Privacy Under Pressure: The Federal Data Grab Targeting America’s Emergency Rooms
In a move that has sent shockwaves through the American healthcare sector, the Consumer Product Safety Commission (CPSC)—a diminutive federal agency typically known for overseeing the safety of toasters, lawn mowers, and children’s toys—has initiated an aggressive, expansive program to ingest millions of personally identifiable medical records. By pressuring the nation’s largest health systems to surrender private patient data from emergency room visits, the agency is embarking on a controversial transformation that legal experts and hospital administrators warn may violate federal privacy laws and overstep the agency’s statutory mandate.
The initiative, characterized by the agency as a “modernization” of its injury surveillance infrastructure, seeks to bypass the traditional, voluntary frameworks that have governed injury reporting for decades. Instead, the agency is leveraging a private contractor, Konza Health, to automatically siphon vast quantities of sensitive health data, ranging from basic broken bones to psychiatric crisis interventions and complex vaccine reactions.
The Scope of the Data Harvest
The CPSC’s ambition is to integrate at least 100 major hospital systems into this new digital pipeline by the end of 2026. Internal documents and correspondence obtained by KFF Health News reveal that the agency’s demands are not merely for statistical trends, but for raw, identifiable patient information—including names, residential addresses, and specific clinical diagnoses.
Unlike the existing National Electronic Injury Surveillance System (NEISS), which relies on trained personnel to identify and report injuries linked specifically to consumer products while stripping away personal identifiers, this new program is sweeping in its breadth. Emails from Konza Health to hospital executives have explicitly described participation as “mandatory” or “required,” with the contractor signaling that it will pull records for over 10,000 distinct clinical conditions, many of which fall entirely outside the CPSC’s regulatory purview, such as injuries resulting from contact with stingrays or suspected reactions to vaccines.
A Chronology of the Surveillance Shift
The shift began in the early months of 2026, coinciding with a period of significant volatility at the CPSC. Following the firing of the agency’s three Democratic board members by the Trump administration, the CPSC experienced a "brain drain," with nearly 20% of career staff departing within the first 16 months.

In this vacuum of oversight, the agency’s leadership pivoted toward a more centralized, AI-driven surveillance model.
- Late 2025: The CPSC awarded a five-year contract worth up to $15.9 million to Konza Health, a Kansas-based data exchange entity, to handle the massive influx of electronic health records (EHRs).
- February 2026: At a toy industry trade conference, acting CPSC Chairman Peter Feldman publicly championed the investment in "AI-enabled workflows" designed to enhance the volume of data intake.
- Spring 2026: Confidential "onboarding" letters were dispatched to hospitals nationwide, instructing them to prepare for the mandatory transmission of patient data.
- July 21, 2026: Following inquiries from journalists, the CPSC formally acknowledged the existence of the program, though it notably omitted the depth of its data demands and the legal alarm it had triggered among hospital counsel.
The Legal and Ethical Firestorm
The fundamental tension in this program lies in the collision between federal data collection and the Health Insurance Portability and Accountability Act (HIPAA). While federal public health authorities are generally restricted from mandating the reporting of private health data, CPSC officials have reportedly hinted that hospitals failing to comply could face scrutiny under "information blocking" regulations—a federal policy originally designed to prevent hospitals from hindering the interoperability of medical data.
Legal scholars, such as Sharona Hoffman of Case Western Reserve University, argue that the CPSC’s approach is fundamentally flawed. “The whole thing is troubling,” Hoffman stated. “If this company really is collecting identifiable information, that is worrisome for patients.”
The concern is twofold: first, the legal authority of a product safety agency to demand comprehensive medical records of all ER visits, regardless of whether a product was involved; and second, the vulnerability of such a massive data repository to breaches. The CPSC has a documented history of insecurity; between 2017 and 2019, the agency improperly released the personal health information of roughly 30,000 individuals. Critics argue that involving a private third-party contractor like Konza Health only compounds these risks, creating a target for cybercriminals and raising the specter of commercial misuse of patient records.
Official Responses and Justifications
CPSC spokesperson Steve Roney has defended the project, framing it as a necessary technological evolution. In response to inquiries, Roney noted that the previous, voluntary nature of NEISS limited the "sample size and usefulness" of the data. He acknowledged that the agency had not yet completed the public notice and comment period required by federal law for data collection involving ten or more entities, despite its goal of recruiting 100 hospitals.

Meanwhile, Konza Health’s CEO, Laura McCrary, has attempted to mitigate privacy concerns, asserting that the company will filter out names and addresses not deemed "necessary" by the CPSC before finalizing the data transfer. However, this assurance does little to calm hospitals that are currently being told they must provide the raw data in the first place. Furthermore, while the CPSC claims their contract prohibits Konza from selling or marketing the data, the lack of transparency regarding the full terms of the $15.9 million contract leaves many industry watchdogs skeptical.
Implications for the Future of Patient Privacy
The CPSC’s program is not occurring in a vacuum. It is part of a broader, administration-wide trend toward accessing granular medical data. From the Office of Personnel Management’s requests for federal workers’ health records to Health and Human Services Secretary Robert F. Kennedy Jr.’s use of private organizations to study vaccine and autism correlations, the federal government is increasingly utilizing private intermediaries to bypass traditional bureaucratic and privacy hurdles.
For the hospitals, the pressure to comply is immense. Smaller, rural, and publicly owned hospitals, which often rely on federal cooperation, feel the squeeze of "mandatory" language. Larger, more robust institutions, such as Mass General Brigham in Boston, have taken a firm stand, citing their inability to provide such records due to federal privacy laws.
The consequences of this program are profound. If the CPSC succeeds in turning emergency rooms into a direct, automated pipeline for federal data collection, it sets a precedent for other federal agencies to treat the sanctity of the doctor-patient relationship as a secondary concern to administrative data-gathering.
As hospitals grapple with the choice between cooperating with an agency that possesses the power to penalize them and adhering to their duty to protect patient privacy, the project highlights a dangerous shift in the digital age: the normalization of surveillance over medical care. Whether this "modernization" results in safer consumer products or simply a more vulnerable American public remains the central question, one that is currently being litigated in the quiet, tense boardrooms of health systems across the country.