22. DRAFT - DHA Privacy Impact Assessment PIA_Processes and Procedures.docx

DOCX document 2 MB Posted

Attached to
Charleston Consolidated Storage Distribution Center Federal contract opportunity
Solicitation number
Not on record
Issued by
Department of the Army Corps of Engineers Engineering District Little Rock

About this file

This document provides notice of an upcoming solicitation for initial outfitting services at a consolidated storage and distribution center. The U.S. Army Corps of Engineers Little Rock District intends to issue a request for quote under simplified acquisition procedures for a total small business set-aside contract valued between $1.5-2 million. The scope of work involves initial outfitting of the Charleston Consolidated Storage and Distribution Center. A site visit is scheduled for August 23rd and questions may be submitted through August 25th. The anticipated period of performance is January 19th to March 19th, 2023. This pre-solicitation notice informs potential small business contractors of the upcoming requirement and relevant procurement details.

View the file

Other files for this federal contract opportunity

Other files attached to Charleston Consolidated Storage Distribution Center, newest first.
File Type Posted
16. DRAFT - Checklist_Control System Factory Acceptance Test and Site Acceptance Test.pdf PDF
9. DRAFT - JB Charleston CSDC_Existing Inventory_ 23Mar22.pdf PDF
29. DRAFT - Template-DHA RMF System Enterprise and Information Security Architecture.pdf PDF
26. DRAFT - Template_DHA RMF System Authorization Boundary.pdf PDF
0. DRAFT - SOW-FY22. IOT RD_PN89902_CSDC Charleston_2022.08.05.docx DOCX document
23. DRAFT - DHA RMF Information Flow Diagram.pdf PDF
14. DRAFT - JBCHS IDEA FONSI-FONPA_A7 Signed (2).pdf PDF
33. DRAFT - Template-System Level Configuration Management Plan.doc DOC document
3. DRAFT - Charleston CSDC IOT Project Status Report (PSR).xlsx XLSX spreadsheet
7. DRAFT - CSDC GC Schedule 30Jun22.pdf PDF
11. DRAFT - JSN U0096 3-phase 480 VAC Powered Battery Charger For JSN U0060 Electric Forklift.pdf PDF
2. Base Access WORKSHEET V9_Dec20_ACC (002).pdf PDF
30. DRAFT - Template-DHA-FE FRCS Vendor Risk Assessment_v2.0.docx DOCX document
17. DRAFT - DHA 27 41 43 Audio Video Conferencing.pdf PDF
19. DRAFT - DHA ACAS-NESSUS Scanning Guide-CUI.pdf PDF
12. DRAFT - DHA FE Wayfinding Guidelines-Signage Standards (Draft)_01Mar22.pdf PDF
11. DRAFT - JSN U1021 Wall-MountedWireGuidanceSystemLineDriverandGuidanceControlWire-Forklift(JSN U0060).pdf PDF
5. DRAFT - Interiors_JBC CSDC - DP2 FINAL_drawings.pdf PDF
1. DRAFT - Drawings Installation Map - CSDS and ACC.pdf PDF
8. DRAFT - JB Charleston CSDC_PRCL_v.2_21Jan21.pdf PDF
20. DRAFT - DHA FRCS Baseline Categorization Memorandum-1 Oct 2020.pdf PDF
0. DRAFT FY22 IOT CSDC_Div 00_CLIN BID Schedule.xlsx XLSX spreadsheet
15. DRAFT - JB Charleston CSDC_Facility Site Approval.pdf PDF
13. DRAFT - JB Charleston CSDC_Program for Design_5Feb22.pdf PDF
Draft Solicitation_Special Notice_Charleston CSDC.pdf PDF
25. DRAFT - Template_DHA RMF Security Control Plan_Implementation Guidance.xlsx XLSX spreadsheet
31. DRAFT - Template-Inventory Report-Hardware-Software.pdf PDF
6. DRAFT - JBC CSDC - DP2 FINAL_drawings.pdf PDF
10. DRAFT - JB Charleston CSDC_DOR-Provided Final Furniture-Equipment Package_17Jan22.pdf PDF
21. DRAFT - DHA MDE Categorization Memo.pdf PDF
11. DRAFT - JSN U0060 Electric Swivel Seated-Narrow-Isle 33' Vertical Swing Reach 3K Fork Lift.pdf PDF
32. DRAFT - Template-Ports-Protocols-Services Management Registry Update.xlsx XLSX spreadsheet
28. DRAFT - Template_Program of Record_DHA Info Sys Contingency Plan.docx DOCX document
2. Real ID TRI-Fold (15Sep20-V42).pdf PDF
27. DRAFT - Template_Information System_Incident Response Plan.docx DOCX document
24. DRAFTExample_IP Network External to Control System_Generic ICS Med-COI Boundary Diagram v4 (1).pdf PDF
18. DRAFT - DHA 27 52 33 Refrigerator Monitoring Systems.pdf PDF
Show all 37

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

DEF ENS E HEA LTH AGENCY

Privacy Impact Assessment Processes and Procedures

This reference provides a clear and straightforward overview to assist you with conducting a privacy risk assessment. The tools we use when facilitating a privacy risk assessment are privacy threshold analysis (PTA) and privacy impact assessments (PIA) which are important to the privacy and data protection of the life cycle information management.

Per Section 208 of the E-Government Act of 2002, federal agencies must conduct an analysis of how they handle personally identifiable information (PII). The Department of Defense (DoD) established the DoD Instruction 5400.16, DoD Privacy Impact Assessment (PIA) Guidance (DoDI 5400.16), implementing the requirements in the E-Government Act. The DoDI 5400.16 provides a standardized methodology across DoD for conducting PIAs. However, as privacy professionals, we are bound to have different interpretations of the requirements outlined in the laws, DoD policies, and guidance.

When you engage in conducting your privacy risk assessment, keep in mind that the PTA and PIA serve as valuable tools used to help all stakeholders understand the mechanics of the information system, the information collected, the privacy concerns, and the mitigation strategies for any potential privacy risks. The PTA and PIA process also allows the program manager or system owner to determine whether the information system is compliant with the E-Government Act, DoD policies, and guidance regarding privacy at any point in the life cycle.

It is with great enthusiasm that we provide these processes and procedures for your use to sail smoothly through the privacy risk assessment using the tools of the trade: PTAs and PIAs. We are hopeful that this reference will alleviate most differences in interpreting and understanding of the law, DoD policies, and guidance for conducting your privacy risk assessment. As you embark upon your journey of preparing a PTA and/or PIA for your information system, this is your opportunity to identify key problems and answer the hard questions.

Introduction The Defense Health Agency (DHA) Privacy and Civil Liberties Office (PCLO) is committed to ensuring the appropriate protection of privacy and civil liberties in the course of fulfilling its missions. The DHA and the Military Health System (MHS) utilize information and information technology (IT) resources to conduct their operations, and thus, PII are collected, maintained, and disseminated to provide services to tri-care beneficiaries, civilian employees, and contractors.

A privacy impact assessment (PIA), which is required by Section 208 of the E-Government Act of 2002, is an important process that assists the DHA PCLO in achieving its objective. Section 208 requires all Federal government agencies to conduct a PIA before developing or procuring information technology that collects, maintains, or disseminates PII or before initiating a new collection of information that will be collected, maintained, or disseminated using information technology and that includes any PII in certain situations involving the public. A PIA should also be completed or updated when changes are made to a system that create new privacy risk (e.g., conversion, significant mergers, new public access). The Office of Management and Budget OMB Circular No. A-130, Managing Information as a Strategic Resource (July 28, 2016), p. 75. A privacy threshold analysis (PTA) is a guideline from the NIST Special Publication 800-52, Guide to Protecting the Confidentiality of Personally Identifiable Information (April 2010), and is considered a best business practice within the DHA PCLO. A PTA is the first step in determining the necessary privacy protections for an information collection. It determines (1) whether an activity involves PII or otherwise may impact privacy; (2) whether a PIA is required; (3) whether an existing SORN covers an information collection, or if a new one is required; (4) and if any other privacy requirement are needed.

Section 208 also requires Federal agencies to make their PIAs publicly available. However, Department of Defense Instruction (DoDI) 5400.16, DoD Privacy Impact Assessment (PIA) Guidance (July 14, 2015), requires only Section I of the PIA to be published on the agency’s website. Additionally, DoDI 5400.16 provides the procedures for the completion and approval of PIAs to analyze and ensure PII in electronic form is collected, stored, protected, used, shared, and managed in a manner that protects privacy. The Chief Information Officer (CIO) approves PIAs conducted by the DHA’s program offices.

This guidance is designed to assist program offices to effectively conduct a PTA and or PIA and how to properly document the privacy risk assessment. This guidance reflects the requirements of Section 208 of the E-Government Act and DoDI 5400.16. The Chief, DHA PCLO encourages all program offices and system owners developing new PTAs and PIAs, or updating existing PIAs, to follow these processes and procedures.

References

· Section 208 of Public Law 107-347, E-Government Act of 2002, December 17, 2002

· Office of Management and Budget (OMB) Memorandum M-03-22, OMB Guidance for Implementing the Privacy Provisions of the E-Government Act of 2002, September 26, 2003

· OMB Circular No. A-130, Managing Information as a Strategic Resource, July 28, 2016

· DoD Instruction 5400.16, DoD Privacy Impact Assessment (PIA) Guidance, August 17, 2015, (CH 1 August 11, 2017)

Privacy Threshold Analysis (PTA) An information system owner and program manager should conduct a PTA to determine PII holding within the information system. Program offices who are acquisitioning a new information system or transitioning an information system to DHA that does not have a PIA, are required to complete a PTA to determine whether the information system contains PII, needs a system of records notice (SORN), and/or needs other privacy requirements are necessary. A properly completed PTA also provides the foundation for a PIA should one be required.

Upon completion of the PTA, DHA Form 61, e-mail the DHA Form to the DHA PCLO for review and determination to dha.ncr.pcl.mbx.piamail@mail.mil. Upon review, the DHA PCLO will return the PTA with the determination, rationale for the determination, and provide further instructions.

Communication Communication between DHA PCLO Cyber Security Division, and the Records Management Office is the key to completing an effective PIA. The PIA process (see Appendix III) requires ongoing collaboration between all aforementioned stakeholders to ensure appropriate and timely handling of privacy concerns. Publishing PIAs builds public trust and fosters openness and transparency in the operations of DHA.

Section 208 of the E-Government Act requires, where practicable, that agencies make PIAs publicly available as implemented by DoDI 5400.16. Therefore, PIAs should be clear and non-technical to the public. The PIA should demonstrate that an in-depth privacy risk assessment was conducted to ensure that the appropriate privacy safeguards were built into the system.

Below are some helpful tips for completing the PIA:

· Draft PIAs from the perspective of a member of the public who knows nothing about the information system, technology, or rulemaking. Write the PIA with sufficient detail to permit the DHA PCLO to evaluate the privacy risks and mitigation steps.

· Address what and why the information is collected, intended use of the information, with whom the information will shared, and how the information collected will be protected.

· Section 1 of the PIA will be published on the DHA’s web site. PIAs submitted to the DHA PCLO should be free of spelling and grammatical errors.

· Spell out each acronym the first time you use it in the document, for example, Office of Management and Budget (OMB).

· Use words, phrases, or names in the PIA that are readily known to the lay person.

· Define technical terms.

· Clearly reference projects and systems and provide explanations to aid the general public.

· Use the complete name of reference documents. For example, references to National Institute of Science and Technology (NIST) publications and other documents should include the complete name of the reference (e.g., NIST Special Publication 800-53A, Assessing Security and Privacy Controls in Federal Information Systems and Organizations). Subsequent references may use the abbreviated format.

The PIA should describe the flow of personal data so that everyone can understand the impact the new system or modification to an existing system may have on the privacy of the public or those who work for the Federal government. The PIA allows the DHA PCLO to determine if an information system is compliant with relevant data protection legislation and DoD policy requirements and facilitates the MHS Chief Information Officer (CIO) and Health Information Technology’s (HIT) consideration of system compliance with all DoD cybersecurity policies, final reviews and approval.

The program office or the information system owner should complete the DoD PIA template, DD Form 2930, and e-mail the form without signatures to the DHA PCLO at dha.ncr.pcl.mbx.piamail@mail.mil.

Instructions for Completing the PIA On page one of the PIA form, enter the name of the DoD information system or electronic collection name in the first field. Using the drop down box, select the name of the DoD component that owns the system. If you cannot locate the name the Component in the drop down box, write the name of the Component in the second field. Do not write in the approval date for the PIA because the approval date will auto populate.

Section 1: PII Description Summary (For Public Release)

a. The PII is:

Does this Department of Defense (DoD) information system or electronic collection of information (referred to as an "electronic collection" for the purpose of this form) collect, maintain, use, and/or disseminate PII about members of the general public, Federal employees, federal contractors or foreign nationals employed at U.S. military facilities internationally? If you collect information from foreign nationals, they are included in the general public category.

Select one category only from the choices provided.

b. The PII is in a: (Check one) Select one option only from the choices provided:

· New DoD Information System

· Existing DoD Information System

· Significantly Modified DoD Information System

· New Electronic Collection

· Existing Electronic Collection

c. Describe the purpose of this DoD information system or electronic collection and describe the types of personal information about individuals collected in the system.

Describe the purpose of the DoD information system or electronic collection and the types of personal information about individuals collected in the system. Explain the primary uses of the system, including any subsystem(s), showing how the information system and subsystems will use the PII. Provide a brief general description of personal information about individuals that is collected in the information system (e.g. personal descriptors, ID numbers, ethnicity, health, financial, employment, credit); categories of individuals (e.g. dependents, retirees and/or their dependents, active duty, contractors, foreign nationals, former spouses, reservist, national guard personnel) that information will be collected from (or about) within the system. Do not provide an entire list of PII data elements. You will provide the list of PII data elements in Section 2. In this section, provide the name of the office that owns and/or manages the information system. Please do not include actual PII as this section will be published on the DHA PCLO website.

d. Why is the PII collected and/or what is the intended use of the PII? (e.g., verification, identification, authentication, data matching, mission-related use, administrative use) Include the PII category and reason it is being collected. Stating the general purpose of the system without explaining why particular types of personally identifiable information should be collected and stored is not an adequate response to this question.

e. Do individuals have the opportunity to object to the collection of their PII?

The opportunity to object is only available at the initial point of data collection. If option “Yes” is selected, explain the method(s) individuals can use to object to each mode of collection (e.g., telephone, face-to-face, etc.), and the consequences, if any, if an individual objects (i.e., comprehensive healthcare may not be possible). If your system receives PII from a system-to-system interface, then select “No” because the opportunity to object is only available at the source system.

Additionally, DoD 5400.11-R, Department of Defense Privacy Program, C4, Disclosures of Personal Information to Other Agencies and Third Parties, lists the approved circumstances wherein an individual would not be given an opportunity to object to the collection of their PII.

f. Do individuals have the opportunity to consent to the specific uses of their PII?

Explain how consent is obtained from individuals after they provide their PII. If applicable, explain how authorization is obtained from individuals after they provide their PII. Also explain if consent requires an individual to take action rather than consent being assumed as a default.

Explain if the refusal of an individual to consent to the collection or use of personal information disrupts the level of program service provided to the individual (e.g., comprehensive healthcare may not be possible). Explain the method(s) individuals can use to consent to each specific use (e.g., telephone, face-to-face, etc.) of PII. Explain consequences, if any, if an individual withholds consent (e.g., healthcare may not be possible).

g. When an individual is asked to provide PII, a Privacy Act Statement (PAS) and/or a Privacy Advisory must be provided. (Check as appropriate and provide the actual wording.)

Prior to collecting PII, DoD 5400.11-R, C2.1.4, requires a PAS to be provided to the individual. The PAS enables the individual to make an informed decision whether to provide the information requested. If PII is solicited by a DoD system (e.g., collected as part of an email feedback / comments feature on a Web site) and the information is not maintained in a Privacy Act system of records, the solicitation of such information triggers the requirement for a Privacy Advisory.

In the free text box, provide the language of the PAS or the Privacy Advisory if Privacy Act Statement or Privacy Advisory is selected. If a Privacy Act Statement or Privacy Advisory is not required, select Not Applicable

h. With whom will the PII be shared through data exchange, both within your DoD Component and outside your Component? (Check all that apply) If your system/application shares data with another system/application, include that system under the appropriate sub-category listed below. Provide a short explanation of why the PII is shared. If you do not know whether systems share data, you can contact the business owner of the data or the IT specialist who knows what other interfaces exist between the systems/applications. For information shared with contractor(s), please indicate whether Business Associate Agreement or other appropriate privacy contract language is provided in the contract(s) (if applicable). Include the appropriate privacy contract clause. language from the contract or other appropriate contract language whether FAR privacy clauses, i.e., 52.224-1, Privacy Act Notification 52.224-2, Privacy Act, and FAR 39.105 are included in the contract. Also indicate if the contractor accesses the systems/data locally and/or VPN, versus those who maintain PII at their location (cloud, data export/import, etc.). If the latter, please include types and requirements (e.g., DSAA, BAA, and/or SSV).

i. Source of the PII collected is: (Check all that apply and list all information systems if applicable) If you select “Other Federal Information Systems”, list the agency and the information system; for example, the information is collected from a Veterans Administration information system.

j. How will the information be collected? (Check all that apply and list all Official Form Numbers if applicable) Describe why information from sources other than the individual are required. For example, if a program is using data from a commercial aggregator of information, state the fact that this is where the information is coming from and explain why the program is using this source of data.

Provide the DoD form number(s) and name(s) if form(s) are used to collect PII. Also, provide the URL if PII is collected via web site.

k. Does this DoD Information System or electronic collection require a Privacy Act System of Records Notice (SORN)?

If the information system or collection system has a SORN, enter the SORN System Identifier, the DHA-assigned designator, not the Federal Register number. Reference the DHA PCLO website for current DHA SORNs.

If the SORN has not been published in the Federal Register, enter the date of when the SORN was submitted to the Defense Privacy, Civil Liberties, and Transparency Division for approval. If a SORN is not required, explain the reason a SORN is not required according to DoD Regulation 5400.11-R, Department of Defense Privacy Program.

l. What is the National Archives and Records Administration (NARA) approved, pending or general records schedule (GRS) disposition authority for the system or for the records maintained in the system?

(1) List any of NARA’s Records Control Schedule (RCS) Job Numbers or General Records Schedule (GRS) authority that apply to the PII maintained in the system; and/or state if NARA is determining the appropriate RCS Job Number or GRS for some or all of the PII maintained in the system and that the PII should be maintained until a determination is provided.

(2) If pending, please provide the date the SF-115 was submitted to NARA. If you do not know the date, contact the records management office for the date.

(3) Provide the records management retention instructions.

Contact Records Management to obtain this information if you do not have it.

m. What is the authority to collect information? A Federal law or Executive Order must authorize the collection and maintenance of a system of records. For PII not collected or maintained in a system of records, the collection or maintenance of the PII must be necessary to discharge the requirements of a statue or Executive Order.

If this information system has a SORN, the authorities cited in the PIA and the existing SORN should be similar. For example, 10 U.S.C. Chapter 55, Sections 1071-1097b, Medical and Dental Care; 42 U.S.C. Chapter 117, Sections 11131-11152, Reporting of Information; DoD 6025.18-R, DoD Health Information Privacy Regulation; DoD 6010.8-R, CHAMPUS; DoD Instruction 6015.23, Delivery of Healthcare at Military Treatment Facilities: Foreign Service Care; Third-Party Collection; Beneficiary Counseling and Assistance Coordinators (BCACs); Pub.L. 104-91, and E.O. 9397 (SSN), as amended. This is only an example; do not copy and paste this example in your PIA.

If this information system does not have a SORN, cite the legal authorities and the DoD regulations, instructions, and policies for this information system or electronic collection.

n. Does this DoD information system or electronic collection have an active and approved Office of Management and Budget (OMB) Control Number?

If a form and/or information system is used to collect data from other than DoD military, DoD civilians, or other Federal employees, OMB approval is required unless there is an exemption noted in the approved authority.

If you do not know the OMB Control Number, contact the DHA Information Management Control Officer (IMCO).

In compliance with Section 208 of the E-Government Act of 2002, Sections 1 of the PIA will be posted to the DHA’s web site. Posting of this Section indicates that the PIA has been reviewed to ensure that the appropriate safeguards are in place to protect privacy. If Section 1 contains information that would reveal controlled unclassified information or raise security concerns, the DHA may restrict the publication of Section 1.

Section 2: PII Risk Review

a. What PII will be collected (a data element alone or in combination that can uniquely identify an individual)? (Check all that apply) Take reasonable steps to limit the amount of information collected necessary to accomplish the intended purpose of the system.

Identify and list individual PII or PII groupings that is collected and stored in the system. This could include, but is not limited to, name, other names used, birth date, citizenship, legal status, mailing/home address, telephone number, social security number (SSN), truncated SSN, personal e-mail address, mother’s maiden name, race/ethnicity, medical information, financial information, marital status, spouse information, child information, biometrics, disability information, driver’s license, place of birth, or any other PII. If you select “other”, specify what information is being collected.

List existing DoD information systems, other Federal information systems or databases, or commercial systems that provide the specific information identified above. For example, is the information collected directly from the individual as part of an application for a benefit, or is it collected from other sources, such as commercial data aggregators?

Describe why information from sources other than the individual are required. For example, if a program is using data from a commercial aggregator of information, state the fact that this is where the information is coming from and explain why the program is using this source of data.

If the SSN is collected, complete the following questions.

(1) Is there a current (dated within two (2) years) DPCLTD approved SSN Justification Memorandum in place?

If "Yes", provide the signatory and date approval. If “No”, explain why there is no SSN Justification Memorandum.

(2) Describe the approved acceptable use in accordance with DoD Instruction 1000.30 “Reduction of Social Security Number (SSN) Use within DoD” Enclosure 2, Sections 2.c.(1-13).

Email your completed SSN justification memorandum to dha.ncr.pcl.mbx.privacyactmail@mail.mil.

(3) Describe the mitigation efforts to reduce the use including visibility and printing of SSN in accordance with DoD Instruction 1000.30, “Reduction of Social Security Number (SSN) Use within DoD”.

Provide a brief description of the mitigation plan. For example, has your system undertaken any efforts to prevent direct visibility to SSNs when not needed such as a Form that previously collected/collects PII has been updated to no longer collect the SSN; Role-based access has been implemented to prevent unauthorized disclosure to users without the appropriate role credentials; etc.?

Note: According to DoDI 1000.30, use of the SSN includes the SSN in any form, including, but not limited to, truncated, masked, partially masked, encrypted, or disguised SSNs are not considered Risk Mitigation measures.

(4) Has a plan to eliminate the use of the SSN or mitigate its use and or visibility been identified in the approved SSN Justification request?

If "Yes", provide the unique identifier and when can it be eliminated. If "No", explain.

Within this section, elaborate on every reasonable step that has been taken, or is being taken to reduce the use of the SSN, and protect it where the use is still required.

Note: Justification for the use of the SSN to be contained in an application does not constitute authority to use the SSN in every transaction or interaction. Any transaction that includes the display, transfer, or presentation of the SSN should be closely scrutinized to determine if some alternate form of identification or authentication may suffice (DoDI 1000.30).

b. What is the PII confidentiality impact level?

Please select only one, low, moderate or high. Refer to NIST Special Publication 800-122, Guide to Protecting the Confidentiality of Personally Identifiable Information (PII) (April 6, 2010): Recommendations of the National Institute of Standards and Technology, Chapter 3 PII Confidentiality Impact Levels when determining the impact level. If you experience difficulty determining the PII confidentiality impact level, contact your program office Cyber Security Division for assistance to determine the impact level. Additionally, Chapter 3 of NIST SP 800-122 lists 6 factors for determining PII confidentiality levels:

1. Identifiability

2. Quantity of PII

3. Data field sensitivity

4. Context of use

5. Obligations to protect confidentiality

6. Access to and location of PII These factors must be considered together to determine PII confidentiality levels. One factor by itself might indicate a low impact level, but another factor might indicate a high impact level, and thus override the first factor.

c. How will the PII be secured?

(1) Physical Controls Check all applicable boxes. If “Other” is selected, specify the other physical controls in place in the field provided. In addition to the selected controls, address if the system currently or will be accessed at more than one site. If the system is operated in more than one site, explain how consistent use of the system and data will be maintained at all sites.

The response should be consistent with the system’s security plan.

(2) Administrative Controls Check all applicable boxes. If “Other” is selected, specify the other administrative controls in place in the field provided. In addition to the selected controls, explain where backups occur, how often they occur, and how the data is safeguarded. If backups are not encrypted, provide the DHA PCLO with a Plan of Action & Milestones documenting when encryption will occur.

Address if the system has a user’s manual, and maintain audit logs. Explain the current or future processes in place for periodic review of PII contained in the system to ensure data integrity, availability, accuracy, and relevancy. Additionally, address any training for users of the system.

The response should be consistent with the system’s security plan.

(3) Technical Controls Check all applicable boxes. If “Other” is selected, specify the other technical controls in place in the field provided. In addition to the selected controls, address whether the system hosts or will host a web site accessible by the public.

The response should be consistent with the system’s security plan.

d. What additional measures/safeguards have been put in place to address privacy risks for this information system or electronic collection?

The following must be addressed:

Describe the privacy risks associated with the PII and the mitigation strategy (e.g., awareness and training programs, limited physical access, data encryption, violations for unauthorized monitoring, etc.).

Note: it is appropriate to address administrative, physical, and technical controls in place to protect the system (DoDI 8580.02, Security of Individually Identifiable Health Information in DoD Health Care Programs, Enclosure 4).

· Is all PII evaluated for impact of loss or unauthorized disclosure and protected accordingly?

· Are all electronic PII records assigned a High or Moderate impact category and protected at a Confidentiality level of controlled unclassified information (CUI) or higher, unless specifically cleared for public release (Ref. NIST SP 800-122 “Guide to Protecting the Confidentiality of Personally Identifiable Information" or FIPS Pub 199 "Standards for Security Categorization of Federal Information and Information Systems")?

· If applicable, are High impact category PII records routinely processed or stored on mobile computing devices or removable electronic media?

· If applicable, can High impact PII records be accessed by users remotely?

· If PII may be downloaded to a workstation, mobile computing device, or removable electronic media, what mechanisms are in place to secure that media from unauthorized disclosure, theft, or loss?

· If applicable, can mobile computing devices that contain High impact PII, including those approved for routine processing, be removed from protected workplaces?

· If applicable, does the website employ (or will it employ) persistent tracking technology?

· Are employees with access to personal information in your organization provided with training related to privacy protection?

· Are programs and information technology staff aware of the relevant policies regarding breaches of security or confidentiality?

· Are there controls in place to ensure that data is not made available or disclosed to unauthorized individuals, entities, or processes?

· Are there controls in place to ensure that data has not been altered or destroyed in an unauthorized manner?

Section 3: Related Compliance Information

a. Is this DoD Information System registered in the DoD IT Portfolio Repository (DITPR) or the DoD Secret Internet Protocol Router Network (SIPRNET) Information Technology (IT) Registry or Risk Management Framework (RMF) tool?

If the DoD information system is registered in DITPR, the SIPRNET IT registry, or the RMF tool, provide the corresponding identification number. Contact the System Program Manager if the identification numbers is not known. If the DoD information is not registered in DITPR, the SIPRNET IT registry, or the RMF tool, explain why the DoD information system is not registered.

b. DoD information systems require assessment and authorization under the DoD Instruction 8510.01, “Risk Management Framework for DoD Information Technology”.

Indicate the status of the assessment and authorization (A&A) to include the approval date. The types of A&A are authorization to operate (ATO), ATO with conditions, interim authorization to operate (IATO), and denial of authorization to operate DATO.

(1) If the authorization and assessment is pending, indicate the type and projected date of completion.

(2) If an assessment and authorization is not using RMF, indicate the projected transition date.

c. Does this DoD information system have an IT investment Unique Investment Identifier (UII), required by Office of Management and Budget (OMB) Circular A-11?

Please check “yes” or “no.” Enter the UII in the field. If the UII is unknown, contact the DHA IT Budget Point of Contact to obtain the UII.

Section 4: Review and Approval Signatures When submitting the form to the DHA PCLO for review, do not submit the PIA with signatures. In addition to the names of the individuals signing the PIA, the following fields are required: individual’s title, organization, work telephone number, the Defense Switched Network (DSN) number, e-mail address, date of review, and signature. Omission of the information in the required fields will result in the return of the PIA.

The DHA PCLO will facilitate the coordination for signatures in this order: the Program Manager or Designee, other Official as designated by the Component, and the DHA PCLO (this signature will be completed when the Senior Component Official for Privacy (SCOP) or Designee signs the PIA). It is mandatory for the Component Records Officer, Component Senior Information Security Officer or Designee, the SCOP or Designee, and the Component CIO reviewing official to sign. The DHA SCOP has designated the DHA PCLO to sign on behalf of the SCOP; therefore, the DHA PCLO will sign the PIA in both fields when the PIA is returned for the SCOP’s signature.

Appendix I PIA Triggers

According to OMB Memorandum M-03-22, the system activities listed below may trigger a PIA:

Conversions - When converting paper-based records to electronic systems.

Anonymous to Non-Anonymous - When functions applied to an existing information collection change anonymous information into information in identifiable form.

Significant System Management Changes - When new uses of an existing IT system, including application of new technologies, significantly change how information in identifiable form is managed in the system: For example, when an agency employs new relational database technologies or web-based processing to access multiple data stores, such additions could create a more open environment and avenues for exposure of data that previously did not exist.

Significant Merging - When agencies adopt or alter business processes so that government databases holding information in identifiable form are merged, centralized, matched with other databases or otherwise significantly manipulated. For example, when databases are merged to create one central source of information, such a link may aggregate data in ways that create privacy concerns not previously at issue.

New Public Access - When user-authenticating technology (e.g., password, digital certificate, biometric) is newly applied to an electronic information system accessed by members of the public.

Commercial Sources - When agencies systematically incorporate into existing information systems databases of information in identifiable form purchased or obtained from commercial or public sources. (Merely querying such a source on an ad hoc basis using existing technology does not trigger the PIA requirement).

New Interagency Uses - When agencies work together on shared functions involving significant new uses or exchanges of information in identifiable form, such as the cross-cutting E- Government initiatives; in such cases, the lead agency should prepare the PIA.

Internal Flow or Collection - When alteration of a business process results in significant new uses or disclosures of information or incorporation into the system of additional items of information in identifiable form.

Alteration in Character of Data - When new information in identifiable form added to a collection raises the risks to personal privacy. For example, the addition of health or financial information may lead to additional privacy concerns that otherwise would not arise.

Appendix II Definitions

Data Aggregation - Any process in which information is gathered and expressed in a summary form for purposes such as statistical analysis. A common aggregation purpose is to compile information about particular groups based on specific variables such as age, profession, or income.

DoD Information System - Information system (IS): A discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information. Information systems also include specialized systems such as industrial/process controls systems, telephone switching and private branch exchange (PBX) systems, and environmental control systems. Source: 44 U.S.C. Sec 3502.

Electronic Collection of Information - Any collection of information enabled by IT.

Federal Personnel - Officers and employees of the Government of the United States, members of the uniformed services (including members of the Reserve Components), and individuals entitled to receive immediate or deferred retirement benefits under any retirement program of the United States (including survivor benefits). For the purposes of PIAs, DoD dependents are considered members of the general public.

Note: If the system collects data from 10 or more members of the public (see federal personnel definition in the appendix) in a 12-month period, there is a requirement for an OMB Control Number (unless there is an exemption noted in an approved authority).

National Security Systems - As defined in the Clinger-Cohen Act, an information system operated by the federal government, the function, operation or use of which involves: (a) intelligence activities, (b) cryptologic activities related to national security, (c) command and control of military forces, (d) equipment that is an integral part of a weapon or weapons systems, or (e) systems critical to the direct fulfillment of military or intelligence missions, but does not include systems used for routine administrative and business applications, such as payroll, finance, logistics and personnel management.

Personally Identifiable Information - Information about an individual that identifies, links, relates or is unique to, or describes him or her (e.g., a social security number; age; marital status; race; salary; home telephone number; other demographic, biometric, personnel, medical, and financial information). Also, information that can be used to distinguish or trace an individual's identity, such as his or her name; social security number; date and place of birth; mother's maiden name; and biometric records, including any other personal information that is linked or linkable to a specified individual.

Privacy Act Statements - When an individual is requested to furnish personal information about himself or herself for inclusion in a system of records, providing a Privacy Act Statement is required to enable the individual to make an informed decision whether to provide the information requested.

Privacy Advisory - A notification informing an individual as to why information is being solicited and how such information will be used. If PII is solicited by a DoD system (e.g., collected as part of an email feedback/comments feature on a Web site) and the information is not maintained in a Privacy Act system of records, the solicitation of such information triggers the requirement for a privacy advisory.

System of Records Notice (SORN) - Public notice of the existence and character of a group of records under the control of an agency from which information is retrieved by the name of the individual or by some identifying number, symbol, or other identifying particular assigned to the individual. The Privacy Act of 1974 requires this notice to be published in the Federal Register upon establishment or substantive revision of the system, and establishes what information about the system must be include.

Appendix III PIA Process

Program Manager (or designee) submit DD Form 2930 to DHA PCLO PIA Team Please use the DHA PIA Processes and Procedures to complete DD Form 2930. As a reminder, the form should be submitted unsigned.

PIA Team review and request updates from PM (or designee), as needed (this may require several cycles) Subjects that may require additional review include: Paperwork Reduction Act compliance, Privacy Act/System of Record Notice, HIPAA compliance, Records Management Inventory

DHA PCLO (Gov’t) review and approval to begin signature coordination process

PIA Team work with PM (or designee) to obtain appropriate signatures Upon receipt of signature from PM (and/or other designee(s)), the PIA Team will obtain signatures from DHA SIAO, DHA PCLO, and DHA CIO.

Final signed DD Form 2930 returned to PM

DHA Privacy and Civil Liberties Staff

Rahwa Keleta Acting Chief, DHA Privacy and Civil Liberties Office Acting Chief, Freedom of Information Act rahwa.a.keleta.civ@mail.mil

Nadine Brown Freedom of Information Act Officer nadine.r.brown4.civ@mail.mil

Rita Deshields Data Sharing Compliance Manager rita.s.deshields.civ@mail.mil

John Eckert, Captain, USPHS Human Research Protection john.j.eckert14.mil@mail.mil

Rahwa Keleta HIPAA Compliance Manager rahwa.a.keleta.civ@mail.mil

Jennifer Noble, PhDc, MBA/HRM, FAHM, CIPP/G Federal Privacy Compliance Manager marilynn.j.noble.civ@mail.mil image1.jpeg image2.png image3.png image4.png image5.png image6.png image7.jpeg image8.png image9.png image10.png image11.png image12.png image13.jpeg image14.jpeg image15.jpeg image16.png image17.png image18.png image19.png image20.png image21.png image22.png image23.png image24.png image25.png image26.png image27.png image28.png image29.png image30.jpeg

File details come from the government source that posted it. Updated .