The Consumer Product Safety Commission (CPSC) is pressuring hospitals to provide personally identifiable medical records from emergency-room visits as part of an expanded injury-surveillance effort, according to reporting by KFF Health News that draws on internal documents. Hospitals—at least 100, per an internal memo—are being asked to send detailed records to Konza Health, a private contractor working with the agency, with requests tied to records covering tens of thousands of conditions rather than only consumer-product injuries. The expanded scope would require hospitals to transfer identifiable information about patients who come to emergency departments for more than 10,000 conditions, including some not related to products regulated by CPSC.
The CPSC and Konza describe the effort as “modernizing” a system that currently relies on manual chart review by emergency-department nurses to identify consumer-related incidents. The disclosures are raising privacy concerns, including risks of data breaches and broader surveillance of patients. Experts also question the agency’s legal authority and whether the agency is complying with federal notice and public-comment requirements for collecting information from 10 or more entities.
KFF Health News reports hospitals received differing messages about whether participation is mandatory and whether exemptions are available. Some hospitals that previously shared de-identified data say they will stop, and at least one described the reporting as not required.