Data Grab Archives - Ñî¹óåú´«Ã½Ò•îl Health News /series/data-grab/ Ñî¹óåú´«Ã½Ò•îl Health News produces in-depth journalism on health issues and is a core operating program of KFF. Mon, 27 Jul 2026 14:56:16 +0000 en-US hourly 1 https://wordpress.org/?v=6.8.6 /wp-content/uploads/sites/8/2023/04/kffhealthnews-icon.png?w=32 Data Grab Archives - Ñî¹óåú´«Ã½Ò•îl Health News /series/data-grab/ 32 32 161476233 Trump Administration Demands Hospitals Share Emergency Room Records /health-industry/cpsc-consumer-product-safety-commission-trump-er-injury-data-grab-neiss-konza/ Mon, 27 Jul 2026 09:00:00 +0000 /?p=2262089 A tiny federal agency tasked with protecting the public from injuries caused by lawn mowers and coffeemakers is demanding that some of the nation’s biggest health systems turn over detailed, personally identifiable medical records of all patients who seek help at their emergency rooms.

The Consumer Product Safety Commission, responsible for tracking and issuing recalls of dangerous products sold in the U.S., began discreetly pressuring hospital executives this year to share personally identifiable health data with a private contractor. But hospital lawyers and other industry experts have questioned the agency’s authority to collect, its ability to safeguard such a swath of sensitive information, and whether it has followed the legal process to overhaul its surveillance system.

After Ñî¹óåú´«Ã½Ò•îl Health News asked the CPSC about the new system, the the program on July 21. Left unmentioned, however, is the alarm it has raised among hospital executives, as well as the nature and extent of the agency’s data demands.

In a stark departure from its product-focused mission, the agency’s goal is to obtain millions of Americans’ medical records from emergency room visits for most injuries, from a broken bone to a childhood vaccine reaction or even a suicide attempt, according to documents and emails obtained by Ñî¹óåú´«Ã½Ò•îl Health News, as well as interviews with five people involved or familiar with the discussions.

A CPSC official also insisted in the emails that the institutions provide all ER patients’ identifiable information — such as names, addresses, diagnoses, and other personal details — to the contractor, Konza Health, for analysis. In correspondence with , Konza representatives described participation as “mandatory” or “required.”

As a condition of viewing the correspondence, Ñî¹óåú´«Ã½Ò•îl Health News agreed not to republish some of the emails it obtained.

The CPSC wants at least 100 hospitals to start sending detailed medical records by the end of this year, according to an .

“The whole thing is troubling,” said Sharona Hoffman, a professor of health law at Case Western Reserve University who noted that giving a private entity access to a sweeping collection of data will introduce risks to patient privacy. “If this company really is collecting identifiable information, that is worrisome for patients.”

The new project was launched amid upheaval at the traditionally independent agency, which is without a governing board since President Donald Trump fired the CPSC’s three Democratic board members. Nearly 1 in 5 career staffers left the CPSC in the first 16 months of the new administration, according to a Ñî¹óåú´«Ã½Ò•îl Health News analysis of federal workforce data.

The initiative also comes as the Trump administration has sought unprecedented access to millions of Americans’ medical records, with the Office of Personnel Management requesting federal workers’ sensitive health information and Health and Human Services Secretary Robert F. Kennedy Jr. using a private organization to collect more medical records for his studies on vaccines and autism.

Steve Roney, CPSC spokesperson, said in an emailed statement on July 10 that the CPSC is “modernizing” its surveillance system. Asked whether the CPSC will file complaints against hospitals that do not participate, he said only that while the previous system “operated as a voluntary program, the ability of hospitals to opt out limited the sample size and usefulness of the data.”

Roney also acknowledged that the agency had not yet notified the public, as “required by law.”

Federal law requires the agency to provide notice and a public comment period before requesting information from 10 or more entities, a step it has not taken despite plans for 100 hospitals to join the surveillance system. Ñî¹óåú´«Ã½Ò•îl Health News independently confirmed with over a dozen hospitals that they had been approached.

Federal public health authorities that private health data be reported. But CPSC officials have that if hospitals decline to share data with the new surveillance system, they could be subject to strict penalties from a data-sharing regulation known as “information blocking.”

Yet some hospital executives say they are reluctant to share patients’ sensitive data because they’re concerned about a different violation — that of .

AI Takes Over

Dozens of ERs across the country already participate in the CPSC’s voluntary National Electronic Injury Surveillance System, or NEISS, through which trained hospital workers report injuries involving consumer products, almost always stripped of patients’ identifiable information. The system helps the CPSC identify products, such as baby loungers, toys, and household appliances, with a pattern of injuring consumers.

The new injury surveillance program goes much further.

At a toy industry trade event in February, acting CPSC Chairman Peter Feldman said the agency is “investing in AI-enabled workflows that improve the quality and quantity of injury surveillance data, while also building up digital infrastructure to handle a massive new volume of electronic health records.”

Konza Health, a Kansas-based organization that runs the state’s health data exchange, will automatically pull and analyze medical records of all patient visits from ERs nationwide. Konza won a worth up to $15.9 million with the CPSC last fall.

In email correspondence with hospital technology officials, Konza Health President and CEO Laura McCrary also has described ERs’ participation as “required,” stipulating that they share patients’ records with identifying information.

McCrary told Ñî¹óåú´«Ã½Ò•îl Health News by email that the company is not using AI to process the records it receives, saying instead that Konza will use “advanced analytic parsing and filtering capabilities.” Roney, the CPSC spokesperson, did not answer questions about the .

For years, agency officials moving away from human contractors and automating NEISS to save time and money.

But without workers on-site, hospital staffers may no longer receive training to determine what clinical information is important to include for the CPSC. In short, the changes could dilute the quality of the product safety data the agency collects.

“They want to suck in as much data as possible, but I’m not sure how thoughtful they’re being about what is collected and what is actually needed by the agency,” said former CPSC chair Alexander Hoehn-Saric, one of the Democratic appointees Trump fired last year.

Record Number of Career Staff Left CPSC Last Year (Column Chart)

Wanted: Injuries From Vaccines and Stingrays

The CPSC’s new data collection appears to contradict its own 214-page , which instructs hospitals not to include identifiable information “such as names, birthdates, or addresses” when reporting cases.

The agency is supposed to receive patients’ identifying information only when needed for follow-up investigations, which happens in fewer than 1% of reported cases, according to the manual.

The CPSC has also historically limited the records it collects to minimize privacy violations in case of a data breach.

The risk is not hypothetical: From 2017 to 2019, the agency improperly released personal health information of around 30,000 people, a disclosure that a top Republican at the time

Konza, however, will receive even more sensitive information on many more people. McCrary said in a statement that Konza will remove patients’ names, addresses, and medical information “not needed by CPSC” before sharing records with the agency.

Leaving a private organization to collect sensitive information introduces risks, including that it could be stolen or used for business purposes, said Hoffman, the Case Western professor.

“Very often, they will use information for marketing because now they’re going to know what conditions people have,” she said.

Roney said that its contract with Konza, which has not been made public, prohibits the organization from selling or marketing the data it collects.

The CPSC’s manual also identifies types of ER visits that should not be reported to the CPSC, which has jurisdiction over only certain consumer products. Excluded injuries are those caused by food, illegal drugs, medical devices, alcohol, or plants, as well as injuries that did not involve consumer products — such as a cut from a rock or broken bones from a fall on the ground — and suicide attempts by adults.

But in a to one hospital and reviewed by Ñî¹óåú´«Ã½Ò•îl Health News, Konza set no such limits on the information it would gather from ER records and said it would hold on to patient health information for at least 30 days.

In an email sent to hospital technology officials, McCrary wrote that Konza would provide the CPSC with records when a patient is treated in the ER for any of more than 10,000 conditions. The expansive list of diagnostic codes Konza provided in the email includes injuries that do not involve consumer products.

Child injuries resulting from “poisoning by” vaccines or contact with stingrays, neither of which is regulated by the CPSC, are included in the list.

A limited number of hospitals once shared deidentified data on all injuries — regardless of product involvement — through the NEISS using the Centers for Disease Control and Prevention’s injury-tracking program. But the CDC halted that data collection, after funding and staffing were cut last year, and has not restarted it.

Pressure on Hospitals

CPSC Chief Data Officer Elizabeth Puchek, who joined the agency late last year after engineering U.S. Citizenship and Immigration Services’ data system, has told hospitals in emails that they must seek an exemption from the program if they decline to share patients’ emergency room records with Konza.

The CPSC’s targeted outreach has included some of the nation’s largest urban and rural health systems, as well as small, publicly owned hospitals.

Staff members at Mary Greeley Medical Center in Ames, Iowa, said that Konza and federal officials told them their participation in the new program was mandatory. The hospital, which has long participated in NEISS, signed a new contract in April to share its ER records with Konza.

Yet the hospital is reevaluating its participation after being notified that the funds it received to participate in NEISS were “no longer available,” spokesperson Steve Sullivan said.

Several hospital executives, lawyers, and others have raised doubts about the CPSC’s claimed authority.

Harborview Medical Center spokesperson Susan Gregg said the Seattle hospital’s emergency room has “voluntarily submitted de-identified data for many years, but we are not obligated to report this information.”

In Boston, Mass General Brigham has declined to participate in the new program, with spokesperson Kelly Mitchell saying that “to protect patient privacy, we are unable to provide these medical records.”

Henry Ford Health in Detroit; St. Luke’s in Boise, Idaho; and Sanford Health based in Sioux Falls, South Dakota — which together handle over a million ER visits a year — are among the health systems that have been approached but not yet entered into an agreement with Konza, according to representatives. Several of the nation’s busiest hospital systems targeted for the program — including the Mayo Clinic in Minnesota, Yale New Haven Hospital in Connecticut, Nationwide Children’s Hospital and the Cleveland Clinic in Ohio, and Baylor Scott & White Health in Texas — declined to answer questions about whether they’re participating.

Hoehn-Saric, the agency’s former chairman, said he was surprised that the CPSC would insist that hospitals provide identifiable records from all emergency room visits.

“This idea that they can simply demand patient information from a hospital and that the hospital would provide it — I really don’t understand the basis for that,” he said.

Ñî¹óåú´«Ã½Ò•îl Health News is a national newsroom that produces in-depth journalism about health issues and is one of the core operating programs at KFF—an independent source of health policy research, polling, and journalism. Learn more about .

This article first appeared on Ñî¹óåú´«Ã½Ò•îl Health News and is republished here under a .

]]>
2262089
Trump’s Personnel Agency Says It Will Remove Some Identifying Info as It Sweeps Up Medical Records /insurance/trump-opm-federal-workers-medical-records-data-privacy-pseudonymize/ Wed, 22 Jul 2026 09:00:00 +0000 /?p=2263660 The Trump administration is forging ahead with a controversial plan to collect the medical records of millions of federal workers and retirees, as well as their family members.

The Office of Personnel Management posted last month that it will begin routinely collecting identifiable, personal health information on more than 8 million people — despite concerns from privacy advocates and Democrats, who have demanded the agency drop the plan. The notice will go into effect July 24, allowing OPM to begin its collection at any point afterward.

In reaction to privacy concerns raised by insurers and others, OPM now says the identities of enrollees will be “pseudonymized” — meaning names, addresses, and Social Security numbers will be removed — before the agency’s analysts review the massive new health datasets it will soon begin receiving.

Birth years of enrollees will be retained, and the agency’s “technical staff” will receive member IDs that it will scramble into different, unique numbers before releasing them to other staffers, according to the notice.

But the notice also specifies that OPM retains the right to reidentify the records.

Sixty-five insurance companies will be required to routinely send OPM detailed data — including names, addresses, doctor information, diagnoses, prescriptions filled, and payment details — on health care services paid through the Federal Employees Health Benefits and Postal Service Health Benefits programs.

In a change to its original proposal, first reported by Ñî¹óåú´«Ã½Ò•îl Health News, the agency says it also wants to peek at records kept by Medicare, the federally funded health insurance for older and disabled Americans, to examine claims from federal employees and retirees, and their families, who depend on both programs.

In its latest notice, OPM argues that the vast trove of data is necessary to ferret out fraud and overpayments in the FEHB and PSHB programs. Those programs cost roughly , with about $50 billion covered by the federal government and $30 billion funded by enrollees. The Trump administration has ramped up efforts, led by Vice President JD Vance, to curtail what it says is rampant fraud and misuse of publicly funded health benefits.

The effort still faces criticism that it doesn’t go far enough to protect the privacy of federal workers and their families.

“Clearly, this administration has not earned our trust with Americans’ sensitive data,” Sen. Mark Warner (D-Va.) said in an emailed statement to Ñî¹óåú´«Ã½Ò•îl Health News. “If OPM wants to work in good faith to reduce fraud, they should come to Congress, including to folks like me who are engaged on this issue and represent many federal workers and retirees and their families, and work to build consensus and trust before implementing these sweeping changes.”

The , posted in December, sparked concerns in part because it did not specify what the Trump administration planned to do with the sensitive health information it receives — and did not instruct insurers to redact identifying information.

OPM General Counsel Kurt Dykstra said the detailed records are critical to the administration’s mission of rooting out fraud and could help identify fraud perpetrated not only by medical providers but also by enrollees.

But when pressed for instances of workers, retirees, or their relatives committing such fraud, Dykstra only noted generally that healthcare fraud does occur.

The information could demonstrate “potential anomalies in usage patterns that could be related to the individual, but really also could be related to the provider, the treater, the clinic — whoever it is that’s actually providing the care,” Dykstra told Ñî¹óåú´«Ã½Ò•îl Health News in an interview.

Records deemed suspicious by OPM’s data analysts could then be referred to the agency’s Office of the Inspector General for further investigation, which could include “determining who’s involved and what the potential issues are, what the ramifications look like,” Dykstra said.

OPM’s plan to collect and analyze medical records has prompted unease among unions and federal workers, to mass firings and layoffs — in some cases, they say, driven by political retribution — since President Donald Trump took office.

Health privacy lawyers say, too, that while pseudonymizing workers’ details is a step in the right direction, it might not go far enough to protect their privacy.

OPM’s notice mostly complies with the Health Insurance Portability and Accountability Act, the federal law commonly called HIPAA that protects sensitive health data from being shared, said Matt Fisher, a health privacy lawyer. But he noted one exception: The member ID that insurers provide enrollees can be used to identify them.

“The described process arguably comes down to trusting internal controls in OPM to ensure that data is walled off as proposed,” Fisher said in an email. “The ideal would be for only truly de-identified information to be shared in the first place.”

Insurers regularly share information about claims with employers who offer health plans to employees, in efforts to control costs. But since employers themselves are not covered by HIPAA, large datasets are typically de-identified, meaning the insurers remove identifying information such as employees’ names or addresses, to comply with the law.

Employers, too, have been accused of using health information to target employees for dismissals. Most recently, a group of Meta employees filed a lawsuit of using artificial intelligence to target for layoffs those who had taken medical or family leave.

Pseudonymizing details such as names or addresses would go only so far to protect privacy, since medical conditions in particular can make it very easy to identify certain employees, said Joseph Lorenzo Hall, a technologist at the Center for Democracy & Technology, a nonprofit that advocates for data privacy.

“The richer the data, the more likely it is going to be identifying,” Hall said.

“In this case, you may be the only person in a region that has that particular kind of medical procedure, condition, or even prescription,” he said. “All of those things can be extremely identifying, even when you remove or obfuscate or pseudonymize direct identifiers.”

Most federal retirees decide to continue with FEHB plans and enroll in Medicare once they turn 65, which provides more comprehensive coverage and allows family members to remain enrolled in FEHB plans, said John Hatton, the staff vice president for policy and programs at the National Active and Retired Federal Employees Association.

OPM wants to analyze medical records for those dual enrollees as well. The agency is asking for all of their cost and service use records from the Centers for Medicare & Medicaid Services.

Still, Hatton said, OPM’s latest notice provides more details about how the agency says it will use the sensitive health information it receives and safeguard it.

“It’s a big improvement over the last notice, which was very lacking in detail and explanation for why they wanted all the medical claims data and how they’re going to protect the privacy of the data,” Hatton said.

“We’d be open to seeing even more security around the privacy of the data so there really is a clear wall,” he added.

Ñî¹óåú´«Ã½Ò•îl Health News is a national newsroom that produces in-depth journalism about health issues and is one of the core operating programs at KFF—an independent source of health policy research, polling, and journalism. Learn more about .

This article first appeared on Ñî¹óåú´«Ã½Ò•îl Health News and is republished here under a .

]]>
2263660
RFK Jr. Seeks To Peek at Americans’ Medical Records for Clues on Autism and Vaccines /mental-health/sharing-patients-medical-records-access-rfk-jr-project-link-autism-vaccine-injuries/ Thu, 04 Jun 2026 09:00:00 +0000 U.S. health secretary Robert F. Kennedy Jr. is pursuing federal government access to most Americans’ medical records, in a quest to research a link between vaccines and autism — a connection the medical establishment studied for decades and flatly rejects.

The Department of Health and Human Services is seeking data from little-known state systems that allow hospitals and clinics to exchange detailed, identifiable patient information, Ñî¹óåú´«Ã½Ò•îl Health News has learned.

In private meetings, some public health leaders have objected to giving Kennedy’s team access to such data, raising doubts that it’s legal or that the information would even be useful.

They have also expressed concerns about allowing the federal government to peer into the minutiae of Americans’ medical records, which could mean viewing anything from doctors’ notes to prescription history. HHS has offered no insight into how it will protect or handle the personal health information it obtains.

But Kennedy told Ñî¹óåú´«Ã½Ò•îl Health News that medical records are key to investigating the cause of autism, vaccine safety, and chronic diseases. And millions of dollars in grant money has poured into a Nebraska nonprofit that has assisted Kennedy’s effort, according to state records.

He and his advisers have been frustrated that federal access to Americans’ medical records has been limited.

“We need a good health record system, and one of the things that really surprised me most when I came into office is that there is — that the systems are broken,” Kennedy said in a May interview. “We’ve had to go to the states and, luckily, we’ve got a lot of cooperation from the states, but we now have databases together that we can actually do the studies on. Those studies are in motion.”

HHS has not publicly announced any new projects involving medical records and autism or vaccine research. Kennedy faced blowback last year when he proposed compiling the medical records of people with autism to create a federal disease registry — which health department officials .

But Kennedy said in May, “We have a whole pipeline of studies that will be done over the next year.”

Though the White House has steered Kennedy away from further changes to U.S. vaccine policy ahead of November’s crucial midterm elections, President Donald Trump has regularly echoed Kennedy’s doubts about vaccine safety and last week signed an executive order calling for the U.S. to reduce the number of vaccines recommended for children.

Kennedy’s political appointees and allies — including William “Reyn” Archer III, a former Texas health official and whom Kennedy hired as a senior adviser — have led the initiative for the health department to collect and examine medical records.

A man sits at a table with a placard with his name on it. Other faces are seen blurred in the foreground in front of him.
William “Reyn” Archer III, a former Texas health commissioner, attends the Advisory Committee on Immunization Practices meeting at Centers for Disease Control and Prevention headquarters on Sept. 20. (Mary Conlon/AP)

Federal officials met with leaders of the state-run health information exchange systems several times over the past year and asked how the personal medical records they maintain could be used for vaccine research, according to seven people who participated in the discussions or were familiar with them.

Craig Behm, who runs the Maryland health information exchange, said Kennedy’s team asked about how the vast trove of medical records they store from hospitals and health systems could be used to study vaccines.

“If this administration wants to conduct research on the effectiveness of vaccines, are you saying you all can help us conduct that research?” Behm recalled being asked by a top official at HHS’ health information technology office.

Last June, Behm and leaders of other state exchanges met with Kennedy’s top advisers to discuss sharing more medical data with federal agencies. The state organizations followed up with a pitch in October for a new surveillance system that would give the federal health department “real-time, 24-hour data feeds on opioid and chronic disease trends” within a year, according to a presentation reviewed by Ñî¹óåú´«Ã½Ò•îl Health News. Under the proposal, HHS would get data from 90% of the population’s medical records by 2028.

Administration officials regularly asked during the meetings how the records could be used to monitor vaccine safety. Kennedy has rejected the federal government’s current vaccine-monitoring systems; decades of research has shown immunizations are safe and effective for most people.

“Vaccine safety, or whatever words you want to use, has come up pretty consistently in those conversations,” said John Kansky, CEO of the Indiana Health Information Exchange.

Kansky sees the potential value of sharing information from the exchanges for public health but is worried about the focus on vaccines: “It’s like, oh man, I wish you would have picked something that pushed fewer buttons for people.”

A System To Monitor Chronic Disease

Nearly every state has at least one health information exchange — often regulated by state laws and run by private companies or nonprofits — that enables hospitals and health systems to immediately share patients’ medical records with one another. The systems allow doctors and nurses to quickly pull up nearly anyone’s medical history and records at emergency rooms or share after-visit summaries and notes with patients’ primary care providers, for example.

In certain circumstances — most often dealing with cases of infectious diseases such as measles or flu — the exchanges notify public health authorities, like the state health department or the Centers for Disease Control and Prevention. Using the exchanges for broader public health purposes is not an unusual idea in itself. But it can present privacy, legal, and ethical complications, health officials say.

In the end, Behm said his organization in Maryland declined to share more data with the federal government for vaccine research, noting that sharing medical records for that purpose would require a rash of approvals from hospitals, state political leaders, and research boards. Any new data-sharing agreement should also have a clear, detailed framework outlining what would be shared and with whom, he added.

“A number of us said, ‘We can’t do anything our agreements don’t allow us to do, so no,’” Behm said. Indeed, most health information exchanges have contractual restrictions on who can access clinical data.

Kansky said Indiana is still weighing whether to provide additional data for Kennedy’s project, and that nothing has yet been shared.

HHS spokesperson Emily Hilliard did not answer questions about how many states are participating in Kennedy’s project, what new data the agency is collecting, how much the federal government is spending on the initiative, how it is protecting patient privacy, or who has access to the data.

“HHS is strengthening public health surveillance and modernizing data systems to better understand and combat the childhood chronic disease epidemic as part of Secretary Kennedy’s Make America Healthy Again agenda,” Hilliard said in an emailed statement. “Americans deserve robust systems to monitor the drivers of chronic illness.”

Kennedy has asserted, without evidence, that vaccines can cause chronic illness.

A Kennedy Partner in Nebraska

At least one state has been cooperative.

The former leader of Nebraska’s state health information exchange has led the effort to share data from medical records with the federal government.

Jaime Bland, former CEO of CyncHealth — the Nebraska health information exchange used by in the state — said several states are looking to “open up channels” to provide more analysis to Kennedy’s team.

“They’re looking at the data differently and providing some insights back to the CDC,” Bland told Ñî¹óåú´«Ã½Ò•îl Health News.

Bland was among a group who proposed that CyncHealth would help kick off the initiative, according to a 43-slide PowerPoint presented to federal officials during an October meeting.

CyncHealth and other state health information exchanges would “ingest data from hospitals, clinics, laboratories, pharmacies, payers, and social services agencies,” then “link claims and clinical records through a master patient index.”

Data from the exchanges “will be deidentified where appropriate,” according to one slide.

The federal government would pay the exchanges for furnishing the records, according to the proposal: $3 a person, annually.

Officials would “frame publicly that this is not a new database, but a federated trust model that delivers real-time data for all HHS missions,” the presentation reads.

After the meeting, Nebraska’s health department was awarded a large grant from the CDC, and CyncHealth in turn got millions of dollars from the state.

On Dec. 19, the CDC announced new funding under its , which sends money to state and local health departments for lab work, health information enhancements, and solutions for outbreaks.

Nebraska’s state health department was awarded $18.7 million — the most of any state last year, though Nebraska is the 38th most populous state. By comparison, Texas received $9.2 million, and California got $10.8 million.

CyncHealth was then awarded three contracts totaling $13.6 million from the state health department just weeks later, on Jan. 9 and Jan. 16, according to a publicly accessible database of state contracts.

Grace McNamara, a spokesperson for CyncHealth, said it retained $2.4 million of the funding for Kennedy’s project; the remaining money was distributed to “other participating states and various vendor organizations for implementation support.”

A former CDC official who was aware of the transaction, but not authorized to speak publicly about it, confirmed the money was intended for CyncHealth to supply data for Kennedy’s initiative to look at vaccines and autism. McNamara said that the “work is focused on improving outcomes related to acute and chronic illnesses.”

“The referenced project is not research, but rather a proof-of-concept project on how health information exchange and public health can work together to improve health outcomes and is not specific to autism,” she said in an emailed statement.

McNamara did not answer questions about what type of medical data is being provided to the federal health department or whether patients’ identifying information is removed.

Bland left her post at CyncHealth — where she was paid nearly — in December. She was named in April as the chief data strategist for the MAHA Institute — a think tank founded by allies of Kennedy and Trump to advance their Make America Healthy Again movement.

Bland agreed with Kennedy that data from state health information exchanges could provide more insight into autism’s causes or vaccine injuries.

“The data is so fragmented, so modeled when it comes to population health and public health, that we lose sight of the individual stories,” Bland said. She told a story she had heard about a woman who had a seizure after receiving the HPV vaccine.

“You know, the vaccine is safe — it absolutely is — but it wasn’t safe for her,” Bland said. “As public health officials, we say the vaccine is safe. But there are cases where it is not.”

Daniel Jernigan, a former top CDC official who left the agency last summer, said he tried to point Kennedy to data that would help the health secretary study vaccine safety and autism.

Dan Jernigan shakes the hand of a man off screen outside of the CDC headquarters.
Former CDC official Daniel Jernigan greets a supporter after resigning from the agency on Aug. 28. (Elijah Nouvelage/Getty Images)

After 31 years at the CDC overseeing public health surveillance, emerging infectious diseases, and the influenza divisions, Jernigan thought the solution was simple. The secretary could work with researchers to obtain huge databases pulled from health systems nationwide and maintained by major electronic health records companies.

Those databases are deidentified, meaning they don’t include patient names or other information that can identify individuals. Jernigan said Kennedy didn’t seem interested.

Instead, as The New York Times first reported, the health secretary dispatched two top advisers — Archer and Hannah Anderson, his former deputy chief of staff — to the CDC’s headquarters in Atlanta last July to download millions of identifiable patient records directly from the Vaccine Safety Datalink, the system the health agency uses to investigate complications from vaccines. The records, though, were decades old.

Jernigan said the federal government has limited legal authority to access medical records from state health information exchanges. In any case, examining those records may provide a view of a person’s medical history that will not necessarily produce answers to Kennedy’s questions about vaccines and autism.

“If they’re just using the electronic health record data, there are limits to that,” Jernigan said. “If they’re only looking at electronic health record data, all you’re going to get is what was captured in the encounter. It’s not going to be very satisfying.”

Ñî¹óåú´«Ã½Ò•îl Health News data reporter Maia Rosenfeld contributed to this article.

Ñî¹óåú´«Ã½Ò•îl Health News is a national newsroom that produces in-depth journalism about health issues and is one of the core operating programs at KFF—an independent source of health policy research, polling, and journalism. Learn more about .

This article first appeared on Ñî¹óåú´«Ã½Ò•îl Health News and is republished here under a .

]]>
2245892
Democrats Demand Trump Administration Halt Plan To Collect Federal Workers’ Health Data /health-industry/opm-federal-workers-health-records-hipaa-democratic-letters/ Tue, 21 Apr 2026 09:00:00 +0000 /?p=2228955 Democratic lawmakers are demanding that the Trump administration halt plans to collect sensitive medical records for millions of federal workers and retirees, as well as their family members.

The Office of Personnel Management 65 insurance companies to provide monthly reports with detailed medical and pharmaceutical claims data of more than 8 million people enrolled in federal health plans, Ñî¹óåú´«Ã½Ò•îl Health News reported earlier this month. The request, which could dramatically expand the personally identifiable medical information OPM can access, alarmed health ethicists, insurance company executives, and privacy advocates.

Now, OPM Director Scott Kupor has two letters on his desk — one from 16 U.S. senators and another led by Rep. Robert Garcia, the top Democrat on the House Oversight Committee — asking him to drop the agency’s proposal.

“The collection of broad, personally identifiable data regarding medical care and treatment raises concerns that OPM could target certain federal employees seeking vital health care services that the Administration disagrees with on political grounds,” the Democratic House members , citing Ñî¹óåú´«Ã½Ò•îl Health News.

The letters from congressional Democrats alone are unlikely to reverse OPM’s plans. Republicans — who control Congress and, ultimately, any oversight activities — have not weighed in on OPM’s notice.

OPM did not immediately respond to a request for comment on the letters. The agency, which said in its notice that it will use the data for oversight and to manage the federal health plans, has not publicly addressed written concerns about its proposal.

The notice, posted and sent to insurers in December, states that insurers are legally permitted to disclose “protected health information” to OPM and does not provide instructions to redact identifying information, such as names or diagnoses, from the claims.

That data could be used to implement cost-saving measures, health policy experts told Ñî¹óåú´«Ã½Ò•îl Health News earlier this month. But it would also give the Trump administration — which has laid off or fired tens of thousands of federal workers — access to a vast trove of personal information.

In the letters, Democratic lawmakers lay out a number of concerns about potential consequences of OPM’s obtaining detailed medical claims for millions of federal workers.

The — led by Adam Schiff of California and Mark Warner of Virginia — argues that OPM is not equipped to safeguard such sensitive data and that the administration could share the records across government agencies, as it has done with personal information on millions of Medicaid enrollees.

They also assert that the agency does not have a legal right to the data and that insurers’ sharing the information with OPM would “violate the core principles of the Health Insurance Portability and Accountability Act.” HIPAA requires certain organizations that maintain identifiable health information — such as hospitals and insurers — to protect it from being disclosed without patient consent. The proposal, the senators warn, threatens patients’ relationships with their clinicians, especially “sensitive disclosures regarding mental health, chronic illness, or other deeply personal conditions.”

“For these reasons, we strongly urge you to cease any further consideration of this proposal,” states the letter, which was sent to Kupor on April 19.

The American Federation of Government Employees, the largest union for federal employees, to Ñî¹óåú´«Ã½Ò•îl Health News’ reporting. The union noted in a statement from its national president, Everett Kelley, that OPM’s proposal “comes in the context of coordinated attacks on federal employees and repeated stretching of the legal boundaries for sharing sensitive personal data across government agencies.

“The question of what this administration intends to do with eight million Americans’ most private health information is not academic,” the AFGE statement read. “It is urgent.”

In an emailed statement, Kelley applauded the congressional letters.

“We are pleased that Democratic lawmakers on the Hill are just as outraged as we are over this administration’s blatant attempt to breach the privacy of millions of Americans across the country,” Kelley wrote. “We share their concerns regarding potential misuse of the information to continue illegally targeting workers and their demand for OPM to withdraw this proposal.”

Ñî¹óåú´«Ã½Ò•îl Health News is a national newsroom that produces in-depth journalism about health issues and is one of the core operating programs at KFF—an independent source of health policy research, polling, and journalism. Learn more about .

This article first appeared on Ñî¹óåú´«Ã½Ò•îl Health News and is republished here under a .

]]>
2228955