Law and Governmentcpsc emergency room data collection
Summary (tl;dr)
The Trump administration, via the Consumer Product Safety Commission (CPSC), is controversially demanding that at least 100 U.S. hospitals share detailed, personally identifiable emergency room records, raising significant privacy and legal concerns.
Essential Background
For over 45 years, the U.S. Consumer Product Safety Commission (CPSC) has operated the National Electronic Injury Surveillance System (NEISS), a voluntary program collecting anonymized data from a sample of hospital emergency departments to track consumer product-related injuries nationwide. This system helped identify product hazards, initiate recalls, and develop safety standards. The previous NEISS manual specifically instructed hospitals not to include personally identifiable information in reports.
The Full Story
The Trump administration has recently directed the Consumer Product Safety Commission (CPSC) to overhaul its injury surveillance system, moving from the voluntary, anonymized NEISS to a new initiative, NEISS-R, which mandates that at least 100 hospitals nationwide provide detailed, personally identifiable emergency room records to a private contractor, Konza Health. This includes sensitive data like patients' names, addresses, diagnoses, and can cover a wide array of incidents from broken bones to vaccine reactions and even suicide attempts. The CPSC formally announced this new program on July 21, 2026, describing it as a modernization to improve data accuracy and enable faster product safety interventions. However, hospital executives and legal experts across the country are raising alarms, questioning the CPSC's legal authority to compel such data sharing, its ability to protect patient privacy, and its failure to provide a legally required public notice and comment period for this expanded data collection. Several health systems, including Mass General Brigham, Henry Ford Health, and Harborview Medical Center, have already expressed their reluctance or declined to participate.
Why It Matters
This shift in data collection is sparking a significant debate over patient privacy, federal overreach, and the legal boundaries of government agencies. Critics argue that the demand for personally identifiable information, especially by a private contractor, poses substantial risks to patient confidentiality and could potentially violate federal privacy laws like HIPAA. The lack of public comment and the CPSC's assertion that participation is "mandatory" also raise concerns about due process and transparency. While the CPSC states the aim is to modernize and improve product safety, the broad scope of data requested—including non-product-related injuries—and the agency's recent internal upheavals (including dismissals of board members and staff turnover) further fuel skepticism among healthcare providers and privacy advocates. The outcome of this initiative could set a precedent for how federal agencies collect and use sensitive health data in the future.
Geographic Location
- Washington, D.C., District of Columbia, United States (location of Consumer Product Safety Commission, federal agency mandating data collection)
- Kansas, United States (location of Konza Health, the private contractor receiving the data)
- Boston, Suffolk County, Massachusetts, United States (Mass General Brigham declined or questioned participation)
- Detroit, Wayne County, Michigan, United States (Henry Ford Health declined or questioned participation)
- Seattle, King County, Washington, United States (Harborview Medical Center declined or questioned participation)