The CPSC's modernization of NEISS (NEISS-R) aims to improve injury surveillance, but a KFF Health News investigation revealed documents and hospital accounts indicating the agency asked major health systems to provide identifiable ER patient records to a contractor, Konza Health, and treated participation as mandatory. The CPSC says NEISS-R will follow privacy-by-design principles and limit collection, but critics point to frequent healthcare data breaches—including an October 2025 incident affecting 63,883,942 records—as proof that bulk identifiable data collection raises unacceptable risks. The piece urges public pressure on Congress and direct inquiries to the CPSC to demand clearer limits and stronger safeguards.
CPSC's Push to Collect ER Medical Records Sparks Major Privacy Concerns

At RideApart we regularly report on powersports recalls so readers can learn about dangerous products and get them fixed. Our reporting relies heavily on safety data from federal agencies, including the National Highway Traffic Safety Administration (NHTSA) and the U.S. Consumer Product Safety Commission (CPSC).
One part of the CPSC's work—NEISS injury statistics—has come under scrutiny for privacy reasons. The agency's proposed modernization of NEISS (NEISS-R) aims to improve nationwide injury surveillance, but recent reporting raises serious questions about how much identifiable health data the CPSC intends to collect and how that data will be handled.
What KFF Found
On July 27, 2026, KFF Health News published an investigation that reported the CPSC requested detailed, personally identifiable medical records from several major health systems. KFF's reporting was based on interviews with hospital staff and a review of documents and emails that appear to show the CPSC sought "all ER patients' identifiable information — names, addresses, diagnoses, and other personal details — to the contractor, Konza Health, for analysis." The documents also describe participation by hospitals as mandatory or required.
CPSC's Response and Its Privacy Claims
After questions from KFF, the CPSC issued a July 22, 2026 press release describing NEISS-R and emphasizing privacy and security measures. The release says the system will exchange data through a federally designated Qualified Health Information Network with contractual privacy requirements, follow privacy-by-design principles, limit collection and retention to the minimum necessary, support de-identification before information reaches the agency, and reduce manual handling of sensitive records. The CPSC also notes a transition to a modern, cloud-based architecture with standardized federal security controls.
Privacy and security by design. NEISS-R will exchange data through a federally designated Qualified Health Information Network, supported by contractual privacy requirements and standardized security safeguards. The system is built on privacy-by-design principles: it will limit collection and retention to the minimum data necessary for CPSC's statutory mission, support de-identification before information reaches CPSC, and reduce manual handling of sensitive records. CPSC has also transitioned from an on-premises environment to a modern, cloud-based architecture built on standardized federal security controls.
Why This Matters
On paper, those protections sound reasonable. In practice, the investigation and the documents raise several concerns:
- If the agency truly needs only minimal, de-identified data for most cases (historically reported as about 1% of incidents), why request full identifiable ER records from health systems?
- The CPSC has contracted Konza Health to ingest and process the requested data. Any time more companies handle sensitive medical information, the number of potential points of failure grows.
- Healthcare data breaches are common. Analyses reported by the HIPAA Journal show hundreds of healthcare data breaches every year since 2022. In the 12 months from June 2025 through May 2026, October 2025 alone reportedly exposed 63,883,942 people’s healthcare data.
- The agency also experienced significant staffing departures in 2025, the largest number for career staff in a decade, a fact that may affect institutional continuity and oversight.
Risk vs. Reward
Collecting detailed medical records could improve the speed and accuracy of injury surveillance. But it also increases privacy risk and the chance of misuse or accidental exposure. If de-identification and data minimization are the real goals, the CPSC should explain why bulk identifiable records are needed and demonstrate strict, enforceable limits on collection, access, retention, and downstream uses.
What You Can Do
Because the CPSC is a federal agency, the most direct way to influence its approach is through elected representatives. U.S. residents concerned about patient privacy can contact their members of Congress and the CPSC to demand transparency, strict limits on identifiable data collection, and robust legal safeguards against misuse. You can also ask hospitals whether participation in NEISS-R data-sharing is voluntary or required.
We support strong injury surveillance, but it must not come at the expense of patient privacy. Medical records should remain under the control of patients, their healthcare providers, and only those they explicitly authorize.
Help us improve.




























