The Consumer Product Safety Commission is demanding that hospital systems nationwide turn over detailed medical records of emergency room patients. This initiative requires hospitals to share sensitive, personally identifiable information with a private contractor, Konza Health, to support a new injury surveillance system. While the agency traditionally tracks product-related injuries, this push covers a vast array of visits including suicide attempts, vaccine reactions, and injuries involving no consumer products at all.

Legal experts and hospital officials are questioning the agency’s authority to mandate these collections. Historically, hospital participation in injury reporting has been voluntary, with data submitted in a deidentified format to protect patient privacy. Under the new directive, hospitals are being told that participation is mandatory, with officials suggesting that failure to comply could result in penalties related to information blocking regulations. The shift represents a significant change in how federal agencies interact with private health records.

Internal documents reveal that the CPSC intends to onboard at least 100 hospitals by the end of this year. Many large health systems remain hesitant, citing concerns over federal privacy laws and the security of patient data handled by a third-party contractor. While the agency maintains that this move is a modernization effort, critics point to the lack of required public notice and the potential for unauthorized data usage as significant red flags.

Some hospital executives have already refused to participate, prioritizing patient privacy standards over the agency’s demands. Others are currently reevaluating their agreements as they weigh the threat of federal penalties against the ethical risks of sharing patient records. As the program expands, the conflict between government data collection and healthcare privacy regulations continues to intensify across the industry.