The Great Data Grab: Inside the CPSC’s Controversial Push to Ingest Millions of Patient Records
In a move that has sent shockwaves through the American healthcare sector, the Consumer Product Safety Commission (CPSC)—a federal agency historically known for policing the safety of lawn mowers and coffee makers—has launched an aggressive, secretive campaign to ingest millions of granular, personally identifiable medical records from the nation’s emergency rooms.
This initiative, which marks a radical departure from the agency’s established mission, is being framed by the current administration as a "modernization" of its injury surveillance infrastructure. However, legal scholars, hospital executives, and privacy advocates warn that the program operates in a regulatory gray area, potentially bypassing federal privacy protections and forcing private health systems into a precarious position regarding the handling of sensitive patient data.
The Scope of the Mandate: A Drastic Shift in Surveillance
The CPSC’s traditional mechanism for tracking product-related injuries is the National Electronic Injury Surveillance System (NEISS). For decades, this voluntary system has functioned by having trained hospital personnel report injuries linked specifically to consumer goods. Crucially, these reports are almost always scrubbed of personally identifiable information (PII) before reaching the agency.
The new program, however, represents a fundamental shift. Internal documents and communications obtained by KFF Health News reveal that the agency is pressuring at least 100 of the nation’s largest hospital systems to hand over full, identifiable medical records for all emergency room visits. This sweeping data dragnet includes diagnoses that have nothing to do with consumer products, ranging from suicide attempts to vaccine reactions and injuries caused by wildlife, such as stingray stings.
The agency has enlisted a private, Kansas-based contractor, Konza Health, to serve as the repository and analyst for this data. Konza, which holds a $15.9 million, five-year contract with the CPSC, has reportedly informed hospital technology officials that participation in this new data-sharing scheme is "mandatory."
Chronology: From Voluntary Reporting to Coerced Compliance
The transition toward this more invasive surveillance model has accelerated during a period of significant upheaval within the CPSC.
- Early 2026: Following the dismissal of the agency’s three Democratic board members by the Trump administration, the CPSC began discreetly pressuring health system executives to onboard with the new system. During this period, the agency saw a turnover rate of nearly 20% of its career staff.
- February 2026: At a toy industry conference, Acting CPSC Chairman Peter Feldman publicly signaled the shift, announcing that the agency was "investing in AI-enabled workflows" to handle a massive influx of electronic health records.
- March 2026: Konza Health began issuing "onboarding letters" to major hospital systems, explicitly describing the data transfer as a requirement rather than a voluntary contribution.
- July 2026: After inquiries from journalists, the CPSC officially announced the program. Notably, the announcement omitted the contentious nature of the data demands and the alarm it had already sparked among hospital administrators.
Supporting Data and the "Information Blocking" Threat
The CPSC’s push is supported by a mix of administrative pressure and the looming threat of regulatory punishment. While federal law prohibits public health authorities from legally mandating that private hospitals report raw patient data, CPSC officials have suggested that non-compliance could trigger penalties under the "information blocking" provisions of federal law—a regulation originally designed to ensure interoperability between electronic health record systems.

This threat has placed hospital legal teams in an impossible bind. On one hand, they face pressure from the federal government to release patient data; on the other, they face potential litigation and regulatory action for violating the Health Insurance Portability and Accountability Act (HIPAA), which governs the protection of personal health information.
The scale of the data requested is staggering. While the previous NEISS system focused on specific product-related hazards, the new mandate captures virtually any diagnosis code. Emails indicate that Konza is seeking records for over 10,000 different conditions, including those explicitly excluded by the CPSC’s own operating manuals.
The Role of Private Contractors and AI
The reliance on Konza Health has raised significant alarms regarding data security and corporate overreach. Unlike the previous system, which utilized trained, on-site hospital personnel to filter and de-identify data, the new model relies on automated "parsing and filtering" performed by a private entity.
Sharona Hoffman, a professor of health law at Case Western Reserve University, argues that introducing a private middleman into the medical record pipeline creates unacceptable risks. "If this company really is collecting identifiable information, that is worrisome for patients," Hoffman noted. "Very often, they will use information for marketing because now they’re going to know what conditions people have."
While Konza’s CEO, Laura McCrary, claims the organization will strip away PII before sending the records to the CPSC, critics point to the agency’s history of failure in protecting sensitive information. Between 2017 and 2019, the CPSC improperly leaked the medical records of approximately 30,000 individuals—a lapse that led to severe rebukes from Congress. Entrusting a private contractor with even more sensitive, high-volume data, experts argue, invites a catastrophe of a much larger magnitude.
Official Responses and Administrative Justification
The CPSC’s defense of the program centers on the necessity of "modernization." Steve Roney, a CPSC spokesperson, admitted that the agency had not yet provided the mandatory public notice required by law for such a massive data collection effort, but maintained that the previous voluntary system limited the "usefulness of the data."
When pressed on the use of AI to process these records, the agency has been notably evasive. While Acting Chairman Feldman touted "AI-enabled workflows," the agency’s spokesperson declined to provide specific details on how that AI is trained or what criteria it uses to flag records.

Furthermore, the agency has failed to address why it requires PII for cases that do not involve consumer products. In the agency’s own 214-page operating manual, it is explicitly instructed not to collect names, birthdates, or addresses, except in rare instances requiring a follow-up investigation—a threshold met by less than 1% of historical cases.
Implications for Patient Privacy and Healthcare Trust
The implications of this initiative extend far beyond the walls of the CPSC. It reflects a broader trend within the current administration to gain unprecedented access to the private medical records of American citizens. This includes the Office of Personnel Management’s push for federal workers’ health data and the Department of Health and Human Services’ involvement in private data-collection projects regarding vaccine research.
For hospitals, the cost of participation is high. Many systems have already been told that funding for their previous, legitimate participation in NEISS has been "no longer available," effectively forcing them to choose between bearing the cost of this new, invasive program or losing their standing with the agency.
Major systems have responded with varying degrees of resistance. While some smaller hospitals have felt compelled to sign agreements, others, such as Mass General Brigham in Boston, have taken a firm stand. "To protect patient privacy, we are unable to provide these medical records," said spokesperson Kelly Mitchell.
As the CPSC continues to push for full implementation by the end of 2026, the silence from the broader healthcare industry is beginning to break. The central question remains: Does a government agency charged with the safety of toasters and lawn mowers have the legal or moral authority to vacuum up the intimate medical history of the American public?
For now, the agency is betting that it can bypass the public comment process and coerce hospitals into compliance before the legal, ethical, and privacy implications can be fully adjudicated. For the millions of Americans whose ER visits are now being funneled into a private contractor’s database, the consequences of this "modernization" may not be known until the next inevitable data breach occurs.