The Trump Administration’s Consumer Product Safety Commission (CPSC) is pressing hospitals to participate in an overhaul of the National Electronic Injury Surveillance System (NEISS). The longstanding program uses a sample of emergency departments to identify injuries involving consumer products and produce national estimates. Under the new NEISS-Remodel program, CPSC contractor Konza Health would electronically retrieve and screen emergency-room records, with the Agency seeking participation from at least 100 hospitals. CPSC says the change will replace a labor-intensive system dating to 1972, expand coverage to all 50 states and identify emerging hazards faster.

The controversy centers on how much information hospitals would provide before relevant cases are identified. According to documents and emails reviewed by KFF Health News, hospitals have been asked to provide Konza with identifiable information – including names, addresses and diagnoses – covering a broad range of emergency visits. Konza would determine which encounters may involve consumer products and de-identify information before it reaches CPSC. This reverses the traditional model, in which hospital personnel selected product-related cases and submitted de-identified data, with identifying information requested only for rare follow-up investigations.

CPSC maintains that the system has “privacy by design.” The Agency says records will be exchanged through a federally designated Qualified Health Information Network, protected by contractual and standardized security safeguards, and limited to the minimum data necessary for its mission. It also argues that the Health Insurance Portability and Accountability Act (HIPAA) permits hospitals to disclose protected health information to CPSC as a public-health authority and that refusing a lawful request could raise concerns under federal information-blocking rules.

Hospitals and privacy experts question both propositions. HIPAA permits disclosures for public-health activities, but permission is not necessarily a mandate. Hospitals must also consider HIPAA’s minimum-necessary standard and whether CPSC’s request extends beyond consumer-product injuries into records involving suicide attempts, vaccine reactions and other conditions outside the Agency’s traditional jurisdiction. The involvement of a private contractor, cybersecurity risks and the lack of patient notice or consent add to those concerns. The Department of Health and Human Services (HHS) guidance says hospitals retain discretion to make their own minimum-necessary determinations when the standard applies.

Several health systems have resisted or questioned participation. Harborview Medical Center said its prior participation was voluntary and involved de-identified data. Mass General Brigham reportedly declined because of patient-privacy concerns, while Henry Ford Health, St. Luke’s and Sanford Health had not signed agreements according to KFF. Mary Greeley Medical Center said it was reevaluating its role. The American Hospital Association has not announced formal opposition or litigation. Consumer Reports supports modernizing injury surveillance but says CPSC should not collect patients’ personal medical records.

The dispute is raising significant legal questions. Potential claims could focus on whether CPSC can compel participation, whether the collection complies with HIPAA and information-blocking rules, and whether the Agency violated the Paperwork Reduction Act by seeking standardized information from more than nine entities without public notice and review. CPSC acknowledged to KFF that it had not yet provided the required public notice. For now, AHPA is monitoring these discussions while also assessing the agency’s request.

Topics: Health IT HHS