An Injury Tracking System That Reaches Past Its Own Jurisdiction
A federal agency that regulates lawn mowers, cribs, and coffee makers is asking some of the country's largest hospital systems to hand over identifiable medical records from every patient who walks into their emergency departments.
The request comes from the Consumer Product Safety Commission, which is rebuilding the injury database it has used since 1972. The agency announced the overhaul on July 22, describing a system called NEISS-Remodel, or NEISS-R, that would expand from roughly 70 participating hospitals across 36 states to 100 hospitals in all 50 states and lift the volume of records reviewed from about 400,000 a year to roughly 2 million.
What the announcement did not describe is the breadth of what the agency is asking for. According to documents and emails obtained by KFF Health News, a CPSC official told hospitals that they must supply names, addresses, diagnoses, and other identifying details for all emergency department patients to a private contractor, Konza Health. The list of diagnostic codes the contractor circulated runs to more than 10,000 conditions and includes injuries the CPSC has no statutory role in overseeing, such as reactions coded as poisoning by vaccines and contact with stingrays.
For readers, this is not an abstract question about federal data architecture. It is a question about whether a record of a broken wrist, a medication reaction, or a mental health crisis leaves the hospital with a name attached to it.
What the Agency Has Confirmed and What Remains Contested
CPSC spokesperson Steve Roney said in a July 10 statement that the agency is "modernizing" its surveillance system, and that the ability of hospitals to opt out of the previous voluntary program had limited the usefulness of the data. Roney also acknowledged the agency had not yet given the public notice required by law.
That gap matters. Federal law requires an agency to publish notice and open a comment period before collecting information from 10 or more entities. The CPSC plans to enroll 100 hospitals and has not taken that step. Separately, federal public health guidance holds that private health data reporting cannot be legally mandated by federal health authorities.
Hospitals say the pressure has been real. CPSC Chief Data Officer Elizabeth Puchek told hospitals in emails that institutions declining to participate must seek a formal exemption. Both the agency and the contractor described participation in correspondence as mandatory or required, even though the underlying NEISS program has always been voluntary.
Several major systems have pushed back. In Boston, Mass General Brigham declined outright, with spokesperson Kelly Mitchell saying that "to protect patient privacy, we are unable to provide these medical records." In Seattle, Harborview Medical Center spokesperson Susan Gregg said the hospital has "voluntarily submitted de-identified data for many years, but we are not obligated to report this information." Henry Ford Health in Detroit, St. Luke's in Boise, and Sanford Health in Sioux Falls have been approached but have not signed agreements.
Konza Health, a Kansas-based organization that operates the state's health information exchange, won a five-year contract worth up to $15.9 million. Its president and chief executive, Laura McCrary, told KFF Health News the company will strip patients' names, addresses, and clinical information not needed by the CPSC before passing records to the agency, and said Konza is not using artificial intelligence to process them. A contract offered to one hospital, however, set no limits on what would be collected and provided for holding patient health information for at least 30 days.
Why This Is a Question About Surveillance Design, Not Just Privacy
The strongest criticism of the plan is not that broader data is inherently bad. It is that the collection appears untethered from what the agency is legally allowed to act on.
The CPSC's own 214-page NEISS coding manual instructs hospitals not to include identifiable details such as names, birthdates, or addresses, and directs coders to exclude entire categories of visits, including injuries caused by food, medical devices, alcohol, or plants, falls onto the ground with no product involved, and suicide attempts by adults. Identifiable information has historically been sought only when a follow-up investigation was needed, which the manual says happens in fewer than 1% of reported cases.
Alexander Hoehn-Saric, a former CPSC chairman removed from the commission last year, said he was surprised the agency would insist on identifiable records from all emergency visits. "I really don't understand the basis for that," he said.
Sharona Hoffman, a professor of health law at Case Western Reserve University, told KFF Health News the arrangement introduces risk regardless of intent. "The whole thing is troubling," she said, noting that a private entity holding a sweeping collection of identified records creates exposure that did not previously exist.
There is precedent for concern about the agency's handling of sensitive information. Between 2017 and 2019, the CPSC improperly released personal health information belonging to roughly 30,000 people, a disclosure that drew a formal letter of concern from the Senate Commerce Committee at the time.
Acting CPSC Chairman Peter Feldman said at a toy industry event in February that the agency is "investing in AI-enabled workflows that improve the quality and quantity" of its injury data while building infrastructure for a much larger volume of electronic health records. Roney did not answer questions about the use of AI.
Who Is Most Affected and What the Practical Risk Looks Like
The people with the most at stake are patients treated at the specific hospitals that sign agreements, and the effect is not evenly distributed.
Anyone who visits an emergency department at a participating hospital would have a record generated and transmitted, regardless of whether a consumer product was involved. That includes patients seen for mental health crises, medication reactions, and injuries with no product connection at all, categories the agency's own manual has long excluded.
Patients treated at systems that have declined, including Mass General Brigham and Harborview, are not affected by this collection. Several of the country's busiest systems, including Mayo Clinic, Yale New Haven Hospital, Nationwide Children's Hospital, Cleveland Clinic, and Baylor Scott and White Health, declined to say whether they are participating, so patients in those markets cannot yet determine their status.
There is also a data quality question that cuts the other way. Under the old system, trained on-site staff decided which clinical details mattered for product safety. Automating that step without those workers could dilute the very product hazard signal the agency exists to detect, which would slow recalls rather than speed them.
What Readers Can Reasonably Do Now
There is no action most people need to take today, and no evidence that any patient has been harmed by this program.
Patients who want to know their hospital's position can ask its privacy officer or health information management department directly whether the facility has entered an agreement with Konza Health for emergency department data, and what identifiers are shared. Under federal privacy rules, patients can also request an accounting of certain disclosures of their protected health information.
No one should delay or avoid emergency care over this. Emergency departments remain the correct destination for chest pain, difficulty breathing, signs of stroke, severe bleeding, or a rapidly worsening condition, and declining care carries far greater risk than a records dispute.
What Happens Next
The CPSC has said NEISS-R should be fully operational by early 2027 and wants at least 100 hospitals sending records by the end of this year, according to an internal mid-year memo to the commission. Because the required public notice and comment period has not been opened, the timing of any formal rulemaking is unclear.
Congressional offices, hospital associations, and state attorneys general are the parties most likely to act next, and any legal challenge would probably turn on the notice requirement and on whether the agency can compel reporting at all. MedicalDaily will track whether the CPSC publishes a formal notice, whether additional health systems confirm or decline participation, and whether the contract with Konza Health is made public.
The confirmed facts are that a federal agency has asked 100 hospitals for identifiable records from all emergency visits, that its request extends to injury categories outside its jurisdiction, and that it has not completed the public notice its own spokesperson says the law requires. The people most affected are patients at hospitals that sign on. The most reasonable step is a direct question to your hospital's privacy office. The central uncertainty is whether the agency has the legal authority it has implied.
Frequently Asked Questions
What exactly is the CPSC asking hospitals to provide? According to documents and emails reported by KFF Health News, the agency asked hospitals to send identifiable records, including names, addresses, and diagnoses, for all emergency department patients to its contractor, Konza Health, covering more than 10,000 diagnostic codes.
Is this the same as the old NEISS program? No. The long-running National Electronic Injury Surveillance System was voluntary, involved roughly 70 hospitals, and relied on trained staff to code product-related injuries with identifying details almost always removed. The new program is far broader and asks for identifiable records.
Does the CPSC regulate all the injuries on the list? No. The list includes categories the agency has no statutory role in overseeing. The CPSC's own coding manual instructs hospitals to exclude several of these categories from reporting.
Can a federal agency require hospitals to hand over patient records? That is disputed. Hospital lawyers and health law scholars have questioned the authority, and federal guidance holds that public health authorities cannot legally mandate private health data reporting. The agency has also not completed the public notice required before collecting information from 10 or more entities.
Which hospitals have declined? Mass General Brigham in Boston has declined. Harborview Medical Center in Seattle said it is not obligated to report. Henry Ford Health, St. Luke's in Boise, and Sanford Health have been approached but have not signed agreements.
How can I find out whether my hospital is participating? Contact the hospital's privacy officer or health information management department and ask directly whether it has an agreement with Konza Health covering emergency department records.
Should I avoid the emergency room because of this? No. Emergency departments remain the appropriate place for serious or rapidly worsening symptoms. Delaying urgent care carries a far greater health risk.