CPSC Demands Private Patient Data from Hospital ERs

For decades, Americans have accepted that government agencies collect certain information to protect public health and consumer safety. Hospitals report infectious diseases. Manufacturers report defective medical devices. Emergency departments contribute anonymous injury data that help identify dangerous products before more people are hurt.

These surveillance systems serve an important purpose. They identify patterns that no single hospital, manufacturer, or physician could detect alone. When they work as intended, they save lives.

But every surveillance system depends on one essential principle, to collect only the information necessary to accomplish the mission.

That principle deserves renewed attention as the Consumer Product Safety Commission (CPSC), under the Trump administration, seeks to expand the amount of information collected through its National Electronic Injury Surveillance System (NEISS). According to reporting by KFF Health News, the agency is requesting access to additional emergency department information that critics argue extends well beyond traditional product injury surveillance.

The debate should not begin with politics. It should begin with a simple question,
“what information does the government need to keep consumers safe?”

Safety surveillance is a legitimate government function

The CPSC has a clear congressional mission: identify dangerous consumer products and protect the public from unreasonable risks of injury.

Its NEISS database has long helped investigators identify emerging hazards involving everything from children’s toys and power tools to household appliances and recreational equipment. The data allow analysts to recognize injury trends that individual hospitals would never see on their own. Few would question the value of that mission.

Likewise, the Food and Drug Administration (FDA) relies on adverse event reporting to detect problems involving medical devices, pharmaceuticals, and biologics. These systems have led to recalls, safety alerts, design improvements, and labeling changes that have undoubtedly prevented injuries.

Effective surveillance is not the problem. The question is whether expanding surveillance requires expanding access to patients’ personal information.

HIPAA is not the whole answer

Whenever government seeks greater access to medical information, one law inevitably enters the discussion: the Health Insurance Portability and Accountability Act, better known as HIPAA.

The law is often misunderstood, because it does not prohibit every disclosure of patient information. The law contains numerous exceptions that permit hospitals and healthcare providers to share information for public health activities and other purposes authorized by law.

That means the central question in this debate is not simply whether the CPSC can legally receive certain information. The more important question is whether it needs that information to carry out its statutory mission.

Legality and necessity are not the same thing. Good regulatory policy asks both questions.

If the government seeks broader access to emergency department records, it should clearly demonstrate why each category of information is necessary, how it advances consumer product safety, and why less personally identifiable information would not achieve the same objective.

HIPAA establishes the legal framework for protecting patient information. Public policy must still determine how much information government agencies should collect, retain, and use.

Regulatory lines are already more complicated than most people realize

Medical device professionals understand something most Americans do not. Federal responsibility for product safety is already divided among multiple agencies.

Consider hospital bed injuries. The FDA regulates the hospital bed itself as a medical device. The CPSC regulates many aftermarket bed rails that are sold separately for consumer use. A single patient injury may involve products falling under two different regulatory authorities.

It is an unusual, and often confusing, division of responsibility. That complexity makes coordination between agencies essential, but coordination should not automatically become justification for collecting more personal information than is necessary.

The forgotten principle of data minimization

One of the foundational principles of modern privacy and information governance is data minimization.

Whether found in cybersecurity frameworks, international privacy standards, quality systems, or healthcare compliance programs, the concept is remarkably consistent – collect only the information necessary to accomplish a legitimate purpose.

Organizations are expected to justify why each category of information is needed. They are expected to avoid collecting data simply because technology makes it possible. And they are expected to recognize that every additional piece of personal information carries additional responsibility and additional risk.

That principle applies just as much to government agencies as it does to private companies.

The burden of proof belongs to the government

If CPSC believes broader emergency department data are necessary, it should explain why. Not in general terms but in specific detail. The request must explain why CPSC is adding new data elements, and how it will improve product safety.

It must also consider whether the same objective can be achieved using de-identified information and what safeguards are in place to prevent secondary uses not related to product safety.

The agency must also define, in writing, how the information will be stored and used, how long and how the information will be retained, and who will have access to the information (and for what specific purposes).

Those are not political questions; they are questions of sound governance. Public agencies routinely ask manufacturers to justify design decisions, risk controls, validation activities, and data collection practices.

Citizens should reasonably expect the same discipline from government.

Trust is part of every surveillance system

Public health surveillance depends on public confidence. Patients generally accept that information will be collected when they believe it serves a legitimate, clearly defined purpose.

That trust becomes more fragile when the purpose appears to expand beyond its original scope, or when agencies fail to explain why additional information is necessary.

Whether the issue involves infectious disease, medical devices, consumer products, or emergency room visits, transparency matters. So does restraint.

The more information government collects, the greater its obligation to demonstrate that every requested field serves a clearly defined public purpose.

Conclusion

Consumer safety and personal privacy are not competing values. A well-designed regulatory system should protect both.

No one disputes the importance of identifying dangerous products before more people are injured. Surveillance systems such as NEISS have played an important role in improving consumer safety for decades.

But good regulatory policy follows an equally important principle of collecting only what is needed.

If more specific emergency department private patient data are truly necessary to fulfill the CPSC’s statutory mission, the agency should be prepared to explain exactly why. If the same safety objectives can be achieved using less (or no) personally identifiable information, that approach should be sufficient.

Americans should expect government agencies to respect not only the letter of HIPAA but also the broader principles that inspired it: collecting only what is necessary, protecting patient privacy, and maintaining public trust.

Effective regulation is built not only on authority, but also on proportionality, transparency, and public trust. Those principles should guide every agency entrusted with Americans’ personal information.