The Consumer Product Safety Commission (CPSC), the federal agency charged with tracking consumer-product injuries and issuing recalls, has initiated a plan to collect detailed emergency department records from U.S. hospitals. The agency aims to enroll at least 100 hospitals to begin sending comprehensive ER records by the end of the year, according to an internal CPSC memo reviewed by KFF Health News. This represents a departure from the long-standing, largely voluntary National Electronic Injury Surveillance System (NEISS) model, which historically collected deidentified information on product-related injuries.
The new effort is described by CPSC officials as a modernization of its surveillance infrastructure intended to increase the quantity and quality of injury data. The program relies on a private contractor, Konza Health, to pull and analyze medical records from participating emergency departments.
Konza Health, a Kansas-based organization that operates the state’s health information exchange, holds a five-year contract with the CPSC worth up to $15.9 million. Konza representatives have communicated with hospital technology officials that participation by ERs is “required,” and in at least one case offered a contract that specified the contractor would retain patient health information for at least 30 days.
Konza’s president and CEO told KFF Health News the company will not use AI to process records but will employ “advanced analytic parsing and filtering capabilities.” The CPSC has publicly discussed investing in AI-enabled workflows to handle a larger volume of electronic health records, though questions remain about exactly which automated methods will be used in practice.
Emails and contract materials obtained by KFF Health News indicate Konza would receive personally identifiable information including names, addresses, diagnoses and other personal details for ER visits. Konza informed hospitals it would provide the CPSC with records when a patient was treated in the ER for any of more than 10,000 diagnostic codes.
That diagnostic list reportedly includes conditions that do not involve consumer products and therefore fall outside the CPSC’s regulatory jurisdiction, such as vaccine reactions and certain wildlife injuries. Konza stated it would remove identifying details and any medical information “not needed by CPSC” before sharing records with the agency, but the initial transfer to Konza would contain identifying data.
Federal law requires agencies to provide public notice and an opportunity for comment when requesting information from 10 or more entities. As of the reporting, the CPSC had not provided the required public notice, despite targeting roughly 100 hospitals.
Some CPSC communications have suggested that hospitals declining to share data could face penalties under a regulation related to information blocking, while hospitals have raised concerns that complying could violate federal privacy protections, including HIPAA. Legal experts and hospital counsel have questioned the CPSC’s statutory authority to compel identifiable medical records and whether the agency has followed legally required procedures to expand its surveillance system.
Experts cited by KFF Health News warned that routing identifiable patient records to a private contractor increases risks of unauthorized use, marketing, or data theft. The CPSC previously improperly released personal health information for about 30,000 people between 2017 and 2019, a lapse that underscores concerns about data security and limiting collection to what is necessary.
Konza and CPSC statements assert contractual prohibitions on selling or marketing collected data and indicate Konza will scrub unnecessary identifiers before passing records to the agency. Nevertheless, observers noted that entrusting a private organization with a broad pool of identifiable records creates additional privacy and compliance risks.
CPSC outreach has included a mix of large urban health systems, regional systems, and small public hospitals. Dozens of ERs already participate in NEISS by submitting deidentified, product-focused reports; the new program would expand the type and identifiability of data collected.
Some hospitals have signed new agreements to share ER records with Konza. Mary Greeley Medical Center in Ames, Iowa, which historically participated in NEISS, signed a new contract in April but later said it was reevaluating participation after notification that prior NEISS funds were no longer available. Other major health systems contacted — including Mass General Brigham — have declined to provide identifiable records, citing patient privacy. Several high-volume systems targeted for the program either declined to comment or said they had not yet entered agreements.
Hospital representatives and former CPSC leadership have expressed surprise and concern that the agency is insisting on identifiable records for all ER visits rather than limiting collection to cases relevant to the CPSC’s consumer-product mission.
CPSC officials have argued that the previous, largely voluntary NEISS approach limited sample size and usefulness because hospitals could opt out. The agency hopes automated, large-scale data collection will enhance its ability to detect injury patterns linked to consumer products.
Critics warn that removing trained hospital reporters and relying on automated extraction could dilute the clinical specificity and relevance of what is captured. The NEISS manual historically instructed hospitals not to include identifiers and to limit reporting to product-linked injuries; expanding collection to all ER diagnoses may generate a larger but less targeted dataset and raise persistent privacy and legal questions.
CPSC spokesperson Steve Roney described the project as modernizing surveillance and acknowledged the agency had not yet provided public notice required by law. Konza’s CEO said the firm would strip identifying data not needed by the CPSC and that the company is not employing AI for record processing. Legal and privacy experts, as well as a former CPSC chair, have questioned the agency’s authority, the sufficiency of safeguards, and whether the changes will produce the intended improvements without undue risk to patient privacy.
Details about the full terms of the CPSC–Konza contract and the agency’s planned public notice and comment process were not reported in the KFF Health News article.