CPSC's NEISS Overhaul: Emergency Department Data Demands Raise Privacy, Authority, and Compliance Questions

Article

On July 22, 2026, the Consumer Product Safety Commission (CPSC) announced plans to restructure its National Electronic Injury Surveillance System (NEISS) beginning in 2027. Established in 1972, the CPSC is a federal regulatory agency responsible for protecting the public from unreasonable risks of injury associated with consumer products. To support this mission, the CPSC collects data on consumer product-related injuries through NEISS, which compiles information from a nationally representative sample of participating hospitals across the United States. The agency uses that data, together with other sources, to set research priorities, pursue recalls, develop safety standards, and support public awareness campaigns.

Traditionally, a NEISS hospital coordinator collected injury surveillance data by reviewing emergency department records at the end of each day and identifying cases associated with consumer product use. The CPSC’s coding manual directs coordinators to omit identifiers such as names, birthdates, and addresses, and to exclude categories outside the agency’s jurisdiction, including injuries caused by food, medical devices, alcohol, illegal drugs, or plants, injuries not involving a consumer product, and suicide attempts by adults. Identifiable information reached the CPSC only for follow-back investigations, which the manual indicates occur in fewer than 1% of reported cases.

The new program, known as NEISS-Remodel or NEISS-R, will replace this manual data-collection approach with a highly automated process. CPSC has partnered with a private entity, Konza Health (Konza), a Kansas-based organization that operates that state’s health information exchange, under a five-year contract worth up to $15.9 million.  The contract has not been made public. Konza will automatically extract data from all emergency department patients’ electronic health records (EHR). The new system will expand NEISS’s geographic scope from approximately 70 hospitals across 36 states to a target of 100 hospitals across all 50 states and will increase annual record volume from roughly 400,000 to approximately 2 million.

The CPSC has stated that data will be exchanged through a federally designated Qualified Health Information Network, that collection will be limited to the minimum necessary for its statutory mission, and that records will be de-identified before reaching the agency. It has not published operational detail substantiating those representations. Despite the potential reduction in operating costs, the change raises serious concerns for providers. Automation also removes the trained on-site personnel who previously exercised judgment about what to report, which a former CPSC chairman has publicly warned may dilute the quality of the product safety data the program is intended to produce.

CPSC officials have taken the position that healthcare entities are required to supply requested EHR data to public health authorities and have warned that refusal to participate in the new surveillance system may expose providers to penalties for “information blocking” under 45 C.F.R. Part 171. Documents and emails from Konza’s President and Chief Executive Officer and other representatives describe participation in the new program as “required” or “mandatory.” Elizabeth Puchek, CPSC’s Chief Data Officer, has stated in emails to hospital executives that they must seek an exemption if their hospital declines to participate. However, healthcare executives and lawyers question the authority of the CPSC to mandate participation, arguing that a federal agency cannot obligate hospitals to share patients’ private health data. The HIPAA Privacy Rule supports that view: 45 C.F.R. § 164.512(b) permits, but does not require, a covered entity to disclose protected health information to a public health authority. Because Konza is acting on behalf of the CPSC rather than the hospital, it is not the hospital’s business associate, and any disclosure without patient authorization must independently qualify under the Privacy Rule, most plausibly as a disclosure to a person acting under a grant of authority from or under contract with a public health authority. See 45 C.F.R. §§ 164.501, 164.512(b). Whether the CPSC qualifies as a public health authority for this purpose remains an open question.

The information blocking exposure is also narrower than the agency’s framing suggests. Healthcare providers are not subject to the civil monetary penalties that apply to certified health IT developers, health information exchanges, and health information networks; providers instead face “appropriate disincentives” administered through federal payment programs. Information blocking analysis further turns on whether an actor has interfered with access, exchange, or use of electronic health information that it is required or permitted to provide, and a permissive Privacy Rule provision that merely allows a plan for such disclosure does not plainly create such an obligation. The Privacy Exception at 45 C.F.R. § 171.202 and the Preventing Harm Exception at § 171.201 may also be available. Providers declining to participate should document their analysis under the applicable exception contemporaneously.

A separate procedural question overhangs the entire program. Federal law requires an agency to provide public notice and an opportunity to comment before collecting information from 10 or more persons. See 44 U.S.C. §§ 3502(3), 3506(c). The CPSC intends to onboard at least 100 hospitals and has not taken that step. An agency spokesperson has acknowledged that the public had not been notified as required by law. Because no formal collection has been proposed, the program’s ultimate scope, retention terms, and data flows may change materially, and this omission is likely to feature in any legal challenge.

Many are also concerned about the scope of the program and the presence of safeguards to protect sensitive patient information. For example, the purpose of the CPSC is to address consumer product-related injuries. However, a contract between Konza and a participating hospital shows that Konza did not limit its request for emergency department admission, discharge, and transfer messages to product-related cases, and provided for retention of patient health information for at least 30 days. Konza has advised hospital officials that it will furnish the CPSC with records for more than 10,000 diagnostic conditions, including pediatric injuries coded as poisoning by vaccines and contact with stingrays, neither of which the CPSC regulates. Reported categories also include suicide attempts, which the agency’s own coding manual excludes for adults.

Moreover, the new program provides less protection for patients’ personally identifiable information (PII). While protected health information (PHI) refers to individually identifiable information created, maintained, or transmitted by a covered entity for the provision of care, PII includes any information that can be used to identify an individual, whether or not it is related to healthcare, such as names, dates of birth, or addresses. In the past, the CPSC has instructed providers not to include PII in case comments. Under the new program, complete identifiable records leave the covered entity first, and Konza is then responsible for removing any PII deemed unnecessary. The sequencing matters.  The covered entity’s minimum necessary obligation under 45 C.F.R. § 164.502(b) attaches at the point of disclosure, not at the point the contractor later filters. Participation also triggers ongoing obligations for providers, including the accounting of disclosures requirement at 45 C.F.R. § 164.528 and the need to confirm that the organization’s notice of privacy practices under § 164.520 accurately describes the disclosure. Automated extraction of all emergency department encounters will further capture records that HIPAA does not govern alone, including substance use disorder treatment information subject to 42 C.F.R. Part 2, reproductive health care information, minors’ records, and categories protected by state law such as HIV status, mental health, and genetic information.

Similarly, despite Konza’s contract prohibiting it from selling patient information, stakeholders are concerned about the risks of providing a private, third-party entity with access to patient data. Some are concerned about the opportunity for Konza to utilize the data for its own business purposes. Even with appropriate safeguards, Konza’s possession of sensitive patient information introduces an additional point of vulnerability in the data-sharing chain and increases the potential for unauthorized access or cyberattack. Because of the concerns surrounding NEISS-R, most notably the fear of violating federal privacy laws, some hospitals have declined to participate.

Healthcare organizations should continue to monitor developments surrounding the NEISS-R program, including publication of any formal notice and comment period, congressional or state attorney general inquiry, legal challenges, and regulatory guidance from HHS or ASTP/ONC that may affect its implementation. Organizations should not treat participation as compulsory without analysis and should document the basis for whatever position they take. Organizations considering participation should request the full data specification—including the diagnostic code list, message types, retention terms, downstream recipients, and de-identification methodology—and carefully review any agreements with Konza to assess whether the proposed data-sharing arrangements comply with applicable federal and state privacy laws.

If participation is desired, organizations should seek contractual limits on scope, deletion timelines, audit rights, breach notification terms, prohibitions on secondary use, and indemnification, and should confirm the specific Privacy Rule provision on which each disclosure will rely. Any entity considering participation should also evaluate whether its EHR systems can support the program’s automated data extraction and transmission while also maintaining sufficient security controls, and whether the extraction can exclude specially protected categories. Finally, any participating organization should update its accounting of disclosures processes and notice of privacy practices and should be prepared to address patient concerns regarding the collection and disclosure of emergency department data.

This post was co-authored by Grace Owens, a law clerk in Burr & Forman's Daniel Island office. Grace attends Mercer University Walter F. George School of Law.

References

  • https://kffhealthnews.org/health-industry/cpsc-consumer-product-safety-commission-trump-er-injury-data-grab-neiss-konza/
  • https://www.cpsc.gov/Newsroom/News-Releases/2026/CPSC-Modernizes-Decades-Old-Injury-Surveillance-System-to-Protect-More-Americans-Faster
  • https://distilinfo.com/2026/07/22/neiss-r-injury-surveillance-cpsc/
  • https://www.cpsc.gov/s3fs-public/JANUARY-2025-NEISS-CPSC-only-Coding-Manual-Rev-1_0.pdf
  • https://www.cpsc.gov/s3fs-public/FY-2026-Mid-Year-Memo-to-Commission_V2-bl-signed.pdf
  • https://www.usaspending.gov/award/CONT_AWD_61320625C0001_6100_-NONE-_-NONE-
  • https://consumerfed.org/news/blogs/modernization-or-misstep-new-injury-surveillance-and-personal-health-data-demands-from-the-cpsc/
  • https://www.cpsc.gov/s3fs-public/NEISS_Overview_Fact_Sheet_2026.pdf
  • https://www.cpsc.gov/Safety-Education/Safety-Guides/General-Information/Who-We-Are---What-We-Do-for-You
  • https://www.cpsc.gov/Join-NEISS/What-is-NEISS
  • https://www.cpsc.gov/Research--Statistics/NEISS-Injury-Data/Neiss-Frequently-Asked-Questions


Related Professionals

Related Capabilities

Burr
Jump to Page
Arrow icon Top

Contact Us

Cookie Preference Center

Necessary Cookies

Always Active

Necessary cookies enable core functionality such as security, network management, and accessibility. These cookies may only be disabled by changing your browser settings, but this may affect how the website functions.

Analytical Cookies

Analytical cookies help us improve our website by collecting and reporting information on its usage. We access and process information from these cookies at an aggregate level.