A coalition of high-ranking Democratic lawmakers has formally called on the Trump administration to immediately halt a newly launched federal surveillance initiative that systematically collects and analyzes the personally identifiable health records of Americans visiting emergency rooms.
The program, spearheaded quietly by the Consumer Product Safety Commission (CPSC), has sparked widespread backlash from hospital executives, healthcare legal experts, and privacy advocates. Originally established to monitor injuries related strictly to consumer goods, the agency’s expanded initiative sweeps up millions of detailed medical records for more than 10,000 distinct conditions and injuries—ranging from routine ailments to sensitive personal matters like vaccine reactions, suicide attempts, and animal envenomations—regardless of whether a consumer product was involved.
The initiative marks a significant departure from decades-long federal data practices and has placed the CPSC at the center of a burgeoning national debate over health data privacy, federal overreach, and the boundaries of executive authority.
Legislative Pushback and Accusations of Overreach
Led by Senator Ed Markey (D-Mass.), a member of the Senate Health, Education, Labor, and Pensions Committee, a group of prominent lawmakers dispatched an urgent letter to CPSC Acting Chairman Peter Feldman demanding the immediate suspension of the program, officially designated as NEISS-R.
In the strongly worded correspondence, lawmakers argued that the sweeping collection of identifiable patient data far exceeds the statutory mission and legal authority of the commission. Joining Markey in signing the document were prominent congressional leaders, including Senator Richard Blumenthal (D-Conn.), Representative Jan Schakowsky (D-Ill.), and Senator Ron Wyden (D-Ore.), ranking member of the Senate Finance Committee.
"This unprecedented and sweeping effort to collect identifiable patient data is untethered from the Commission’s statutory mission and authority, and is ripe for misuse by an administration that has repeatedly sought access to Americans’ most personal information," the lawmakers wrote. "Americans should be able to seek medical care without fear that their personal health information will be swept into a federal database and repurposed for political ends."
The lawmakers emphasized that the administration bypassed formal regulatory procedures and failed to publish a detailed, legally required public plan for its expansive data collection. They also highlighted contradictory statements and sudden policy reversals from the agency regarding whether hospital participation was mandatory or voluntary, raising serious questions about the transparency and legality of the rollout.
Evolution of the National Electronic Injury Surveillance System
To understand the controversy surrounding NEISS-R, it is necessary to examine the history of the original data-gathering mechanism it replaced. For decades, the CPSC operated the National Electronic Injury Surveillance System (NEISS), a voluntary reporting network utilizing trained hospital personnel embedded within approximately 70 medical facilities nationwide.
Historically, the scope of NEISS was narrowly tailored to monitor product-related safety hazards—such as malfunctioning household appliances, dangerous toys, or defective power tools. Furthermore, historical data protocols dictated that personally identifiable information (PII) was rarely requested, accounting for fewer than 1% of total cases and typically reserved exclusively for narrow follow-up investigations.
The landscape shifted dramatically early this year when CPSC officials executed a quiet overhaul of the system. Rebranded as NEISS-R, the program expanded its purview to capture virtually all emergency room presentations. Instead of relying solely on hospital-employed safety coordinators, the agency contracted out the massive data harvest to Konza Health, a Kansas-based health information technology company that secured a lucrative five-year contract worth up to $15.9 million last year.
Coercion, Compliance, and the Threat of Penalties
Internal documents, emails, and contract language reviewed by investigative journalists revealed a high-pressure campaign directed at hospital executives. Representatives from Konza Health and CPSC officials repeatedly characterized hospital participation in the new system as "mandatory" or "required."
In internal communications, CPSC Chief Data Officer Elizabeth Puchek informed healthcare administrators that hospitals would be required to formally apply for exemptions from the program or face strict legal penalties. To enforce compliance, the agency leveraged federal "information blocking" regulations—rules originally designed under the 21st Century Cures Act to ensure that patients could freely access their own electronic health records.
The CPSC’s public website and official communications asserted that these data-sharing mandates compelled hospitals to surrender electronic health information (EHI) upon request to public health authorities, threatening non-compliant institutions with federal sanctions.
This aggressive posture drew immediate and fierce resistance from the healthcare sector. In August, the American Hospital Association (AHA) submitted a formal comment letter expressing profound "confusion and concern about the scope of patient information" demanded by the federal government and criticizing the abrupt shift in policy.
Facing mounting pushback from hospital legal teams and privacy advocates, the CPSC began quietly backtracking. In recent weeks, the agency scrubbed references to "information blocking" penalties from its public-facing web pages.
Pressed on the discrepancies, CPSC Acting Chairman Peter Feldman—a Trump appointee—insisted in a subsequent interview that the program would remain entirely voluntary. However, lawmakers argued that the administration’s tactical retreat does little to erase the months of intimidation and coercion experienced by hospital administrators.
Broader Context of Federal Health Data Acquisition
The CPSC’s aggressive data grab does not exist in a vacuum. It is part of a broader, synchronized effort across multiple federal agencies during the current administration to acquire large-scale, sensitive medical data on American citizens.
Critics and government watchdogs have pointed to several parallel initiatives:
- The Office of Personnel Management (OPM): Initiated requests for the sensitive health records of federal employees.
- Department of Health and Human Services (HHS): Under the leadership of Secretary Robert F. Kennedy Jr., the agency has deputized private organizations to harvest extensive medical records to fuel independent studies on vaccines and autism.
This aggregation of private medical data by non-traditional federal watchdogs has alarmed civil liberties organizations, who warn that the decentralization and outsourcing of health data collection to private vendors creates severe vulnerabilities regarding data security, corporate misuse, and mission creep.
Official Responses and Next Steps
Thus far, the CPSC has offered limited commentary regarding the mounting political and legal pressure. CPSC spokesperson Steve Roney acknowledged receipt of the lawmakers’ oversight letter but declined to answer specific substantive questions about the program’s legal foundation or its future trajectory.
"We received the letter, and will respond directly, through the appropriate channels," Roney said in a brief official statement.
As the September 18 deadline set by Senator Markey and his colleagues approaches, the commission faces mounting pressure to justify its actions. The inquiry demands a full accounting of the legal rationale behind the Konza Health contract, the protocols established to safeguard patient privacy, and an explanation for the agency’s shifting stance on mandatory versus voluntary compliance.
Implications for Patient Privacy and Healthcare Trust
The confrontation over NEISS-R highlights a delicate tension between public health surveillance and individual medical privacy. Healthcare ethicists warn that if patients believe their emergency room visits—particularly regarding sensitive behavioral health issues, substance use, or controversial medical treatments—are being funneled into federal databases via private contractors without explicit consent, it could deter vulnerable populations from seeking necessary emergency care.
Furthermore, the involvement of third-party private entities like Konza Health raises critical questions about data governance, commercial access to protected health information (PHI), and the erosion of traditional HIPAA protections under the guise of public health and consumer safety mandates.
As Congress steps up its oversight and hospital networks demand absolute clarity, the future of the NEISS-R program remains highly uncertain, serving as a critical test case for the limits of federal surveillance over personal health data.









Leave a Reply