CPSC’s Identifiable ER Data Push Meets Hospital Resistance
Yesterday’s clearest privacy risks came from system design rather than a new law: a federal agency seeking identifiable records before de-identification, an AI sharing feature making conversations searchable, and another large breach exposing customer data.
The CPSC plan was the most consequential development. It moves the privacy question upstream—from how information is protected after receipt to whether names, addresses, and diagnoses should enter a contractor-run pipeline at all—while hospitals are already constraining a program whose authority and process remain disputed.
Reporting by KFF Health News, carried by the Orange County Register and other outlets, detailed the CPSC’s effort to have at least 100 hospitals provide emergency-room records through Konza Health by the end of 2026. The records could include names, addresses, diagnoses, and other details before filtering; the proposed scope covers more than 10,000 conditions, including some not clearly connected to consumer products.
The legal and procedural foundation remains unsettled. CPSC officials described participation as required, but hospital lawyers questioned the agency’s authority, and the agency acknowledged it had not completed the public notice-and-comment process normally required for information requests covering 10 or more entities. Mass General Brigham declined to participate, while other hospitals reconsidered or withheld agreements.
Origin Energy confirmed unauthorized access affecting about 900,000 current and former customers. SecurityWeek reported that the exposed information included names, birth dates, contact details, account information, and partial payment card or bank account numbers. An attacker’s claim of two million victims remains unconfirmed.
Reports that publicly shared Claude conversations appeared in Google searches exposed a different kind of product risk. This was not described as an intrusion into private chats: users had created public links. But reported examples involving health, legal, business, and children’s information showed how easily a sharing action can outlive the audience a user had in mind.
Utah’s announcement tied to the $18 million multistate 23andMe settlement was implementation rather than a new enforcement turn. Even so, it kept attention on the unusually long afterlife of genetic-data failures: the 2023 breach, bankruptcy, consumer compensation, and restrictions sought for future use of previously collected data now form one continuing accountability process.
Key Points
- Hospital resistance is becoming an operational privacy control in its own right. In the absence of a settled mandate, legal reviews and refusals are determining whether the CPSC program can move from a federal plan to a functioning national data pipeline.
- De-identification after collection is not equivalent to collecting de-identified data. Under the reported design, Konza would still receive identifiable clinical records before removing unnecessary fields, creating vendor-access, retention, and security questions that the traditional reporting model largely avoided.
- The Claude episode showed that product language matters as much as technical access controls. A link may be public in platform terms yet feel limited to the person who created it; search indexing turns that mismatch into durable exposure, potentially extending to caches and archives even after a link is revoked.
- Origin Energy’s response illustrates why early assessments of threat claims must remain provisional. The company began investigating in early July, initially found the information lacked credibility, and confirmed access after receiving new information on July 22.
- A quieter compliance issue emerged around AI-generated client-call records. Advisor Perspectives noted that SEC Rule 204-2 may treat transcripts and summaries created for RIAs as books and records, potentially requiring five-year retention and production to the SEC. That is an application of existing rules, not a new AI regulation.
Implications
Hospitals approached by CPSC should assess the agency’s legal authority, HIPAA basis, minimum-necessary scope, patient-notice posture, and whether participation is actually mandatory before transferring records. Vendor terms should address access, retention, subcontractors, deletion, incident response, and the point at which identifiers are removed.
Product teams should treat public-link features as publication systems, not lightweight collaboration tools. Clear warnings, noindex controls, revocation behavior, cache-removal procedures, and safeguards against sharing sensitive content belong in the core design.
Organizations handling extortion claims need a process for revisiting initial credibility judgments as new evidence arrives. Origin Energy’s experience shows that a weak first lead can still develop into a breach affecting hundreds of thousands of people.
RIAs using AI assistants on client calls should determine whether generated transcripts or summaries fall within existing recordkeeping duties before deploying them widely. Privacy, consent, retention, vendor access, and deletion settings cannot be evaluated separately from SEC compliance.
Watchpoints
Watch
Whether CPSC publishes a formal legal basis, privacy documentation, data-minimization rules, and the missing notice-and-comment materials.
Watch
Whether additional hospital systems refuse participation or negotiate narrower data fields, shorter retention, and stronger contractual safeguards.
Watch
Origin Energy’s final affected-person count, regulatory response, and any evidence that the exposed data has been used for fraud or targeted phishing.
Watch
Whether Anthropic or search engines change indexing controls for Claude share pages and how previously indexed material is removed from caches and archives.
Watch
How the 23andMe settlement’s deletion, security, and future-use restrictions are implemented by the entities now controlling the company’s genetic-data assets.
Fallout
Meaningful movement was concentrated in three subjects: government access to identifiable health records, the continuing operational and legal consequences of large breaches, and the way AI tools can turn apparently limited interactions into public or regulated records.
Identifiable Health Data in Government Programs
Federal injury surveillance has traditionally relied on reports stripped of identifying information. The CPSC initiative would place identifiable emergency-room records into a contractor-operated collection and filtering process, materially changing where privacy risk enters the system.
Fresh developments
Yesterday’s reporting clarified the intended scale and mechanics: at least 100 hospitals, a five-year Konza Health contract worth up to $15.9 million, more than 10,000 diagnostic conditions, and reported retention of patient health information for at least 30 days. It also clarified the resistance. Hospitals are questioning both the CPSC’s authority to require the records and their own authority to disclose them.
Why we noticed
The important distinction is architectural. Removing identifiers before agency use may reduce what the CPSC ultimately sees, but it does not eliminate the contractor’s initial access to sensitive records. That concern is sharpened by a documented CPSC disclosure of personal health information involving approximately 30,000 people between 2017 and 2019.
Watch for:
- A published legal basis and completed public process
- Binding limits on Konza’s access, retention, and downstream use
- Further hospital refusals or negotiated limits
Large-Scale Breaches and Their Aftermath
Large organizations continue to disclose compromises of identity, account, payment, health, and genetic information. The immediate incident and the eventual legal consequences increasingly unfold on different timelines.
Fresh developments
Origin Energy confirmed that roughly 900,000 current and former customers were affected, giving a firmer scale to an incident first investigated earlier in July. At the other end of the timeline, Utah’s participation in the $18 million 23andMe settlement showed a 2023 breach continuing through state enforcement, bankruptcy, compensation, and controls on data held by successor entities.
Why we noticed
These cases show two different phases of the same governance problem. Origin Energy is still establishing incident scope and potential misuse; 23andMe is demonstrating how accountability can persist years later, especially when the compromised information is genetic and cannot meaningfully be replaced.
Watch for:
- Origin Energy’s final scope and regulatory notifications
- Evidence of phishing, fraud, or publication of stolen data
- Implementation of 23andMe deletion and future-use restrictions
AI Tools Create Durable Records
AI products are making it easier to share, summarize, and record sensitive interactions. Those conveniences can also turn material users perceive as temporary or narrowly shared into searchable, archived, or legally retained records.
Fresh developments
Publicly shared Claude conversations were reported in Google results, apparently because the share pages were accessible to search engines rather than because private accounts were breached. Separately, compliance guidance for RIAs warned that AI-generated client-call transcripts and summaries may fall under SEC Rule 204-2 recordkeeping requirements.
Why we noticed
The common issue is durability. A share link can become searchable beyond its intended audience, while an automated summary can become a regulated business record. Organizations adopting AI tools therefore need to govern not only what the systems process, but what new records they create and how long those records persist.
Watch for:
- Changes to Claude share-page indexing and user warnings
- Guidance on removing cached or archived conversations
- How RIAs classify and retain AI-generated call records
Final Thought
Yesterday underscored the difference between data that never needs to be collected and data promised to be protected after collection. Controls applied downstream cannot erase the exposure created when sensitive information enters a system upstream.
