Privacy Narrative

19BOI Privacy Narrative Final.pdf

National Diabetes Prevention Program Introductory Session Project

Privacy Narrative

OMB: 0920-1300

Document [pdf]
Download: pdf | pdf
Information Collection Request - Privacy Narrative
National Diabetes Prevention Program (DPP) Introductory Session Project
Title: ______________________________________________________________________________________
Krista Proia, CDC Task Order Technical Monitor
Point of Contact: _____________________________________________________________________________

Data Collection

CDC contractors will collect business contact information (i.e., names, email addresses, and
mailing addresses) of the primary point of contact for each class location delivering the National
Diabetes Prevention Program Lifestyle Change Program (National DPP LCP). A survey item included
in the Phase 1 Landscape Assessment Survey for CDC-recognized organizations (Attachment 1) asks
CDC-recognized organizations to provide the contact information (i.e., name, email, and mailing
address) for any affiliated locations where LCP classes are delivered (i.e., class locations) so that CDC
contractors can send a modified version of the Landscape Assessment Survey (Attachment 1aa) to
those class locations. [A Privacy Act Statement appears on the first page of the online and paper
versions of the Phase 1 Landscape Assessment Survey for CDC-recognized organizations
(Attachment 1) and on the modified survey for affiliated class locations (Attachment 1aa.)]
Data Storage and Security
For Phase 1, business contact information constitutes personally identifiable information (PII) for
respondents to the Landscape Assessment Survey. Trained CDC contractors will keep survey
responses in a password-protected, secure share drive folder within the contractor's network. Databases
and project file shares will be backed up nightly to minimize the risk of losing significant data through
hardware or software malfunctions. Only authorized staff will have access to these folders. All staff
are required to take general information security training and Health Insurance Portability and
Accountability Act of 1996 (HIPAA) security training before being granted access to project data. We
will store respondent data in a separate server from PII.
CDC will not have direct contact with organizational primary points of contacts or with
Introductory Session/BYB Discovery Session attendees, nor will CDC receive any identifiable
response data from respondents. Although CDC knows the names of the CDC-recognized
organizations and key program staff, CDC will not be able to link specific responses to actual
Business
information
(names,
organizations.
No data
to CDCNo
fromIfthe
or
reportscontact
produced
will include
PIIemail
or
Does
this ICR request
anydelivered
PII? ✔ Yes
yes,contractor
describe: _____________________________________
address, and business mailing address) of
identifiable information.

✔ No for each class location
Does this ICR include a form that requires a Privacy Act Statement?the primary
Yes contact

delivering
National
LCP. is
All information collected throughout the study will be stored
until 5the
years
afterDPP
the project
✔
Does
this ICROnce
require
a PIA?have passed,
Yes
No information
If yes,
a signed PIA already
completed.
5 years
the
willdoes
be permanently
deleted.exist? ✔ Yes

C/I/O Approval
Associate Director for Science

Lawrence
Barker -S
Comments:

Digitally signed by
Lawrence Barker -S
Date: 2019.11.22
12:57:10 -05'00'

Information Systems Security Officer

Cynthia
Allen -S

Digitally signed by
Cynthia Allen -S
Date: 2019.11.26
11:13:14 -05'00'

No


File Typeapplication/pdf
File Modified0000-00-00
File Created0000-00-00

© 2024 OMB.report | Privacy Policy