The CPSC plans to modernize NEISS to pull data from electronic health records next year to detect product-related injuries faster. Reports say the agency sought identifiable ER records—including names, addresses and diagnoses—to be shared with a private contractor, raising privacy and security concerns. Officials say the prior voluntary system limited usefulness, but experts call for clear safeguards, data-minimization and independent oversight before sharing millions of medical records.
CPSC Move to Pull Identifiable ER Records Sparks Privacy Alarm

The Consumer Product Safety Commission (CPSC) says it is modernizing the National Electronic Injury Surveillance System (NEISS) to detect consumer-product-related injuries faster by drawing data from electronic health records (EHRs) starting next year. What began as a public-safety effort has become a flashpoint over patient privacy after reports that the agency sought detailed, personally identifiable emergency-room records to be shared with a private contractor.
What the Proposal Would Do
According to reporting by KFF Health News and CNN, the CPSC has contacted hospital leaders this year seeking "identifiable information" from ER visits — names, addresses, diagnoses and other personal details — to assemble a national dataset that would allow near-real-time detection of product-safety problems. The agency says a modernized NEISS would improve the speed and usefulness of surveillance compared with the prior voluntary system, in which hospitals could opt out and limit the sample size.
Privacy Concerns
"If this company really is collecting identifiable information, that is worrisome for patients," said Sharona Hoffman, a professor of health law at Case Western Reserve University.
Privacy and health-data experts, hospital officials and consumer advocates warn that sharing millions of identifiable records with a private contractor raises substantial confidentiality and security risks. Critics say the request stretches beyond product-focused surveillance into the realm of highly sensitive medical information, covering incidents from broken bones and vaccine reactions to suicide attempts.
CPSC Response And Political Context
Steve Roney, a CPSC spokesperson, told KFF Health News that the agency is "modernizing" its surveillance capabilities and noted that the prior voluntary program’s opt-outs limited usefulness. He did not provide details about safeguards, data de-identification, or contractual protections for patient information in those statements.
Trust in the agency has been strained by recent political events: last year, President Donald Trump removed the CPSC’s three Democratic board members, prompting legal challenges and a Supreme Court decision that affected the agency’s governance. Observers say that context shapes public concern over broad data access by a federal agency working with a private contractor.
Balancing Safety And Privacy
Supporters of improved surveillance emphasize the potential to spot dangerous products more quickly and prevent additional harm. Opponents emphasize transparency, strict limits on identifiable data, robust cybersecurity protections, and independent oversight before millions of medical records are shared. Hospitals and stakeholders are weighing whether the public-safety benefits justify the privacy and security trade-offs.
Help us improve.
























