Dear Commissioners,
I am writing on behalf of Bend Privacy Alliance regarding Items 3 and 4 on the July 29 consent agenda: the proposed awards for Third-Party Administrator and Pharmacy Benefits Management services.
These vendors will likely handle highly sensitive medical, prescription, claims, eligibility, and dependent information belonging to County employees and their families. However, the agenda packet does not include the proposed contracts, business associate agreements, statements of work, data-security requirements, retention provisions, subcontractor disclosures, breach-notification terms, or restrictions on secondary use of the information.
Because the award notices state that the contracts may be processed administratively if no protest is filed by 5:00 PM on Wednesday, August 5, 2026, this may be the Board’s final opportunity to address these issues publicly before execution.
We respectfully ask that Items 3 and 4 be pulled from the consent agenda so staff can address the following questions:
- What categories of employee and dependent information will each vendor receive?
- Do the contracts prohibit sale, advertising, unrelated analytics, commercial profiling, product development, and use of County data to train artificial-intelligence systems?
- May either vendor retain or use aggregated or "de-identified" claims or prescription information for purposes unrelated to administering the County plan?
- Which subcontractors, cloud providers, analytics companies, pharmacies, or other downstream entities may receive the information?
- What retention and deletion requirements apply during and after the contracts?
- What encryption, access-control, logging, independent auditing, and incident-response requirements are mandatory?
- How quickly must the County be notified of a suspected or confirmed breach?
- Does the County retain the right to audit compliance, investigate incidents, and verify deletion?
- How were privacy and cybersecurity evaluated during vendor selection?
We also noticed that the Item 3 award notice is labeled "Contract for Pharmacy Benefits Manager Services," even though Item 3 concerns Third-Party Administrator services and identifies Moda Health as the selected vendor. We ask that the County clarify and correct this apparent labeling error before approval.
Bend Privacy Alliance is not alleging misconduct by either selected vendor. Our concern is that the public packet does not provide enough information to determine whether appropriate safeguards have been incorporated into contracts involving some of the County’s most sensitive personal information.
At minimum, we request that the County publish the proposed contracts and applicable data-protection provisions before they are finalized.
Thank you for your consideration and for your work to protect County employees and their families.
Sincerely,
Jonathan Westmoreland
Bend Privacy Alliance
Leave a Reply