Why is a tiny federal agency demanding detailed medical records from emergency room visits? That’s a question that, as yet, doesn’t have a good answer.
The Consumer Product Safety Commission (CPSC) has been pressuring executives from at least 100 hospitals to start sending detailed medical records by the end of the year, according to an internal memo obtained as part of an investigation by KFF Health News. This would mean that hospitals would be required to hand over the personally identifiable medical records of patients who seek help at emergency rooms to Konza Health, a private contractor working with the federal agency.
Dozens of ERs already voluntarily report information from ER visits that involve injuries from consumer products—information that’s useful for this agency that’s tasked with tracking and issuing recalls of dangerous products. What’s more, a limited number of hospitals previously shared data on all injuries, regardless of whether or not a product was involved, to a program overseen by the Centers for Disease Control and Prevention. But data collection for that program ceased last year amid staffing and funding cuts.
The new surveillance program would collect far more personal information and for a far wider swath of patients—and for purposes that remain unclear. That’s because the new system will collect the medical records of people who visit the ER for one of more than 10,000 conditions, some of which aren’t regulated by the agency and don’t involve consumer products.
What’s more, the federal agency hasn’t yet notified the public that it plans to expand the amount of information it seeks about ER visits, something that is mandated by federal law. Any federal agency must provide a notice and public comment period before it can request information from 10 or more entities, and KFF Health News confirmed that more than a dozen hospitals had been approached about the new mandatory surveillance system.
‘MODERNIZING’ SURVEILLANCE SYSTEM
Ostensibly, the reason the CPSC wants to collect more information is to make improvements. A spokesperson for the agency told KFF Health News that it is “modernizing” its surveillance system.
The outlet obtained an email sent by a program manager working for Konza to a hospital executive in Iowa that likewise noted a modernization effort.
“The current process requires emergency department nurses to review patient charts and manually identify consumer-related incidents and then enter information into a national database,” the letter read. “This is an expensive and inefficient method of data collection.”
PRIVACY CONCERNS
Expanding both the amount and scope of data collected is raising alarm bells among experts, who point to a variety of aspects they find problematic—from the risk of a data breach to a level of surveillance many patients may find disturbing.
What’s more, the changes could actually dilute the quality of the product safety data that the agency is tasked with collecting, according to Alexander Hoehn-Saric, the former chair of the CPSC who was one of three Democratic appointees fired by President Donald Trump in 2025.
“They want to suck in as much data as possible, but I’m not sure how thoughtful they’re being about what is collected and what is actually needed by the agency,” Hoehn-Saric told KFF Health News. “This idea that they can simply demand patient information from a hospital and that the hospital would provide it—I really don’t understand the basis for that.”
There are also lingering questions about the potential use of AI in analyzing data and whether information collected might be used for marketing purposes, though representatives from both CPSC and Konza Health told KFF Health News that AI won’t be used to process records and that their contract prohibits selling or marketing the data collected.
But hiring a private contractor to collect sensitive information introduces new risks for patient privacy, as Sharona Hoffman, a professor of health law at Case Western Reserve University, told KFF Health News. “If this company really is collecting identifiable information, that is worrisome for patients.”
HOSPITALS PUSH BACK
As notices of the new system have gone out, that’s created a hot potato for hospital executives who are tasked with ensuring patient privacy.
There’s also some conflicting messaging. Konza representatives have described the new surveillance system as mandatory, while a CPSC executive has indicated that it’s possible for hospitals to be exempted.
The outlet reported that Elizabeth Puchek, chief data officer at CPSC, has emailed hospitals saying they can seek an exemption from the program if they decline to share patients’ emergency room records with Konza.
And some hospitals seem inclined to do just that.
Seattle-based Harborview Medical Center is among a few identified by KFF Health News that has voluntarily submitted de-identified emergency room data to the agency for years, but will stop.
“We are not obligated to report this information,” a spokesperson told the outlet.
