Trump ER Data Demand Has Four Legal Vulnerabilities
- Authority
- Consumer Product Safety Commission (CPSC)
- Rule type
- regulation
- Jurisdiction scope
- US federal
- Source text
- Read primary rule text ↗
Transmit identifiable ER records to CPSC for NEISS-R
The enforceability problem begins before anyone reaches the politics of emergency-room surveillance. Hospitals are reportedly being asked by the Consumer Product Safety Commission to transmit identifiable emergency-room records for the updated National Electronic Injury Surveillance System, known as NEISS-R, even though the public paperwork trail does not appear to match the program now being pressed on providers.[1]
As of July 30, 2026, no court has ruled that NEISS-R is unlawful. That matters. A hospital privacy officer or in-house lawyer is not holding a clean injunction, a definitive agency adjudication, or a settled safe harbor. They are holding a federal demand, a set of agency assurances, a HIPAA analysis that may answer only part of the question, and a threat environment that includes information-blocking penalties.

The first question is therefore not whether richer injury surveillance is useful. It may be. The question is narrower and more uncomfortable: did the CPSC identify a valid legal route for this agency, this program, this volume of hospitals, this level of patient identifiability, and this breadth of injury categories?
On the materials now public, the demand is vulnerable on four separate grounds: the Paperwork Reduction Act notice problem, the Consumer Product Safety Act scope problem, the agency’s own NEISS instruction not to collect personally identifiable information, and the Information Blocking Rule’s privacy exception. None requires a court to conclude that injury surveillance is a bad idea. Each asks whether the agency used the legal tool it claims to be using.
The cleanest problem is the missing NEISS-R paperwork trail
The CPSC did publish a February 27, 2025 Federal Register notice for “Agency Information Collection Activities” at 90 FR 10815. But the notice described an extension of an existing information collection for NEISS and related activities, not a new NEISS-R architecture requiring hospitals to transmit identifiable electronic health-record data at the scale now reported.[2]
That distinction is not clerical. The Paperwork Reduction Act is built around advance public notice, comment, and review before an agency collects information from ten or more persons. Its public-protection feature is blunt: an information collection that lacks valid PRA approval is not supposed to be enforceable against the recipient. If the notice told the public one thing while the agency later demanded something materially different, a hospital has a serious threshold objection before it ever argues HIPAA, preemption, or patient expectations.
KFF Health News reported that a CPSC spokesperson confirmed the agency had not issued a separate PRA public notice for the NEISS-R expansion.[1] That confirmation is the pressure point. The agency can argue that NEISS-R is a modernization of the existing NEISS collection, but calling a program modernized does not answer whether the public was asked to comment on the actual collection now being imposed.
For counsel, the practical comparison is simple enough to put in a refusal letter or litigation memo:
| Public notice issue | Why it matters |
|---|---|
| February 2025 notice described an existing NEISS collection | A routine renewal may not authorize a materially different identifiable-records program |
| NEISS-R reportedly demands identifiable ER records | Identifiability changes privacy burden, operational burden, and legal risk |
| No separate NEISS-R PRA notice was confirmed in reporting | The agency’s enforceability position depends on treating the old notice as enough |
| The PRA claim has not yet been tested in court for NEISS-R | The argument is strong enough to preserve, but not already adjudicated |
This is the most administratively ordinary vulnerability and possibly the most consequential. Agencies lose collection leverage when they skip the required public process. A hospital does not need to prove bad faith to raise it; it needs to show mismatch.
The ICD-code sweep strains the CPSC’s product-safety mandate
The second vulnerability is not about paperwork formality. It is about statutory fit. The CPSC’s organic authority is tied to consumer product safety. NEISS has long served that mission by sampling emergency-department injuries associated with consumer products. NEISS-R, as reported, sweeps much wider.
KFF Health News reported that the NEISS-R code list covers more than 10,000 ICD codes and includes categories such as vaccine-related encounters, marine animal contact, stingray injuries, and adult suicide attempts.[1] Those examples do not sit naturally inside the CPSC’s consumer-product lane. Vaccines implicate public-health and drug-regulatory authorities. Marine animal contact may be clinically relevant, but it is not obviously a consumer product incident. Adult suicide attempts raise a still different set of clinical, behavioral-health, and privacy stakes.
A statutory-scope argument should not overstate the point. Some ICD-coded encounters that appear broad at first glance may still involve consumer products once the clinical narrative is reviewed. A fall, burn, laceration, poisoning, or foreign-body injury can become product-relevant only after context is added. The problem is that NEISS-R appears to ask hospitals to transmit first and sort later.
That sequencing matters legally. If the agency’s authority extends to consumer-product-related injuries, it needs a limiting principle before identifiable data leaves the hospital, not merely an internal promise that non-product material will be filtered downstream. Otherwise, the asserted product-safety collection becomes a general emergency-room injury feed.

This is where the modernization argument does some work but not enough. Modernization can justify replacing manual abstraction with electronic feeds. It can justify reducing lag, improving completeness, or standardizing reporting. It does not, by itself, expand a product-safety agency into unrelated clinical surveillance.
The NEISS manual points in the opposite direction on PII
The third vulnerability is awkward for the agency because it comes from inside the NEISS materials themselves. The CPSC’s NEISS HIPAA and Data Security materials state that participating hospitals should not include personally identifiable information in the narrative text submitted to the agency.[3]
An operating manual is not a statute, and it does not freeze an agency forever. The CPSC can revise procedures. It can decide that a legacy process no longer supports the surveillance quality it wants. But when the existing NEISS operating framework tells hospitals not to send PII, and the new demand reportedly requires identifiable records, the agency has created a reliance and consistency problem.
That problem is practical before it is philosophical. Hospital privacy teams train staff around data-minimization rules. They distinguish abstract injury surveillance from identifiable chart disclosure. They ask whether the disclosed fields are necessary to the stated purpose. A demand that reverses the prior PII instruction should come with clear legal authority, defined fields, retention rules, vendor-handling terms, and a public approval trail. The public materials described so far do not close those gaps.
HIPAA permission is not the same as CPSC authority
The CPSC’s HIPAA position deserves a fair reading. Its NEISS HIPAA materials explain that HIPAA can permit disclosures to public-health authorities under specified conditions.[3] A hospital should not reflexively answer every government health-data request with “HIPAA forbids it.” Often, HIPAA is a permission structure, not a categorical bar.
But that is exactly why the agency’s HIPAA argument cannot do all the work. A HIPAA pathway may mean a covered entity is allowed to disclose certain protected health information to a qualifying public-health authority. It does not prove that the requesting agency has complied with the PRA. It does not prove that the Consumer Product Safety Act authorizes the full ICD-code sweep. It does not cure a conflict with NEISS’s own PII instruction. And it does not turn a vendor’s unpublished handling process into a statutory authorization.
For hospital counsel, this distinction is more than academic. The disclosure question and the collection-authority question sit on opposite sides of the transaction. HIPAA may address whether the hospital may disclose. The CPSC still has to show that it may demand.
The information-blocking threat has a privacy exception problem
The fourth vulnerability is a refusal point. The Information Blocking Rule is not a general-purpose cudgel for forcing hospitals to transmit data whenever a federal agency wants it. ONC’s information-blocking framework includes exceptions, and the Privacy Exception at 45 CFR § 171.204 permits an actor to withhold access, exchange, or use of electronic health information when the conditions of the exception are met, including where disclosure would violate applicable privacy law.[4]
That does not mean every hospital can simply invoke privacy and stop reading. The exception has conditions. A refusal should be documented, tied to identified legal constraints, and reviewed against the exact request. But it does mean that an information-blocking penalty threat is incomplete if it ignores the rule’s own privacy architecture.
The strongest hospital position would not be a generic privacy objection. It would identify the specific defects: no NEISS-R-specific PRA notice, unresolved statutory scope for non-product injuries, inconsistency with existing NEISS PII guidance, unclear downstream handling, and the availability of the Privacy Exception while those issues remain unresolved.
The surrounding facts make informal assurances harder to rely on
The remaining facts do not prove unlawfulness by themselves. They do, however, affect how much comfort a hospital should take from agency confidence.
KFF Health News reported that the CPSC awarded a $15.9 million contract to Konza Health for the updated system, that the contract had not been made public, and that Konza would retain full personally identifiable information for at least 30 days before filtering.[1] Without the contract language, counsel cannot verify retention limits, subcontractor controls, audit rights, breach-notification obligations, or whether filtering occurs before or after legally sensitive fields are exposed.
KFF also reported a prior CPSC data-security failure involving more than 30,000 records improperly released to Consumer Reports and other parties between 2017 and 2019, with affected individuals not notified, based on internal agency records.[1] That history is not a cheap character argument. It is relevant because the legal sufficiency of this program depends partly on downstream handling assurances that hospitals cannot independently inspect.
Agency-capacity context points the same way. CNN reported that, after President Trump fired Democratic commissioners and the Supreme Court allowed the firings to stand, the CPSC had no governing board; CNN also reported that 63 career staffers, nearly one in five, left the agency in 2025.[5] Those facts do not answer the PRA question or the scope question. They do explain why a hospital may be unwilling to treat informal implementation statements as a substitute for published legal authority.
What a defensible hospital response preserves
A hospital evaluating a NEISS-R demand should separate three questions that agencies and vendors often blend together:
- May the hospital disclose the requested data under HIPAA or another privacy rule?
- Did the CPSC complete the public approval process required for this particular information collection?
- Does the CPSC’s statutory mandate reach all categories of identifiable records being requested?
- If the hospital refuses or narrows disclosure, does the Information Blocking Rule’s Privacy Exception protect that position?
Those questions should not be answered from a fact sheet alone. The hospital needs the actual demand, the requested fields, the asserted OMB control number, the claimed statutory authority, the vendor-flow description, and the agency’s position on why the February 2025 notice covers NEISS-R. If those materials are missing or nonresponsive, that absence is part of the legal record.
The most disciplined conclusion is not that NEISS-R is dead. It is that the demand should not be treated as self-enforcing merely because it arrives from a federal agency. No court has yet blessed or rejected this program. The PRA theory has not been tested here. But the visible record gives hospitals at least four independent grounds to refuse, narrow, or challenge the demand before sending identifiable emergency-room records into a system whose legal foundation remains unsettled.
References
- Trump Administration Demands Hospitals Share Emergency Room Records, KFF Health News
- Agency Information Collection Activities notice, Federal Register, Feb. 27, 2025
- NEISS HIPAA and Data Security page, CPSC.gov
- Information Blocking exceptions, HealthIT.gov
- Trump administration demands hospitals share emergency room records, CNN
Operationalizing workflow
No workflow has been explicitly linked to this obligation yet. See Workflows generally.
Illustrative cases
No illustrative case is currently tracked for this obligation. See Risk Digest for documented incidents generally.
← Back to RegulationReport a correction or tip
Spotted an outdated figure, a misstated fact, or a ruling this regulation entry should reflect? Public comments are disabled for this content given the professional cost of a misreported case outcome, penalty amount, or rule text — use the structured correction channel instead.
Report a correction or tip for this record →