The Consumer Product Safety Commission wants names, addresses, and diagnoses for every emergency room patient at 100 hospitals, routed through a private contractor.

 

What happened

The Consumer Product Safety Commission has been pressing hospital executives to share personally identifiable medical records for all emergency department patients with a private contractor, KFF Health News reported on July 27, 2026, based on documents, emails, and interviews with five people involved in the discussions. The contractor is Konza Health, a Kansas organization that runs that state's health data exchange and won a five-year contract worth up to $15.9 million last fall. An internal agency memo puts the target at 100 hospitals sending records by the end of 2026. The agency announced the program publicly on July 21, after KFF Health News asked about it. Reporters independently confirmed with more than a dozen hospitals that they had been approached.

 

Going deeper

The existing National Electronic Injury Surveillance System has run for decades on a different model, with trained hospital staff reporting product-related injuries almost always stripped of identifying details. The replacement would have Konza pull records automatically for more than 10,000 diagnostic codes, a list that includes injuries the agency does not regulate, such as childhood reactions coded as poisoning by vaccines and contact with stingrays. The agency's own 214-page coding manual instructs hospitals to leave out identifiable details such as names, birthdates, and addresses, and excludes whole categories of visits including injuries from food, alcohol, medical devices, and plants. Identifying information is supposed to reach the agency only for follow-up investigations, which the manual puts at fewer than 1% of reported cases. A contract offered to one hospital and reviewed by KFF Health News set no limits on what would be collected and allowed Konza to hold patient health information for at least 30 days.

 

What was said

"The whole thing is troubling," said Sharona Hoffman, a professor of health law at Case Western Reserve University, who told KFF Health News that handing a private entity a sweeping collection of records introduces privacy risk. CPSC spokesperson Steve Roney said the agency is modernizing its surveillance system and, when asked whether it would file complaints against hospitals that decline, said only that under the previous voluntary program the ability to opt out "limited the sample size and usefulness of the data." Alexander Hoehn-Saric, a former CPSC chairman removed by the administration last year, questioned the premise: "I really don't understand the basis for that."

 

In the know

Refusals are already accumulating. Mass General Brigham has declined outright, with a spokesperson saying the system is unable to provide the records to protect patient privacy, according to KFF Health News. Harborview Medical Center said it has submitted de-identified data voluntarily for years without any obligation to report. Henry Ford Health, St. Luke's in Boise, and Sanford Health have been approached without entering agreements. Agency officials have suggested that hospitals declining could face penalties under the information blocking rule, which applies to providers, certified health IT developers, and health information networks, and which carries nine exceptions including one for privacy where a precondition of applicable law has not been satisfied. Roney acknowledged the agency had not yet given the public notice required by law, a step federal rules require before requesting information from ten or more entities.

 

The big picture

Compliance officers weighing a request like this face a narrow question rather than a political one. The Privacy Rule permits disclosure to a public health authority authorized by law to collect information for preventing or controlling injury, alongside other limits on use and disclosure, and the minimum necessary standard applies to what leaves the building. A request covering all emergency visits across 10,000 diagnostic codes, including categories the agency's own manual excludes, invites a documented analysis of what the authority actually reaches. The agency disputes the characterization of what it will hold, telling BankInfoSecurity that Konza's role is to extract the limited product-injury data needed and remove identifying information before anything reaches the CPSC, and that identifiable information does not leave the network. History gives hospitals a reason to ask how that will be enforced, since the agency improperly released the personal health information of roughly 30,000 people between 2017 and 2019, a data breach that drew a written complaint from a senior Republican senator at the time.

 

FAQs

Does HIPAA permit disclosing records to a federal agency without patient authorization?

The Privacy Rule allows disclosure to public health authorities legally authorized to collect information for preventing or controlling disease or injury, without authorization. The permission turns on the agency's actual legal authority to collect the specific information requested, which is what several hospitals in this case have questioned.

 

Would the contractor be a business associate?

That depends on whether it is performing a function on behalf of the covered entity or receiving the data as a recipient in its own right. Organizations should establish which arrangement applies before transmitting anything, since the answer determines whether a business associate agreement is required and who carries breach notification duties.

 

What does the minimum necessary standard require here?

Covered entities must limit disclosures to the amount reasonably necessary for the stated purpose. Where a requester asks for categories the requester's own documentation excludes from its remit, the entity should document its analysis of what portion is necessary rather than transmitting the full request by default.

 

Can declining a federal data request count as information blocking?

Not automatically. The rule contains nine exceptions, including a privacy exception covering situations where a precondition under applicable law has not been met, and practices falling outside every exception are still evaluated case by case rather than penalized on sight. Actors carry the burden of showing their practice fits an exception.

 

What should a hospital document when it receives a request like this?

The specific legal authority cited, the exact data elements and codes requested, the intended recipients and retention period, the minimum necessary analysis performed, and the basis for whatever decision follows. Contemporaneous documentation is what supports the position later if a regulator or an oversight body asks.