

Webcast On Demand

Distributed Database Security with Real-time Monitoring

View this demo and learn how IBM InfoSphere Guardium database activity monitoring can help protect your sensitive data in distributed DBMS environments with a holistic approach to data security and compliance.

Sponsor: IBM

See more White Papers | Webcasts

Ask a question

Ask a Question