Privacy Under Pressure: The CPSC’s Controversial New Data-Collection Mandate
A tiny federal agency, historically known for policing the safety of lawnmowers and household appliances, has embarked on an ambitious and highly controversial effort to overhaul the nation’s medical surveillance system. The Consumer Product Safety Commission (CPSC) is currently pressuring some of the largest healthcare systems in the United States to surrender deep, personally identifiable medical records for every patient admitted to their emergency departments.
This shift marks a radical departure from the agency’s established mandate. For decades, the CPSC has operated the National Electronic Injury Surveillance System (NEISS), a voluntary, de-identified program designed to track consumer product-related injuries. However, the agency’s new initiative, which involves a private contractor, has sparked alarm among hospital legal counsel, privacy advocates, and industry experts, who question both the legal authority behind the demand and the security risks posed by such a massive centralization of sensitive patient data.
The Scope of the Data Grab
The CPSC’s objective, as detailed in internal agency documents and confirmed through interviews with industry stakeholders, is to ingest millions of medical records annually. The requested data is not limited to product-related injuries; it covers the entire spectrum of emergency room visits, ranging from simple bone fractures to complex psychiatric episodes and even vaccine reactions.
In correspondence sent to hospital administrators, the CPSC’s designated contractor, Konza Health, has described participation in this new, automated surveillance program as "mandatory" or "required." The agency’s demands include the transmission of patient names, physical addresses, specific clinical diagnoses, and other granular personal identifiers. This represents a stark pivot from the previous standard, where hospitals provided anonymized data to help the CPSC identify patterns of injury related to specific consumer goods.
The goal, according to an internal agency memo, is to bring at least 100 major hospital systems into the fold by the end of 2026.
Chronology of a Quiet Transformation
The push for this data-sharing program began in early 2026, coinciding with a period of significant upheaval within the CPSC. Following the firing of the commission’s three Democratic board members by the Trump administration, the agency has operated without a governing board. Workforce data indicates that nearly 20% of the agency’s career staff departed within the first 16 months of this administration, leaving the remaining infrastructure vulnerable to rapid, top-down policy shifts.
- Fall 2025: The CPSC awarded a five-year, $15.9 million contract to Kansas-based Konza Health to build and manage a new digital infrastructure for injury surveillance.
- February 2026: Acting CPSC Chairman Peter Feldman announced the agency’s investment in "AI-enabled workflows" during a trade industry event, framing the move as a modernization effort.
- March 2026: Konza Health began circulating "onboarding" letters to hospital executives, explicitly characterizing the data-sharing requirements as mandatory.
- July 2026: Following inquiries from KFF Health News, the CPSC officially announced the program. However, the announcement notably omitted the specific nature of the identifiable data demands and the growing resistance from healthcare providers.
Supporting Data and Technical Concerns
The methodology behind the new surveillance system is centered on "automated parsing." While the CPSC has historically relied on on-site human staff to review medical charts—ensuring that only relevant, product-related injury data is extracted—the new model shifts this responsibility to Konza Health.

Konza has indicated that it will scan records for over 10,000 diagnostic codes. Crucially, this list includes conditions entirely outside the CPSC’s jurisdiction, such as injuries resulting from medical procedures, encounters with wildlife, or complex behavioral health crises.
Critics, including former CPSC leadership, warn that this "suck-in" approach to data collection creates significant security vulnerabilities. The agency has a spotty track record with data security; between 2017 and 2019, the CPSC was responsible for the improper release of personal health information belonging to approximately 30,000 citizens. By centralizing millions of records through a private third party, the agency is arguably compounding the risk of a catastrophic data breach.
Sharona Hoffman, a professor of health law at Case Western Reserve University, noted that the involvement of a private entity introduces a new layer of risk. "If this company is collecting identifiable information, that is worrisome," Hoffman said. "There is the constant risk of misuse, including for marketing purposes, given that these companies now possess a deep diagnostic profile of a vast swath of the population."
Official Responses and Justifications
The CPSC has defended the program as a necessary "modernization" of its surveillance capabilities. Steve Roney, a spokesperson for the agency, argued that the previous, voluntary system was limited by its sample size and the ability of hospitals to opt out, which allegedly rendered the data less useful for regulatory decision-making.
When pressed on whether the agency has the legal authority to mandate this reporting, Roney avoided a direct answer, instead pointing to the general desire for better data. He acknowledged that the agency had not yet fulfilled the legal requirement to provide notice and a public comment period—a standard procedural step required when a federal agency requests information from 10 or more entities.
Regarding the use of Artificial Intelligence to process the records, the agency’s messaging has been inconsistent. While the Acting Chairman spoke publicly about "AI-enabled workflows," Konza’s leadership has attempted to walk back that terminology, describing their methods as "advanced analytic parsing and filtering capabilities."
Implications for Privacy and Healthcare
The implications of this initiative extend far beyond the CPSC’s traditional mission. By demanding that hospitals turn over records that include identifiers, the agency is potentially forcing healthcare systems to violate federal HIPAA regulations, which strictly govern the disclosure of protected health information.

Several major institutions have pushed back. Mass General Brigham in Boston, citing patient privacy, has formally declined to participate. Other systems, including those in Seattle and Detroit, have expressed deep skepticism regarding the legal standing of the CPSC’s mandate. Meanwhile, hospitals that previously received federal funding for their participation in the older, voluntary NEISS program have been informed that those funds are no longer available, leaving them in a financial bind: comply with the data-sharing mandate or lose the support they rely on to maintain their reporting infrastructure.
The broader context of this move is equally unsettling to privacy advocates. This effort follows a pattern of heightened interest in medical records by the current administration, including requests by the Office of Personnel Management for federal workers’ health data and the use of private organizations by the Department of Health and Human Services to aggregate medical records for research on vaccines and autism.
Conclusion: A Precedent for Surveillance?
The CPSC’s attempt to pivot from product safety to population-wide health data surveillance raises a fundamental question: to what extent should a small regulatory body have access to the most intimate details of a patient’s life?
By bypassing public transparency requirements and leveraging the threat of "information blocking" penalties against hospitals, the agency is fundamentally altering the relationship between the government, private healthcare providers, and the patients they serve. As hospitals grapple with whether to comply or resist, the case serves as a stark reminder of the fragile state of medical privacy in an era where federal agencies are increasingly utilizing private contractors to bypass traditional oversight.
Until the agency addresses the legal questions regarding its authority and provides a transparent account of how it intends to protect the data of millions of Americans, the "modernization" of the CPSC’s injury surveillance system will likely continue to be viewed not as a safety improvement, but as an alarming encroachment on the privacy of the American public.