CPSC Request for Hospital Emergency Room Data Raises HIPAA Privacy Concerns

The United States Consumer Product Safety Commission (CPSC) is seeking to collect digital patient data from hospitals for the National Electronic Injury Surveillance System (NEISS) Remodel project, prompting concerns about the scope of information requested and its compatibility with HIPAA requirements.

What is the NEISS Remodel Project?

For more than 5 decades, NEISS has been collecting information on consumer product-related injuries in the United States. The current system manually reviews and codes medical records from about 70 of the nation’s 5,000+ hospital emergency departments. Fourteen states are not currently represented in the project. The limited geographic coverage has reduced CPSC’s ability to identify rare and emerging product hazards.

The planned NEISS Remodel, or NEISS-R, project would expand coverage to all 50 states. The project would automate data collection through electronic health record infrastructure and exchange information through a federally designated Qualified Health Information Network, or QHIN.

CPSC says the collected and retained data are limited to the minimum necessary information to fulfill its mission. The system also supports de-identification of the information before reaching CPSC.

CPSC awarded Konza Health in Kansas a $15.9 million contract in 2025 to support the NEISS Remodel project. CPSC is aiming to collect the requested information from over 100 hospitals by the end of 2026.

Automated Collection of Patient Data

Under the existing system, emergency department nurses review patient charts, identify consumer-related accidents, and enter information into a national database.

Under NEISS-R, data collection would be automated. Konza Health, also known as TEFCA QHIN, would be responsible for removing identifying information before data transfers to CPSC.

Letters sent by Konza Health to hospitals describe a process in which accident-related diagnosis codes would be used to identify patients who may have experienced consumer product-related accidents. Konza Health would then request additional clinical information for identified accidents and provide that information to CPSC for follow-up. The letters also request meetings with selected hospitals to establish connectivity methods for secure data exchange.

Scope of Requested Information

Privacy concerns have been raised because the automated process would involve identifiable patient information being sent to Konza Health. With the previous manual system, nurses were directed not to give identifiable information, including patient names, birth dates or addresses.

The information requested through the automated system may extend beyond data related to consumer product injuries. KFF Health News reported that the requested information could include medical records from emergency room visits involving injuries ranging from broken bones to childhood vaccine reactions and suicide attempts.

Communications between Konza Health and technology officials at one hospital indicated that emergency room data was requested for more than 10,000 conditions, including injuries unrelated to consumer products. The broader request has led to resistance from some hospitals. CPSC and Konza Health have suggested that refusing to provide required data could be viewed as information blocking and could result in penalties.

HIPAA Privacy Requirements

The hospitals are not required, under HIPAA, to submit data to CPSC, but may be permitted, for public health purposes. Disclosures must be limited to the minimum necessary information for the purpose of the disclosure.

Because CPSC is collecting information to fulfill its consumer product safety mission, the disclosed data should be limited to that purpose. If CPSC needs more data than waht it previously gathered, additional rulemaking would be needed. The HIPAA Minimum Necessary Rule is relevant to the requested disclosures. The disclosures should be restricted to information required for CPSC’s public health activities concerning consumer product safety.

The information blocking regulations contain a privacy exception intended to prevent health information from being required to be disclosed in a manner prohibited by state or federal privacy laws.

There is a potential compliance conflict for participating hospitals. For example, the hospitals that decline to provide requested information could face potential information blocking penalties. The hospitals that provide information could face potential HIPAA penalties if the disclosure does not comply with HIPAA requirements.

Consumer Reports Position

Consumer Reports supports the NEISS program and has supported strengthening the system because it provides information about products associated with injuries. William Wallace, Director of Safety Advocacy at Consumer Reports, said the organization supports modernizing how CPSC collects and analyzes emergency room data but objects to collecting personal medical records that are unrelated to consumer product safety.

Consumer Reports has called for CPSC to abandon plans to collect patients’ personal information from emergency room visits. The organization also called for CPSC to provide information about what it would collect, how the information would be analyzed, and how sensitive information would be protected before changing the NEISS program.

Consumer Reports also called for CPSC to make its contract with Konza Health public and to provide a complete proposal for public comment.

Elizabeth Hernandez

Elizabeth Hernandez is the editor of HIPAA News section of HIPAA Coach and an experienced journalist in the healthcare sector. She specializes in healthcare and HIPAA compliance, making her a go-to source for information on healthcare regulations. Her work focuses on the importance of patient privacy and secure information handling. Elizabeth also has a postgraduate degree in journalism. Follow on Twitter: You can follow Elizabeth on twitter at https://twitter.com/ElizabethHzone