The federal agency that recalls dangerous toys, faulty appliances and other unsafe consumer products is asking hospitals across the country for something it has never sought on this scale: patients' emergency room records.
According to a report by KFF Health News, the U.S. Consumer Product Safety Commission (CPSC) has asked hospitals to provide records containing personally identifiable information, including patients' names, addresses, diagnoses and other details. The information would be collected by a private contractor, Konza Health, and analyzed on the agency's behalf.
The request isn't limited to injuries involving consumer products.
KFF reports the records could include more than 10,000 different medical conditions, ranging from broken bones and vaccine reactions to attempted suicides. Emergency rooms in the United States see about 43.5 million injury-related visits each year, according to the Centers for Disease Control and Prevention.
That broad scope has caught the attention of hospitals and privacy experts alike.
The CPSC's own operating manual tells hospitals not to include identifying information such as names, birth dates or addresses when reporting most injuries. The manual says patient identities are typically requested only for follow-up investigations, which make up less than 1% of reported cases.
Konza Health President and CEO Laura McCrary told KFF the company would receive records for patients treated for thousands of conditions, including many that have nothing to do with consumer products. She said Konza would strip out patients' names, addresses and any medical information "not needed by CPSC" before sending records to the agency.
An internal CPSC memo obtained by KFF says the agency expects at least 100 hospitals to begin sharing information by the end of the year.
Not every hospital is on board.
Susan Gregg, a spokesperson for Harborview Medical Center, told KFF the hospital has "voluntarily submitted de-identified data for many years, but we are not obligated to report this information."
Mass General Brigham in Boston has also declined to participate.
"To protect patient privacy, we are unable to provide these medical records," spokesperson Kelly Mitchell told KFF.
Health law experts say the proposal raises important privacy questions.
"The whole thing is troubling," Sharona Hoffman, a professor of health law at Case Western Reserve University, told KFF. "If this company really is collecting identifiable information, that is worrisome for patients."
Former CPSC Chairman Alexander Hoehn-Saric questioned whether the agency needs as much information as it is requesting.
"They want to suck in as much data as possible, but I'm not sure how thoughtful they're being about what is collected and what is actually needed by the agency," Hoehn-Saric told KFF.
The rollout has also drawn scrutiny because the CPSC did not publicly announce the expanded data request before approaching hospitals. Federal law generally requires agencies to provide public notice and allow time for public comment before requesting information from 10 or more entities. KFF confirmed that more than a dozen hospitals have already been contacted.
The CPSC has said hospitals can request an exemption if they choose not to participate.
For now, it's unclear how many hospitals will ultimately agree to share patient records. What is clear is that the request has sparked a debate that goes well beyond product safety, touching on patient privacy, government authority and how much personal medical information should be shared with federal agencies.
