Skip to main content
FEHBARAgency supplement

Federal Employees Health Benefits

The FEHB acquisition rules — for federal employee health-insurance carriers.

Last reviewedJune 9, 2026Version v1

Cybersecurity rules in this supplement

The FEHB acquisition rules (FEHBAR) do not add a general cybersecurity-safeguarding clause. Their information rule is confidentiality-focused:

FEHBAR Subpart 1624.1 — Protection of Individual Privacy with clause 1652.224-70 — Confidentiality of Records. Require carriers to keep enrollee records confidential under the Privacy Act framework.

Because FEHB carriers handle health data, HIPAA and other health-privacy laws also apply; for general cybersecurity, the FAR baseline governs.

In plain terms

The FEHB rules require carriers to keep enrollee health records confidential, but they don't add a dedicated cyber clause. HIPAA covers health-data security, and the FAR baseline sets the general cyber floor.

Who it applies to

FEHB health-insurance carriers and their subcontractors handling enrollee records.

What it requires

Follow the FAR baseline, keep enrollee records confidential under the FEHBAR clause, and meet HIPAA obligations where protected health information is involved.

Why it matters

Enrollee health data is sensitive and HIPAA-covered, so confidentiality and health-privacy compliance matter even without a FEHBAR-specific cyber clause.

Citation

Federal Employees Health Benefits Acquisition Regulation (FEHBAR), codified at 48 C.F.R. Chapter 16.