Trump administration demands hospitals share emergency room records

A tiny federal agency tasked with protecting the public from injuries caused by lawn mowers and coffeemakers is demanding that some of the nationβs biggest health systems turn over detailed, personally identifiable medical records of all patients who seek help at their emergency rooms.
The Consumer Product Safety Commission, responsible for tracking and issuing recalls of dangerous products sold in the U.S., began discreetly pressuring hospital executives this year to share personally identifiable health data with a private contractor. But hospital lawyers and other industry experts have questioned the agencyβs authority to collect, its ability to safeguard such a swath of sensitive information, and whether it has followed the legal process to overhaul its surveillance system.
After KFF Health News asked the CPSC about the new system, the agency announced the program on July 21. Left unmentioned, however, is the alarm it has raised among hospital executives, as well as the nature and extent of the agencyβs data demands.
In a stark departure from its product-focused mission, the agencyβs goal is to obtain millions of Americansβ medical records from emergency room visits for most injuries, from a broken bone to a childhood vaccine reaction or even a suicide attempt, according to documents and emails obtained by KFF Health News, as well as interviews with five people involved or familiar with the discussions.
A CPSC official also insisted in the emails that the institutions provide all ER patientsβ identifiable information β such as names, addresses, diagnoses, and other personal details β to the contractor, Konza Health, for analysis. In correspondence with hospital executives, Konza representatives described participation as βmandatoryβ or βrequired.β
As a condition of viewing the correspondence, KFF Health News agreed not to republish some of the emails it obtained.
The CPSC wants at least 100 hospitals to start sending detailed medical records by the end of this year, according to an internal memo.
Related: EMS workers struggling with burnout
βThe whole thing is troubling,β said Sharona Hoffman, a professor of health law at Case Western Reserve University who noted that giving a private entity access to a sweeping collection of data will introduce risks to patient privacy. βIf this company really is collecting identifiable information, that is worrisome for patients.β
The new project was launched amid upheaval at the traditionally independent agency, which is without a governing board since President Donald Trump fired the CPSCβs three Democratic board members. Nearly 1 in 5 career staffers left the CPSC in the first 16 months of the new administration, according to a KFF Health News analysis of federal workforce data.
The initiative also comes as the Trump administration has sought unprecedented access to millions of Americansβ medical records, with the Office of Personnel Management requesting federal workersβ sensitive health information and Health and Human Services Secretary Robert F. Kennedy Jr. using a private organization to collect more medical records for his studies on vaccines and autism.
Steve Roney, CPSC spokesperson, said in an emailed statement on July 10 that the CPSC is βmodernizingβ its surveillance system. Asked whether the CPSC will file complaints against hospitals that do not participate, he said only that while the previous system βoperated as a voluntary program, the ability of hospitals to opt out limited the sample size and usefulness of the data.β
Roney also acknowledged that the agency had not yet notified the public, as βrequired by law.β
Federal law requires the agency to provide notice and a public comment period before requesting information from 10 or more entities, a step it has not taken despite plans for 100 hospitals to join the surveillance system. KFF Health News independently confirmed with over a dozen hospitals that they had been approached.
Federal public health authorities cannot legally mandate that private health data be reported. But CPSC officials have suggested publicly and privately that if hospitals decline to share data with the new surveillance system, they could be subject to strict penalties from a data-sharing regulation known as βinformation blocking.β
Yet some hospital executives say they are reluctant to share patientsβ sensitive data because theyβre concerned about a different violation β that of federal privacy law.
AI Takes Over
Dozens of ERs across the country already participate in the CPSCβs voluntary National Electronic Injury Surveillance System, or NEISS, through which trained hospital workers report injuries involving consumer products, almost always stripped of patientsβ identifiable information. The system helps the CPSC identify products, such as baby loungers, toys, and household appliances, with a pattern of injuring consumers.
Related: Trump admin threatening deferral of Medicaid payments
The new injury surveillance program goes much further.
At a toy industry trade event in February, acting CPSC Chairman Peter Feldman said the agency is βinvesting in AI-enabled workflows that improve the quality and quantity of injury surveillance data, while also building up digital infrastructure to handle a massive new volume of electronic health records.β
Konza Health, a Kansas-based organization that runs the stateβs health data exchange, will automatically pull and analyze medical records of all patient visits from ERs nationwide. Konza won a five-year contract worth up to $15.9 million with the CPSC last fall.
In email correspondence with hospital technology officials, Konza Health President and CEO Laura McCrary also has described ERsβ participation as βrequired,β stipulating that they share patientsβ records with identifying information.
McCrary told KFF Health News by email that the company is not using AI to process the records it receives, saying instead that Konza will use βadvanced analytic parsing and filtering capabilities.β Roney, the CPSC spokesperson, did not answer questions about the use of AI.
For years, agency officials have discussed moving away from human contractors and automating NEISS to save time and money.
But without workers on-site, hospital staffers may no longer receive training to determine what clinical information is important to include for the CPSC. In short, the changes could dilute the quality of the product safety data the agency collects.
βThey want to suck in as much data as possible, but Iβm not sure how thoughtful theyβre being about what is collected and what is actually needed by the agency,β said former CPSC chair Alexander Hoehn-Saric, one of the Democratic appointees Trump fired last year.

Wanted: Injuries From Vaccines and Stingrays
The CPSCβs new data collection appears to contradict its own 214-page operating manual, which instructs hospitals not to include identifiable information βsuch as names, birthdates, or addressesβ when reporting cases.
The agency is supposed to receive patientsβ identifying information only when needed for follow-up investigations, which happens in fewer than 1% of reported cases, according to the manual.
The CPSC has also historically limited the records it collects to minimize privacy violations in case of a data breach.
Related: Vaccine hesitancy doubles number of measles vaccine exemptions
The risk is not hypothetical: From 2017 to 2019, the agency improperly released personal health information of around 30,000 people, a disclosure that a top Republican at the time called βconcerning.β
Konza, however, will receive even more sensitive information on many more people. McCrary said in a statement that Konza will remove patientsβ names, addresses, and medical information βnot needed by CPSCβ before sharing records with the agency.
Leaving a private organization to collect sensitive information introduces risks, including that it could be stolen or used for business purposes, said Hoffman, the Case Western professor.
βVery often, they will use information for marketing because now theyβre going to know what conditions people have,β she said.
Roney said that its contract with Konza, which has not been made public, prohibits the organization from selling or marketing the data it collects.
The CPSCβs manual also identifies types of ER visits that should not be reported to the CPSC, which has jurisdiction over only certain consumer products. Excluded injuries are those caused by food, illegal drugs, medical devices, alcohol, or plants, as well as injuries that did not involve consumer products β such as a cut from a rock or broken bones from a fall on the ground β and suicide attempts by adults.
But in a contract offered to one hospital and reviewed by KFF Health News, Konza set no such limits on the information it would gather from ER records and said it would hold on to patient health information for at least 30 days.
In an email sent to hospital technology officials, McCrary wrote that Konza would provide the CPSC with records when a patient is treated in the ER for any of more than 10,000 conditions. The expansive list of diagnostic codes Konza provided in the email includes injuries that do not involve consumer products.
Child injuries resulting from βpoisoning byβ vaccines or contact with stingrays, neither of which is regulated by the CPSC, are included in the list.
A limited number of hospitals once shared deidentified data on all injuries β regardless of product involvement β through the NEISS using the Centers for Disease Control and Preventionβs injury-tracking program. But the CDC halted that data collection, after funding and staffing were cut last year, and has not restarted it.
Pressure on Hospitals
CPSC Chief Data Officer Elizabeth Puchek, who joined the agency late last year after engineering U.S. Citizenship and Immigration Servicesβ data system, has told hospitals in emails that they must seek an exemption from the program if they decline to share patientsβ emergency room records with Konza.
Related: USCIS emphasizes βgood moral characterβ qualification in citizenship process
The CPSCβs targeted outreach has included some of the nationβs largest urban and rural health systems, as well as small, publicly owned hospitals.
Staff members at Mary Greeley Medical Center in Ames, Iowa, said that Konza and federal officials told them their participation in the new program was mandatory. The hospital, which has long participated in NEISS, signed a new contract in April to share its ER records with Konza.
Yet the hospital is reevaluating its participation after being notified that the funds it received to participate in NEISS were βno longer available,β spokesperson Steve Sullivan said.
Several hospital executives, lawyers, and others have raised doubts about the CPSCβs claimed authority.
Harborview Medical Center spokesperson Susan Gregg said the Seattle hospitalβs emergency room has βvoluntarily submitted de-identified data for many years, but we are not obligated to report this information.β
In Boston, Mass General Brigham has declined to participate in the new program, with spokesperson Kelly Mitchell saying that βto protect patient privacy, we are unable to provide these medical records.β
Henry Ford Health in Detroit; St. Lukeβs in Boise, Idaho; and Sanford Health based in Sioux Falls, South Dakota β which together handle over a million ER visits a year β are among the health systems that have been approached but not yet entered into an agreement with Konza, according to representatives. Several of the nationβs busiest hospital systems targeted for the program β including the Mayo Clinic in Minnesota, Yale New Haven Hospital in Connecticut, Nationwide Childrenβs Hospital and the Cleveland Clinic in Ohio, and Baylor Scott & White Health in Texas β declined to answer questions about whether theyβre participating.
Hoehn-Saric, the agencyβs former chairman, said he was surprised that the CPSC would insist that hospitals provide identifiable records from all emergency room visits.
βThis idea that they can simply demand patient information from a hospital and that the hospital would provide it β I really donβt understand the basis for that,β he said.
KFF Health News is a national newsroom that produces in-depth journalism about health issues and is one of the core operating programs at KFFβan independent source of health policy research, polling, and journalism. Learn more about KFF.
This article first appeared on KFF Health News and is republished here under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.
![]()
The post Trump administration demands hospitals share emergency room records appeared first on MinnPost.