The Consumer Product Safety Commission is pressing hospitals to hand over emergency room records for a remodeled injury surveillance system, drawing privacy objections and raising questions about HIPAA compliance.
By the end of the year, the CPSC wants more than 100 hospitals feeding digital patient data to Konza Health, a Kansas contractor awarded a $15.9M contract to support the NEISS Remodel project. The new National Electronic Injury Surveillance System replaces a manual process in which ER nurses reviewed charts and coded consumer product-related injuries, expanding coverage to all 50 states through electronic health record infrastructure and a Qualified Health Information Network.
KFF Health News reported that emails and interviews show the agency is seeking identifiable patient data, including names, addresses, and diagnoses, for ER visits tied to more than 10,000 conditions, many unrelated to consumer products, such as vaccine reactions and suicide attempts. A CPSC official allegedly insisted hospitals provide all ER patients’ identifiable information to Konza Health for analysis.
The demand puts hospitals between two regulatory risks. Refusing could be treated as information blocking with significant penalties, while sharing beyond what CPSC’s consumer product safety mission requires could run afoul of the HIPAA minimum necessary standard. Under current rules, hospitals may disclose data to CPSC for public health purposes but are not required to, and the privacy exception to information blocking protects disclosures prohibited by federal privacy law.
