CPSC demanded identifiable ER records from 100+ hospitals through contractor Konza Health without required public notice
On July 21, 2026, the Consumer Product Safety Commission publicly announced a program requiring at least 100 hospitals — including Mayo Clinic and Cleveland Clinic — to turn over identifiable emergency-room records to Konza Health, a Kansas-based data firm holding a $15.9 million, five-year CPSC contract. A July 27 KFF Health News investigation revealed CPSC had been pressuring hospitals since earlier in the year and had not provided the public notice and comment period federal law requires before requesting data from ten or more entities; CPSC and Konza officials described participation as "mandatory," and Konza said it would hold identifiable data for at least 30 days before filtering it.
Actors
- Consumer Product Safety Commission
- Konza Health
On July 21, 2026, the Consumer Product Safety Commission — an independent agency whose mandate is tracking injuries from consumer products — publicly announced a program requiring hospitals to turn over identifiable emergency-room records, after having discreetly pressured at least 100 hospitals, including Mayo Clinic, Cleveland Clinic, Yale New Haven, and Mass General Brigham, to participate. A KFF Health News investigation published six days later, on July 27, 2026, revealed the pressure campaign's scope: a CPSC official had told hospital executives in emails that they must provide all ER patients' identifiable information, including names, addresses, and diagnoses, to Konza Health, a Kansas-based data-exchange operator that won a $15.9 million, five-year CPSC contract last fall, covering most patient injuries from broken bones to suicide attempts; Konza representatives separately described hospital participation as "mandatory" or "required." CPSC Chief Data Officer Elizabeth Puchek told hospitals declining to share records that they must formally seek an exemption.
The program marks a sharp departure from CPSC's existing injury-surveillance system, which its own 214-page operating manual instructs hospitals to report without identifying information except in the fewer than 1% of cases needing follow-up. Konza said it would hold identifiable patient data for at least 30 days before filtering it, under a contract CPSC has not made public, and disclosed diagnostic codes covering more than 10,000 conditions — including vaccine reactions and stingray injuries that fall outside CPSC's product-safety jurisdiction. CPSC acknowledged it had not given the public notice and comment period that federal law requires before requesting data from ten or more entities, despite planning to enroll 100 hospitals. The agency previously mishandled the personal health information of roughly 30,000 people in a 2017-2019 breach.
CPSC spokesperson Steve Roney said the agency is "modernizing" its surveillance system and that its contract with Konza bars the company from selling or marketing the data. Case Western Reserve health law professor Sharona Hoffman said turning the data over to a private contractor introduces risks that a company could misuse or fail to safeguard it. Some hospitals, including Harborview Medical Center and Mass General Brigham, have declined to participate, citing their own privacy obligations; others, including Mary Greeley Medical Center in Iowa, signed on after being told participation was mandatory.
Why we recorded this
Federal agencies may only collect personal data within their statutory mission and must give the public notice and a comment period before demanding records from ten or more entities. The Consumer Product Safety Commission — an agency whose mandate is tracking injuries from consumer products — pressured at least 100 hospitals to hand over identifiable emergency-room records, including names and diagnoses, to a private contractor, while its own spokesperson acknowledged it had not given the legally required public notice. This archive records when an agency expands its data collection far beyond its statutory purpose and skips the procedural safeguards Congress built in to check that expansion.
Sources
- Trump Administration Demands Hospitals Share Emergency Room Records — KFF Health News primary accessed July 28, 2026
- Trump administration demands hospitals share emergency room records — Nevada Current secondary accessed July 28, 2026
- Trump administration takes emergency room records — MS NOW (Maddowblog) secondary accessed July 28, 2026
See also
- HHS created new pathway to share TANF recipients' Social Security numbers and immigration status with DHS
- New Mexico probation officers referred probationers to ICE in violation of state privacy law, ethics commission alleged
- Chico, California police department shared license-plate data with ICE and Border Patrol for two years in violation of state law
- Injustice Watch investigation found Illinois police and sheriffs circumvented TRUST Act to help ICE detain, deport immigrants
- Injustice Watch/WIRED investigation found Illinois state's attorneys shared residents' personal data with ICE despite TRUST Act
Receive the daily digest by email
One email each morning with every entry filed the day before. Free. No tracking, no ads. Unsubscribe anytime.
