Draft PIA

DMHRSi_DraftPIA.pdf

Defense Medical Human Resources System Internet (DMHRSi)

Draft PIA

OMB: 0720-0041

Document [pdf]
Download: pdf | pdf
PRIVACY IMPACT ASSESSMENT (PIA)
PRESCRIBING AUTHORITY: DoD Instruction 5400.16, "DoD Privacy Impact Assessment (PIA) Guidance". Complete this form for Department of Defense
(DoD) information systems or electronic collections of information (referred to as an "electronic collection" for the purpose of this form) that collect, maintain, use,
and/or disseminate personally identifiable information (PII) about members of the public, Federal employees, contractors, or foreign nationals employed at U.S.
military facilities internationally. In the case where no PII is collected, the PIA will serve as a conclusive determination that privacy requirements do not apply to
system.
1. DOD INFORMATION SYSTEM/ELECTRONIC COLLECTION NAME:

Defense Medical Human Resources System - Internet (DMHRSi)
3. PIA APPROVAL DATE:

2. DOD COMPONENT NAME:

Defense Health Agency

SECTION 1: PII DESCRIPTION SUMMARY (FOR PUBLIC RELEASE)
a. The PII is: (Check one. Note: Federal contractors, military family members, and foreign nationals are included in general public.)
From members of the general public

From Federal employees

from both members of the general public and Federal employees

Not Collected (if checked proceed to Section 4)

b. The PII is in a: (Check one.)
New DoD Information System

New Electronic Collection

Existing DoD Information System

Existing Electronic Collection

Significantly Modified DoD Information System
c. Describe the purpose of this DoD information system or electronic collection and describe the types of personal information about individuals
collected in the system.

Defense Medical Human Resources System - Internet (DMHRSi) is a web-based system that allows for enhanced management and oversight
within the Department of Defense (DoD). DMHRSi enables consolidation of all Human Resources (HR) functions (i.e., essential manpower,
personnel, labor cost assignment, education & training, and readiness information) including the following: Personnel in/out processing time
greatly reduced; Provides tri-service standardized labor costing approach; Personnel have visibility of their own information; Provides
instant visibility of assignment of projected gains/losses; Provides single database source of instant query/access for all personnel types and
readiness posture of all personnel assigned to platforms; Allows for instant visibility of available training at command and across Military
Health System (MHS) and tracks historical training; Tracks readiness equipment/clothing issuance and medical/administration requirements;
Reduces upper echelon queries due to their ability to view command data and provides visibility of staffing levels (required and actual).
The system is accessible via a public web site across the internet by anyone with the Uniform Resource Locator (URL). The system is not
intended to be accessed by the general public; an individual must have an active .mil email account to access the web site and must have their
account authenticated by a system administrator.
Data is collected in DMHRSi from the following categories of individuals: Military Personnel (Active Duty, Reservist, Guard) for Army,
Navy, Air Force; Borrowed Personnel as applicable from Coast Guard, Public Health Services, Local Nationals, Marines; Federal Civilians
(DoD, Army, Navy, Air Force, VA); Contractors and Volunteer personnel.
DMHRSi collects, maintains, transmits, and stores the following types of personally identifiable information (PII): personal descriptors, ID
numbers, ethnicity, employment, and education information. PII elements are used for identification in both input and output transactions.
This practice is driven by the lack of unique identifiers in the external systems to which DMHRSi interfaces. The PII elements that are used
typically are some combination of DoD Electronic Data Interchange Personal Identifier (EDIPI), SSN, full name, and month of birth.
DMHRSi is owned and managed by the Clinical Support Program Management Office under the executive management of Defense Health
Agency (DHA), Deputy Assistant Director Information Operations (DADIO/J6), Solution Delivery Division (SDD), 5109 Leesburg Pike
(Sky 6), Falls Church VA 22041
d. Why is the PII collected and/or what is the intended use of the PII? (e.g., verification, identification, authentication, data matching, mission-related use,
administrative use)

PII is collected in DMHRSi to support the following HR functions: manpower, personnel, labor cost assignment, education and training,
and readiness.
PII is used for various MHS business processes, including identifying individuals with specific medical skill levels or qualifications,
DD FORM 2930, JUN 2017

PREVIOUS EDITION IS OBSOLETE.

AEM Designer

Page 1 of 12

tracking personnel utilization and costs, and identifying and analyzing staffing capabilities at Military Treatment Facilities (MTFs)
worldwide.
Yes
No

e. Do individuals have the opportunity to object to the collection of their PII?

(1) If "Yes," describe the method by which individuals can object to the collection of PII.
(2) If "No," state the reason why individuals cannot object to the collection of PII.

Individuals do not have the opportunity to object to the collection of their PII because DMHRSi is not the initial point of collection.
f. Do individuals have the opportunity to consent to the specific uses of their PII?

Yes

No

(1) If "Yes," describe the method by which individuals can give or withhold their consent.
(2) If "No," state the reason why individuals cannot give or withhold their consent.

Individuals do not have the opportunity to consent to the specific use of their PII because DMHRSi is not the initial point of collection.

g. When an individual is asked to provide PII, a Privacy Act Statement (PAS) and/or a Privacy Advisory must be provided. (Check as appropriate and
provide the actual wording.)
Privacy Act Statement

Privacy Advisory

Not Applicable

Purpose: Defense Medical Human Resources System - Internet (DMHRSi) is a web-based system that allows for enhanced management and
oversight within the Department of Defense (DoD). DMHRSi enables consolidation of all Human Resources (HR) functions (i.e., essential
manpower, personnel, labor cost assignment, education & training, and readiness information) including the following: Personnel in/out
processing time greatly reduced; Provides tri-service standardized labor costing approach; Personnel have visibility of their own information;
Provides instant visibility of assignment of projected gains/losses; Provides single database source of instant query/access for all personnel
types and readiness posture of all personnel assigned to platforms; Allows for instant visibility of available training at command and across
Military Health System (MHS) and tracks historical training; Tracks readiness equipment/clothing issuance and medical/administration
requirements; Reduces upper echelon queries due to their ability to view command data and provides visibility of staffing levels (required
and actual).
Authorities: DoDI 1322.24, Medical Readiness Training; DoD 6010.13-M, Medical Expense Performance Reporting System (MEPRS) for
Fixed Medical and Dental Treatment Facilities; DoD 5136.1-P, Medical Readiness Strategic Plan (MHSP); E.O. 12656, Assignment of
Emergency Preparedness Responsibilities; and E.O. 9397 (SSN), as amended.
Privacy Act Statement: DMHRSi will not collect any personally identifiable information (PII) from individuals to be stored in a system of
records and retrieved by a personal identifier. Therefore, the Privacy Act does not apply to this system, and no separate Privacy Act
Statement or Advisory is necessary. “Not applicable” should be checked in section 1g of the PIA. However, DMHRSi will collect PII
directly from other DoD information systems, and the system owners should monitor the Privacy Act compliance posture of those source
systems.
h. With whom will the PII be shared through data/system exchange, both within your DoD Component and outside your Component?
(Check all that apply)

Defense Health Agency (DHA) Military Treatment
Facilities (MTFs) worldwide
PII data is shared with the Army, Air Force, DHA, Navy,
and senior leadership to support the MHS with a fully
Specify. functional HR management system that consolidates
medical personnel information and provides enhanced
reporting capabilities.

Within the DoD Component

Specify.

Other DoD Components (i.e. Army, Navy, Air Force)

Other Federal Agencies (i.e. Veteran’s Affairs, Energy, State)

Specify.

State and Local Agencies

Specify.

DD FORM 2930, JUN 2017

Department of Veterans Affairs

PREVIOUS EDITION IS OBSOLETE.

AEM Designer

Page 2 of 12

Cape Fox Contract Language: Specifically references DHA
Procedures, Guidance and Information 224.90.
The NikSoft Systems Corporation Contract Language:
The contractor shall comply with DoD 8570.01-M,
“Information Assurance Workforce Improvement Program,
CH4” November 10, 2015 as amended; 8500.01,
“Cybersecurity”, dated March 14, 2014; DoD Manual
(DoDM) 6025.18, “Implementation of the Health Insurance
Portability and Accountability Act (HIPAA) Privacy Rule
Compliance in DoD Health Care Programs” dated March 3,
2019, Department of Defense Instruction (DoDI) 6025.18
“HIPAA Privacy Rule Compliance in DoD Health Care
Programs”, dated March 13, 2019; and DoDM 5200.02
“Procedures for the DoD Personnel Security Program
(PSP),” incorporation change 3, effective September 24,
2020.

Contractor (Name of contractor and describe the language in
the contract that safeguards PII. Include whether FAR privacy
clauses, i.e., 52.224-1, Privacy Act Notification, 52.224-2,
Privacy Act, and FAR 39.105 are included in the contract.)

Planned Systems International (PSI) Contract Language:
The Contractor shall establish appropriate administrative,
technical, and physical safeguards to protect any and all
Government data. The Contractor shall also ensure the
confidentiality, integrity, and availability of Government
data in compliance with all applicable laws and regulations,
including data breach reporting and response requirements,
Specify. in accordance with DFAR Subpart 224.1 (Protection of
Individual Privacy), which incorporates by reference DoDD
5400.11, “DoD Privacy Program,” May 8, 2007, and DoD
5400.11-R, “DoD Privacy Program,” May 14, 2007. The
Contractor shall also comply with federal laws relating to
freedom of information and records management.
Irving Burton Associates Contract Language:
Personally Identifiable Information (PII), Protected Health
Information (PHI), and Federal Information Requirements
(refer to Clause Section for DHA Procedures, Guidance and
Information 224.90 if applicable).
“The Contractor shall establish appropriate administrative,
technical, and physical safeguards to protect any and all
Government data, to ensure the confidentiality, integrity,
and availability of Government data.” Also, the contractor's
company must have a valid Data Sharing Agreement on file
with the Defense Health Agency Privacy and Civil Liberties
Office prior to their employees accessing the DMHRSi
system.
“The contractor will comply with the requirements in Office
of Management and Budget (OMB) Circular A-130, in the
DoD Directive 5400.11, “DoD Privacy Program,” October
29, 2014, and in the DoD 5400.11-R, “Department of
Defense Privacy Program,” May 14, 2007.”

Other (e.g., commercial providers, colleges).

Specify.

i. Source of the PII collected is: (Check all that apply and list all information systems if applicable)
Individuals

Databases

Existing DoD Information Systems

Commercial Systems

Other Federal Information Systems

DD FORM 2930, JUN 2017

PREVIOUS EDITION IS OBSOLETE.

AEM Designer

Page 3 of 12

System-to-System – for Active Duty and Federal employees, PII is sourced from the following Service and Federal personnel HR systems:
• Department of Defense, Army Training Management System (ATMS) - Digital Training Management System (DTMS)
• Department of Defense, Centralized Credentials Quality Assurance System (CCQAS)
• Federal Information System, Center for Medicare and Medicaid Services (CMS) for National Provider Identification Number
• Department of Defense, Defense Civilian Personnel Data System (DCPDS)
• Department of Defense, Defense Civilian Pay System (DCPS)
• Department of Defense, Defense Manpower Data Center (DMDC) EBLLS
• Department of Defense Healthcare Management System Modernization (DHMSM) Program - CLARIVA
• Department of Defense, Integrated Personnel and Pay System - Army (IPPS-A)
• Department of Defense, Joint Knowledge Online (JKO)
• Department of Defense, Medical Operational Data System - Enlisted (MODSE)
• Department of Defense, Medical Operational Data System - Guard (MODSG)
• Department of Defense, Medical Operational Data System - Officer (MODSO)
• Department of Defense, Medical Operational Data System - Reserve (MODSR)
• Department of Defense, Medical Readiness Decision Support System - Unit Level training and Reporting Application (MRDSS-ULTRA)
• Department of Defense, Military Health System (MHS) Data Repository (MDR)
• Department of Defense, Military Personnel Data System (MILPDS)
• Department of Defense, Navy Standard Integrated Personnel System Active - Enlisted (NSIPS Active Enlisted)
• Department of Defense, Navy Standard Integrated Personnel System Reserve - Enlisted (NSIPS Reserve Enlisted)
• Department of Defense, Navy Standard Integrated Personnel System Active - Officer (NSIPS Active Officer)
• Department of Defense, Navy Standard Integrated Personnel System Reserve - Officer (NSIPS Reserve Officer)
• Department of Defense, Navy Training Management and Planning System (NTMPS)
j. How will the information be collected? (Check all that apply and list all Official Form Numbers if applicable)
E-mail

Official Form (Enter Form Number(s) in the box below)

In-Person Contact

Paper

Fax

Telephone Interview

Information Sharing - System to System

Website/E-Form

Other (If Other, enter the information in the box below)

DMHRSi URL: https://dmhrsi.csd.disa.mil
In-Person Contact - Data on contractors, some foreign nationals, and volunteers are manually entered into the DMHRSi system. These
individuals do not come across from a Federal personnel system. Their information is collected by entering the informtiaon through the
front end application. Manually entering data can only be done by users with the proper role authorization.
Information Sharing from System to System – DMHRSi collects most of the data through formal data interfaces via DoD controlled
networks from DoD and Service/Federal personnel systems. This process covers the data related to Active Duty military, Federal
employees, National Guard, and Reserve personnel.
k. Does this DoD Information system or electronic collection require a Privacy Act System of Records Notice (SORN)?
A Privacy Act SORN is required if the information system or electronic collection contains information about U.S. citizens or lawful permanent U.S. residents that
is retrieved by name or other unique identifier. PIA and Privacy Act SORN information must be consistent.
Yes

No

If "Yes," enter SORN System Identifier
SORN Identifier, not the Federal Register (FR) Citation. Consult the DoD Component Privacy Office for additional information or http://dpcld.defense.gov/
Privacy/SORNs/
or
If a SORN has not yet been published in the Federal Register, enter date of submission for approval to Defense Privacy, Civil Liberties, and Transparency
Division (DPCLTD). Consult the DoD Component Privacy Office for this date
If "No," explain why the SORN is not required in accordance with DoD Regulation 5400.11-R: Department of Defense Privacy Program.

Applicable System of Records Notice (SORN): DMHRSi will not collect any personally identifiable information (PII) from individuals to
be stored in a system of records and retrieved by a personal identifier. Therefore, no SORN is necessary. However, DMHRSi will collect
PII directly from other DoD information systems, and the system owners should monitor the SORN compliance posture of those source
systems.
l. What is the National Archives and Records Administration (NARA) approved, pending or general records schedule (GRS) disposition authority

DD FORM 2930, JUN 2017

PREVIOUS EDITION IS OBSOLETE.

AEM Designer

Page 4 of 12

for the system or for the records maintained in the system?
(1) NARA Job Number or General Records Schedule Authority.

DAA-0330-2016-0014

(2) If pending, provide the date the SF-115 was submitted to NARA.

(3) Retention Instructions.

Cut off upon notification separation or termination from MHS assignment and/or employment. Destroy contractor, volunteer, and duplicate
data on Active Duty, Guard, Reserve, and Federal Government employees from other military service electronic information systems 4
year(s) after cutoff.
m. What is the authority to collect information? A Federal law or Executive Order must authorize the collection and maintenance of a system of
records. For PII not collected or maintained in a system of records, the collection or maintenance of the PII must be necessary to discharge the
requirements of a statue or Executive Order.
(1) If this system has a Privacy Act SORN, the authorities in this PIA and the existing Privacy Act SORN should be similar.
(2) If a SORN does not apply, cite the authority for this DoD information system or electronic collection to collect, use, maintain and/or disseminate PII.
(If multiple authorities are cited, provide all that apply).
(a) Cite the specific provisions of the statute and/or EO that authorizes the operation of the system and the collection of PII.
(b) If direct statutory authority or an Executive Order does not exist, indirect statutory authority may be cited if the authority requires the
operation or administration of a program, the execution of which will require the collection and maintenance of a system of records.
(c) If direct or indirect authority does not exist, DoD Components can use their general statutory grants of authority (“internal housekeeping”) as
the primary authority. The requirement, directive, or instruction implementing the statute within the DoD Component must be identified.

DoD 6010.13-M, Medical Expense Performance Reporting System (MEPRS) for Fixed Medical and Dental Treatment Facilities; DoD
5136.1-P, Medical Readiness Strategic Plan (MHSP); E.O. 12656, Assignment of Emergency Preparedness Responsibilities; and E.O. 9397
(SSN), as amended.
n. Does this DoD information system or electronic collection have an active and approved Office of Management and Budget (OMB) Control
Number?
Contact the Component Information Management Control Officer or DoD Clearance Officer for this information. This number indicates OMB approval to
collect data from 10 or more members of the public in a 12-month period regardless of form or format.
Yes

No

Pending

(1) If "Yes," list all applicable OMB Control Numbers, collection titles, and expiration dates.
(2) If "No," explain why OMB approval is not required in accordance with DoD Manual 8910.01, Volume 2, " DoD Information Collections Manual:
Procedures for DoD Public Information Collections.”
(3) If "Pending," provide the date for the 60 and/or 30 day notice and the Federal Register citation.

OMB Control Number: 0720-0041
Title: Defense Medical Human Resources System Internet (DMHRSi)
Expiration Date: 03/31/2022

DD FORM 2930, JUN 2017

PREVIOUS EDITION IS OBSOLETE.

AEM Designer

Page 5 of 12


File Typeapplication/pdf
File TitleDD 2930, Privacy Impact Assessment (PIA), Jun 2017.pdf
AuthorHechtAS
File Modified2022-03-28
File Created2022-03-28

© 2024 OMB.report | Privacy Policy