[[DATA PRIVACY CONCERNS ERODE TRUST IN FEDERAL SAFETY AGENCY’S NEW MEDICAL RECORD INITIATIVE]]
A small federal safety agency, best known for recalling hazardous consumer products like coffee makers and lawn equipment, has quietly initiated a sweeping program demanding emergency rooms across the country surrender patients’ personally identifiable medical records.
The Consumer Product Safety Commission (CPSC) began pressuring major health systems this year to share sensitive patient data with private contractor Konza Health, prompting immediate pushback from hospital executives and legal experts questioning both the agency’s authority and data protection practices.
While the CPSC publicly announced the program following inquiries from KFF Health News, details revealed through obtained documents and confidential interviews show the agency seeks comprehensive medical records – including names, addresses, diagnoses, and treatment details – from thousands of hospitals nationwide.
According to KFF Health News’ investigation, the agency intends to collect records covering virtually all emergency room injuries – from fractures and vaccine reactions to mental health crises – arguing the expanded scope will improve consumer product safety investigations. The initiative aims to enroll at least 100 hospitals before year’s end, despite lacking proper legal notices to participating institutions.
“Let me be clear, this goes against Federal Privacy Law,” said FDA Commissioner Robert Califf in a July statement. “I’m not surprised they’re making these demands, but it’s reckless and illegal. Patient information in the hands of CPSC could result in unnecessary education and prosecution of health providers.”
The expansion coincides with significant turmoil within the CPSC, including staff turnover and controversial leadership changes under the current administration. The agency’s aggressive data collection approach mirrors other Trump-era health data initiatives, including HHS Secretary Robert F. Kennedy Jr.’s controversial vaccine research partnerships.
CPSC spokesperson Steve Roney defended the program as a modernization effort, acknowledging past voluntary reporting systems suffered from limited participation. However, he failed to clarify whether hospitals refusing to comply might face enforcement actions under federal information blocking regulations.
Privacy advocates warn the requirement to share identifiable data with a commercial entity presents significant risks, citing the agency’s own history of improper health data disclosures. Konza Health, which will store records for 30 days before sharing with CPSC, claims to redact non-essential information – a claim contradicted by their expanded scope documents.
The new program builds on the CPSC’s existing voluntary injury reporting system, NEISS, which previously collected anonymized injury data.
Health systems interviewed by KFF Health News received contradictory messages – some were told participation was mandatory while others were informed they could withdraw at any time. Major health networks like Mayo Clinic and Cleveland Clinic remain undecided, while Mass General Brigham explicitly declined participation citing privacy obligations.
Independent legal experts express skepticism about the agency’s claimed authority, questioning how it can legally demand sensitive information from protected health information databases without proper regulatory filings or public comment periods.
The program’s implementation coincides with broader concerns about federal data collection practices and the potential misuse of sensitive health information in politically charged investigations.”
Also Read
- NHS Patient Records Transfer to US Private Equity Firm Raises Governance Concerns
- Prime Minister Commits Political Resources to Overhaul Social Care Framework
- Crystalys Therapeutics Secures $130M to Advance Gout Drug Through Clinical Trials
- This Week in Medicine: Censorship Claims, Funding Gaps, and Calls for Oversight


