Data Overreach or Modernization? The CPSC’s Controversial Push for Millions of Patient Records
In a move that has sent shockwaves through the American healthcare sector, the Consumer Product Safety Commission (CPSC)—a federal agency historically tasked with the relatively narrow mission of tracking hazards like faulty coffeemakers and unsafe lawn mowers—is now aggressively demanding access to the highly sensitive, personally identifiable medical records of millions of Americans.
This sweeping surveillance initiative represents a radical departure from the agency’s established mandate. By pressuring the nation’s largest hospital systems to surrender detailed emergency room records, the CPSC has bypassed traditional regulatory safeguards, sparking a fierce debate among legal scholars, privacy advocates, and hospital executives regarding the limits of federal power and the sanctity of the patient-physician privilege.
The Scope of the Mandate
According to internal documents and communications obtained by KFF Health News, the CPSC is aiming to integrate at least 100 hospitals into a new, automated data-sharing system by the end of 2026. Unlike the voluntary, de-identified reporting that has characterized the National Electronic Injury Surveillance System (NEISS) for decades, this new program requires the transmission of granular data.
The agency is reportedly seeking names, home addresses, specific medical diagnoses, and other identifying markers for virtually every patient treated in emergency rooms across the country. The criteria for these records are staggering in their breadth: the agency is casting a wide net that includes not just product-related injuries, but also vaccine reactions, suicide attempts, and common medical ailments that have no connection to consumer products.
A Chronology of Regulatory Upheaval
The push for this massive data repository began in the shadow of significant institutional instability at the CPSC. Following the firing of the agency’s three Democratic board members by President Donald Trump, the commission has operated without its traditional governing board, leading to a period of internal turbulence.
- Early 2026: Amidst a high staff turnover rate—with nearly 20% of career employees departing—the agency began discreetly pressuring hospital executives to join the new surveillance program.
- Spring 2026: Konza Health, a Kansas-based data exchange firm, secured a $15.9 million contract to facilitate the collection and parsing of this massive volume of patient data.
- July 21, 2026: Under pressure from inquiries by investigative journalists, the CPSC finally went public with its "modernization" initiative, though it notably omitted the scale of its demand for personally identifiable information (PII).
- Ongoing: Hospital legal teams across the country are currently evaluating whether to comply with these demands or risk the potential consequences of "information blocking" regulations, which federal officials have hinted could be used as a stick against non-compliant institutions.
The Role of Konza Health and AI Integration
At the heart of this initiative is the partnership with Konza Health. While the CPSC has publicly framed this as an AI-driven "modernization" of its infrastructure, the reality of the data pipeline is more complex.
Acting CPSC Chairman Peter Feldman has publicly touted the use of "AI-enabled workflows" to improve injury surveillance. However, the operational reality involves Konza acting as a middleman, pulling raw electronic health records (EHR) directly from hospital databases. While Konza’s leadership has attempted to downplay the use of "AI" in favor of "advanced analytic parsing," the shift from human-reviewed, de-identified reporting to an automated, bulk-data model raises significant concerns about the dilution of data quality.

Former CPSC Chair Alexander Hoehn-Saric, one of the officials dismissed during the recent administrative turnover, expressed profound skepticism. "They want to suck in as much data as possible, but I’m not sure how thoughtful they’re being about what is collected and what is actually needed," Hoehn-Saric noted. By removing human oversight—the nurses and technicians who previously determined the relevance of an injury—the agency risks filling its database with "noise" that provides little actual value for product safety.
Official Responses and Justifications
The CPSC’s official stance, articulated by spokesperson Steve Roney, is that the current voluntary system is insufficient. Roney argued that the ability for hospitals to opt out has "limited the sample size and usefulness of the data," necessitating a more mandatory, systematic approach.
However, the agency finds itself in a precarious legal position. Federal law requires the CPSC to provide notice and a public comment period before requesting information from 10 or more entities. To date, the agency has failed to initiate this required rulemaking process, despite having already approached over a dozen hospital systems and targeting 100 for participation.
When pressed on whether the agency would penalize hospitals that refuse to comply, officials have pointedly suggested that refusing to share data could trigger federal "information blocking" penalties. This creates an impossible choice for hospitals: comply and risk violating HIPAA (the Health Insurance Portability and Accountability Act) and patient trust, or refuse and face federal regulatory wrath.
Privacy Implications: A "Worrisome" Precedent
The security of this data is a primary concern for privacy experts. The CPSC has a documented history of mishandling sensitive information; between 2017 and 2019, the agency was responsible for the improper release of personal health information belonging to 30,000 individuals.
"The whole thing is troubling," says Sharona Hoffman, a professor of health law at Case Western Reserve University. "If this company [Konza] really is collecting identifiable information, that is worrisome for patients. Once you move data into the hands of a private contractor, the risk of data breaches, unauthorized re-identification, and commercial exploitation increases exponentially."
Furthermore, the scope of the data collection is clearly overstepping the agency’s statutory authority. Internal documents show that Konza intends to collect data on over 10,000 conditions, including those explicitly excluded by the CPSC’s own operating manual, such as injuries from stingrays or reactions to vaccines. By collecting such wide-ranging data, the agency is creating a "honeypot" of sensitive medical information that far exceeds the needs of a product safety commission.

The Institutional Climate
This initiative does not exist in a vacuum. It is part of a broader, administration-wide effort to consolidate medical data. Similar projects have been observed within the Office of Personnel Management, which has sought access to the records of federal employees, and through Department of Health and Human Services initiatives aimed at investigating vaccines and autism.
For many hospital systems, this represents a fundamental challenge to their mission. While some have signed on—often under the impression that participation was mandatory—others are standing their ground. Mass General Brigham in Boston has explicitly declined to participate, citing the need to protect patient privacy. Others, like the Mayo Clinic and the Cleveland Clinic, remain silent, reflecting the immense pressure and confusion surrounding the directive.
Conclusion: A Conflict of Mission
The CPSC’s mandate is to protect the public from dangerous consumer products. By effectively transforming into a data-mining entity that collects comprehensive health histories, the agency risks alienating the very partners—hospitals—that are essential to its success.
If the agency continues to prioritize "quantity over quality" and ignores the legal and ethical barriers surrounding patient privacy, it may find that its attempt to "modernize" actually results in the collapse of the decades-old, trust-based collaboration that has successfully identified and recalled dangerous products in the past. As legal challenges and public outcry continue to mount, the question remains: is the CPSC fulfilling its duty to the public, or is it fundamentally compromising the privacy of the people it was built to protect?
The path forward for the CPSC is fraught with legal landmines. Without a transparent, legally sound framework that respects HIPAA and the privacy rights of American patients, this initiative stands as a cautionary tale of bureaucratic overreach in the digital age.