Privacy Under Siege: The CPSC’s Controversial Push for Massive Patient Data Collection
In a move that has sent shockwaves through the American healthcare sector, the Consumer Product Safety Commission (CPSC)—a federal agency historically focused on the benign tasks of tracking lawn mower malfunctions and coffee maker defects—has initiated a sweeping, controversial campaign to harvest detailed, personally identifiable medical records from the nation’s largest hospital systems.
The program, which marks a radical departure from the agency’s established mission, aims to bypass traditional privacy safeguards by funneling sensitive emergency room (ER) data to a private contractor, Konza Health. While the CPSC claims it is merely "modernizing" its injury surveillance, hospital executives, privacy advocates, and legal experts are sounding the alarm, questioning the legality of the demand, the security of the data, and the potential for a massive federal overreach into the sanctity of the doctor-patient relationship.
The Scope of the "Data Grab"
The CPSC’s new mandate is staggering in its breadth. Rather than focusing on injuries linked to specific consumer products—the agency’s statutory mandate—it is seeking comprehensive records for all emergency room visits. This includes highly sensitive information such as patient names, residential addresses, and specific diagnostic codes for conditions ranging from broken bones to suicide attempts and potential vaccine reactions.
According to internal memos and correspondence reviewed by KFF Health News, the agency is pressuring at least 100 of the nation’s top hospital systems to begin transmitting these records by the end of 2026. Representatives from Konza Health, the private entity awarded a $15.9 million, five-year contract to manage this data, have explicitly described participation in the program as "mandatory" or "required" in communications with hospital administrators.
A Chronology of Escalation
The transition from a voluntary, anonymized reporting system to this aggressive, mandatory, and identifiable data collection began in the wake of significant leadership turnover at the CPSC. Following the firing of the agency’s three Democratic board members by the Trump administration, the agency entered a period of administrative upheaval. Nearly one in five career staffers departed in the first 16 months of the new administration, creating a vacuum that has been filled by a new, more centralized directive.
- Fall 2025: The CPSC awards a $15.9 million contract to Konza Health to overhaul the agency’s injury surveillance infrastructure.
- Early 2026: CPSC officials begin discreetly pressuring hospital executives to sign on to the new system, which utilizes "AI-enabled workflows" to scrape ER records.
- February 2026: Acting CPSC Chairman Peter Feldman publicly signals the agency’s intent to invest in massive digital infrastructure to handle patient records.
- March 2026: Documentation shows the agency pushing for mandatory participation, explicitly requesting personally identifiable information (PII).
- July 2026: Following inquiries from journalists, the CPSC publicly acknowledges the program but fails to disclose the mandatory nature of the demands or the extent of the PII collection.
Supporting Data: A System Out of Bounds
The CPSC’s existing tool for tracking injuries, the National Electronic Injury Surveillance System (NEISS), has long operated as a voluntary program. For decades, trained hospital staff submitted de-identified reports on injuries involving specific products, such as toys or household appliances. This system allowed the agency to issue recalls and safety warnings while maintaining strict adherence to privacy laws.

The new program, however, ignores these established boundaries. The CPSC’s own 214-page operating manual explicitly instructs hospitals not to include identifiable information like birthdates or names, noting that such data is only necessary in less than 1% of cases for specific follow-up. The current initiative ignores this protocol entirely, demanding the bulk transmission of PII for every ER patient.
Furthermore, the diagnostic codes Konza Health is requesting are incredibly expansive, covering over 10,000 conditions. These include injuries entirely outside the CPSC’s jurisdiction, such as "poisoning by vaccines," stingray encounters, and illnesses unrelated to consumer products. This "data-sucking" approach suggests that the agency is prioritizing volume over necessity, a strategy that legal experts say creates unnecessary risk.
Official Responses and Justifications
The CPSC’s defense of the program has been characterized by shifting narratives. Spokesperson Steve Roney stated in July that the agency is simply "modernizing" its surveillance to improve the "usefulness of the data." He admitted that the agency had failed to provide public notice—a clear violation of federal law requiring a public comment period before requesting information from 10 or more entities.
When pressed on whether hospitals would face penalties for refusing, the agency has leaned on the threat of "information blocking" regulations—a federal rule designed to prevent healthcare providers from hindering the exchange of electronic health information. However, legal experts point out that these regulations were never intended to force private hospitals to turn over patient records to a federal agency for non-clinical research purposes.
Konza Health, for its part, claims it will parse the data and remove unnecessary information before it reaches the CPSC. Yet, as Sharona Hoffman, a professor of health law at Case Western Reserve University, noted: "If this company really is collecting identifiable information, that is worrisome for patients. Leaving a private organization to collect sensitive information introduces risks, including that it could be stolen or used for business purposes."
Implications for Privacy and Healthcare
The implications of this program are profound. By centralizing the health records of millions of Americans within a private contractor’s database, the CPSC is creating a "honey pot" for potential data breaches. The history of the agency itself is a warning: between 2017 and 2019, the CPSC improperly released the personal health information of approximately 30,000 people.

Moreover, the ethical concerns regarding the "marketing" of health data remain. While the CPSC claims its contract with Konza prohibits the selling or marketing of the data, the mere existence of a massive, searchable repository of health conditions is an invitation for misuse.
The impact on hospitals has been one of mounting anxiety. While some institutions, like Mary Greeley Medical Center in Iowa, initially capitulated to the pressure, others have pushed back. Mass General Brigham in Boston has explicitly declined to participate, citing the need to protect patient privacy. Other major systems, including the Mayo Clinic and the Cleveland Clinic, have remained silent, caught between the threat of federal "information blocking" penalties and their legal and ethical obligations to their patients.
A Future Under Surveillance
The CPSC’s initiative reflects a broader trend within the current administration to gain unprecedented access to private health records, often utilizing private organizations to bypass the standard scrutiny applied to federal data collection. From the Office of Personnel Management’s requests for federal workers’ health records to the Department of Health and Human Services’ partnerships for vaccine studies, the sanctity of medical privacy is being eroded.
As the deadline for the "mandatory" participation approaches, the healthcare industry stands at a crossroads. Will hospitals yield to federal pressure and sacrifice the privacy of their patients for the sake of an agency’s "modernization," or will they stand firm in the defense of HIPAA and the fundamental rights of the individuals they treat?
Ultimately, the CPSC’s push raises a foundational question for American democracy: does a federal agency tasked with regulating household products have the right to curate a national database of the private medical histories of its citizens? As of now, the agency’s actions suggest they believe the answer is yes—a conclusion that sets a dangerous precedent for the future of digital health privacy in the United States.