Return To Full Article
You can republish this story for free. Click the "Copy HTML" button below. Questions? Get more details.

Trump Administration Demands Hospitals Share Emergency Room Records

A tiny federal agency tasked with protecting the public from injuries caused by lawn mowers and coffeemakers is demanding that some of the nation鈥檚 biggest health systems turn over detailed, personally identifiable medical records of all patients who seek help at their emergency rooms.

The Consumer Product Safety Commission, responsible for tracking and issuing recalls of dangerous products sold in the U.S., began discreetly pressuring hospital executives this year to share personally identifiable health data with a private contractor. But hospital lawyers and other industry experts have questioned the agency鈥檚 authority to collect, its ability to safeguard such a swath of sensitive information, and whether it has followed the legal process to overhaul its surveillance system.

After 吃瓜不打烊 asked the CPSC about the new system, the the program on July 21. Left unmentioned, however, is the alarm it has raised among hospital executives, as well as the nature and extent of the agency鈥檚 data demands.

In a stark departure from its product-focused mission, the agency鈥檚 goal is to obtain millions of Americans鈥 medical records from emergency room visits for most injuries, from a broken bone to a childhood vaccine reaction or even a suicide attempt, according to documents and emails obtained by 吃瓜不打烊, as well as interviews with five people involved or familiar with the discussions.

A CPSC official also insisted in the emails that the institutions provide all ER patients鈥 identifiable information 鈥 such as names, addresses, diagnoses, and other personal details 鈥 to the contractor, Konza Health, for analysis. In correspondence with , Konza representatives described participation as 鈥渕andatory鈥 or 鈥渞equired.鈥

As a condition of viewing the correspondence, 吃瓜不打烊 agreed not to republish some of the emails it obtained.

The CPSC wants at least 100 hospitals to start sending detailed medical records by the end of this year, according to an .

鈥淭he whole thing is troubling,鈥 said Sharona Hoffman, a professor of health law at Case Western Reserve University who noted that giving a private entity access to a sweeping collection of data will introduce risks to patient privacy. 鈥淚f this company really is collecting identifiable information, that is worrisome for patients.鈥

The new project was launched amid upheaval at the traditionally independent agency, which is without a governing board since President Donald Trump fired the CPSC鈥檚 three Democratic board members. Nearly 1 in 5 career staffers left the CPSC in the first 16 months of the new administration, according to a 吃瓜不打烊 analysis of federal workforce data.

The initiative also comes as the Trump administration has sought unprecedented access to millions of Americans鈥 medical records, with the Office of Personnel Management requesting federal workers鈥 sensitive health information and Health and Human Services Secretary Robert F. Kennedy Jr. using a private organization to collect more medical records for his studies on vaccines and autism.

Steve Roney, CPSC spokesperson, said in an emailed statement on July 10 that the CPSC is 鈥渕odernizing鈥 its surveillance system. Asked whether the CPSC will file complaints against hospitals that do not participate, he said only that while the previous system 鈥渙perated as a voluntary program, the ability of hospitals to opt out limited the sample size and usefulness of the data.鈥

Roney also acknowledged that the agency had not yet notified the public, as 鈥渞equired by law.鈥

Federal law requires the agency to provide notice and a public comment period before requesting information from 10 or more entities, a step it has not taken despite plans for 100 hospitals to join the surveillance system. 吃瓜不打烊 independently confirmed with over a dozen hospitals that they had been approached.

Federal public health authorities that private health data be reported. But CPSC officials have that if hospitals decline to share data with the new surveillance system, they could be subject to strict penalties from a data-sharing regulation known as 鈥渋nformation blocking.鈥

Yet some hospital executives say they are reluctant to share patients鈥 sensitive data because they鈥檙e concerned about a different violation 鈥 that of .

AI Takes Over

Dozens of ERs across the country already participate in the CPSC鈥檚 voluntary National Electronic Injury Surveillance System, or NEISS, through which trained hospital workers report injuries involving consumer products, almost always stripped of patients鈥 identifiable information. The system helps the CPSC identify products, such as baby loungers, toys, and household appliances, with a pattern of injuring consumers.

The new injury surveillance program goes much further.

At a toy industry trade event in February, acting CPSC Chairman Peter Feldman said the agency is 鈥渋nvesting in AI-enabled workflows that improve the quality and quantity of injury surveillance data, while also building up digital infrastructure to handle a massive new volume of electronic health records.鈥

Konza Health, a Kansas-based organization that runs the state鈥檚 health data exchange, will automatically pull and analyze medical records of all patient visits from ERs nationwide. Konza won a worth up to $15.9 million with the CPSC last fall.

In email correspondence with hospital technology officials, Konza Health President and CEO Laura McCrary also has described ERs鈥 participation as 鈥渞equired,鈥 stipulating that they share patients鈥 records with identifying information.

McCrary told 吃瓜不打烊 by email that the company is not using AI to process the records it receives, saying instead that Konza will use 鈥渁dvanced analytic parsing and filtering capabilities.鈥 Roney, the CPSC spokesperson, did not answer questions about the .

For years, agency officials moving away from human contractors and automating NEISS to save time and money.

But without workers on-site, hospital staffers may no longer receive training to determine what clinical information is important to include for the CPSC. In short, the changes could dilute the quality of the product safety data the agency collects.

鈥淭hey want to suck in as much data as possible, but I鈥檓 not sure how thoughtful they鈥檙e being about what is collected and what is actually needed by the agency,鈥 said former CPSC chair Alexander Hoehn-Saric, one of the Democratic appointees Trump fired last year.

Record Number of Career Staff Left CPSC Last Year (Column Chart)

Wanted: Injuries From Vaccines and Stingrays

The CPSC鈥檚 new data collection appears to contradict its own 214-page , which instructs hospitals not to include identifiable information 鈥渟uch as names, birthdates, or addresses鈥 when reporting cases.

The agency is supposed to receive patients鈥 identifying information only when needed for follow-up investigations, which happens in fewer than 1% of reported cases, according to the manual.

The CPSC has also historically limited the records it collects to minimize privacy violations in case of a data breach.

The risk is not hypothetical: From 2017 to 2019, the agency improperly released personal health information of around 30,000 people, a disclosure that a top Republican at the time

Konza, however, will receive even more sensitive information on many more people. McCrary said in a statement that Konza will remove patients鈥 names, addresses, and medical information 鈥渘ot needed by CPSC鈥 before sharing records with the agency.

Leaving a private organization to collect sensitive information introduces risks, including that it could be stolen or used for business purposes, said Hoffman, the Case Western professor.

鈥淰ery often, they will use information for marketing because now they鈥檙e going to know what conditions people have,鈥 she said.

Roney said that its contract with Konza, which has not been made public, prohibits the organization from selling or marketing the data it collects.

The CPSC鈥檚 manual also identifies types of ER visits that should not be reported to the CPSC, which has jurisdiction over only certain consumer products. Excluded injuries are those caused by food, illegal drugs, medical devices, alcohol, or plants, as well as injuries that did not involve consumer products 鈥 such as a cut from a rock or broken bones from a fall on the ground 鈥 and suicide attempts by adults.

But in a to one hospital and reviewed by 吃瓜不打烊, Konza set no such limits on the information it would gather from ER records and said it would hold on to patient health information for at least 30 days.

In an email sent to hospital technology officials, McCrary wrote that Konza would provide the CPSC with records when a patient is treated in the ER for any of more than 10,000 conditions. The expansive list of diagnostic codes Konza provided in the email includes injuries that do not involve consumer products.

Child injuries resulting from 鈥減oisoning by鈥 vaccines or contact with stingrays, neither of which is regulated by the CPSC, are included in the list.

A limited number of hospitals once shared deidentified data on all injuries 鈥 regardless of product involvement 鈥 through the NEISS using the Centers for Disease Control and Prevention鈥檚 injury-tracking program. But the CDC halted that data collection, after funding and staffing were cut last year, and has not restarted it.

Pressure on Hospitals

CPSC Chief Data Officer Elizabeth Puchek, who joined the agency late last year after engineering U.S. Citizenship and Immigration Services鈥 data system, has told hospitals in emails that they must seek an exemption from the program if they decline to share patients鈥 emergency room records with Konza.

The CPSC鈥檚 targeted outreach has included some of the nation鈥檚 largest urban and rural health systems, as well as small, publicly owned hospitals.

Staff members at Mary Greeley Medical Center in Ames, Iowa, said that Konza and federal officials told them their participation in the new program was mandatory. The hospital, which has long participated in NEISS, signed a new contract in April to share its ER records with Konza.

Yet the hospital is reevaluating its participation after being notified that the funds it received to participate in NEISS were 鈥渘o longer available,鈥 spokesperson Steve Sullivan said.

Several hospital executives, lawyers, and others have raised doubts about the CPSC鈥檚 claimed authority.

Harborview Medical Center spokesperson Susan Gregg said the Seattle hospital鈥檚 emergency room has 鈥渧oluntarily submitted de-identified data for many years, but we are not obligated to report this information.鈥

In Boston, Mass General Brigham has declined to participate in the new program, with spokesperson Kelly Mitchell saying that 鈥渢o protect patient privacy, we are unable to provide these medical records.鈥

Henry Ford Health in Detroit; St. Luke鈥檚 in Boise, Idaho; and Sanford Health based in Sioux Falls, South Dakota 鈥 which together handle over a million ER visits a year 鈥 are among the health systems that have been approached but not yet entered into an agreement with Konza, according to representatives. Several of the nation鈥檚 busiest hospital systems targeted for the program 鈥 including the Mayo Clinic in Minnesota, Yale New Haven Hospital in Connecticut, Nationwide Children鈥檚 Hospital and the Cleveland Clinic in Ohio, and Baylor Scott & White Health in Texas 鈥 declined to answer questions about whether they鈥檙e participating.

Hoehn-Saric, the agency鈥檚 former chairman, said he was surprised that the CPSC would insist that hospitals provide identifiable records from all emergency room visits.

鈥淭his idea that they can simply demand patient information from a hospital and that the hospital would provide it 鈥 I really don鈥檛 understand the basis for that,鈥 he said.

吃瓜不打烊 is a national newsroom that produces in-depth journalism about health issues and is one of the core operating programs at KFF鈥攁n independent source of health policy research, polling, and journalism. Learn more about .

Help 吃瓜不打烊 track this article

By including these elements when you republish, you help us:
  • Understand which communities and people we鈥檙e reaching.
  • Measure the impact of our health journalism.
  • Continue providing free, high-quality health news to the public.
Canonical Tag

Include this in your page's <head> section to properly attribute this content.

Tracking Snippet

Add this snippet at the end of your republished article to help us track its reach.