Skip to content

Risk Digest

CPSC Emergency Room Data Requests Threaten Patient Privacy Rights

Hospitals caught between HIPAA and the Information Blocking Rule face a legal paradox when the CPSC demands emergency room records. This analysis explains how the Privacy Exception resolves the conflict and what patient privacy rights are at stake.

By Editorial TeamUpdated Jul 27, 2026Verified Jul 28, 2026
REPORTED — UNVERIFIED
Jurisdiction
US Federal
Court
U.S. Consumer Product Safety Commission
AI tool named
Konza Health
Ruling date
Feb 27, 2025
Source document
View primary court order ↗
Last verified
Jul 28, 2026

Lex Machina Review is an independent risk-tracking and reference resource. Nothing on this site is legal advice, and using it does not create an attorney-client relationship. Every record is reviewed against primary sources but may not reflect the most current status of a matter — always verify directly against the cited court order, rule text, or a licensed attorney before relying on it.

Companion explanation — secondary to the source document above

A hospital receiving a CPSC emergency room data request under the reported NEISS-R program is not facing an abstract policy dispute. It is being asked to choose between two immediate legal risks: disclose identifiable emergency-room records and potentially create HIPAA exposure for an unauthorized release of protected health information, or refuse and face reported suggestions from CPSC officials that nonparticipation could be treated as information blocking.[1]

That is the wrong way to put a privacy officer, general counsel, or health information management lead on the spot. Mass General Brigham’s reported response makes the point in the plainest operational language: “to protect patient privacy, we are unable to provide these medical records.”[1] The legal question is whether that refusal is merely a business choice, or whether federal privacy law and the Information Blocking Rule give the hospital a defensible path to say no.

Hospital pressed between HIPAA patient privacy and the Information Blocking Rule with a Privacy Exception barrier

Current as of July 28, 2026, the public record is still narrow. The controversy broke through KFF Health News reporting, with CNN/KFF coverage carrying several of the hospital examples now circulating in compliance discussions.[1] The ONC materials on information blocking and its exceptions are primary regulatory guidance for the information-blocking side.[2] The February 2025 Federal Register notice is the key public notice document available for the NEISS renewal issue.[3] Before a hospital makes a final production or refusal decision, counsel should read CPSC’s own HIPAA fact sheet and any contract materials directly; the fact sheet could not be fully reviewed from the materials available here, and public summaries are not a substitute for the agency’s actual legal theory.

Injury surveillance has legitimate uses. Emergency-room data can show whether products are harming people in ways that ordinary complaint channels miss. That does not answer the hospital’s disclosure question. The person signing off on production is not approving “surveillance” in the abstract; that person is authorizing the release of patient-level medical records.

HIPAA can permit covered entities to disclose protected health information without patient authorization for public-health purposes. Permission, however, is not the same thing as a mandatory disclosure power. KFF reports that CDC guidance recognizes that federal public health authorities cannot legally mandate private health data reporting, and KFF also reports expert concern that CPSC’s status as a consumer product safety regulator complicates any easy reliance on public-health-style reasoning.[1]

That distinction matters because many hospital disclosures live in the space between “allowed if the conditions are met” and “required by law.” A HIPAA-permitted disclosure may still require the hospital to verify the recipient’s authority, the purpose, the minimum necessary scope, and any applicable state-law constraints. A mandatory reporting law changes the analysis; a request letter, contractor process, or policy preference does not necessarily do so.

The available reporting says CPSC’s NEISS-R effort uses Konza Health, a Qualified Health Information Network under TEFCA, as part of the data-access structure.[1] That status may matter operationally. It does not, by itself, make CPSC a public health authority with compulsory reporting power, and it does not erase HIPAA’s privacy conditions. A QHIN can be a conduit for exchange; it is not a legal solvent for every upstream authority problem.

Where the Information Blocking Rule actually points

The information-blocking concern is not imaginary. The 21st Century Cures Act framework and ONC’s implementing materials address practices by covered actors that are likely to interfere with access, exchange, or use of electronic health information.[2] Hospitals should not casually label an uncomfortable request as a privacy problem if the law permits the disclosure and no privacy condition is actually implicated.

But the Information Blocking Rule is not a command to violate HIPAA. ONC’s Information Blocking materials identify exceptions, including a Privacy Exception, for practices that meet regulatory conditions when an actor does not fulfill a request in order to protect an individual’s privacy.[2] That is the missing piece in the reported pressure: if the hospital’s reason for refusal is that disclosure would violate HIPAA or another privacy law, the information-blocking analysis does not end with “you failed to share.”

Legal diagram showing disclosure risk, refusal risk, and the Privacy Exception protecting patient privacy

That does not mean every refusal is protected. The Privacy Exception is a regulatory route, not a magic phrase. A hospital relying on it should be able to identify the privacy law at issue, the facts that make disclosure noncompliant, and the relationship between those facts and the records requested. If the concern is HIPAA, the file should say what HIPAA condition is not satisfied. If the concern is state privacy law, the file should name the state-law restriction and explain why it applies.

The strongest hospital position is therefore not “we are worried about privacy.” It is: the request seeks protected health information; the requester’s asserted authority has not been shown to require disclosure; the proposed HIPAA permission has not been established on the records and scope requested; and refusal is being made to protect patient privacy within the Information Blocking Rule’s Privacy Exception. That is a compliance record, not a press statement.

The authority question cannot be bypassed through a contractor

CPSC’s reported use of Konza Health is legally interesting because it may make data acquisition easier. It does not answer whether the agency may obtain the records in identifiable form over a hospital’s HIPAA objection. The relevant question remains the authority of the disclosure: who is asking, under what legal power, for what records, at what level of identifiability, and subject to what privacy limitations.

KFF reports that CPSC materials or officials have invoked public-health-style reasoning, including the idea that HIPAA contains special provisions allowing hospitals to provide data for public-health research purposes.[1] Even if that is the agency’s position, a hospital should separate three propositions that are often blended together in operational conversations:

  • HIPAA may permit some disclosures of PHI for certain public-health purposes without patient authorization.
  • A permitted disclosure is not automatically a compelled disclosure.
  • A data-exchange intermediary’s status does not independently create agency authority to demand identifiable records.

Sharona Hoffman of Case Western Reserve University School of Law is reported as questioning CPSC’s legal authority in this setting.[1] That expert skepticism should not be treated as a court ruling. It is, however, a warning that a hospital should not let the presence of a federal agency letter, a contractor agreement, or a network credential substitute for a statutory and regulatory analysis.

Mary Greeley Medical Center’s reported course is useful for exactly that reason. The hospital initially signed a participation agreement and then began reconsidering amid privacy concerns.[1] That is not proof that participation is unlawful. It is proof that the legal question is serious enough that a signed operational document should not end the review.

The silence of other systems does not fill the gap. KFF reports that Mayo Clinic, Yale New Haven, Cleveland Clinic, and Baylor Scott & White declined to answer questions about participation status.[1] That leaves the field without a reliable map of adoption. It also means counsel should resist arguments that “everyone is doing it” or “no one is doing it.” The public facts do not support either claim.

The Federal Register notice problem is not just procedural housekeeping

The February 27, 2025 Federal Register notice for the National Electronic Injury Surveillance System was framed as an extension of collection and comment request for NEISS.[3] On the materials reviewed here, the notice did not describe the NEISS-R program’s broader scope or the Konza Health contract.[3]

That omission matters because public notice is one of the few places where hospitals, patients, privacy advocates, and state regulators can see the shape of a federal data-collection program before it becomes an operational demand. If the public notice describes a routine renewal while the implementation reaches toward a materially broader identifiable-records program, the legitimacy problem is not merely cosmetic.

Still, the notice issue should not be asked to do too much work. An inadequate or incomplete notice may strengthen objections to the program’s rollout. It does not, standing alone, decide whether a particular hospital may disclose PHI under HIPAA or whether a refusal qualifies under the Privacy Exception. Those questions still require request-by-request analysis.

How hospitals should preserve the patient privacy rights issue

For hospital privacy teams, the immediate task is to make the record before the dispute hardens. If CPSC, Konza, or another participant asks for identifiable emergency-room records, the hospital should keep the request, the legal authority cited, the data fields sought, any implementation guide, any agreement presented for signature, and every communication suggesting that refusal could trigger information-blocking consequences.

The refusal analysis should be written at the level a regulator or court could later audit. A useful file will not merely say “patient privacy rights.” It will connect the request to HIPAA’s disclosure rules, identify why the hospital does not view the disclosure as required or permitted on the present showing, and then map that conclusion to the Information Blocking Rule’s Privacy Exception.

Hospital actionWhy it matters
Identify the exact records and data elements requestedThe HIPAA analysis depends on scope, identifiability, purpose, and minimum necessary limits.
Ask CPSC to state the legal authority compelling or permitting disclosureA public-health rationale is not the same as a mandatory reporting power.
Review CPSC’s HIPAA fact sheet and contract materials directlyPublic summaries may omit conditions, limitations, or assumptions.
Document the HIPAA basis for refusal if the hospital declinesA generic privacy objection is weaker than a rule-based explanation.
Map the refusal to the Information Blocking Privacy ExceptionThe exception is the regulatory answer to a privacy-law conflict.
Preserve penalty-related communicationsAny information-blocking threat becomes part of the hospital’s defense record.

Hospitals should also route the issue through the same governance channels they would use for other high-consequence data events. The exposure is not identical to a cyber incident, but the discipline is similar: preserve records, identify the PHI, assign responsibility, and avoid informal workarounds. For comparison, our analysis of AnMed hospital cyberattack legal risks explains how quickly hospital privacy questions can become litigation questions once patient data leaves expected channels.

The same practical caution applies outside hospitals. The Gemini privacy settings and client data analysis is a useful reminder that privacy duties often turn on who controls the data and what downstream use has been authorized. And in healthcare-specific disputes, patient-facing rights questions—like those discussed in our levothyroxine recall patient rights coverage—tend to become more concrete when the institution can show what it did to protect patients before a dispute became public.

The defensible posture

A hospital evaluating a CPSC emergency room data request should not assume that refusal is automatically safe. The Privacy Exception has not been litigated in this NEISS-R setting, and a hospital that relies on it should expect its facts, documentation, and interpretation of HIPAA to be tested. That uncertainty is precisely why the decision should be escalated and documented rather than handled as routine data exchange.

Nor should the hospital assume that participation is automatically lawful because the request is connected to a federal safety program. The unresolved authority question, the reported reliance on information-blocking pressure, the limits of QHIN status, and the availability of the Privacy Exception all point to the same operational conclusion: patient privacy rights are not a secondary concern to be managed after the transfer. They are the legal constraint that determines whether the transfer may occur at all.

References

  1. Trump’s Consumer Product Safety Commission Wants ER Injury Data. Privacy Experts Are Alarmed, KFF Health News.
  2. Information Blocking, HealthIT.gov.
  3. Agency Information Collection Activities; Extension of Collection; Comment Request; National Electronic Injury Surveillance System (NEISS), Federal Register, February 27, 2025.

Report a correction or tip

Spotted an outdated figure, a misstated fact, or a ruling this case record should reflect? Public comments are disabled for this content given the professional cost of a misreported case outcome, penalty amount, or rule text — use the structured correction channel instead.

Report a correction or tip for this record →