CPSC's legal authority to compel hospital records is contested
The Consumer Product Safety Commission's new NEISS-R program demands identifiable hospital ER records under contested legal theories. This analysis examines the three pillars of CPSC's claimed authority and the legal defenses available to hospitals that refuse, including the HIPAA public-health-authority distinction, the Information Blocking Rule's Privacy Exception, and the missing Paperwork Reduction Act clearance.
- Jurisdiction
- US Federal
- Court
- U.S. District Court
- AI tool named
- None
- Ruling date
- Jul 28, 2026
- Source document
- View primary court order ↗
- Last verified
- Jul 28, 2026
Lex Machina Review is an independent risk-tracking and reference resource. Nothing on this site is legal advice, and using it does not create an attorney-client relationship. Every record is reviewed against primary sources but may not reflect the most current status of a matter — always verify directly against the cited court order, rule text, or a licensed attorney before relying on it.
Companion explanation — secondary to the source document above
Risk-digest posture: this analysis is written for hospital counsel and litigators assessing CPSC hospital data collection legal authority before a court has tested the new NEISS-R demand. Last verified: July 28, 2026, UTC. Source basis: KFF Health News reporting on the demand letters, hospital refusals, Konza, and Paperwork Reduction Act status; the CPSC’s 2014 HIPAA public-health-authority notice; the 2025 Federal Register renewal of the legacy NEISS information collection; and Foley & Lardner’s description of the CPSC announcement. This is legal-risk analysis, not legal advice. [1][2][3][4]
The demand letter problem
The immediate problem for a hospital lawyer is not whether injury surveillance is useful. It is whether the Consumer Product Safety Commission can lawfully turn a product-injury reporting program into a demand for identifiable emergency-department records at scale, then frame nonparticipation as legally risky before the legal theory has been tested.
KFF Health News reported on July 27, 2026, that the CPSC is seeking identifiable emergency room records through NEISS-R, an updated version of the National Electronic Injury Surveillance System, and that some major systems, including Mass General Brigham and Harborview Medical Center, have refused or resisted participation on patient-privacy grounds. The same report says the program would use Konza Health, a Qualified Health Information Network under TEFCA, to collect records across more than 10,000 ICD codes. [1]
That reporting is the factual trigger, not a final adjudication record. KFF’s account relies in part on unnamed people and communications it describes, so the exact wording and context of every hospital exchange should be treated as something counsel would verify before relying on it. But the reported facts are concrete enough to identify the legal fault line: CPSC appears to be invoking a HIPAA public-health-authority notice, the Information Blocking Rule, and its product-safety statute as if the three together compel bulk identifiable extraction.

What is actually changing from legacy NEISS to NEISS-R
The clearance problem starts with a practical difference. Legacy NEISS was a manual reporting system built around consumer-product injury surveillance. Hospitals abstracted relevant emergency-department cases, and the traditional model was largely de-identified. KFF reports that the existing NEISS operating manual is 214 pages and instructs hospitals not to include identifiable information except in less than 1% of cases. [1]
NEISS-R, as reported, is structurally different. Instead of hospital staff manually sending product-injury abstractions, an automated exchange would pull identifiable emergency records through Konza and the TEFCA network architecture. Instead of a narrower product-category screen, the reported scope reaches more than 10,000 ICD codes. KFF identifies examples in the demanded universe that include vaccine reactions, suicide attempts, and stingray injuries. [1]

That contrast does most of the legal work. A permission notice written for product-safety PHI, an OMB clearance renewed for the legacy NEISS collection, and a health-information interoperability rule do not automatically carry over to a materially broader, identifiable, automated extraction model. CPSC may describe NEISS-R as a modernization of the existing injury surveillance system, and Foley & Lardner’s July 24, 2026 summary captures that agency-side framing. [4] The hospital-side question is narrower and harder: where is the compulsory authority for this version of the collection?
The HIPAA notice permits disclosure; it does not itself compel it
The strongest-looking CPSC document is the 2014 Federal Register notice titled “Public Health Authority Notification.” In that notice, the CPSC announced that it is a public health authority under HIPAA for purposes of receiving protected health information related to injuries or deaths associated with consumer products. The notice’s operative language is permissive: covered entities “may disclose” PHI to the CPSC without individual authorization when the disclosure fits the public-health-authority framework. [2]
For hospital counsel, the verb matters. HIPAA permission answers one question: whether HIPAA necessarily bars a covered entity from disclosing relevant PHI to CPSC. It does not answer a different question: whether CPSC can compel a hospital to disclose all records within the NEISS-R feed. A permissive HIPAA pathway is not a subpoena, not an OMB clearance, and not an independent statutory command to turn over every record the agency wants.
The relevance boundary matters too. The 2014 notice ties the CPSC’s public-health-authority role to injuries and deaths associated with consumer products. [2] If NEISS-R is demanding identifiable records across more than 10,000 ICD codes, including categories that do not obviously involve consumer products, the hospital’s objection is not simply “privacy.” It is that the agency has moved from receiving relevant PHI to claiming a right to a broad emergency-record stream and then sorting relevance later.
CPSC can respond that many emergency-department records do not reveal their product-safety relevance until reviewed. That argument may support some form of access or sampling. It does not by itself dissolve the statutory and HIPAA boundaries that made the 2014 notice plausible in the first place.
The Information Blocking Rule cuts both ways
The sharpest practical paradox is the reported use of the Information Blocking Rule as pressure. KFF reports that CPSC communications have cited information-blocking concepts in connection with hospital resistance. [1] That is a serious citation to put in a demand letter because hospitals understand the compliance exposure attached to interfering with access, exchange, or use of electronic health information.
But the Information Blocking Rule is not a one-way release valve for every governmental data request. Its Privacy Exception, codified at 45 CFR 171.201, exists precisely because actors may need to decline or limit access, exchange, or use of electronic health information to protect privacy. A hospital that can document that its refusal or limitation is tied to HIPAA privacy analysis is not in the same position as a provider simply obstructing exchange for business convenience.
This is where a generic refusal letter becomes dangerous. “We have privacy concerns” is a thinner record than “the requested NEISS-R feed includes identifiable PHI outside CPSC’s consumer-product injury authority, the 2014 notice is permissive, and the hospital is invoking a privacy-based basis for non-disclosure under the Information Blocking Rule’s Privacy Exception.” The latter still may be contested, but it identifies the legal exception the agency’s pressure theory must overcome.
The enforcement posture is also uncertain because CPSC is not the HHS office that administers the Information Blocking Rule. If CPSC complains that a hospital’s refusal is information blocking, the question becomes whether HHS would treat a HIPAA-grounded privacy refusal as sanctionable despite the Privacy Exception. No court has answered that question on the NEISS-R facts.

The product-safety statute is bounded by product-safety relevance
The Consumer Product Safety Act gives CPSC a real product-safety mission. The issue is not whether the agency may collect injury information at all. The issue is whether 15 U.S.C. 2054 and related CPSC authority reach the full NEISS-R demand as reported.
The 2014 public-health-authority notice itself frames the CPSC’s HIPAA role around information related to injuries or deaths associated with consumer products. [2] That framing is difficult to square with a demand that sweeps in categories such as vaccine reactions, suicide attempts, and stingray injuries unless CPSC can explain how the feed is limited to, or necessary for identifying, consumer-product incidents. KFF’s reporting does not establish that every demanded ICD code lacks product relevance, but it does show why a hospital would ask for a code-level justification rather than accept the statutory citation as self-executing. [1]
The statutory mismatch matters most in enforcement. If CPSC later threatens a hospital for refusing NEISS-R access, the agency would have to defend not only the general value of injury surveillance but the legal fit between its consumer-product mandate and the breadth of the identifiable records requested. A court reviewing that dispute would likely care less about the word “modernization” than about the limiting principle.
The Paperwork Reduction Act issue may ripen first
The procedural weakness is easier to state than the HIPAA and information-blocking disputes. The existing OMB clearance for NEISS, control number 3041-0029, was renewed in a May 23, 2025 Federal Register notice. That notice concerns an extension of the National Electronic Injury Surveillance System and follow-up activities. [3]
A hospital resisting NEISS-R can argue that the 2025 renewal covered the legacy manual NEISS collection, not an automated identifiable extraction through Konza across a vastly expanded ICD-code universe. If the collection method, burden, data elements, and privacy implications have materially changed, the Paperwork Reduction Act objection is not cosmetic. It goes to whether CPSC has obtained approval for the collection it is actually attempting to run.
KFF reported that CPSC spokesperson Steve Roney said no public notice had been issued as of July 10, 2026. [1] That statement should be attributed carefully; it is reported by KFF, not independently established here. Still, if accurate, it creates a near-term administrative-law problem for CPSC. The agency may be able to seek new clearance. It may be able to defend some transitional theory. But demanding production before the appropriate clearance is in place gives hospitals and challengers a more concrete objection than generalized discomfort with data sharing.
What a defensible refusal theory would have to preserve
A hospital does not need to claim that CPSC has no role in injury surveillance to resist the reported NEISS-R demand. The stronger position is narrower: CPSC may receive relevant PHI as a public health authority when HIPAA permits disclosure, but the 2014 notice does not itself compel disclosure; the Information Blocking Rule includes a privacy pathway rather than eliminating HIPAA judgment; the CPSC’s statutory authority is bounded by consumer-product relevance; and the current PRA clearance appears to have been renewed for the legacy NEISS collection, not this automated identifiable feed.
That theory leaves room for CPSC to narrow the request, obtain updated clearance, provide code-level justification, or litigate the point. It also leaves room for hospitals to participate if they conclude the legal and operational risks are acceptable. What it does not leave intact is the idea that a hospital must treat NEISS-R refusal as plainly unlawful merely because three legal concepts appear in the same agency communication.
As of this writing, no court has ruled on the NEISS-R theory. That uncertainty cuts both directions, but it is not empty uncertainty. Hospitals have colorable defenses, and any enforcement threat now rests on contested, untested legal ground.
References
- Trump Administration Demands Hospitals Share Emergency Room Records — KFF Health News, July 27, 2026.
- Public Health Authority Notification — Federal Register, March 3, 2014.
- Agency Information Collection Activities; Extension of Collection; National Electronic Injury Surveillance System (NEISS) and Follow-Up Activities — Federal Register, May 23, 2025.
- CPSC Announces Updated National Electronic Injury Surveillance System — Foley & Lardner LLP, July 24, 2026.
Related records
Tool profile
Browse tool evaluations →Governing regulation
Browse the obligations tracker →Preventive workflow
Browse verification workflows →
Report a correction or tip
Spotted an outdated figure, a misstated fact, or a ruling this case record should reflect? Public comments are disabled for this content given the professional cost of a misreported case outcome, penalty amount, or rule text — use the structured correction channel instead.
Report a correction or tip for this record →