A tiny federal agency in the US, tasked with protecting the public from injuries caused by lawnmowers and items like household appliances, is demanding that some of the nation’s biggest health systems turn over detailed, personally identifiable medical records of all patients who seek help at their emergency rooms, reports KFF Health News.
The Consumer Product Safety Commission (CPSC), responsible for tracking and issuing recalls of dangerous products sold in the US, began discreetly pressuring hospital executives this year to share personally identifiable health data with a private contractor.
But hospital lawyers and other industry experts have questioned the agency’s authority to collect, its ability to safeguard such sensitive information, and whether it has followed the legal process to overhaul its surveillance system.
After KFF Health News asked the CPSC about the new system, the agency announced the programme on 21 July. Left unmentioned, however, is the alarm it has raised among hospital executives, as well as the nature and extent of the agency’s data demands.
In a stark departure from its product-focused mission, the agency’s goal is to obtain millions of Americans’ medical records from emergency room visits for most injuries, from a broken bone to a childhood vaccine reaction or even a suicide attempt, according to documents and emails obtained by KFF Health News, as well as interviews with five people involved or familiar with the discussions.
A CPSC official also insisted in the emails that the institutions provide all ER patients’ identifiable information – names, addresses, diagnoses, and other personal details – to the contractor, Konza Health, for “analysis”.
In correspondence with hospital executives, Konza representatives described participation as “mandatory” or “required”.
The CPSC wants at least 100 hospitals to start sending detailed medical records by the end of this year, according to an internal memo.
“The whole thing is troubling,” said Sharona Hoffman, a professor of health law at Case Western Reserve University, who noted that giving a private entity access to a sweeping collection of data will introduce risks to patient privacy. “If this company really is collecting identifiable information, that is worrisome for patients.”
The new project was launched amid upheaval at the traditionally independent agency, which is without a governing board since President Donald Trump fired the CPSC’s three Democratic board members. Almost a fifth of the career staffers left the CPSC in the first 16 months of the new administration.
The initiative also comes as the Trump administration has sought unprecedented access to millions of Americans’ medical records, with the Office of Personnel Management requesting federal workers’ sensitive health information and Health and Human Services Secretary Robert F. Kennedy Jr. using a private organisation to collect more medical records for his studies on vaccines and autism.
Steve Roney, CPSC spokesperson, said the CPSC is “modernising” its surveillance system. Asked whether the CPSC will file complaints against hospitals that do not participate, he said only that while the previous system “operated as a voluntary programme, the ability of hospitals to opt out limited the sample size and usefulness of the data”.
Roney also acknowledged that the agency had not yet notified the public, as “required by law”.
Federal law requires the agency to provide notice and a public comment period before requesting information from 10 or more entities, a step it has not taken despite plans for 100 hospitals to join the surveillance system.
Public health authorities also cannot legally mandate that private health data be reported. But CPSC officials have suggested publicly and privately that if hospitals decline to share data with the new surveillance system, they could be subject to strict penalties from a data-sharing regulation known as “information blocking”.
Yet some hospital executives say they are reluctant to share patients’ sensitive data because they’re concerned about a different violation – that of federal privacy law.
AI takes over
Dozens of ERs countrywide already participate in the CPSC’s voluntary National Electronic Injury Surveillance System, or NEISS, through which trained hospital workers report injuries involving consumer products, almost always stripped of patients’ identifiable information.
The system helps the CPSC identify products, like baby loungers, toys, and household appliances, with a pattern of injuring consumers.
The new injury surveillance programme goes much further.
Konza Health, a Kansas-based organisation that runs the state’s health data exchange, will automatically pull and analyse medical records of all patient visits from ERs nationwide.
Konza won a five-year contract worth up to $15.9m with the CPSC last year.
In email correspondence with hospital technology officials, Konza Health President and CEO Laura McCrary also has described ERs’ participation as “required”, stipulating that they share patients’ records with identifying information.
McCrary told KFF Health News that the company is not using AI to process the records it receives, saying instead that Konza will use “advanced analytic parsing and filtering capabilities”.
For years, agency officials have discussed moving away from human contractors and automating NEISS to save time and money.
But without workers on-site, hospital staffers may no longer receive training to determine what clinical information is important to include for the CPSC. In short, the changes could dilute the quality of the product safety data the agency collects.
“They want to suck in as much data as possible, but I’m not sure how thoughtful they’re being about what is collected and what is actually needed by the agency,” said former CPSC chair Alexander Hoehn-Saric, whom Trump fired last year.
The CPSC’s new data collection appears to contradict its own 214-page operating manual, which instructs hospitals not to include identifiable information “such as names, birthdates, or addresses” when reporting cases.
The agency is supposed to receive patients’ identifying information only when needed for follow-up investigations, which happens in fewer than 1% of reported cases, according to the manual.
The CPSC has also historically limited the records it collects to minimise privacy violations in case of a data breach.
The risk is not hypothetical: from 2017 to 2019, the agency improperly released personal health information of around 30 000 people.
Konza, however, will receive even more sensitive information on many more people, and despite claiming it will remove patients’ names, addresses, and medical information “not needed by CPSC” before sharing records with the agency, allowing a private organisation to collect sensitive information introduces risks, including that it could be stolen or used for business purposes, said Hoffman, the Case Western professor.
“Very often, they will use information for marketing because now they’re going to know what conditions people have,” she said.
Roney said its contract with Konza, which has not been made public, prohibits the organisation from selling or marketing the data it collects.
The CPSC’s manual also identifies types of ER visits that should not be reported to the CPSC, which has jurisdiction over only certain consumer products. Excluded injuries are those caused by food, illegal drugs, medical devices, alcohol, or plants, as well as injuries that did not involve consumer products – such as a cut from a rock or broken bones from a fall on the ground – and suicide attempts by adults.
But in a contract offered to one hospital and reviewed by KFF Health News, Konza set no such limits on the information it would gather from ER records and said it would hold on to patient health information for at least 30 days.
In an email sent to hospital technology officials, McCrary wrote that Konza would provide the CPSC with records when a patient is treated in the ER for any of more than 10 000 conditions. The expansive list of diagnostic codes Konza provided in the email includes injuries that do not involve consumer products.
Child injuries resulting from “poisoning by” vaccines or contact with stingrays, neither of which is regulated by the CPSC, are included in the list.
A limited number of hospitals once shared de-identified data on all injuries – regardless of product involvement – through the NEISS using the Centre for Disease Control and Prevention’s injury-tracking programme. But the CDC halted that data collection, after funding and staffing were cut last year, and has not restarted it.
Pressure on hospitals
CPSC Chief Data Officer Elizabeth Puchek, who joined the agency late last year after engineering US Citizenship and Immigration Services’ data system, has told hospitals in emails that they must seek an exemption from the programme if they decline to share patients’ emergency room records with Konza.
The CPSC’s targeted outreach has included some of the country’s largest urban and rural health systems, as well as small, publicly-owned hospitals.
Staff at Mary Greeley Medical Centre in Iowa, said Konza and federal officials told them their participation in the new programme was mandatory. The hospital, which has long participated in NEISS, signed a new contract in April to share its ER records with Konza.
Yet the hospital is re-evaluating its participation after being notified that the funds it received to participate in NEISS were “no longer available”, spokesperson Steve Sullivan said.
Several hospital executives, lawyers, and others have raised doubts about the CPSC’s claimed authority.
In Boston, Mass General Brigham has declined to participate in the new programme, with spokesperson Kelly Mitchell saying that “to protect patient privacy, we are unable to provide these medical records”.
Several of the nation’s busiest hospital systems targeted for the programme – including the Mayo Clinic in Minnesota, Yale New Haven Hospital in Connecticut, Nationwide Children’s Hospital and the Cleveland Clinic in Ohio, and Baylor Scott & White Health in Texas – declined to answer questions about whether they’re participating.
Hoehn-Saric, the agency’s former chairman, said he was surprised that the CPSC would insist hospitals provide identifiable records from all emergency room visits.
“This idea that they can simply demand patient information … and that the hospital would provide it – I really don’t understand the basis for that,” he said.
See more from MedicalBrief archives:
Experts call for legal framework for patients’ data
Medical providers most likely to be the culprits in health data breaches
POPIA is coming into force – are you ready?
