Key Points
CPSC demands 100 hospitals send all ER records including names and diagnoses to contractor Konza Health by December 31, 2026.
Agency skipped required federal public comment period and previously breached 30,000 people's health data from 2017 to 2019.
Major health systems including Mass General Brigham, Henry Ford Health, and Harborview Medical Center have refused, citing HIPAA violations and legal authority questions.
Old voluntary NEISS system covered 70 hospitals in 36 states; new mandatory system aims to expand to all 50 states.
The Consumer Product Safety Commission is requiring at least 100 hospitals to hand over detailed emergency room records, including patient names, addresses, and diagnoses, to a private contractor by year-end 2026. The agency, normally tasked with tracking injuries from lawn mowers and appliances, began pressuring hospital executives this year to share the data. Hospital lawyers and privacy experts say the move may violate federal law and lacks the legal authority the CPSC claims.
What the CPSC is demanding
The CPSC wants hospitals to provide personally identifiable information on all emergency room visits, not just product-related injuries. Records would cover broken bones, vaccine reactions, suicide attempts, and more than 10,000 diagnostic codes. A CPSC official told hospitals in emails that providing names, addresses, diagnoses, and other personal details to contractor Konza Health is “mandatory” or “required.” The old National Electronic Injury Surveillance System, or NEISS, relied on voluntary participation and de-identified data from roughly 70 hospitals across 36 states.
Why hospitals and lawyers are alarmed
Sharona Hoffman, a health law professor at Case Western Reserve University, told KFF Health News that patient privacy will be at risk. The CPSC’s own operating manual previously instructed hospitals not to include names, birthdates, or addresses in case reports. The agency skipped the federal Paperwork Reduction Act requirement for public notice and comment before collecting private information. Several major health systems, including Mass General Brigham in Boston, Henry Ford Health in Detroit, and Harborview Medical Center in Seattle, have declined or questioned participation citing HIPAA violations and legal obligations.
A history of data breaches at the agency
Between 2017 and 2019, the CPSC improperly released the personal health information of approximately 30,000 people to outside parties including Consumer Reports. The affected individuals were never notified. A Senate investigation found the breach resulted from inadequate training and poor IT management. The agency is now operating without its full governing board and has lost nearly one in five career staff members, raising questions about its ability to safeguard millions of new records.
What happens next
The CPSC announced the program on July 21 but provided no public comment period as required by law. The agency claims the new system, called NEISS-Remodel or NEISS-R, will expand surveillance to all 50 states and improve hazard detection. However, hospital attorneys question whether the CPSC has statutory authority to mandate the reporting of private health data or to penalize hospitals that refuse. Legal challenges are expected.
Final Thoughts
The CPSC’s demand for unredacted ER records from 100 hospitals by year-end 2026 represents the broadest federal reach into hospital patient data in recent memory. With a prior breach affecting 30,000 people and no public comment period, major health systems are resisting. Expect legal battles over the agency’s authority and patient privacy protections.
FAQs
The CPSC says it is modernizing its injury surveillance system to detect product hazards faster and expand coverage to all 50 states. The old system relied on 70 hospitals and left 14 states uncovered.
Names, addresses, diagnoses, and other personally identifiable details for all ER visits, including broken bones, vaccine reactions, suicide attempts, and over 10,000 diagnostic codes unrelated to consumer products.
No. The agency skipped the Paperwork Reduction Act requirement for public notice and comment before collecting private information from hospitals. The program was announced July 21 with no public comment period.
No. Between 2017 and 2019, the CPSC improperly released personal health information of approximately 30,000 people to outside parties. A Senate investigation found inadequate training and poor IT management caused the breach.
Disclaimer:
The content shared by Meyka AI PTY LTD is solely for research and informational purposes. Meyka is not a financial advisory service, and the information provided should not be considered investment or trading advice.
About Author

Danny Kontos
Co FounderDanny Kontos has been a stock investor since 2007 and co-founded Meyka in 2023. He keeps a small, focused portfolio and only moves when the numbers are hard to argue with. He has waited years on a single position before. Before Meyka, he ran a web hosting company and a mortgage lending platform, so he knows what a well-run business actually looks like under the hood. This article did not come from a news cycle. It came from someone who has been watching this space for a long time.
What brings you to Meyka?
Pick what interests you most and we will get you started.
I'm here to read news
Find more articles like this one
I'm here to research stocks
Ask Meyka Analyst about any stock
I'm here to track my Portfolio
Get daily updates and alerts (coming March 2026)