The Data Dragnet: Federal Safety Agency’s Push for Millions of Private Medical Records Sparks Privacy Alarm
In a quiet but sweeping expansion of federal power, the Consumer Product Safety Commission (CPSC)—a diminutive agency historically tasked with the relatively narrow mandate of monitoring lawn mowers, coffee makers, and children’s toys—is aggressively demanding that the nation’s largest health systems surrender the granular, personally identifiable medical records of every patient who visits their emergency rooms.
This initiative, which marks a radical departure from the agency’s product-focused mission, has sent shockwaves through the hospital industry. Legal experts, hospital administrators, and patient privacy advocates are raising urgent questions regarding the CPSC’s legal authority, its capacity to secure such sensitive data, and the potential for a massive, unauthorized surveillance apparatus to be built on the backs of unsuspecting patients.
The Scope of the Demand
According to internal documents and correspondence obtained by KFF Health News, the CPSC is not merely seeking data on injuries linked to consumer products. Instead, the agency is casting a wide net, aiming to harvest the medical history of millions of Americans for everything from broken bones and vaccine reactions to sensitive psychiatric episodes, including suicide attempts.
The agency has tapped a private contractor, Konza Health, to serve as the repository for this massive influx of information. In emails sent to hospital executives, representatives from Konza have explicitly described the submission of patient names, home addresses, specific diagnoses, and other protected health information (PHI) as "mandatory" or "required." The goal, as outlined in an internal CPSC memo, is to have at least 100 hospitals fully integrated into this new surveillance system by the end of 2026.
A Chronology of the Secret Surveillance Push
The transformation of the CPSC’s data-gathering operations has unfolded rapidly and with little public transparency.
- Late 2025: The CPSC begins discreetly pressuring hospital executives to transition from the traditional, voluntary reporting system to a new, automated data pipeline.
- Early 2026: Amidst significant leadership upheaval at the CPSC—following the termination of its governing board and the departure of nearly 20% of its career staff—the agency accelerates its "modernization" efforts.
- March 2026: Konza Health intensifies its outreach to hospitals, issuing onboarding letters that frame the data-sharing requirements as non-negotiable.
- July 2026: After inquiries from KFF Health News, the CPSC officially announces the program. However, the agency’s public communication omits the contentious nature of the data demands and the growing alarm within the healthcare sector.
The Disconnect Between Mission and Methodology
For decades, the CPSC has operated the National Electronic Injury Surveillance System (NEISS). Historically, this system functioned through trained hospital personnel who manually extracted de-identified data regarding injuries caused by specific products. This process was designed to ensure that the agency received only the information necessary to identify safety hazards while rigorously protecting patient privacy.
The new program, by contrast, relies on "AI-enabled workflows" and "advanced analytic parsing" to vacuum up vast swaths of electronic health records. During a toy industry trade event in February, acting CPSC Chairman Peter Feldman championed this shift, describing it as a necessary evolution to handle a "massive new volume" of data.

Yet, this shift contradicts the agency’s own long-standing operating manual, which explicitly instructs hospitals to exclude names, birthdates, and specific addresses. Furthermore, the list of diagnostic codes provided by Konza to hospitals includes conditions entirely outside the CPSC’s jurisdiction, such as injuries resulting from vaccine reactions or encounters with wildlife—categories that have no bearing on the safety of household consumer goods.
Official Responses and Justifications
The CPSC’s official stance, articulated by spokesperson Steve Roney, is that the agency is simply "modernizing" its infrastructure. When questioned about the legal basis for the mandatory nature of the program, Roney conceded that the previous voluntary model limited the "usefulness" of the data, but he stopped short of detailing the enforcement mechanisms for hospitals that refuse to comply.
Despite these claims, the agency faces significant legal hurdles. Federal law mandates that the CPSC provide a public comment period and formal notice before requesting information from 10 or more entities. To date, the agency has failed to initiate this required process, even as it approaches dozens of hospitals with these expansive demands.
Furthermore, CPSC officials have hinted—both in public statements and private correspondence—that hospitals failing to participate could be flagged for "information blocking," a severe regulatory designation that could lead to significant financial penalties under federal health law.
The Privacy Paradox: A History of Vulnerability
The decision to entrust a private contractor like Konza Health with such a massive repository of American medical records has drawn sharp criticism. Sharona Hoffman, a professor of health law at Case Western Reserve University, warns that the centralization of identifiable patient data introduces significant risks of data breaches and misuse.
"If this company really is collecting identifiable information, that is worrisome for patients," Hoffman noted. "Very often, they will use information for marketing because now they’re going to know what conditions people have."
The CPSC’s own track record lends weight to these concerns. Between 2017 and 2019, the agency inadvertently exposed the sensitive health information of approximately 30,000 individuals—a breach that was later labeled "concerning" by members of the Senate Commerce Committee. By expanding the volume of data collected and involving a third-party private entity, critics argue that the agency is exponentially increasing the surface area for a potential catastrophic data leak.

Implications for Healthcare and Patient Trust
The push to centralize this data is occurring within a broader, controversial trend under the current administration, which has seen federal agencies, including the Office of Personnel Management and the Department of Health and Human Services, seek unprecedented access to private medical records.
For hospital systems, the dilemma is acute. Institutions like Mass General Brigham in Boston have already formally declined to participate, citing their primary duty to protect patient privacy. Others, such as Mary Greeley Medical Center in Iowa, initially signed on under the impression that the program was mandatory, only to express deep reservations once the reality of the data-sharing requirements became clear.
The potential erosion of the patient-provider relationship is perhaps the most significant implication. Patients seeking emergency care expect that their medical information will be used for their treatment and safety, not as part of a sprawling, AI-driven federal surveillance dragnet. If hospitals are forced to become conduits for this data, the fundamental trust that underpins the American healthcare system could be irreparably damaged.
As of now, the standoff continues. Major systems, including the Mayo Clinic, the Cleveland Clinic, and Yale New Haven Hospital, have remained largely silent, refusing to disclose whether they have capitulated to the CPSC’s demands. Meanwhile, legal experts like former CPSC Chairman Alexander Hoehn-Saric remain skeptical of the agency’s overreach. "They want to suck in as much data as possible," Hoehn-Saric said, "but I’m not sure how thoughtful they’re being about what is collected and what is actually needed by the agency."
For now, the future of the nation’s medical privacy remains in limbo, caught between a federal agency’s hunger for data and the mounting resistance of the institutions tasked with healing the public.