Why It Matters
The Consumer Product Safety Commission is demanding that major hospital systems hand over detailed emergency room records containing patients’ names, addresses, and diagnoses to a private contractor, raising questions about federal authority, patient privacy protections, and whether proper legal procedures were followed before collecting sensitive health data on millions of Americans.
What Happened
The CPSC began pressing hospital executives this year to share personally identifiable medical records with Konza Health, a Kansas-based organization that operates the state’s health data exchange. According to internal agency communications, CPSC officials told hospital executives that participation was “mandatory” or “required,” with the goal of obtaining detailed records from emergency room visits covering injuries ranging from broken bones to vaccine reactions to suicide attempts.
The agency made the program public on July 21 following inquiries from health journalism outlets. CPSC awarded Konza Health a five-year contract valued at up to $15.9 million last fall, and the agency now aims to have at least 100 hospitals begin sending detailed patient records by year’s end.
Hospital lawyers and industry experts have raised concerns about the CPSC’s legal authority to collect such data, the company’s ability to safeguard sensitive information, and whether the agency followed required legal procedures. Some hospital executives worried the effort could violate federal privacy law. CPSC officials have suggested that hospitals declining to share data could face penalties under “information blocking” regulations.
A CPSC spokesperson acknowledged the concerns, stating that “giving a private entity access to a sweeping collection of data will introduce risks to patient privacy,” and describing the arrangement as “troubling.”
By the Numbers
At least 100 hospitals targeted to begin sending records by end of 2026
$15.9 million — five-year contract value with Konza Health
Nearly 1 in 5 career staffers left CPSC in first 16 months of current administration
Dozens of emergency rooms — already participate in CPSC’s voluntary National Electronic Injury Surveillance System (NEISS)
Legal and Privacy Questions
Federal law requires the CPSC to provide public notice and allow a comment period before requesting information from 10 or more entities. The agency has not yet notified the public as the statute requires. A Case Western Reserve University professor of health law said that “if this company really is collecting identifiable information, that is worrisome for patients.”
The CPSC’s existing injury surveillance program, NEISS, already involves dozens of hospitals but operates on a voluntary basis and strips away patient identifiable information before data is submitted. The new effort marks a significant departure by seeking personally identifiable health records directly.
Zoom Out
The CPSC has operated without a governing board since President Trump removed three Democratic board members earlier in his term. Staff departures have accelerated within the agency, with nearly one in five career employees leaving during the first 16 months of the current administration. These staffing and governance changes have occurred as the agency pursues expanded data collection authority and partners with private contractors to access health information on a scale previously handled only through voluntary, anonymized reporting systems.
What’s Next
The CPSC has not announced whether it will comply with the federal notice-and-comment requirement before proceeding. Hospital systems continue to assess whether to participate in the data-sharing arrangement and whether the demands align with patient privacy obligations under federal law. The agency’s intentions regarding enforcement actions against hospitals that decline to participate remain unclear.