Cybersecurity rules in this supplement
The FEHB acquisition rules (FEHBAR) do not add a general cybersecurity-safeguarding clause. Their information rule is confidentiality-focused:
FEHBAR Subpart 1624.1 — Protection of Individual Privacy with clause 1652.224-70 — Confidentiality of Records. Require carriers to keep enrollee records confidential under the Privacy Act framework.
Because FEHB carriers handle health data, HIPAA and other health-privacy laws also apply; for general cybersecurity, the FAR baseline governs.
In plain terms
The FEHB rules require carriers to keep enrollee health records confidential, but they don't add a dedicated cyber clause. HIPAA covers health-data security, and the FAR baseline sets the general cyber floor.
Who it applies to
FEHB health-insurance carriers and their subcontractors handling enrollee records.
What it requires
Follow the FAR baseline, keep enrollee records confidential under the FEHBAR clause, and meet HIPAA obligations where protected health information is involved.
Why it matters
Enrollee health data is sensitive and HIPAA-covered, so confidentiality and health-privacy compliance matter even without a FEHBAR-specific cyber clause.
Citation
Federal Employees Health Benefits Acquisition Regulation (FEHBAR), codified at 48 C.F.R. Chapter 16.