The Consumer Product Safety Commission, a small federal agency, is requiring hospitals to provide detailed medical records of emergency room patients, including names, addresses, and diagnoses.
The agency, which monitors injuries from consumer products like lawn mowers and coffeemakers, began pressing hospital executives earlier this year to share personally identifiable health data with a private contractor. The request has raised concerns among hospital lawyers and privacy experts about legal authority and data protection.
Agency shifts from voluntary reporting to mandatory data demands
The CPSC’s new surveillance system represents a significant change from its National Electronic Injury Surveillance System (NEISS), which depends on voluntary reporting from about 100 hospitals. Under NEISS, trained staff submit anonymized injury reports involving consumer products, allowing the agency to identify dangerous trends in household items.
The updated program, disclosed in July, would require hospitals to automatically send all emergency room records—regardless of whether a consumer product was involved—to a private contractor. The agency aims to enroll at least 100 hospitals by year’s end, according to an internal memo.
In emails to hospital leaders, representatives described participation as mandatory. The contractor, which manages health data exchange, would analyze records for injuries, including those unrelated to consumer products, such as vaccine reactions.
Related: Can Video Games Improve Focus and Concentration?
The CPSC’s operating manual instructs hospitals to exclude identifiable information unless needed for follow-up investigations, which occur in fewer than 1% of cases. Yet the agency now seeks those details for every ER visit, contradicting its own policies.
Hospitals push back over privacy concerns and legal authority
Several major health systems have refused to comply, citing patient privacy and legal risks. Hospitals resisting the request worry about violating the Health Insurance Portability and Accountability Act (HIPAA), which restricts sharing patient records.
The agency’s authority to demand such data remains unclear. Federal law requires public notice and a comment period before collecting information from 10 or more entities, a step the CPSC skipped despite targeting 100 hospitals. A spokesperson acknowledged in July that the agency had not followed this requirement.
Data security risks and broader implications
The CPSC’s expanded surveillance effort comes amid internal challenges. Nearly 20% of its staff left in the first 16 months of the Trump administration, and it has operated without a governing board since the president removed its three Democratic members. The initiative aligns with broader federal efforts to access medical records, including requests from the Office of Personnel Management and Health and Human Services Secretary Robert F. Kennedy Jr. for vaccine-related data.
The contractor has promised to remove unnecessary personal details before sharing records with the CPSC, but privacy experts warn that entrusting a private contractor with sensitive data creates risks. Sharona Hoffman, a health law professor at Case Western Reserve University, noted that giving a private entity access to a sweeping collection of data will introduce risks to patient privacy.
Related: Fasting and Liposomal Vitamin C Target Cancer
The CPSC’s manual excludes certain injuries, such as those caused by food, illegal drugs, or suicide attempts. However, the contract with one hospital, reviewed by journalists, set no such limits and required retaining patient records for at least 30 days.
Mary Greeley Medical Center in Iowa, which signed a contract in April, is reconsidering after losing its NEISS funding. “We are reevaluating our participation,” a spokesperson said.
At a toy industry event in February, acting CPSC Chair Peter Feldman mentioned the agency was “investing in AI-enabled workflows” to improve injury tracking. A spokesperson later clarified that the contractor is not using AI but “advanced analytic parsing” to process records. The agency has not explained how it will ensure data quality without trained hospital staff reviewing cases.
The CPSC has previously mishandled sensitive information. From 2017 to 2019, it improperly released health data of about 30,000 people, an incident a lawmaker called troubling. With the new system, the agency would collect far more data, increasing the risk of another breach.
Concerns about human desire and motivation extend beyond medical privacy, highlighting how data misuse can affect public trust.
