A tiny federal company tasked with defending the general public from accidents attributable to garden mowers and coffeemakers is demanding that among the nation’s greatest well being techniques flip over detailed, personally identifiable medical records of all sufferers who search assist at their emergency rooms.
The Consumer Product Safety Commission, chargeable for monitoring and issuing recollects of harmful merchandise bought within the U.S., started discreetly pressuring hospital executives this yr to share personally identifiable well being information with a non-public contractor. But hospital legal professionals and different business consultants have questioned the company’s authority to gather, its capability to safeguard such a swath of delicate info, and whether or not it has adopted the authorized course of to overtake its surveillance system.
After KFF Health News requested the CPSC concerning the new system, the agency announced this system on July 21. Left unmentioned, nonetheless, is the alarm it has raised amongst hospital executives, in addition to the character and extent of the company’s information demands.
In a stark departure from its product-focused mission, the company’s aim is to acquire tens of millions of Americans’ medical records from emergency room visits for many accidents, from a damaged bone to a childhood vaccine response or perhaps a suicide try, in line with paperwork and emails obtained by KFF Health News, in addition to interviews with 5 folks concerned or conversant in the discussions.
A CPSC official additionally insisted within the emails that the establishments present all ER sufferers’ identifiable info — similar to names, addresses, diagnoses, and different private particulars — to the contractor, Konza Health, for evaluation. In correspondence with hospital executives, Konza representatives described participation as “mandatory” or “required.”
As a situation of viewing the correspondence, KFF Health News agreed to not republish among the emails it obtained.
The CPSC needs no less than 100 hospitals to begin sending detailed medical records by the top of this yr, in line with an internal memo.
“The whole thing is troubling,” mentioned Sharona Hoffman, a professor of well being legislation at Case Western Reserve University, who famous that giving a non-public entity entry to a sweeping assortment of knowledge will introduce dangers to affected person privateness. “If this company really is collecting identifiable information, that is worrisome for patients.”
The new mission was launched amid upheaval on the historically unbiased company, which is with no governing board since President Donald Trump fired the CPSC’s three Democratic board members. Nearly 1 in 5 profession staffers left the CPSC within the first 16 months of the brand new administration, in line with a KFF Health News evaluation of federal workforce information.
The initiative additionally comes because the Trump administration has sought unprecedented entry to tens of millions of Americans’ medical records, with the Office of Personnel Management requesting federal staff’ delicate well being info and Health and Human Services Secretary Robert F. Kennedy Jr. using a private organization to gather extra medical records for his research on vaccines and autism.
Steve Roney, CPSC spokesperson, mentioned in an emailed assertion on July 10 that CPSC is “modernizing” its surveillance system. Asked whether or not the CPSC will file complaints towards hospitals that don’t take part, he mentioned solely that whereas the earlier system “operated as a voluntary program, the ability of hospitals to opt out limited the sample size and usefulness of the data.”
Roney additionally acknowledged that the company had not but notified the general public, as “required by law.”
Federal legislation requires the company to supply discover and a public remark interval earlier than requesting info from 10 or extra entities, a step it has not taken regardless of plans for 100 hospitals to affix the surveillance system. KFF Health News independently confirmed with over a dozen hospitals that that they had been approached.
Federal public well being authorities cannot legally mandate that personal well being information be reported. But CPSC officers have suggested publicly and privately that if hospitals decline to share information with the brand new surveillance system, they could possibly be topic to strict penalties from a data-sharing regulation referred to as “information blocking.”
Yet some hospital executives say they’re reluctant to share sufferers’ delicate information as a result of they’re involved a couple of completely different violation — that of federal privacy law.
Dozens of ERs throughout the nation already take part within the CPSC’s voluntary National Electronic Injury Surveillance System, or NEISS, by which educated hospital staff report accidents involving shopper merchandise, nearly all the time stripped of sufferers’ identifiable info. The system helps the CPSC determine merchandise, similar to child loungers, toys, and family home equipment, with a sample of injuring shoppers.
The new harm surveillance program goes a lot additional.
At a toy business commerce occasion in February, appearing CPSC Chairman Peter Feldman mentioned the company is “investing in AI-enabled workflows that improve the quality and quantity of injury surveillance data, while also building up digital infrastructure to handle a massive new volume of electronic health records.”
Konza Health, a Kansas-based group that runs the state’s well being information change, will mechanically pull and analyze medical records of all affected person visits from ERs nationwide. Konza gained a five-year contract value as much as $15.9 million with CPSC final fall.
In e mail correspondence with hospital know-how officers, Konza Health President and CEO Laura McCrary additionally has described ERs’ participation as “required,” stipulating that they share sufferers’ records with figuring out info.
McCrary informed KFF Health News by e mail that the corporate shouldn’t be utilizing AI to course of the records it receives, saying as a substitute that Konza will use “advanced analytic parsing and filtering capabilities.” Roney, the CPSC spokesperson, didn’t reply questions concerning the use of AI.
For years, company officers have discussed transferring away from human contractors and automating NEISS to save lots of money and time.
But with out staff on-site, hospital staffers might now not obtain coaching to find out what scientific info is vital to incorporate for the CPSC. In brief, the modifications may dilute the standard of the product security information the company collects.
“They want to suck in as much data as possible, but I’m not sure how thoughtful they’re being about what is collected and what is actually needed by the agency,” mentioned former CPSC chair Alexander Hoehn-Saric, one of many Democratic appointees Trump fired final yr.
Wanted: Injuries from vaccines and stingrays
The CPSC’s new information assortment seems to contradict its personal 214-page operating manual, which instructs hospitals to not embody identifiable info “such as names, birthdates, or addresses” when reporting circumstances.
The company is meant to obtain sufferers’ figuring out info solely when wanted for follow-up investigations, which occurs in fewer than 1% of reported circumstances, in line with the guide.
The CPSC has additionally traditionally restricted the records it collects to reduce privateness violations in case of an information breach.
The danger shouldn’t be hypothetical: From 2017 to 2019, the company improperly launched private well being info of round 30,000 folks, a disclosure {that a} high Republican on the time called “concerning.”
Konza, nonetheless, will obtain much more delicate info on many extra folks. McCrary mentioned in a press release that Konza will take away sufferers’ names, addresses, and medical info “not needed by CPSC” earlier than sharing records with the company.
Leaving a non-public group to gather delicate info introduces dangers, together with that it could possibly be stolen or used for enterprise functions, mentioned Hoffman, the Case Western professor.
“Very often, they will use information for marketing because now they’re going to know what conditions people have,” she mentioned.
Roney mentioned that its contract with Konza, which has not been made public, prohibits the group from promoting or advertising and marketing the information it collects.
The CPSC’s guide additionally identifies sorts of ER visits that shouldn’t be reported to the CPSC, which has jurisdiction over solely sure shopper merchandise. Excluded accidents are these attributable to meals, unlawful medicine, medical gadgets, alcohol, or crops, in addition to accidents that didn’t contain shopper merchandise — similar to a reduce from a rock or damaged bones from a fall on the bottom — and suicide makes an attempt by adults.
But in a contract offered to at least one hospital and reviewed by KFF Health News, Konza set no such limits on the knowledge it will collect from ER records and mentioned it will maintain onto affected person well being info for no less than 30 days.
In an e mail despatched to hospital know-how officers, McCrary wrote that Konza would offer CPSC with records when a affected person is handled within the ER for any of greater than 10,000 situations. The expansive record of diagnostic codes Konza offered within the e mail consists of accidents that don’t contain shopper merchandise.
Child accidents ensuing from “poisoning by” vaccines or contact with stingrays, neither of which is regulated by the CPSC, are included within the record.
A restricted variety of hospitals as soon as shared deidentified information on all accidents — no matter product involvement — by the NEISS utilizing the Centers for Disease Control and Prevention’s injury-tracking program. But the CDC halted that information assortment, after funding and staffing have been reduce final yr, and has not restarted it.
CPSC Chief Data Officer Elizabeth Puchek, who joined the company late final yr after engineering U.S. Citizenship and Immigration Services’ information system, has informed hospitals in emails that they have to search an exemption from this system if they refuse to share sufferers’ emergency room records with Konza.
The CPSC’s targeted outreach has included some of the nation’s largest urban and rural health systems, as well as small, publicly owned hospitals.
Staff members at Mary Greeley Medical Center in Ames, Iowa, said that Konza and federal officials told them their participation in the new program was mandatory. The hospital, which has long participated in NEISS, signed a new contract in April to share its ER records with Konza.
Yet the hospital is reevaluating its participation after being notified that the funds it received to participate in NEISS were “no longer available,” spokesperson Steve Sullivan said.
Several hospital executives, lawyers, and others have raised doubts about CPSC’s claimed authority.
Harborview Medical Center spokesperson Susan Gregg said the Seattle hospital’s emergency room has “voluntarily submitted de-identified data for many years, but we are not obligated to report this information.”
In Boston, Mass General Brigham has declined to participate in the new program, with spokesperson Kelly Mitchell saying that “to protect patient privacy, we are unable to provide these medical records.”
Henry Ford Health in Detroit; St. Luke’s in Boise, Idaho; and Sanford Health based in Sioux Falls, South Dakota — which together handle over a million ER visits a year — are among the health systems that have been approached but not yet entered into an agreement with Konza, according to representatives. Several of the nation’s busiest hospital systems targeted for the program — including the Mayo Clinic in Minnesota, Yale New Haven Hospital in Connecticut, Nationwide Children’s Hospital and the Cleveland Clinic in Ohio, and Baylor Scott & White Health in Texas — declined to answer questions about whether they’re participating.
Hoehn-Saric, the agency’s former chairman, said he was surprised that the CPSC would insist that hospitals provide identifiable records from all emergency room visits.
“This idea that they can simply demand patient information from a hospital and that the hospital would provide it — I really don’t understand the basis for that,” he said.
KFF Health News is a nationwide newsroom that produces in-depth journalism about well being points and is without doubt one of the core working applications at KFF — the unbiased supply for well being coverage analysis, polling, and journalism.