Democrats urge consumer product agency halt public health modernization project

Kent Nishimura / AFP via Getty Images
The lawmakers say the project is particularly concerning as the Trump administration has a “broader pattern” of “seeking unprecedented access to Americans’ private data.”
A bicameral group of 12 Democrats wants the Consumer Product Safety Commission to “immediately suspend” a data collection modernization project that seeks to have major U.S. hospitals send emergency room patients’ personally identifiable medical records to a contractor, KONZA Health.
“We have significant concerns about the necessity and legality of this initiative, the adequacy of its privacy protections, and the purposes to which this trove of sensitive data may ultimately be put,” the lawmakers wrote in a Thursday letter sent to CPSC acting Chairman Peter Feldman.
When reached for comment, CPSC said it had not yet received the letter. A KONZA Health spokesperson said “we are reviewing the concerns raised and defer to CPSC for comment at this time.”
For months, CPSC and KONZA Health have asked hospitals nationwide to participate in a public health surveillance project known as NEISS-R. Under it, hospitals would send medical records to KONZA Health, which will “automatically filter and transmit minimum necessary” data that CPSC needs to detect potentially hazardous consumer products like lawn mowers, Nextgov/FCW previously reported.
The project, first reported by KFF Health, drew scrutiny from hospitals and consumer safety advocacy groups over data privacy concerns. Feldman explained how NEISS-R will protect patient data, including personally identifiable information, and that the program will be a voluntary collaboration with hospitals in a recent interview with Nextgov/FCW.
But Democrats remain concerned that the NEISS-R initiative will not adequately protect patient data.
“There is no plausible justification for requiring the name, birthdate, and home address of every emergency department patient, collected proactively and in bulk,” reads the letter led by Sen. Edward Markey, D-Mass., Sen. Richard Blumenthal, D-Conn., Rep. Janice Schakowsky, D-Ill., and Rep. Kevin Mullin, D-Calif.
Feldman previously told Nextgov/FCW that KONZA Health would retain some patient contact information for up to six months in rare instances where the agency wants to contact patients about extraordinary injuries.
But the lawmakers told Feldman his statement is an apparent contradiction because KONZA Health offered hospitals contracts stating that identifiable patient records will be deleted 30 days after receipt. The contracts also indicated some patient data held by KONZA Health would not be protected by HIPAA, the letter said.
“The Commission is therefore calling for hospitals to send identifiable medical information into a system with alarmingly little clarity about the enforceable rules that govern its use, retention, sharing, or deletion,” the lawmakers continued.
Democrats are alarmed that CPSC is asking hospitals to send KONZA Health data that is seemingly out of its public health mandate, such as vaccination and contacts with stingrays.
Feldman told Nextgov/FCW that CPSC will not be screening for information about stingray contacts but defended the agency’s authority to assess medical records for vaccinations and other injuries. He added that the agency will publish a full list of diagnostic codes KONZA Health will screen for through NEISS-R but did not offer a timeline.
The lawmakers also criticized Feldman for backtracking on claims that hospitals must share data with KONZA Health by telling Nextgov/FCW that participation in NEISS-R is voluntary.
“This reversal does not undo the coercion hospitals experienced, but rather raises the question of whether the Commission's purported legal justifications were ever more than post-hoc cover for an agenda that had little to do with its statutory authority,” the lawmakers wrote.
In informing hospitals they must participate in NEISS-R, CPSC and KONZA Health alluded to the possibility that not sharing data could violate federal “information blocking” rules. Feldman has said that the CPSC will not submit formal information blocking complaints to the Health and Human Services Department should hospitals not participate in NEISS-R.
Since Nextgov/FCW’s report, the agency has removed references to those rules on the NEISS website “without any public correction or acknowledgment that the claim it spent months promoting was without basis,” according to the letter.
Democrats wrote that CPSC appears to have bypassed federal requirements that agencies subject major data collection changes to notice and comment periods. Feldman did not commit to opening NEISS-R to public comment in an interview with Nextgov/FCW, even though an agency spokesperson previously told KFF Health CPSC has not yet notified the public “as required by law.”
“The Commission is advancing this effort amid a broader pattern of the Trump administration seeking unprecedented access to Americans’ private data,” the lawmakers conclude, pointing to the Office of Personnel Management’s plan to collect federal employees' medical records and Homeland Security’s move to obtain Medicaid records for deportment proceedings.
Democrats are requesting the CPSC answer a series of 11 questions about NEISS-R by Sept. 18.




