Pia

Attachment 4 - HHS Privacy Impact Assessment (PIA) Form.docx

Application Forms for the NIDA Summer Research Internship Program

PIA

OMB: 0925-0738

Document [docx]
Download: docx | pdf

Save

Shape1

Privacy Impact Assessment Form

v 1.47.4


Status n/a Form Number n/a Form Date n/a


Question Answer


  1. OPDIV: National Institutes of Health

  2. PIA Unique Identifier: n/a


2a Name: NIDA Summer Research Internship Program






  1. The subject of this PIA is which of the following?





3a Identify the Enterprise Performance Lifecycle Phase of the system.


3b Is this a FISMA-Reportable system?


Does the system include a Website or online


General Support System (GSS) Major Application

Minor Application (stand-alone) Minor Application (child) Electronic Information Collection Unknown


Operations and Maintenance


Yes No

Yes
















Accept

  1. application available to and for the use of the general

public? No

Reject


  1. Agency Contractor

    Identify the operator.



POC Title




  1. Point of Contact (POC):

POC Name


POC Organization POC Email



Accept Reject

POC Phone



  1. New Existing

    Is this a new or existing system?



  1. Does the system have Security Authorization (SA)?

Accept Reject


Shape2

Yes

No

8b Planned Date of Security Authorization

November 30, 2019

Not Applicable

Shape3 Shape5 Shape7 Shape9 Shape11 Shape4 Shape6 Shape8 Shape10 Shape12 Shape13 Shape14





9 Indicate the following reason(s) for updating this PIA. Choose from the following options.

PIA Validation (PIA

Refresh/Annual Review) Anonymous to Non- Anonymous

New Public Access

Internal Flow or Collection Commercial Sources

Other...

Significant System

Management Change Alteration in Character of Data

New Interagency Uses Conversion




Accept Reject

10 Describe in further detail any changes to the system that have occurred since the last PIA.



Accept

Reject


11 Describe the purpose of the system.



Accept

Reject

Describe the type of information the system will

12 collect, maintain (store), or share. (Subsequent questions will identify if this information is PII and ask

about the specific data elements.)



Accept Reject

Provide an overview of the system and describe the

13 information it will collect, maintain (store), or share, either permanently or temporarily.



Accept Reject


14 Does the system collect, maintain, use or share PII?

Yes

No


Accept

Reject













15 Indicate the type of PII that the system will collect or maintain.

Social Security Number Name

Driver's License Number Mother's Maiden Name E-Mail Address

Phone Numbers

Medical Notes Certificates

Education Records Military Status

Foreign Activities Taxpayer ID Other...

Other...

Other...

Other...

Other...

Date of Birth Photographic Identifiers Biometric Identifiers Vehicle Identifiers Mailing Address

Medical Records Number

Financial Account Info Legal Documents Device Identifiers Employment Status Passport Number












Accept Reject

Shape19 Shape22 Shape24 Shape25 Shape15 Shape16 Shape17 Shape18 Shape20 Shape21 Shape23 Shape26 Shape27 Shape28 Shape29 Shape30

Employees

Public Citizens

Indicate the categories of individuals about whom PII Business Partners/Contacts (Federal, state, local agencies)

16 is collected, maintained or shared. Vendors/Suppliers/Contractors

Patients

Other




Accept Reject


17 How many individuals' PII is in the system?

Accept

Reject


18 For what primary purpose is the PII used?

Accept

Reject

19 Describe the secondary uses for which the PII will be used (e.g. testing, training or research)


Accept

Reject


20 Describe the function of the SSN.

Accept Reject


20a Cite the legal authority to use the SSN.

21 Identify legal authorities governing information use and disclosure specific to the system and program.

Accept

Reject

Are records on the system retrieved by one or more Yes

22 PII data elements? No

Accept

Reject


Published:



Identify the number and title of the Privacy Act

System of Records Notice (SORN) that is being used Published: 22a to cover the system or identify if a SORN is being

developed.

Published:


In Progress

Shape33 Shape35 Shape38 Shape40 Shape42 Shape44 Shape31 Shape32 Shape34 Shape36 Shape37 Shape39 Shape41 Shape43 Shape45








23 Identify the sources of PII in the system.

Directly from an individual about whom the information pertains

In-Person Hard Copy: Mail/Fax

Email Online Other Government Sources

Within the OPDIV Other HHS OPDIV

State/Local/Tribal

Foreign Other Federal Entities

Other Non-Government Sources

Members of the Public Commercial Data Broker Public Media/Internet

Private Sector

Other












Accept Reject

23a Identify the OMB information collection approval number and expiration date.


24 Is the PII shared with other organizations?

Yes

No

Accept

Reject

Describe the process in place to notify individuals

25 that their personal information will be collected. If no prior notice is given, explain the reason.


Accept

Reject

26 Is the submission of PII by individuals voluntary or mandatory?

Voluntary

Mandatory

Accept

Reject

Describe the method for individuals to opt-out of the

27 collection or use of their PII. If there is no option to object to the information collection, provide a

reason.



Accept Reject

Describe the process to notify and obtain consent

from the individuals whose PII is in the system when major changes occur to the system (e.g., disclosure

28 and/or data uses have changed since the notice at the time of original collection). Alternatively, describe why they cannot be notified or have their consent obtained.




Accept Reject

Describe the process in place to resolve an

individual's concerns when they believe their PII has

29 been inappropriately obtained, used, or disclosed, or that the PII is inaccurate. If no process exists, explain why not.



Accept Reject

Describe the process in place for periodic reviews of

30 PII contained in the system to ensure the data's integrity, availability, accuracy and relevancy. If no

processes are in place, explain why not.


Accept Reject

Shape52 Shape54 Shape56 Shape58 Shape61 Shape63 Shape65

Users


Administrators


Developers


Contractors


Others



Shape46 Shape47 Shape48 Shape49 Shape50 Shape51 Shape53 Shape55 Shape57 Shape59 Shape60 Shape62 Shape64 Shape66 Shape67 Shape68







31





Identify who will have access to the PII in the system and the reason why they require access.










Accept Reject


32

Describe the procedures in place to determine which system users (administrators, developers, contractors, etc.) may access PII.


Accept Reject


33

Describe the methods in place to allow those with

access to PII to only access the minimum amount of information necessary to perform their job.


Accept

Reject



34

Identify training and awareness provided to personnel (system owners, managers, operators, contractors and/or program managers) using the system to make them aware of their responsibilities for protecting the information being collected and maintained.




Accept Reject


35

Describe training system users receive (above and beyond general security and privacy awareness training).


Accept Reject


36

Do contracts include Federal Acquisition Regulation and other appropriate clauses ensuring adherence to privacy provisions and practices?

Yes No

Accept Reject


37

Describe the process and guidelines in place with regard to the retention and destruction of PII. Cite specific records retention schedules.


Accept Reject


38

Describe, briefly but with specificity, how the PII will be secured in the system using administrative, technical, and physical controls.


Accept Reject


39


Identify the publicly-available URL:


Accept

Reject


40


Does the website have a posted privacy notice?

Yes

No

Accept

Reject


40a

Is the privacy policy available in a machine-readable format?

Yes

No



41

Does the website use web measurement and customization technology?

Yes

No

Accept

Reject

Shape70 Shape73 Shape74 Shape75 Shape76 Shape77 Shape78 Shape79 Shape80 Shape81 Shape82 Shape83

Technologies Web beacons


Web bugs

Select the type of website measurement and

41a customization technologies is in use and if it is used

to collect PII. (Select all that apply) Session Cookies


Persistent Cookies



Other...

Collects PII?



Yes

No

Yes

No

Yes

No

Yes

No

Yes

No

Does the website have any information or pages Yes

42 directed at children under the age of thirteen? No



Accept Reject

Is there a unique privacy policy for the website, and

does the unique privacy policy address the process Yes

42a for obtaining parental consent if any information is No

collected?

Does the website contain links to non- federal Yes

43 government websites external to HHS? No



Accept

Reject

Is a disclaimer notice provided to users that follow Yes 43a external links to websites not owned or operated by

HHS? No



REVIEWER QUESTIONS: The following section contains Reviewer Questions which are not to be filled out unless the user is an OPDIV Senior Officer for Privacy.

Reviewer Questions


Answer



1 Are the questions on the PIA answered correctly, accurately, and completely?



Yes

No

Accept

Reject

Reviewer

Notes

2 Does the PIA appropriately communicate the purpose of PII in the system and is the purpose justified by appropriate legal authorities?

Yes

No

Accept

Reject

Reviewer

Notes

3 Do system owners demonstrate appropriate understanding of the impact of the PII in the system and provide sufficient oversight to employees and contractors?

Yes

No

Accept

Reject

Reviewer

Notes


4 Does the PIA appropriately describe the PII quality and integrity of the data?



Yes

No

Accept

Reject

Reviewer

Notes

Shape84 Shape85 Shape86 Shape87 Shape88 Shape89 Shape90 Shape91 Shape92 Shape93 Shape94 Shape95 Shape96 Shape97 Shape98 Shape99 Shape100 Shape101


Reviewer Questions

Answer



5


Is this a candidate for PII minimization?

Yes

No

Accept

Reject

Reviewer

Notes


6


Does the PIA accurately identify data retention procedures and records retention schedules?

Yes

No

Accept

Reject

Reviewer

Notes


7


Are the individuals whose PII is in the system provided appropriate participation?

Yes

No

Accept

Reject

Reviewer

Notes


8


Does the PIA raise any concerns about the security of the PII?

Yes

No

Accept

Reject

Reviewer

Notes

9

Is applicability of the Privacy Act captured correctly and is a SORN published or does it need to be?

Yes

No

Accept

Reject

Reviewer

Notes


10


Is the PII appropriately limited for use internally and with third parties?

Yes

No

Accept

Reject

Reviewer

Notes


11


Does the PIA demonstrate compliance with all Web privacy requirements?

Yes

No

Accept

Reject

Reviewer

Notes


12


Were any changes made to the system because of the completion of this PIA?

Yes

No

Accept

Reject

Reviewer

Notes




General Comments


Shape102


OPDIV Senior Official for Privacy Signature


HHS Senior Agency Official for Privacy


Shape103 Third-Party Website Assessment PIA Form

v 1.47.4


Status Form Number Read Only Form Date Read Only


Question Answer


  1. OPDIV: Read Only - OPDIV

  2. TPWA Unique Identifier (UID): Read Only - TPWA UID

  3. TPWA Name: Read Only - TPWA Name


  1. Is this a new TPWA?






Yes No


4a Please provide the reason for revision


Will the use of a third-party Website or application

  1. create a new or modify an existing HHS/OPDIV System of Records Notice (SORN) under the Privacy

Act?


5a Indicate the SORN number (or identify plans to put one in place.)


Will the use of a third-party Website or application

  1. create an information collection subject to OMB clearance under the Paperwork Reduction Act (PRA)?


Indicate the OMB approval number and approval 6a number expiration date (or describe the plans to

obtain OMB clearance.)



  1. Does the third-party Website or application contain Federal Records?






SORN Number:


If not published:





OMB Approval Number Expiration Date Explanation


Yes No






Yes No






Yes No


Accept Reject






Accept Reject






Accept Reject

POC Title




  1. Point of Contact (POC):

POC Name


POC Organization POC Email


Accept Reject

POC Phone


  1. Describe the specific purpose for the OPDIV use of the third-party Website or application:

Have the third-party privacy policies been reviewed

  1. to evaluate any risks and to determine whether the Website or application is appropriate for OPDIV use?




Yes No

Accept Reject Accept Reject

Shape104 Shape105 Shape106 Shape107 Shape108 Shape109 Shape110 Shape111 Shape112 Shape113 Shape114 Shape115 Shape116 Shape117 Shape118

Describe alternative means by which the public can

11 obtain comparable information or services if they choose not to use the third-party Website or

application:


Accept Reject

Does the third-party Website or application have

12 appropriate branding to distinguish the OPDIV activities from those of nongovernmental actors?

Yes

No

Accept

Reject

13 How does the public navigate to the third party Website or application from the OPIDIV?


Accept

Reject

13a Please describe how the public navigate to the third- party website or application:

If the public navigate to the third-party website or

13b application via an external hyperlink, is there an alert to notify the public that they are being directed to a

nongovernmental Website?

Yes No


Has the OPDIV Privacy Policy been updated to

14 describe the use of a third-party Website or application?

Yes No

Accept Reject

14a Provide a hyperlink to the OPDIV Privacy Policy:

15 Is an OPDIV Privacy Notice posted on the third-party Website or application?

Yes No

Accept Reject

Confirm that the Privacy Notice contains all of the

following elements: (i) An explanation that the Website or application is not government-owned or government-operated; (ii) An indication of whether and how the OPDIV will maintain, use, or share PII

15a that becomes available; (iii) An explanation that by using the third-party Website or application to communicate with the OPDIV, individuals may be providing nongovernmental third-parties with access to PII; (iv) A link to the official OPDIV Website; and (v) A link to the OPDIV Privacy Policy





Yes No


Is the OPDIV's Privacy Notice prominently displayed

15b at all locations on the third-party Website or application where the public might make PII

available?

Yes No


16 Is PII collected by the OPDIV from the third-party Website or application?

Yes

No

Accept

Reject

17 Will the third-party Website or application make PII available to the OPDIV?

Yes

No

Accept

Reject

Describe the PII that will be collected by the OPDIV

from the third-party Website or application and/or

18 the PII which the public could make available to the OPDIV through the use of the third-party Website or

application and the intended or expected use of the PII:




Accept Reject

Describe the type of PII from the third-party Website

19 or application that will be shared, with whom the PII will be shared, and the purpose of the information

sharing:


Accept Reject

Shape119 Shape120 Shape121 Shape122 Shape123 Shape124 Shape125 Shape126 Shape127 Shape128 Shape129 Shape130 Shape131 Shape132 Shape133 Shape134 Shape135

19a If PII is shared, how are the risks of sharing PII mitigated?


20


Will the PII from the third-party Website or application be maintained by the OPDIV?

Yes

No


Accept

Reject

20a If PII will be maintained, indicate how long the PII will be maintained:


21


Describe how PII that is used or maintained will be secured:



Accept

Reject


22


What other privacy risks exist and how will they be mitigated?



Accept

Reject


REVIEWER QUESTIONS: The following section contains Reviewer Questions which are not to be filled out unless the user is an OPDIV Senior Officer for Privacy.



Reviewer Questions


Answer




1


Are the responses accurate and complete?


Yes

No

Accept

Reject

Reviewer

Notes



2


Is the TPWA compliant with all M-10-23 requirements, including appropriate branding and alerts?

Yes

No

Accept

Reject

Reviewer

Notes



3


Has the OPDIV posted an updated privacy notice on the TPWA and does it contain the five required elements?

Yes

No

Accept

Reject

Reviewer

Notes



4


Does the PIA clearly identify PII made available and/or collected by the TPWA?


Yes

No

Accept

Reject

Reviewer

Notes



5


Is the handling of PII appropriate?


Yes

No

Accept

Reject

Reviewer

Notes


General Comments


Shape136



Shape137

Page 4 of 11


File Typeapplication/vnd.openxmlformats-officedocument.wordprocessingml.document
File Modified0000-00-00
File Created2021-01-15

© 2024 OMB.report | Privacy Policy