Get all your news in one place.
100's of premium titles.
One app.
Start reading
Medical Daily
Medical Daily
Cole Mercer

A Federal Product Safety Agency Is Asking Hospitals for Patient Names Its Own Manual Tells Them to Leave Out

The Consumer Product Safety Commission has spent decades telling hospitals a simple thing about injury reporting: leave the patient's identity out of it. The agency's own 214-page coding manual instructs hospitals not to include identifiable information "such as names, birthdates, or addresses" when reporting cases, and reserves identifiers for the follow-up investigations that account for fewer than one percent of reports.

Its new surveillance program asks for the opposite. According to documents and emails obtained by KFF Health News and published on July 27, a CPSC official has insisted that participating hospitals provide identifiable information for all emergency room patients, including names, addresses and diagnoses, to a private contractor called Konza Health. The agency wants at least 100 hospitals sending detailed records by the end of this year.

The contradiction between the manual and the request is the news here. It is also the clearest available measure of how far the program departs from what the agency has historically done.


What the Agency Has Traditionally Collected

For more than 45 years, the CPSC has run the National Electronic Injury Surveillance System, a statistical sample of roughly 100 hospitals whose trained staff code emergency visits involving consumer products. NEISS is how the country learns that a category of baby lounger, a style of furniture or a household appliance is sending people to the emergency room with a pattern that regulators can act on. The data are almost always stripped of identifiers before they leave the hospital.

The manual also limits what belongs in the system. Injuries caused by food, illegal drugs, medical devices, alcohol or plants are excluded, as are injuries with no consumer product involved, such as a fall on bare ground, and suicide attempts by adults.

The new program's scope is far larger. In an email to hospital technology officials, Konza Health President and CEO Laura McCrary wrote that the company would provide CPSC with records for patients treated for any of more than 10,000 conditions. The list includes child injuries from stingray contact and from "poisoning by" vaccines, neither of which falls under the agency's jurisdiction. A contract offered to one hospital and reviewed by KFF Health News set no limits on what would be gathered and said patient health information would be retained for at least 30 days.

Konza, which operates Kansas's health data exchange, won a five-year contract worth up to $15.9 million with the CPSC last fall. McCrary said the company will remove names, addresses, and medical information not needed by the agency before sharing records, and said Konza is not using AI to process them.


Where the Legal Questions Sit

Federal law requires the agency to provide public notice and a comment period before requesting information from 10 or more entities. CPSC spokesperson Steve Roney acknowledged that the agency had not yet notified the public as "required by law," even as it planned for 100 participating hospitals. The agency announced the program on July 21 after KFF Health News asked about it.

Federal public health authorities also cannot legally compel private health data to be reported. Yet CPSC Chief Data Officer Elizabeth Puchek has told hospitals in emails that they must seek an exemption if they decline to participate, and Konza representatives described participation to hospital executives as mandatory or required. Agency officials have suggested that hospitals declining to share data could face penalties under the information blocking rule.

Sharona Hoffman, a professor of health law at Case Western Reserve University, told KFF Health News that giving a private entity access to this volume of data creates privacy risk. "If this company really is collecting identifiable information, that is worrisome for patients," she said.

The risk has precedent inside the agency. Between 2017 and 2019, the CPSC improperly released personal health information belonging to roughly 30,000 people.


How Hospitals Are Responding

The responses on the record are notably direct. Mass General Brigham in Boston has declined to participate, with spokesperson Kelly Mitchell saying that "to protect patient privacy, we are unable to provide these medical records." Harborview Medical Center in Seattle said through spokesperson Susan Gregg that its emergency room has "voluntarily submitted de-identified data for many years" and is not obligated to report this information.

Henry Ford Health in Detroit, St. Luke's in Boise and Sanford Health in Sioux Falls, which together handle more than a million emergency visits a year, have been approached but have not entered agreements. Mayo Clinic, Yale New Haven Hospital, Nationwide Children's Hospital, the Cleveland Clinic and Baylor Scott and White Health declined to answer questions about participation.

Mary Greeley Medical Center in Ames, Iowa, signed a contract in April after being told participation was mandatory. It is now reconsidering after learning the funding it had received for NEISS participation was no longer available.

Former CPSC chairman Alexander Hoehn-Saric, one of three Democratic commissioners fired by President Trump, questioned the premise. Speaking of the demand for identifiable records, he said, "I really don't understand the basis for that."


The Injury Data the Country Already Stopped Collecting

There is a second thread running underneath this story, and it cuts the other way. For years, a limited number of hospitals shared de-identified data on all injuries, regardless of product involvement, through NEISS under an arrangement with the CDC's injury tracking program. That All Injury Program is how researchers tracked national trends in falls, drownings, poisonings, and violence-related injuries.

The CDC halted that collection after funding and staffing cuts last year and has not restarted it. So the country simultaneously lost a de-identified all-injury dataset that answered broad public health questions and gained a proposal to collect identifiable records on a far larger scale through a product safety agency.

Hoehn-Saric, who ran the agency, questioned whether the volume is matched by thought. He said the effort appears aimed at pulling in as much data as possible without clear attention to what is actually needed.

There is a quality concern as well. Without trained NEISS coders on site, hospital staff may no longer receive guidance on which clinical details matter for product safety analysis, which could degrade the very data the agency relies on to spot emerging hazards.


What This Means for Patients and What Comes Next

For most people, nothing changes today. A patient who visits an emergency room at a participating hospital would not be asked to sign anything different, and would generally have no way to know their record had been transmitted.

That is the practical concern. Patients cannot opt out of a program they are not told about, and the categories involved include some of the most sensitive entries in a medical record, from mental health crises to vaccine reactions. People seeking emergency care for a suicide attempt fall within the diagnostic code list that Konza described, despite the agency's own manual excluding adult suicide attempts from reporting.

Readers who want to know whether their local hospital participates can ask the health system's privacy officer directly, and can request an accounting of disclosures, a right patients hold under federal privacy rules. Nobody should delay emergency care over this.

Nearly one in five career staffers left the CPSC in the first 16 months of the current administration, and the agency has been without a governing board since the three Democratic commissioners were removed. The required public notice and comment period has not occurred. Whether it does, whether Congress examines the program, and whether more health systems follow Mass General Brigham in declining are the developments worth watching between now and the end-of-year deadline.


Developing Story Timeline

July 27, 2026: KFF Health News publishes documents and emails showing the CPSC requested identifiable records from all ER patients at targeted hospitals.

July 21, 2026: CPSC publicly announces the new injury surveillance program after being asked about it by reporters.

July 10, 2026: A CPSC spokesperson says the agency is modernizing its surveillance system and acknowledges public notice has not been given.

April 2026: Mary Greeley Medical Center signs a data agreement with Konza Health after being told participation was mandatory.

Fall 2025: Konza Health wins a five-year CPSC contract worth up to $15.9 million.


Frequently Asked Questions

What happened? The CPSC asked at least 100 hospitals to send identifiable emergency room records to a private contractor by the end of 2026, which appears to conflict with its own operating manual.

What does the manual actually say? It instructs hospitals not to include identifiable information such as names, birthdates, or addresses, and reserves identifiers for follow-up investigations covering under one percent of cases.

Is participation required? Federal public health authorities cannot legally compel reporting of private health data. Agency and contractor communications described participation as mandatory, and hospitals were told to seek an exemption to decline.

What kinds of records are involved? More than 10,000 diagnostic codes, including injuries with no consumer product involvement, vaccine reactions and suicide attempts.

Which hospitals have refused? Mass General Brigham declined. Harborview Medical Center said it is not obligated to report. Several large systems have been approached without signing agreements.

How can I find out if my hospital participates? Contact the health system's privacy officer and ask, and request an accounting of disclosures of your records.

What should patients do? Nothing that delays emergency care. Those with concerns can raise them with the hospital's privacy office and with their congressional representatives.

Sign up to read this article
Read news from 100's of titles, curated specifically for you.
Already a member? Sign in here
Related Stories
Top stories on inkl right now
One subscription that gives you access to news from hundreds of sites
Already a member? Sign in here
Our Picks
Fourteen days free
Download the app
One app. One membership.
100+ trusted global sources.