Inventory Management System Public Housing Information

IMS PIC PIA (7) 5-23-23.pdf

Family Report, MTW Family Report, MTW Expansion Family Report

Inventory Management System Public Housing Information

OMB: 2577-0083

Document [pdf]
Download: pdf | pdf
Department of Housing and Urban Development (HUD) Privacy Impact Assessment (PIA)
Prescribing Authority: Public Law 107-347, Section 208(b). Complete this form for Department of Housing and Urban
Development information systems or electronic collections (referred to as "electronic collections" for the purpose of this
form) of information that collect, maintain, use, and / or disseminate Personally Identifiable Information (PII) about members
of the public, Federal employees, and contractors. In the case where no PII is collected, the PIA will serve as a conclusive
determination that privacy requirements do not apply to the system. Please be sure to use plain language and be as concise as
possible.

HUD’s PIAs describe: (1) the legal authority that permits the collection of information; (2) the specific type of information
used by the system; (3) how and why the system uses the information; (4) whether the system provides notice to individuals
that their information is used by the system; (5) the length of time the system retains information; (6) whether and with whom
the system disseminates information; (7) procedures individuals may use to access or amend information used by the system;
and (8) physical, technical, and administrative safeguards applied to the system to secure the information.
Note: Program Offices utilizing Shared Drive and SharePoint locations to store information such as PII are required to
conduct a PIA. Program Offices completing a PIA for PII storage in the HUD Shared Drive will use will use either CSAM
ID P207, P209, P212 or 1098 whereas the PIA for PII storage in SharePoint will use the CSAM ID D100. After completion
of all required information in the PIA, PIA are required to be routed to the Shared Drive Administrator and/or SharePoint
Administrator for signature approval in addition to all the required signatures.
For further information and
instructions
on how to fill out the PIA, please see the PIA Reference Guide. Please submit all
CSAM
ID:
completed PIAs using the submission feature located at the bottom of page 7.

1. HUD INFORMATION SYSTEM: P113 - Inventory Management System/ Public Housing Information
2. HUD DIVISION NAME: PIH
3. CSAM ID: 1015

Center

Section 1: PII Description Summary (For Public Release)
a. The PII is: (Check all that apply)
✔ From members of the general public

✔ From a third-party source

✔ From Federal employees and / or Federal contractors

✔ From vendors

b. The PII is in a / an: (Check one)
New HUD Information System
✔ Existing HUD Information System
Significantly modified HUD Information System (if selected,

No PII (Fill out 1c &1l, then go to Section 4)
Other (Please specify in the box below)

New collection
Existing collection

please describe the modification in the box below)

c. Describe the purpose of this HUD information system or project, including the types of personal
information collected within the system.

d.

IMS/PIC serves as a national repository of information related to Public Housing Authorities (PHAs), HUD-assisted
families, and HUD-assisted properties, to provide rental assistance, information sharing, monitoring, and
evaluating the effectiveness of PIH programs and subsidies. IMS/PIC allows HUD to collect and maintain records
on individuals and organizations administering, participating in, or potentially affected by, housing assistance
programs administered by HUD. Information is retrieved by property physical characteristics while personal data
Why
is the
PII collected
andand
/ orpersonal
what isdescription.
the intended
use are
of the
PII? (e.g.
verification,
identification,
involves
physical
composition
Reports
generated
using
a combination
of both data,
authentication,
dataAuthority’s
matching, mission-related
use,
administrative
while Housing
monitor and use
personal
data. use)
The PII collected is used by HUD and entities that administer HUD assisted housing programs to perform the
1
IMS-PIC includes PIC Maintenance, PIH Information, Housing Inventory, Executive Summary, Form 50058,
following:
andand
MTW
as matching
a sub-components
of the
system.
-ADHOC
Verification
data
using Social
Security
Numbers and income information in order to deter and detect
abuses and to increase the effective distribution of rental assistance to individuals that meet the requirements of
Typed
PII collected:
Full
Name, Age, Citizenship, Date of Birth, Employment status, Financial information,
federalofrental
assistance
programs

e. Do individuals have the opportunity to object to the collection of their PII?
If “Yes,” describe the method by which individuals can object to the PII collection.
If “No,” state the reason why individuals cannot object to the PII collection.

f.

✔ Yes

No

Individuals have the opportunity to object to the collection of their PII via HUD Form 9866, Authorization for the
Release of Information/Privacy Act Notice. Those who do not consent to the collection of their PII are subject to
denial of their eligibility or termination of assisted housing benefits, or both; however denial is subject ✔to grievance
Yes
No
Doand
individuals
have the opportunity to consent to the specific uses of their PII?
hearing procedures.

If “Yes,” describe the method by which individuals can give or withhold their consent.
The form states:
If “No,”
state
the reason
cannot
give orform
withhold
theirinconsent.
Failure
to Sign
Consent
Form: why
Your individuals
failure to sign
the consent
may result
the denial of eligibility or
termination
of
assisted
housing
benefits,
or
both.
Denial
of
eligibility
or
termination
of benefits
subjectover
to the
Individuals have the opportunity to consent to the uses of their PII. All applicants and
annuallyistenants
theHA’s
grievance
procedures
and
Section
8
informal
hearing
procedures.
age of 18 are asked to sign form HUD 9886 Authorization for the Release of Information/Privacy Act Notice.

g. When
an states:
individual is asked to provide PII, is a Privacy Act Statement (PAS) and / or a Privacy
The form
Failure
to
Sign
Consent(Please
Form:provide
Your failure
to sign
the consent
form
may
result
the
denial of eligibility or
Advisory provided?
the actual
wording
in the box
below
and
checkinas
appropriate)
termination of assisted housing benefits, or both. Denial of eligibility or termination of benefits is subject to the HA’s
✔ Privacy Act Statement
☐
☐hearing
Privacyprocedures.
Advisory
☐ Not Applicable
grievance
procedures and Section 8 informal
Purpose: IMS/PIC serves as a national repository of information related to Public Housing Authorities (PHA5),
Tribally Designated Housing Entities (TDHE), HUD-assisted families, HUD-assisted properties, and other HUD
programs, for the purpose of monitoring and evaluating the effectiveness of PIH rental housing assistance
programs. IMS/PIC allows PHAs, TDHEs, and their-hired management agents to electronically submit information
to HUD that is related to the administration of HUD’s Pill programs. It collects data for PIH operations, including
data submitted via the Internet from HUDs field offices, and accurately tracks activities and processes.
Authorities: The U.S. Housing Act of 1937, as amended, 42 U.S.C. 1437; Title VI of the Civil Rights Act of 1962
(42 U.S.C.
2000d);
ThePII
Fairbe
Housing
(42 U.S.C.
3601-3619);
Housing
Community
Development
Act of
h. With
whom
will the
sharedAct
through
data
exchange,The
both
within
your HUD
Division and
outside
1981, Public Law 97-35, 85 stat., 348,408; and The Housing and Community Development Act of 1987, 42 U.S.C.
your Division? (Check all that apply)
3543.
PIH Rental Assistance Programs, Office of Public
Routine Uses: Please see SORN for all Routine Uses.
✔ Within the HUD Office / Division
☐
Housing
and Voucher
Programs,
Office of Public
Disclosure:
Voluntary. Refusal to provide information could result
in applications
not being
processed.
the
Office
of
the Inspector
General,
Public
Housing
Housing
the Real
Estate
Assessment
SORN
ID andHUD
URL:Office(s)
PIH/FRN /- Division(s)
Inventory Management System (Public
andInvestments,
Indian
Housing
Information
Center
✔ Other
☐
Occupancy
Division,
Office
of Policy
Development
Center, the Office
of the
Inspector
General,
Public
(IMS/PIC)) https://www.hud.gov/sites/dfiles/OCHCO/documents/IMSsorn.pdf
Social
Security Office
Administration,
Federal Emergency
and
Research,
of Chief Office
Financial
Officer
✔ Other federal agencies
☐
Housing
Occupancy Division,
of Policy
Management Agency, Universal Service
Development
and
Research
Public
Housing
Agencies
will be able to see the PII
Administrative
Company
(USAC)/Federal
✔ State & local agencies
☐
data
that
they
submit
to
validate
proper
submission.
Communications Committee (FCC),
Department
of
☐ Contractors (Include name of contractor and
Health and Human Services, U.S. Department of
Veterans Affairs (VA)
describe the language in the contract that safeguards PII in the box below.)

☐ Other

i.

Source(s) of the PII collected is / are: (Check all that apply & list all information systems if applicable)
✔ Databases
☐
✔ Individuals
☐
☐ Publicly available data (e.g., obtained from
☐ Existing HUD information systems
✔ Other Federal information systems
☐

j.

internet, news feeds, court records)

IMS/PIC receives PII from HUD staff; HUD contractors; PHAs, and their hired management agents; the Social
Security Administration; the Department of Veteran Affairs; the Federal Emergency Management Agency; the
Federal Communications Commission and other state and local agencies.
How will the information be collected? (Check all that apply & list all Official Form Numbers if applicable)

☐ Encrypted Email
✔ Face-to-face contact
☐
☐ Fax

✔ Information sharing /system-to system
☐
✔ Official form
☐

✔ Telephone interview
☐
✔ Website / e-form
☐
✔ Paper
☐

☐
✔ Other (if selected, enter information in the box )

HUD-50058, Family Report
HUD 50058-MTW, MTW Family Report and MTW Expansion
HUD 52723, Operating Fund Calculation of Operating Subsidy
HUD 52722, Operating Fund Calculation of Utilities Expense Level
HUD-9886, Authorization for the Release of Information/Privacy Act Notice

2

k. Does this HUD information system require a Privacy Act System of Records Notice (SORN)?
A SORN is required if the information system contains information about U.S. citizens or lawful permanent
U.S. residents that is retrieved by name of another unique identifier. PIA and Privacy Act SORN
information must be consistent.
✔

Yes

No

If “Yes” enter SORN System Identifier:
If a SORN has not yet been published in the Federal Register, enter date of submission for approval.
If "No" explain why the SORN is not required.
HUD/PIH.FRN 01 - Inventory Management System (Public and Indian Housing Information Center (IMS/PIC), CPO
approved as "good faith" 15 Jun 2022.

l. What is the National Archive and Records Administration (NARA) approved, pending, or General
Records Schedule (GRS) disposition authority for the system or for the records maintained in the
system?(Please consult Office of Records Management to assure that the following information is accurate)
(1) NARA Job Number or GRS Authority: NC1-207-96-5
(2) If pending, provide the date the SF-115 was submitted to NARA:
(3) Retention instructions:
Electronic records are maintained and destroyed in accordance with requirements of the HUD Records Disposition
Schedule, 2225-6. In accordance with 24 CFR 908.101 and HUD record retention requirements at 24 CFR 85.42, PHAs
are required to retain at least three years’ worth of IMS/PIC data either electronically or in paper form.

m. What is the authority to collect information? A Federal law or Executive Order must authorize the
collection and maintenance of a system of records. For PII not collected or maintained in a system of
records, the collection or maintenance of the PII must be necessary to discharge the requirements of a
statue or Executive Order.
The U.S. Housing Act of 1937, as amended, 42 U.S.C. 1437; 42 U.S.C. 3543, Preventing fraud and abuse in
Department of Housing and Urban Development programs. Title VI of the Civil Rights Act of 1962 (42 U.S.C. 2000d);
The Fair Housing Act (42 U.S.C. 3601-3619); The Housing Community Development Act of 1981, Public Law 97-35, 85
stat., 348,408; and The Housing and Community Development Act of 1987, 42 U.S.C. 3543. 24 CFR Part 908,
Electronic Transmission of Required Family Data for Public Housing, Indian Housing and Section 8 Rental Certificate,
Rental Voucher and Moderate Rehabilitation Programs; 42 U.S.C. Ch. 68: Disaster Relief § 5121 et seq, Congressional
Findings and Declaration.

n. Does this Information System or E-Collection have an active and approved Office of
Management and Budget (OMB) Control Number?
This number indicates OMB approval to collect data from 10 or more members of the public in a 12-month
period regardless of form or format.
Yes No Pending
If “Yes,” list all applicable OMB Control Numbers, collection titles, and expiration dates.
If “No,” explain why OMB approval is not required in accordance with proper HUD authority.
If “Pending,” provide the date for the 60 and / or 30 day notice and the Federal Register citation.
✔

- OMB Control Number 2577-0083, Family Report, MTW Family Report, MTW Expansion Family Report, Expiration
date: 12/31/2023
- OMB Control Number 2577-0266, Enterprise Income Verification (EIV) System - Debts owed to Public Housing
Agencies and Terminations, Expiration date: 4/30/2023
- OMB Control Number 2577-0178, Family Self-Sufficiency Program (FSS), Expiration date: 4/30/2025
- OMB Control Number 2577-0296, Project Based Voucher (PBV) Online Form, Expiration date: 1/31/2024

3

Section 2: PII Risk Review
a. What PII will be collected or maintained on the information system or project: (Check all that apply)
✔ Age
☐
☐ Alias
☐ Audio Recordings
☐ Biometrical Identifiers (e.g.,
fingerprint(s), iris image)

✔ Employment Status, History, or
☐
Information (e.g., title, position)
☐ Fax Number
✔ Financial Information (e.g.,
☐
credit report, account number)

☐ Foreign activities
✔ Full Name
☐
marriage)
✔ Citizenship(s)
☐ Gender
☐
☐ Geolocation Information
☐ Credit Card Number
✔ Home Address
☐ Criminal records information
☐
✔ Date of Birth
☐
☐ Internet Cookie Containing PII
☐ Device identifiers (e.g., mobile
☐ Investigation Report or Database
devices)
☐ IP / MAC Address
☐ Drivers’ License / State ID
☐ Legal Documents, Records
Number
☐ Marital Status
☐ Education Records
☐ Military status or other
☐ Email Address(es)
information
☐ Employee Identification Number ☐ Mother’s Maiden Name
☐ Passport Information
☐ Certificates (e.g., birth, death,

☐ Phone Number(s)
☐ Photographic Identifiers (e.g.,
photograph, video, x-ray)

☐ Place of Birth
☐ Protected Health Information
✔ Race / Ethnicity
☐
☐ Religion
✔ Salary
☐
✔ Sex
☐
✔ Social Security Number
☐
(SSN) (Full or in any form)

☐ Taxpayer ID
☐ User ID
☐ Vehicle Identifiers (e.g.,
license plate)

☐ Web uniform resource
locator(s)
☐ Work Address
✔ Other (if selected, please
☐

enter the information below)

Relationship to head of household, disability status, alien registration number, family income and asset
information.

b. If the SSN is collected, please list the proper HUD authority to do so.
The U.S. Housing Act of 1937, as amended, 42 U.S.C. 1437; 42 U.S.C. 3543, Preventing fraud and abuse in
Department of Housing and Urban Development programs;, 24 CFR Part 908, Electronic Transmission of
Required Family Data for Public Housing, Indian Housing and Section 8 Rental Certificate, Rental Voucher and
Moderate Rehabilitation Programs; 42 U.S.C. Ch. 68: Disaster Relief § 5121 et seq, Congressional Findings
and Declaration.

4

Section 3: PII Security Measures

a. How will the PII be secured? (Include any physical, administrative, technical controls, and other controls place)
(1) Physical Controls. (Check all that apply)
Cipher locks
Combination locks
Key cards
Security Guards

Closed Circuit TV
Identification badges
Safes
✔ If Other, enter the information in the box below

Computer files and printed listings are maintained in locked cabinets. User’s access, updates access, read-only
access, and approval access based on the user’s role and security access level.

(2) Administrative Controls. (Check all that apply)
✔ Backups Secured Off-Site
✔ Encryption of Backups
✔ Methods to Ensure Only Authorized
Personnel Access to PII

✔ Periodic Security Audits

Regular Monitoring of Users' Security Practices
If Other, enter the information in the box below

(3) Technical Controls (Check all that apply)
Biometrics
✔ Encryption of Data at Rest
✔
✔
✔
✔

Firewall
Role-Based Access Controls
Virtual Private Network (VPN)
Encryption of Data in Transit
Used Only for Privileged (Elevated Roles)

Public Key Infrastructure Certificates
✔ External Certificate Authority Certificates
✔ Least Privilege Access
✔ User Identification and Password
✔ PIV Card
✔ Intrusion Detection System (IDS)

If Other, enter the information in the box below

b. What additional measures / safeguards have been put in place to address privacy risks for
this information system or electronic collection? (Input N/A if not applicable)

c.

Risks Related to Information Sharing - Each Agency sharing information with IMS/PIC has a signed Computer
Matching Agreement detailing the information being exchanged, and the purpose to which that information can be
used, if/how long the information can be retained, whether it can be duplicated, and whether it can be disseminated
to other parties. Enterprise authentication and authorization services for role based access ensure the Government
Where
PIIonly
stored
within
the system?
(Checkinall
apply)
Agencyiscan
access
the information
detailed
thethat
CMA.
All information is encrypted in transit, and strong
authentication
procedures
are
required
for
Agency
authentication.
The CMAs
detail the audit logging requirements
✔
☐ In hard copy
documents
☐ On a centralized HUD server
for the IMS/PIC system on information shared, it also details the procedures and points of contact if a there is a
☐
(Please ifspecify
in the box
below)
✔ Other
☐ Ondata
individual
laptops
suspected
breach. HUD
The CMAs
are reviewed annually
to determine
they should
be renewed.

☐ In e-mails

RisksPlease
Relatedspecify
to Retention
- Records
are retained for extended lengths of tie due to reporting requirements;
selection(s)
made.
therefore the following mitigation is done:
· Review
current holdings
of of
PIIrecords.
and ensure
arereferenced
accurate, relevant,
timely,
and complete
On
PHA controlled
systems
Thethey
SORs
here are the
systems
owned and controlled by the
· Reduce
PII holdings to the minimum necessary for proper performance of agency functions
PHAs
themselves.
· Develop a schedule for periodic review of PII holdings
· Establish a plan to eliminate the unnecessary collection and use of SSNs.

d. Indicate the assessment and authorization status:
Risks Related to Redress - To provide effective redress, HUD (i) provides effective notice of the existence of a PII
✔ Authorization to Operate (ATO)
12/20/18
Dateand
Granted:
collection; (ii) provides plain language explanations of the processes
mechanisms
for requesting access to
ATO
Conditions
Date orGranted:
records;
(iii)with
establishes
criteria for submitting requests for correction
amendment; (iv) implements resources to
analyze
and adjudicate
requests;
implements
theInterim
means of correcting
or amending data collections; and (vi)
Denial
of Authorization
to(v)
Operate
(DATO)
Date Granted:
reviews
any
decisions
that
may
have
been
the
result
of
inaccurate
information.
Authorization to Test (ATT)
Date Granted:

5

Section 4: Review and Approval Signatures
Completion of the PIA requires coordination by the System Manager, Information System Security Officer, Privacy
Liaison Officer, and HUD Records Officer BEFORE it is sent to the HUD Privacy Office. HUD Privacy Office will
review and forward to HUD Chief Privacy Officer and Senior Agency Official for Privacy for signature.
Signatures for PII Storage in Shared Drive and Share Point PIAs:
*If PIA is regarding PII storage on Shared Drive, PIA must be routed to the Shared Drive Administrator for signature.
**If PIA is regarding PII storage on SharePoint, PIA must be routed to both the Shared Drive AND SharePoint
Administrators for signature.

System Manager (or Shared Drive Administrator if applicable*):
Name: Robert Dalzell

4/18/22

Digitally signed by
ROBERT
ROBERT DALZELL
2022.04.18
DALZELL Date:
Signature: _____________________
16:50:39 -04'00'

SharePoint Administrator (if applicable)**:
Name: N/A

Signature: _____________________

Information System Security Officer:
Name: Rodney Gunn

4/19/22

signed by
RODNEY Digitally
RODNEY GUNN
Date: 2022.04.19
GUNN
07:42:54 -04'00'
Signature: _____________________

Records Management Liaison Officer:
Name: Daniella Mungo

5/6/22

signed by
DANIELLA Digitally
DANIELLA MUNGO
Date: 2022.05.06
MUNGO
Signature: ____________________
17:40:42 -04'00'

Privacy Liaison Officer:
Name: Huy Le

3/8/22

HUY LE

Digitally signed by HUY
LE
Date: 2022.03.08
06:56:07 -05'00'

Signature: _____________________

HUD Records Officer:
Name: Marcus Smallwood

Signature:

5/19/22

Digitally signed by: MARCUS SMALLWOOD
DN: CN = MARCUS SMALLWOOD C = US O =
U.S. Government OU = Department of Housing
and Urban Development, Office of Administration
Date: 2022.05.09 13:09:32 -04'00'

MARCUS
SMALLWOOD
_____________________

Once all required signatures are collected on this page, please send PIA to the HUD Privacy Office via the privacy
submission button on page 7.

6

Section 4: Review and Approval Signatures Continued
HUD Privacy Office will route the PIA to Chief Privacy Office and Senior Agency Official for Privacy for signatures.

HUD Chief Privacy Officer:

Name: FOR - LaDonne White
SHALANDA

Digitally signed by SHALANDA
CAPEHART

Date: 2022.08.24 10:03:24 -04'00'
Signature: CAPEHART
_____________________

8/24/22

Senior Agency Official for Privacy:
Name:

Bradley S. Jewitt
BRADLEY JEWITT

Digitally signed by BRADLEY
JEWITT
Date: 2022.08.30 21:27:31 -04'00'

Signature: _____________________

8/30/22

PIH-33

PIA NUMBER: _________________________________
8/30/22

PIA APPROVAL DATE: _________________________
Once completed, FOLFNWKHEHORZEOXHEXWWRQWRHPDLOWKHFRPSOHWHFRS\WRWKH3ULYDF\iQER[ ([email protected])
1RWHWKDWonly Section 1 of this PIA will be published to HUD's public website.

Submit to Privacy Inbox

Please check the boxes below that are relevant to your Annual Certification and PIA process.

✔ This is a new PIA
This is a revision for an existing PIA
This is an annual certification for an existing PIA
This is a correction for an existing publication
This is a Notification of Rescindment for an existing PIA

7
Last Updated 3/04/2021


File Typeapplication/pdf
AuthorBogale, Rahel
File Modified2022-08-31
File Created2019-12-09

© 2024 OMB.report | Privacy Policy