A new policy being pushed by Big Pharma giants could endanger Americans’ medical privacy, opening the door for hackers to access sensitive records.
The push is part of an effort by drug companies to limit the financial impact of a federal drug discount program on their profits, but critics warn it could expose sensitive patient health data, including information tied to hot-button culture war issues that draw scrutiny from the Right and the far Left alike.
Recommended Stories
The drugmakers are Eli Lilly and Novo Nordisk. Both announced this year that they will require pharmacies to submit claims-level patient data to receive drug discounts under 340B, a federal law that requires drug companies that sell to Medicare and Medicaid at taxpayer expense to offer discounts on those same drugs to pharmacies affiliated with hospitals serving high proportions of poorer Americans. Many of those hospitals and pharmacies sit in conservative, rural areas.
The change may sound harmless, but the claims-level data both companies are demanding could force disclosure of a wide range of specific medical events. Some is less politically charged, such as whether a patient was diagnosed with or treated for cancer or heart disease, or suffered depression or anxiety. But it could also reveal whether a patient received certain vaccines, or didn’t, along with infertility or hormone treatment, or a miscarriage requiring drugs normally used to perform abortions. Claims-level data can also expose treatment for post-traumatic stress disorder, a major issue for veterans, along with drug addiction and HIV treatment, both significant in parts of red America hit hard by the opioid crisis.
Lilly and Nordisk want healthcare providers to upload patient information to a third-party website, arguing the requirement is necessary to stop hospitals from abusing 340B discounts. Purchases within the program exploded from $16.2 billion in 2016 to $66.3 billion in 2024.
The companies claim no protected health information will be collected. But the new process requires 340B IDs, drug types, and prescription numbers, data that has been compared to digital fingerprints. Providers are already bound by extensive privacy mandates under privacy laws. Requirements for pharmaceutical companies handling this data remain far less defined.
The changes come as privacy concerns are rising nationwide, from Flock camera surveillance to fears over health data in the age of artificial intelligence. A 2024 United States of Care poll found 53% of voters want Congress to oversee the protection of patients’ privacy and data. This isn’t a fringe worry limited to civil libertarians. It’s a mainstream concern that cuts across the political spectrum, and one that should alarm anyone whose medical history includes a vaccination record, a fertility treatment, or a mental health diagnosis.
Cybersecurity adds another layer of risk. The 2024 Change Healthcare cyberattack affected an estimated 192.7 million people. Second Sight Solutions, hired to host 340B data management services, is owned by Berkeley Research Group, which suffered a massive ransomware attack last year that exposed the data of more than 100,000 Americans, including active-duty military members, their families, and clergy sex abuse survivors. No 340B data were taken in that breach, but it’s a warning sign for what this new system could invite.
One pharmacist described the data Lilly and Nordisk are seeking as essential to “seamless healthcare delivery.” It’s easy to see how that same data would be a prime target if hackers gained access.
Hospital groups opposing the plans have largely sidestepped the privacy question in their comments, focusing instead on administrative burden. Novant Health’s Matthew Webber said hospitals will need to outsource new reporting workflows, and the American Hospital Association warned the policy will raise costs and undermine access to care for safety-net providers. Rural hospitals, which lean on 340B revenue to offset Medicaid and Medicare shortfalls, could be hit hardest. Nearly 39% of U.S. hospitals lost money in 2023, according to Trilliant Health, and Medicaid reforms, along with declining ACA enrollment, are expected to add further strain.
The AHA has proposed a government-run clearinghouse to handle 340B claims instead, but that raises its own red flags. The Office of Personnel Management once let hackers access the data of 22.1 million people, a reminder that centralizing sensitive health records under federal control creates fresh vulnerabilities of its own.
With the national debt at $40 trillion and privacy concerns only intensifying, Lilly and Nordisk’s new policy looks like a bridge too far. If drugmakers want to close the loopholes they’re worried about, they need a plan that doesn’t put every American’s medical history, from vaccine records to addiction treatment, within reach of a third-party database and the hackers who might come looking for it.
Taylor Millard (@TaylorMillard) is a freelance journalist who lives in Virginia.