The pipeline

Every emergency room in the country already reports some data voluntarily to CPSC's National Electronic Injury Surveillance System (NEISS) — but only injuries tied to consumer products, and only stripped of anything that identifies the patient. That's the system that's caught patterns in baby loungers, toys, and household appliances for decades.

What's being built now is different in kind, not just degree. According to internal emails and a contract reviewed by KFF Health News — the outlet that broke this story, in reporting independently confirmed for this piece — CPSC wants all ER visits, for any reason, from at least 100 hospitals by the end of 2026, complete with patients' names, addresses, and diagnoses. Konza Health, a Kansas-based organization that runs that state's health data exchange, would automatically pull and analyze those records under a five-year contract worth up to $15.9 million, awarded last fall. In correspondence with hospital executives, Konza representatives described participation as "mandatory" or "required."

Acting CPSC Chairman Peter Feldman previewed part of this at a toy-industry trade event in February, saying the agency is "investing in AI-enabled workflows that improve the quality and quantity of injury surveillance data, while also building up digital infrastructure to handle a massive new volume of electronic health records."

A desk covered in labeled evidence: a folder stack marked ER RECORDS, NAMES, ADDRESSES, DIAGNOSES, and ER INTAKE RECORDS sits next to a tube of records marked PRIVATE CONTRACTOR and tagged $15.9M CONTRACT, a box marked CPSC REQUEST, and a wall sign reading PUBLIC NOTICE NOT FOUND What's actually changing hands: identifiable records, run through a private contractor, under a multimillion-dollar contract — without the public notice federal law requires. Original illustration for The BL:UF.

The agency's press release leaves out what its own paper trail shows

CPSC didn't announce this program voluntarily — it did so only after KFF Health News asked about it, publishing a press release on July 21 or 22 (the two accounts differ by a day) describing the effort as "modernizing" its injury-surveillance system.

Here's what's worth sitting with, precisely: CPSC's own announcement says the new system will "support de-identification before information reaches CPSC." Konza's CEO, Laura McCrary, told KFF in a statement that Konza "will remove patients' names, addresses, and medical information 'not needed by CPSC'" before records reach the agency. Neither of those two statements is necessarily false on its own — but neither says what hospitals are actually being asked to send Konza in the first place, which internal correspondence and the contract itself describe as fully identifiable data, participation framed to hospital executives as mandatory. The press release doesn't mention Konza by name. It doesn't mention that hospitals were told sharing was required. It doesn't mention the public-notice requirement CPSC hasn't met. What the agency told the public and what its own paperwork shows aren't the same story — not because the press release states something untrue, but because it leaves out everything about the program that would raise a question.

The legal problem CPSC's own spokesperson admits

Federal law — the Paperwork Reduction Act, specifically 44 U.S.C. § 3506(c)(2)(A), with the "10 or more entities" threshold defined in § 3502(3)(A) — requires an agency to publish notice and accept public comment before collecting identical information from 10 or more entities. CPSC is targeting at least 100 hospitals. It hasn't done this.

This isn't a technicality CPSC is unaware of. CPSC spokesperson Steve Roney said in a July 10 emailed statement that the agency is "modernizing" its surveillance system, and acknowledged the agency had not yet notified the public as "required by law." Asked whether CPSC would take action against hospitals that decline to participate, he said only that the old system's voluntary, opt-out structure "limited the sample size and usefulness of the data" — not a denial that the new one is different.

What makes this more pointed: CPSC has a clean, current compliance record for its old program. Federal Register filings from February and May of 2025 show CPSC properly running the required 60-day comment period for the existing, voluntary, de-identified NEISS system, under OMB control numbers already on the books. That paper trail exists. No equivalent filing exists anywhere — not on regulations.gov, not in the Federal Register — for the new, identifiable, 100-hospital program. The agency knows how to do this correctly. It did it correctly for the old system. It hasn't done it for the new one.

A threat that may not hold up

CPSC has suggested, publicly and privately, that hospitals which decline to share data could face penalties under a federal rule called "information blocking" — part of the 21st Century Cures Act, written by HHS's health-IT policy office (ONC, renamed ASTP in 2023) with civil penalties for entities like health information networks enforced through the HHS Office of Inspector General. That rule exists to stop hospitals from improperly refusing legitimate requests to access, exchange, or use electronic health information — a patient asking for their own chart, or one provider requesting records from another for treatment.

It was not built, and has no legal track record, as a tool for compelling compliance with a federal agency's request that hasn't itself gone through the legal process required to make it official. No court has tested whether it can be used this way. As KFF's reporting puts it plainly: "federal public health authorities cannot legally mandate that private health data be reported." Whether "information blocking" penalties could actually survive a legal challenge on these specific facts is untested — but CPSC has raised it as a consequence regardless.

It's also worth knowing CPSC's own track record with data it already collects. CPSC's Office of Inspector General found that a breach the agency initially described as spanning 2017-2019 — and initially said involved 29 to 36 recipients — actually dated back to at least 2010 and involved CPSC employees improperly releasing sensitive information in 1,725 emails to 556 recipients, plus an unsecured shared drive hundreds of unauthorized staff could access. CPSC's original estimate put the toll at approximately 30,000 people and 10,900 businesses — but the OIG found that estimate itself was incomplete, and its own recommendations call on CPSC to still establish an accurate final count. The OIG's own report states plainly that the breach was "not the result of outside hackers gaining access to the CPSC's information technology (IT) systems," but was "caused by a combination of mismanagement and incompetence" — including senior managers who, the report says, signed statements affirming effective internal controls "despite knowing this was not true." A separate Senate Commerce Committee investigation produced its own report on the same breach in October 2019. Neither report resulted in a fine or a binding corrective-action order — only 40 non-binding OIG recommendations, which the agency "generally concurred" with, and the OIG report itself notes CPSC "has a history of concurring with but not promptly implementing audit recommendations." That's the closest thing to a precedent for what happens if something goes wrong with the much larger volume of identifiable data CPSC is now asking for.

If the data really is stripped before CPSC sees it, who's checking — and what if it isn't?

CPSC's press release and Konza's own statement both describe some form of de-identification happening before records reach the agency. Nobody — not CPSC, not Konza, not any reporting on this program — has explained why hospitals need to send fully identifiable data to Konza in the first place if the goal is a de-identified result. One plausible technical reason: Konza describes itself as a federally designated "Qualified Health Information Network," and that kind of system's core function is matching the same patient's records across different providers, which requires identifiers to do the matching before anything gets aggregated or stripped. That's a reasonable inference about how these systems generally work — it is not something anyone in this specific program has actually said, and it shouldn't be mistaken for a stated justification.

It's also not clear what legal framework governs Konza's handling of the data, or what happens if something goes wrong. Two different regimes could apply, with very different consequences. If Konza is bound as a HIPAA "business associate," current federal penalty tiers run up to $2,190,294 per violation, with the company independently liable regardless of what the hospitals did. If instead Konza is operating purely as a federal contractor under the Privacy Act, the criminal penalty for a willful violation is a misdemeanor capped at $5,000 — against a contract worth up to $15.9 million. No public source states which of these applies, and the CPSC-Konza contract itself has not been made public; the only description of its privacy terms is CPSC's own unverified claim that it bars Konza from selling or marketing the data.

No GAO report, no CPSC Inspector General review, and no contract-mandated independent audit of this specific program turned up in a search of the public record. Kansas does regulate Konza, but only in its separate role running that state's own health information exchange — a different function from the nationwide ER-data pipeline it's building for CPSC. As it stands, every claim about how this data will be kept safe is coming from the same organizations being asked to safeguard it, with no named outside party confirmed to be checking.

Not the only agency asking

This isn't an isolated CPSC initiative. It's the third medical-records story in a pattern documented by the same KFF Health News reporting team over the past four months:

  • In April, KFF reported that the Office of Personnel Management demanded monthly medical claims, pharmacy, and encounter data from 65 insurers covering more than 8 million federal workers, retirees, members of Congress, postal workers, and their families — through its own Paperwork Reduction Act filing. Sixteen U.S. senators wrote to OPM Director Scott Kupor demanding it be withdrawn, in a separate letter from a second one led by Rep. Robert Garcia and other House Democrats.
  • In June, KFF reported that HHS Secretary Robert F. Kennedy Jr. is collecting medical records for vaccine and autism research through state and regional health information exchanges — most concretely Nebraska's CyncHealth, which received $13.6 million in state contracts after Nebraska's health department got an $18.7 million CDC grant, with CyncHealth keeping $2.4 million for Kennedy's initiative. Maryland and Indiana exchanges have also been approached. HHS hasn't publicly confirmed the project's full scope.

Sharona Hoffman, a health law professor at Case Western Reserve University, has been quoted across more than one of these stories making the same underlying point — in the CPSC story: "The whole thing is troubling... If this company really is collecting identifiable information, that is worrisome for patients." In the OPM story: "the more information they have, they could use it to discipline or target people who are not cooperating politically."

What connects these three, and what doesn't, is worth being precise about. In March 2025, President Trump signed Executive Order 14243, "Stopping Waste, Fraud, and Abuse by Eliminating Information Silos," directing federal agencies broadly — a definition that would sweep in CPSC as an independent agency — to tear down barriers to inter-agency data sharing and review their privacy notices for elimination or modification. The timing lines up: Konza's contract was awarded roughly six months after that order. But KFF's CPSC reporting does not cite the order by name, and nothing in the public record directly ties CPSC's program to it. The honest version of this: the order created conditions where an expansion like this one would face less internal resistance — it does not prove CPSC's specific program was ordered or directed by it. Treat the connection as context, not as a proven cause.

Who's said yes, who's said no

Some hospitals have already pushed back. Mass General Brigham in Boston told KFF it is "unable to provide these medical records." Harborview Medical Center in Seattle said it voluntarily sends de-identified data only and "we are not obligated to report this information." Henry Ford Health, St. Luke's in Boise, and Sanford Health in Sioux Falls have been approached but haven't agreed. Mayo Clinic, Yale New Haven, Nationwide Children's, Cleveland Clinic, and Baylor Scott & White all declined to answer KFF's questions about it.

At least one hospital already signed on — Mary Greeley Medical Center in Ames, Iowa, in April — and is now reevaluating, according to KFF's reporting.

The American Hospital Association has not made a public statement on this specific program as of this writing.

What this piece is not saying

This isn't saying CPSC has already obtained identifiable records from 100 hospitals — it's asking, and some hospitals have said no. It isn't saying CPSC's press release contains a false statement — the de-identification line and Konza's own "not needed by CPSC" language may both be technically accurate as far as they go. It isn't saying the "information blocking" threat has been used or tested in any actual case — it's been raised as a possibility, not deployed. It isn't saying Executive Order 14243 ordered this specific program — that link is timing, not documentation. And it isn't saying every hospital contacted has objected — several have engaged without committing either way, and one already agreed. What's established: CPSC is seeking data well beyond its historical mandate, through a mechanism its own spokesperson admits skipped a legally required step, using a threat whose legal footing hasn't been tested, while its public description of the program leaves out the parts — Konza's role, the "mandatory" language hospitals were given, the missed legal notice — that would tell the public what's actually being asked of them.

What can I do?

There's no open public comment docket for this program yet — because CPSC hasn't filed the one the law requires. That itself is worth knowing: there's currently no formal federal channel for the public to weigh in, though CPSC's failure to open one is itself the kind of thing that can be raised directly with the agency or with a member of Congress.

If you've been treated at an ER recently: you can ask your hospital directly whether it participates in CPSC's new injury-surveillance program (distinct from the older, voluntary NEISS) and whether your identifiable information was shared. Hospitals are not obligated to share this data absent a properly completed federal rulemaking — Harborview and Mass General Brigham's responses show declining is a real option institutions are exercising.

Contact CPSC directly, since no formal comment docket exists yet: CPSC's official contact page lists the agency's phone line, mailing address, and web form for public inquiries and complaints.

Read KFF Health News's full original investigation, including the internal emails and contract language this piece draws on: "CPSC Wants Hospitals to Report Identifiable ER Data," by Amanda Seitz, Maia Rosenfeld, and Darius Tahir.

The Receipts