The Privacy Frontier: Federal Agency’s Massive Health Data Grab Sparks Industry Alarm
In a move that has sent shockwaves through the American healthcare sector, the Consumer Product Safety Commission (CPSC)—a relatively small federal agency traditionally focused on the safety of household goods like lawnmowers, coffee makers, and children’s toys—is spearheading an ambitious and controversial initiative to ingest the granular, personally identifiable medical records of millions of Americans visiting emergency rooms nationwide.
This sweeping data-collection project, launched discreetly earlier this year, marks a radical departure from the agency’s historical mandate. By bypassing standard transparency protocols and utilizing a private contractor, the CPSC is effectively positioning itself as a central repository for sensitive health data, raising urgent questions among legal scholars, hospital administrators, and privacy advocates regarding the limits of federal authority and the security of patient information.
The Core Mandate: From Toasters to Triage
For decades, the CPSC has operated the National Electronic Injury Surveillance System (NEISS), a voluntary and largely de-identified program that helps regulators identify products that pose recurring hazards to the public. Under this established framework, hospitals contribute sanitized data regarding injuries directly linked to consumer goods.
The new program, however, fundamentally alters this relationship. According to internal documents, emails, and interviews with stakeholders, the agency is demanding that at least 100 of the nation’s largest hospital systems surrender comprehensive, identifiable patient data—including names, residential addresses, and specific diagnostic codes—to a third-party organization, Konza Health.
Unlike the previous iteration of the surveillance system, this new architecture does not limit its scope to consumer product-related injuries. Instead, the initiative appears designed to sweep in records for nearly all ER visits, ranging from routine bone fractures to complex clinical encounters, including vaccine reactions and, in some instances, mental health crisis events.
A Chronology of the Secret Surveillance Pivot
The genesis of this initiative coincides with a period of significant upheaval within the CPSC. Following the firing of the agency’s three Democratic board members by the Trump administration and the subsequent departure of nearly 20% of its career staff in the first 16 months of the new term, the internal culture of the commission has undergone a stark transformation.
- Fall 2024: The CPSC awards a five-year contract, valued at approximately $15.9 million, to Konza Health, a Kansas-based organization specializing in health data exchanges.
- Early 2025: The agency begins quiet, targeted outreach to hospital executives, characterizing participation in the new, AI-enabled data pipeline as "mandatory" or "required."
- February 2026: Acting CPSC Chairman Peter Feldman publicly signals the agency’s intent to invest in "AI-enabled workflows" capable of managing a massive influx of electronic health records.
- March 2026: Onboarding letters are dispatched to hospital systems, with Konza representatives emphasizing that the transition to the new surveillance model is not optional.
- July 2026: Following inquiries from KFF Health News, the CPSC officially acknowledges the existence of the program, though it omits details regarding the scope of the "identifiable" nature of the data demands.
The Role of Private Contractors and AI
Central to this controversy is the role of Konza Health. While the CPSC claims the initiative is an effort to "modernize" its surveillance infrastructure, critics argue that the reliance on a private entity to parse sensitive medical data introduces an unnecessary layer of vulnerability.

Konza’s President and CEO, Laura McCrary, has described the data-sharing process as a requirement for hospitals. While McCrary maintains that the company employs "advanced analytic parsing" rather than artificial intelligence to process the files, the agency’s own strategic planning documents explicitly reference a shift toward AI-enabled surveillance.
The concern among privacy experts is two-fold: the technical risk of data breaches and the commercial risk of mission creep. "If this company really is collecting identifiable information, that is worrisome for patients," notes Sharona Hoffman, a professor of health law at Case Western Reserve University. She warns that private entities, once in possession of vast health datasets, may be tempted to leverage that information for secondary purposes, despite contractual prohibitions against marketing or sales.
Legal and Ethical Implications: A Violation of Precedent?
The CPSC’s aggressive stance on data collection faces significant legal hurdles. Under the Paperwork Reduction Act, federal agencies are generally required to provide public notice and a window for public comment before mandating data collection from ten or more entities. The CPSC has yet to complete this step, despite its goal of integrating 100 hospitals into the new system.
Furthermore, the agency’s authority to mandate the submission of identifiable health records remains dubious. Federal public health authorities, such as the CDC, do not possess the legal power to compel the reporting of private, non-deidentified health data. In an attempt to bypass this, CPSC officials have reportedly suggested—both in private correspondence and public rhetoric—that hospitals failing to participate could face penalties under "information blocking" regulations, a threat that hospital lawyers have labeled as a significant overreach.
The history of the CPSC also casts a shadow over the project. Between 2017 and 2019, the agency was involved in a significant breach that exposed the personal health information of approximately 30,000 individuals. Critics argue that by expanding the volume of data collected and outsourcing it to a third party, the agency is exponentially increasing the risk of another, far more damaging incident.
Institutional Resistance and the "Opt-Out" Struggle
As the CPSC exerts pressure, the medical community is pushing back. The resistance is diverse, spanning from prestigious academic medical centers to large regional health systems.
Boston’s Mass General Brigham has explicitly declined to participate, citing an inability to provide patient medical records due to federal privacy laws. Similarly, officials at Harborview Medical Center in Seattle have clarified that while they have historically submitted de-identified data voluntarily, they view themselves as under no legal obligation to comply with the new, more intrusive demands.

Even hospitals that have historically been cooperative are expressing second thoughts. At Mary Greeley Medical Center in Iowa, the discovery that funding for traditional injury reporting had been cut, coupled with the mandatory nature of the new data-sharing contract, has led leadership to reconsider their involvement.
Broader Policy Context
The CPSC initiative does not exist in a vacuum. It is unfolding alongside a series of broader administrative efforts to aggregate health records. The Office of Personnel Management has sought increased access to the health records of federal employees, and Health and Human Services Secretary Robert F. Kennedy Jr. has utilized private organizations to gather medical data for research on vaccine safety and autism.
Collectively, these initiatives suggest a shift in federal philosophy regarding the ownership and utility of personal health information. The CPSC, however, appears to be moving faster and with less transparency than most. By attempting to convert a system meant for identifying faulty consumer goods into a dragnet for medical records—including diagnoses like vaccine reactions and suicide attempts—the agency is inviting a constitutional and ethical confrontation.
Looking Ahead: The Cost of Modernization
The CPSC maintains that its previous voluntary system was flawed, with the ability of hospitals to opt out limiting the statistical significance of the data. However, former CPSC Chairman Alexander Hoehn-Saric argues that the quality of data is at risk of being diluted. Without the presence of on-site trained human staff to interpret the clinical nuances of an injury, the agency is essentially "sucking in" massive amounts of raw data without a clear strategy for how to prioritize it.
As the agency continues its pursuit of this digital infrastructure, the standoff between federal regulators and hospital systems is likely to intensify. With questions regarding the legality of the "information blocking" threats and the security of patient data still unanswered, the CPSC finds itself at a crossroads: it can either restore trust through transparency and strict privacy safeguards, or it risks alienating the very healthcare partners it needs to fulfill its core mission of protecting the American public.
For now, patients remain largely unaware that their most intimate ER visits may soon be funneled into a federal database managed by a private firm—a reality that, for many, represents a breach of the sacred trust between doctor and patient.