Skip to content

Regulation

Why CPSC's ER Records Demand Is Legally Untested

By Editorial TeamUpdated Aug 3, 2026
Authority
U.S. Consumer Product Safety Commission
Rule type
regulation
Jurisdiction scope
US federal
Effective date
Jul 22, 2026
Source text
Read primary rule text ↗

Hospitals should verify CPSC's authority and privacy limits before transmitting identifiable emergency-department records under NEISS-R.

Regulation & Ethics obligations-tracker record. Last verified: August 3, 2026 (UTC). The live issue is not whether the Consumer Product Safety Commission may modernize injury surveillance. The narrower issue is whether the agency’s NEISS-R push for identifiable emergency-department records has a tested legal foundation, when the public announcement emphasizes privacy by design and the reported hospital-facing materials describe broader, identifiable data demands.

Hospital emergency department records flowing toward a government data hub, divided by a red fault line between public documents and internal memos
IssueCurrent status as of August 3, 2026Why it matters for counsel
Public NEISS-R modernization announcementConfirmed. CPSC announced on July 22, 2026 that it was modernizing the National Electronic Injury Surveillance System and described the change as faster, broader, and privacy-conscious.[1]This is the agency’s public baseline, but it does not by itself answer what hospitals are being asked to transmit.
Agency legal-position pageConfirmed. CPSC’s NEISS page states the agency’s position that it is a public health authority, cites HIPAA’s public-health disclosure provision at 45 C.F.R. § 164.512(b), and invokes information-blocking rules under 45 C.F.R. Part 171.[2]These are asserted authorities, not a court ruling or a NEISS-R-specific rulemaking record.
Legacy NEISS operating baselineConfirmed. The January 2025 NEISS coding manual tells hospitals to exclude identifiers from regular NEISS coding and describes identifiable follow-up collection as limited to less than 1% of NEISS cases.[3]That baseline is materially different from a routine feed of identifiable emergency-room records.
Most recent identified PRA noticeConfirmed. The February 27, 2025 Federal Register notice covered the legacy NEISS collection under OMB Control No. 3041-0029 and described 1.15 million reportable records from about 4.5 million reviewed charts.[4]No NEISS-R-specific Federal Register notice was identified in this verification pass.
Hospital-facing demand recordReported. KFF Health News reported internal emails, memos, contract details, and hospital responses describing a target of 100 hospitals by the end of 2026, mandatory language, identifiable records, and no prior public notice.[5]This is the main gap: the reported operational ask is more intrusive than the public-facing modernization description.
Formal litigation, oversight letters, new Federal Register notice, or published Konza contract specific to NEISS-RNone identified in this research pass as of August 3, 2026.The legal concerns are active and material, but still largely untested in formal public channels.

The gap is the risk signal

CPSC’s July 22 announcement is written as a modernization notice: an old injury-surveillance system is being updated so the agency can detect product hazards faster and protect more people. That mission is not peripheral. NEISS has long been one of the federal government’s core tools for tracking consumer-product injuries treated in emergency departments, and a stale data pipeline can leave real hazards buried in paper or delayed abstractions.

The legal concern starts where the public description stops. The announcement does not resolve whether hospitals are being asked to send identifiable emergency-room records at scale, whether that collection has been noticed under the Paperwork Reduction Act for this revised program, or whether the agency’s HIPAA and information-blocking theories will survive review in the form now being pressed.

KFF’s July 27 report is the documentable source for the sharper version of the problem. It reported that internal materials showed CPSC seeking to expand participation to 100 hospitals by the end of 2026, that hospitals were told participation was mandatory, and that the data demands included identifiable emergency-room records rather than only de-identified coded injury reports.[5] KFF also reported contract details involving Konza Health, including a five-year, $15.9 million figure drawn from USAspending and a proposed contract term allowing retention of protected health information for at least 30 days; in this verification pass, the USAspending page itself could not be independently reviewed beyond a shell page, so that contract amount remains reported through KFF rather than independently confirmed here.[5]

That distinction matters in a board memo. A confirmed CPSC press release and a reported set of internal hospital-facing demands do not carry the same evidentiary weight. They do, however, create a live mismatch that cannot be responsibly collapsed into “the agency modernized NEISS.” If a hospital is being asked to transmit identifiable emergency-department records now, counsel needs the authority chain for that ask, not only the public rationale for a modernization project.

What changed from the legacy NEISS baseline

The January 2025 NEISS coding manual is the cleanest baseline because it is CPSC’s own operating document. It instructs coders to exclude identifiers from NEISS records and says identifiable information is collected only for follow-up investigations involving less than 1% of NEISS cases.[3] That is not the same operational model as routine collection of identifiable emergency-room records for a modernized intake system.

The February 2025 Federal Register notice likewise describes the legacy collection. It states that CPSC expected about 1.15 million reportable records from approximately 4.5 million reviewed charts under OMB Control No. 3041-0029.[4] That notice is useful precisely because it is ordinary administrative paper: it tells counsel what was publicly described before NEISS-R became the current dispute.

The record also contains unresolved figure conflicts. CPSC’s July 2026 release describes legacy NEISS as involving about 70 hospitals, while CPSC’s NEISS page describes about 100 hospitals.[1][2] Foley & Lardner’s client alert describes the legacy system as producing about 400,000 records annually and says the modernized program could rise to about 2 million records, while the February 2025 Federal Register notice uses the separate 1.15 million reportable-records figure from about 4.5 million reviewed charts.[9][4] Those figures may be measuring different things, but this record does not harmonize them without a source document that does the work.

The authority map is still mostly an asserted map

CPSC’s public legal position has two main prongs. First, the agency says it is a public health authority for HIPAA purposes and points to 45 C.F.R. § 164.512(b), the provision allowing covered entities to disclose protected health information to public health authorities for specified public-health activities.[2] Second, it invokes the information-blocking rules at 45 C.F.R. Part 171, framing refusal to provide electronic health information as potentially problematic under that regime.[2]

For a hospital privacy officer, the first question is not whether those citations exist. They do. The question is whether the particular NEISS-R demand being made to a particular hospital fits the cited authority, including the scope of the records requested, the identifiers included, any state-law limits, the role of a contractor, and the absence so far of a NEISS-R-specific public notice or adjudicated decision.

Authority or objectionCurrent source postureCounsel-facing significance
HIPAA public-health-authority theoryAgency claim. CPSC’s NEISS page states that CPSC is a public health authority and cites 45 C.F.R. § 164.512(b).[2]The cited pathway may matter, but the record identified no court ruling applying it to the reported NEISS-R identifiable-records demand.
Information-blocking theoryAgency claim. CPSC’s NEISS page invokes 45 C.F.R. Part 171.[2]The agency is presenting access as legally required, but the theory has not been tested publicly in this NEISS-R setting.
Paperwork Reduction Act objectionDocument-grounded objection. The last identified Federal Register notice covered legacy NEISS and its existing burden estimates, not a separately noticed NEISS-R identifiable-records program.[4]If the operational collection materially changed, counsel will look for the missing NEISS-R-specific PRA record.
State-law privacy varianceOutside analysis. Melissa Soliz described multiple possible HIPAA pathways and warned that state privacy law may vary in ways hospitals cannot ignore.[8]A HIPAA disclosure theory does not automatically end the state-law analysis for every hospital.
Contractor and retention questionsReported. KFF reported Konza-related contract details, including PHI retention for at least 30 days, but the published contract record was not identified in this pass.[5]Counsel cannot assess data handling, downstream use, or audit rights cleanly without the operative contract terms.

Soliz’s interview is useful because it does not pretend HIPAA has only one door. She described three possible HIPAA pathways and warned that state-law variation remains part of the analysis.[8] That is the right level of caution for this stage: the presence of a federal disclosure permission, if applicable, does not make every operational demand settled, and it does not erase the need to verify state-specific obligations.

The privacy history does not prove the current claim, but it changes how assurances should be read

There is a prior CPSC privacy-management record that deserves limited, careful use. In 2020, the CPSC Office of Inspector General reported an improper release of health information affecting 30,000 people, involving 1,725 emails sent to 556 recipients, and described mismanagement and incompetence while making 40 recommendations.[6] Senator Roger Wicker had raised formal Senate Commerce Committee concerns about the breach in an October 16, 2019 letter to CPSC.[7]

That history is not evidence that NEISS-R is presently mishandling data. It is evidence that privacy assurances from this agency should be evaluated against controls, contracts, retention limits, and audit trails rather than accepted as a complete risk answer. The difference is not semantic. A breach report is institutional history; it is not proof of current misconduct.

Who is exposed to the uncertainty

Hospitals sit first in the line of consequence because they are the entities asked to transmit records. The American Hospital Association framed the announcement for hospitals shortly after the CPSC release, and the Emergency Nurses Association separately issued a statement addressing emergency-department patient information.[10][11] Their posture matters less as a vote count than as a signal that this is already an operational healthcare compliance issue, not merely a consumer-product policy update.

Manufacturers and product-liability litigants are not bystanders. Foley & Lardner warned that a larger NEISS-R data stream could create reliability and litigation issues if records are unverified or are treated as evidence of product hazards in ways that shift burdens in product-liability disputes.[9] That concern is downstream from the hospital privacy question, but it is not remote. Injury-surveillance data can migrate quickly from public-health signal to enforcement context to private litigation exhibit.

Public-interest groups are also split in ways that do not reduce to a simple privacy-versus-safety frame. Consumer Federation of America objected to the personal-health-data demands while still operating from a consumer-safety perspective.[12] That is a useful reminder that the debate is not whether injury surveillance matters. The contested point is whether this particular identifiable-records path has been justified, limited, and publicly tested.

Konza and analytics: reported, contested, and not yet contract-clean

KFF reported Konza Health contract details and described internal materials involving advanced analytic parsing and filtering capabilities, while also reporting a denial from Konza’s CEO that the system uses artificial intelligence.[5] That leaves a definitional uncertainty rather than a clean finding. “AI-enabled” may be a fair shorthand in some technology discussions, but it is too loose for this record unless tied to the exact contract language or a tested technical description.

For present purposes, the stronger concern is simpler: the operative contract record was not identified as a published document in this verification pass. Without it, counsel cannot confirm retention terms, subcontractor controls, permitted uses, security obligations, breach duties, audit rights, or whether the contractor’s role changes the HIPAA and state-law analysis.

What to watch next

The next useful developments are not more generalized statements that modernization is good or bad. The record needs procedural and legal anchors.

  • A NEISS-R-specific Federal Register notice or PRA submission that describes the revised collection, the identifiers requested, the hospitals covered, the burden estimate, and the role of any contractor.
  • A published Konza contract, statement of work, data-use agreement, or comparable record showing retention, security, audit, and permitted-use limits.
  • A court challenge or administrative decision testing CPSC’s HIPAA public-health-authority and information-blocking theories in this setting.
  • Formal congressional, state-attorney-general, or inspector-general oversight directed at NEISS-R rather than earlier CPSC privacy incidents.
  • A narrower agency limitation on identifiable data collection, including whether identifiers are required routinely, only temporarily, or only for follow-up investigations.
  • Hospital-facing correspondence that clarifies whether participation is mandatory, what refusal consequences CPSC asserts, and how the agency applies information-blocking rules to nonparticipation.

Until one of those anchors appears, the safest status description is not “illegal” and not “resolved.” It is legally untested, materially contested, and actively track. That is a narrower conclusion, but it is the one the current source record supports.

References

  1. CPSC Modernizes Decades-Old Injury Surveillance System to Protect More Americans Faster, U.S. Consumer Product Safety Commission, July 22, 2026.
  2. What is NEISS, U.S. Consumer Product Safety Commission.
  3. January 2025 NEISS Coding Manual (Rev 1.0), U.S. Consumer Product Safety Commission, January 2025.
  4. Agency Information Collection Activities; Extension of Collection; Comment Request; National Electronic Injury Surveillance System (NEISS), Federal Register, February 27, 2025.
  5. Trump Administration Demands Hospitals Share Emergency Room Records, KFF Health News, July 27, 2026.
  6. CPSC OIG Clearinghouse Data Breach Investigation Report, Office of Inspector General, September 25, 2020.
  7. Scanned Wicker Letter 10 16 2019, U.S. Senate Committee on Commerce, Science, and Transportation, October 16, 2019.
  8. CPSC’s Push for Patient Data Raises Privacy and Legal Questions, Healthcare Innovation, July 31, 2026.
  9. CPSC Announces Updated National Electronic Injury Surveillance System, Foley & Lardner, July 24, 2026.
  10. Consumer Product Safety Commission Announces Modernization of National Consumer Product Injury Database, AHA News, July 24, 2026.
  11. ENA Statement: Emergency Department Patient Information & Injury, Emergency Nurses Association, July 30, 2026.
  12. Modernization or Misstep? New Injury Surveillance and Personal Health Data Demands from the CPSC, Consumer Federation of America, July 30, 2026.

Operationalizing workflow

No workflow has been explicitly linked to this obligation yet. See Workflows generally.

Illustrative cases

No illustrative case is currently tracked for this obligation. See Risk Digest for documented incidents generally.

← Back to Regulation

Report a correction or tip

Spotted an outdated figure, a misstated fact, or a ruling this regulation entry should reflect? Public comments are disabled for this content given the professional cost of a misreported case outcome, penalty amount, or rule text — use the structured correction channel instead.

Report a correction or tip for this record →