CPSC NEISS Remodel Raises HIPAA Concerns Over Hospital Patient Data Requests

The United States Consumer Product Safety Commission is seeking digital patient data from hospitals for the National Electronic Injury Surveillance System Remodel project while concerns have been raised about the scope of the requested information and its compatibility with HIPAA requirements.

NEISS Remodel Project

The National Electronic Injury Surveillance System has collected information on consumer product-related injuries in the United States for more than 50 years. The medical records provided by about 70 hospital emergency departments are manually reviewed and coded. Fourteen states are not currently represented in the project. The limited geographic coverage has reduced CPSC’s ability to identify rare and emerging product hazards.

The planned NEISS Remodel project would expand coverage to all 50 states. The project would automate data collection through electronic health record infrastructure and exchange information through a federally designated Qualified Health Information Network. CPSC awarded Konza Health in Kansas a $15.9 million contract in 2025 to support the NEISS Remodel project.

Automated Patient Data Collection

Under the existing system, emergency department nurses review patient charts and identify consumer-related accidents before entering information into a national database. Under NEISS Remodel, data collection would be automated. Konza Health would remove identifying information before data transfers to CPSC.

Letters sent by Konza Health to hospitals describe a process that would use accident-related diagnosis codes to identify patients who may have experienced consumer product-related accidents. Konza Health may request additional clinical information for identified accidents and give that information to CPSC for follow-up.

Scope of Requested Information

Privacy concerns have been raised because the automated process would involve identifiable patient information being sent to Konza Health. The information requested through the automated system may include data related to consumer product injuries. KFF Health News reported that the requested information could include medical records from emergency room visits involving injuries ranging from broken bones to childhood vaccine reactions and suicide attempts.

Communications between Konza Health and technology officials at one hospital indicated that emergency room data was requested for more than 10,000 conditions, including injuries unrelated to consumer products.

The broader request has led to resistance from some hospitals. CPSC and Konza Health have suggested that refusing to provide required data could be viewed as information blocking and could result in penalties.

HIPAA Privacy Compliance

Hospitals are not required under HIPAA to submit data to CPSC, but may be permitted to disclose information for public health purposes. Disclosures must be limited to the minimum necessary information for the purpose of the disclosure.

CPSC is collecting information to fulfill its consumer product safety mission. The disclosed data should therefore be limited to that purpose. If CPSC needs more data than it previously gathered, additional rulemaking would be necessary. The HIPAA Minimum Necessary Rule is relevant to the requested disclosures.

The information blocking regulations contain a privacy exception intended to prevent health information from being required to be shared in a prohibited manner by state or federal privacy laws. Participating hospitals could face competing compliance concerns. Hospitals that decline to provide requested information could face potential information blocking penalties. Hospitals that provide information that do not comply with HIPAA could face potential HIPAA penalties.

Consumer Reports Position

Consumer Reports supports the NEISS program and has supported strengthening the system because it provides information about products associated with injuries. William Wallace, Director of Safety Advocacy at Consumer Reports, said the organization supports modernizing how CPSC collects and analyzes emergency room data, but objects to collecting personal medical records unrelated to consumer product safety.

The organization also called for CPSC to provide information about what it would collect, how the information would be analyzed, and how sensitive information would be protected before changing the NEISS program. Consumer Reports also called for CPSC to make its contract with Konza Health public and provide a complete proposal for public comment.

Twitter Facebook LinkedIn Reddit Copy link Link copied to clipboard
Photo of author

Posted by

John Blacksmith

John Blacksmith is a journalist with several years experience in both print and online publications. John has specialised in Information technology in the healthcare sector and in particular in healthcare data security and privacy. His focus on healthcare data means he has specialist knowledge of the HIPAA regulations. John has a degree in journalism and many years experience.
Twitter
LinkedIn