
Congress wants employers and unions to finally see where their health care dollars go. A last-minute change could let insurers and PBMs keep some of the most important receipts hidden.
For years, employers and other plan sponsors, such as unions, have been fighting to get the one thing they need to better control their own health care spending: the claims data their insurers/third-party administrators and pharmacy benefit managers generate on their behalf but routinely refuse to hand over. A bill working its way through Congress – the Patients Deserve Price Tags Act (PDPTA) – would finally force that data into the open. The bill is also a real test case for a simple idea: that transparency itself can help drive down unnecessary spending, lower overall health care costs, benefit patients, and strip middlemen of the leverage they use to pocket money they were never entitled to.
The fiscal case backs this up. A recent independent analysis by economists Daniel Arnold and Christopher Whaley estimates the bill would generate roughly $122 billion in additional federal revenue over 2026–2035, with a plausible range of $25 billion to $270 billion, by driving down employer plan spending in ways that eventually show up as higher taxable wages. That’s the standard logic the Congressional Budget Office uses for scoring changes in employer-sponsored insurance. Even at the low end of that wide range, it’s a meaningful number.
The usefulness of the bill, however, would be significantly undermined by a single sentence, added to Section 7 just before it was voted out of the Senate Health, Education, Labor and Pensions (HELP) Committee, that could gut the very accountability mechanism the bill is built around.
First, because this is an area where there is a lot of confusion, here’s some information and context. A plan sponsor, as noted above, is typically an employer or union that offers subsidized health benefits to workers and their families. In that role, the employers and unions are the actual “insurers.” They hire companies we typically call insurers (like Cigna, Aetna, UnitedHealthcare or a Blue Cross plan) to administer those health benefits. In that role, those companies are third-party administrators (TPAs) who use the employers’ and unions’ – and workers’ – money to pay claims, create provider networks, serve as gatekeepers to care and handle other administrative responsibilities, like approving and denying coverage for care (called utilization management or prior authorization). Employers and unions pay those TPAs huge fees to do that work.
So huge, in fact, that at Cigna, where I used to work, approximately 80% or more of revenues from the company’s U.S. commercial health insurance operations came from administrative-services-only arrangements. Even though workers have insurance cards in their wallets with the logo of a company like Cigna or Aetna, which we think of as an insurer, the workers’ employer or union is, in fact, the insurer.
Section 7 of the bill gives employer and union health plans the right to access their own complete claims data — from the insurers, third-party administrators (TPAs), and pharmacy benefit managers (PBMs) that plan sponsors hire to handle those administrative duties, and the plan sponsors give the TPAs access to the money in the bank accounts the plan sponsors set up to cover the cost of their workers’ health care benefits. Those TPAs and PBMs (which are typically owned by the TPAs) are the middlemen that are involved in every dollar a plan sponsor spends. They set network prices, retain rebates from pharmaceutical companies (kickbacks, in plainer, more precise language) and generally control the only detailed record of where a plan sponsor’s money actually went. When employers and unions can’t see that record – and in today’s world they usually do not, even though we’re talking about their own money – they can’t audit it, and audits are the only way plan sponsors ever catch things like phantom billing, upcoding, duplicate charges or the disparities in denials and prior-authorization patterns that Congress has spent years scrutinizing.
Section 7’s whole purpose is to let the people paying the bills finally be able to trace where their money goes.
The new language in the Senate bill just before it was voted out of the HELP Committee says that, “A covered service provider would not have to disclose data that could ‘reasonably identify’ a participant or beneficiary, as defined under HIPAA’s individually identifiable health information standard.”
On its face, that sounds like ordinary patient-privacy boilerplate, but it is much more than that. HIPAA already has a detailed, well-established process for exactly this situation — dealing with a health plan’s right to receive identifiable claims data for plan administration. That process encompasses two well-defined de-identification methods – the 18-identifier “Safe Harbor” standard, and “expert determination” – for when identifiability genuinely needs to be limited.
The newly inserted language doesn’t invoke either of those. To the delight of my former employers in the health insurance business, it creates a new, undefined standard — “could reasonably identify” — with no cross-reference to how HIPAA actually determines that, and no appeals process if a plan sponsor disagrees. And it hands the decision to the very parties Section 7 exists to hold accountable. If that language stays in the bill, the insurer, TPA, or PBM would get to decide, on its own, what counts as identifiable enough to withhold from plan sponsors. Keep in mind that the TPAs and PBMs, which are constantly trying to maximize their revenues, by their very nature have access to identifiable data on every insured American.
De-identification of that data before it is shared with plan sponsors doesn’t just strip names and Social Security numbers. Done under a vague, self-certified standard, it can also strip exact service dates, zip codes, and the member-level identifiers that let an employer or union sponsored health plan connect one claim to another. Those are precisely the fields that let a plan sponsor piece together a pattern.
Here’s a hypothetical example of how PDPTA would enable employers to get a better handle on how their TPAs/PBMs are using their money to pay claims – and how the inserted language would stymie their ability to do so:
Suppose an employer plan noticed it had been billed for six services in a single week for one patient from one provider. Because it could see the clustered service dates, the plan could investigate, discover the services had never been performed, report the provider for false billing, and recover the money. But strip out exact dates — which the new language would allow — and that same claim would just look like six services spread out over time. The fraud would likely go uncaught, and the health plan (which means, ultimately, workers’ wages and other compensation) would eat the loss.
The same missing fields also hide denial-rate disparities and turnaround-time patterns — the exact behavior lawmakers keep asking about in prior-authorization hearings. And they would block plan sponsors from recovering overcharges they can no longer prove occurred.
Here’s something else to keep in mind: PBMs and insurers already sell claims-level data to drug manufacturers, data brokers, and analytics firms for their own commercial gain. The inserted language would let them keep doing that while blocking the employer or union that actually paid for the data from ever seeing it themselves.
Some of the lawmakers who care most about getting this right have raised a concern that deserves to be taken seriously, hence the newly added language. They don’t want employers gaining routine access to their own employees’ identifiable medical records. That’s not a paranoid fear. An employer that can see an employee receiving mental health treatment, fertility care or substance-use treatment has information that, mishandled, could influence a promotion, a layoff list or a manager’s private judgment about someone, even where no law technically permits that use.
That concern is exactly why HIPAA built a specific structure for it, back when Congress first grappled with this same problem in the 1990s. Think of it as a locked door inside an employer’s own building. When a company sponsors a health plan for its workers, HIPAA doesn’t let that identifiable medical data just flow into the regular HR filing system where a manager could stumble across it. Instead, the law requires the employer to designate a small, specific group of people – usually benefits staff, auditors or a third party working on the plan’s behalf – who are allowed through that locked door to see identifiable claims data, but only to do plan-administration work like trying to ensure that claims are paid correctly by TPAs and PBMs and checking for fraud. Everyone else at the company – HR generalists, supervisors, anyone who could use the information in a hiring, firing or promotion decision – stays on the other side of the door. The employer has to sign a formal certification promising to keep that separation in place, and using the data for an employment decision is exactly the kind of violation HIPAA’s firewall exists to catch. And violating HIPAA can be very costly: fines of $50-$250,000 per offense and up to 10 years in jail. That is a very real disincentive to mishandle the data.
That’s the tool already built for the harm some lawmakers say they have concerns about. It doesn’t block identifiable data from ever reaching the plan; it controls who inside the plan gets to see it and what they’re allowed to do with it.
The Section 7 carve-out language inserted in the bill doesn’t touch that door at all. It does something completely different: It lets the TPA, PBM or insurer decide, on its own, that a given piece of data simply won’t go through the door in the first place – not to the walled-off auditors – not to anyone – no matter how carefully separated they are from HR. That’s not tightening the firewall that some lawmakers are worried about breaching. It’s blocking the room entirely, including the auditors it was built to let in.
Here’s what should trouble anyone who takes the privacy concern seriously: The same companies that would get to make that call are, separately, in the business of selling similar claims data to outside parties, including data brokers, drug manufacturers and marketing analytics firms, under HIPAA’s “de-identified” label. Privacy researchers have spent years documenting how easily that kind of de-identified data can be re-identified, especially once it’s cross-matched against other data sets a broker already holds. In other words, the industry treats “identifiable enough to protect from a plan’s own fiduciary auditors” as an easy bar to clear, while treating “de-identified enough to sell for profit” as an even easier one. That’s not privacy protection with a consistent standard. That’s a standard that moves depending on who’s asking and who profits.
If the goal is protecting employees from having their sensitive health information misused – and it should be – the fix is to reinforce the locked-door system Congress already built: stronger certification requirements, even more severe penalties if an employer ever uses plan data in an employment decision, and access limited strictly to the walled-off audit function. That protects workers without stripping Section 7 of its ability to catch fraud. A vague, vendor-administered “reasonably identify” standard doesn’t strengthen that door. It just lets the vendor decide who never gets a key.
The good news is that PDPTA is moving through Congress. On the Senate side, the HELP Committee approved it on a bipartisan basis in late July. The lead sponsors – Roger Marshall (R-Kansas) and John Hickenlooper (D-Colorado) – were joined by Senators Chuck Grassley and Joni Ernst of Iowa and Cynthia Lummis of Wyoming, all Republicans, and Democrats Tammy Baldwin of Wisconsin, Cory Booker of New Jersey, Elizabeth Warren of Massachusetts and John Fetterman of Pennsylvania. That’s the kind of bipartisan coalition that rarely comes together on health care and even more rarely survives a full committee markup intact.
House versions of the Senate bill also have strong bipartisan support and are working their way through three committees (Energy and Commerce, Education and Workforce, and Ways and Means) — reflecting how many parts of federal law it touches.
With a bill this far along, this close to bipartisan agreement, and this close to the end of the current Congress, the pressure to move fast is real. That’s exactly why the Section 7 carve-out needs fixing now, while it’s still open for amendment, rather than after passage when it would take an entirely new bill to undo it. That clearly is not the intention of the bill’s many sponsors.
The transparency goal of the bill is sound, the projected fiscal upside is real even under conservative assumptions, and Section 7’s data-access right is exactly the kind of tool plan sponsors need.
Companies like the ones I used to work for undoubtedly were happy to see the new language inserted in the bill, and I’m hearing evidence that they’re working behind the scenes to keep it in the bill by creating the false narrative that employers and unions want this data primarily to learn more about their workers’ health. That simply doesn’t hold up. For one thing, as I’ve explained, HIPAA is clear on how employers can use the data and what happens if they violate existing law. But it is important to keep in mind that federal law also now makes it abundantly clear that plan sponsors are fiduciaries of workers’ money. They can be sued – and some are being sued – for not fulfilling their fiduciary responsibility under the law. And plan sponsors need data they all too often cannot get from their TPAs and PBMs to meet the law’s requirements.
I’ve written before about how often plan sponsors that sue their own TPAs and PBMs to get the data they need in order to have any assurance that they are not being double billed or defrauded in other ways get bogged down for the simple reason that they can’t get at their own claims data in a form they can actually audit. Section 7, done right, is a legislative fix for that problem. But “done right” requires closing this loophole before the bill moves further. At minimum, that means:
- Cross-referencing HIPAA’s existing Safe Harbor or expert-determination standards instead of inventing a new, undefined one;
- Requiring the covered entity to justify any withheld field against that established standard, rather than self-certifying; and
- Giving plans a way to challenge a withholding decision, instead of leaving the provider as sole judge.
One sentence, fixed, would let PDPTA keep its promise. Left as recently changed, it lets the middlemen write themselves an exemption from the very oversight the bill is meant to create.

